Записи ntop
22 опубликованных записей вендора ntop.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 59,1 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-125 Out-of-bounds Read5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-787 Out-of-bounds Write2
- CWE-190 Integer Overflow or Wraparound1
- CWE-254 7PK - Security Features1
- CWE-335 Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
22 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2020-11939Эксплойта нет | In nDPI through 3.2 Stable, the SSH protocol dissector has multiple KEXINIT integer overflows that result in a controlled remote heap overflntop · ndpi · CWE-190 | Критическая9,8 | — | 3,3 % | 23 апр. 2020 г. |
39Наблюдать | CVE-2020-15475Эксплойта нет | In nDPI through 3.2, ndpi_reset_packet_line_info in lib/ndpi_main.c omits certain reinitialization, leading to a use-after-free.ntop · ndpi · CWE-416 | Критическая9,8 | — | 1,2 % | 1 июл. 2020 г. |
39Наблюдать | CVE-2020-15474Эксплойта нет | In nDPI through 3.2, there is a stack overflow in extractRDNSequence in lib/protocols/tls.c.ntop · ndpi · CWE-787 | Критическая9,8 | — | 1,2 % | 1 июл. 2020 г. |
39Наблюдать | CVE-2026-38968Эксплойта нет | ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking.ntop · ntopng · CWE-341 | Критическая9,8 | — | 0,6 % | 2 июл. 2026 г. |
36Наблюдать | CVE-2017-5473Proof of concept | Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authentication of arbitrary userntop · ntopng · CWE-352 | Высокая8,8 | — | 3,6 % | 14 янв. 2017 г. |
36Наблюдать | CVE-2021-36082Эксплойта нет | ntop nDPI 3.4 has a stack-based buffer overflow in processClientServerHello.ntop · ndpi · CWE-787 | Высокая8,8 | — | 1,8 % | 30 июн. 2021 г. |
36Наблюдать | CVE-2020-15472Эксплойта нет | In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/protocols/h323.c, as demontop · ndpi · CWE-125 | Критическая9,1 | — | 1,5 % | 1 июл. 2020 г. |
36Наблюдать | CVE-2020-15473Эксплойта нет | In nDPI through 3.2, the OpenVPN dissector is vulnerable to a heap-based buffer over-read in ndpi_search_openvpn in lib/protocols/openvpn.c.ntop · ndpi · CWE-125 | Критическая9,1 | — | 1,3 % | 1 июл. 2020 г. |
36Наблюдать | CVE-2020-15471Эксплойта нет | In nDPI through 3.2, the packet parsing code is vulnerable to a heap-based buffer over-read in ndpi_parse_packet_line_info in lib/ndpi_main.ntop · ndpi · CWE-125 | Критическая9,1 | — | 1,3 % | 1 июл. 2020 г. |
35Наблюдать | CVE-2018-12520Proof of concept | An issue was discovered in ntopng 3.4 before 3.4.180617.ntop · ntopng · CWE-335 | Высокая8,1 | — | 10,5 % | 5 июл. 2018 г. |
33Наблюдать | CVE-2025-25066Эксплойта нет | nDPI through 4.12 has a potential stack-based buffer overflow in ndpi_address_cache_restore in lib/ndpi_cache.c.ntop · ndpi · CWE-121 | Высокая8,4 | — | 0,2 % | 3 февр. 2025 г. |
31Наблюдать | CVE-2020-15476Эксплойта нет | In nDPI through 3.2, the Oracle protocol dissector has a heap-based buffer over-read in ndpi_search_oracle in lib/protocols/oracle.c.ntop · ndpi · CWE-125 | Высокая7,5 | — | 2,1 % | 1 июл. 2020 г. |
31Наблюдать | CVE-2017-7458Эксплойта нет | The NetworkInterface::getHost function in NetworkInterface.cpp in ntopng before 3.0 allows remote attackers to cause a denial of service (NUntop · ntopng · CWE-476 | Высокая7,5 | — | 1,9 % | 26 июн. 2017 г. |
30Наблюдать | CVE-2020-11940Эксплойта нет | In nDPI through 3.2 Stable, an out-of-bounds read in concat_hash_string in ssh.c can be exploited by a network-positioned attacker that can ntop · ndpi · CWE-125 | Высокая7,5 | — | 1,3 % | 23 апр. 2020 г. |
30Наблюдать | CVE-2017-7459Эксплойта нет | ntopng before 3.0 allows HTTP Response Splitting.ntop · ntopng · CWE-74 | Высокая7,5 | — | 0,9 % | 26 июн. 2017 г. |
26Наблюдать | CVE-2015-8368Proof of concept | ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and usernntop · ntopng · CWE-254 | Средняя6,0 | — | 5,1 % | 17 дек. 2015 г. |
24Наблюдать | CVE-2017-7416Эксплойта нет | ntopng before 3.0 allows XSS because GET and POST parameters are improperly validated.ntop · ntopng · CWE-79 | Средняя6,1 | — | 0,6 % | 26 июн. 2017 г. |
24Наблюдать | CVE-2024-53426Эксплойта нет | A heap-buffer-overflow vulnerability has been identified in ntopng 6.2 in the Flow::dissectMDNS function.CWE-120 | Средняя6,2 | — | 0,3 % | 21 нояб. 2024 г. |
22Наблюдать | CVE-2009-2732Proof of concept | The checkHTTPpassword function in http.c in ntop 3.3.10 and earlier allows remote attackers to cause a denial of service (NULL pointer derefntop · ntop · CWE-119 | Средняя5,0 | — | 7,3 % | 21 авг. 2009 г. |
18Наблюдать | CVE-2014-5464Proof of concept | Cross-site scripting (XSS) vulnerability in the nDPI traffic classification library in ntopng (aka ntop) before 1.2.1 allows remote attackerntop · ntopng · CWE-79 | Средняя4,3 | — | 4,5 % | 8 сент. 2014 г. |
18Наблюдать | CVE-2014-4165Эксплойта нет | Cross-site scripting (XSS) vulnerability in ntop allows remote attackers to inject arbitrary web script or HTML via the title parameter in antop · ntop · CWE-79 | Средняя4,3 | — | 2,1 % | 16 июн. 2014 г. |
17Наблюдать | CVE-2014-4329Эксплойта нет | Cross-site scripting (XSS) vulnerability in lua/host_details.lua in ntopng 1.1 allows remote attackers to inject arbitrary web script or HTMntop · ntopng · CWE-79 | Средняя4,3 | — | 1,2 % | 19 июн. 2014 г. |
- CVE-2020-1193940В плане
In nDPI through 3.2 Stable, the SSH protocol dissector has multiple KEXINIT integer overflows that result in a controlled remote heap overfl
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %ntop · ndpi23 апр. 2020 г.
