Vulnerabilities > NTP > NTP

DATE CVE VULNERABILITY TITLE RISK
2017-01-30 CVE-2015-7976 7PK - Security Features vulnerability in multiple products
The ntpq saveconfig command in NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4.3.25, 4.3.70, and 4.3.77 does not properly filter special characters, which allows attackers to cause unspecified impact via a crafted filename.
network
low complexity
ntp suse novell opensuse CWE-254
4.0
2017-01-30 CVE-2015-7975 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in NTP
The nextvar function in NTP before 4.2.8p6 and 4.3.x before 4.3.90 does not properly validate the length of its input, which allows an attacker to cause a denial of service (application crash).
local
low complexity
ntp CWE-119
2.1
2017-01-30 CVE-2015-7973 7PK - Security Features vulnerability in multiple products
NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to conduct replay attacks by sniffing the network.
5.8
2017-01-27 CVE-2016-1551 7PK - Security Features vulnerability in multiple products
ntpd in NTP 4.2.8p3 and NTPsec a5fb34b9cc89b92a8fef2f459004865c93bb7f92 relies on the underlying operating system to protect it from requests that impersonate reference clocks.
network
high complexity
ntp ntpsec CWE-254
2.6
2017-01-13 CVE-2016-9312 Resource Management Errors vulnerability in NTP 4.2.4/4.2.7/4.2.8
ntpd in NTP before 4.2.8p9, when running on Windows, allows remote attackers to cause a denial of service via a large UDP packet.
network
low complexity
ntp microsoft CWE-399
5.0
2017-01-13 CVE-2016-9311 NULL Pointer Dereference vulnerability in NTP 4.2.4/4.2.7/4.2.8
ntpd in NTP before 4.2.8p9, when the trap service is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted packet.
network
ntp CWE-476
7.1
2017-01-13 CVE-2016-9310 Resource Exhaustion vulnerability in NTP 4.2.4/4.2.7/4.2.8
The control mode (mode 6) functionality in ntpd in NTP before 4.2.8p9 allows remote attackers to set or unset traps via a crafted control mode packet.
network
low complexity
ntp CWE-400
6.4
2017-01-13 CVE-2016-7434 Improper Input Validation vulnerability in NTP 4.2.8/4.2.7
The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query.
network
low complexity
ntp hpe CWE-20
4.3
2017-01-13 CVE-2016-7433 Incorrect Calculation vulnerability in NTP 4.2.4/4.2.7/4.2.8
NTP before 4.2.8p9 does not properly perform the initial sync calculations, which allows remote attackers to unspecified impact via unknown vectors, related to a "root distance that did not include the peer dispersion."
network
low complexity
ntp CWE-682
5.3
2017-01-13 CVE-2016-7431 Improper Input Validation vulnerability in NTP 4.2.8
NTP before 4.2.8p9 allows remote attackers to bypass the origin timestamp protection mechanism via an origin timestamp of zero.
network
low complexity
ntp CWE-20
5.0