Записи NTP
99 опубликованных записей вендора ntp.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 3 · 3 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 94,9 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-20 Improper Input Validation24
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer10
- CWE-787 Out-of-bounds Write8
- CWE-400 Uncontrolled Resource Consumption5
- CWE-287 Improper Authentication4
- CWE-476 NULL Pointer Dereference4
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
99 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
64На этой неделе | CVE-2015-7871Готовый эксплойт | Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication.ntp · ntp · CWE-287 | Критическая9,8 | — | 81,8 % | 7 авг. 2017 г. |
54В плане | CVE-2014-9295Proof of concept | Multiple stack-based buffer overflows in ntpd in NTP before 4.2.8 allow remote attackers to execute arbitrary code via a crafted packet, relntp · ntp · CWE-119 | Высокая7,5 | — | 79,1 % | 19 дек. 2014 г. |
49В плане | CVE-2013-5211Готовый эксплойт | The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplificatntp · ntp · CWE-20 | Средняя5,0 | — | 97,5 % | 2 янв. 2014 г. |
47В плане | CVE-2018-12327Proof of concept | Stack-based buffer overflow in ntpq and ntpdc of NTP version 4.2.8p11 allows an attacker to achieve code execution or escalate to higher printp · ntp · CWE-787 | Критическая9,8 | — | 28,0 % | 20 июн. 2018 г. |
46В плане | CVE-2016-7434Proof of concept | The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query.ntp · ntp · CWE-20 | Высокая7,5 | — | 52,9 % | 13 янв. 2017 г. |
43В плане | CVE-2016-4957Эксплойта нет | ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet.ntp · ntp · CWE-476 | Высокая7,5 | — | 44,9 % | 4 июл. 2016 г. |
43В плане | CVE-2015-7705Эксплойта нет | The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large nntp · ntp · CWE-20 | Критическая9,8 | — | 12,4 % | 7 авг. 2017 г. |
43В плане | CVE-2015-7853Эксплойта нет | The datalen parameter in the refclock driver in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to execute arbitrantp · ntp · CWE-120 | Критическая9,8 | — | 11,8 % | 7 авг. 2017 г. |
42В плане | CVE-2018-7183Эксплойта нет | Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arbitrary code by leverntp · ntp · CWE-787 | Критическая9,8 | — | 10,2 % | 8 мар. 2018 г. |
40В плане | CVE-2015-7849Эксплойта нет | Use-after-free vulnerability in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to possibly execntp · ntp · CWE-416 | Высокая8,8 | — | 16,8 % | 7 авг. 2017 г. |
39Наблюдать | CVE-2016-9312Эксплойта нет | ntpd in NTP before 4.2.8p9, when running on Windows, allows remote attackers to cause a denial of service via a large UDP packet.ntp · ntp · CWE-399 | Высокая7,5 | — | 31,2 % | 13 янв. 2017 г. |
39Наблюдать | CVE-2018-7182Proof of concept | The ctl_getitem method in ntpd in ntp-4.2.8p6 before 4.2.8p11 allows remote attackers to cause a denial of service (out-of-bounds read) via ntp · ntp · CWE-125 | Высокая7,5 | — | 28,8 % | 6 мар. 2018 г. |
39Наблюдать | CVE-2015-7854Эксплойта нет | Buffer overflow in the password management functionality in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated usntp · ntp · CWE-120 | Высокая8,8 | — | 14,6 % | 7 авг. 2017 г. |
37Наблюдать | CVE-2017-6458Эксплойта нет | Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenticated users to have ntp · ntp · CWE-119 | Высокая8,8 | — | 6,5 % | 27 мар. 2017 г. |
36Наблюдать | CVE-2017-6460Эксплойта нет | Stack-based buffer overflow in the reslist function in ntpq in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote servers have unspecntp · ntp · CWE-119 | Высокая8,8 | — | 2,7 % | 27 мар. 2017 г. |
35Наблюдать | CVE-2009-3563Готовый эксплойт | ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and bandwidth consumption)ntp · ntp | Средняя6,4 | — | 32,1 % | 9 дек. 2009 г. |
35Наблюдать | CVE-2015-7855Proof of concept | The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service ntp · ntp · CWE-20 | Средняя6,5 | — | 31,1 % | 7 авг. 2017 г. |
35Наблюдать | CVE-2016-4953Эксплойта нет | ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoontp · ntp · CWE-287 | Высокая7,5 | — | 17,2 % | 4 июл. 2016 г. |
34Наблюдать | CVE-2016-4954Эксплойта нет | The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-varintp · ntp · CWE-362 | Высокая7,5 | — | 13,2 % | 4 июл. 2016 г. |
34Наблюдать | CVE-2014-9294Эксплойта нет | util/ntp-keygen.c in ntp-keygen in NTP before 4.2.7p230 uses a weak RNG seed, which makes it easier for remote attackers to defeat cryptograntp · ntp | Высокая7,5 | — | 13,0 % | 19 дек. 2014 г. |
34Наблюдать | CVE-2014-9293Эксплойта нет | The config_auth function in ntpd in NTP before 4.2.7p11, when an auth key is not configured, improperly generates a key, which makes it easintp · ntp | Высокая7,5 | — | 13,0 % | 19 дек. 2014 г. |
34Наблюдать | CVE-2016-7426Эксплойта нет | NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allontp · ntp · CWE-400 | Высокая7,5 | — | 12,5 % | 13 янв. 2017 г. |
34Наблюдать | CVE-2015-7979Эксплойта нет | NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (client-server association tear down) by senntp · ntp · CWE-19 | Высокая7,5 | — | 11,9 % | 30 янв. 2017 г. |
33Наблюдать | CVE-2009-1252Эксплойта нет | Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSSntp · ntp · CWE-119 | Средняя6,8 | — | 21,3 % | 19 мая 2009 г. |
33Наблюдать | CVE-2015-7704Эксплойта нет | The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of craftntp · ntp · CWE-20 | Высокая7,5 | — | 11,0 % | 7 авг. 2017 г. |
- CVE-2015-787164На этой неделе
Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication.
