Vulnerabilities
Vulnerable Software
Fedoraproject:  >> Fedora  >> 21  Security Vulnerabilities
ntpd in ntp before 4.2.8p3 with remote configuration enabled allows remote authenticated users with knowledge of the configuration password and access to a computer entrusted to perform remote configuration to cause a denial of service (service crash) via a NULL byte in a crafted configuration directive packet.
CVSS Score
5.3
EPSS Score
0.015
Published
2017-08-24
The prefix variable in the get_or_define_ns function in Lasso before commit 6d854cef4211cdcdbc7446c978f23ab859847cdd allows remote attackers to cause a denial of service (uninitialized memory access and application crash) via unspecified vectors.
CVSS Score
7.5
EPSS Score
0.011
Published
2017-08-11
ganglia-web before 3.7.1 allows remote attackers to bypass authentication.
CVSS Score
9.8
EPSS Score
0.021
Published
2017-08-09
ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when the lowest order byte of the temp variable is between 0x20 and 0x7f and not #, which might allow remote attackers to obtain the value of generated MD5 keys via a brute force attack with the 93 possible keys.
CVSS Score
7.5
EPSS Score
0.062
Published
2017-08-09
The log_config_command function in ntp_parser.y in ntpd in NTP before 4.2.7p42 allows remote attackers to cause a denial of service (ntpd crash) via crafted logconfig commands.
CVSS Score
7.5
EPSS Score
0.118
Published
2017-07-21
ntp_openssl.m4 in ntpd in NTP before 4.2.7p112 allows remote attackers to cause a denial of service (segmentation fault) via a crafted statistics or filegen configuration command that is not enabled during compilation.
CVSS Score
7.5
EPSS Score
0.104
Published
2017-07-21
The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet.
CVSS Score
7.5
EPSS Score
0.036
Published
2017-07-21
The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time when started with the -g option, or to alter the time by up to 900 seconds otherwise by responding to an unspecified number of requests from trusted sources, and leveraging a resulting denial of service (abort and restart).
CVSS Score
7.5
EPSS Score
0.312
Published
2017-07-21
Blkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code.
CVSS Score
7.8
EPSS Score
0.001
Published
2017-03-31
Integer overflow in the read_fragment_table_4 function in unsquash-4.c in Squashfs and sasquatch allows remote attackers to cause a denial of service (application crash) via a crafted input, which triggers a stack-based buffer overflow.
CVSS Score
5.5
EPSS Score
0.002
Published
2017-03-17


Contact Us

Shodan ® - All rights reserved