Vulnerabilities (CVE)

Vendor filter

Ntp Subscribe

Product filter

Ntp Subscribe

Filter

87 total CVE
CVE Vendors Products Updated CVSS
CVE-2018-7170 4 Ntp, Synology, Slackware and 1 more 9 Ntp, Diskstation Manager, Router Manager and 6 more 2019-06-11 3.5
ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key to create arbitrarily-many ephemeral associations in order to win the clock selection of ntpd and modify a victim's clock via...
CVE-2019-8936 5 Netapp, Ntp, Fedoraproject and 2 more 5 Data Ontap Operating In 7-mode, Ntp, Fedora and 2 more 2019-05-31 5.0
NTP through 4.2.8p12 has a NULL Pointer Dereference.
CVE-2019-11331 1 Ntp 1 Ntp 2019-05-10 6.8
Network Time Protocol (NTP), as specified in RFC 5905, uses port 123 even for modes where a fixed port number is not required, which makes it easier for remote attackers to conduct off-path attacks.
CVE-2018-12327 1 Ntp 1 Ntp 2019-03-21 7.5
Stack-based buffer overflow in ntpq and ntpdc of NTP version 4.2.8p11 allows an attacker to achieve code execution or escalate to higher privileges via a long string as the argument for an IPv4 or IPv6 command-line parameter. NOTE: It is unclear...
CVE-2018-7182 3 Ntp, Netapp, Canonical 3 Ntp, Element Software, Ubuntu Linux 2019-03-01 5.0
The ctl_getitem method in ntpd in ntp-4.2.8p6 before 4.2.8p11 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mode 6 packet with a ntpd instance from 4.2.8p6 through 4.2.8p10.
CVE-2018-7185 5 Ntp, Synology, Slackware and 2 more 9 Ntp, Diskstation Manager, Router Manager and 6 more 2019-02-28 5.0
The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by continually sending a packet with a zero-origin timestamp and source IP address of the "other side" of an interleaved...
CVE-2018-7183 4 Ntp, Freebsd, Netapp and 1 more 4 Ntp, Freebsd, Element Software and 1 more 2019-02-28 7.5
Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arbitrary code by leveraging an ntpq query and sending a response with a crafted array.
CVE-2018-7184 5 Ntp, Synology, Slackware and 2 more 10 Ntp, Diskstation Manager, Router Manager and 7 more 2019-02-28 5.0
ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, which allows remote attackers to cause a denial of service (disruption) by sending a packet with a zero-origin timestamp causing the association to...
CVE-2017-6463 1 Ntp 1 Ntp 2019-01-24 4.0
NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote authenticated users to cause a denial of service (daemon crash) via an invalid setting in a :config directive, related to the unpeer option.
CVE-2017-6462 1 Ntp 1 Ntp 2019-01-24 4.6
Buffer overflow in the legacy Datum Programmable Time Server (DPTS) refclock driver in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows local users to have unspecified impact via a crafted /dev/datum device.
CVE-2016-9311 1 Ntp 1 Ntp 2019-01-24 7.1
ntpd in NTP before 4.2.8p9, when the trap service is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted packet.
CVE-2016-9310 1 Ntp 1 Ntp 2019-01-24 6.4
The control mode (mode 6) functionality in ntpd in NTP before 4.2.8p9 allows remote attackers to set or unset traps via a crafted control mode packet.
CVE-2016-7428 1 Ntp 1 Ntp 2019-01-24 3.3
ntpd in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (reject broadcast mode packets) via the poll interval in a broadcast packet.
CVE-2016-7427 1 Ntp 1 Ntp 2019-01-24 3.3
The broadcast mode replay prevention functionality in ntpd in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (reject broadcast mode packets) via a crafted broadcast mode packet.
CVE-2016-7426 1 Ntp 1 Ntp 2019-01-24 4.3
NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers to cause a denial of service (prevent responses from the sources) by sending responses...
CVE-2014-9295 1 Ntp 1 Ntp 2018-11-30 7.5
Multiple stack-based buffer overflows in ntpd in NTP before 4.2.8 allow remote attackers to execute arbitrary code via a crafted packet, related to (1) the crypto_recv function when the Autokey Authentication feature is used, (2) the ctl_putdata...
CVE-2016-7431 1 Ntp 1 Ntp 2018-11-08 5.0
NTP before 4.2.8p9 allows remote attackers to bypass the origin timestamp protection mechanism via an origin timestamp of zero. NOTE: this vulnerability exists because of a CVE-2015-8138 regression.
CVE-2015-7976 4 Suse, Ntp, Novell and 1 more 12 Leap, Linux Enterprise Desktop, Manager and 9 more 2018-10-30 4.0
The ntpq saveconfig command in NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4.3.25, 4.3.70, and 4.3.77 does not properly filter special characters, which allows attackers to cause unspecified impact via a crafted filename.
CVE-2015-5300 9 Fedoraproject, Redhat, Canonical and 6 more 22 Fedora, Enterprise Linux Hpc Node Eus, Enterprise Linux Server and 19 more 2018-10-30 5.0
The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time when started with the -g...
CVE-2016-4955 4 Ntp, Oracle, Novell and 1 more 12 Leap, Suse Manager, Suse Linux Enterprise Desktop and 9 more 2018-10-30 2.6
ntpd in NTP 4.x before 4.2.8p8, when autokey is enabled, allows remote attackers to cause a denial of service (peer-variable clearing and association outage) by sending (1) a spoofed crypto-NAK packet or (2) a packet with an incorrect MAC value...