VDB
CVE-2001-0414
CVE-2001-0414
PUBLISHED
KEV
CVSS 10 CRITICAL
Buffer overflow in ntpd ntp daemon 4.0.99k and earlier (aka xntpd and xntp3) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long readvar argument.
EPSS 81.16% · 99.2th percentile
Risk Scores
CVSS 2.0
10
EPSS Score
81.16%
99.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| dave_mills | ntpd | 4.0.99a, 4.0.99b, 4.0.99d |
| dave_mills | xntp3 | *, 5.93, 5.93c |
Exploit Intelligence
- CIRCL seen: CVE-2001-0414 (circl-sighting)
- CIRCL confirmed: CVE-2001-0414 (circl-sighting)
- CIRCL seen: CVE-2001-0414 (circl-sighting)
- CIRCL seen: CVE-2001-0414 (circl-sighting)
- 20010413 PROGENY-SA-2001-02A: [UPDATE] ntpd remote buffer overflow (circl)
- FreeBSD-SA-01:31 (circl)
- MDKSA-2001:036 (circl)
- NetBSD-SA2001-004 (circl)
- SSE074 (circl)
- 20010404 ntpd =< 4.0.99k remote buffer overflow (circl)
…and 24 more exploits
Timeline
- Apr 4, 2001 CVE Published
- Apr 4, 2001 PoC Published
- Aug 25, 2010 PoC Published
- Sep 23, 2010 PoC Published
- May 29, 2018 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
References
- RHSA-2001:045 vendor-advisory
- SuSE-SA:2001:10 vendor-advisory
- 20010409 [ESA-20010409-01] xntp buffer overflow mailing-list
- 20010409 ntp-4.99k23.tar.gz is available mailing-list
- SSE073 vendor-advisory
- MDKSA-2001:036 vendor-advisory
- NetBSD-SA2001-004 vendor-advisory
- SSE074 vendor-advisory
- 20010404 ntpd =< 4.0.99k remote buffer overflow mailing-list
- CLA-2001:392 vendor-advisory
- 805 vdb
- 20010409 ntpd - new Debian 2.2 (potato) version is also vulnerable mailing-list
- 2540 vdb
- oval:org.mitre.oval:def:3831 vdb
- 20010406 Immunix OS Security update for ntp and xntp3 mailing-list
- 20010405 Re: ntpd =< 4.0.99k remote buffer overflow] mailing-list
- 20010413 PROGENY-SA-2001-02A: [UPDATE] ntpd remote buffer overflow mailing-list
- 20010408 [slackware-security] buffer overflow fix for NTP mailing-list
- 20010418 IBM MSS Outside Advisory Redistribution: IBM AIX: Buffer Overflow Vulnerability in (x)ntp mailing-list
- FreeBSD-SA-01:31 vendor-advisory
…and 5 more