Search CVE reports


Toggle filters

1 – 10 of 14 results


CVE-2024-53426

Medium priority
Needs evaluation

A heap-buffer-overflow vulnerability has been identified in ntopng 6.2 in the Flow::dissectMDNS function.

1 affected package

ntopng

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ntopng Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-31129

Medium priority

Some fixes available 4 of 92

moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. Affected versions of moment were found to use an inefficient parsing algorithm. Specifically using string-to-date parsing in moment...

11 affected packages

gnucash, mediawiki, node-moment, ntopng, odoo...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
gnucash Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
mediawiki Needs evaluation Needs evaluation Needs evaluation Needs evaluation Not in release
node-moment Not affected Fixed Fixed Fixed Needs evaluation
ntopng Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
odoo Needs evaluation Needs evaluation Not in release Not in release Not in release
omnidb Needs evaluation Needs evaluation Needs evaluation Not in release Not in release
postfixadmin Vulnerable Fixed Not affected Not affected Not affected
ruby-momentjs-rails Needs evaluation Needs evaluation Needs evaluation Not in release Not in release
sabnzbdplus Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
syncthing Needs evaluation Needs evaluation Needs evaluation Needs evaluation Not in release
wordpress Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show all 11 packages Show less packages

CVE-2018-12520

High priority

Some fixes available 2 of 5

An issue was discovered in ntopng 3.4 before 3.4.180617. The PRNG involved in the generation of session IDs is not seeded at program startup. This results in deterministic session IDs being allocated for active user sessions. An...

1 affected package

ntopng

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ntopng Not affected Not affected Not affected Fixed Fixed
Show less packages

CVE-2017-7458

Low priority
Vulnerable

The NetworkInterface::getHost function in NetworkInterface.cpp in ntopng before 3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty field that should have...

1 affected package

ntopng

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ntopng Not affected Needs evaluation Not affected Not affected Vulnerable
Show less packages

CVE-2017-7459

Medium priority
Vulnerable

ntopng before 3.0 allows HTTP Response Splitting.

1 affected package

ntopng

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ntopng Not affected Needs evaluation Not affected Not affected Vulnerable
Show less packages

CVE-2017-7416

Medium priority
Vulnerable

ntopng before 3.0 allows XSS because GET and POST parameters are improperly validated.

1 affected package

ntopng

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ntopng Not affected Needs evaluation Not affected Not affected Vulnerable
Show less packages

CVE-2017-5473

Medium priority
Vulnerable

Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authentication of arbitrary users, as demonstrated by admin/add_user.lua,...

1 affected package

ntopng

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ntopng Not affected Needs evaluation Not affected Not affected Vulnerable
Show less packages

CVE-2015-8368

Medium priority
Ignored

ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and username parameter to admin/password_reset.lua.

1 affected package

ntopng

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ntopng Not affected
Show less packages

CVE-2014-5515

Medium priority
Ignored

ntopng: Several vulnerabilities fixed upstream in 1.2.1

1 affected package

ntopng

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ntopng Not affected
Show less packages

CVE-2014-5514

Medium priority
Ignored

ntopng: Several vulnerabilities fixed upstream in 1.2.1

1 affected package

ntopng

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ntopng Not affected
Show less packages