Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2011-0414

31
FAUCET Score

CVE-2011-0414 describes a denial-of-service vulnerability affecting ISC BIND versions 9.7.1 through 9.7.2-P3 when configured as an authoritative server. Remote attackers can trigger a deadlock and daemon hang by sending a query during an IXFR transfer or DDNS update. This vulnerability has a CVSS score of 7.1, indicating a high severity with network-based attacks and medium complexity leading to a complete loss of availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) is listed, the CVE has received some community discussion and media coverage, suggesting awareness within the cybersecurity community.

Impacted Technologies

VendorProductVersion(s)CPE
9.7.1CPE matchmatch criteria
cpe:2.3:a:isc:bind:9.7.1:*:*:*:*:*:*:*
9.7.1CPE matchmatch criteria
cpe:2.3:a:isc:bind:9.7.1:p1:*:*:*:*:*:*
9.7.1CPE matchmatch criteria
cpe:2.3:a:isc:bind:9.7.1:p2:*:*:*:*:*:*
9.7.1CPE matchmatch criteria
cpe:2.3:a:isc:bind:9.7.1:rc1:*:*:*:*:*:*
9.7.2CPE matchmatch criteria
cpe:2.3:a:isc:bind:9.7.2:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.1HIGH

AV:N/AC:M/Au:N/C:N/I:N/A:C

Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
6.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
13.60%
Probability of exploitation in next 30 days
EPSS Percentile
96.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.1360 is in the 79th percentile among its peer group of 8,918 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: bind

Vendor Advisories (1)

redhatCVE-2011-0414Moderate

bind: named lockup with IXFR or DDNS update and a high query rate

Feb 22, 2011

References

lists.opensuse.org / opensuse-security-announce/2011-04/msg00000.html
bugzilla.redhat.com / show_bug.cgi
secunia.com / advisories/43439
secunia.com / advisories/43443
Vendor Advisory
debian.org / security/2011/dsa-2208
isc.org / software/bind/advisories/cve-2011-0414
Vendor Advisory
kb.cert.org / vuls/id/449980
US Government Resource
kb.cert.org / vuls/id/559980
US Government Resource
securitytracker.com / id
ubuntu.com / usn/USN-1070-1
vupen.com / english/advisories/2011/0466
Vendor Advisory
vupen.com / english/advisories/2011/0489
Vendor Advisory