NTP is a foundational network time protocol implementation deployed across virtually all networked systems—servers, workstations, appliances, and IoT devices—making it one of the most pervasive components in the digital infrastructure landscape. The vendor's vulnerability profile concentrates in a single product line and clusters around parser and resource-handling classes: improper input validation, memory-buffer boundary violations, out-of-bounds writes, and uncontrolled resource consumption that are characteristic of a protocol implementation handling untrusted network input. A meaningful share of vulnerabilities reach serious severity, and public exploit code has been developed for a portion of the disclosed issues, reflecting the protocol's role in infrastructure where time synchronization is critical and attacks can propagate network-wide. Defenders should treat NTP updates as high-priority given the product's ubiquity and the difficulty of inventorying all instances in large networks; live exploitation and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ntp over time
Signals from CVEs in this vendor scope (99 CVEs).
99 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-7871CRITICAL Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication. | Aug 7, 2017 | 9.8 | 83 | NO | YES |
CVE-2013-5211MEDIUM The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via forged (1) REQ_MON_GETLIST or ( | Jan 2, 2014 | 5.0 | 83 | NO | YES |
CVE-2016-7434HIGH The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query. | Jan 13, 2017 | 7.5 | 65 | NO | YES |
CVE-2014-9295HIGH Multiple stack-based buffer overflows in ntpd in NTP before 4.2.8 allow remote attackers to execute arbitrary code via a crafted packet, related to (1) the crypto_recv function whe | Dec 20, 2014 | 7.5 | 64 | NO | NO |
CVE-2018-12327CRITICAL Stack-based buffer overflow in ntpq and ntpdc of NTP version 4.2.8p11 allows an attacker to achieve code execution or escalate to higher privileges via a long string as the argumen | Jun 20, 2018 | 9.8 | 57 | NO | YES |
CVE-2018-7182HIGH The ctl_getitem method in ntpd in ntp-4.2.8p6 before 4.2.8p11 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mode 6 packet with a ntpd inst | Mar 6, 2018 | 7.5 | 51 | NO | YES |
CVE-2016-4957HIGH ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because of an incorrect fix | Jul 5, 2016 | 7.5 | 49 | NO | NO |
CVE-2009-3563MEDIUM ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by using MODE_PRIVATE to send a spoofed | Dec 9, 2009 | 6.4 | 48 | NO | YES |
CVE-2015-7855MEDIUM The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (assertion failure) via a 6 or mode 7 pa | Aug 7, 2017 | 6.5 | 43 | NO | YES |
CVE-2018-7183CRITICAL Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arbitrary code by leveraging an ntpq query and sending a respon | Mar 8, 2018 | 9.8 | 36 | NO | NO |
Signals from CVEs in this vendor scope (99 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ntp.
Media articles that mention a CVE ID that affects a product developed by Ntp — matched by CVE ID, not by vendor name.