CVE-2009-0025
- EPSS 6.86%
- Veröffentlicht 07.01.2009 17:30:00
- Zuletzt bearbeitet 16.06.2026 23:04:06
BIND 9.6.0, 9.5.1, 9.5.0, 9.4.3, and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulne...
CVE-2008-4163
- EPSS 4.65%
- Veröffentlicht 22.09.2008 18:52:13
- Zuletzt bearbeitet 16.06.2026 22:57:17
Unspecified vulnerability in ISC BIND 9.3.5-P2-W1, 9.4.2-P2-W1, and 9.5.0-P2-W1 on Windows allows remote attackers to cause a denial of service (UDP client handler termination) via unknown vectors.
CVE-2008-1447
- EPSS 95.18%
- Veröffentlicht 08.07.2008 23:41:00
- Zuletzt bearbeitet 16.06.2026 22:51:45
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and other implementations allow remote attackers to spoof DNS traffic vi...
- EPSS 12.3%
- Veröffentlicht 16.01.2008 02:00:00
- Zuletzt bearbeitet 16.06.2026 22:48:59
Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code...
CVE-2007-2930
- EPSS 7.59%
- Veröffentlicht 12.09.2007 01:17:00
- Zuletzt bearbeitet 16.06.2026 22:40:43
The (1) NSID_SHUFFLE_ONLY and (2) NSID_USE_POOL PRNG algorithms in ISC BIND 8 before 8.4.7-P1 generate predictable DNS query identifiers when sending outgoing queries such as NOTIFY messages when answering questions as a resolver, which allows remote...
CVE-2007-2925
- EPSS 6.15%
- Veröffentlicht 24.07.2007 17:30:00
- Zuletzt bearbeitet 16.06.2026 22:40:42
The default access control lists (ACL) in ISC BIND 9.4.0, 9.4.1, and 9.5.0a1 through 9.5.0a5 do not set the allow-recursion and allow-query-cache ACLs, which allows remote attackers to make recursive queries and query the cache.
CVE-2007-2926
- EPSS 13.09%
- Veröffentlicht 24.07.2007 17:30:00
- Zuletzt bearbeitet 16.06.2026 22:40:42
ISC BIND 9 through 9.5.0a5 uses a weak random number generator during generation of DNS query ids when answering resolver questions or sending NOTIFY messages to slave name servers, which makes it easier for remote attackers to guess the next query i...
CVE-2007-2241
- EPSS 7.55%
- Veröffentlicht 02.05.2007 10:19:00
- Zuletzt bearbeitet 16.06.2026 22:39:12
Unspecified vulnerability in query.c in ISC BIND 9.4.0, and 9.5.0a1 through 9.5.0a3, when recursion is enabled, allows remote attackers to cause a denial of service (daemon exit) via a sequence of queries processed by the query_addsoa function.
CVE-2007-0493
- EPSS 12.08%
- Veröffentlicht 25.01.2007 20:28:00
- Zuletzt bearbeitet 16.06.2026 22:35:41
Use-after-free vulnerability in ISC BIND 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (named daemon crash) via unspecified vectors that c...
CVE-2007-0494
- EPSS 43.36%
- Veröffentlicht 25.01.2007 20:28:00
- Zuletzt bearbeitet 16.06.2026 22:35:41
ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (exit) via a type * (ANY) DNS query response that ...