CVEs (184)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Freebsd IscOpenbsd3Bind FreebsdOpenbsdApr 16, 2026 Nov 29, 2002 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer overflow in named in BIND 4 versions 4.9.10 and earlier, and 8 versions 8.3.3 and earlier, allows remote attackers to execute arbitrary code via a certain DNS server response containing SIG resource records (RR). |
Buffer overflows in the DNS stub resolver library in ISC BIND 4.9.2 through 4.9.10, and other derived libraries such as BSD libc and GNU glibc, allow remote attackers to execute arbitrary code via DNS server responses th...Show more |
Buffer overflow in DNS resolver functions that perform lookup of network names and addresses, as used in BIND 4.9.8 and ported to glibc 2.2.5 and earlier, allows remote malicious DNS servers to execute arbitrary code thr...Show more |
Buffer overflow in the DNS resolver code used in libc, glibc, and libbind, as derived from ISC BIND, allows remote malicious DNS servers to cause a denial of service and possibly execute arbitrary code via the stub resol...Show more |
ISC BIND 9 before 9.2.1 allows remote attackers to cause a denial of service (shutdown) via a malformed DNS packet that triggers an error condition that is not properly handled when the rdataset parameter to the dns_mess...Show more |
dnskeygen in BIND 8.2.4 and earlier, and dnssec-keygen in BIND 9.1.2 and earlier, set insecure permissions for a HMAC-MD5 shared secret key file used for DNS Transactional Signatures (TSIG), which allows attackers to obt...Show more |
Format string vulnerability in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges. |
BIND 4 and BIND 8 allow remote attackers to access sensitive information such as environment variables. |
Buffer overflow in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges. |
Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges. |
named in BIND 8.2 through 8.2.2-P6 allows remote attackers to cause a denial of service by sending an SRV record to the server, aka the "srv bug." |
named in BIND 8.2 through 8.2.2-P6 allows remote attackers to cause a denial of service by making a compressed zone transfer (ZXFR) request and performing a name service query on an authoritative record that is not cache...Show more |
Buffer overflow in host command allows a remote attacker to execute arbitrary commands via a long response to an AXFR query. |
The resolver in glibc 2.1.3 uses predictable IDs, which allows a local attacker to spoof DNS query results. |
Denial of service in BIND named via maxdname. |
Denial of service in BIND named via consuming more than "fdmax" file descriptors. |
Denial of service in BIND by improperly closing TCP sessions via so_linger. |
Buffer overflow in BIND 8.2 via NXT records. |
named in ISC BIND 4.9 and 8.1 allows local users to destroy files via a symlink attack on (1) named_dump.db when root kills the process with a SIGINT, or (2) named.stats when SIGIOT is used. |
8Data General IbmIsc+5 more11Aix Asl Ux 4800Bind+8 moreApr 16, 2026 Apr 8, 1998 N/A· v4 5.4 MEDIUM· v3 10.0 HIGH· v2 Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer. |