<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:17:51 +0000</lastBuildDate>
    <item>
      <title>certfr-2021-avi-255 — De multiples vulnérabilités ont été découvertes dans les produits
Siemens. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-255</link>
      <description>certfr-2021-avi-255</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-255</guid>
    </item>
    <item>
      <title>cnvd-2015-06120</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2015-06120</link>
      <description>cnvd-2015-06120</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2015-06120</guid>
    </item>
    <item>
      <title>EUVD-2026-93240</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-93240</link>
      <description>EUVD-2026-93240</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-93240</guid>
    </item>
    <item>
      <title>fkie_cve-2015-5219</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2015-5219</link>
      <description>&lt;p&gt;The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2015-5219</guid>
    </item>
    <item>
      <title>GHSA-38qh-x54p-8w2g</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-38qh-x54p-8w2g</link>
      <description>&lt;p&gt;The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-38qh-x54p-8w2g</guid>
    </item>
    <item>
      <title>gsd-2015-5219</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2015-5219</link>
      <description>gsd-2015-5219</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2015-5219</guid>
    </item>
    <item>
      <title>ICSA-21-103-11 — Siemens TIM 4R-IE Devices</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-21-103-11</link>
      <description>&lt;p&gt;The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet. The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large number of crafted requests. The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (assertion failure) via a 6 or mode 7 packet containing a long data value. Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication. NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to conduct replay attacks by sniffing the network. NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a &amp;#34;skeleton key.&amp;#34; ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command. NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (client-server association tear down) by sending broadcast packets with invalid authe…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet. The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large number of crafted requests. The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (assertion failure) via a 6 or mode 7 packet containing a long data value. Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication. NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to conduct replay attacks by sniffing the network. NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a &amp;#34;skeleton key.&amp;#34; ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command. NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (client-server association tear down) by sending broadcast packets with invalid authe…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-21-103-11</guid>
    </item>
    <item>
      <title>RHSA-2016:0780 — Red Hat Security Advisory: ntp security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2016:0780</link>
      <description>&lt;p&gt;ntp: crash with crafted logconfig configuration command ntp: ntpd crash when processing config commands with statistics type ntp: infinite loop in sntp processing crafted packet ntp: incomplete checks in ntp_crypto.c ntp: incomplete checks in ntp_crypto.c ntp: slow memory leak in CRYPTO_ASSOC ntp: incomplete checks in ntp_crypto.c ntp: config command can be used to set the pidfile and drift file paths ntp: ntpq atoascii memory corruption vulnerability ntp: restriction list NULL pointer dereference ntp: stack exhaustion in recursive traversal of restriction list&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ntp: crash with crafted logconfig configuration command ntp: ntpd crash when processing config commands with statistics type ntp: infinite loop in sntp processing crafted packet ntp: incomplete checks in ntp_crypto.c ntp: incomplete checks in ntp_crypto.c ntp: slow memory leak in CRYPTO_ASSOC ntp: incomplete checks in ntp_crypto.c ntp: config command can be used to set the pidfile and drift file paths ntp: ntpq atoascii memory corruption vulnerability ntp: restriction list NULL pointer dereference ntp: stack exhaustion in recursive traversal of restriction list&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2016:0780</guid>
    </item>
    <item>
      <title>RHSA-2016:2583 — Red Hat Security Advisory: ntp security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2016:2583</link>
      <description>&lt;p&gt;ntp: crash with crafted logconfig configuration command ntp: ntpd crash when processing config commands with statistics type ntp: config command can be used to set the pidfile and drift file paths ntp: infinite loop in sntp processing crafted packet ntp: incomplete checks in ntp_crypto.c ntp: incomplete checks in ntp_crypto.c ntp: slow memory leak in CRYPTO_ASSOC ntp: incomplete checks in ntp_crypto.c ntp: config command can be used to set the pidfile and drift file paths ntp: ntpq atoascii memory corruption vulnerability ntp: missing key check allows impersonation between authenticated peers (VU#357792) ntp: restriction list NULL pointer dereference ntp: stack exhaustion in recursive traversal of restriction list ntp: off-path denial of service on authenticated broadcast mode ntp: potential infinite loop in ntpq&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ntp: crash with crafted logconfig configuration command ntp: ntpd crash when processing config commands with statistics type ntp: config command can be used to set the pidfile and drift file paths ntp: infinite loop in sntp processing crafted packet ntp: incomplete checks in ntp_crypto.c ntp: incomplete checks in ntp_crypto.c ntp: slow memory leak in CRYPTO_ASSOC ntp: incomplete checks in ntp_crypto.c ntp: config command can be used to set the pidfile and drift file paths ntp: ntpq atoascii memory corruption vulnerability ntp: missing key check allows impersonation between authenticated peers (VU#357792) ntp: restriction list NULL pointer dereference ntp: stack exhaustion in recursive traversal of restriction list ntp: off-path denial of service on authenticated broadcast mode ntp: potential infinite loop in ntpq&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2016:2583</guid>
    </item>
    <item>
      <title>SUSE-SU-2016:1311-1 — Security update for ntp</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2016:1311-1</link>
      <description>&lt;p&gt;Security update for ntp&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for ntp&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2016:1311-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2015-5219</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2015-5219</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: ntp&lt;/p&gt;
&lt;p&gt;The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: ntp&lt;/p&gt;
&lt;p&gt;The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2015-5219</guid>
    </item>
  </channel>
</rss>
