CVE-2015-5477

EXPLOITED

ISC BIND 9.x <9.9.7-P2, 9.10.x <9.10.2-P3 - DoS

Title source: llm

Description

named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.

Exploits (11)

nomisec WORKING POC 65 stars
by robertdavidgraham · dos
https://github.com/robertdavidgraham/cve-2015-5477
nomisec WORKING POC 14 stars
by elceef · poc
https://github.com/elceef/tkeypoc
nomisec WORKING POC 1 stars
by hmlio · poc
https://github.com/hmlio/vaas-cve-2015-5477
nomisec WORKING POC 1 stars
by knqyf263 · dos
https://github.com/knqyf263/cve-2015-5477
nomisec WORKING POC 1 stars
by ilanyu · poc
https://github.com/ilanyu/cve-2015-5477
nomisec STUB
by likekabin · poc
https://github.com/likekabin/ShareDoc_cve-2015-5477
nomisec WORKING POC
by xycloops123 · remote
https://github.com/xycloops123/TKEY-remote-DoS-vulnerability-exploit
exploitdb WORKING POC VERIFIED
by Errata Security · cdosmultiple
https://www.exploit-db.com/exploits/37721
vulncheck_xdb WORKING POC
dos
https://gitlab.com/LinuxGun/cve-2015-5477
metasploit WORKING POC
by Jonathan Foote, throwawayokejxqbbif, wvu · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/dos/dns/bind_tkey.rb
exploitdb WORKING POC
by elceef · pythondosmultiple
https://www.exploit-db.com/exploits/37723

References (42)

... and 22 more

Scores

EPSS 0.9275
EPSS Percentile 99.8%

Exploitation Intel

VulnCheck KEV 2015-08-02

Classification

CWE
CWE-19
Status draft

Affected Products (2)

isc/bind < 9.9.7
isc/bind < 9.10.2

Timeline

Published Jul 29, 2015
Tracked Since Feb 18, 2026