Ntop

Ndpi

12 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.61%
  • Veröffentlicht 24.09.2026 00:00:00
  • Zuletzt bearbeitet 24.09.2026 21:08:55

nDPI 5.1.0 contains a memory access issue in the DNS dissector and serializer deserialization code. Specially crafted network input can cause byte-buffer addresses at odd offsets to be cast to uint16_t or wider integer pointers and directly dereferen...

  • EPSS 0.35%
  • Veröffentlicht 04.09.2026 22:38:48
  • Zuletzt bearbeitet 23.09.2026 17:17:46

ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi_json_string_escape function that writes beyond caller-supplied buffer boundaries. Attackers can trigger the overflow by supplying crafted network packet data inclu...

  • EPSS 0.18%
  • Veröffentlicht 03.02.2025 06:15:11
  • Zuletzt bearbeitet 02.10.2025 18:29:35

nDPI through 4.12 has a potential stack-based buffer overflow in ndpi_address_cache_restore in lib/ndpi_cache.c.

Exploit
  • EPSS 1.76%
  • Veröffentlicht 01.07.2021 03:15:08
  • Zuletzt bearbeitet 21.11.2024 06:13:06

ntop nDPI 3.4 has a stack-based buffer overflow in processClientServerHello.

  • EPSS 1.29%
  • Veröffentlicht 01.07.2020 11:15:11
  • Zuletzt bearbeitet 26.01.2026 17:16:06

In nDPI through 3.2, the packet parsing code is vulnerable to a heap-based buffer over-read in ndpi_parse_packet_line_info in lib/ndpi_main.c.

  • EPSS 1.48%
  • Veröffentlicht 01.07.2020 11:15:11
  • Zuletzt bearbeitet 21.11.2024 05:05:34

In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/protocols/h323.c, as demonstrated by a payload packet length that is too short.

  • EPSS 1.29%
  • Veröffentlicht 01.07.2020 11:15:11
  • Zuletzt bearbeitet 26.01.2026 17:16:07

In nDPI through 3.2, the OpenVPN dissector is vulnerable to a heap-based buffer over-read in ndpi_search_openvpn in lib/protocols/openvpn.c.

  • EPSS 1.2%
  • Veröffentlicht 01.07.2020 11:15:11
  • Zuletzt bearbeitet 21.11.2024 05:05:35

In nDPI through 3.2, there is a stack overflow in extractRDNSequence in lib/protocols/tls.c.

  • EPSS 1.24%
  • Veröffentlicht 01.07.2020 11:15:11
  • Zuletzt bearbeitet 21.11.2024 05:05:35

In nDPI through 3.2, ndpi_reset_packet_line_info in lib/ndpi_main.c omits certain reinitialization, leading to a use-after-free.

Exploit
  • EPSS 2.11%
  • Veröffentlicht 01.07.2020 11:15:11
  • Zuletzt bearbeitet 21.11.2024 05:05:35

In nDPI through 3.2, the Oracle protocol dissector has a heap-based buffer over-read in ndpi_search_oracle in lib/protocols/oracle.c.