ntop kayıtları
ntop üreticisine ait 22 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %59,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-125 Out-of-bounds Read5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-787 Out-of-bounds Write2
- CWE-190 Integer Overflow or Wraparound1
- CWE-254 7PK - Security Features1
- CWE-335 Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
22 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2020-11939İstismar yok | In nDPI through 3.2 Stable, the SSH protocol dissector has multiple KEXINIT integer overflows that result in a controlled remote heap overflntop · ndpi · CWE-190 | Kritik9,8 | — | %3,3 | 23 Nis 2020 |
39İzleyin | CVE-2020-15475İstismar yok | In nDPI through 3.2, ndpi_reset_packet_line_info in lib/ndpi_main.c omits certain reinitialization, leading to a use-after-free.ntop · ndpi · CWE-416 | Kritik9,8 | — | %1,2 | 1 Tem 2020 |
39İzleyin | CVE-2020-15474İstismar yok | In nDPI through 3.2, there is a stack overflow in extractRDNSequence in lib/protocols/tls.c.ntop · ndpi · CWE-787 | Kritik9,8 | — | %1,2 | 1 Tem 2020 |
39İzleyin | CVE-2026-38968İstismar yok | ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking.ntop · ntopng · CWE-341 | Kritik9,8 | — | %0,6 | 2 Tem 2026 |
36İzleyin | CVE-2017-5473Kavram kanıtı | Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authentication of arbitrary userntop · ntopng · CWE-352 | Yüksek8,8 | — | %3,6 | 14 Oca 2017 |
36İzleyin | CVE-2021-36082İstismar yok | ntop nDPI 3.4 has a stack-based buffer overflow in processClientServerHello.ntop · ndpi · CWE-787 | Yüksek8,8 | — | %1,8 | 30 Haz 2021 |
36İzleyin | CVE-2020-15472İstismar yok | In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/protocols/h323.c, as demontop · ndpi · CWE-125 | Kritik9,1 | — | %1,5 | 1 Tem 2020 |
36İzleyin | CVE-2020-15473İstismar yok | In nDPI through 3.2, the OpenVPN dissector is vulnerable to a heap-based buffer over-read in ndpi_search_openvpn in lib/protocols/openvpn.c.ntop · ndpi · CWE-125 | Kritik9,1 | — | %1,3 | 1 Tem 2020 |
36İzleyin | CVE-2020-15471İstismar yok | In nDPI through 3.2, the packet parsing code is vulnerable to a heap-based buffer over-read in ndpi_parse_packet_line_info in lib/ndpi_main.ntop · ndpi · CWE-125 | Kritik9,1 | — | %1,3 | 1 Tem 2020 |
35İzleyin | CVE-2018-12520Kavram kanıtı | An issue was discovered in ntopng 3.4 before 3.4.180617.ntop · ntopng · CWE-335 | Yüksek8,1 | — | %10,5 | 5 Tem 2018 |
33İzleyin | CVE-2025-25066İstismar yok | nDPI through 4.12 has a potential stack-based buffer overflow in ndpi_address_cache_restore in lib/ndpi_cache.c.ntop · ndpi · CWE-121 | Yüksek8,4 | — | %0,2 | 3 Şub 2025 |
31İzleyin | CVE-2020-15476İstismar yok | In nDPI through 3.2, the Oracle protocol dissector has a heap-based buffer over-read in ndpi_search_oracle in lib/protocols/oracle.c.ntop · ndpi · CWE-125 | Yüksek7,5 | — | %2,1 | 1 Tem 2020 |
31İzleyin | CVE-2017-7458İstismar yok | The NetworkInterface::getHost function in NetworkInterface.cpp in ntopng before 3.0 allows remote attackers to cause a denial of service (NUntop · ntopng · CWE-476 | Yüksek7,5 | — | %1,9 | 26 Haz 2017 |
