Show filters
62 Total Results
Displaying 31-40 of 62
Sort by:
Attacker Value
Unknown

CVE-2015-7702

Disclosure Date: August 07, 2017 (last updated November 26, 2024)
The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash). NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.
Attacker Value
Unknown

CVE-2015-7691

Disclosure Date: August 07, 2017 (last updated November 26, 2024)
The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted packets containing particular autokey operations. NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.
Attacker Value
Unknown

CVE-2015-7703

Disclosure Date: July 24, 2017 (last updated November 26, 2024)
The "pidfile" or "driftfile" directives in NTP ntpd 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77, when ntpd is configured to allow remote configuration, allows remote attackers with an IP address that is allowed to send configuration requests, and with knowledge of the remote configuration password to write to arbitrary files via the :config command.
Attacker Value
Unknown

CVE-2017-6462

Disclosure Date: March 27, 2017 (last updated November 26, 2024)
Buffer overflow in the legacy Datum Programmable Time Server (DPTS) refclock driver in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows local users to have unspecified impact via a crafted /dev/datum device.
0
Attacker Value
Unknown

CVE-2017-6459

Disclosure Date: March 27, 2017 (last updated November 26, 2024)
The Windows installer for NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows local users to have unspecified impact via vectors related to an argument with multiple null bytes.
0
Attacker Value
Unknown

CVE-2017-6451

Disclosure Date: March 27, 2017 (last updated November 26, 2024)
The mx4200_send function in the legacy MX4200 refclock in NTP before 4.2.8p10 and 4.3.x before 4.3.94 does not properly handle the return value of the snprintf function, which allows local users to execute arbitrary code via unspecified vectors, which trigger an out-of-bounds memory write.
0
Attacker Value
Unknown

CVE-2017-6458

Disclosure Date: March 27, 2017 (last updated November 08, 2023)
Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenticated users to have unspecified impact via a long variable.
Attacker Value
Unknown

CVE-2017-6460

Disclosure Date: March 27, 2017 (last updated November 26, 2024)
Stack-based buffer overflow in the reslist function in ntpq in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote servers have unspecified impact via a long flagstr variable in a restriction list response.
0
Attacker Value
Unknown

CVE-2017-6455

Disclosure Date: March 27, 2017 (last updated November 26, 2024)
NTP before 4.2.8p10 and 4.3.x before 4.3.94, when using PPSAPI, allows local users to gain privileges via a DLL in the PPSAPI_DLLS environment variable.
0
Attacker Value
Unknown

CVE-2017-6464

Disclosure Date: March 27, 2017 (last updated November 26, 2024)
NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote attackers to cause a denial of service (ntpd crash) via a malformed mode configuration directive.
0