ISC records
242 published records for vendor isc.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 6 · 2.5%
- Pre-auth RCE
- 20
- With a fix record
- 74%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation36
- CWE-617 Reachable Assertion34
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer8
- CWE-770 Allocation of Resources Without Limits or Throttling8
- CWE-399 Resource Management Errors7
- CWE-264 Permissions, Privileges, and Access Controls6
The weakness classes this vendor ships most often: where to look.
CWEAll records
242 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
64This week | CVE-2021-25216No exploit | A second vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attackdebian · debian linux · CWE-125 | Critical9.8 | — | 82.4% | Apr 28, 2021 |
60This week | CVE-2023-50387Proof of concept | Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of serredhat · enterprise linux · CWE-770 | High7.5 | — | 100.0% | Feb 14, 2024 |
58Plan | CVE-2015-5477Weaponized | named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion faisc · bind · CWE-19 | High7.8 | — | 91.3% | Jul 29, 2015 |
57Plan | CVE-2016-2776Weaponized | buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses,isc · bind · CWE-20 | High7.5 | — | 89.5% | Sep 28, 2016 |
56Plan | CVE-2008-1447Weaponized | The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 microsoft · windows 2000 · CWE-331 | Medium6.8 | — | 95.2% | Jul 8, 2008 |
55Plan | CVE-2011-0997No exploit | dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 allows remote attackers tisc · dhcp · CWE-20 | High7.5 | — | 84.3% | Apr 8, 2011 |
54Plan | CVE-2004-0460No exploit | Buffer overflow in the logging capability for the DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote attackers to cause isc · dhcpd | Critical10.0 | — | 45.3% | Aug 6, 2004 |
53Plan | CVE-2016-1286No exploit | named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure anisc · bind | High8.6 | — | 62.1% | Mar 9, 2016 |
52Plan | CVE-2023-50868Proof of concept | The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a dennetapp · hci baseboard management controller · CWE-400 | High7.5 | — | 73.7% | Feb 14, 2024 |
52Plan | CVE-2017-3144No exploit | Failure to properly clean up closed OMAPI connections can exhaust available socketsisc · dhcp · CWE-400 | High7.5 | — | 72.7% | Jan 16, 2019 |
52Plan | CVE-1999-0043No exploit | Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.isc · inn · CWE-78 | Critical9.8 | — | 44.6% | Dec 4, 1996 |
51Plan | CVE-2020-8617Weaponized | A logic error in code which checks TSIG validity can be used to trigger an assertion failure in tsig.cisc · bind · CWE-617 | Medium5.9 | — | 93.4% | May 19, 2020 |
51Plan | CVE-2015-8605No exploit | ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crashisc · dhcp · CWE-20 | Medium6.5 | — | 82.7% | Jan 14, 2016 |
51Plan | CVE-2020-8625No exploit | A vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attackisc · bind · CWE-120 | High8.1 | — | 64.2% | Feb 17, 2021 |
49Plan | CVE-2001-0010Proof of concept | Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges.isc · bind | Critical10.0 | — | 31.6% | Feb 12, 2001 |
49Plan | CVE-2002-0702Proof of concept | Format string vulnerabilities in the logging routines for dynamic DNS code (print.c) of ISC DHCP daemon (DHCPD) 3 to 3.0.1rc8, with the NSUPisc · dhcpd | Critical10.0 | — | 31.1% | Jul 26, 2002 |
49Plan | CVE-1999-0009Proof of concept | Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.data general · dg ux | Critical10.0 | — | 29.0% | Apr 8, 1998 |
48Plan | CVE-2018-5740Proof of concept | A flaw in the "deny-answer-aliases" feature can cause an assertion failure in namedisc · bind · CWE-617 | High7.5 | — | 59.6% | Jan 16, 2019 |
48Plan | CVE-2014-8500No exploit | ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 does not limit delegation chaining, which allows remote attackeisc · bind · CWE-399 | High7.8 | — | 57.8% | Dec 10, 2014 |
48Plan | CVE-2009-0692Proof of concept | Stack-based buffer overflow in the script_write_params method in client/dhclient.c in ISC DHCP dhclient 4.1 before 4.1.0p1, 4.0 before 4.0.1isc · dhcp · CWE-119 | Critical10.0 | — | 25.8% | Jul 14, 2009 |
45Plan | CVE-2016-2774No exploit | ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number of concurrent TCP sessions, which allows remisc · dhcp · CWE-20 | Medium5.9 | — | 73.6% | Mar 9, 2016 |
45Plan | CVE-2016-1285No exploit | named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, isc · bind | Medium6.8 | — | 59.1% | Mar 9, 2016 |
