ISC kayıtları
isc üreticisine ait 242 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 6 · %2,5
- Pre-auth RCE
- 20
- Düzeltme kaydı olan
- %74
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation36
- CWE-617 Reachable Assertion34
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer8
- CWE-770 Allocation of Resources Without Limits or Throttling8
- CWE-399 Resource Management Errors7
- CWE-264 Permissions, Privileges, and Access Controls6
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
242 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
64Bu hafta | CVE-2021-25216İstismar yok | A second vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attackdebian · debian linux · CWE-125 | Kritik9,8 | — | %82,4 | 28 Nis 2021 |
60Bu hafta | CVE-2023-50387Kavram kanıtı | Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of serredhat · enterprise linux · CWE-770 | Yüksek7,5 | — | %100,0 | 14 Şub 2024 |
58Planlayın | CVE-2015-5477Silahlaştırılmış | named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion faisc · bind · CWE-19 | Yüksek7,8 | — | %91,3 | 29 Tem 2015 |
57Planlayın | CVE-2016-2776Silahlaştırılmış | buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses,isc · bind · CWE-20 | Yüksek7,5 | — | %89,5 | 28 Eyl 2016 |
56Planlayın | CVE-2008-1447Silahlaştırılmış | The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 microsoft · windows 2000 · CWE-331 | Orta6,8 | — | %95,2 | 8 Tem 2008 |
55Planlayın | CVE-2011-0997İstismar yok | dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 allows remote attackers tisc · dhcp · CWE-20 | Yüksek7,5 | — | %84,3 | 8 Nis 2011 |
54Planlayın | CVE-2004-0460İstismar yok | Buffer overflow in the logging capability for the DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote attackers to cause isc · dhcpd | Kritik10,0 | — | %45,3 | 6 Ağu 2004 |
53Planlayın | CVE-2016-1286İstismar yok | named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure anisc · bind | Yüksek8,6 | — | %62,1 | 9 Mar 2016 |
52Planlayın | CVE-2023-50868Kavram kanıtı | The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a dennetapp · hci baseboard management controller · CWE-400 | Yüksek7,5 | — | %73,7 | 14 Şub 2024 |
52Planlayın | CVE-2017-3144İstismar yok | Failure to properly clean up closed OMAPI connections can exhaust available socketsisc · dhcp · CWE-400 | Yüksek7,5 | — | %72,7 | 16 Oca 2019 |
52Planlayın | CVE-1999-0043İstismar yok | Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.isc · inn · CWE-78 | Kritik9,8 | — | %44,6 | 4 Ara 1996 |
51Planlayın | CVE-2020-8617Silahlaştırılmış | A logic error in code which checks TSIG validity can be used to trigger an assertion failure in tsig.cisc · bind · CWE-617 | Orta5,9 | — | %93,4 | 19 May 2020 |
51Planlayın | CVE-2015-8605İstismar yok | ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crashisc · dhcp · CWE-20 | Orta6,5 | — | %82,7 | 14 Oca 2016 |
51Planlayın | CVE-2020-8625İstismar yok | A vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attackisc · bind · CWE-120 | Yüksek8,1 | — | %64,2 | 17 Şub 2021 |
49Planlayın | CVE-2001-0010Kavram kanıtı | Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges.isc · bind | Kritik10,0 | — | %31,6 | 12 Şub 2001 |
49Planlayın | CVE-2002-0702Kavram kanıtı | Format string vulnerabilities in the logging routines for dynamic DNS code (print.c) of ISC DHCP daemon (DHCPD) 3 to 3.0.1rc8, with the NSUPisc · dhcpd | Kritik10,0 | — | %31,1 | 26 Tem 2002 |
49Planlayın | CVE-1999-0009Kavram kanıtı | Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.data general · dg ux | Kritik10,0 | — | %29,0 | 8 Nis 1998 |
48Planlayın | CVE-2018-5740Kavram kanıtı | A flaw in the "deny-answer-aliases" feature can cause an assertion failure in namedisc · bind · CWE-617 | Yüksek7,5 | — | %59,6 | 16 Oca 2019 |
48Planlayın | CVE-2014-8500İstismar yok | ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 does not limit delegation chaining, which allows remote attackeisc · bind · CWE-399 | Yüksek7,8 | — | %57,8 | 10 Ara 2014 |
48Planlayın | CVE-2009-0692Kavram kanıtı | Stack-based buffer overflow in the script_write_params method in client/dhclient.c in ISC DHCP dhclient 4.1 before 4.1.0p1, 4.0 before 4.0.1isc · dhcp · CWE-119 | Kritik10,0 | — | %25,8 | 14 Tem 2009 |
45Planlayın | CVE-2016-2774İstismar yok | ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number of concurrent TCP sessions, which allows remisc · dhcp · CWE-20 | Orta5,9 | — | %73,6 | 9 Mar 2016 |
45Planlayın | CVE-2016-1285İstismar yok | named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, isc · bind | Orta6,8 | — | %59,1 | 9 Mar 2016 |
45Planlayın | CVE-2022-3736İstismar yok | named configured to answer from stale cache may terminate unexpectedly while processing RRSIG queriesisc · bind · CWE-20 | Yüksek7,5 | — | %48,7 | 26 Oca 2023 |
