CVE-2016-4957
- EPSS 59.07%
- Veröffentlicht 05.07.2016 01:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-1547.
CVE-2016-4956
- EPSS 1.4%
- Veröffentlicht 05.07.2016 01:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (interleaved-mode transition and time change) via a spoofed broadcast packet. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-1548.
CVE-2016-4955
- EPSS 1.73%
- Veröffentlicht 05.07.2016 01:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
ntpd in NTP 4.x before 4.2.8p8, when autokey is enabled, allows remote attackers to cause a denial of service (peer-variable clearing and association outage) by sending (1) a spoofed crypto-NAK packet or (2) a packet with an incorrect MAC value at a ...
CVE-2016-4954
- EPSS 5.47%
- Veröffentlicht 05.07.2016 01:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-variable modification) by sending spoofed packets from many source IP addresses in a certain scenario, as demonstr...
CVE-2016-4953
- EPSS 13.62%
- Veröffentlicht 05.07.2016 01:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoofed crypto-NAK packet with incorrect authentication data at a certain time.
CVE-2016-5244
- EPSS 0.56%
- Veröffentlicht 27.06.2016 10:59:11
- Zuletzt bearbeitet 06.05.2026 22:30:45
The rds_inc_info_copy function in net/rds/recv.c in the Linux kernel through 4.6.3 does not initialize a certain structure member, which allows remote attackers to obtain sensitive information from kernel stack memory by reading an RDS message.
- EPSS 44.17%
- Veröffentlicht 16.06.2016 14:59:51
- Zuletzt bearbeitet 21.04.2026 21:07:11
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.
CVE-2016-4156
- EPSS 4.97%
- Veröffentlicht 16.06.2016 14:59:38
- Zuletzt bearbeitet 06.05.2026 22:30:45
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs...
CVE-2016-4155
- EPSS 4.25%
- Veröffentlicht 16.06.2016 14:59:37
- Zuletzt bearbeitet 06.05.2026 22:30:45
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs...
CVE-2016-4154
- EPSS 4.25%
- Veröffentlicht 16.06.2016 14:59:36
- Zuletzt bearbeitet 06.05.2026 22:30:45
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs...