Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

ISC — Vulnerabilities & Security Advisories 116

Browse all 116 CVE security advisories affecting ISC. AI-powered Chinese analysis, POCs, and references for each vulnerability.

ISC, primarily known for its Internet Systems Consortium software including BIND DNS and DHCP servers, serves as critical infrastructure for global name resolution and network configuration. With 101 recorded CVEs, the project has historically faced diverse security challenges, ranging from remote code execution and buffer overflows to cross-site scripting and privilege escalation vulnerabilities. These flaws often stem from complex parsing logic or improper input validation within the core networking daemons. Notable incidents include critical DNS cache poisoning risks and denial-of-service vectors that have prompted urgent patches across major distributions. The high volume of vulnerabilities reflects the software’s pervasive deployment and the rigorous scrutiny applied to its codebase. While ISC maintains an active security response process, the sheer number of disclosed issues highlights the inherent complexity of maintaining foundational internet protocols. Continuous updates remain essential for administrators relying on these tools to ensure network stability and integrity against evolving threat landscapes.

Found 69 results / 116 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2024-1737 BIND's database will be slow if a very large number of RRs exist at the same name — BIND 9 7.5 High 2024-07-23
CVE-2024-0760 A flood of DNS messages over TCP may make the server unstable — BIND 9 7.5 High 2024-07-23
CVE-2023-6516 Specific recursive query patterns may lead to an out-of-memory condition — BIND 9 7.5 High 2024-02-13
CVE-2023-5680 Cleaning an ECS-enabled cache may cause excessive CPU load — BIND 9 5.3 Medium 2024-02-13
CVE-2023-5679 Enabling both DNS64 and serve-stale may cause an assertion failure during recursive resolution — BIND 9 7.5 High 2024-02-13
CVE-2023-5517 Querying RFC 1918 reverse zones may cause an assertion failure when "nxdomain-redirect" is enabled — BIND 9 7.5 High 2024-02-13
CVE-2023-4408 Parsing large DNS messages may cause excessive CPU load — BIND 9 7.5 High 2024-02-13
CVE-2023-4236 named may terminate unexpectedly under high DNS-over-TLS query load — BIND 9 7.5 High 2023-09-20
CVE-2023-3341 A stack exhaustion flaw in control channel code may cause named to terminate unexpectedly — BIND 9 7.5 High 2023-09-20
CVE-2023-2911 Exceeding the recursive-clients quota may cause named to terminate unexpectedly when stale-answer-client-timeout is set to 0 — BIND 9 7.5 High 2023-06-21
CVE-2023-2829 Malformed NSEC records can cause named to terminate unexpectedly when synth-from-dnssec is enabled — BIND 9 7.5 High 2023-06-21
CVE-2023-2828 named's configured cache size limit can be significantly exceeded — BIND 9 7.5 High 2023-06-21
CVE-2022-3924 named configured to answer from stale cache may terminate unexpectedly at recursive-clients soft quota — BIND 9 7.5 High 2023-01-25
CVE-2022-3736 named configured to answer from stale cache may terminate unexpectedly while processing RRSIG queries — BIND 9 7.5 High 2023-01-25
CVE-2022-3488 named may terminate unexpectedly when processing ECS options in repeated responses to iterative queries — BIND 9 7.5 High 2023-01-25
CVE-2022-3094 An UPDATE message flood may cause named to exhaust all available memory — BIND 9 7.5 High 2023-01-25
CVE-2019-6476 An error in QNAME minimization code can cause BIND to exit with an assertion failure — BIND 9 5.9 Medium 2019-10-17
CVE-2019-6475 A flaw in mirror zone validity checking can allow zone data to be spoofed — BIND 9 5.9 Medium 2019-10-17
CVE-2019-6471 A race condition when discarding malformed packets can cause BIND to exit with an assertion failure — BIND 9 5.9 - 2019-10-09
CVE-2018-5745 An assertion failure can occur if a trust anchor rolls over to an unsupported key algorithm when using managed-keys — BIND 9 4.9 - 2019-10-09
CVE-2018-5743 Limiting simultaneous TCP clients was ineffective — BIND 9 - - 2019-10-09
CVE-2018-5744 A specially crafted packet can cause named to leak memory — BIND 9 7.5 - 2019-10-09
CVE-2019-6465 Zone transfer controls for writable DLZ zones were not effective — BIND 9 5.3 - 2019-10-09
CVE-2019-6467 An error in the nxdomain redirect feature can cause BIND to exit with an INSIST assertion failure in query.c — BIND 9 5.9 - 2019-10-09
CVE-2017-3135 Combination of DNS64 and RPZ Can Lead to Crash — BIND 9 5.9 - 2019-01-16
CVE-2016-9778 An error handling certain queries using the nxdomain-redirect feature could cause a REQUIRE assertion failure in db.c — BIND 9 5.9 - 2019-01-16
CVE-2017-3136 An error handling synthesized records could cause an assertion failure when using DNS64 with "break-dnssec yes;" — BIND 9 5.9 - 2019-01-16
CVE-2017-3137 A response packet can cause a resolver to terminate when processing an answer containing a CNAME or DNAME — BIND 9 7.5 - 2019-01-16
CVE-2017-3138 named exits with a REQUIRE assertion failure if it receives a null command string on its control channel — BIND 9 5.3 - 2019-01-16
CVE-2017-3140 An error processing RPZ rules can cause named to loop endlessly after handling a query — BIND 9 7.5 - 2019-01-16

This page lists every published CVE security advisory associated with ISC. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.