Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ntp

First CVE: Aug 6, 2004Active for: 22 yearsTotal CVEs: 99
55.2
VTI Score
TOP TARGET

NTP is a foundational network time protocol implementation deployed across virtually all networked systems—servers, workstations, appliances, and IoT devices—making it one of the most pervasive components in the digital infrastructure landscape. The vendor's vulnerability profile concentrates in a single product line and clusters around parser and resource-handling classes: improper input validation, memory-buffer boundary violations, out-of-bounds writes, and uncontrolled resource consumption that are characteristic of a protocol implementation handling untrusted network input. A meaningful share of vulnerabilities reach serious severity, and public exploit code has been developed for a portion of the disclosed issues, reflecting the protocol's role in infrastructure where time synchronization is critical and attacks can propagate network-wide. Defenders should treat NTP updates as high-priority given the product's ubiquity and the difficulty of inventorying all instances in large networks; live exploitation and severity counts are shown alongside this summary.

FAUCET AI Generated
99
Total CVEs
More Total CVEs than 99% of tracked vendors
9.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ntp over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 6, 2004
21 years ago
Most Recent CVE
Apr 11, 2023
1,200 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (99 CVEs).

99 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2015-7871CRITICAL
Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication.
Aug 7, 20179.883NOYES
CVE-2013-5211MEDIUM
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via forged (1) REQ_MON_GETLIST or (
Jan 2, 20145.083NOYES
CVE-2016-7434HIGH
The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query.
Jan 13, 20177.565NOYES
CVE-2014-9295HIGH
Multiple stack-based buffer overflows in ntpd in NTP before 4.2.8 allow remote attackers to execute arbitrary code via a crafted packet, related to (1) the crypto_recv function whe
Dec 20, 20147.564NONO
CVE-2018-12327CRITICAL
Stack-based buffer overflow in ntpq and ntpdc of NTP version 4.2.8p11 allows an attacker to achieve code execution or escalate to higher privileges via a long string as the argumen
Jun 20, 20189.857NOYES
CVE-2018-7182HIGH
The ctl_getitem method in ntpd in ntp-4.2.8p6 before 4.2.8p11 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mode 6 packet with a ntpd inst
Mar 6, 20187.551NOYES
CVE-2016-4957HIGH
ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because of an incorrect fix
Jul 5, 20167.549NONO
CVE-2009-3563MEDIUM
ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by using MODE_PRIVATE to send a spoofed
Dec 9, 20096.448NOYES
CVE-2015-7855MEDIUM
The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (assertion failure) via a 6 or mode 7 pa
Aug 7, 20176.543NOYES
CVE-2018-7183CRITICAL
Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arbitrary code by leveraging an ntpq query and sending a respon
Mar 8, 20189.836NONO
View all 99 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products99 CVEs
53%
39%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local6 (6.1%)
Network76 (76.8%)
Unknown14 (14.1%)
Physical1 (1.0%)
Adjacent Network2 (2.0%)
Attack Complexity
Low62 (62.6%)
High23 (23.2%)
Unknown14 (14.1%)
User Interaction
None85 (85.9%)
Unknown14 (14.1%)
Required0 (0.0%)
Privileges Required
Low22 (22.2%)
High1 (1.0%)
None62 (62.6%)
Unknown14 (14.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (99 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
3.0% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
5.1% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ntp.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ntp — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ntp's Products

View all 4 CNAs →

Top CWEs