Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 31

Количество 31

suse-cvrf логотип

SUSE-SU-2025:0355-1

больше 1 года назад

Security update for bind

EPSS: Низкий
rocky логотип

RLSA-2025:1670

больше 1 года назад

Important: bind9.18 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-1670

больше 1 года назад

ELSA-2025-1670: bind9.18 security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01787-1

около 1 года назад

Security update for bind

EPSS: Низкий
ubuntu логотип

CVE-2024-12705

больше 1 года назад

Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic. This issue affects BIND 9 versions 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, and 9.18.11-S1 through 9.18.32-S1.

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2024-12705

больше 2 лет назад

Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic. This issue affects BIND 9 versions 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, and 9.18.11-S1 through 9.18.32-S1.

CVSS3: 7.5
EPSS: Средний
nvd логотип

CVE-2024-12705

больше 1 года назад

Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic. This issue affects BIND 9 versions 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, and 9.18.11-S1 through 9.18.32-S1.

CVSS3: 7.5
EPSS: Средний
msrc логотип

CVE-2024-12705

больше 1 года назад

DNS-over-HTTPS implementation suffers from multiple issues under heavy query load

CVSS3: 7.5
EPSS: Средний
debian логотип

CVE-2024-12705

больше 1 года назад

Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU an ...

CVSS3: 7.5
EPSS: Средний
ubuntu логотип

CVE-2024-11187

больше 1 года назад

It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section. An attacker sending many such queries can cause either the authoritative server itself or an independent resolver to use disproportionate resources processing the queries. Zones will usually need to have been deliberately crafted to attack this exposure. This issue affects BIND 9 versions 9.11.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, 9.11.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.32-S1.

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2024-11187

больше 1 года назад

It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section. An attacker sending many such queries can cause either the authoritative server itself or an independent resolver to use disproportionate resources processing the queries. Zones will usually need to have been deliberately crafted to attack this exposure. This issue affects BIND 9 versions 9.11.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, 9.11.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.32-S1.

CVSS3: 7.5
EPSS: Средний
nvd логотип

CVE-2024-11187

больше 1 года назад

It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section. An attacker sending many such queries can cause either the authoritative server itself or an independent resolver to use disproportionate resources processing the queries. Zones will usually need to have been deliberately crafted to attack this exposure. This issue affects BIND 9 versions 9.11.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, 9.11.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.32-S1.

CVSS3: 7.5
EPSS: Средний
msrc логотип

CVE-2024-11187

около 1 года назад

Many records in the additional section cause CPU exhaustion

CVSS3: 7.5
EPSS: Средний
debian логотип

CVE-2024-11187

больше 1 года назад

It is possible to construct a zone such that some queries to it will g ...

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-gf34-2fpp-vmc4

больше 1 года назад

Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic. This issue affects BIND 9 versions 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, and 9.18.11-S1 through 9.18.32-S1.

CVSS3: 7.5
EPSS: Средний
fstec логотип

BDU:2025-07734

больше 1 года назад

Уязвимость реализации DoH сервера DNS BIND, связанная с выделением неограниченной памяти, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Средний
suse-cvrf логотип

SUSE-SU-2025:0427-1

больше 1 года назад

Security update for bind

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2025:0389-1

больше 1 года назад

Security update for bind

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2025:0384-1

больше 1 года назад

Security update for bind

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2025:0359-1

больше 1 года назад

Security update for bind

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
suse-cvrf логотип
SUSE-SU-2025:0355-1

Security update for bind

больше 1 года назад
rocky логотип
RLSA-2025:1670

Important: bind9.18 security update

больше 1 года назад
oracle-oval логотип
ELSA-2025-1670

ELSA-2025-1670: bind9.18 security update (IMPORTANT)

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:01787-1

Security update for bind

около 1 года назад
ubuntu логотип
CVE-2024-12705

Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic. This issue affects BIND 9 versions 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, and 9.18.11-S1 through 9.18.32-S1.

CVSS3: 7.5
18%
Средний
больше 1 года назад
redhat логотип
CVE-2024-12705

Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic. This issue affects BIND 9 versions 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, and 9.18.11-S1 through 9.18.32-S1.

CVSS3: 7.5
18%
Средний
больше 2 лет назад
nvd логотип
CVE-2024-12705

Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic. This issue affects BIND 9 versions 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, and 9.18.11-S1 through 9.18.32-S1.

CVSS3: 7.5
18%
Средний
больше 1 года назад
msrc логотип
CVE-2024-12705

DNS-over-HTTPS implementation suffers from multiple issues under heavy query load

CVSS3: 7.5
18%
Средний
больше 1 года назад
debian логотип
CVE-2024-12705

Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU an ...

CVSS3: 7.5
18%
Средний
больше 1 года назад
ubuntu логотип
CVE-2024-11187

It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section. An attacker sending many such queries can cause either the authoritative server itself or an independent resolver to use disproportionate resources processing the queries. Zones will usually need to have been deliberately crafted to attack this exposure. This issue affects BIND 9 versions 9.11.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, 9.11.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.32-S1.

CVSS3: 7.5
15%
Средний
больше 1 года назад
redhat логотип
CVE-2024-11187

It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section. An attacker sending many such queries can cause either the authoritative server itself or an independent resolver to use disproportionate resources processing the queries. Zones will usually need to have been deliberately crafted to attack this exposure. This issue affects BIND 9 versions 9.11.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, 9.11.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.32-S1.

CVSS3: 7.5
15%
Средний
больше 1 года назад
nvd логотип
CVE-2024-11187

It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section. An attacker sending many such queries can cause either the authoritative server itself or an independent resolver to use disproportionate resources processing the queries. Zones will usually need to have been deliberately crafted to attack this exposure. This issue affects BIND 9 versions 9.11.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, 9.11.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.32-S1.

CVSS3: 7.5
15%
Средний
больше 1 года назад
msrc логотип
CVE-2024-11187

Many records in the additional section cause CPU exhaustion

CVSS3: 7.5
15%
Средний
около 1 года назад
debian логотип
CVE-2024-11187

It is possible to construct a zone such that some queries to it will g ...

CVSS3: 7.5
15%
Средний
больше 1 года назад
github логотип
GHSA-gf34-2fpp-vmc4

Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic. This issue affects BIND 9 versions 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, and 9.18.11-S1 through 9.18.32-S1.

CVSS3: 7.5
18%
Средний
больше 1 года назад
fstec логотип
BDU:2025-07734

Уязвимость реализации DoH сервера DNS BIND, связанная с выделением неограниченной памяти, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
18%
Средний
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0427-1

Security update for bind

15%
Средний
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0389-1

Security update for bind

15%
Средний
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0384-1

Security update for bind

15%
Средний
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0359-1

Security update for bind

15%
Средний
больше 1 года назад

Уязвимостей на страницу