vciy

CVEs we hold for Isc

Records whose assigning authority named Isc as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-9240Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0 - Missing Authorization to Authenticated…iscpcolissimo Colissimo shipping methods for WooCommerce
CVE-2026-81736Remote CPU denial of service through cached SVCB/HTTPS AliasMode treesISC BIND 9
CVE-2026-81563SVCB AliasMode additional-data error leaks qpcache referencesISC BIND 9
CVE-2026-80274Validating resolver can abort while caching a mismatched NOQNAME proofISC BIND 9
CVE-2026-78301Out-of-zone database nodes can become authoritative zone cutsISC BIND 9
CVE-2026-77692Unauthenticated remote crash of named via a single DoH SIG(0) requestISC BIND 9
CVE-2026-77119NSEC3 insecure-referral proof can use unrelated cached NSEC3 RRsetsISC BIND 9
CVE-2026-76163named aborts on a TKEY query when the user configuration has no global options statementISC BIND 9
CVE-2026-75029Message parser retains every identical singleton RDATA, enabling wire-to-work amplificationISC BIND 9
CVE-2026-5950Unbounded resend loop in BIND 9 resolverISC BIND 9
CVE-2026-5947SIG(0) validation during query flood may lead to undefined behaviorISC BIND 9
CVE-2026-5946Invalid handling of CLASS != INISC BIND 9
CVE-2026-3608Stack overflow in Kea daemonsISC Kea
CVE-2026-3593Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementationISC BIND 9
CVE-2026-3592Amplification vulnerabilities via self-pointed glue recordsISC BIND 9
CVE-2026-3591A stack use-after-return flaw in SIG(0) handling code may enable ACL bypassISC BIND 9
CVE-2026-3119Authenticated query containing a TKEY record may cause named to terminate unexpectedlyISC BIND 9
CVE-2026-3104Memory leak in code preparing DNSSEC proofs of non-existenceISC BIND 9
CVE-2026-3039BIND 9 server memory exhaustion during GSS-API TKEY negotiationISC BIND 9
CVE-2026-19941checkwildcard() accepts an out-of-zone NSEC as a wildcard-nonexistence proofISC BIND 9
CVE-2026-19668Resource Exhaustion via Excessive DNSSEC Cryptographic Material MatchingISC BIND 9
CVE-2026-19667Remote assertion failure via 16-bit length truncation in `dns_ncache_add()`ISC BIND 9
CVE-2026-19666Use-after-free in query_addnoqnameproof() via the DNS64 filter64 pathISC BIND 9
CVE-2026-19662qpcache NOQNAME proof use-after-free crashes recursive resolverISC BIND 9
CVE-2026-19033Unauthenticated IXFR deltas are applied to the live zone before TSIG verificationISC BIND 9
CVE-2026-1519Excessive NSEC3 iterations cause high CPU load during insecure delegation validationISC BIND 9
CVE-2026-13321DNSSEC Validation Bypass via Out-of-Zone NSEC Next FieldISC BIND 9
CVE-2026-13204Unexpected exit in certain situations with NSEC and NSEC3 both presentISC BIND 9
CVE-2026-12617Record ordering based unexpected exit with CNAME or DNAMEISC BIND 9
CVE-2026-11721Cache poisoning possible with label count discrepancy, RRSIG, and wildcardsISC BIND 9
CVE-2026-11622Potential memory usage beyond configured limitsISC BIND 9
CVE-2026-11605Unnecessary validation of DNSSEC signed recordsISC BIND 9
CVE-2026-11331Potential wildcard CNAME RPZ policy bypassISC BIND 9
CVE-2026-10822Key Record using PRIVATEDNS algorithm may lead to unexpected exitISC BIND 9
CVE-2026-10723Incorrect acceptance of NSEC3 recordsISC BIND 9
CVE-2025-8696DoS attack against the Stork UI from an unauthenticated userISC Stork
CVE-2025-8677Resource exhaustion via malformed DNSKEY handlingISC BIND 9
CVE-2025-40780Cache poisoning due to weak PRNGISC BIND 9
CVE-2025-40779Kea crash upon interaction between specific client options and subnet selectionISC Kea
CVE-2025-40778Cache poisoning attacks with unsolicited RRsISC BIND 9
CVE-2025-40777A possible assertion failure when 'stale-answer-client-timeout' is set to '0'ISC BIND 9
CVE-2025-40776Birthday Attack against Resolvers supporting ECSISC BIND 9
CVE-2025-40775DNS message with invalid TSIG causes an assertion failureISC BIND 9
CVE-2025-32803Insecure file permissions can result in confidential information leakageISC Kea
CVE-2025-32802Insecure handling of file paths allows multiple local attacksISC Kea
CVE-2025-32801Loading a malicious hook library can lead to local privilege escalationISC Kea
CVE-2025-13878Malformed BRID/HHIT records can cause named to terminate unexpectedlyISC BIND 9
