Your RSA-2048 keys break in 2030. Find every one of them before attackers do.

CVE-2001-0414

Buffer overflow in ntpd ntp daemon 4.0.99k and earlier (aka xntpd and xntp3) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long readvar argument.

Published
Jun 18, 2001
Updated
Apr 16, 2026
Affected
0 pkgs
Patched
None yet
Exploits
5 known

EPSS Exploitation Probability

via FIRST.org ↗
91.7%probability of exploitation in next 30 days
Very High Risk100th percentile+10.52%
78.0%83.6%89.2%94.8%87.7%91.7%Dec 25Apr 26Jun 26

EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.

Description

Buffer overflow in ntpd ntp daemon 4.0.99k and earlier (aka xntpd and xntp3) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long readvar argument.

Affected Products

2 products · 18 configurations
Application
ntpddave_mills
≤ 4.0.99k
11 versions
4.0.994.0.99a4.0.99b4.0.99c4.0.99d4.0.99e4.0.99f4.0.99g4.0.99h4.0.99i4.0.99j
Application
xntp3dave_mills
6 versions
5.935.93a5.93b5.93c5.93d5.93e
Exploits & PoCs
5

Research use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.

EDB-20727remotelinux✓ Verified

NTPd - Remote Buffer Overflow

by babcia padlina ltd · Apr 4, 2001

EDB-16285remotelinux✓ Verified

NTP daemon readvar - Remote Buffer Overflow (Metasploit)

by Metasploit · Aug 25, 2010

EDB-9940remotelinux✓ Verified

NTPd 4.0.99j-k readvar - Remote Buffer Overflow (Metasploit)

by patrick · Apr 4, 2001

Frequently Asked Questions

Buffer overflow in ntpd ntp daemon 4.0.99k and earlier (aka xntpd and xntp3) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long readvar argument.
O3 Security · Impact-Aware SCA

Is CVE-2001-0414 in your stack?

O3 detects CVE-2001-0414 across dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.