Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)5.7%—Netapp Clustered Data OntapNetapp Data OntapFedoraproject FedoraOpensuse Leap+215/5/201917/6/2026
NTP through 4.2.8p12 has a NULL Pointer Dereference.
ModificadaMedia (5.9)3.9%—NTPFreebsdHPE Hpux-ntpSiemens Simatic NET CP 443-1 OPC UA Firmware4/6/201817/6/2026
An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2)…
ModificadaAlta (7.5)9.0%—NTPSynology Router ManagerSynology SkynasSynology Virtual Diskstation Manager+126/3/201817/6/2026
The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by continually sending a packet with a zero-origin timestamp and source IP address of the "other side" of an interleaved association causing the victim ntpd to reset its association.
ModificadaMedia (5.3)2.7%—NTPSynology Router ManagerSynology SkynasSynology Virtual Diskstation Manager+56/3/201817/6/2026
ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key to create arbitrarily-many ephemeral associations in order to win the clock selection of ntpd and modify a victim's clock via a Sybil attack. This issue exists because of an incomplete fix for…
ModificadaAlta (8.8)6.5%—NTPHPE Hpux-ntpApple MAC OS XSiemens Simatic NET CP 443-1 OPC UA Firmware27/3/201717/6/2026
Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenticated users to have unspecified impact via a long variable.
ModificadaAlta (7.5)53%—NTPHPE Hpux-ntp13/1/201717/6/2026
The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query.
ModificadaAlta (7.5)12%—NTPCanonical Ubuntu LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+513/1/201717/6/2026
NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers to cause a denial of service (prevent responses from the sources) by sending responses with a spoofed source address.
ModificadaBaja (1.9)0.64%—FreebsdHpuxFedoraproject FedoraSendmail4/6/201417/6/2026
The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows local users to access unintended high-numbered file descriptors via a custom mail-delivery program.
ModificadaMedia (4.9)0.53%—Hpux12/8/200916/6/2026
Unspecified vulnerability in HP-UX B.11.31 allows local users to cause a denial of service (system crash) via unknown vectors related to the ttrace system call.