CVE-2025-11232Invalid characters cause assertISC Kea
CVE-2024-4076Assertion failure when serving both stale cache data and authoritative zone contentISC BIND 9
CVE-2024-28872Incorrect TLS certificate validation can lead to escalated privilegesISC Stork
CVE-2024-1975SIG(0) can be used to exhaust CPU resourcesISC BIND 9
CVE-2024-1737BIND's database will be slow if a very large number of RRs exist at the same nameISC BIND 9
CVE-2024-12705DNS-over-HTTPS implementation suffers from multiple issues under heavy query loadISC BIND 9
CVE-2024-11187Many records in the additional section cause CPU exhaustionISC BIND 9
CVE-2024-0760A flood of DNS messages over TCP may make the server unstableISC BIND 9
CVE-2023-6516Specific recursive query patterns may lead to an out-of-memory conditionISC BIND 9
CVE-2023-5680Cleaning an ECS-enabled cache may cause excessive CPU loadISC BIND 9
CVE-2023-5679Enabling both DNS64 and serve-stale may cause an assertion failure during recursive resolutionISC BIND 9
CVE-2023-5517Querying RFC 1918 reverse zones may cause an assertion failure when "nxdomain-redirect" is enabledISC BIND 9
CVE-2023-4408Parsing large DNS messages may cause excessive CPU loadISC BIND 9
CVE-2023-4236named may terminate unexpectedly under high DNS-over-TLS query loadISC BIND 9
CVE-2023-3341A stack exhaustion flaw in control channel code may cause named to terminate unexpectedlyISC BIND 9
CVE-2023-2911Exceeding the recursive-clients quota may cause named to terminate unexpectedly when stale-answer-client-timeout is set…ISC BIND 9
CVE-2023-2829Malformed NSEC records can cause named to terminate unexpectedly when synth-from-dnssec is enabledISC BIND 9
CVE-2023-2828named's configured cache size limit can be significantly exceededISC BIND 9
CVE-2022-3924named configured to answer from stale cache may terminate unexpectedly at recursive-clients soft quotaISC BIND 9
CVE-2022-38178Memory leaks in EdDSA DNSSEC verification codeISC BIND9
CVE-2022-38177Memory leak in ECDSA DNSSEC verification codeISC BIND9
CVE-2022-3736named configured to answer from stale cache may terminate unexpectedly while processing RRSIG queriesISC BIND 9
CVE-2022-3488named may terminate unexpectedly when processing ECS options in repeated responses to iterative queriesISC BIND 9
CVE-2022-3094An UPDATE message flood may cause named to exhaust all available memoryISC BIND 9
CVE-2022-3080BIND 9 resolvers configured to answer from stale cache with zero stale-answer-client-timeout may terminate unexpectedlyISC BIND9
CVE-2022-2929DHCP memory leakISC DHCP
CVE-2022-2928An option refcount overflow exists in dhcpdISC DHCP
CVE-2022-2906Memory leaks in code handling Diffie-Hellman key exchange via TKEY RRs (OpenSSL 3.0.0+ only)ISC BIND9
CVE-2022-2881Buffer overread in statistics channel codeISC BIND9
CVE-2022-2795Processing large delegations may severely degrade resolver performanceISC BIND9
CVE-2022-1183Destroying a TLS session early causes assertion failureISC BIND9
CVE-2022-0667Assertion failure on delayed DS lookupISC BIND
CVE-2022-0635no title heldISC BIND
CVE-2022-0396DoS from specifically crafted TCP packetsISC BIND
CVE-2021-25220DNS forwarders - cache poisoning vulnerabilityISC BIND
CVE-2021-25219Lame cache can be abused to severely degrade resolver performanceISC BIND9
CVE-2021-25218A too-strict assertion check could be triggered when responses in BIND 9.16.19 and 9.17.16 require UDP fragmentation if…ISC BIND9
CVE-2021-25217A buffer overrun in lease file parsing code can be used to exploit a common vulnerability shared by dhcpd and dhclientISC DHCP
CVE-2021-25216A second vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attackISC BIND9
CVE-2021-25215An assertion check can fail while answering queries for DNAME records that require the DNAME to be processed to resolve…ISC BIND9
CVE-2021-25214A broken inbound incremental zone update (IXFR) can cause named to terminate unexpectedlyISC BIND9
CVE-2020-8625A vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attackISC BIND9
CVE-2020-8624update-policy rules of type "subdomain" are enforced incorrectlyISC BIND9
CVE-2020-8623A flaw in native PKCS#11 code can lead to a remotely triggerable assertion failure in pk11.cISC BIND9
CVE-2020-8622A truncated TSIG response can lead to an assertion failureISC BIND9
