Vulnerability index

Browse CVEs

14 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Ntp MEDIUM 6.4
CVE-2023-26555

praecis_parse in ntpd/refclock_palisade.c in NTP 4.2.8p15 has an out-of-bounds write. Any attack method would be complex, e.g., with a manipulated GP…

Mitigation only
Fix from $1,600 2023-04-11
Ntp MEDIUM 5.6
CVE-2023-26551

mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write in the cp<cpdec while loop. An adversary may be able to attack a client ntpq p…

Mitigation only
Fix from $1,600 2023-04-11
Ntp MEDIUM 5.6
CVE-2023-26552

mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when adding a decimal point. An adversary may be able to attack a client ntpq …

Mitigation only
Fix from $1,600 2023-04-11
Ntp MEDIUM 5.6
CVE-2023-26553

mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when copying the trailing number. An adversary may be able to attack a client …

Mitigation only
Fix from $1,600 2023-04-11
Ntp MEDIUM 5.6
CVE-2023-26554

mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when adding a '\0' character. An adversary may be able to attack a client ntpq…

Mitigation only
Fix from $1,600 2023-04-11
Ntp MEDIUM 5.3
CVE-2018-8956

ntpd in ntp 4.2.8p10, 4.2.8p11, 4.2.8p12 and 4.2.8p13 allow remote attackers to prevent a broadcast client from synchronizing its clock with a broadc…

Mitigation only
Fix from $1,600 2020-05-06
Ntp HIGH 8.1
CVE-2019-11331

Network Time Protocol (NTP), as specified in RFC 5905, uses port 123 even for modes where a fixed port number is not required, which makes it easier …

Mitigation only
Fix from $1,950 2019-04-18
Ntp CRITICAL 9.8
CVE-2018-12327EPSS 29%

Stack-based buffer overflow in ntpq and ntpdc of NTP version 4.2.8p11 allows an attacker to achieve code execution or escalate to higher privileges v…

No fix yet
Fix from $2,300 2018-06-20
Ntp MEDIUM 6.5
CVE-2017-6463EPSS 5%

NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote authenticated users to cause a denial of service (daemon crash) via an invalid setting in a…

Mitigation only
Fix from $1,600 2017-03-27
Ntp MEDIUM 5.5
CVE-2017-6459

The Windows installer for NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows local users to have unspecified impact via vectors related to an argumen…

Mitigation only
Fix from $1,600 2017-03-27
Ntp MEDIUM 5.3
CVE-2016-7431EPSS 9%

NTP before 4.2.8p9 allows remote attackers to bypass the origin timestamp protection mechanism via an origin timestamp of zero. NOTE: this vulnerabi…

No fix yet
Fix from $1,600 2017-01-13
Ntp HIGH 7.2
CVE-2016-1548

An attacker can spoof a packet from a legitimate ntpd server with an origin timestamp that matches the peer->dst timestamp recorded for that server. …

No fix yet
Fix from $1,950 2017-01-06
Ntp MEDIUM 6.5
CVE-2016-1549

A malicious authenticated peer can create arbitrarily-many ephemeral associations in order to win the clock selection algorithm in ntpd in NTP 4.2.8p…

Mitigation only
Fix from $1,600 2017-01-06
Ntp MEDIUM 5.3
CVE-2016-1550

An exploitable vulnerability exists in the message authentication functionality of libntp in ntp 4.2.8p4 and NTPSec a5fb34b9cc89b92a8fef2f459004865c9…

No fix yet
Fix from $1,600 2017-01-06