Skip to content
Noroxi

ntop records

22 published records for vendor ntop.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
59.1%
Median publish → KEV
No record has entered KEV

All records

22 records
  • In nDPI through 3.2 Stable, the SSH protocol dissector has multiple KEXINIT integer overflows that result in a controlled remote heap overfl

    CriticalCVSS 9.8No exploitEPSS 3%

    ntop · ndpiApr 23, 2020

  • In nDPI through 3.2, ndpi_reset_packet_line_info in lib/ndpi_main.c omits certain reinitialization, leading to a use-after-free.

    CriticalCVSS 9.8No exploitEPSS 1%

    ntop · ndpiJul 1, 2020

  • In nDPI through 3.2, there is a stack overflow in extractRDNSequence in lib/protocols/tls.c.

    CriticalCVSS 9.8No exploitEPSS 1%

    ntop · ndpiJul 1, 2020

  • ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking.

    CriticalCVSS 9.8No exploitEPSS 1%

    ntop · ntopngJul 2, 2026

  • CVE-2017-5473
    36Monitor

    Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authentication of arbitrary user

    HighCVSS 8.8Proof of conceptEPSS 4%

    ntop · ntopngJan 14, 2017

  • ntop nDPI 3.4 has a stack-based buffer overflow in processClientServerHello.

    HighCVSS 8.8No exploitEPSS 2%

    ntop · ndpiJun 30, 2021

  • In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/protocols/h323.c, as demo

    CriticalCVSS 9.1No exploitEPSS 1%

    ntop · ndpiJul 1, 2020

  • In nDPI through 3.2, the OpenVPN dissector is vulnerable to a heap-based buffer over-read in ndpi_search_openvpn in lib/protocols/openvpn.c.

    CriticalCVSS 9.1No exploitEPSS 1%

    ntop · ndpiJul 1, 2020

  • In nDPI through 3.2, the packet parsing code is vulnerable to a heap-based buffer over-read in ndpi_parse_packet_line_info in lib/ndpi_main.

    CriticalCVSS 9.1No exploitEPSS 1%

    ntop · ndpiJul 1, 2020

  • An issue was discovered in ntopng 3.4 before 3.4.180617.

    HighCVSS 8.1Proof of conceptEPSS 11%

    ntop · ntopngJul 5, 2018

  • nDPI through 4.12 has a potential stack-based buffer overflow in ndpi_address_cache_restore in lib/ndpi_cache.c.

    HighCVSS 8.4No exploitEPSS 0%

    ntop · ndpiFeb 3, 2025

  • In nDPI through 3.2, the Oracle protocol dissector has a heap-based buffer over-read in ndpi_search_oracle in lib/protocols/oracle.c.

    HighCVSS 7.5No exploitEPSS 2%

    ntop · ndpiJul 1, 2020

  • CVE-2017-7458
    31Monitor

    The NetworkInterface::getHost function in NetworkInterface.cpp in ntopng before 3.0 allows remote attackers to cause a denial of service (NU

    HighCVSS 7.5No exploitEPSS 2%

    ntop · ntopngJun 26, 2017

  • In nDPI through 3.2 Stable, an out-of-bounds read in concat_hash_string in ssh.c can be exploited by a network-positioned attacker that can

    HighCVSS 7.5No exploitEPSS 1%

    ntop · ndpiApr 23, 2020

  • CVE-2017-7459
    30Monitor

    ntopng before 3.0 allows HTTP Response Splitting.

    HighCVSS 7.5No exploitEPSS 1%

    ntop · ntopngJun 26, 2017

  • CVE-2015-8368
    26Monitor

    ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and usern

    MediumCVSS 6.0Proof of conceptEPSS 5%

    ntop · ntopngDec 17, 2015

  • CVE-2017-7416
    24Monitor

    ntopng before 3.0 allows XSS because GET and POST parameters are improperly validated.

    MediumCVSS 6.1No exploitEPSS 1%

    ntop · ntopngJun 26, 2017

  • A heap-buffer-overflow vulnerability has been identified in ntopng 6.2 in the Flow::dissectMDNS function.

    MediumCVSS 6.2No exploitEPSS 0%

    Nov 21, 2024

  • CVE-2009-2732
    22Monitor

    The checkHTTPpassword function in http.c in ntop 3.3.10 and earlier allows remote attackers to cause a denial of service (NULL pointer deref

    MediumCVSS 5.0Proof of conceptEPSS 7%

    ntop · ntopAug 21, 2009

  • CVE-2014-5464
    18Monitor

    Cross-site scripting (XSS) vulnerability in the nDPI traffic classification library in ntopng (aka ntop) before 1.2.1 allows remote attacker

    MediumCVSS 4.3Proof of conceptEPSS 4%

    ntop · ntopngSep 8, 2014

  • CVE-2014-4165
    18Monitor

    Cross-site scripting (XSS) vulnerability in ntop allows remote attackers to inject arbitrary web script or HTML via the title parameter in a

    MediumCVSS 4.3No exploitEPSS 2%

    ntop · ntopJun 16, 2014

  • CVE-2014-4329
    17Monitor

    Cross-site scripting (XSS) vulnerability in lua/host_details.lua in ntopng 1.1 allows remote attackers to inject arbitrary web script or HTM

    MediumCVSS 4.3No exploitEPSS 1%

    ntop · ntopngJun 19, 2014