Page 17 of 179 results (0.006 seconds)

CVSS: 7.8EPSS: 0%CPEs: 2EXPL: 0

21 Jul 2001 — dnskeygen in BIND 8.2.4 and earlier, and dnssec-keygen in BIND 9.1.2 and earlier, set insecure permissions for a HMAC-MD5 shared secret key file used for DNS Transactional Signatures (TSIG), which allows attackers to obtain the keys and perform dynamic DNS updates. • http://www.osvdb.org/5609 • CWE-276: Incorrect Default Permissions •

CVSS: 10.0EPSS: 7%CPEs: 10EXPL: 4

12 Feb 2001 — Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges. • https://www.exploit-db.com/exploits/277 •

CVSS: 7.5EPSS: 1%CPEs: 15EXPL: 0

12 Feb 2001 — BIND 4 and BIND 8 allow remote attackers to access sensitive information such as environment variables. • http://www.cert.org/advisories/CA-2001-02.html •

CVSS: 10.0EPSS: 2%CPEs: 5EXPL: 0

12 Feb 2001 — Buffer overflow in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges. • http://www.cert.org/advisories/CA-2001-02.html •

CVSS: 10.0EPSS: 2%CPEs: 5EXPL: 0

12 Feb 2001 — Format string vulnerability in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges. • http://www.cert.org/advisories/CA-2001-02.html •

CVSS: 7.5EPSS: 3%CPEs: 11EXPL: 0

19 Dec 2000 — named in BIND 8.2 through 8.2.2-P6 allows remote attackers to cause a denial of service by sending an SRV record to the server, aka the "srv bug." • http://archives.neohapsis.com/archives/linux/suse/2000-q4/0657.html •

CVSS: 7.5EPSS: 38%CPEs: 1EXPL: 2

19 Dec 2000 — named in BIND 8.2 through 8.2.2-P6 allows remote attackers to cause a denial of service by making a compressed zone transfer (ZXFR) request and performing a name service query on an authoritative record that is not cached, aka the "zxfr bug." • https://www.exploit-db.com/exploits/20388 •

CVSS: 10.0EPSS: 16%CPEs: 1EXPL: 3

29 Nov 2000 — Buffer overflow in host command allows a remote attacker to execute arbitrary commands via a long response to an AXFR query. • https://www.exploit-db.com/exploits/20374 •

CVSS: 7.5EPSS: 1%CPEs: 8EXPL: 0

03 May 2000 — The resolver in glibc 2.1.3 uses predictable IDs, which allows a local attacker to spoof DNS query results. • http://www.securityfocus.com/bid/1166 •

CVSS: 10.0EPSS: 0%CPEs: 4EXPL: 0

10 Nov 1999 — Denial of service in BIND by improperly closing TCP sessions via so_linger. • ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt •