Записи ISC
242 опубликованных записей вендора isc.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 6 · 2,5 %
- Pre-auth RCE
- 20
- С записью об исправлении
- 74 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-20 Improper Input Validation36
- CWE-617 Reachable Assertion34
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer8
- CWE-770 Allocation of Resources Without Limits or Throttling8
- CWE-399 Resource Management Errors7
- CWE-264 Permissions, Privileges, and Access Controls6
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
242 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
64На этой неделе | CVE-2021-25216Эксплойта нет | A second vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attackdebian · debian linux · CWE-125 | Критическая9,8 | — | 82,4 % | 28 апр. 2021 г. |
60На этой неделе | CVE-2023-50387Proof of concept | Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of serredhat · enterprise linux · CWE-770 | Высокая7,5 | — | 100,0 % | 14 февр. 2024 г. |
58В плане | CVE-2015-5477Готовый эксплойт | named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion faisc · bind · CWE-19 | Высокая7,8 | — | 91,3 % | 29 июл. 2015 г. |
57В плане | CVE-2016-2776Готовый эксплойт | buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses,isc · bind · CWE-20 | Высокая7,5 | — | 89,5 % | 28 сент. 2016 г. |
56В плане | CVE-2008-1447Готовый эксплойт | The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 microsoft · windows 2000 · CWE-331 | Средняя6,8 | — | 95,2 % | 8 июл. 2008 г. |
55В плане | CVE-2011-0997Эксплойта нет | dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 allows remote attackers tisc · dhcp · CWE-20 | Высокая7,5 | — | 84,3 % | 8 апр. 2011 г. |
54В плане | CVE-2004-0460Эксплойта нет | Buffer overflow in the logging capability for the DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote attackers to cause isc · dhcpd | Критическая10,0 | — | 45,3 % | 6 авг. 2004 г. |
53В плане | CVE-2016-1286Эксплойта нет | named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure anisc · bind | Высокая8,6 | — | 62,1 % | 9 мар. 2016 г. |
52В плане | CVE-2023-50868Proof of concept | The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a dennetapp · hci baseboard management controller · CWE-400 | Высокая7,5 | — | 73,7 % | 14 февр. 2024 г. |
52В плане | CVE-2017-3144Эксплойта нет | Failure to properly clean up closed OMAPI connections can exhaust available socketsisc · dhcp · CWE-400 | Высокая7,5 | — | 72,7 % | 16 янв. 2019 г. |
52В плане | CVE-1999-0043Эксплойта нет | Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.isc · inn · CWE-78 | Критическая9,8 | — | 44,6 % | 4 дек. 1996 г. |
51В плане | CVE-2020-8617Готовый эксплойт | A logic error in code which checks TSIG validity can be used to trigger an assertion failure in tsig.cisc · bind · CWE-617 | Средняя5,9 | — | 93,4 % | 19 мая 2020 г. |
51В плане | CVE-2015-8605Эксплойта нет | ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crashisc · dhcp · CWE-20 | Средняя6,5 | — | 82,7 % | 14 янв. 2016 г. |
51В плане | CVE-2020-8625Эксплойта нет | A vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attackisc · bind · CWE-120 | Высокая8,1 | — | 64,2 % | 17 февр. 2021 г. |
49В плане | CVE-2001-0010Proof of concept | Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges.isc · bind | Критическая10,0 | — | 31,6 % | 12 февр. 2001 г. |
49В плане | CVE-2002-0702Proof of concept | Format string vulnerabilities in the logging routines for dynamic DNS code (print.c) of ISC DHCP daemon (DHCPD) 3 to 3.0.1rc8, with the NSUPisc · dhcpd | Критическая10,0 | — | 31,1 % | 26 июл. 2002 г. |
49В плане | CVE-1999-0009Proof of concept | Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.data general · dg ux | Критическая10,0 | — | 29,0 % | 8 апр. 1998 г. |
48В плане | CVE-2018-5740Proof of concept | A flaw in the "deny-answer-aliases" feature can cause an assertion failure in namedisc · bind · CWE-617 | Высокая7,5 | — | 59,6 % | 16 янв. 2019 г. |
48В плане | CVE-2014-8500Эксплойта нет | ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 does not limit delegation chaining, which allows remote attackeisc · bind · CWE-399 | Высокая7,8 | — | 57,8 % | 10 дек. 2014 г. |
48В плане | CVE-2009-0692Proof of concept | Stack-based buffer overflow in the script_write_params method in client/dhclient.c in ISC DHCP dhclient 4.1 before 4.1.0p1, 4.0 before 4.0.1isc · dhcp · CWE-119 | Критическая10,0 | — | 25,8 % | 14 июл. 2009 г. |
45В плане | CVE-2016-2774Эксплойта нет | ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number of concurrent TCP sessions, which allows remisc · dhcp · CWE-20 | Средняя5,9 | — | 73,6 % | 9 мар. 2016 г. |
45В плане | CVE-2016-1285Эксплойта нет | named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, isc · bind | Средняя6,8 | — | 59,1 % | 9 мар. 2016 г. |
45В плане | CVE-2022-3736Эксплойта нет | named configured to answer from stale cache may terminate unexpectedly while processing RRSIG queriesisc · bind · CWE-20 | Высокая7,5 | — | 48,7 % | 26 янв. 2023 г. |
45В плане | CVE-2004-0461Эксплойта нет | The DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, usesisc · dhcpd | Критическая10,0 | — | 16,8 % | 6 авг. 2004 г. |
44В плане | CVE-2013-2266Эксплойта нет | libdns in ISC BIND 9.7.x and 9.8.x before 9.8.4-P2, 9.8.5 before 9.8.5b2, 9.9.x before 9.9.2-P2, and 9.9.3 before 9.9.3b2 on UNIX platforms isc · bind · CWE-119 | Высокая7,8 | — | 42,9 % | 28 мар. 2013 г. |
- CVE-2021-2521664На этой неделе
A second vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attack
КритическаяCVSS 9,8Эксплойта нетEPSS 82 %debian · debian linux28 апр. 2021 г.
