NTP kayıtları
ntp üreticisine ait 99 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 3 · %3
- Pre-auth RCE
- 5
- Düzeltme kaydı olan
- %94,9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation24
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer10
- CWE-787 Out-of-bounds Write8
- CWE-400 Uncontrolled Resource Consumption5
- CWE-287 Improper Authentication4
- CWE-476 NULL Pointer Dereference4
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
99 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
64Bu hafta | CVE-2015-7871Silahlaştırılmış | Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication.ntp · ntp · CWE-287 | Kritik9,8 | — | %81,8 | 7 Ağu 2017 |
54Planlayın | CVE-2014-9295Kavram kanıtı | Multiple stack-based buffer overflows in ntpd in NTP before 4.2.8 allow remote attackers to execute arbitrary code via a crafted packet, relntp · ntp · CWE-119 | Yüksek7,5 | — | %79,1 | 19 Ara 2014 |
49Planlayın | CVE-2013-5211Silahlaştırılmış | The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplificatntp · ntp · CWE-20 | Orta5,0 | — | %97,5 | 2 Oca 2014 |
47Planlayın | CVE-2018-12327Kavram kanıtı | Stack-based buffer overflow in ntpq and ntpdc of NTP version 4.2.8p11 allows an attacker to achieve code execution or escalate to higher printp · ntp · CWE-787 | Kritik9,8 | — | %28,0 | 20 Haz 2018 |
46Planlayın | CVE-2016-7434Kavram kanıtı | The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query.ntp · ntp · CWE-20 | Yüksek7,5 | — | %52,9 | 13 Oca 2017 |
43Planlayın | CVE-2016-4957İstismar yok | ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet.ntp · ntp · CWE-476 | Yüksek7,5 | — | %44,9 | 4 Tem 2016 |
43Planlayın | CVE-2015-7705İstismar yok | The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large nntp · ntp · CWE-20 | Kritik9,8 | — | %12,4 | 7 Ağu 2017 |
43Planlayın | CVE-2015-7853İstismar yok | The datalen parameter in the refclock driver in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to execute arbitrantp · ntp · CWE-120 | Kritik9,8 | — | %11,8 | 7 Ağu 2017 |
42Planlayın | CVE-2018-7183İstismar yok | Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arbitrary code by leverntp · ntp · CWE-787 | Kritik9,8 | — | %10,2 | 8 Mar 2018 |
40Planlayın | CVE-2015-7849İstismar yok | Use-after-free vulnerability in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to possibly execntp · ntp · CWE-416 | Yüksek8,8 | — | %16,8 | 7 Ağu 2017 |
39İzleyin | CVE-2016-9312İstismar yok | ntpd in NTP before 4.2.8p9, when running on Windows, allows remote attackers to cause a denial of service via a large UDP packet.ntp · ntp · CWE-399 | Yüksek7,5 | — | %31,2 | 13 Oca 2017 |
39İzleyin | CVE-2018-7182Kavram kanıtı | The ctl_getitem method in ntpd in ntp-4.2.8p6 before 4.2.8p11 allows remote attackers to cause a denial of service (out-of-bounds read) via ntp · ntp · CWE-125 | Yüksek7,5 | — | %28,8 | 6 Mar 2018 |
39İzleyin | CVE-2015-7854İstismar yok | Buffer overflow in the password management functionality in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated usntp · ntp · CWE-120 | Yüksek8,8 | — | %14,6 | 7 Ağu 2017 |
37İzleyin | CVE-2017-6458İstismar yok | Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenticated users to have ntp · ntp · CWE-119 | Yüksek8,8 | — | %6,5 | 27 Mar 2017 |
36İzleyin | CVE-2017-6460İstismar yok | Stack-based buffer overflow in the reslist function in ntpq in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote servers have unspecntp · ntp · CWE-119 | Yüksek8,8 | — | %2,7 | 27 Mar 2017 |
35İzleyin | CVE-2009-3563Silahlaştırılmış | ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and bandwidth consumption)ntp · ntp | Orta6,4 | — | %32,1 | 9 Ara 2009 |
35İzleyin | CVE-2015-7855Kavram kanıtı | The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service ntp · ntp · CWE-20 | Orta6,5 | — | %31,1 | 7 Ağu 2017 |
35İzleyin | CVE-2016-4953İstismar yok | ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoontp · ntp · CWE-287 | Yüksek7,5 | — | %17,2 | 4 Tem 2016 |
34İzleyin | CVE-2016-4954İstismar yok | The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-varintp · ntp · CWE-362 | Yüksek7,5 | — | %13,2 | 4 Tem 2016 |
34İzleyin | CVE-2014-9294İstismar yok | util/ntp-keygen.c in ntp-keygen in NTP before 4.2.7p230 uses a weak RNG seed, which makes it easier for remote attackers to defeat cryptograntp · ntp | Yüksek7,5 | — | %13,0 | 19 Ara 2014 |
34İzleyin | CVE-2014-9293İstismar yok | The config_auth function in ntpd in NTP before 4.2.7p11, when an auth key is not configured, improperly generates a key, which makes it easintp · ntp | Yüksek7,5 | — | %13,0 | 19 Ara 2014 |
34İzleyin | CVE-2016-7426İstismar yok | NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allontp · ntp · CWE-400 | Yüksek7,5 | — | %12,5 | 13 Oca 2017 |
34İzleyin | CVE-2015-7979İstismar yok | NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (client-server association tear down) by senntp · ntp · CWE-19 | Yüksek7,5 | — | %11,9 | 30 Oca 2017 |
33İzleyin | CVE-2009-1252İstismar yok | Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSSntp · ntp · CWE-119 | Orta6,8 | — | %21,3 | 19 May 2009 |
33İzleyin | CVE-2015-7704İstismar yok | The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of craftntp · ntp · CWE-20 | Yüksek7,5 | — | %11,0 | 7 Ağu 2017 |
- CVE-2015-787164Bu hafta
Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication.
