Ntop
Ntop Ndpi: vulnerabilidades y CVE
Ntop Ndpi tiene 12 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses2
Críticas6
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-88357 | Alta (7.5) | 0.60% | — | 24 sept 2026 | nDPI 5.1.0 contains a memory access issue in the DNS dissector and serializer deserialization code. Specially crafted network input can cause byte-buffer addresses at odd offsets to be cast to uint16_t or wider integer… |
| CVE-2026-86098 | Alta (8.3) | 0.59% | — | 4 sept 2026 | ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi_json_string_escape function that writes beyond caller-supplied buffer boundaries. Attackers can trigger the overflow by supplying… |
| CVE-2025-25066 | Alta (8.4) | 0.18% | — | 3 feb 2025 | nDPI through 4.12 has a potential stack-based buffer overflow in ndpi_address_cache_restore in lib/ndpi_cache.c. |
| CVE-2021-36082 | Alta (8.8) | 1.8% | — | 1 jul 2021 | ntop nDPI 3.4 has a stack-based buffer overflow in processClientServerHello. |
| CVE-2020-15476 | Alta (7.5) | 2.1% | — | 1 jul 2020 | In nDPI through 3.2, the Oracle protocol dissector has a heap-based buffer over-read in ndpi_search_oracle in lib/protocols/oracle.c. |
| CVE-2020-15475 | Crítica (9.8) | 1.2% | — | 1 jul 2020 | In nDPI through 3.2, ndpi_reset_packet_line_info in lib/ndpi_main.c omits certain reinitialization, leading to a use-after-free. |
| CVE-2020-15474 | Crítica (9.8) | 1.2% | — | 1 jul 2020 | In nDPI through 3.2, there is a stack overflow in extractRDNSequence in lib/protocols/tls.c. |
| CVE-2020-15473 | Crítica (9.1) | 1.3% | — | 1 jul 2020 | In nDPI through 3.2, the OpenVPN dissector is vulnerable to a heap-based buffer over-read in ndpi_search_openvpn in lib/protocols/openvpn.c. |
| CVE-2020-15472 | Crítica (9.1) | 1.5% | — | 1 jul 2020 | In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/protocols/h323.c, as demonstrated by a payload packet length that is too short. |
| CVE-2020-15471 | Crítica (9.1) | 1.3% | — | 1 jul 2020 | In nDPI through 3.2, the packet parsing code is vulnerable to a heap-based buffer over-read in ndpi_parse_packet_line_info in lib/ndpi_main.c. |
| CVE-2020-11940 | Alta (7.5) | 1.3% | — | 23 abr 2020 | In nDPI through 3.2 Stable, an out-of-bounds read in concat_hash_string in ssh.c can be exploited by a network-positioned attacker that can send malformed SSH protocol messages on a network segment monitored by nDPI's… |
| CVE-2020-11939 | Crítica (9.8) | 3.3% | — | 23 abr 2020 | In nDPI through 3.2 Stable, the SSH protocol dissector has multiple KEXINIT integer overflows that result in a controlled remote heap overflow in concat_hash_string in ssh.c. Due to the granular nature of the overflow… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.