Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2008-1447

87
FAUCET Score

CVE-2008-1447, known as the "Kaminsky bug," is a critical DNS cache poisoning vulnerability affecting various DNS implementations, including BIND and Microsoft DNS. It exploits insufficient randomness in DNS transaction IDs and source ports, allowing remote attackers to spoof DNS traffic via a birthday attack using in-bailiwick referrals. This vulnerability has a CVSS score of 6.8 (Medium) due to its network attack vector and high impact on integrity, despite requiring high attack complexity. Although not listed in KEV, exploit modules are available in Metasploit and ExploitDB, and it garnered significant community discussion and media coverage at the time of its discovery.

Impacted Technologies

VendorProductVersion(s)CPE
4CPE matchmatch criteria
cpe:2.3:a:isc:bind:4:*:*:*:*:*:*:*
8CPE matchmatch criteria
cpe:2.3:a:isc:bind:8:*:*:*:*:*:*:*
9.2.9CPE matchmatch criteria
cpe:2.3:a:isc:bind:9.2.9:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.8MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.2
Impact Score
4.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
95.18%
Probability of exploitation in next 30 days
EPSS Percentile
99.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
Metasploit: DNS BailiWicked Domain Attack · Jul 21, 2008
ExploitDB: EDB-6130 · Jul 25, 2008
This CVE's current EPSS score of 0.9518 is in the 100th percentile among its peer group of 19,955 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (8)

debianpatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: bind-20:9.2.4-22.el3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: bind-20:9.2.4-28.0.1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: selinux-policy-targeted-0:1.17.30-2.150.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 2.1Fixed in: bind-0:9.2.1-10.el2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: selinux-policy-0:2.4.6-137.1.el5_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: dnsmasq-0:2.45-1.el5_2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: bind-30:9.3.4-6.0.2.P1.el5_2
View patch

Vendor Advisories (1)

redhatCVE-2008-1447Important

bind: implement source UDP port randomization (CERT VU#800113)

Jul 8, 2008

References

ftp.netbsd.org / pub/NetBSD/security/advisories/NetBSD-SA2008-009.txt.asc
Third Party AdvisoryVendor Advisory
blog.invisibledenizen.org / 2008/07/kaminskys-dns-issue-accidentally-leaked.html
Technical Description
bugs.debian.org / cgi-bin/bugreport.cgi
Third Party Advisory
h20000.www2.hp.com / bizsupport/TechSupport/Document.jsp
Broken Link
h20000.www2.hp.com / bizsupport/TechSupport/Document.jsp
Broken Link
lists.apple.com / archives/security-announce//2008/Jul/msg00003.html
Mailing ListThird Party Advisory
lists.apple.com / archives/security-announce//2008/Sep/msg00003.html
Mailing ListThird Party Advisory
lists.apple.com / archives/security-announce//2008/Sep/msg00004.html
Mailing ListThird Party Advisory
lists.apple.com / archives/security-announce//2008/Sep/msg00005.html
Mailing ListThird Party Advisory
lists.grok.org.uk / pipermail/full-disclosure/2008-August/064118.html
Broken Link
lists.opensuse.org / opensuse-security-announce/2008-07/msg00003.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2008-08/msg00006.html
Third Party Advisory
marc.info
Third Party Advisory
marc.info
Third Party Advisory
marc.info
Third Party Advisory
marc.info
Third Party Advisory
rhn.redhat.com / errata/RHSA-2008-0533.html
Third Party Advisory
docs.microsoft.com / en-us/security-updates/securitybulletins/2008/ms08-037
PatchVendor Advisory
secunia.com / advisories/30925
Third Party Advisory
secunia.com / advisories/30973
Third Party Advisory
secunia.com / advisories/30977
Third Party Advisory
secunia.com / advisories/30979
Third Party Advisory
secunia.com / advisories/30980
Third Party Advisory
secunia.com / advisories/30988
Third Party AdvisoryVendor Advisory
secunia.com / advisories/30989
Vendor Advisory
secunia.com / advisories/30998
Third Party Advisory
secunia.com / advisories/31011
Third Party Advisory
secunia.com / advisories/31012
Third Party Advisory
secunia.com / advisories/31014
Third Party Advisory
secunia.com / advisories/31019
Third Party Advisory
secunia.com / advisories/31022
Third Party Advisory
secunia.com / advisories/31030
Third Party Advisory
secunia.com / advisories/31031
Third Party Advisory
secunia.com / advisories/31033
Vendor Advisory
secunia.com / advisories/31052
Vendor Advisory
secunia.com / advisories/31065
Third Party Advisory
secunia.com / advisories/31072
Third Party Advisory
secunia.com / advisories/31093
Third Party Advisory
secunia.com / advisories/31094
Vendor Advisory
secunia.com / advisories/31137
Vendor Advisory
secunia.com / advisories/31143
Third Party Advisory
secunia.com / advisories/31151
Third Party Advisory
secunia.com / advisories/31152
Third Party Advisory
secunia.com / advisories/31153
Third Party Advisory
secunia.com / advisories/31169
Third Party Advisory
secunia.com / advisories/31197
Vendor Advisory
secunia.com / advisories/31199
Third Party Advisory
secunia.com / advisories/31204
Third Party Advisory
secunia.com / advisories/31207
Vendor Advisory
secunia.com / advisories/31209
Third Party Advisory
secunia.com / advisories/31212
Third Party Advisory
secunia.com / advisories/31213
Third Party Advisory
secunia.com / advisories/31221
Third Party Advisory
secunia.com / advisories/31236
Third Party Advisory
secunia.com / advisories/31237
Vendor Advisory
secunia.com / advisories/31254
Vendor Advisory
secunia.com / advisories/31326
Third Party Advisory
secunia.com / advisories/31354
Third Party Advisory
secunia.com / advisories/31422
Third Party Advisory
secunia.com / advisories/31430
Third Party Advisory
secunia.com / advisories/31451
Third Party Advisory
secunia.com / advisories/31482
Third Party Advisory
secunia.com / advisories/31495
Third Party Advisory
secunia.com / advisories/31588
Third Party Advisory
secunia.com / advisories/31687
Third Party Advisory
secunia.com / advisories/31823
Third Party Advisory
secunia.com / advisories/31882
Third Party Advisory
secunia.com / advisories/31900
Third Party Advisory
secunia.com / advisories/33178
Third Party Advisory
secunia.com / advisories/33714
Third Party Advisory
secunia.com / advisories/33786
Third Party Advisory
security.freebsd.org / advisories/FreeBSD-SA-08:06.bind.asc
Third Party Advisory
security.gentoo.org / glsa/glsa-200807-08.xml
Third Party Advisory
security.gentoo.org / glsa/glsa-200812-17.xml
Third Party Advisory
security.gentoo.org / glsa/glsa-201209-25.xml
Third Party Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/43334
Third Party AdvisoryVDB Entry
exchange.xforce.ibmcloud.com / vulnerabilities/43637
Third Party AdvisoryVDB Entry
slackware.com / security/viewer.php
Third Party Advisory
slackware.com / security/viewer.php
Third Party Advisory
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12117
Tool Signature
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5725
Tool Signature
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5761
Tool Signature
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5917
Tool Signature
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9627
Tool Signature
sunsolve.sun.com / search/document.do
Third Party Advisory
sunsolve.sun.com / search/document.do
Third Party Advisory
support.apple.com / kb/HT3026
Third Party Advisory
support.apple.com / kb/HT3129
Third Party Advisory
support.citrix.com / article/CTX117991
Third Party Advisory
support.citrix.com / article/CTX118183
Third Party Advisory
support.nortel.com / go/main.jsp
Third Party Advisory
exploit-db.com / exploits/6122
Third Party AdvisoryVDB Entry
exploit-db.com / exploits/6123
Third Party AdvisoryVDB Entry
exploit-db.com / exploits/6130
Third Party AdvisoryVDB Entry
redhat.com / archives/fedora-package-announce/2008-July/msg00402.html
Third Party Advisory
redhat.com / archives/fedora-package-announce/2008-July/msg00458.html
Third Party Advisory
up2date.astaro.com / 2008/08/up2date_7202_released.html
Third Party Advisory
wiki.rpath.com / wiki/Advisories:rPSA-2008-0231
Third Party Advisory
wiki.rpath.com / wiki/Advisories:rPSA-2010-0018
Third Party Advisory
bluecoat.com / support/security-advisories/dns_cache_poisoning
