📦 Bind

by Isc

🔍 What is Bind?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-50387

HIGH CVSS 7.5 Feb 14, 2024

CVE-2023-50387 (KeyTrap) is a DNSSEC protocol vulnerability that allows remote attackers to cause denial of service by exhausting CPU resources through specially crafted DNSSEC responses. The vulnerab...

CVE-2023-6516

HIGH CVSS 7.5 Feb 13, 2024

This vulnerability in BIND 9 DNS resolver allows attackers to cause uncontrolled memory growth by triggering specific query patterns that overwhelm cache cleanup mechanisms. Affected systems running B...

CVE-2023-4408

HIGH CVSS 7.5 Feb 13, 2024

CVE-2023-4408 is a denial-of-service vulnerability in BIND's DNS message parsing code where crafted queries cause excessive CPU consumption due to algorithmic complexity issues. This affects both auth...

CVE-2023-5679

HIGH CVSS 7.5 Feb 13, 2024

A vulnerability in BIND DNS servers where enabling both DNS64 and serve-stale features can cause named to crash during recursive resolution. This affects BIND 9 installations with these specific featu...

CVE-2023-4236

HIGH CVSS 7.5 Sep 20, 2023

A denial-of-service vulnerability in BIND 9's DNS-over-TLS implementation causes the named service to crash when handling high volumes of DNS-over-TLS queries due to assertion failures from incorrect ...

CVE-2023-2829

HIGH CVSS 7.5 Jun 21, 2023

A vulnerability in BIND 9 DNS servers configured with DNSSEC validation and aggressive cache usage allows remote attackers to cause denial of service by sending specially crafted NSEC records. This af...

CVE-2022-1183

HIGH CVSS 7.5 May 19, 2022

This vulnerability causes the BIND DNS server to crash with an assertion failure when configured with HTTP references in listen-on statements. It affects BIND servers using DNS over HTTPS (DoH) config...

CVE-2022-0635

HIGH CVSS 7.5 Mar 23, 2022

CVE-2022-0635 is a denial-of-service vulnerability in BIND 9.18.0 where specific DNS queries can trigger an assertion failure, causing the named process to terminate. This affects organizations runnin...

CVE-2022-0667

HIGH CVSS 7.5 Mar 22, 2022

CVE-2022-0667 is a denial-of-service vulnerability in BIND 9.18.0 where specially crafted queries cause the BIND process to exit, disrupting DNS services. This affects organizations running BIND 9.18....

CVE-2021-25215

HIGH CVSS 7.5 Apr 29, 2021

This vulnerability in BIND DNS servers allows remote attackers to cause denial of service by sending specially crafted DNS queries that trigger an assertion failure, causing the named process to termi...