CVE-2016-9042
- EPSS 2.53%
- Published 04.06.2018 20:29:00
- Last modified 21.11.2024 03:00:29
An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate repl...
CVE-2017-6458
- EPSS 5.22%
- Published 27.03.2017 17:59:00
- Last modified 20.04.2025 01:37:25
Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenticated users to have unspecified impact via a long variable.
CVE-2016-2518
- EPSS 1.47%
- Published 30.01.2017 21:59:01
- Last modified 20.04.2025 01:37:25
The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode value.
CVE-2016-4956
- EPSS 2.28%
- Published 05.07.2016 01:59:03
- Last modified 12.04.2025 10:46:40
ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (interleaved-mode transition and time change) via a spoofed broadcast packet. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-1548.
CVE-2016-4955
- EPSS 5.19%
- Published 05.07.2016 01:59:02
- Last modified 12.04.2025 10:46:40
ntpd in NTP 4.x before 4.2.8p8, when autokey is enabled, allows remote attackers to cause a denial of service (peer-variable clearing and association outage) by sending (1) a spoofed crypto-NAK packet or (2) a packet with an incorrect MAC value at a ...
CVE-2016-4954
- EPSS 2.18%
- Published 05.07.2016 01:59:01
- Last modified 12.04.2025 10:46:40
The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-variable modification) by sending spoofed packets from many source IP addresses in a certain scenario, as demonstr...
CVE-2016-4953
- EPSS 12.64%
- Published 05.07.2016 01:59:00
- Last modified 12.04.2025 10:46:40
ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoofed crypto-NAK packet with incorrect authentication data at a certain time.