- EPSS 9.79%
- Veröffentlicht 06.12.2010 13:44:54
- Zuletzt bearbeitet 16.06.2026 23:23:08
named in ISC BIND 9.7.2-P2 does not check all intended locations for allow-query ACLs, which might allow remote attackers to make successful requests for private DNS records via the standard DNS query mechanism.
CVE-2010-3762
- EPSS 8.09%
- Veröffentlicht 05.10.2010 22:00:06
- Zuletzt bearbeitet 16.06.2026 23:23:28
ISC BIND before 9.7.2-P2, when DNSSEC validation is enabled, does not properly handle certain bad signatures if multiple trust anchors exist for a single zone, which allows remote attackers to cause a denial of service (daemon crash) via a DNS query.
- EPSS 3.5%
- Veröffentlicht 05.10.2010 22:00:01
- Zuletzt bearbeitet 16.06.2026 23:15:43
ISC BIND 9.7.2 through 9.7.2-P1 uses an incorrect ACL to restrict the ability of Recursion Desired (RD) queries to access the cache, which allows remote attackers to obtain potentially sensitive information via a DNS query.
CVE-2010-0213
- EPSS 6.52%
- Veröffentlicht 28.07.2010 12:48:51
- Zuletzt bearbeitet 16.06.2026 23:15:43
BIND 9.7.1 and 9.7.1-P1, when a recursive validating server has a trust anchor that is configured statically or via DNSSEC Lookaside Validation (DLV), allows remote attackers to cause a denial of service (infinite loop) via a query for an RRSIG recor...
CVE-2010-0097
- EPSS 9.36%
- Veröffentlicht 22.01.2010 22:00:00
- Zuletzt bearbeitet 16.06.2026 23:15:28
ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a f...
- EPSS 6.78%
- Veröffentlicht 22.01.2010 22:00:00
- Zuletzt bearbeitet 16.06.2026 23:15:51
Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisonin...
CVE-2010-0382
- EPSS 7.24%
- Veröffentlicht 22.01.2010 22:00:00
- Zuletzt bearbeitet 16.06.2026 23:16:03
ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta handles out-of-bailiwick data accompanying a secure response without re-fetching from the original source, which allows remote attackers to ha...
CVE-2009-4022
- EPSS 7.95%
- Veröffentlicht 25.11.2009 16:30:00
- Zuletzt bearbeitet 16.06.2026 23:12:51
Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS c...
CVE-2009-0696
- EPSS 12.65%
- Veröffentlicht 29.07.2009 17:30:00
- Zuletzt bearbeitet 16.06.2026 23:05:35
The dns_db_findrdataset function in db.c in named in ISC BIND 9.4 before 9.4.3-P3, 9.5 before 9.5.1-P3, and 9.6 before 9.6.1-P1, when configured as a master server, allows remote attackers to cause a denial of service (assertion failure and daemon ex...
CVE-2009-0265
- EPSS 2.47%
- Veröffentlicht 26.01.2009 15:30:04
- Zuletzt bearbeitet 16.06.2026 23:04:37
Internet Systems Consortium (ISC) BIND 9.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature...