Vulnerabilidades em ISC

130 resultados
Análise Vexday

Com 107 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, o ISC apresenta taxa de exploração abaixo da média geral do catálogo, o que indica um perfil de risco operacional relativamente contido. No entanto, chama atenção o EPSS de 0,9342 associado ao CVE-2020-8617, indicando altíssima probabilidade de exploração para essa vulnerabilidade específica — um sinal de que a ausência de entradas no KEV não elimina exposição relevante. O tipo de falha mais recorrente é CWE-617 (Reachable Assertion), que pode ser explorada para causar negação de serviço em implementações de software como o BIND. Com 3 CVEs com PoC pública e 6 surgidas nos últimos 90 dias, equipes responsáveis por infraestruturas baseadas em tecnologias ISC devem manter ciclos de patching ativos e monitorar especialmente as entradas com alto EPSS.

CVE-2023-5517HIGHQuerying RFC 1918 reverse zones may cause an assertion failure when "nxdomain-redirect" is enabledEPSS 1.2%CVE-2023-5679HIGHEnabling both DNS64 and serve-stale may cause an assertion failure during recursive resolutionEPSS 1.2%CVE-2023-6516HIGHSpecific recursive query patterns may lead to an out-of-memory conditionEPSS 1.1%CVE-2026-3039HIGHBIND 9 server memory exhaustion during GSS-API TKEY negotiationEPSS 1.0%CVE-2025-40777HIGHA possible assertion failure when 'stale-answer-client-timeout' is set to '0'EPSS 0.9%CVE-2023-2829HIGHMalformed NSEC records can cause named to terminate unexpectedly when synth-from-dnssec is enabledEPSS 0.9%CVE-2019-6473MEDIUMA packet containing a malformed DUID can cause the kea-dhcp6 server to terminateEPSS 0.8%CVE-2019-6472MEDIUMA packet containing a malformed DUID can cause the kea-dhcp6 server to terminateEPSS 0.8%CVE-2019-6474MEDIUMA packet containing a malformed DUID can cause the kea-dhcp6 server to terminateEPSS 0.7%CVE-2026-3104HIGHMemory leak in code preparing DNSSEC proofs of non-existenceEPSS 0.7%CVE-2022-2928MEDIUMAn option refcount overflow exists in dhcpdEPSS 0.7%CVE-2025-40778HIGHCache poisoning attacks with unsolicited RRsEPSS 0.7%CVE-2026-5950MEDIUMUnbounded resend loop in BIND 9 resolverEPSS 0.7%CVE-2022-2929MEDIUMDHCP memory leakEPSS 0.6%CVE-2023-5680MEDIUMCleaning an ECS-enabled cache may cause excessive CPU loadEPSS 0.6%CVE-2026-3119MEDIUMAuthenticated query containing a TKEY record may cause named to terminate unexpectedlyEPSS 0.6%CVE-2026-11605HIGHUnnecessary validation of DNSSEC signed recordsEPSS 0.5%CVE-2026-13204HIGHUnexpected exit in certain situations with NSEC and NSEC3 both presentEPSS 0.5%CVE-2026-11622HIGHPotential memory usage beyond configured limitsEPSS 0.5%CVE-2025-40779HIGHKea crash upon interaction between specific client options and subnet selectionEPSS 0.5%