The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via forged (1) REQ_MON_GETLIST or (2) REQ_MON_GETLIST_1 requests, as exploited in the wild in December 2013.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This vulnerability has a 97.55% probability of being exploited in the next 30 days, ranking higher than 100% of all scored CVEs.