Show filters
210 Total Results
Displaying 71-80 of 210
Sort by:
Attacker Value
Unknown

CVE-2017-14651

Disclosure Date: September 21, 2017 (last updated November 26, 2024)
WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.
Attacker Value
Unknown

CVE-2015-3405

Disclosure Date: August 09, 2017 (last updated November 26, 2024)
ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when the lowest order byte of the temp variable is between 0x20 and 0x7f and not #, which might allow remote attackers to obtain the value of generated MD5 keys via a brute force attack with the 93 possible keys.
0
Attacker Value
Unknown

CVE-2015-7705

Disclosure Date: August 07, 2017 (last updated November 26, 2024)
The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large number of crafted requests.
Attacker Value
Unknown

CVE-2015-7704

Disclosure Date: August 07, 2017 (last updated November 26, 2024)
The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" messages.
Attacker Value
Unknown

CVE-2015-7852

Disclosure Date: August 07, 2017 (last updated November 26, 2024)
ntpq in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted mode 6 response packets.
Attacker Value
Unknown

CVE-2015-7701

Disclosure Date: August 07, 2017 (last updated November 26, 2024)
Memory leak in the CRYPTO_ASSOC function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (memory consumption).
Attacker Value
Unknown

CVE-2015-7692

Disclosure Date: August 07, 2017 (last updated November 26, 2024)
The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash). NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.
Attacker Value
Unknown

CVE-2015-7702

Disclosure Date: August 07, 2017 (last updated November 26, 2024)
The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash). NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.
Attacker Value
Unknown

CVE-2015-7691

Disclosure Date: August 07, 2017 (last updated November 26, 2024)
The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted packets containing particular autokey operations. NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.
Attacker Value
Unknown

CVE-2015-7703

Disclosure Date: July 24, 2017 (last updated November 26, 2024)
The "pidfile" or "driftfile" directives in NTP ntpd 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77, when ntpd is configured to allow remote configuration, allows remote attackers with an IP address that is allowed to send configuration requests, and with knowledge of the remote configuration password to write to arbitrary files via the :config command.