Show filters
352 Total Results
Displaying 311-320 of 352
Sort by:
Attacker Value
Unknown

CVE-2007-2926

Disclosure Date: July 24, 2007 (last updated October 04, 2023)
ISC BIND 9 through 9.5.0a5 uses a weak random number generator during generation of DNS query ids when answering resolver questions or sending NOTIFY messages to slave name servers, which makes it easier for remote attackers to guess the next query id and perform DNS cache poisoning.
0
Attacker Value
Unknown

CVE-2007-2241

Disclosure Date: May 02, 2007 (last updated October 04, 2023)
Unspecified vulnerability in query.c in ISC BIND 9.4.0, and 9.5.0a1 through 9.5.0a3, when recursion is enabled, allows remote attackers to cause a denial of service (daemon exit) via a sequence of queries processed by the query_addsoa function.
0
Attacker Value
Unknown

CVE-2007-0494

Disclosure Date: January 25, 2007 (last updated October 04, 2023)
ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (exit) via a type * (ANY) DNS query response that contains multiple RRsets, which triggers an assertion error, aka the "DNSSEC Validation" vulnerability.
0
Attacker Value
Unknown

CVE-2007-0493

Disclosure Date: January 25, 2007 (last updated October 04, 2023)
Use-after-free vulnerability in ISC BIND 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (named daemon crash) via unspecified vectors that cause named to "dereference a freed fetch context."
0
Attacker Value
Unknown

CVE-2006-4095

Disclosure Date: September 06, 2006 (last updated February 16, 2024)
BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via certain SIG queries, which cause an assertion failure when multiple RRsets are returned.
Attacker Value
Unknown

CVE-2006-4096

Disclosure Date: September 06, 2006 (last updated October 04, 2023)
BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via a flood of recursive queries, which cause an INSIST failure when the response is received after the recursion queue is empty.
0
Attacker Value
Unknown

CVE-2006-2073

Disclosure Date: April 27, 2006 (last updated October 04, 2023)
Unspecified vulnerability in ISC BIND allows remote attackers to cause a denial of service via a crafted DNS message with a "broken" TSIG, as demonstrated by the OUSPG PROTOS DNS test suite.
0
Attacker Value
Unknown

CVE-2006-0987

Disclosure Date: March 03, 2006 (last updated February 22, 2025)
The default configuration of ISC BIND before 9.4.1-P1, when configured as a caching name server, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed source IP addresses.
0
Attacker Value
Unknown

CVE-2006-0527

Disclosure Date: February 02, 2006 (last updated February 22, 2025)
BIND 4 (BIND4) and BIND 8 (BIND8), if used as a target forwarder, allows remote attackers to gain privileged access via a "Kashpureff-style DNS cache corruption" attack.
0
Attacker Value
Unknown

CVE-2005-0033

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Buffer overflow in the code for recursion and glue fetching in BIND 8.4.4 and 8.4.5 allows remote attackers to cause a denial of service (crash) via queries that trigger the overflow in the q_usedns array that tracks nameservers and addresses.
0