KritikCVSS 9,8SilahlaştırılmışEPSS %82ntp · ntp7 Ağu 2017
- CVE-2014-929554Planlayın
Multiple stack-based buffer overflows in ntpd in NTP before 4.2.8 allow remote attackers to execute arbitrary code via a crafted packet, rel
YüksekCVSS 7,5Kavram kanıtıEPSS %79ntp · ntp19 Ara 2014
- CVE-2013-521149Planlayın
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplificat
OrtaCVSS 5,0SilahlaştırılmışEPSS %98ntp · ntp2 Oca 2014
- CVE-2018-1232747Planlayın
Stack-based buffer overflow in ntpq and ntpdc of NTP version 4.2.8p11 allows an attacker to achieve code execution or escalate to higher pri
KritikCVSS 9,8Kavram kanıtıEPSS %28ntp · ntp20 Haz 2018
- CVE-2016-743446Planlayın
The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query.
YüksekCVSS 7,5Kavram kanıtıEPSS %53ntp · ntp13 Oca 2017
- CVE-2016-495743Planlayın
ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet.
YüksekCVSS 7,5İstismar yokEPSS %45ntp · ntp4 Tem 2016
- CVE-2015-770543Planlayın
The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large n
KritikCVSS 9,8İstismar yokEPSS %12ntp · ntp7 Ağu 2017
- CVE-2015-785343Planlayın
The datalen parameter in the refclock driver in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to execute arbitra
KritikCVSS 9,8İstismar yokEPSS %12ntp · ntp7 Ağu 2017
- CVE-2018-718342Planlayın
Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arbitrary code by lever
KritikCVSS 9,8İstismar yokEPSS %10ntp · ntp8 Mar 2018
- CVE-2015-784940Planlayın
Use-after-free vulnerability in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to possibly exec
YüksekCVSS 8,8İstismar yokEPSS %17ntp · ntp7 Ağu 2017
- CVE-2016-931239İzleyin
ntpd in NTP before 4.2.8p9, when running on Windows, allows remote attackers to cause a denial of service via a large UDP packet.
YüksekCVSS 7,5İstismar yokEPSS %31ntp · ntp13 Oca 2017
- CVE-2018-718239İzleyin
The ctl_getitem method in ntpd in ntp-4.2.8p6 before 4.2.8p11 allows remote attackers to cause a denial of service (out-of-bounds read) via
YüksekCVSS 7,5Kavram kanıtıEPSS %29ntp · ntp6 Mar 2018
- CVE-2015-785439İzleyin
Buffer overflow in the password management functionality in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated us
YüksekCVSS 8,8İstismar yokEPSS %15ntp · ntp7 Ağu 2017
- CVE-2017-645837İzleyin
Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenticated users to have
YüksekCVSS 8,8İstismar yokEPSS %7ntp · ntp27 Mar 2017
- CVE-2017-646036İzleyin
Stack-based buffer overflow in the reslist function in ntpq in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote servers have unspec
YüksekCVSS 8,8İstismar yokEPSS %3ntp · ntp27 Mar 2017
- CVE-2009-356335İzleyin
ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and bandwidth consumption)
OrtaCVSS 6,4SilahlaştırılmışEPSS %32ntp · ntp9 Ara 2009
- CVE-2015-785535İzleyin
The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service
OrtaCVSS 6,5Kavram kanıtıEPSS %31ntp · ntp7 Ağu 2017
- CVE-2016-495335İzleyin
ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoo
YüksekCVSS 7,5İstismar yokEPSS %17ntp · ntp4 Tem 2016
- CVE-2016-495434İzleyin
The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-vari
YüksekCVSS 7,5İstismar yokEPSS %13ntp · ntp4 Tem 2016
- CVE-2014-929434İzleyin
util/ntp-keygen.c in ntp-keygen in NTP before 4.2.7p230 uses a weak RNG seed, which makes it easier for remote attackers to defeat cryptogra
YüksekCVSS 7,5İstismar yokEPSS %13ntp · ntp19 Ara 2014
- CVE-2014-929334İzleyin
The config_auth function in ntpd in NTP before 4.2.7p11, when an auth key is not configured, improperly generates a key, which makes it easi
YüksekCVSS 7,5İstismar yokEPSS %13ntp · ntp19 Ara 2014
- CVE-2016-742634İzleyin
NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allo
YüksekCVSS 7,5İstismar yokEPSS %12ntp · ntp13 Oca 2017
- CVE-2015-797934İzleyin
NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (client-server association tear down) by sen
YüksekCVSS 7,5İstismar yokEPSS %12ntp · ntp30 Oca 2017
- CVE-2009-125233İzleyin
Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSS
OrtaCVSS 6,8İstismar yokEPSS %21ntp · ntp19 May 2009
- CVE-2015-770433İzleyin
The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of craft
YüksekCVSS 7,5İstismar yokEPSS %11ntp · ntp7 Ağu 2017