45Planlayın | CVE-2004-0461İstismar yok | The DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, usesisc · dhcpd | Kritik10,0 | — | %16,8 | 6 Ağu 2004 |
44Planlayın | CVE-2013-2266İstismar yok | libdns in ISC BIND 9.7.x and 9.8.x before 9.8.4-P2, 9.8.5 before 9.8.5b2, 9.9.x before 9.9.2-P2, and 9.9.3 before 9.9.3b2 on UNIX platforms isc · bind · CWE-119 | Yüksek7,8 | — | %42,9 | 28 Mar 2013 |
- CVE-2021-2521664Bu hafta
A second vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attack
KritikCVSS 9,8İstismar yokEPSS %82debian · debian linux28 Nis 2021
- CVE-2023-5038760Bu hafta
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of ser
YüksekCVSS 7,5Kavram kanıtıEPSS %100redhat · enterprise linux14 Şub 2024
- CVE-2015-547758Planlayın
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion fa
YüksekCVSS 7,8SilahlaştırılmışEPSS %91isc · bind29 Tem 2015
- CVE-2016-277657Planlayın
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses,
YüksekCVSS 7,5SilahlaştırılmışEPSS %89isc · bind28 Eyl 2016
- CVE-2008-144756Planlayın
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2
OrtaCVSS 6,8SilahlaştırılmışEPSS %95microsoft · windows 20008 Tem 2008
- CVE-2011-099755Planlayın
dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 allows remote attackers t
YüksekCVSS 7,5İstismar yokEPSS %84isc · dhcp8 Nis 2011
- CVE-2004-046054Planlayın
Buffer overflow in the logging capability for the DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote attackers to cause
KritikCVSS 10,0İstismar yokEPSS %45isc · dhcpd6 Ağu 2004
- CVE-2016-128653Planlayın
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure an
YüksekCVSS 8,6İstismar yokEPSS %62isc · bind9 Mar 2016
- CVE-2023-5086852Planlayın
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a den
YüksekCVSS 7,5Kavram kanıtıEPSS %74netapp · hci baseboard management controller14 Şub 2024
- CVE-2017-314452Planlayın
Failure to properly clean up closed OMAPI connections can exhaust available sockets
YüksekCVSS 7,5İstismar yokEPSS %73isc · dhcp16 Oca 2019
- CVE-1999-004352Planlayın
Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.
KritikCVSS 9,8İstismar yokEPSS %45isc · inn4 Ara 1996
- CVE-2020-861751Planlayın
A logic error in code which checks TSIG validity can be used to trigger an assertion failure in tsig.c
OrtaCVSS 5,9SilahlaştırılmışEPSS %93isc · bind19 May 2020
- CVE-2015-860551Planlayın
ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash
OrtaCVSS 6,5İstismar yokEPSS %83isc · dhcp14 Oca 2016
- CVE-2020-862551Planlayın
A vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attack
YüksekCVSS 8,1İstismar yokEPSS %64isc · bind17 Şub 2021
- CVE-2001-001049Planlayın
Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges.
KritikCVSS 10,0Kavram kanıtıEPSS %32isc · bind12 Şub 2001
- CVE-2002-070249Planlayın
Format string vulnerabilities in the logging routines for dynamic DNS code (print.c) of ISC DHCP daemon (DHCPD) 3 to 3.0.1rc8, with the NSUP
KritikCVSS 10,0Kavram kanıtıEPSS %31isc · dhcpd26 Tem 2002
- CVE-1999-000949Planlayın
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
KritikCVSS 10,0Kavram kanıtıEPSS %29data general · dg ux8 Nis 1998
- CVE-2018-574048Planlayın
A flaw in the "deny-answer-aliases" feature can cause an assertion failure in named
YüksekCVSS 7,5Kavram kanıtıEPSS %60isc · bind16 Oca 2019
- CVE-2014-850048Planlayın
ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 does not limit delegation chaining, which allows remote attacke
YüksekCVSS 7,8İstismar yokEPSS %58isc · bind10 Ara 2014
- CVE-2009-069248Planlayın
Stack-based buffer overflow in the script_write_params method in client/dhclient.c in ISC DHCP dhclient 4.1 before 4.1.0p1, 4.0 before 4.0.1
KritikCVSS 10,0Kavram kanıtıEPSS %26isc · dhcp14 Tem 2009
- CVE-2016-277445Planlayın
ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number of concurrent TCP sessions, which allows rem
OrtaCVSS 5,9İstismar yokEPSS %74isc · dhcp9 Mar 2016
- CVE-2016-128545Planlayın
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages,
OrtaCVSS 6,8İstismar yokEPSS %59isc · bind9 Mar 2016
- CVE-2022-373645Planlayın
named configured to answer from stale cache may terminate unexpectedly while processing RRSIG queries
YüksekCVSS 7,5İstismar yokEPSS %49isc · bind26 Oca 2023
- CVE-2004-046145Planlayın
The DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, uses
KritikCVSS 10,0İstismar yokEPSS %17isc · dhcpd6 Ağu 2004
- CVE-2013-226644Planlayın
libdns in ISC BIND 9.7.x and 9.8.x before 9.8.4-P2, 9.8.5 before 9.8.5b2, 9.9.x before 9.9.2-P2, and 9.9.3 before 9.9.3b2 on UNIX platforms
YüksekCVSS 7,8İstismar yokEPSS %43isc · bind28 Mar 2013