- CVE-2023-5038760На этой неделе
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of ser
ВысокаяCVSS 7,5Proof of conceptEPSS 100 %redhat · enterprise linux14 февр. 2024 г.
- CVE-2015-547758В плане
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion fa
ВысокаяCVSS 7,8Готовый эксплойтEPSS 91 %isc · bind29 июл. 2015 г.
- CVE-2016-277657В плане
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses,
ВысокаяCVSS 7,5Готовый эксплойтEPSS 89 %isc · bind28 сент. 2016 г.
- CVE-2008-144756В плане
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2
СредняяCVSS 6,8Готовый эксплойтEPSS 95 %microsoft · windows 20008 июл. 2008 г.
- CVE-2011-099755В плане
dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 allows remote attackers t
ВысокаяCVSS 7,5Эксплойта нетEPSS 84 %isc · dhcp8 апр. 2011 г.
- CVE-2004-046054В плане
Buffer overflow in the logging capability for the DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote attackers to cause
КритическаяCVSS 10,0Эксплойта нетEPSS 45 %isc · dhcpd6 авг. 2004 г.
- CVE-2016-128653В плане
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure an
ВысокаяCVSS 8,6Эксплойта нетEPSS 62 %isc · bind9 мар. 2016 г.
- CVE-2023-5086852В плане
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a den
ВысокаяCVSS 7,5Proof of conceptEPSS 74 %netapp · hci baseboard management controller14 февр. 2024 г.
- CVE-2017-314452В плане
Failure to properly clean up closed OMAPI connections can exhaust available sockets
ВысокаяCVSS 7,5Эксплойта нетEPSS 73 %isc · dhcp16 янв. 2019 г.
- CVE-1999-004352В плане
Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.
КритическаяCVSS 9,8Эксплойта нетEPSS 45 %isc · inn4 дек. 1996 г.
- CVE-2020-861751В плане
A logic error in code which checks TSIG validity can be used to trigger an assertion failure in tsig.c
СредняяCVSS 5,9Готовый эксплойтEPSS 93 %isc · bind19 мая 2020 г.
- CVE-2015-860551В плане
ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash
СредняяCVSS 6,5Эксплойта нетEPSS 83 %isc · dhcp14 янв. 2016 г.
- CVE-2020-862551В плане
A vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attack
ВысокаяCVSS 8,1Эксплойта нетEPSS 64 %isc · bind17 февр. 2021 г.
- CVE-2001-001049В плане
Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges.
КритическаяCVSS 10,0Proof of conceptEPSS 32 %isc · bind12 февр. 2001 г.
- CVE-2002-070249В плане
Format string vulnerabilities in the logging routines for dynamic DNS code (print.c) of ISC DHCP daemon (DHCPD) 3 to 3.0.1rc8, with the NSUP
КритическаяCVSS 10,0Proof of conceptEPSS 31 %isc · dhcpd26 июл. 2002 г.
- CVE-1999-000949В плане
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
КритическаяCVSS 10,0Proof of conceptEPSS 29 %data general · dg ux8 апр. 1998 г.
- CVE-2018-574048В плане
A flaw in the "deny-answer-aliases" feature can cause an assertion failure in named
ВысокаяCVSS 7,5Proof of conceptEPSS 60 %isc · bind16 янв. 2019 г.
- CVE-2014-850048В плане
ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 does not limit delegation chaining, which allows remote attacke
ВысокаяCVSS 7,8Эксплойта нетEPSS 58 %isc · bind10 дек. 2014 г.
- CVE-2009-069248В плане
Stack-based buffer overflow in the script_write_params method in client/dhclient.c in ISC DHCP dhclient 4.1 before 4.1.0p1, 4.0 before 4.0.1
КритическаяCVSS 10,0Proof of conceptEPSS 26 %isc · dhcp14 июл. 2009 г.
- CVE-2016-277445В плане
ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number of concurrent TCP sessions, which allows rem
СредняяCVSS 5,9Эксплойта нетEPSS 74 %isc · dhcp9 мар. 2016 г.
- CVE-2016-128545В плане
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages,
СредняяCVSS 6,8Эксплойта нетEPSS 59 %isc · bind9 мар. 2016 г.
- CVE-2022-373645В плане
named configured to answer from stale cache may terminate unexpectedly while processing RRSIG queries
ВысокаяCVSS 7,5Эксплойта нетEPSS 49 %isc · bind26 янв. 2023 г.
- CVE-2004-046145В плане
The DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, uses
КритическаяCVSS 10,0Эксплойта нетEPSS 17 %isc · dhcpd6 авг. 2004 г.
- CVE-2013-226644В плане
libdns in ISC BIND 9.7.x and 9.8.x before 9.8.4-P2, 9.8.5 before 9.8.5b2, 9.9.x before 9.9.2-P2, and 9.9.3 before 9.9.3b2 on UNIX platforms
ВысокаяCVSS 7,8Эксплойта нетEPSS 43 %isc · bind28 мар. 2013 г.