Vulnerabilities > ISC > High

DATE CVE VULNERABILITY TITLE RISK
2024-07-11 CVE-2024-28872 Improper Certificate Validation vulnerability in ISC Stork
The TLS certificate validation code is flawed.
network
high complexity
isc CWE-295
8.1
2024-02-14 CVE-2023-50387 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue.
7.5
2023-01-26 CVE-2022-3924 Reachable Assertion vulnerability in ISC Bind
This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` that also make use of the option `stale-answer-client-timeout`, configured with a value greater than zero. If the resolver receives many queries that require recursion, there will be a corresponding increase in the number of clients that are waiting for recursion to complete.
network
low complexity
isc CWE-617
7.5
2023-01-26 CVE-2022-3094 Use After Free vulnerability in ISC Bind
Sending a flood of dynamic DNS updates may cause `named` to allocate large amounts of memory.
network
low complexity
isc CWE-416
7.5
2023-01-26 CVE-2022-3488 Reachable Assertion vulnerability in ISC Bind
Processing of repeated responses to the same query, where both responses contain ECS pseudo-options, but where the first is broken in some way, can cause BIND to exit with an assertion failure. 'Broken' in this context is anything that would cause the resolver to reject the query response, such as a mismatch between query and answer name. This issue affects BIND 9 versions 9.11.4-S1 through 9.11.37-S1 and 9.16.8-S1 through 9.16.36-S1.
network
low complexity
isc CWE-617
7.5
2023-01-26 CVE-2022-3736 Unspecified vulnerability in ISC Bind
BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the resolver receives an RRSIG query. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.
network
low complexity
isc
7.5
2022-09-21 CVE-2022-2881 Out-of-bounds Read vulnerability in ISC Bind
The underlying bug might cause read past end of the buffer and either read memory it should not read, or crash the process.
network
low complexity
isc CWE-125
8.2
2022-09-21 CVE-2022-2906 Memory Leak vulnerability in ISC Bind
An attacker can leverage this flaw to gradually erode available memory to the point where named crashes for lack of resources.
network
low complexity
isc CWE-401
7.5
2022-09-21 CVE-2022-38177 Memory Leak vulnerability in multiple products
By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak.
network
low complexity
isc debian fedoraproject netapp CWE-401
7.5
2022-09-21 CVE-2022-38178 Memory Leak vulnerability in multiple products
By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak.
network
low complexity
isc debian fedoraproject netapp CWE-401
7.5