Internet Systems Consortium (ISC)

First CVE: Jan 16, 2019Active for: 8 years
121
CVEs Published
More CVEs Published than 73% of tracked CNAs
15.1
Avg CVEs / Year
More Avg CVEs / Year than 62% of tracked CNAs
7.1
Avg CVSS Score
Higher Avg CVSS Score than 47% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Internet Systems Consortium (ISC) as a CNA, 79.3% affect products that Internet Systems Consortium (ISC) develops as a vendor.

79.3%
20.7%
Self-reported: 96Third-party: 25

Of all the CVEs published that affect products developed by Internet Systems Consortium (ISC), 39.2% are self-published by Internet Systems Consortium (ISC) as a CNA.

39.2%
60.8%
Self-published: 96Published by other CNAs: 149

Trends Over Time

The number and severity of CVEs published by Internet Systems Consortium (ISC) over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 16, 2019
7 years ago
Most Recent CVE
Jul 22, 2026
2 days ago

Top CVEs

All CVEs published by Internet Systems Consortium (ISC) as a CNA, regardless of affected vendor or product.

121 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfully guesses) the name of a TSIG
May 19, 20205.985NOYES
In BIND 9.5.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.11.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.
Apr 29, 20219.876NONO
BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a configuration which uses BIND's default settings the vulnerabl
Feb 17, 20218.162NONO
A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool of socket descriptors available to the DHCP server. Affects I
Jan 16, 20197.559NONO
"deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the
Jan 16, 20197.558NONO
A use-after-free vulnerability exists within the DNS-over-HTTPS implementation. This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and 9.20.9-S1 thr
May 20, 20269.843NONO
BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the resolver receives an RRSIG quer
Jan 26, 20237.543NONO
The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50
Jul 22, 20268.640NONO
BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in some cases to a use-after-free error that can trigger an assertion failure and cr
Jan 16, 20197.538NONO
Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that s
May 20, 20267.537NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA121 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local4 (3.3%)
Network111 (91.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network6 (5.0%)
Attack Complexity
Low108 (89.3%)
High13 (10.7%)
Unknown0 (0.0%)
User Interaction
None120 (99.2%)
Unknown0 (0.0%)
Required1 (0.8%)
Privileges Required
Low11 (9.1%)
High4 (3.3%)
None106 (87.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (121 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.8% of CVEs· 86th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
1.7% of CVEs· 86th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Internet Systems Consortium (ISC) as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Internet Systems Consortium (ISC) as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs