Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2006-4095

24
FAUCET Score

CVE-2006-4095 is a denial-of-service vulnerability affecting BIND versions prior to 9.2.6-P1 and 9.3.2-P1, including products from Apple, Canonical, and ISC. This flaw allows remote attackers to crash the BIND service through specially crafted SIG queries that trigger an assertion failure when multiple RRsets are returned. Rated with a CVSS score of 7.5 (High), it is easily exploitable over the network with low attack complexity and no user interaction, leading to a complete loss of availability. Despite its age and severity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
<= 9.2.6CPE matchmatch criteria
cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:*
>= 9.3.0, <= 9.3.2CPE matchmatch criteria
cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:*
5.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:5.04:*:*:*:*:*:*:*
5.10CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:5.10:*:*:*:*:*:*:*
6.06CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
12.55%
Probability of exploitation in next 30 days
EPSS Percentile
95.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.1255 is in the 94th percentile among its peer group of 51,553 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2006-4095

CVE-2006-4095

References

docs.info.apple.com / article.html
Broken Link
lists.apple.com / archives/security-announce/2007/May/msg00004.html
Mailing List
secunia.com / advisories/21752
Broken Link
secunia.com / advisories/21786
Broken Link
secunia.com / advisories/21816
Broken Link
secunia.com / advisories/21818
Broken Link
secunia.com / advisories/21828
Broken Link
secunia.com / advisories/21835
Broken Link
secunia.com / advisories/21838
Broken Link
secunia.com / advisories/21912
Broken Link
secunia.com / advisories/21926
Broken Link
secunia.com / advisories/22298
Broken Link
secunia.com / advisories/24950
Broken Link
secunia.com / advisories/25402
Broken Link
security.freebsd.org / advisories/FreeBSD-SA-06:20.bind.asc
Third Party Advisory
security.gentoo.org / glsa/glsa-200609-11.xml
Third Party Advisory
securitytracker.com / id
Broken LinkThird Party AdvisoryVDB Entry
exchange.xforce.ibmcloud.com / vulnerabilities/28745
Third Party AdvisoryVDB Entry
issues.rpath.com / browse/RPL-626
Broken Link
slackware.com / security/viewer.php
Broken Link
www2.itrc.hp.com / service/cki/docDisplay.do
Broken Link
kb.cert.org / vuls/id/915404
PatchThird Party AdvisoryUS Government Resource
mandriva.com / security/advisories
Broken Link
niscc.gov.uk / niscc/docs/re-20060905-00590.pdf
Broken LinkPatch
novell.com / linux/security/advisories/2006_23_sr.html
Broken Link
novell.com / linux/security/advisories/2006_24_sr.html
Broken Link
openbsd.org / errata.html
Release Notes
openpkg.com / security/advisories/OpenPKG-SA-2006.019.html
Broken Link
securityfocus.com / archive/1/445600/100/0/threaded
Broken LinkThird Party AdvisoryVDB Entry
securityfocus.com / bid/19859
Broken LinkThird Party AdvisoryVDB Entry
ubuntu.com / usn/usn-343-1
Third Party Advisory
us.debian.org / security/2006/dsa-1172
Broken Link
vupen.com / english/advisories/2006/3473
Broken Link
vupen.com / english/advisories/2007/1401
Broken Link
vupen.com / english/advisories/2007/1939
Broken Link