Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2770▲ 14 respecto a la semana anterior
Críticas / altas1475▲ 292 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 447 respecto a la semana anterior
–

13 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.60%—Ntop NdpiAI24/9/202624/9/2026
nDPI 5.1.0 contains a memory access issue in the DNS dissector and serializer deserialization code. Specially crafted network input can cause byte-buffer addresses at odd offsets to be cast to uint16_t or wider integer pointers and directly dereferenced without alignment checks. This results in undefined behavior and…
AplazadaAlta (8.3)0.59%—Ntop NdpiAI4/9/202623/9/2026
ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi_json_string_escape function that writes beyond caller-supplied buffer boundaries. Attackers can trigger the overflow by supplying crafted network packet data including TLS SNI, HTTP headers, or DNS names that reach the vulnerable…
AplazadaBaja (1.9)0.17%—Abrinsmead Mindpilot-mcpAI8/8/202612/8/2026
A flaw has been found in abrinsmead mindpilot-mcp 0.5.0. Affected by this issue is some unknown functionality of the component HistoryService. This manipulation of the argument ID causes path traversal. The attack needs to be launched locally. The project was informed of the problem early through an issue report but…
AnalizadaAlta (8.4)0.18%—Ntop Ndpi3/2/202517/6/2026
nDPI through 4.12 has a potential stack-based buffer overflow in ndpi_address_cache_restore in lib/ndpi_cache.c.
ModificadaAlta (8.8)1.8%—Ntop Ndpi1/7/202117/6/2026
ntop nDPI 3.4 has a stack-based buffer overflow in processClientServerHello.
ModificadaAlta (7.5)2.1%—Ntop NdpiDebian Linux1/7/202017/6/2026
In nDPI through 3.2, the Oracle protocol dissector has a heap-based buffer over-read in ndpi_search_oracle in lib/protocols/oracle.c.
ModificadaCrítica (9.8)1.2%—Ntop Ndpi1/7/202017/6/2026
In nDPI through 3.2, ndpi_reset_packet_line_info in lib/ndpi_main.c omits certain reinitialization, leading to a use-after-free.
ModificadaCrítica (9.8)1.2%—Ntop Ndpi1/7/202017/6/2026
In nDPI through 3.2, there is a stack overflow in extractRDNSequence in lib/protocols/tls.c.
ModificadaCrítica (9.1)1.3%—Ntop Ndpi1/7/202017/6/2026
In nDPI through 3.2, the OpenVPN dissector is vulnerable to a heap-based buffer over-read in ndpi_search_openvpn in lib/protocols/openvpn.c.
ModificadaCrítica (9.1)1.5%—Ntop NdpiDebian Linux1/7/202017/6/2026
In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/protocols/h323.c, as demonstrated by a payload packet length that is too short.
ModificadaCrítica (9.1)1.3%—Ntop Ndpi1/7/202017/6/2026
In nDPI through 3.2, the packet parsing code is vulnerable to a heap-based buffer over-read in ndpi_parse_packet_line_info in lib/ndpi_main.c.
ModificadaAlta (7.5)1.3%—Ntop Ndpi23/4/202017/6/2026
In nDPI through 3.2 Stable, an out-of-bounds read in concat_hash_string in ssh.c can be exploited by a network-positioned attacker that can send malformed SSH protocol messages on a network segment monitored by nDPI's library.
ModificadaCrítica (9.8)3.3%—Ntop Ndpi23/4/202017/6/2026
In nDPI through 3.2 Stable, the SSH protocol dissector has multiple KEXINIT integer overflows that result in a controlled remote heap overflow in concat_hash_string in ssh.c. Due to the granular nature of the overflow primitive and the ability to control both the contents and layout of the nDPI library's heap memory…