30İzleyin | CVE-2020-11940İstismar yok | In nDPI through 3.2 Stable, an out-of-bounds read in concat_hash_string in ssh.c can be exploited by a network-positioned attacker that can ntop · ndpi · CWE-125 | Yüksek7,5 | — | %1,3 | 23 Nis 2020 |
30İzleyin | CVE-2017-7459İstismar yok | ntopng before 3.0 allows HTTP Response Splitting.ntop · ntopng · CWE-74 | Yüksek7,5 | — | %0,9 | 26 Haz 2017 |
26İzleyin | CVE-2015-8368Kavram kanıtı | ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and usernntop · ntopng · CWE-254 | Orta6,0 | — | %5,1 | 17 Ara 2015 |
24İzleyin | CVE-2017-7416İstismar yok | ntopng before 3.0 allows XSS because GET and POST parameters are improperly validated.ntop · ntopng · CWE-79 | Orta6,1 | — | %0,6 | 26 Haz 2017 |
24İzleyin | CVE-2024-53426İstismar yok | A heap-buffer-overflow vulnerability has been identified in ntopng 6.2 in the Flow::dissectMDNS function.CWE-120 | Orta6,2 | — | %0,3 | 21 Kas 2024 |
22İzleyin | CVE-2009-2732Kavram kanıtı | The checkHTTPpassword function in http.c in ntop 3.3.10 and earlier allows remote attackers to cause a denial of service (NULL pointer derefntop · ntop · CWE-119 | Orta5,0 | — | %7,3 | 21 Ağu 2009 |
18İzleyin | CVE-2014-5464Kavram kanıtı | Cross-site scripting (XSS) vulnerability in the nDPI traffic classification library in ntopng (aka ntop) before 1.2.1 allows remote attackerntop · ntopng · CWE-79 | Orta4,3 | — | %4,5 | 8 Eyl 2014 |
18İzleyin | CVE-2014-4165İstismar yok | Cross-site scripting (XSS) vulnerability in ntop allows remote attackers to inject arbitrary web script or HTML via the title parameter in antop · ntop · CWE-79 | Orta4,3 | — | %2,1 | 16 Haz 2014 |
17İzleyin | CVE-2014-4329İstismar yok | Cross-site scripting (XSS) vulnerability in lua/host_details.lua in ntopng 1.1 allows remote attackers to inject arbitrary web script or HTMntop · ntopng · CWE-79 | Orta4,3 | — | %1,2 | 19 Haz 2014 |
- CVE-2020-1193940Planlayın
In nDPI through 3.2 Stable, the SSH protocol dissector has multiple KEXINIT integer overflows that result in a controlled remote heap overfl
KritikCVSS 9,8İstismar yokEPSS %3ntop · ndpi23 Nis 2020
- CVE-2020-1547539İzleyin
In nDPI through 3.2, ndpi_reset_packet_line_info in lib/ndpi_main.c omits certain reinitialization, leading to a use-after-free.
KritikCVSS 9,8İstismar yokEPSS %1ntop · ndpi1 Tem 2020
- CVE-2020-1547439İzleyin
In nDPI through 3.2, there is a stack overflow in extractRDNSequence in lib/protocols/tls.c.
KritikCVSS 9,8İstismar yokEPSS %1ntop · ndpi1 Tem 2020
- CVE-2026-3896839İzleyin
ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking.
KritikCVSS 9,8İstismar yokEPSS %1ntop · ntopng2 Tem 2026
- CVE-2017-547336İzleyin
Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authentication of arbitrary user
YüksekCVSS 8,8Kavram kanıtıEPSS %4ntop · ntopng14 Oca 2017
- CVE-2021-3608236İzleyin
ntop nDPI 3.4 has a stack-based buffer overflow in processClientServerHello.
YüksekCVSS 8,8İstismar yokEPSS %2ntop · ndpi30 Haz 2021
- CVE-2020-1547236İzleyin
In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/protocols/h323.c, as demo
KritikCVSS 9,1İstismar yokEPSS %1ntop · ndpi1 Tem 2020
- CVE-2020-1547336İzleyin
In nDPI through 3.2, the OpenVPN dissector is vulnerable to a heap-based buffer over-read in ndpi_search_openvpn in lib/protocols/openvpn.c.
