Show filters
352 Total Results
Displaying 311-320 of 352
Sort by:
Attacker Value
Unknown
CVE-2007-2926
Disclosure Date: July 24, 2007 (last updated October 04, 2023)
ISC BIND 9 through 9.5.0a5 uses a weak random number generator during generation of DNS query ids when answering resolver questions or sending NOTIFY messages to slave name servers, which makes it easier for remote attackers to guess the next query id and perform DNS cache poisoning.
0
Attacker Value
Unknown
CVE-2007-2241
Disclosure Date: May 02, 2007 (last updated October 04, 2023)
Unspecified vulnerability in query.c in ISC BIND 9.4.0, and 9.5.0a1 through 9.5.0a3, when recursion is enabled, allows remote attackers to cause a denial of service (daemon exit) via a sequence of queries processed by the query_addsoa function.
0
Attacker Value
Unknown
CVE-2007-0494
Disclosure Date: January 25, 2007 (last updated October 04, 2023)
ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (exit) via a type * (ANY) DNS query response that contains multiple RRsets, which triggers an assertion error, aka the "DNSSEC Validation" vulnerability.
0
Attacker Value
Unknown
CVE-2007-0493
Disclosure Date: January 25, 2007 (last updated October 04, 2023)
Use-after-free vulnerability in ISC BIND 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (named daemon crash) via unspecified vectors that cause named to "dereference a freed fetch context."
0
Attacker Value
Unknown
CVE-2006-4095
Disclosure Date: September 06, 2006 (last updated February 16, 2024)
BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via certain SIG queries, which cause an assertion failure when multiple RRsets are returned.
0
Attacker Value
Unknown
CVE-2006-4096
Disclosure Date: September 06, 2006 (last updated October 04, 2023)
BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via a flood of recursive queries, which cause an INSIST failure when the response is received after the recursion queue is empty.
0
Attacker Value
Unknown
CVE-2006-2073
Disclosure Date: April 27, 2006 (last updated October 04, 2023)
Unspecified vulnerability in ISC BIND allows remote attackers to cause a denial of service via a crafted DNS message with a "broken" TSIG, as demonstrated by the OUSPG PROTOS DNS test suite.
0
Attacker Value
Unknown
CVE-2006-0987
Disclosure Date: March 03, 2006 (last updated February 22, 2025)
The default configuration of ISC BIND before 9.4.1-P1, when configured as a caching name server, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed source IP addresses.
0
Attacker Value
Unknown
CVE-2006-0527
Disclosure Date: February 02, 2006 (last updated February 22, 2025)
BIND 4 (BIND4) and BIND 8 (BIND8), if used as a target forwarder, allows remote attackers to gain privileged access via a "Kashpureff-style DNS cache corruption" attack.
0
Attacker Value
Unknown
CVE-2005-0033
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Buffer overflow in the code for recursion and glue fetching in BIND 8.4.4 and 8.4.5 allows remote attackers to cause a denial of service (crash) via queries that trigger the overflow in the q_usedns array that tracks nameservers and addresses.
0