Vulnerabilities > ISC > Bind > 9.4.1
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2009-01-07 | CVE-2009-0025 | Improper Authentication vulnerability in ISC Bind BIND 9.6.0, 9.5.1, 9.5.0, 9.4.3, and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077. | 6.8 |
2008-01-16 | CVE-2008-0122 | Numeric Errors vulnerability in ISC Bind Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted input that triggers memory corruption. | 10.0 |
2007-07-24 | CVE-2007-2925 | Unspecified vulnerability in ISC Bind 9.4.0/9.4.1/9.5.0 The default access control lists (ACL) in ISC BIND 9.4.0, 9.4.1, and 9.5.0a1 through 9.5.0a5 do not set the allow-recursion and allow-query-cache ACLs, which allows remote attackers to make recursive queries and query the cache. network isc | 5.8 |