Netapp

Oncommand Unified Manager

169 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 22.61%
  • Veröffentlicht 07.08.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" messages.

  • EPSS 25%
  • Veröffentlicht 07.08.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large number of crafted requests.

  • EPSS 4.25%
  • Veröffentlicht 07.08.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Use-after-free vulnerability in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to possibly execute arbitrary code or cause a denial of service (crash) via crafted packets.

  • EPSS 2.8%
  • Veröffentlicht 07.08.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to cause a denial of service (infinite loop or crash) by pointing the key file at the log file.

  • EPSS 3.54%
  • Veröffentlicht 07.08.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

ntpq in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted mode 6 response packets.

  • EPSS 20.96%
  • Veröffentlicht 07.08.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The datalen parameter in the refclock driver in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a negative input value.

  • EPSS 4.19%
  • Veröffentlicht 07.08.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Buffer overflow in the password management functionality in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted key file.

Exploit
  • EPSS 60.88%
  • Veröffentlicht 07.08.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (assertion failure) via a 6 or mode 7 packet containing a long data value.

  • EPSS 76.65%
  • Veröffentlicht 07.08.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication.

  • EPSS 8.41%
  • Veröffentlicht 27.07.2017 21:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and sent in response lines and headers. Accepting these different behaviors represented a security concern when httpd participates in...