45Plan | CVE-2022-3736No exploit | named configured to answer from stale cache may terminate unexpectedly while processing RRSIG queriesisc · bind · CWE-20 | High7.5 | — | 48.7% | Jan 26, 2023 |
45Plan | CVE-2004-0461No exploit | The DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, usesisc · dhcpd | Critical10.0 | — | 16.8% | Aug 6, 2004 |
44Plan | CVE-2013-2266No exploit | libdns in ISC BIND 9.7.x and 9.8.x before 9.8.4-P2, 9.8.5 before 9.8.5b2, 9.9.x before 9.9.2-P2, and 9.9.3 before 9.9.3b2 on UNIX platforms isc · bind · CWE-119 | High7.8 | — | 42.9% | Mar 28, 2013 |
- CVE-2021-2521664This week
A second vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attack
CriticalCVSS 9.8No exploitEPSS 82%debian · debian linuxApr 28, 2021
- CVE-2023-5038760This week
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of ser
HighCVSS 7.5Proof of conceptEPSS 100%redhat · enterprise linuxFeb 14, 2024
- CVE-2015-547758Plan
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion fa
HighCVSS 7.8WeaponizedEPSS 91%isc · bindJul 29, 2015
- CVE-2016-277657Plan
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses,
HighCVSS 7.5WeaponizedEPSS 89%isc · bindSep 28, 2016
- CVE-2008-144756Plan
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2
MediumCVSS 6.8WeaponizedEPSS 95%microsoft · windows 2000Jul 8, 2008
- CVE-2011-099755Plan
dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 allows remote attackers t
HighCVSS 7.5No exploitEPSS 84%isc · dhcpApr 8, 2011
- CVE-2004-046054Plan
Buffer overflow in the logging capability for the DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote attackers to cause
CriticalCVSS 10.0No exploitEPSS 45%isc · dhcpdAug 6, 2004
- CVE-2016-128653Plan
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure an
HighCVSS 8.6No exploitEPSS 62%isc · bindMar 9, 2016
- CVE-2023-5086852Plan
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a den
HighCVSS 7.5Proof of conceptEPSS 74%netapp · hci baseboard management controllerFeb 14, 2024
- CVE-2017-314452Plan
Failure to properly clean up closed OMAPI connections can exhaust available sockets
HighCVSS 7.5No exploitEPSS 73%isc · dhcpJan 16, 2019
- CVE-1999-004352Plan
Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.
CriticalCVSS 9.8No exploitEPSS 45%isc · innDec 4, 1996
- CVE-2020-861751Plan
A logic error in code which checks TSIG validity can be used to trigger an assertion failure in tsig.c
MediumCVSS 5.9WeaponizedEPSS 93%isc · bindMay 19, 2020
- CVE-2015-860551Plan
ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash
MediumCVSS 6.5No exploitEPSS 83%isc · dhcpJan 14, 2016
- CVE-2020-862551Plan
A vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attack
HighCVSS 8.1No exploitEPSS 64%isc · bindFeb 17, 2021
- CVE-2001-001049Plan
Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges.
CriticalCVSS 10.0Proof of conceptEPSS 32%isc · bindFeb 12, 2001
- CVE-2002-070249Plan
Format string vulnerabilities in the logging routines for dynamic DNS code (print.c) of ISC DHCP daemon (DHCPD) 3 to 3.0.1rc8, with the NSUP
CriticalCVSS 10.0Proof of conceptEPSS 31%isc · dhcpdJul 26, 2002
- CVE-1999-000949Plan
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
CriticalCVSS 10.0Proof of conceptEPSS 29%data general · dg uxApr 8, 1998
- CVE-2018-574048Plan
A flaw in the "deny-answer-aliases" feature can cause an assertion failure in named
HighCVSS 7.5Proof of conceptEPSS 60%isc · bindJan 16, 2019
- CVE-2014-850048Plan
ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 does not limit delegation chaining, which allows remote attacke
HighCVSS 7.8No exploitEPSS 58%isc · bindDec 10, 2014
- CVE-2009-069248Plan
Stack-based buffer overflow in the script_write_params method in client/dhclient.c in ISC DHCP dhclient 4.1 before 4.1.0p1, 4.0 before 4.0.1
CriticalCVSS 10.0Proof of conceptEPSS 26%isc · dhcpJul 14, 2009
- CVE-2016-277445Plan
ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number of concurrent TCP sessions, which allows rem
MediumCVSS 5.9No exploitEPSS 74%isc · dhcpMar 9, 2016
- CVE-2016-128545Plan
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages,
MediumCVSS 6.8No exploitEPSS 59%isc · bindMar 9, 2016
- CVE-2022-373645Plan
named configured to answer from stale cache may terminate unexpectedly while processing RRSIG queries
HighCVSS 7.5No exploitEPSS 49%isc · bindJan 26, 2023
- CVE-2004-046145Plan
The DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, uses
CriticalCVSS 10.0No exploitEPSS 17%isc · dhcpdAug 6, 2004
- CVE-2013-226644Plan
libdns in ISC BIND 9.7.x and 9.8.x before 9.8.4-P2, 9.8.5 before 9.8.5b2, 9.9.x before 9.9.2-P2, and 9.9.3 before 9.9.3b2 on UNIX platforms
HighCVSS 7.8No exploitEPSS 43%isc · bindMar 28, 2013