Vulnerabilities > Ntop > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-07-01 CVE-2021-36082 Out-of-bounds Write vulnerability in Ntop Ndpi 3.4
ntop nDPI 3.4 has a stack-based buffer overflow in processClientServerHello.
network
ntop CWE-787
6.8
2020-07-01 CVE-2020-15476 Out-of-bounds Read vulnerability in multiple products
In nDPI through 3.2, the Oracle protocol dissector has a heap-based buffer over-read in ndpi_search_oracle in lib/protocols/oracle.c.
network
low complexity
ntop debian CWE-125
5.0
2020-07-01 CVE-2020-15473 Out-of-bounds Read vulnerability in Ntop Ndpi
In nDPI through 3.2, the OpenVPN dissector is vulnerable to a heap-based buffer over-read in ndpi_search_openvpn in lib/protocols/openvpn.c.
network
low complexity
ntop CWE-125
6.4
2020-07-01 CVE-2020-15472 Out-of-bounds Read vulnerability in multiple products
In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/protocols/h323.c, as demonstrated by a payload packet length that is too short.
network
low complexity
ntop debian CWE-125
6.4
2020-07-01 CVE-2020-15471 Out-of-bounds Read vulnerability in Ntop Ndpi
In nDPI through 3.2, the packet parsing code is vulnerable to a heap-based buffer over-read in ndpi_parse_packet_line_info in lib/ndpi_main.c.
network
low complexity
ntop CWE-125
6.4
2020-04-23 CVE-2020-11940 Out-of-bounds Read vulnerability in Ntop Ndpi
In nDPI through 3.2 Stable, an out-of-bounds read in concat_hash_string in ssh.c can be exploited by a network-positioned attacker that can send malformed SSH protocol messages on a network segment monitored by nDPI's library.
network
low complexity
ntop CWE-125
5.0
2017-06-26 CVE-2017-7458 NULL Pointer Dereference vulnerability in Ntop Ntopng
The NetworkInterface::getHost function in NetworkInterface.cpp in ntopng before 3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty field that should have contained a hostname or IP address.
network
low complexity
ntop CWE-476
5.0
2017-06-26 CVE-2017-7459 Injection vulnerability in Ntop Ntopng
ntopng before 3.0 allows HTTP Response Splitting.
network
low complexity
ntop CWE-74
5.0
2017-06-26 CVE-2017-7416 Cross-site Scripting vulnerability in Ntop Ntopng
ntopng before 3.0 allows XSS because GET and POST parameters are improperly validated.
network
ntop CWE-79
4.3
2017-01-14 CVE-2017-5473 Cross-Site Request Forgery (CSRF) vulnerability in Ntop Ntopng
Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authentication of arbitrary users, as demonstrated by admin/add_user.lua, admin/change_user_prefs.lua, admin/delete_user.lua, and admin/password_reset.lua.
network
ntop CWE-352
6.8