İçeriğe atla
Noroxi

ntop kayıtları

ntop üreticisine ait 22 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
1
Düzeltme kaydı olan
%59,1
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

22 kayıt
  • CVE-2020-11939
    40Planlayın

    In nDPI through 3.2 Stable, the SSH protocol dissector has multiple KEXINIT integer overflows that result in a controlled remote heap overfl

    KritikCVSS 9,8İstismar yokEPSS %3

    ntop · ndpi23 Nis 2020

  • CVE-2020-15475
    39İzleyin

    In nDPI through 3.2, ndpi_reset_packet_line_info in lib/ndpi_main.c omits certain reinitialization, leading to a use-after-free.

    KritikCVSS 9,8İstismar yokEPSS %1

    ntop · ndpi1 Tem 2020

  • CVE-2020-15474
    39İzleyin

    In nDPI through 3.2, there is a stack overflow in extractRDNSequence in lib/protocols/tls.c.

    KritikCVSS 9,8İstismar yokEPSS %1

    ntop · ndpi1 Tem 2020

  • CVE-2026-38968
    39İzleyin

    ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking.

    KritikCVSS 9,8İstismar yokEPSS %1

    ntop · ntopng2 Tem 2026

  • CVE-2017-5473
    36İzleyin

    Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authentication of arbitrary user

    YüksekCVSS 8,8Kavram kanıtıEPSS %4

    ntop · ntopng14 Oca 2017

  • CVE-2021-36082
    36İzleyin

    ntop nDPI 3.4 has a stack-based buffer overflow in processClientServerHello.

    YüksekCVSS 8,8İstismar yokEPSS %2

    ntop · ndpi30 Haz 2021

  • CVE-2020-15472
    36İzleyin

    In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/protocols/h323.c, as demo

    KritikCVSS 9,1İstismar yokEPSS %1

    ntop · ndpi1 Tem 2020

  • CVE-2020-15473
    36İzleyin

    In nDPI through 3.2, the OpenVPN dissector is vulnerable to a heap-based buffer over-read in ndpi_search_openvpn in lib/protocols/openvpn.c.

    KritikCVSS 9,1İstismar yokEPSS %1

    ntop · ndpi1 Tem 2020

  • CVE-2020-15471
    36İzleyin

    In nDPI through 3.2, the packet parsing code is vulnerable to a heap-based buffer over-read in ndpi_parse_packet_line_info in lib/ndpi_main.

    KritikCVSS 9,1İstismar yokEPSS %1

    ntop · ndpi1 Tem 2020

  • CVE-2018-12520
    35İzleyin

    An issue was discovered in ntopng 3.4 before 3.4.180617.

    YüksekCVSS 8,1Kavram kanıtıEPSS %11

    ntop · ntopng5 Tem 2018

  • CVE-2025-25066
    33İzleyin

    nDPI through 4.12 has a potential stack-based buffer overflow in ndpi_address_cache_restore in lib/ndpi_cache.c.

    YüksekCVSS 8,4İstismar yokEPSS %0

    ntop · ndpi3 Şub 2025

  • CVE-2020-15476
    31İzleyin

    In nDPI through 3.2, the Oracle protocol dissector has a heap-based buffer over-read in ndpi_search_oracle in lib/protocols/oracle.c.

    YüksekCVSS 7,5İstismar yokEPSS %2

    ntop · ndpi1 Tem 2020

  • CVE-2017-7458
    31İzleyin

    The NetworkInterface::getHost function in NetworkInterface.cpp in ntopng before 3.0 allows remote attackers to cause a denial of service (NU

    YüksekCVSS 7,5İstismar yokEPSS %2

    ntop · ntopng26 Haz 2017

  • CVE-2020-11940
    30İzleyin

    In nDPI through 3.2 Stable, an out-of-bounds read in concat_hash_string in ssh.c can be exploited by a network-positioned attacker that can

    YüksekCVSS 7,5İstismar yokEPSS %1

    ntop · ndpi23 Nis 2020

  • CVE-2017-7459
    30İzleyin

    ntopng before 3.0 allows HTTP Response Splitting.

    YüksekCVSS 7,5İstismar yokEPSS %1

    ntop · ntopng26 Haz 2017

  • CVE-2015-8368
    26İzleyin

    ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and usern

    OrtaCVSS 6,0Kavram kanıtıEPSS %5

    ntop · ntopng17 Ara 2015

  • CVE-2017-7416
    24İzleyin

    ntopng before 3.0 allows XSS because GET and POST parameters are improperly validated.

    OrtaCVSS 6,1İstismar yokEPSS %1

    ntop · ntopng26 Haz 2017

  • CVE-2024-53426
    24İzleyin

    A heap-buffer-overflow vulnerability has been identified in ntopng 6.2 in the Flow::dissectMDNS function.

    OrtaCVSS 6,2İstismar yokEPSS %0

    21 Kas 2024

  • CVE-2009-2732
    22İzleyin

    The checkHTTPpassword function in http.c in ntop 3.3.10 and earlier allows remote attackers to cause a denial of service (NULL pointer deref

    OrtaCVSS 5,0Kavram kanıtıEPSS %7

    ntop · ntop21 Ağu 2009

  • CVE-2014-5464
    18İzleyin

    Cross-site scripting (XSS) vulnerability in the nDPI traffic classification library in ntopng (aka ntop) before 1.2.1 allows remote attacker

    OrtaCVSS 4,3Kavram kanıtıEPSS %4

    ntop · ntopng8 Eyl 2014

  • CVE-2014-4165
    18İzleyin

    Cross-site scripting (XSS) vulnerability in ntop allows remote attackers to inject arbitrary web script or HTML via the title parameter in a

    OrtaCVSS 4,3İstismar yokEPSS %2

    ntop · ntop16 Haz 2014

  • CVE-2014-4329
    17İzleyin

    Cross-site scripting (XSS) vulnerability in lua/host_details.lua in ntopng 1.1 allows remote attackers to inject arbitrary web script or HTM

    OrtaCVSS 4,3İstismar yokEPSS %1

    ntop · ntopng19 Haz 2014