Vulnerability index

Browse CVEs

56 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ntp MEDIUM 6.4
CVE-2023-26555

praecis_parse in ntpd/refclock_palisade.c in NTP 4.2.8p15 has an out-of-bounds write. Any attack method would be complex, e.g., with a manipulated GP…

Mitigation only
Fix from $1,600 2023-04-11
Ntp MEDIUM 5.6
CVE-2023-26551

mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write in the cp<cpdec while loop. An adversary may be able to attack a client ntpq p…

Mitigation only
Fix from $1,600 2023-04-11
Ntp MEDIUM 5.6
CVE-2023-26552

mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when adding a decimal point. An adversary may be able to attack a client ntpq …

Mitigation only
Fix from $1,600 2023-04-11
Ntp MEDIUM 5.6
CVE-2023-26553

mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when copying the trailing number. An adversary may be able to attack a client …

Mitigation only
Fix from $1,600 2023-04-11
Ntp MEDIUM 5.6
CVE-2023-26554

mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when adding a '\0' character. An adversary may be able to attack a client ntpq…

Mitigation only
Fix from $1,600 2023-04-11
Ntp HIGH 7.4
CVE-2020-13817

ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit or system time change) by pred…

Fix: 4.2.8 / 4.3.100+
Fix from $1,950 2020-06-04
Ntp MEDIUM 5.3
CVE-2018-8956

ntpd in ntp 4.2.8p10, 4.2.8p11, 4.2.8p12 and 4.2.8p13 allow remote attackers to prevent a broadcast client from synchronizing its clock with a broadc…

Mitigation only
Fix from $1,600 2020-05-06
Ntp MEDIUM 6.5
CVE-2015-7851

Directory traversal vulnerability in the save_config function in ntpd in ntp_control.c in NTP before 4.2.8p4, when used on systems that do not use '\…

Fix: 4.2.8 / 4.3.77+
Fix from $1,600 2020-01-28
Ntp HIGH 8.1
CVE-2019-11331

Network Time Protocol (NTP), as specified in RFC 5905, uses port 123 even for modes where a fixed port number is not required, which makes it easier …

Mitigation only
Fix from $1,950 2019-04-18
Ntp CRITICAL 9.8
CVE-2018-12327EPSS 29%

Stack-based buffer overflow in ntpq and ntpdc of NTP version 4.2.8p11 allows an attacker to achieve code execution or escalate to higher privileges v…

No fix yet
Fix from $2,300 2018-06-20
Ntp MEDIUM 5.3
CVE-2018-7170

ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key to create arbitrarily-many ep…

Fix: 1.1.6-6931-3 / 2.2.3-1505+
Fix from $1,600 2018-03-06
Ntp CRITICAL 9.8
CVE-2015-7853EPSS 12%

The datalen parameter in the refclock driver in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to execute arbitrary code o…

Fix: 4.2.8 / 4.3.77+
Fix from $2,300 2017-08-07
Ntp HIGH 8.8
CVE-2015-7849EPSS 17%

Use-after-free vulnerability in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to possibly execute arbit…

Fix: 4.2.8 / 4.3.77+
Fix from $1,950 2017-08-07
Ntp HIGH 8.8
CVE-2015-7854EPSS 15%

Buffer overflow in the password management functionality in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to ca…

Fix: 4.2.8 / 4.3.77+
Fix from $1,950 2017-08-07
Ntp HIGH 8.8
CVE-2017-6458EPSS 7%

Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenticated users to have unspecifi…

Fix: 4.2.8 / 4.3.94+
Fix from $1,950 2017-03-27
Ntp HIGH 8.8
CVE-2017-6460

Stack-based buffer overflow in the reslist function in ntpq in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote servers have unspecified imp…

Patch available
Fix from $1,950 2017-03-27
Ntp HIGH 7.8
CVE-2017-6451

The mx4200_send function in the legacy MX4200 refclock in NTP before 4.2.8p10 and 4.3.x before 4.3.94 does not properly handle the return value of th…

Patch available
Fix from $1,950 2017-03-27
Ntp HIGH 7.8
CVE-2017-6452

Stack-based buffer overflow in the Windows installer for NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows local users to have unspecified impact vi…

Patch available
Fix from $1,950 2017-03-27
Ntp HIGH 7.8
CVE-2017-6462

Buffer overflow in the legacy Datum Programmable Time Server (DPTS) refclock driver in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows local users…

Patch available
Fix from $1,950 2017-03-27
Ntp HIGH 7.0
CVE-2017-6455

NTP before 4.2.8p10 and 4.3.x before 4.3.94, when using PPSAPI, allows local users to gain privileges via a DLL in the PPSAPI_DLLS environment variab…

Patch available
Fix from $1,950 2017-03-27
Ntp MEDIUM 6.5
CVE-2017-6463EPSS 5%

NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote authenticated users to cause a denial of service (daemon crash) via an invalid setting in a…

Mitigation only
Fix from $1,600 2017-03-27
Ntp MEDIUM 6.5
CVE-2017-6464EPSS 5%

NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote attackers to cause a denial of service (ntpd crash) via a malformed mode configuration dire…

Patch available
Fix from $1,600 2017-03-27
Ntp MEDIUM 5.5
CVE-2017-6459

The Windows installer for NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows local users to have unspecified impact via vectors related to an argumen…

Mitigation only
Fix from $1,600 2017-03-27
Ntp MEDIUM 5.9
CVE-2016-2519EPSS 7%

ntpd in NTP before 4.2.8p7 and 4.3.x before 4.3.92 allows remote attackers to cause a denial of service (ntpd abort) by a large request data value, w…

Fix: after 4.2.8
Fix from $1,600 2017-01-30
Ntp MEDIUM 5.3
CVE-2016-2516EPSS 9%

NTP before 4.2.8p7 and 4.3.x before 4.3.92, when mode7 is enabled, allows remote attackers to cause a denial of service (ntpd abort) by using the sam…

Fix: after 4.2.8
Fix from $1,600 2017-01-30
Ntp MEDIUM 5.3
CVE-2016-2517EPSS 9%

NTP before 4.2.8p7 and 4.3.x before 4.3.92 allows remote attackers to cause a denial of service (prevent subsequent authentication) by leveraging kno…

Fix: after 4.2.8
Fix from $1,600 2017-01-30
Ntp HIGH 7.5
CVE-2015-7978EPSS 10%

NTP before 4.2.8p6 and 4.3.0 before 4.3.90 allows a remote attackers to cause a denial of service (stack exhaustion) via an ntpdc relist command, whi…

Fix: after 4.2.8
Fix from $1,950 2017-01-30
Ntp HIGH 7.5
CVE-2015-7979EPSS 12%

NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (client-server association tear down) by sending broa…

Fix: after 4.2.8
Fix from $1,950 2017-01-30
Ntp MEDIUM 6.2
CVE-2015-7975

The nextvar function in NTP before 4.2.8p6 and 4.3.x before 4.3.90 does not properly validate the length of its input, which allows an attacker to ca…

Fix: after 4.2.8
Fix from $1,600 2017-01-30
Ntp MEDIUM 5.9
CVE-2015-8158EPSS 8%

The getresponse function in ntpq in NTP versions before 4.2.8p9 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (infinit…

Fix: after 4.2.8
Fix from $1,600 2017-01-30