Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 3.9% | — | NTPFreebsdHPE Hpux-ntpSiemens Simatic NET CP 443-1 OPC UA Firmware | 4/6/2018 | 17/6/2026 | An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2)… | |
| Modificada | Alta (8.8) | 6.5% | — | NTPHPE Hpux-ntpApple MAC OS XSiemens Simatic NET CP 443-1 OPC UA Firmware | 27/3/2017 | 17/6/2026 | Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenticated users to have unspecified impact via a long variable. | |
| Modificada | Media (5.3) | 15% | — | NTPDebian LinuxNetapp Clustered Data OntapNetapp Data Ontap+13 | 30/1/2017 | 17/6/2026 | The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode value. | |
| Modificada | Media (5.3) | 16% | — | NTPOracle SolarisSuse Manager ProxySuse Openstack Cloud+6 | 5/7/2016 | 17/6/2026 | ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (interleaved-mode transition and time change) via a spoofed broadcast packet. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-1548. | |
| Modificada | Media (5.9) | 8.8% | — | NTPOracle SolarisSuse Manager ProxySuse Openstack Cloud+6 | 5/7/2016 | 17/6/2026 | ntpd in NTP 4.x before 4.2.8p8, when autokey is enabled, allows remote attackers to cause a denial of service (peer-variable clearing and association outage) by sending (1) a spoofed crypto-NAK packet or (2) a packet with an incorrect MAC value at a certain time. | |
| Modificada | Alta (7.5) | 13% | — | NTPOracle SolarisSuse ManagerSuse Manager Proxy+8 | 5/7/2016 | 17/6/2026 | The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-variable modification) by sending spoofed packets from many source IP addresses in a certain scenario, as demonstrated by triggering an incorrect leap indication. | |
| Modificada | Alta (7.5) | 17% | — | NTPOracle SolarisSuse ManagerSuse Manager Proxy+8 | 5/7/2016 | 17/6/2026 | ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoofed crypto-NAK packet with incorrect authentication data at a certain time. |