Vulnerability index

Browse CVEs

56 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ntp MEDIUM 5.3
CVE-2015-8138EPSS 6%

NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to bypass the origin timestamp validation via a packet with an origin timestamp se…

Fix: after 4.2.8
Fix from $1,600 2017-01-30
Ntp MEDIUM 5.3
CVE-2015-8139EPSS 6%

ntpq in NTP before 4.2.8p7 allows remote attackers to obtain origin timestamps and then impersonate peers via unspecified vectors.

Fix: after 4.2.8
Fix from $1,600 2017-01-30
Ntp HIGH 7.5
CVE-2016-7434EPSS 53%

The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query.

Fix: 4.3.94+
Fix from $1,950 2017-01-13
Ntp HIGH 7.5
CVE-2016-9312EPSS 31%

ntpd in NTP before 4.2.8p9, when running on Windows, allows remote attackers to cause a denial of service via a large UDP packet.

Fix: after 4.2.8
Fix from $1,950 2017-01-13
Ntp MEDIUM 6.5
CVE-2016-9310EPSS 11%

The control mode (mode 6) functionality in ntpd in NTP before 4.2.8p9 allows remote attackers to set or unset traps via a crafted control mode packet.

Fix: after 4.2.8
Fix from $1,600 2017-01-13
Ntp MEDIUM 5.9
CVE-2016-9311EPSS 11%

ntpd in NTP before 4.2.8p9, when the trap service is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and cras…

Fix: after 4.2.8
Fix from $1,600 2017-01-13
Ntp MEDIUM 5.3
CVE-2016-7431EPSS 9%

NTP before 4.2.8p9 allows remote attackers to bypass the origin timestamp protection mechanism via an origin timestamp of zero. NOTE: this vulnerabi…

No fix yet
Fix from $1,600 2017-01-13
Ntp MEDIUM 5.3
CVE-2016-7433EPSS 10%

NTP before 4.2.8p9 does not properly perform the initial sync calculations, which allows remote attackers to unspecified impact via unknown vectors, …

Fix: after 4.2.8
Fix from $1,600 2017-01-13
Ntp HIGH 7.2
CVE-2016-1548

An attacker can spoof a packet from a legitimate ntpd server with an origin timestamp that matches the peer->dst timestamp recorded for that server. …

No fix yet
Fix from $1,950 2017-01-06
Ntp MEDIUM 6.5
CVE-2016-1549

A malicious authenticated peer can create arbitrarily-many ephemeral associations in order to win the clock selection algorithm in ntpd in NTP 4.2.8p…

Mitigation only
Fix from $1,600 2017-01-06
Ntp MEDIUM 5.3
CVE-2016-1547EPSS 5%

An off-path attacker can cause a preemptible client association to be demobilized in NTP 4.2.8p4 and earlier and NTPSec a5fb34b9cc89b92a8fef2f4590048…

Fix: after 4.2.8
Fix from $1,600 2017-01-06
Ntp MEDIUM 5.3
CVE-2016-1550

An exploitable vulnerability exists in the message authentication functionality of libntp in ntp 4.2.8p4 and NTPSec a5fb34b9cc89b92a8fef2f459004865c9…

No fix yet
Fix from $1,600 2017-01-06
Ntp HIGH 7.5
CVE-2016-4957EPSS 45%

ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exi…

Patch available
Fix from $1,950 2016-07-05
Ntp MEDIUM 5.3
CVE-2016-4956EPSS 16%

ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (interleaved-mode transition and time change) via a spoofed broad…

Fix: 4.2.8 / 4.3.93+
Fix from $1,600 2016-07-05
Ntp MEDIUM 5.9
CVE-2016-4955EPSS 9%

ntpd in NTP 4.x before 4.2.8p8, when autokey is enabled, allows remote attackers to cause a denial of service (peer-variable clearing and association…

Fix: 4.2.8 / 4.3.93+
Fix from $1,600 2016-07-05
Ntp HIGH 7.5
CVE-2016-4954EPSS 13%

The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-variable modi…

Fix: 4.2.8 / 4.3.93+
Fix from $1,950 2016-07-05
Ntp HIGH 7.5
CVE-2016-4953EPSS 17%

ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoofed crypt…

Fix: 4.2.8 / 4.3.93+
Fix from $1,950 2016-07-05
Ntp MEDIUM 5.0
CVE-2014-9296EPSS 16%

The receive function in ntp_proto.c in ntpd in NTP before 4.2.8 continues to execute after detecting a certain authentication error, which might allo…

Fix: after 4.2.7
Fix from $1,600 2014-12-20
Ntp HIGH 7.5
CVE-2014-9295EPSS 78%

Multiple stack-based buffer overflows in ntpd in NTP before 4.2.8 allow remote attackers to execute arbitrary code via a crafted packet, related to (…

Fix: after 4.2.7
Fix from $1,950 2014-12-20
Ntp HIGH 7.5
CVE-2014-9294EPSS 13%

util/ntp-keygen.c in ntp-keygen in NTP before 4.2.7p230 uses a weak RNG seed, which makes it easier for remote attackers to defeat cryptographic prot…

Fix: after 4.2.7
Fix from $1,950 2014-12-20
Ntp HIGH 7.5
CVE-2014-9293EPSS 13%

The config_auth function in ntpd in NTP before 4.2.7p11, when an auth key is not configured, improperly generates a key, which makes it easier for re…

Fix: after 4.2.7
Fix from $1,950 2014-12-20
Ntp MEDIUM 6.4
CVE-2009-3563EPSS 32%

ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by using…

Fix: after 4.2.2p4
Fix from $1,600 2009-12-09
Ntp MEDIUM 6.8
CVE-2009-1252EPSS 21%

Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSSL and aut…

Patch available
Fix from $1,600 2009-05-19
Ntp MEDIUM 6.8
CVE-2009-0159EPSS 13%

Stack-based buffer overflow in the cookedprint function in ntpq/ntpq.c in ntpq in NTP before 4.2.4p7-RC2 allows remote NTP servers to execute arbitra…

Fix: after 4.2.4p7
Fix from $1,600 2009-04-14
Ntp MEDIUM 5.0
CVE-2009-0021

NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows …

Fix: after 4.2.4p4
Fix from $1,600 2009-01-07
Ntp MEDIUM 5.0
CVE-2004-0657

Integer overflow in the NTP daemon (NTPd) before 4.0 causes the NTP server to return the wrong date/time offset when a client requests a date/time th…

Fix: 4.0+
Fix from $1,600 2004-08-06