Isc
isc
238 CVEs • 8 products
Products (8)
Click to collapseToggle
Products (8)
Click to collapse
CVEs (238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FedoraprojectIsc+1 more9Active Iq Unified Manager BindDebian Linux+6 moreJun 17, 2026 Jun 21, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 If the `recursive-clients` quota is reached on a BIND 9 resolver configured with both `stale-answer-enable yes;` and `stale-answer-client-timeout 0;`, a sequence of serve-stale-related lookups could cause `named` to loop...Show more |
2Isc Netapp7Active Iq Unified Manager BindH300s Firmware+4 moreJun 17, 2026 Jun 21, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A `named` instance configured to run as a DNSSEC-validating recursive resolver with the Aggressive Use of DNSSEC-Validated Cache (RFC 8198) option (`synth-from-dnssec`) enabled can be remotely terminated using a zone wit...Show more |
4Debian FedoraprojectIsc+1 more9Active Iq Unified Manager BindDebian Linux+6 moreJun 17, 2026 Jun 21, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent to authoritative servers. The size limit for that cache database can b...Show more |
This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` that also make use of the option `stale-answer-client-timeout`, configured with a value greater than zero. If the resolver receives many queries tha...Show more |
BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the resolver receives an RRSIG query. This issue affects BIND 9 versions 9....Show more |
Processing of repeated responses to the same query, where both responses contain ECS pseudo-options, but where the first is broken in some way, can cause BIND to exit with an assertion failure. 'Broken' in this context...Show more |
Sending a flood of dynamic DNS updates may cause `named` to allocate large amounts of memory. This, in turn, may cause `named` to exit due to a lack of free memory. We are not aware of any cases where this has been explo...Show more |
3Debian FedoraprojectIsc3Debian Linux DhcpFedoraJun 17, 2026 Oct 7, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 In ISC DHCP 1.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1 a system with access to a DHCP server, sending DHCP packets crafted to include fqdn labels longer than 63 bytes, could eventually cause the server to run ou...Show more |
3Debian FedoraprojectIsc3Debian Linux DhcpFedoraJun 17, 2026 Oct 7, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 In ISC DHCP 4.4.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1, when the function option_code_hash_lookup() is called from add_option(), it increases the option's refcount field. However, there is not a corresponding...Show more |
By sending specific queries to the resolver, an attacker can cause named to crash. |
4Debian FedoraprojectIsc+1 more4Active Iq Unified Manager BindDebian Linux+1 moreJun 17, 2026 Sep 21, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for l...Show more |
4Debian FedoraprojectIsc+1 more4Active Iq Unified Manager BindDebian Linux+1 moreJun 17, 2026 Sep 21, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for l...Show more |
An attacker can leverage this flaw to gradually erode available memory to the point where named crashes for lack of resources. Upon restart the attacker would have to begin again, but nevertheless there is the potential...Show more |
The underlying bug might cause read past end of the buffer and either read memory it should not read, or crash the process. |
3Debian FedoraprojectIsc3Bind Debian LinuxFedoraJun 17, 2026 Sep 21, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service. |
2Isc Netapp6Bind H300s FirmwareH410c Firmware+3 moreJun 17, 2026 May 19, 2022 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure. Vulnerable configurations are those that include a reference to http within the listen-on statements in thei...Show more |
5Fedoraproject IscJuniper+2 more12Bind FedoraH300e Firmware+9 moreJun 17, 2026 Mar 23, 2022 N/A· v4 6.8 MEDIUM· v3 4.0 MEDIUM· v2 BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -> 9.11.36-S1 9.16.8-S1 -> 9.16.26-S1 Versions of BIND 9 earlier than those shown - back to 9.1.0, including Supported...Show more |
2Isc Netapp9Bind H300e FirmwareH300s Firmware+6 moreJun 17, 2026 Mar 23, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Versions affected: BIND 9.18.0 When a vulnerable version of named receives a series of specific queries, the named process will eventually terminate due to a failed assertion check. |
4Fedoraproject IscNetapp+1 more11Bind FedoraH300e Firmware+8 moreJun 17, 2026 Mar 23, 2022 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 BIND 9.16.11 -> 9.16.26, 9.17.0 -> 9.18.0 and versions 9.16.11-S1 -> 9.16.26-S1 of the BIND Supported Preview Edition. Specifically crafted TCP streams can cause connections to BIND to remain in CLOSE_WAIT status for an...Show more |
2Isc Netapp9Bind H300e FirmwareH300s Firmware+6 moreJun 17, 2026 Mar 22, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When the vulnerability is triggered the BIND process will exit. BIND 9.18.0 |