CVE-2019-8936
- EPSS 8.16%
- Veröffentlicht 15.05.2019 16:29:01
- Zuletzt bearbeitet 21.11.2024 04:50:41
NTP through 4.2.8p12 has a NULL Pointer Dereference.
CVE-2016-9042
- EPSS 2.53%
- Veröffentlicht 04.06.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:00:29
An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate repl...
CVE-2018-7170
- EPSS 1.01%
- Veröffentlicht 06.03.2018 20:29:01
- Zuletzt bearbeitet 14.01.2025 19:29:55
ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key to create arbitrarily-many ephemeral associations in order to win the clock selection of ntpd and modify a victim's clock via a Sy...
CVE-2018-7185
- EPSS 16.93%
- Veröffentlicht 06.03.2018 20:29:01
- Zuletzt bearbeitet 14.01.2025 19:29:55
The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by continually sending a packet with a zero-origin timestamp and source IP address of the "other side" of an interleaved association ...
CVE-2017-6458
- EPSS 5.22%
- Veröffentlicht 27.03.2017 17:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenticated users to have unspecified impact via a long variable.
CVE-2016-7426
- EPSS 38.91%
- Veröffentlicht 13.01.2017 16:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers to cause a denial of service (prevent responses from the sources) by sending responses wit...
CVE-2016-7434
- EPSS 63.46%
- Veröffentlicht 13.01.2017 16:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query.