ntop records
22 published records for vendor ntop.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 59.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-125 Out-of-bounds Read5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-787 Out-of-bounds Write2
- CWE-190 Integer Overflow or Wraparound1
- CWE-254 7PK - Security Features1
- CWE-335 Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
22 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-11939No exploit | In nDPI through 3.2 Stable, the SSH protocol dissector has multiple KEXINIT integer overflows that result in a controlled remote heap overflntop · ndpi · CWE-190 | Critical9.8 | — | 3.3% | Apr 23, 2020 |
39Monitor | CVE-2020-15475No exploit | In nDPI through 3.2, ndpi_reset_packet_line_info in lib/ndpi_main.c omits certain reinitialization, leading to a use-after-free.ntop · ndpi · CWE-416 | Critical9.8 | — | 1.2% | Jul 1, 2020 |
39Monitor | CVE-2020-15474No exploit | In nDPI through 3.2, there is a stack overflow in extractRDNSequence in lib/protocols/tls.c.ntop · ndpi · CWE-787 | Critical9.8 | — | 1.2% | Jul 1, 2020 |
39Monitor | CVE-2026-38968No exploit | ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking.ntop · ntopng · CWE-341 | Critical9.8 | — | 0.6% | Jul 2, 2026 |
36Monitor | CVE-2017-5473Proof of concept | Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authentication of arbitrary userntop · ntopng · CWE-352 | High8.8 | — | 3.6% | Jan 14, 2017 |
36Monitor | CVE-2021-36082No exploit | ntop nDPI 3.4 has a stack-based buffer overflow in processClientServerHello.ntop · ndpi · CWE-787 | High8.8 | — | 1.8% | Jun 30, 2021 |
36Monitor | CVE-2020-15472No exploit | In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/protocols/h323.c, as demontop · ndpi · CWE-125 | Critical9.1 | — | 1.5% | Jul 1, 2020 |
36Monitor | CVE-2020-15473No exploit | In nDPI through 3.2, the OpenVPN dissector is vulnerable to a heap-based buffer over-read in ndpi_search_openvpn in lib/protocols/openvpn.c.ntop · ndpi · CWE-125 | Critical9.1 | — | 1.3% | Jul 1, 2020 |
36Monitor | CVE-2020-15471No exploit | In nDPI through 3.2, the packet parsing code is vulnerable to a heap-based buffer over-read in ndpi_parse_packet_line_info in lib/ndpi_main.ntop · ndpi · CWE-125 | Critical9.1 | — | 1.3% | Jul 1, 2020 |
35Monitor | CVE-2018-12520Proof of concept | An issue was discovered in ntopng 3.4 before 3.4.180617.ntop · ntopng · CWE-335 | High8.1 | — | 10.5% | Jul 5, 2018 |
33Monitor | CVE-2025-25066No exploit | nDPI through 4.12 has a potential stack-based buffer overflow in ndpi_address_cache_restore in lib/ndpi_cache.c.ntop · ndpi · CWE-121 | High8.4 | — | 0.2% | Feb 3, 2025 |
31Monitor | CVE-2020-15476No exploit | In nDPI through 3.2, the Oracle protocol dissector has a heap-based buffer over-read in ndpi_search_oracle in lib/protocols/oracle.c.ntop · ndpi · CWE-125 | High7.5 | — | 2.1% | Jul 1, 2020 |
31Monitor | CVE-2017-7458No exploit | The NetworkInterface::getHost function in NetworkInterface.cpp in ntopng before 3.0 allows remote attackers to cause a denial of service (NUntop · ntopng · CWE-476 | High7.5 | — | 1.9% | Jun 26, 2017 |
30Monitor | CVE-2020-11940No exploit | In nDPI through 3.2 Stable, an out-of-bounds read in concat_hash_string in ssh.c can be exploited by a network-positioned attacker that can ntop · ndpi · CWE-125 | High7.5 | — | 1.3% | Apr 23, 2020 |
30Monitor | CVE-2017-7459No exploit | ntopng before 3.0 allows HTTP Response Splitting.ntop · ntopng · CWE-74 | High7.5 | — | 0.9% | Jun 26, 2017 |
26Monitor | CVE-2015-8368Proof of concept | ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and usernntop · ntopng · CWE-254 | Medium6.0 | — | 5.1% | Dec 17, 2015 |
24Monitor | CVE-2017-7416No exploit | ntopng before 3.0 allows XSS because GET and POST parameters are improperly validated.ntop · ntopng · CWE-79 | Medium6.1 | — | 0.6% | Jun 26, 2017 |
24Monitor | CVE-2024-53426No exploit | A heap-buffer-overflow vulnerability has been identified in ntopng 6.2 in the Flow::dissectMDNS function.CWE-120 | Medium6.2 | — | 0.3% | Nov 21, 2024 |
22Monitor | CVE-2009-2732Proof of concept | The checkHTTPpassword function in http.c in ntop 3.3.10 and earlier allows remote attackers to cause a denial of service (NULL pointer derefntop · ntop · CWE-119 | Medium5.0 | — | 7.3% | Aug 21, 2009 |
18Monitor | CVE-2014-5464Proof of concept | Cross-site scripting (XSS) vulnerability in the nDPI traffic classification library in ntopng (aka ntop) before 1.2.1 allows remote attackerntop · ntopng · CWE-79 | Medium4.3 | — | 4.5% | Sep 8, 2014 |
18Monitor | CVE-2014-4165No exploit | Cross-site scripting (XSS) vulnerability in ntop allows remote attackers to inject arbitrary web script or HTML via the title parameter in antop · ntop · CWE-79 | Medium4.3 | — | 2.1% | Jun 16, 2014 |
17Monitor | CVE-2014-4329No exploit | Cross-site scripting (XSS) vulnerability in lua/host_details.lua in ntopng 1.1 allows remote attackers to inject arbitrary web script or HTMntop · ntopng · CWE-79 | Medium4.3 | — | 1.2% | Jun 19, 2014 |
- CVE-2020-1193940Plan
In nDPI through 3.2 Stable, the SSH protocol dissector has multiple KEXINIT integer overflows that result in a controlled remote heap overfl
CriticalCVSS 9.8No exploitEPSS 3%ntop · ndpiApr 23, 2020
- CVE-2020-1547539Monitor
In nDPI through 3.2, ndpi_reset_packet_line_info in lib/ndpi_main.c omits certain reinitialization, leading to a use-after-free.
