The Internet Systems Consortium develops a focused but foundational set of infrastructure software: BIND (DNS), DHCP and its successor Kea, and INN (news distribution), all of which are deeply embedded in internet-critical services and present across authoritative nameservers, enterprise networks, and service provider infrastructure. Despite this narrow product count, the vendor's vulnerability footprint is substantial and highly prominent in the landscape, reflecting the universal deployment and long operational lifespans of its core products. The exposure recurs through weakness classes centered on input validation, memory-safety issues including buffer-bounds violations and reachable assertions, and protocol-parsing edge cases that are characteristic of systems software handling untrusted network data. Vulnerabilities affecting this vendor frequently acquire public exploit code, making patches operationally urgent even where severity bands vary. Defenders should maintain close tracking of ISC's advisories and treat BIND and DHCP updates as high-priority across DNS and network infrastructure; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Internet Systems Consortium (ISC) over time
Of all the CVEs published by Internet Systems Consortium (ISC) as a CNA, 79.3% affect products that Internet Systems Consortium (ISC) develops as a vendor.
Of all the CVEs published that affect products developed by Internet Systems Consortium (ISC), 39.2% are self-published by Internet Systems Consortium (ISC) as a CNA.
Signals from CVEs in this vendor scope (245 CVEs).
245 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-2776HIGH buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause | Sep 28, 2016 | 7.5 | 87 | NO | YES |
CVE-2015-5477HIGH named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries. | Jul 29, 2015 | 7.8 | 87 | NO | YES |
CVE-2008-1447MEDIUM The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; an | Jul 8, 2008 | 6.8 | 87 | NO | YES |
CVE-2020-8617MEDIUM Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfully guesses) the name of a TSIG | May 19, 2020 | 5.9 | 85 | NO | YES |
CVE-2023-50387HIGH Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more D | Feb 14, 2024 | 7.5 | 78 | NO | NO |
CVE-2010-2156MEDIUM ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 allows remote attackers to cause a denial of service (server exit) via a zero-length client ID. | Jun 7, 2010 | 5.0 | 77 | NO | YES |
CVE-2021-25216CRITICAL In BIND 9.5.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.11.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9. | Apr 29, 2021 | 9.8 | 76 | NO | NO |
CVE-2023-50868HIGH The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA- | Feb 14, 2024 | 7.5 | 72 | NO | NO |
CVE-2011-0997HIGH dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 allows remote attackers to execute arbitrary commands via shell m | Apr 8, 2011 | 7.5 | 72 | NO | NO |
CVE-2020-8625HIGH BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a configuration which uses BIND's default settings the vulnerabl | Feb 17, 2021 | 8.1 | 62 | NO | NO |
Signals from CVEs in this vendor scope (245 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Internet Systems Consortium (ISC).
Media articles that mention a CVE ID that affects a product developed by Internet Systems Consortium (ISC) — matched by CVE ID, not by vendor name.