Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 5.7% | — | Netapp Clustered Data OntapNetapp Data OntapFedoraproject FedoraOpensuse Leap+2 | 15/5/2019 | 17/6/2026 | NTP through 4.2.8p12 has a NULL Pointer Dereference. | |
| Modificada | Media (5.9) | 3.9% | — | NTPFreebsdHPE Hpux-ntpSiemens Simatic NET CP 443-1 OPC UA Firmware | 4/6/2018 | 17/6/2026 | An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2)… | |
| Modificada | Alta (7.5) | 9.0% | — | NTPSynology Router ManagerSynology SkynasSynology Virtual Diskstation Manager+12 | 6/3/2018 | 17/6/2026 | The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by continually sending a packet with a zero-origin timestamp and source IP address of the "other side" of an interleaved association causing the victim ntpd to reset its association. | |
| Modificada | Media (5.3) | 2.7% | — | NTPSynology Router ManagerSynology SkynasSynology Virtual Diskstation Manager+5 | 6/3/2018 | 17/6/2026 | ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key to create arbitrarily-many ephemeral associations in order to win the clock selection of ntpd and modify a victim's clock via a Sybil attack. This issue exists because of an incomplete fix for… | |
| Modificada | Alta (8.8) | 6.5% | — | NTPHPE Hpux-ntpApple MAC OS XSiemens Simatic NET CP 443-1 OPC UA Firmware | 27/3/2017 | 17/6/2026 | Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenticated users to have unspecified impact via a long variable. | |
| Modificada | Alta (7.5) | 53% | — | NTPHPE Hpux-ntp | 13/1/2017 | 17/6/2026 | The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query. | |
| Modificada | Alta (7.5) | 12% | — | NTPCanonical Ubuntu LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+5 | 13/1/2017 | 17/6/2026 | NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers to cause a denial of service (prevent responses from the sources) by sending responses with a spoofed source address. | |
| Modificada | Baja (1.9) | 0.64% | — | FreebsdHpuxFedoraproject FedoraSendmail | 4/6/2014 | 17/6/2026 | The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows local users to access unintended high-numbered file descriptors via a custom mail-delivery program. | |
| Modificada | Media (4.9) | 0.53% | — | Hpux | 12/8/2009 | 16/6/2026 | Unspecified vulnerability in HP-UX B.11.31 allows local users to cause a denial of service (system crash) via unknown vectors related to the ttrace system call. |