Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ntopng CRITICAL 9.8
CVE-2026-38968

ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cp…

Fix: after 6.6
Fix from $2,300 2026-07-02
Ndpi HIGH 8.4
CVE-2025-25066

nDPI through 4.12 has a potential stack-based buffer overflow in ndpi_address_cache_restore in lib/ndpi_cache.c.

Fix: after 4.12
Fix from $1,950 2025-02-03
Ndpi HIGH 8.8
CVE-2021-36082

ntop nDPI 3.4 has a stack-based buffer overflow in processClientServerHello.

Patch available
Fix from $1,950 2021-07-01
Ndpi CRITICAL 9.8
CVE-2020-15474

In nDPI through 3.2, there is a stack overflow in extractRDNSequence in lib/protocols/tls.c.

Fix: after 3.2
Fix from $2,300 2020-07-01
Ndpi CRITICAL 9.8
CVE-2020-15475

In nDPI through 3.2, ndpi_reset_packet_line_info in lib/ndpi_main.c omits certain reinitialization, leading to a use-after-free.

Fix: after 3.2
Fix from $2,300 2020-07-01
Ndpi CRITICAL 9.1
CVE-2020-15471

In nDPI through 3.2, the packet parsing code is vulnerable to a heap-based buffer over-read in ndpi_parse_packet_line_info in lib/ndpi_main.c.

Fix: after 3.2
Fix from $2,300 2020-07-01
Ndpi CRITICAL 9.1
CVE-2020-15473

In nDPI through 3.2, the OpenVPN dissector is vulnerable to a heap-based buffer over-read in ndpi_search_openvpn in lib/protocols/openvpn.c.

Fix: after 3.2
Fix from $2,300 2020-07-01
Ndpi CRITICAL 9.8
CVE-2020-11939

In nDPI through 3.2 Stable, the SSH protocol dissector has multiple KEXINIT integer overflows that result in a controlled remote heap overflow in con…

Fix: after 3.2
Fix from $2,300 2020-04-23
Ndpi HIGH 7.5
CVE-2020-11940

In nDPI through 3.2 Stable, an out-of-bounds read in concat_hash_string in ssh.c can be exploited by a network-positioned attacker that can send malf…

Fix: after 3.2
Fix from $1,950 2020-04-23
Ntopng HIGH 8.1
CVE-2018-12520EPSS 11%

An issue was discovered in ntopng 3.4 before 3.4.180617. The PRNG involved in the generation of session IDs is not seeded at program startup. This re…

Fix: 3.4.180617+
Fix from $1,950 2018-07-05
Ntopng HIGH 7.5
CVE-2017-7458

The NetworkInterface::getHost function in NetworkInterface.cpp in ntopng before 3.0 allows remote attackers to cause a denial of service (NULL pointe…

Fix: after 2.4
Fix from $1,950 2017-06-26
Ntopng HIGH 7.5
CVE-2017-7459

ntopng before 3.0 allows HTTP Response Splitting.

Fix: after 2.4
Fix from $1,950 2017-06-26
Ntopng MEDIUM 6.1
CVE-2017-7416

ntopng before 3.0 allows XSS because GET and POST parameters are improperly validated.

Fix: after 2.4
Fix from $1,600 2017-06-26
Ntopng HIGH 8.8
CVE-2017-5473

Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authentication of arbitrary users, as dem…

Fix: after 2.4
Fix from $1,950 2017-01-14
Ntopng MEDIUM 6.0
CVE-2015-8368EPSS 5%

ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and username param…

Fix: after 2.0.151021
Fix from $1,600 2015-12-17
Ntop MEDIUM 5.0
CVE-2009-2732EPSS 7%

The checkHTTPpassword function in http.c in ntop 3.3.10 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference an…

Fix: after 3.3.10
Fix from $1,600 2009-08-21