КритическаяCVSS 9,8Готовый эксплойтEPSS 82 %ntp · ntp7 авг. 2017 г.
- CVE-2014-929554В плане
Multiple stack-based buffer overflows in ntpd in NTP before 4.2.8 allow remote attackers to execute arbitrary code via a crafted packet, rel
ВысокаяCVSS 7,5Proof of conceptEPSS 79 %ntp · ntp19 дек. 2014 г.
- CVE-2013-521149В плане
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplificat
СредняяCVSS 5,0Готовый эксплойтEPSS 98 %ntp · ntp2 янв. 2014 г.
- CVE-2018-1232747В плане
Stack-based buffer overflow in ntpq and ntpdc of NTP version 4.2.8p11 allows an attacker to achieve code execution or escalate to higher pri
КритическаяCVSS 9,8Proof of conceptEPSS 28 %ntp · ntp20 июн. 2018 г.
- CVE-2016-743446В плане
The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query.
ВысокаяCVSS 7,5Proof of conceptEPSS 53 %ntp · ntp13 янв. 2017 г.
- CVE-2016-495743В плане
ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet.
ВысокаяCVSS 7,5Эксплойта нетEPSS 45 %ntp · ntp4 июл. 2016 г.
- CVE-2015-770543В плане
The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large n
КритическаяCVSS 9,8Эксплойта нетEPSS 12 %ntp · ntp7 авг. 2017 г.
- CVE-2015-785343В плане
The datalen parameter in the refclock driver in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to execute arbitra
КритическаяCVSS 9,8Эксплойта нетEPSS 12 %ntp · ntp7 авг. 2017 г.
- CVE-2018-718342В плане
Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arbitrary code by lever
КритическаяCVSS 9,8Эксплойта нетEPSS 10 %ntp · ntp8 мар. 2018 г.
- CVE-2015-784940В плане
Use-after-free vulnerability in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to possibly exec
ВысокаяCVSS 8,8Эксплойта нетEPSS 17 %ntp · ntp7 авг. 2017 г.
- CVE-2016-931239Наблюдать
ntpd in NTP before 4.2.8p9, when running on Windows, allows remote attackers to cause a denial of service via a large UDP packet.
ВысокаяCVSS 7,5Эксплойта нетEPSS 31 %ntp · ntp13 янв. 2017 г.
- CVE-2018-718239Наблюдать
The ctl_getitem method in ntpd in ntp-4.2.8p6 before 4.2.8p11 allows remote attackers to cause a denial of service (out-of-bounds read) via
ВысокаяCVSS 7,5Proof of conceptEPSS 29 %ntp · ntp6 мар. 2018 г.
- CVE-2015-785439Наблюдать
Buffer overflow in the password management functionality in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated us
ВысокаяCVSS 8,8Эксплойта нетEPSS 15 %ntp · ntp7 авг. 2017 г.
- CVE-2017-645837Наблюдать
Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenticated users to have
ВысокаяCVSS 8,8Эксплойта нетEPSS 7 %ntp · ntp27 мар. 2017 г.
- CVE-2017-646036Наблюдать
Stack-based buffer overflow in the reslist function in ntpq in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote servers have unspec
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %ntp · ntp27 мар. 2017 г.
- CVE-2009-356335Наблюдать
ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and bandwidth consumption)
СредняяCVSS 6,4Готовый эксплойтEPSS 32 %ntp · ntp9 дек. 2009 г.
- CVE-2015-785535Наблюдать
The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service
СредняяCVSS 6,5Proof of conceptEPSS 31 %ntp · ntp7 авг. 2017 г.
- CVE-2016-495335Наблюдать
ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoo
ВысокаяCVSS 7,5Эксплойта нетEPSS 17 %ntp · ntp4 июл. 2016 г.
- CVE-2016-495434Наблюдать
The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-vari
ВысокаяCVSS 7,5Эксплойта нетEPSS 13 %ntp · ntp4 июл. 2016 г.
- CVE-2014-929434Наблюдать
util/ntp-keygen.c in ntp-keygen in NTP before 4.2.7p230 uses a weak RNG seed, which makes it easier for remote attackers to defeat cryptogra
ВысокаяCVSS 7,5Эксплойта нетEPSS 13 %ntp · ntp19 дек. 2014 г.
- CVE-2014-929334Наблюдать
The config_auth function in ntpd in NTP before 4.2.7p11, when an auth key is not configured, improperly generates a key, which makes it easi
ВысокаяCVSS 7,5Эксплойта нетEPSS 13 %ntp · ntp19 дек. 2014 г.
- CVE-2016-742634Наблюдать
NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allo
ВысокаяCVSS 7,5Эксплойта нетEPSS 12 %ntp · ntp13 янв. 2017 г.
- CVE-2015-797934Наблюдать
NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (client-server association tear down) by sen
ВысокаяCVSS 7,5Эксплойта нетEPSS 12 %ntp · ntp30 янв. 2017 г.
- CVE-2009-125233Наблюдать
Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSS
СредняяCVSS 6,8Эксплойта нетEPSS 21 %ntp · ntp19 мая 2009 г.
- CVE-2015-770433Наблюдать
The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of craft
ВысокаяCVSS 7,5Эксплойта нетEPSS 11 %ntp · ntp7 авг. 2017 г.