Vulnerability Details CVE-2015-7849
Use-after-free vulnerability in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to possibly execute arbitrary code or cause a denial of service (crash) via crafted packets.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.025
EPSS Ranking 84.5%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.5
Products affected by CVE-2015-7849
-
cpe:2.3:a:netapp:oncommand_balance:-
-
cpe:2.3:a:netapp:oncommand_performance_manager:-
-
cpe:2.3:a:netapp:oncommand_unified_manager:-
-
-
-
-
-
-
-
Ntp
»
Ntp
»
Version: 4.2.7p444
cpe:2.3:a:ntp:ntp:4.2.7p444
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:o:netapp:clustered_data_ontap:-
-
cpe:2.3:o:netapp:data_ontap:-