Vulnerabilities in ISC

130 results
Vexday analysis

Com 107 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, o ISC apresenta taxa de exploração abaixo da média geral do catálogo, o que indica um perfil de risco operacional relativamente contido. No entanto, chama atenção o EPSS de 0,9342 associado ao CVE-2020-8617, indicando altíssima probabilidade de exploração para essa vulnerabilidade específica — um sinal de que a ausência de entradas no KEV não elimina exposição relevante. O tipo de falha mais recorrente é CWE-617 (Reachable Assertion), que pode ser explorada para causar negação de serviço em implementações de software como o BIND. Com 3 CVEs com PoC pública e 6 surgidas nos últimos 90 dias, equipes responsáveis por infraestruturas baseadas em tecnologias ISC devem manter ciclos de patching ativos e monitorar especialmente as entradas com alto EPSS.

CVE-2024-1975HIGHSIG(0) can be used to exhaust CPU resourcesEPSS 2.1%CVE-2024-1737HIGHBIND's database will be slow if a very large number of RRs exist at the same nameEPSS 2.1%CVE-2024-4076HIGHAssertion failure when serving both stale cache data and authoritative zone contentEPSS 2.1%CVE-2020-8619MEDIUMA buffer boundary check assertion in rdataset.c can fail incorrectly during zone transferEPSS 2.1%CVE-2022-2906HIGHMemory leaks in code handling Diffie-Hellman key exchange via TKEY RRs (OpenSSL 3.0.0+ only)EPSS 2.1%CVE-2019-6469MEDIUMBIND Supported Preview Edition can exit with an assertion failure if ECS is in useEPSS 2.0%CVE-2022-3080HIGHBIND 9 resolvers configured to answer from stale cache with zero stale-answer-client-timeout may terminate unexpectedlyEPSS 1.9%CVE-2018-5739MEDIUMFailure to release memory may exhaust system resourcesEPSS 1.9%CVE-2026-5946HIGHInvalid handling of CLASS != INEPSS 1.9%CVE-2020-8618MEDIUMA buffer boundary check assertion in rdataset.c can fail incorrectly during zone transferEPSS 1.8%CVE-2026-1519HIGHExcessive NSEC3 iterations cause high CPU load during insecure delegation validationEPSS 1.6%CVE-2026-3593HIGHHeap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementationEPSS 1.5%CVE-2017-3141HIGHWindows service and uninstall paths are not quoted when BIND is installedEPSS 1.4%CVE-2022-2881MEDIUMBuffer overread in statistics channel codeEPSS 1.4%CVE-2026-5947HIGHSIG(0) validation during query flood may lead to undefined behaviorEPSS 1.4%CVE-2026-3608HIGHStack overflow in Kea daemonsEPSS 1.4%CVE-2022-0635HIGHVersions affected: BIND 9.18.0 When a vulnerable version of named receives a series of specific queries, the named process will eventually tEPSS 1.3%CVE-2022-0667HIGHAssertion failure on delayed DS lookupEPSS 1.3%CVE-2023-4408HIGHParsing large DNS messages may cause excessive CPU loadEPSS 1.3%CVE-2019-6475MEDIUMA flaw in mirror zone validity checking can allow zone data to be spoofedEPSS 1.3%