← All CVEs

CVE-2002-1219

high · 7.5

Buffer overflow in named in BIND 4 versions 4.9.10 and earlier, and 8 versions 8.3.3 and earlier, allows remote attackers to execute arbitrary code via a certain DNS server response containing SIG resource records (RR).

7.5
CVSS
12.3%
EPSS (exploit prob.)
96th
EPSS percentile
2002-11-29
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

VendorProductAffected versions
iscbind4.9.5
iscbind4.9.6
iscbind4.9.7
iscbind4.9.8
iscbind4.9.9
iscbind4.9.10
iscbind8.2
iscbind8.2.1
iscbind8.2.2
iscbind8.2.3
iscbind8.2.4
iscbind8.2.5
iscbind8.2.6
iscbind8.3.0
iscbind8.3.1
iscbind8.3.2
iscbind8.3.3
freebsdfreebsd4.4
freebsdfreebsd4.5
freebsdfreebsd4.6
freebsdfreebsd4.7
openbsdopenbsd3.0
openbsdopenbsd3.1
openbsdopenbsd3.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2002-1219