Third Party Advisory
caughq.org / exploits/CAU-EX-2008-0002.txt
Third Party Advisory
caughq.org / exploits/CAU-EX-2008-0003.txt
Third Party Advisory
cisco.com / en/US/products/products_security_advisory09186a00809c2168.shtml
Third Party Advisory
debian.org / security/2008/dsa-1603
Patch
debian.org / security/2008/dsa-1604
Third Party Advisory
debian.org / security/2008/dsa-1605
Third Party Advisory
debian.org / security/2008/dsa-1619
Third Party Advisory
debian.org / security/2008/dsa-1623
Third Party Advisory
doxpara.com / DMK_BO2K8.ppt
Third Party Advisory
doxpara.com
Third Party Advisory
ibm.com / support/docview.wss
Third Party Advisory
ibm.com / support/docview.wss
Third Party Advisory
ibm.com / support/docview.wss
Third Party Advisory
ibm.com / support/docview.wss
Third Party Advisory
ibm.com / support/docview.wss
Third Party Advisory
ibm.com / support/docview.wss
Third Party Advisory
ipcop.org / index.php
Third Party Advisory
isc.org / index.pl
Third Party Advisory
kb.cert.org / vuls/id/800113
Third Party AdvisoryUS Government Resource
kb.cert.org / vuls/id/MIMG-7DWR4J
Third Party AdvisoryUS Government Resource
kb.cert.org / vuls/id/MIMG-7ECL8Q
Third Party AdvisoryUS Government Resource
mandriva.com / security/advisories
Third Party Advisory
nominum.com / asset_upload_file741_2661.pdf
Third Party Advisory
novell.com / support/viewContent.do
Third Party Advisory
openbsd.org / errata42.html
Third Party Advisory
openbsd.org / errata43.html
Third Party Advisory
phys.uu.nl / ~rombouts/pdnsd/ChangeLog
Third Party Advisory
phys.uu.nl / ~rombouts/pdnsd.html
Third Party Advisory
redhat.com / support/errata/RHSA-2008-0789.html
Third Party Advisory
rtpro.yamaha.co.jp / RT/FAQ/Security/VU800113.html
Third Party Advisory
ruby-lang.org / en/news/2008/08/08/multiple-vulnerabilities-in-ruby
Third Party Advisory
securityfocus.com / archive/1/495289/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / archive/1/495869/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / bid/30131
Third Party AdvisoryVDB Entry
securitytracker.com / id
Third Party AdvisoryVDB Entry
securitytracker.com / id
Third Party AdvisoryVDB Entry
securitytracker.com / id
Third Party AdvisoryVDB Entry
securitytracker.com / id
Third Party AdvisoryVDB Entry
securitytracker.com / id
Third Party AdvisoryVDB Entry
securitytracker.com / id
Third Party AdvisoryVDB Entry
securitytracker.com / id
Third Party AdvisoryVDB Entry
securitytracker.com / id
Third Party AdvisoryVDB Entry
securitytracker.com / id
Third Party AdvisoryVDB Entry
securitytracker.com / id
Third Party AdvisoryVDB Entry
securitytracker.com / id
Third Party AdvisoryVDB Entry
securitytracker.com / id
Third Party AdvisoryVDB Entry
securitytracker.com / id
Third Party AdvisoryVDB Entry
securitytracker.com / id
Third Party AdvisoryVDB Entry
securitytracker.com / id
Third Party AdvisoryVDB Entry
securitytracker.com / id
Third Party AdvisoryVDB Entry
securitytracker.com / id
Third Party AdvisoryVDB Entry
securitytracker.com / id
Third Party AdvisoryVDB Entry
securitytracker.com / id
Third Party AdvisoryVDB Entry
ubuntu.com / usn/usn-622-1
Third Party Advisory
ubuntu.com / usn/usn-627-1
Third Party Advisory
unixwiz.net / techtips/iguide-kaminsky-dns-vuln.html
Third Party Advisory
us-cert.gov / cas/techalerts/TA08-190A.html
Third Party AdvisoryUS Government Resource
us-cert.gov / cas/techalerts/TA08-190B.html
Third Party AdvisoryUS Government Resource
us-cert.gov / cas/techalerts/TA08-260A.html
Third Party AdvisoryUS Government Resource
vmware.com / security/advisories/VMSA-2008-0014.html
Third Party Advisory
vupen.com / english/advisories/2008/2019/references
Third Party Advisory
vupen.com / english/advisories/2008/2023/references
Third Party Advisory
vupen.com / english/advisories/2008/2025/references
Third Party Advisory
vupen.com / english/advisories/2008/2029/references
Third Party Advisory
vupen.com / english/advisories/2008/2030/references
Third Party Advisory
vupen.com / english/advisories/2008/2050/references
Third Party Advisory
vupen.com / english/advisories/2008/2051/references
Third Party Advisory
vupen.com / english/advisories/2008/2052/references
Third Party Advisory
vupen.com / english/advisories/2008/2055/references
Third Party Advisory
vupen.com / english/advisories/2008/2092/references
Third Party Advisory
vupen.com / english/advisories/2008/2113/references
Third Party Advisory
vupen.com / english/advisories/2008/2114/references
Third Party Advisory
vupen.com / english/advisories/2008/2123/references
Third Party Advisory
vupen.com / english/advisories/2008/2139/references
Third Party Advisory
vupen.com / english/advisories/2008/2166/references
Third Party Advisory
vupen.com / english/advisories/2008/2195/references
Third Party Advisory
vupen.com / english/advisories/2008/2196/references
Third Party Advisory
vupen.com / english/advisories/2008/2197/references
Third Party Advisory
vupen.com / english/advisories/2008/2268
Third Party Advisory
vupen.com / english/advisories/2008/2291
Third Party Advisory
vupen.com / english/advisories/2008/2334
Third Party Advisory
vupen.com / english/advisories/2008/2342
Third Party Advisory
vupen.com / english/advisories/2008/2377
Third Party Advisory
vupen.com / english/advisories/2008/2383
Third Party Advisory
vupen.com / english/advisories/2008/2384
Third Party Advisory
vupen.com / english/advisories/2008/2466
Third Party Advisory
vupen.com / english/advisories/2008/2467
Third Party Advisory
vupen.com / english/advisories/2008/2482
Third Party Advisory
vupen.com / english/advisories/2008/2525
Third Party Advisory
vupen.com / english/advisories/2008/2549
Third Party Advisory
vupen.com / english/advisories/2008/2558
Third Party Advisory
vupen.com / english/advisories/2008/2582
Third Party Advisory
vupen.com / english/advisories/2008/2584
Third Party Advisory
vupen.com / english/advisories/2009/0297
Third Party Advisory
vupen.com / english/advisories/2009/0311
Third Party Advisory
vupen.com / english/advisories/2010/0622
Third Party Advisory