Vulnerabilidades em ISC

116 resultados
Análise Vexday

Com 107 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, o ISC apresenta taxa de exploração abaixo da média geral do catálogo, o que indica um perfil de risco operacional relativamente contido. No entanto, chama atenção o EPSS de 0,9342 associado ao CVE-2020-8617, indicando altíssima probabilidade de exploração para essa vulnerabilidade específica — um sinal de que a ausência de entradas no KEV não elimina exposição relevante. O tipo de falha mais recorrente é CWE-617 (Reachable Assertion), que pode ser explorada para causar negação de serviço em implementações de software como o BIND. Com 3 CVEs com PoC pública e 6 surgidas nos últimos 90 dias, equipes responsáveis por infraestruturas baseadas em tecnologias ISC devem manter ciclos de patching ativos e monitorar especialmente as entradas com alto EPSS.

CVE-2018-5738MEDIUMSome versions of BIND can improperly permit recursive query service to unauthorized clientsEPSS 11.2%CVE-2020-8616HIGHBIND does not sufficiently limit the number of fetches performed when processing referralsEPSS 10.6%CVE-2018-5737MEDIUMBIND 9.12's serve-stale implementation can cause an assertion failure in rbtdb.c or other undesirable behavior, even if serve-stale is not enabled.EPSS 10.4%CVE-2017-3137HIGHA response packet can cause a resolver to terminate when processing an answer containing a CNAME or DNAMEEPSS 9.0%CVE-2025-13878HIGHMalformed BRID/HHIT records can cause named to terminate unexpectedlyEPSS 8.2%CVE-2021-25219MEDIUMLame cache can be abused to severely degrade resolver performanceEPSS 8.1%CVE-2016-9778HIGHAn error handling certain queries using the nxdomain-redirect feature could cause a REQUIRE assertion failure in db.cEPSS 6.8%CVE-2018-5743HIGHLimiting simultaneous TCP clients was ineffectiveEPSS 6.5%CVE-2022-1183HIGHDestroying a TLS session early causes assertion failureEPSS 6.4%CVE-2020-8623HIGHA flaw in native PKCS#11 code can lead to a remotely triggerable assertion failure in pk11.cEPSS 6.4%CVE-2018-5734HIGHA malformed request can trigger an assertion failure in badcache.cEPSS 6.3%CVE-2021-25217HIGHA buffer overrun in lease file parsing code can be used to exploit a common vulnerability shared by dhcpd and dhclientEPSS 6.1%CVE-2021-25214MEDIUMA broken inbound incremental zone update (IXFR) can cause named to terminate unexpectedlyEPSS 6.0%CVE-2020-8622MEDIUMA truncated TSIG response can lead to an assertion failureEPSS 5.6%CVE-2017-3138MEDIUMnamed exits with a REQUIRE assertion failure if it receives a null command string on its control channelEPSS 5.5%CVE-2019-6467MEDIUMAn error in the nxdomain redirect feature can cause BIND to exit with an INSIST assertion failure in query.cEPSS 5.5%CVE-2017-3142MEDIUMAn error in TSIG authentication can permit unauthorized zone transfersEPSS 5.4%CVE-2018-5732HIGHA specially constructed response from a malicious server can cause a buffer overflow in dhclientEPSS 5.0%CVE-2024-0760HIGHA flood of DNS messages over TCP may make the server unstableEPSS 4.7%CVE-2019-6477HIGHTCP-pipelined queries can bypass tcp-clients limitEPSS 4.1%