Show filters
62 Total Results
Displaying 61-62 of 62
Sort by:
Attacker Value
Unknown

CVE-2014-9751

Disclosure Date: October 06, 2015 (last updated October 05, 2023)
The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 on Linux and OS X does not properly determine whether a source IP address is an IPv6 loopback address, which makes it easier for remote attackers to spoof restricted packets, and read or write to the runtime state, by leveraging the ability to reach the ntpd machine's network interface with a packet from the ::1 address.
0
Attacker Value
Unknown

CVE-2014-9750

Disclosure Date: October 06, 2015 (last updated October 05, 2023)
ntp_crypto.c in ntpd in NTP 4.x before 4.2.8p1, when Autokey Authentication is enabled, allows remote attackers to obtain sensitive information from process memory or cause a denial of service (daemon crash) via a packet containing an extension field with an invalid value for the length of its value field.
0