KritikCVSS 9,1İstismar yokEPSS %1ntop · ndpi1 Tem 2020
- CVE-2020-1547136İzleyin
In nDPI through 3.2, the packet parsing code is vulnerable to a heap-based buffer over-read in ndpi_parse_packet_line_info in lib/ndpi_main.
KritikCVSS 9,1İstismar yokEPSS %1ntop · ndpi1 Tem 2020
- CVE-2018-1252035İzleyin
An issue was discovered in ntopng 3.4 before 3.4.180617.
YüksekCVSS 8,1Kavram kanıtıEPSS %11ntop · ntopng5 Tem 2018
- CVE-2025-2506633İzleyin
nDPI through 4.12 has a potential stack-based buffer overflow in ndpi_address_cache_restore in lib/ndpi_cache.c.
YüksekCVSS 8,4İstismar yokEPSS %0ntop · ndpi3 Şub 2025
- CVE-2020-1547631İzleyin
In nDPI through 3.2, the Oracle protocol dissector has a heap-based buffer over-read in ndpi_search_oracle in lib/protocols/oracle.c.
YüksekCVSS 7,5İstismar yokEPSS %2ntop · ndpi1 Tem 2020
- CVE-2017-745831İzleyin
The NetworkInterface::getHost function in NetworkInterface.cpp in ntopng before 3.0 allows remote attackers to cause a denial of service (NU
YüksekCVSS 7,5İstismar yokEPSS %2ntop · ntopng26 Haz 2017
- CVE-2020-1194030İzleyin
In nDPI through 3.2 Stable, an out-of-bounds read in concat_hash_string in ssh.c can be exploited by a network-positioned attacker that can
YüksekCVSS 7,5İstismar yokEPSS %1ntop · ndpi23 Nis 2020
- CVE-2017-745930İzleyin
ntopng before 3.0 allows HTTP Response Splitting.
YüksekCVSS 7,5İstismar yokEPSS %1ntop · ntopng26 Haz 2017
- CVE-2015-836826İzleyin
ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and usern
OrtaCVSS 6,0Kavram kanıtıEPSS %5ntop · ntopng17 Ara 2015
- CVE-2017-741624İzleyin
ntopng before 3.0 allows XSS because GET and POST parameters are improperly validated.
OrtaCVSS 6,1İstismar yokEPSS %1ntop · ntopng26 Haz 2017
- CVE-2024-5342624İzleyin
A heap-buffer-overflow vulnerability has been identified in ntopng 6.2 in the Flow::dissectMDNS function.
OrtaCVSS 6,2İstismar yokEPSS %021 Kas 2024
- CVE-2009-273222İzleyin
The checkHTTPpassword function in http.c in ntop 3.3.10 and earlier allows remote attackers to cause a denial of service (NULL pointer deref
OrtaCVSS 5,0Kavram kanıtıEPSS %7ntop · ntop21 Ağu 2009
- CVE-2014-546418İzleyin
Cross-site scripting (XSS) vulnerability in the nDPI traffic classification library in ntopng (aka ntop) before 1.2.1 allows remote attacker
OrtaCVSS 4,3Kavram kanıtıEPSS %4ntop · ntopng8 Eyl 2014
- CVE-2014-416518İzleyin
Cross-site scripting (XSS) vulnerability in ntop allows remote attackers to inject arbitrary web script or HTML via the title parameter in a
OrtaCVSS 4,3İstismar yokEPSS %2ntop · ntop16 Haz 2014
- CVE-2014-432917İzleyin
Cross-site scripting (XSS) vulnerability in lua/host_details.lua in ntopng 1.1 allows remote attackers to inject arbitrary web script or HTM
OrtaCVSS 4,3İstismar yokEPSS %1ntop · ntopng19 Haz 2014