Vulnerabilities > ISC > Bind

DATE CVE VULNERABILITY TITLE RISK
2012-07-25 CVE-2012-3817 Improper Input Validation vulnerability in ISC Bind
ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; 9.9.x before 9.9.1-P2; and 9.6-ESV before 9.6-ESV-R7-P2, when DNSSEC validation is enabled, does not properly initialize the failing-query cache, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) by sending many queries.
network
low complexity
isc CWE-20
7.8
2012-06-05 CVE-2012-1667 Numeric Errors vulnerability in ISC Bind
ISC BIND 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9.1-P1, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P1 does not properly handle resource records with a zero-length RDATA section, which allows remote DNS servers to cause a denial of service (daemon crash or data corruption) or obtain sensitive information from process memory via a crafted record.
network
low complexity
isc CWE-189
8.5
2012-02-08 CVE-2012-1033 Security Bypass vulnerability in ISC BIND
The resolver in ISC BIND 9 through 9.8.1-P1 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack.
network
low complexity
isc
5.0
2011-11-29 CVE-2011-4313 Remote Denial of Service vulnerability in ISC BIND 9 Recursive Queries
query.c in ISC BIND 9.0.x through 9.6.x, 9.4-ESV through 9.4-ESV-R5, 9.6-ESV through 9.6-ESV-R5, 9.7.0 through 9.7.4, 9.8.0 through 9.8.1, and 9.9.0a1 through 9.9.0b1 allows remote attackers to cause a denial of service (assertion failure and named exit) via unknown vectors related to recursive DNS queries, error logging, and the caching of an invalid record by the resolver.
network
low complexity
isc
5.0
2011-07-08 CVE-2011-2465 Remote Denial of Service vulnerability in ISC BIND 9 RPZ Configurations
Unspecified vulnerability in ISC BIND 9 9.8.0, 9.8.0-P1, 9.8.0-P2, and 9.8.1b1, when recursion is enabled and the Response Policy Zone (RPZ) contains DNAME or certain CNAME records, allows remote attackers to cause a denial of service (named daemon crash) via an unspecified query.
network
high complexity
isc
2.6
2011-07-08 CVE-2011-2464 Packet Processing Remote Denial of Service vulnerability in ISC BIND 9
Unspecified vulnerability in ISC BIND 9 9.6.x before 9.6-ESV-R4-P3, 9.7.x before 9.7.3-P3, and 9.8.x before 9.8.0-P4 allows remote attackers to cause a denial of service (named daemon crash) via a crafted UPDATE request.
network
low complexity
isc
5.0
2011-05-31 CVE-2011-1910 Numeric Errors vulnerability in ISC Bind
Off-by-one error in named in ISC BIND 9.x before 9.7.3-P1, 9.8.x before 9.8.0-P2, 9.4-ESV before 9.4-ESV-R4-P1, and 9.6-ESV before 9.6-ESV-R4-P1 allows remote DNS servers to cause a denial of service (assertion failure and daemon exit) via a negative response containing large RRSIG RRsets.
network
low complexity
isc CWE-189
5.0
2011-05-09 CVE-2011-1907 Resource Management Errors vulnerability in ISC Bind 9.8.0
ISC BIND 9.8.x before 9.8.0-P1, when Response Policy Zones (RPZ) RRset replacement is enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an RRSIG query.
network
low complexity
isc CWE-399
5.0
2011-02-23 CVE-2011-0414 Resource Management Errors vulnerability in ISC Bind 9.7.1/9.7.2
ISC BIND 9.7.1 through 9.7.2-P3, when configured as an authoritative server, allows remote attackers to cause a denial of service (deadlock and daemon hang) by sending a query at the time of (1) an IXFR transfer or (2) a DDNS update.
network
isc CWE-399
7.1
2010-12-06 CVE-2010-3615 Permissions, Privileges, and Access Controls vulnerability in ISC Bind 9.7.2
named in ISC BIND 9.7.2-P2 does not check all intended locations for allow-query ACLs, which might allow remote attackers to make successful requests for private DNS records via the standard DNS query mechanism.
network
low complexity
isc CWE-264
5.0