Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
426 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 95% | 💥 Exploit | ISC Bind | 8/7/2008 | 16/6/2026 | The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and other implementations allow remote attackers to spoof DNS traffic via a birthday attack that uses in-bailiwick referrals to conduct cache… | |
| Modificada | Alta (10) | 12% | — | ISC Bind | 16/1/2008 | 16/6/2026 | Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted input that triggers memory corruption. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Matteo Binda ASP Photo Gallery | 15/1/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in Matteo Binda ASP Photo Gallery 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) Imgbig.asp, (b) thumb.asp, and (c) thumbricerca.asp and the (2) ricerca parameter to (d) thumbricerca.asp. | |
| Modificada | Media (4.3) | 7.6% | 💥 Exploit | ISC Bind | 12/9/2007 | 16/6/2026 | The (1) NSID_SHUFFLE_ONLY and (2) NSID_USE_POOL PRNG algorithms in ISC BIND 8 before 8.4.7-P1 generate predictable DNS query identifiers when sending outgoing queries such as NOTIFY messages when answering questions as a resolver, which allows remote attackers to poison DNS caches via unknown vectors. NOTE: this issue… | |
| Modificada | Media (5.8) | 6.1% | — | ISC Bind | 24/7/2007 | 16/6/2026 | The default access control lists (ACL) in ISC BIND 9.4.0, 9.4.1, and 9.5.0a1 through 9.5.0a5 do not set the allow-recursion and allow-query-cache ACLs, which allows remote attackers to make recursive queries and query the cache. | |
| Modificada | Media (4.3) | 13% | 💥 Exploit | ISC Bind | 24/7/2007 | 16/6/2026 | ISC BIND 9 through 9.5.0a5 uses a weak random number generator during generation of DNS query ids when answering resolver questions or sending NOTIFY messages to slave name servers, which makes it easier for remote attackers to guess the next query id and perform DNS cache poisoning. | |
| Modificada | Alta (7.1) | 7.6% | — | ISC Bind | 2/5/2007 | 16/6/2026 | Unspecified vulnerability in query.c in ISC BIND 9.4.0, and 9.5.0a1 through 9.5.0a3, when recursion is enabled, allows remote attackers to cause a denial of service (daemon exit) via a sequence of queries processed by the query_addsoa function. | |
| Modificada | Alta (7.8) | 12% | — | ISC Bind | 25/1/2007 | 16/6/2026 | Use-after-free vulnerability in ISC BIND 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (named daemon crash) via unspecified vectors that cause named to "dereference a freed fetch context." | |
| Modificada | Media (4.3) | 44% | — | ISC Bind | 25/1/2007 | 16/6/2026 | ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (exit) via a type * (ANY) DNS query response that contains multiple RRsets, which triggers an assertion error, aka the… | |
| Modificada | Alta (7.5) | 12% | — | ISC BindCanonical Ubuntu LinuxApple MAC OS XApple MAC OS X Server | 6/9/2006 | 16/6/2026 | BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via certain SIG queries, which cause an assertion failure when multiple RRsets are returned. | |
| Modificada | Media (5) | 8.6% | — | ISC Bind | 6/9/2006 | 16/6/2026 | BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via a flood of recursive queries, which cause an INSIST failure when the response is received after the recursion queue is empty. | |
| Modificada | Media (5) | 8.0% | — | ISC Bind | 27/4/2006 | 16/6/2026 | Unspecified vulnerability in ISC BIND allows remote attackers to cause a denial of service via a crafted DNS message with a "broken" TSIG, as demonstrated by the OUSPG PROTOS DNS test suite. | |
| Modificada | Media (5) | 58% | 💥 PoC | ISC Bind | 3/3/2006 | 16/6/2026 | The default configuration of ISC BIND before 9.4.1-P1, when configured as a caching name server, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed source IP… | |
