CVE-2020-8624
- EPSS 3.67%
- Veröffentlicht 21.08.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:39:08
In BIND 9.9.12 -> 9.9.13, 9.10.7 -> 9.10.8, 9.11.3 -> 9.11.21, 9.12.1 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.12-S1 -> 9.9.13-S1, 9.11.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker who has been granted privileges to ch...
CVE-2020-8619
- EPSS 2.11%
- Veröffentlicht 17.06.2020 22:15:13
- Zuletzt bearbeitet 01.09.2026 20:57:40
In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or more zones and at least one zone ...
CVE-2020-8618
- EPSS 1.85%
- Veröffentlicht 17.06.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:39:08
An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a specially constructed zone, denying service to clients.
CVE-2020-8616
- EPSS 10.59%
- Veröffentlicht 19.05.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 05:39:07
A malicious actor who intentionally exploits this lack of effective limitation on the number of fetches performed when processing referrals can, through the use of specially crafted referrals, cause a recursing server to issue a very large number of ...
CVE-2020-8617
- EPSS 93.42%
- Veröffentlicht 19.05.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 05:39:07
Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfully guesses) the name of a TSIG key used by the server. Since BIND, by default, configures a local se...
CVE-2019-6477
- EPSS 4.06%
- Veröffentlicht 26.11.2019 16:15:13
- Zuletzt bearbeitet 21.11.2024 04:46:31
With pipelining enabled each incoming query on a TCP connection requires a similar resource allocation to a query received via UDP or via TCP without pipelining enabled. A client using a TCP-pipelined connection to a server could consume more resourc...
CVE-2013-5661
- EPSS 3.45%
- Veröffentlicht 05.11.2019 19:15:10
- Zuletzt bearbeitet 21.11.2024 01:57:54
Cache Poisoning issue exists in DNS Response Rate Limiting.
CVE-2018-5742
- EPSS 1.58%
- Veröffentlicht 30.10.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:09:17
While backporting a feature for a newer branch of BIND9, RedHat introduced a path leading to an assertion failure in buffer.c:420. Affects RedHat versions bind-9.9.4-65.el7 -> bind-9.9.4-72.el7. No ISC releases are affected. Other packages from other...
CVE-2019-6475
- EPSS 1.27%
- Veröffentlicht 17.10.2019 20:15:12
- Zuletzt bearbeitet 21.11.2024 04:46:31
Mirror zones are a BIND feature allowing recursive servers to pre-cache zone data provided by other servers. A mirror zone is similar to a zone of type secondary, except that its data is subject to DNSSEC validation before being used in answers, as i...
CVE-2019-6476
- EPSS 2.91%
- Veröffentlicht 17.10.2019 20:15:12
- Zuletzt bearbeitet 21.11.2024 04:46:31
A defect in code added to support QNAME minimization can cause named to exit with an assertion failure if a forwarder returns a referral rather than resolving the query. This affects BIND versions 9.14.0 up to 9.14.6, and 9.15.0 up to 9.15.4.