- CVE-2020-1547539Наблюдать
In nDPI through 3.2, ndpi_reset_packet_line_info in lib/ndpi_main.c omits certain reinitialization, leading to a use-after-free.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ntop · ndpi1 июл. 2020 г.
- CVE-2020-1547439Наблюдать
In nDPI through 3.2, there is a stack overflow in extractRDNSequence in lib/protocols/tls.c.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ntop · ndpi1 июл. 2020 г.
- CVE-2026-3896839Наблюдать
ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ntop · ntopng2 июл. 2026 г.
- CVE-2017-547336Наблюдать
Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authentication of arbitrary user
ВысокаяCVSS 8,8Proof of conceptEPSS 4 %ntop · ntopng14 янв. 2017 г.
- CVE-2021-3608236Наблюдать
ntop nDPI 3.4 has a stack-based buffer overflow in processClientServerHello.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %ntop · ndpi30 июн. 2021 г.
- CVE-2020-1547236Наблюдать
In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/protocols/h323.c, as demo
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %ntop · ndpi1 июл. 2020 г.
- CVE-2020-1547336Наблюдать
In nDPI through 3.2, the OpenVPN dissector is vulnerable to a heap-based buffer over-read in ndpi_search_openvpn in lib/protocols/openvpn.c.
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %ntop · ndpi1 июл. 2020 г.
- CVE-2020-1547136Наблюдать
In nDPI through 3.2, the packet parsing code is vulnerable to a heap-based buffer over-read in ndpi_parse_packet_line_info in lib/ndpi_main.
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %ntop · ndpi1 июл. 2020 г.
- CVE-2018-1252035Наблюдать
An issue was discovered in ntopng 3.4 before 3.4.180617.
ВысокаяCVSS 8,1Proof of conceptEPSS 11 %ntop · ntopng5 июл. 2018 г.
- CVE-2025-2506633Наблюдать
nDPI through 4.12 has a potential stack-based buffer overflow in ndpi_address_cache_restore in lib/ndpi_cache.c.
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %ntop · ndpi3 февр. 2025 г.
- CVE-2020-1547631Наблюдать
In nDPI through 3.2, the Oracle protocol dissector has a heap-based buffer over-read in ndpi_search_oracle in lib/protocols/oracle.c.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %ntop · ndpi1 июл. 2020 г.
- CVE-2017-745831Наблюдать
The NetworkInterface::getHost function in NetworkInterface.cpp in ntopng before 3.0 allows remote attackers to cause a denial of service (NU
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %ntop · ntopng26 июн. 2017 г.
- CVE-2020-1194030Наблюдать
In nDPI through 3.2 Stable, an out-of-bounds read in concat_hash_string in ssh.c can be exploited by a network-positioned attacker that can
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %ntop · ndpi23 апр. 2020 г.
- CVE-2017-745930Наблюдать
ntopng before 3.0 allows HTTP Response Splitting.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %ntop · ntopng26 июн. 2017 г.
- CVE-2015-836826Наблюдать
ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and usern
СредняяCVSS 6,0Proof of conceptEPSS 5 %ntop · ntopng17 дек. 2015 г.
- CVE-2017-741624Наблюдать
ntopng before 3.0 allows XSS because GET and POST parameters are improperly validated.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %ntop · ntopng26 июн. 2017 г.
- CVE-2024-5342624Наблюдать
A heap-buffer-overflow vulnerability has been identified in ntopng 6.2 in the Flow::dissectMDNS function.
СредняяCVSS 6,2Эксплойта нетEPSS 0 %21 нояб. 2024 г.
- CVE-2009-273222Наблюдать
The checkHTTPpassword function in http.c in ntop 3.3.10 and earlier allows remote attackers to cause a denial of service (NULL pointer deref
СредняяCVSS 5,0Proof of conceptEPSS 7 %ntop · ntop21 авг. 2009 г.
- CVE-2014-546418Наблюдать
Cross-site scripting (XSS) vulnerability in the nDPI traffic classification library in ntopng (aka ntop) before 1.2.1 allows remote attacker
СредняяCVSS 4,3Proof of conceptEPSS 4 %ntop · ntopng8 сент. 2014 г.
- CVE-2014-416518Наблюдать
Cross-site scripting (XSS) vulnerability in ntop allows remote attackers to inject arbitrary web script or HTML via the title parameter in a
СредняяCVSS 4,3Эксплойта нетEPSS 2 %ntop · ntop16 июн. 2014 г.
- CVE-2014-432917Наблюдать
Cross-site scripting (XSS) vulnerability in lua/host_details.lua in ntopng 1.1 allows remote attackers to inject arbitrary web script or HTM
СредняяCVSS 4,3Эксплойта нетEPSS 1 %ntop · ntopng19 июн. 2014 г.