Hpe Hpux-Ntp vulnerabilities

7 known vulnerabilities affecting hpe/hpux-ntp.

Total CVEs
7
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2019-8936HIGHCVSS 7.5fixed in c.4.2.8.4.02019-05-15
CVE-2019-8936 [HIGH] CWE-476 CVE-2019-8936: NTP through 4.2.8p12 has a NULL Pointer Dereference. NTP through 4.2.8p12 has a NULL Pointer Dereference.
nvd
CVE-2016-9042MEDIUMCVSS 5.9fixed in c.4.2.8.4.02018-06-04
CVE-2016-9042 [MEDIUM] CWE-20 CVE-2016-9042: An exploitable denial of service vulnerability exists in the origin timestamp check functionality of An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2) causing the reply to be dropped and
nvd
CVE-2018-7185HIGHCVSS 7.5fixed in c.4.2.8.4.02018-03-06
CVE-2018-7185 [HIGH] CVE-2018-7185: The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of serv The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by continually sending a packet with a zero-origin timestamp and source IP address of the "other side" of an interleaved association causing the victim ntpd to reset its association.
nvd
CVE-2018-7170MEDIUMCVSS 5.3fixed in c.4.2.8.4.02018-03-06
CVE-2018-7170 [MEDIUM] CVE-2018-7170: ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the pr ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key to create arbitrarily-many ephemeral associations in order to win the clock selection of ntpd and modify a victim's clock via a Sybil attack. This issue exists because of an incomplete fix for CVE-2016-1549.
nvd
CVE-2017-6458HIGHCVSS 8.8fixed in c.4.2.8.4.02017-03-27
CVE-2017-6458 [HIGH] CWE-119 CVE-2017-6458: Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 a Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenticated users to have unspecified impact via a long variable.
nvd
CVE-2016-7426HIGHCVSS 7.5≥ b.11.31, < c.4.2.8.2.02017-01-13
CVE-2016-7426 [HIGH] CWE-400 CVE-2016-7426: NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers to cause a denial of service (prevent responses from the sources) by sending responses with a spoofed source address.
nvd
CVE-2016-7434HIGHCVSS 7.5PoC≥ b.11.31, < c.4.2.8.2.02017-01-13
CVE-2016-7434 [HIGH] CWE-20 CVE-2016-7434: The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of servic The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query.
nvd