Vulnerability Database

393,392

Total vulnerabilities in the database

CVE-2009-1252 — ntp / ntp

Improper Restriction of Operations within the Bounds of a Memory Buffer

Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSSL and autokey are enabled, allows remote attackers to execute arbitrary code via a crafted packet containing an extension field.

  • Published: May 19, 2009
  • Updated: Oct 3, 2026
  • CVE: CVE-2009-1252
  • Severity: Medium
  • Exploit:
  • CISA KEV:

CVSS v2:

  • Severity: Medium
  • Score: 6.8
  • AV:N/AC:M/Au:N/C:P/I:P/A:P

CWEs:

Software Affected versions
ntp / ntp = 4.2.4p0
ntp / ntp = 4.2.4p1
ntp / ntp = 4.2.4p2
ntp / ntp = 4.2.4p3
ntp / ntp = 4.2.4p4
ntp / ntp = 4.2.4p5
ntp / ntp = 4.2.4p6
ntp / ntp = 4.2.5p0
ntp / ntp = 4.2.5p1
ntp / ntp = 4.2.5p2
ntp / ntp = 4.2.5p3
ntp / ntp = 4.2.5p4
ntp / ntp = 4.2.5p5
ntp / ntp = 4.2.5p6
ntp / ntp = 4.2.5p7
ntp / ntp = 4.2.5p8
ntp / ntp = 4.2.5p9
ntp / ntp = 4.2.5p10
ntp / ntp = 4.2.5p11
ntp / ntp = 4.2.5p12
ntp / ntp = 4.2.5p13
ntp / ntp = 4.2.5p14
ntp / ntp = 4.2.5p15
ntp / ntp = 4.2.5p16
ntp / ntp = 4.2.5p17
ntp / ntp = 4.2.5p18
ntp / ntp = 4.2.5p19
ntp / ntp = 4.2.5p20
ntp / ntp = 4.2.5p21
ntp / ntp = 4.2.5p23
ntp / ntp = 4.2.5p24
ntp / ntp = 4.2.5p25
ntp / ntp = 4.2.5p26
ntp / ntp = 4.2.5p27
ntp / ntp = 4.2.5p28
ntp / ntp = 4.2.5p29
ntp / ntp = 4.2.5p30
ntp / ntp = 4.2.5p31
ntp / ntp = 4.2.5p32
ntp / ntp = 4.2.5p33
ntp / ntp = 4.2.5p35
ntp / ntp = 4.2.5p36
ntp / ntp = 4.2.5p37
ntp / ntp = 4.2.5p38
ntp / ntp = 4.2.5p39
ntp / ntp = 4.2.5p40
ntp / ntp = 4.2.5p41
ntp / ntp = 4.2.5p42
ntp / ntp = 4.2.5p43
ntp / ntp = 4.2.5p44
ntp / ntp = 4.2.5p45
ntp / ntp = 4.2.5p46
ntp / ntp = 4.2.5p47
ntp / ntp = 4.2.5p48
ntp / ntp = 4.2.5p49
ntp / ntp = 4.2.5p50
ntp / ntp = 4.2.5p51
ntp / ntp = 4.2.5p52
ntp / ntp = 4.2.5p53
ntp / ntp = 4.2.5p54
ntp / ntp = 4.2.5p55
ntp / ntp = 4.2.5p56
ntp / ntp = 4.2.5p57
ntp / ntp = 4.2.5p58
ntp / ntp = 4.2.5p59
ntp / ntp = 4.2.5p60
ntp / ntp = 4.2.5p61
ntp / ntp = 4.2.5p62
ntp / ntp = 4.2.5p63
ntp / ntp = 4.2.5p64
ntp / ntp = 4.2.5p65
ntp / ntp = 4.2.5p66
ntp / ntp = 4.2.5p67
ntp / ntp = 4.2.5p68
ntp / ntp = 4.2.5p69
ntp / ntp = 4.2.5p70
ntp / ntp = 4.2.5p71
ntp / ntp = 4.2.5p73

Frequently Asked Questions

A security vulnerability is a weakness in software, hardware, or configuration that can be exploited to compromise confidentiality, integrity, or availability. Many vulnerabilities are tracked as CVEs (Common Vulnerabilities and Exposures), which provide a standardized identifier so teams can coordinate patching, mitigation, and risk assessment across tools and vendors.

CVSS (Common Vulnerability Scoring System) estimates technical severity, but it doesn't automatically equal business risk. Prioritize using context like internet exposure, affected asset criticality, known exploitation (proof-of-concept or in-the-wild), and whether compensating controls exist. A "Medium" CVSS on an exposed, production system can be more urgent than a "Critical" on an isolated, non-production host.

A vulnerability is the underlying weakness. An exploit is the method or code used to take advantage of it. A zero-day is a vulnerability that is unknown to the vendor or has no publicly available fix when attackers begin using it. In practice, risk increases sharply when exploitation becomes reliable or widespread.

Recurring findings usually come from incomplete Asset Discovery, inconsistent patch management, inherited images, and configuration drift. In modern environments, you also need to watch the software supply chain: dependencies, containers, build pipelines, and third-party services can reintroduce the same weakness even after you patch a single host. Unknown or unmanaged assets (often called Shadow IT) are a common reason the same issues resurface.

Use a simple, repeatable triage model: focus first on externally exposed assets, high-value systems (identity, VPN, email, production), vulnerabilities with known exploits, and issues that enable remote code execution or privilege escalation. Then enforce patch SLAs and track progress using consistent metrics so remediation is steady, not reactive.

SynScan combines attack surface monitoring and continuous security auditing to keep your inventory current, flag high-impact vulnerabilities early, and help you turn raw findings into a practical remediation plan.