CVE-2020-8621Attempting QNAME minimization after forwarding can lead to an assertion failure in resolver.cISC BIND9
CVE-2020-8620no title heldISC BIND9
CVE-2020-8619A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transferISC BIND9
CVE-2020-8618A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transferISC BIND9
CVE-2020-8617A logic error in code which checks TSIG validity can be used to trigger an assertion failure in tsig.cISC BIND9
CVE-2020-8616BIND does not sufficiently limit the number of fetches performed when processing referralsISC BIND9
CVE-2019-6477TCP-pipelined queries can bypass tcp-clients limitISC BIND9
CVE-2019-6476An error in QNAME minimization code can cause BIND to exit with an assertion failureISC BIND 9
CVE-2019-6475A flaw in mirror zone validity checking can allow zone data to be spoofedISC BIND 9
CVE-2019-6474A packet containing a malformed DUID can cause the kea-dhcp6 server to terminateISC Kea
CVE-2019-6473A packet containing a malformed DUID can cause the kea-dhcp6 server to terminateISC Kea
CVE-2019-6472A packet containing a malformed DUID can cause the kea-dhcp6 server to terminateISC Kea
CVE-2019-6471A race condition when discarding malformed packets can cause BIND to exit with an assertion failureISC BIND 9
CVE-2019-6469BIND Supported Preview Edition can exit with an assertion failure if ECS is in useISC BIND 9 Supported Preview Edition
CVE-2019-6468BIND Supported Preview Edition can exit with an assertion failure if nxdomain-redirect is usedISC BIND 9 Supported Preview Edition
CVE-2019-6467An error in the nxdomain redirect feature can cause BIND to exit with an INSIST assertion failure in query.cISC BIND 9
CVE-2019-6465Zone transfer controls for writable DLZ zones were not effectiveISC BIND 9
CVE-2019-25481iScripts ReserveLogic Lastest SQL Injection via search endpointiScripts ReserveLogic
CVE-2018-5745An assertion failure can occur if a trust anchor rolls over to an unsupported key algorithm when using managed-keysISC BIND 9
CVE-2018-5744A specially crafted packet can cause named to leak memoryISC BIND 9
CVE-2018-5743Limiting simultaneous TCP clients was ineffectiveISC BIND 9
CVE-2018-5741Update policies krb5-subdomain and ms-subdomain do not enforce controls promised in their documentationISC BIND 9
CVE-2018-5740A flaw in the "deny-answer-aliases" feature can cause an assertion failure in namedISC BIND 9
CVE-2018-5739Failure to release memory may exhaust system resourcesISC Kea DHCP
CVE-2018-5738Some versions of BIND can improperly permit recursive query service to unauthorized clientsISC BIND 9
CVE-2018-5737BIND 9.12's serve-stale implementation can cause an assertion failure in rbtdb.c or other undesirable behavior, even if…ISC BIND 9
CVE-2018-5734A malformed request can trigger an assertion failure in badcache.cISC BIND 9
CVE-2018-5733A malicious client can overflow a reference counter in ISC dhcpdISC DHCP
CVE-2018-5732A specially constructed response from a malicious server can cause a buffer overflow in dhclientISC DHCP
CVE-2017-3145Improper fetch cleanup sequencing in the resolver can cause named to crashISC BIND 9
CVE-2017-3144Failure to properly clean up closed OMAPI connections can exhaust available socketsISC DHCP
CVE-2017-3143An error in TSIG authentication can permit unauthorized dynamic updatesISC BIND 9
CVE-2017-3142An error in TSIG authentication can permit unauthorized zone transfersISC BIND 9
CVE-2017-3141Windows service and uninstall paths are not quoted when BIND is installedISC BIND 9
CVE-2017-3140An error processing RPZ rules can cause named to loop endlessly after handling a queryISC BIND 9
CVE-2017-3138named exits with a REQUIRE assertion failure if it receives a null command string on its control channelISC BIND 9
CVE-2017-3137A response packet can cause a resolver to terminate when processing an answer containing a CNAME or DNAMEISC BIND 9
CVE-2017-3136An error handling synthesized records could cause an assertion failure when using DNS64 with "break-dnssec yes;"ISC BIND 9
CVE-2017-3135Combination of DNS64 and RPZ Can Lead to CrashISC BIND 9
CVE-2016-9778An error handling certain queries using the nxdomain-redirect feature could cause a REQUIRE assertion failure in db.cISC BIND 9
CVE-2012-2248no title heldisc-dhcp

133 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.