Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 48

Количество 48

altlinux логотип

ALT-PU-2025-13412

11 месяцев назад

ALT-PU-2025-13412: package `bind` update to version 9.16.50-alt3

CVSS3: 8.6
EPSS: Низкий
ubuntu логотип

CVE-2025-40778

11 месяцев назад

Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.

CVSS3: 8.6
EPSS: Низкий
redhat логотип

CVE-2025-40778

11 месяцев назад

Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.

CVSS3: 8.6
EPSS: Низкий
nvd логотип

CVE-2025-40778

11 месяцев назад

Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.

CVSS3: 8.6
EPSS: Низкий
msrc логотип

CVE-2025-40778

10 месяцев назад

Cache poisoning attacks with unsolicited RRs

CVSS3: 8.6
EPSS: Низкий
debian логотип

CVE-2025-40778

11 месяцев назад

Under certain circumstances, BIND is too lenient when accepting record ...

CVSS3: 8.6
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:3976-1

11 месяцев назад

Security update for bind

EPSS: Низкий
rocky логотип

RLSA-2025:19835

11 месяцев назад

Important: bind security update

EPSS: Низкий
github логотип

GHSA-xmqp-6cj2-2hh3

11 месяцев назад

Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.

CVSS3: 8.6
EPSS: Низкий
oracle-oval логотип

ELSA-2025-22205

9 месяцев назад

ELSA-2025-22205: bind security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-19835

11 месяцев назад

ELSA-2025-19835: bind security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2025-13637

11 месяцев назад

Уязвимость DNS-сервера BIND, связанная с загрузкой внешних ненадёжных данных вместе с надёжными данными, позволяющая нарушителю перенаправить трафик на вредоносный сайт

CVSS3: 8.6
EPSS: Низкий
ubuntu логотип

CVE-2025-8677

11 месяцев назад

Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion. This issue affects BIND 9 versions 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2025-8677

11 месяцев назад

Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion. This issue affects BIND 9 versions 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.

CVSS3: 7.5
EPSS: Средний
nvd логотип

CVE-2025-8677

11 месяцев назад

Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion. This issue affects BIND 9 versions 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.

CVSS3: 7.5
EPSS: Средний
msrc логотип

CVE-2025-8677

10 месяцев назад

Resource exhaustion via malformed DNSKEY handling

CVSS3: 7.5
EPSS: Средний
debian логотип

CVE-2025-8677

11 месяцев назад

Querying for records within a specially crafted zone containing certai ...

CVSS3: 7.5
EPSS: Средний
ubuntu логотип

CVE-2025-40780

11 месяцев назад

In specific circumstances, due to a weakness in the Pseudo Random Number Generator (PRNG) that is used, it is possible for an attacker to predict the source port and query ID that BIND will use. This issue affects BIND 9 versions 9.16.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.16.8-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.

CVSS3: 8.6
EPSS: Низкий
redhat логотип

CVE-2025-40780

11 месяцев назад

In specific circumstances, due to a weakness in the Pseudo Random Number Generator (PRNG) that is used, it is possible for an attacker to predict the source port and query ID that BIND will use. This issue affects BIND 9 versions 9.16.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.16.8-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.

CVSS3: 8.6
EPSS: Низкий
nvd логотип

CVE-2025-40780

11 месяцев назад

In specific circumstances, due to a weakness in the Pseudo Random Number Generator (PRNG) that is used, it is possible for an attacker to predict the source port and query ID that BIND will use. This issue affects BIND 9 versions 9.16.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.16.8-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.

CVSS3: 8.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
altlinux логотип
ALT-PU-2025-13412

ALT-PU-2025-13412: package `bind` update to version 9.16.50-alt3

CVSS3: 8.6
11 месяцев назад
ubuntu логотип
CVE-2025-40778

Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.

CVSS3: 8.6
1%
Низкий
11 месяцев назад
redhat логотип
CVE-2025-40778

Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.

CVSS3: 8.6
1%
Низкий
11 месяцев назад
nvd логотип
CVE-2025-40778

Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.

CVSS3: 8.6
1%
Низкий
11 месяцев назад
msrc логотип
CVE-2025-40778

Cache poisoning attacks with unsolicited RRs

CVSS3: 8.6
1%
Низкий
10 месяцев назад
debian логотип
CVE-2025-40778

Under certain circumstances, BIND is too lenient when accepting record ...

CVSS3: 8.6
1%
Низкий
11 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:3976-1

Security update for bind

1%
Низкий
11 месяцев назад
rocky логотип
RLSA-2025:19835

Important: bind security update

1%
Низкий
11 месяцев назад
github логотип
GHSA-xmqp-6cj2-2hh3

Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.

CVSS3: 8.6
1%
Низкий
11 месяцев назад
oracle-oval логотип
ELSA-2025-22205

ELSA-2025-22205: bind security update (IMPORTANT)

1%
Низкий
9 месяцев назад
oracle-oval логотип
ELSA-2025-19835

ELSA-2025-19835: bind security update (IMPORTANT)

1%
Низкий
11 месяцев назад
fstec логотип
BDU:2025-13637

Уязвимость DNS-сервера BIND, связанная с загрузкой внешних ненадёжных данных вместе с надёжными данными, позволяющая нарушителю перенаправить трафик на вредоносный сайт

CVSS3: 8.6
1%
Низкий
11 месяцев назад
ubuntu логотип
CVE-2025-8677

Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion. This issue affects BIND 9 versions 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.

CVSS3: 7.5
11%
Средний
11 месяцев назад
redhat логотип
CVE-2025-8677

Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion. This issue affects BIND 9 versions 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.

CVSS3: 7.5
11%
Средний
11 месяцев назад
nvd логотип
CVE-2025-8677

Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion. This issue affects BIND 9 versions 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.

CVSS3: 7.5
11%
Средний
11 месяцев назад
msrc логотип
CVE-2025-8677

Resource exhaustion via malformed DNSKEY handling

CVSS3: 7.5
11%
Средний
10 месяцев назад
debian логотип
CVE-2025-8677

Querying for records within a specially crafted zone containing certai ...

CVSS3: 7.5
11%
Средний
11 месяцев назад
ubuntu логотип
CVE-2025-40780

In specific circumstances, due to a weakness in the Pseudo Random Number Generator (PRNG) that is used, it is possible for an attacker to predict the source port and query ID that BIND will use. This issue affects BIND 9 versions 9.16.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.16.8-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.

CVSS3: 8.6
0%
Низкий
11 месяцев назад
redhat логотип
CVE-2025-40780

In specific circumstances, due to a weakness in the Pseudo Random Number Generator (PRNG) that is used, it is possible for an attacker to predict the source port and query ID that BIND will use. This issue affects BIND 9 versions 9.16.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.16.8-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.

CVSS3: 8.6
0%
Низкий
11 месяцев назад
nvd логотип
CVE-2025-40780

In specific circumstances, due to a weakness in the Pseudo Random Number Generator (PRNG) that is used, it is possible for an attacker to predict the source port and query ID that BIND will use. This issue affects BIND 9 versions 9.16.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.16.8-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.

CVSS3: 8.6
0%
Низкий
11 месяцев назад

Уязвимостей на страницу