Bind
Vendor:
First CVE: Jul 1, 1997 · Active for 29 years
184
Total CVEs
More Total CVEs than 99% of tracked products
6.8
Avg CVEs / Year
Higher CVE frequency than 92% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Bind over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 1, 1997
29 years ago
Most Recent CVE
May 20, 2026
65 days ago
CVE Severity & Scoring
Bind184 CVEs
43%
52%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (1.1%)
Network97 (52.7%)
Unknown84 (45.7%)
Physical0 (0.0%)
Adjacent Network1 (0.5%)
Attack Complexity
Low82 (44.6%)
High18 (9.8%)
Unknown84 (45.7%)
User Interaction
None100 (54.3%)
Unknown84 (45.7%)
Required0 (0.0%)
Privileges Required
Low12 (6.5%)
High4 (2.2%)
None84 (45.7%)
Unknown84 (45.7%)
Top CVEs
Signals from CVEs in this product scope (184 CVEs).
184 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-2776HIGH buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause | Sep 28, 2016 | 7.5 | 87 | NO | YES |
CVE-2015-5477HIGH named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries. | Jul 29, 2015 | 7.8 | 87 | NO | YES |
CVE-2008-1447MEDIUM The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; an | Jul 8, 2008 | 6.8 | 87 | NO | YES |
CVE-2020-8617MEDIUM Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfully guesses) the name of a TSIG | May 19, 2020 | 5.9 | 85 | NO | YES |
CVE-2023-50387HIGH Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more D | Feb 14, 2024 | 7.5 | 78 | NO | NO |
CVE-2021-25216CRITICAL In BIND 9.5.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.11.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9. | Apr 29, 2021 | 9.8 | 76 | NO | NO |
CVE-2023-50868HIGH The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA- | Feb 14, 2024 | 7.5 | 72 | NO | NO |
CVE-2020-8625HIGH BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a configuration which uses BIND's default settings the vulnerabl | Feb 17, 2021 | 8.1 | 62 | NO | NO |
CVE-2016-2775MEDIUM ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote attackers to cause a denial of se | Jul 19, 2016 | 5.9 | 59 | NO | NO |
CVE-2001-0010HIGH Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges. | Feb 12, 2001 | 10.0 | 59 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (184 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
5 CVEs
2.7% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
15 CVEs
8.2% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (184 CVEs).
Media Mentions
Signals from CVEs in this product scope (184 CVEs).
Top CNAs Publishing CVEs For Bind
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.9.9 | 10 | 6.6 | 28.9% | 0 | 0 |
| 9.9.8 | 10 | 6.9 | 27.2% | 0 | 0 |
| 9.9.7 | 4 | 6.4 | 31.2% | 0 | 0 |
| 9.9.6 | 5 | 6.5 | 33.0% | 0 | 0 |
| 9.9.5 | 5 | 6.6 | 35.4% | 0 | 0 |
| 9.9.4 | 7 | 5.0 | 30.9% | 0 | 0 |
| 9.9.3 | 28 | 6.6 | 23.2% | 0 | 1 |
| 9.9.2 | 10 | 7.1 | 29.1% | 0 | 0 |
| 9.9.13 | 9 | 6.8 | 13.5% | 0 | 0 |
| 9.9.12 | 10 | 6.9 | 13.1% | 0 | 0 |
| 9.9.11 | 1 | 7.5 | 27.7% | 0 | 0 |
| 9.9.10 | 7 | 5.8 | 10.1% | 0 | 0 |
| 9.9.1 | 16 | 7.2 | 25.6% | 0 | 0 |
| 9.9.0 | 20 | 7.0 | 23.7% | 0 | 0 |
| 9.8.6 | 8 | 5.6 | 30.7% | 0 | 0 |
| 9.8.5 | 10 | 6.2 | 27.9% | 0 | 0 |
| 9.8.4 | 11 | 6.6 | 29.9% | 0 | 0 |
| 9.8.3 | 15 | 7.0 | 27.3% | 0 | 0 |
| 9.8.2 | 15 | 7.0 | 27.8% | 0 | 0 |
| 9.8.1 | 20 | 6.6 | 25.8% | 0 | 0 |