| Modificada | Alta (7.5) | 8.2% | — | ISC Bind | 2/2/2006 | 16/6/2026 | BIND 4 (BIND4) and BIND 8 (BIND8), if used as a target forwarder, allows remote attackers to gain privileged access via a "Kashpureff-style DNS cache corruption" attack. | |
| Modificada | Media (5) | 11% | — | ISC Bind | 2/5/2005 | 16/6/2026 | Buffer overflow in the code for recursion and glue fetching in BIND 8.4.4 and 8.4.5 allows remote attackers to cause a denial of service (crash) via queries that trigger the overflow in the q_usedns array that tracks nameservers and addresses. | |
| Modificada | Media (4.3) | 6.4% | — | ISC Bind | 2/5/2005 | 16/6/2026 | An "incorrect assumption" in the authvalidated validator function in BIND 9.3.0, when DNSSEC is enabled, allows remote attackers to cause a denial of service (named server exit) via crafted DNS packets that cause an internal consistency test (self-check) to fail. | |
| Modificada | Media (4.3) | 3.2% | — | ISC BindNixu NamesurferCompaq Tru64Freebsd+6 | 15/12/2003 | 16/6/2026 | ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value. | |
| Modificada | Baja (2.1) | 0.34% | — | Bindview NetinventoryBindview Netrc | 31/12/2002 | 16/6/2026 | BindView NetInventory 1.0, when used with NetRC 1.0, allows local users to read sensitive information (passwords) by deleting the HOSTCFG._NI file and forcing an audit, which rewrites the HOSTCFG._NI to HOSTCFG.INI and stores the passwords in cleartext until the audit is complete. | |
| Modificada | Media (5) | 2.4% | — | ISC BindFujitsu UXP V | 31/12/2002 | 16/6/2026 | The DNS resolver in unspecified versions of Fujitsu UXP/V, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via a birthday attack that uses a large number of open queries for the same resource record (RR) combined with spoofed responses, which increases… | |
| Modificada | Media (5) | 2.4% | — | Infoblox DNS ONEISC Bind | 31/12/2002 | 16/6/2026 | The DNS resolver in unspecified versions of Infoblox DNS One, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via a birthday attack that uses a large number of open queries for the same resource record (RR) combined with spoofed responses, which… | |
| Modificada | Media (5) | 8.3% | — | ISC Bind | 31/12/2002 | 16/6/2026 | BIND 4 and BIND 8, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via a birthday attack that uses a large number of open queries for the same resource record (RR) combined with spoofed responses, which increases the possibility of successfully spoofing… | |
| Modificada | Alta (7.5) | 9.9% | — | ISC BindAstaro Security Linux | 29/11/2002 | 16/6/2026 | Buffer overflows in the DNS stub resolver library in ISC BIND 4.9.2 through 4.9.10, and other derived libraries such as BSD libc and GNU glibc, allow remote attackers to execute arbitrary code via DNS server responses that trigger the overflow in the (1) getnetbyname, or (2) getnetbyaddr functions, aka "LIBRESOLV:… | |
| Modificada | Media (5) | 7.6% | — | ISC BindFreebsdOpenbsd | 29/11/2002 | 16/6/2026 | BIND 8.x through 8.3.3 allows remote attackers to cause a denial of service (crash) via SIG RR elements with invalid expiry times, which are removed from the internal BIND database and later cause a null dereference. | |
| Modificada | Media (5) | 9.6% | 💥 Exploit | ISC BindFreebsdOpenbsd | 29/11/2002 | 16/6/2026 | BIND 8.3.x through 8.3.3 allows remote attackers to cause a denial of service (termination due to assertion failure) via a request for a subdomain that does not exist, with an OPT resource record with a large UDP payload size. | |
| Modificada | Alta (7.5) | 12% | — | ISC BindFreebsdOpenbsd | 29/11/2002 | 16/6/2026 | Buffer overflow in named in BIND 4 versions 4.9.10 and earlier, and 8 versions 8.3.3 and earlier, allows remote attackers to execute arbitrary code via a certain DNS server response containing SIG resource records (RR). |