peter bassill · operator
$ cve CVE-2007-2926 JSON

CVE-2007-2926 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 13.1% (pctl 96)

Patch early

A public exploit exists.

Description

ISC BIND 9 through 9.5.0a5 uses a weak random number generator during generation of DNS query ids when answering resolver questions or sending NOTIFY messages to slave name servers, which makes it easier for remote attackers to guess the next query id and perform DNS cache poisoning.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS13.09% — more likely to be exploited than 96% of all CVEs
On CISA KEVno
Public exploityes
Published2007-07-24
Last modified2026-06-16

Affected (1)

VendorProduct
iscbind

Public exploits

SourceTitleDate
exploit-dbBIND 9 0.3beta - DNS Cache Poisoning2007-08-07

References

→ the Explorer  ·  watch your stack  ·  NVD