CriticalCVSS 9.8No exploitEPSS 1%ntop · ndpiJul 1, 2020
- CVE-2020-1547439Monitor
In nDPI through 3.2, there is a stack overflow in extractRDNSequence in lib/protocols/tls.c.
CriticalCVSS 9.8No exploitEPSS 1%ntop · ndpiJul 1, 2020
- CVE-2026-3896839Monitor
ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking.
CriticalCVSS 9.8No exploitEPSS 1%ntop · ntopngJul 2, 2026
- CVE-2017-547336Monitor
Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authentication of arbitrary user
HighCVSS 8.8Proof of conceptEPSS 4%ntop · ntopngJan 14, 2017
- CVE-2021-3608236Monitor
ntop nDPI 3.4 has a stack-based buffer overflow in processClientServerHello.
HighCVSS 8.8No exploitEPSS 2%ntop · ndpiJun 30, 2021
- CVE-2020-1547236Monitor
In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/protocols/h323.c, as demo
CriticalCVSS 9.1No exploitEPSS 1%ntop · ndpiJul 1, 2020
- CVE-2020-1547336Monitor
In nDPI through 3.2, the OpenVPN dissector is vulnerable to a heap-based buffer over-read in ndpi_search_openvpn in lib/protocols/openvpn.c.
CriticalCVSS 9.1No exploitEPSS 1%ntop · ndpiJul 1, 2020
- CVE-2020-1547136Monitor
In nDPI through 3.2, the packet parsing code is vulnerable to a heap-based buffer over-read in ndpi_parse_packet_line_info in lib/ndpi_main.
CriticalCVSS 9.1No exploitEPSS 1%ntop · ndpiJul 1, 2020
- CVE-2018-1252035Monitor
An issue was discovered in ntopng 3.4 before 3.4.180617.
HighCVSS 8.1Proof of conceptEPSS 11%ntop · ntopngJul 5, 2018
- CVE-2025-2506633Monitor
nDPI through 4.12 has a potential stack-based buffer overflow in ndpi_address_cache_restore in lib/ndpi_cache.c.
HighCVSS 8.4No exploitEPSS 0%ntop · ndpiFeb 3, 2025
- CVE-2020-1547631Monitor
In nDPI through 3.2, the Oracle protocol dissector has a heap-based buffer over-read in ndpi_search_oracle in lib/protocols/oracle.c.
HighCVSS 7.5No exploitEPSS 2%ntop · ndpiJul 1, 2020
- CVE-2017-745831Monitor
The NetworkInterface::getHost function in NetworkInterface.cpp in ntopng before 3.0 allows remote attackers to cause a denial of service (NU
HighCVSS 7.5No exploitEPSS 2%ntop · ntopngJun 26, 2017
- CVE-2020-1194030Monitor
In nDPI through 3.2 Stable, an out-of-bounds read in concat_hash_string in ssh.c can be exploited by a network-positioned attacker that can
HighCVSS 7.5No exploitEPSS 1%ntop · ndpiApr 23, 2020
- CVE-2017-745930Monitor
ntopng before 3.0 allows HTTP Response Splitting.
HighCVSS 7.5No exploitEPSS 1%ntop · ntopngJun 26, 2017
- CVE-2015-836826Monitor
ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and usern
MediumCVSS 6.0Proof of conceptEPSS 5%ntop · ntopngDec 17, 2015
- CVE-2017-741624Monitor
ntopng before 3.0 allows XSS because GET and POST parameters are improperly validated.
MediumCVSS 6.1No exploitEPSS 1%ntop · ntopngJun 26, 2017
- CVE-2024-5342624Monitor
A heap-buffer-overflow vulnerability has been identified in ntopng 6.2 in the Flow::dissectMDNS function.
MediumCVSS 6.2No exploitEPSS 0%Nov 21, 2024
- CVE-2009-273222Monitor
The checkHTTPpassword function in http.c in ntop 3.3.10 and earlier allows remote attackers to cause a denial of service (NULL pointer deref
MediumCVSS 5.0Proof of conceptEPSS 7%ntop · ntopAug 21, 2009
- CVE-2014-546418Monitor
Cross-site scripting (XSS) vulnerability in the nDPI traffic classification library in ntopng (aka ntop) before 1.2.1 allows remote attacker
MediumCVSS 4.3Proof of conceptEPSS 4%ntop · ntopngSep 8, 2014
- CVE-2014-416518Monitor
Cross-site scripting (XSS) vulnerability in ntop allows remote attackers to inject arbitrary web script or HTML via the title parameter in a
MediumCVSS 4.3No exploitEPSS 2%ntop · ntopJun 16, 2014
- CVE-2014-432917Monitor
Cross-site scripting (XSS) vulnerability in lua/host_details.lua in ntopng 1.1 allows remote attackers to inject arbitrary web script or HTM
MediumCVSS 4.3No exploitEPSS 1%ntop · ntopngJun 19, 2014