Search: "isc"

277 CVEs found

ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta handles out-of-bailiwick data accompanying a secure response without re-fetching from the or...

Published: 2010-01-22
Products: 168
Vendors:
isc
CVE-2010-0743
5.0 MEDIUM

Multiple format string vulnerabilities in isns.c in (1) Linux SCSI target framework (aka tgt or scsi-target-utils) 1.0.3, 0.9.5, and earlier and (2) iSCSI Enterprise Target (aka iscsitarget) 0.4.16 al...

Published: 2010-04-08
Products: 3
Vendors:
zaal iscsitarget
CVE-2010-1460
5.0 MEDIUM

The IBM BladeCenter with Advanced Management Module (AMM) firmware before bpet50g does not properly perform interrupt sharing for USB and iSCSI, which allows remote attackers to cause a denial of serv...

Published: 2010-04-16
Products: 35
Vendors:
ibm
CVE-2010-2156
5.0 MEDIUM

ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 allows remote attackers to cause a denial of service (server exit) via a zero-length client ID.

Published: 2010-06-07
Products: 15
Vendors:
isc

Multiple SQL injection vulnerabilities in iScripts EasySnaps 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) comment parameter to add_comments.php, (2) values parameter to tag...

Published: 2010-07-02
Products: 1
Vendors:
iscripts
CVE-2010-2221
5.0 MEDIUM

Multiple buffer overflows in the iSNS implementation in isns.c in (1) Linux SCSI target framework (aka tgt or scsi-target-utils) before 1.0.6, (2) iSCSI Enterprise Target (aka iscsitarget or IET) 1.4....

Published: 2010-07-08
Products: 60
Vendors:
linux zaal arne_redlich_\&_ross_walker vladislav_bolkhovitin

SQL injection vulnerability in flashPlayer/playVideo.php in iScripts VisualCaster allows remote attackers to execute arbitrary SQL commands via the product_id parameter.

Published: 2010-07-25
Products: 1
Vendors:
iscripts
CVE-2010-0218
5.0 MEDIUM

ISC BIND 9.7.2 through 9.7.2-P1 uses an incorrect ACL to restrict the ability of Recursion Desired (RD) queries to access the cache, which allows remote attackers to obtain potentially sensitive infor...

Published: 2010-10-05
Products: 2
Vendors:
isc
CVE-2010-3762
4.3 MEDIUM

ISC BIND before 9.7.2-P2, when DNSSEC validation is enabled, does not properly handle certain bad signatures if multiple trust anchors exist for a single zone, which allows remote attackers to cause a...

Published: 2010-10-05
Products: 1
Vendors:
isc
CVE-2010-3611
4.3 MEDIUM

ISC DHCP server 4.0 before 4.0.2, 4.1 before 4.1.2, and 4.2 before 4.2.0-P1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a DHCPv6 packet containing a R...

Published: 2010-11-04
Products: 17
Vendors:
isc
CVE-2010-3613
4.0 MEDIUM

named in ISC BIND 9.6.2 before 9.6.2-P3, 9.6-ESV before 9.6-ESV-R3, and 9.7.x before 9.7.2-P3 does not properly handle the combination of signed negative responses and corresponding RRSIG records in t...

Published: 2010-12-06
Products: 26
Vendors:
isc
CVE-2010-3614
6.4 MEDIUM

named in ISC BIND 9.x before 9.6.2-P3, 9.7.x before 9.7.2-P3, 9.4-ESV before 9.4-ESV-R4, and 9.6-ESV before 9.6-ESV-R3 does not properly determine the security status of an NS RRset during a DNSKEY al...

Published: 2010-12-06
Products: 236
Vendors:
isc
CVE-2010-3615
5.0 MEDIUM

named in ISC BIND 9.7.2-P2 does not check all intended locations for allow-query ACLs, which might allow remote attackers to make successful requests for private DNS records via the standard DNS query...

Published: 2010-12-06
Products: 1
Vendors:
isc
CVE-2010-3616
5.0 MEDIUM

ISC DHCP server 4.2 before 4.2.0-P2, when configured to use failover partnerships, allows remote attackers to cause a denial of service (communications-interrupted state and DHCP client service loss) ...

Published: 2010-12-17
Products: 2
Vendors:
isc

The DHCPv6 server in ISC DHCP 4.0.x and 4.1.x before 4.1.2-P1, 4.0-ESV and 4.1-ESV before 4.1-ESV-R1, and 4.2.x before 4.2.1b1 allows remote attackers to cause a denial of service (assertion failure a...

Published: 2011-01-31
Products: 29
Vendors:
isc

ISC BIND 9.7.1 through 9.7.2-P3, when configured as an authoritative server, allows remote attackers to cause a denial of service (deadlock and daemon hang) by sending a query at the time of (1) an IX...

Published: 2011-02-23
Products: 9
Vendors:
isc
CVE-2011-0001
5.0 MEDIUM

Double free vulnerability in the iscsi_rx_handler function (usr/iscsi/iscsid.c) in the tgt daemon (tgtd) in Linux SCSI target framework (tgt) before 1.0.14, aka scsi-target-utils, allows remote attack...

Published: 2011-03-15
Products: 15
Vendors:
zaal

dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 allows remote attackers to execute arbitrary commands via shell metacharacters in a h...

Published: 2011-04-08
Products: 67
Vendors:
canonical debian isc
CVE-2011-1907
5.0 MEDIUM

ISC BIND 9.8.x before 9.8.0-P1, when Response Policy Zones (RPZ) RRset replacement is enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an RRSIG que...

Published: 2011-05-09
Products: 1
Vendors:
isc
CVE-2011-1910
5.0 MEDIUM

Off-by-one error in named in ISC BIND 9.x before 9.7.3-P1, 9.8.x before 9.8.0-P2, 9.4-ESV before 9.4-ESV-R4-P1, and 9.6-ESV before 9.6-ESV-R4-P1 allows remote DNS servers to cause a denial of service ...

Published: 2011-05-31
Products: 238
Vendors:
isc