Skip to content
Noroxi

ISC records

242 published records for vendor isc.

Researcher profile

Entered KEV
0 · 0%
Weaponized
6 · 2.5%
Pre-auth RCE
20
With a fix record
74%
Median publish → KEV
No record has entered KEV

All records

242 records
  • CVE-2021-25216
    64This week

    A second vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attack

    CriticalCVSS 9.8No exploitEPSS 82%

    debian · debian linuxApr 28, 2021

  • CVE-2023-50387
    60This week

    Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of ser

    HighCVSS 7.5Proof of conceptEPSS 100%

    redhat · enterprise linuxFeb 14, 2024

  • named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion fa

    HighCVSS 7.8WeaponizedEPSS 91%

    isc · bindJul 29, 2015

  • buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses,

    HighCVSS 7.5WeaponizedEPSS 89%

    isc · bindSep 28, 2016

  • The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2

    MediumCVSS 6.8WeaponizedEPSS 95%

    microsoft · windows 2000Jul 8, 2008

  • dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 allows remote attackers t

    HighCVSS 7.5No exploitEPSS 84%

    isc · dhcpApr 8, 2011

  • Buffer overflow in the logging capability for the DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote attackers to cause

    CriticalCVSS 10.0No exploitEPSS 45%

    isc · dhcpdAug 6, 2004

  • named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure an

    HighCVSS 8.6No exploitEPSS 62%

    isc · bindMar 9, 2016

  • The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a den

    HighCVSS 7.5Proof of conceptEPSS 74%

    netapp · hci baseboard management controllerFeb 14, 2024

  • Failure to properly clean up closed OMAPI connections can exhaust available sockets

    HighCVSS 7.5No exploitEPSS 73%

    isc · dhcpJan 16, 2019

  • Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.

    CriticalCVSS 9.8No exploitEPSS 45%

    isc · innDec 4, 1996

  • A logic error in code which checks TSIG validity can be used to trigger an assertion failure in tsig.c

    MediumCVSS 5.9WeaponizedEPSS 93%

    isc · bindMay 19, 2020

  • ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash

    MediumCVSS 6.5No exploitEPSS 83%

    isc · dhcpJan 14, 2016

  • A vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attack

    HighCVSS 8.1No exploitEPSS 64%

    isc · bindFeb 17, 2021

  • Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges.

    CriticalCVSS 10.0Proof of conceptEPSS 32%

    isc · bindFeb 12, 2001

  • Format string vulnerabilities in the logging routines for dynamic DNS code (print.c) of ISC DHCP daemon (DHCPD) 3 to 3.0.1rc8, with the NSUP

    CriticalCVSS 10.0Proof of conceptEPSS 31%

    isc · dhcpdJul 26, 2002

  • Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.

    CriticalCVSS 10.0Proof of conceptEPSS 29%

    data general · dg uxApr 8, 1998

  • A flaw in the "deny-answer-aliases" feature can cause an assertion failure in named

    HighCVSS 7.5Proof of conceptEPSS 60%

    isc · bindJan 16, 2019

  • ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 does not limit delegation chaining, which allows remote attacke

    HighCVSS 7.8No exploitEPSS 58%

    isc · bindDec 10, 2014

  • Stack-based buffer overflow in the script_write_params method in client/dhclient.c in ISC DHCP dhclient 4.1 before 4.1.0p1, 4.0 before 4.0.1

    CriticalCVSS 10.0Proof of conceptEPSS 26%

    isc · dhcpJul 14, 2009

  • ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number of concurrent TCP sessions, which allows rem

    MediumCVSS 5.9No exploitEPSS 74%

    isc · dhcpMar 9, 2016

  • named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages,

    MediumCVSS 6.8No exploitEPSS 59%

    isc · bindMar 9, 2016

  • named configured to answer from stale cache may terminate unexpectedly while processing RRSIG queries

    HighCVSS 7.5No exploitEPSS 49%

    isc · bindJan 26, 2023

  • The DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, uses

    CriticalCVSS 10.0No exploitEPSS 17%

    isc · dhcpdAug 6, 2004

  • libdns in ISC BIND 9.7.x and 9.8.x before 9.8.4-P2, 9.8.5 before 9.8.5b2, 9.9.x before 9.9.2-P2, and 9.9.3 before 9.9.3b2 on UNIX platforms

    HighCVSS 7.8No exploitEPSS 43%

    isc · bindMar 28, 2013