CVE-2015-7853
- EPSS 20.96%
- Veröffentlicht 07.08.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The datalen parameter in the refclock driver in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a negative input value.
CVE-2015-7691
- EPSS 6.22%
- Veröffentlicht 07.08.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted packets containing particular autokey operations. NOTE: This vulnerability exists due to a...
CVE-2015-7692
- EPSS 6.32%
- Veröffentlicht 07.08.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash). NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.
CVE-2015-7701
- EPSS 7.8%
- Veröffentlicht 07.08.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Memory leak in the CRYPTO_ASSOC function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (memory consumption).
CVE-2015-7702
- EPSS 1.42%
- Veröffentlicht 07.08.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash). NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.
CVE-2015-7704
- EPSS 22.61%
- Veröffentlicht 07.08.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" messages.
CVE-2015-7705
- EPSS 25%
- Veröffentlicht 07.08.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large number of crafted requests.
CVE-2015-7849
- EPSS 4.25%
- Veröffentlicht 07.08.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Use-after-free vulnerability in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to possibly execute arbitrary code or cause a denial of service (crash) via crafted packets.
CVE-2015-7850
- EPSS 2.8%
- Veröffentlicht 07.08.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to cause a denial of service (infinite loop or crash) by pointing the key file at the log file.
CVE-2015-7852
- EPSS 3.54%
- Veröffentlicht 07.08.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
ntpq in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted mode 6 response packets.