CVE-2015-7849
- EPSS 4.25%
- Published 07.08.2017 20:29:00
- Last modified 20.04.2025 01:37:25
Use-after-free vulnerability in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to possibly execute arbitrary code or cause a denial of service (crash) via crafted packets.
CVE-2015-7850
- EPSS 2.8%
- Published 07.08.2017 20:29:00
- Last modified 20.04.2025 01:37:25
ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to cause a denial of service (infinite loop or crash) by pointing the key file at the log file.
CVE-2015-7852
- EPSS 3.54%
- Published 07.08.2017 20:29:00
- Last modified 20.04.2025 01:37:25
ntpq in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted mode 6 response packets.
CVE-2015-7853
- EPSS 20.96%
- Published 07.08.2017 20:29:00
- Last modified 20.04.2025 01:37:25
The datalen parameter in the refclock driver in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a negative input value.
CVE-2015-7854
- EPSS 4.19%
- Published 07.08.2017 20:29:00
- Last modified 20.04.2025 01:37:25
Buffer overflow in the password management functionality in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted key file.
CVE-2015-7871
- EPSS 76.65%
- Published 07.08.2017 20:29:00
- Last modified 20.04.2025 01:37:25
Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication.
CVE-2015-7703
- EPSS 4.95%
- Published 24.07.2017 14:29:00
- Last modified 20.04.2025 01:37:25
The "pidfile" or "driftfile" directives in NTP ntpd 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77, when ntpd is configured to allow remote configuration, allows remote attackers with an IP address that is allowed to send configuration requests, and w...
CVE-2016-9841
- EPSS 20.28%
- Published 23.05.2017 04:29:01
- Last modified 20.04.2025 01:37:25
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
CVE-2016-10165
- EPSS 0.87%
- Published 03.02.2017 19:59:00
- Last modified 20.04.2025 01:37:25
The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.
CVE-2016-2518
- EPSS 1.47%
- Published 30.01.2017 21:59:01
- Last modified 20.04.2025 01:37:25
The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode value.