<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:34:49 +0000</lastBuildDate>
    <item>
      <title>certfr-2016-avi-209 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;les produits Cisco&lt;/span&gt;. Certaines d'entre el…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2016-avi-209</link>
      <description>certfr-2016-avi-209</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2016-avi-209</guid>
    </item>
    <item>
      <title>cnvd-2016-03821</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2016-03821</link>
      <description>cnvd-2016-03821</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2016-03821</guid>
    </item>
    <item>
      <title>EUVD-2026-84838</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-84838</link>
      <description>EUVD-2026-84838</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-84838</guid>
    </item>
    <item>
      <title>fkie_cve-2016-4954</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2016-4954</link>
      <description>&lt;p&gt;The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-variable modification) by sending spoofed packets from many source IP addresses in a certain scenario, as demonstrated by triggering an incorrect leap indication.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-variable modification) by sending spoofed packets from many source IP addresses in a certain scenario, as demonstrated by triggering an incorrect leap indication.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2016-4954</guid>
    </item>
    <item>
      <title>GHSA-w5gw-rhc6-c5g8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w5gw-rhc6-c5g8</link>
      <description>&lt;p&gt;The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-variable modification) by sending spoofed packets from many source IP addresses in a certain scenario, as demonstrated by triggering an incorrect leap indication.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-variable modification) by sending spoofed packets from many source IP addresses in a certain scenario, as demonstrated by triggering an incorrect leap indication.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w5gw-rhc6-c5g8</guid>
    </item>
    <item>
      <title>gsd-2016-4954</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2016-4954</link>
      <description>gsd-2016-4954</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2016-4954</guid>
    </item>
    <item>
      <title>ICSA-21-103-11 — Siemens TIM 4R-IE Devices</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-21-103-11</link>
      <description>&lt;p&gt;The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet. The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large number of crafted requests. The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (assertion failure) via a 6 or mode 7 packet containing a long data value. Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication. NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to conduct replay attacks by sniffing the network. NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a &amp;#34;skeleton key.&amp;#34; ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command. NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (client-server association tear down) by sending broadcast packets with invalid authe…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet. The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large number of crafted requests. The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (assertion failure) via a 6 or mode 7 packet containing a long data value. Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication. NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to conduct replay attacks by sniffing the network. NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a &amp;#34;skeleton key.&amp;#34; ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command. NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (client-server association tear down) by sending broadcast packets with invalid authe…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-21-103-11</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:10181-1 — ntp-4.2.8p9-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10181-1</link>
      <description>&lt;p&gt;ntp-4.2.8p9-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ntp-4.2.8p9-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:10181-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2016:1563-1 — Security update for ntp</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2016:1563-1</link>
      <description>&lt;p&gt;Security update for ntp&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for ntp&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2016:1563-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2016-4954</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-4954</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: ntp, Ubuntu:16.04:LTS: ntp&lt;/p&gt;
&lt;p&gt;The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-variable modification) by sending spoofed packets from many source IP addresses in a certain scenario, as demonstrated by triggering an incorrect leap indication.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: ntp, Ubuntu:16.04:LTS: ntp&lt;/p&gt;
&lt;p&gt;The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-variable modification) by sending spoofed packets from many source IP addresses in a certain scenario, as demonstrated by triggering an incorrect leap indication.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-4954</guid>
    </item>
    <item>
      <title>VDE-2022-032 — AUMA: Multiple Vulnerabilities in Automation Runtime NTP Service</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-032</link>
      <description>&lt;p&gt;The SIMA2 Master Station features an NTP service based on ntpd, a reference implementation of the Network Time Protocol (NTP). Affected SIMA2 Master Stations with software version &amp;lt; V2.6 include an outdated version of ntpd which is affected by a large number of vulnerabilities&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The SIMA2 Master Station features an NTP service based on ntpd, a reference implementation of the Network Time Protocol (NTP). Affected SIMA2 Master Stations with software version &amp;lt; V2.6 include an outdated version of ntpd which is affected by a large number of vulnerabilities&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-032</guid>
    </item>
  </channel>
</rss>
