NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 17926 | CVE-2016-1548 | An attacker can spoof a packet from a legitimate ntpd server with an origin timestamp that matches the peer->dst timestamp recorded for that server. After making this switch, the client in NTP 4.2.8p4 and earlier and NTPSec aa48d001683e5b791a743ec9c575aaf7d867a2b0c will reject all future legitimate server responses. It is possible to force the victim client to move time after the mode has been changed. ntpq gives no indication that the mode has been switched. | 2 | 6.4 | Medium | 2017-01-19 | 2017-01-10 | View | |
| 17927 | CVE-2016-1549 | A malicious authenticated peer can create arbitrarily-many ephemeral associations in order to win the clock selection algorithm in ntpd in NTP 4.2.8p4 and earlier and NTPsec 3e160db8dc248a0bcb053b56a80167dc742d2b74 and a5fb34b9cc89b92a8fef2f459004865c93bb7f92 and modify a victim"s clock. | 2 | 4 | Medium | 2017-01-19 | 2017-01-10 | View | |
| 17928 | CVE-2016-1550 | An exploitable vulnerability exists in the message authentication functionality of libntp in ntp 4.2.8p4 and NTPSec a5fb34b9cc89b92a8fef2f459004865c93bb7f92. An attacker can send a series of crafted messages to attempt to recover the message digest key. | 2 | 5 | Medium | 2017-01-19 | 2017-01-10 | View | |
| 22537 | CVE-2016-9964 | redirect() in bottle.py in bottle 0.12.10 doesn"t filter a " " sequence, which leads to a CRLF attack, as demonstrated by a redirect("233 Set-Cookie: name=salt") call. | 2 | 4.3 | Medium | 2017-01-19 | 2017-01-10 | View | |
| 31754 | CVE-2014-3577 | org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient before 4.3.5 and HttpAsyncClient before 4.0.2 does not properly verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a "CN=" string in a field in the distinguished name (DN) of a certificate, as demonstrated by the "foo,CN=www.apache.org" string in the O field. | 2 | 5.8 | Medium | 2017-01-19 | 2017-01-10 | View |
Page 2448 of 17672, showing 5 records out of 88360 total, starting on record 12236, ending on 12240