Known vulnerabilities in ntopng
Vendor:
ntop
Software:
ntopng
Software CPE:
cpe:2.3:a:ntop:ntopng:*:*:*:*:*:*:*:*
Website:
https://www.ntop.org/
Total vulnerabilities:
8
Public exploits:
2
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (8)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU48086 - Use After Free |
CWE-416 | High | 4.2 | 02.11.2020 |
SB2020110219 |
||
| #VU48085 - Cross-Site Request Forgery (CSRF) |
CWE-352 | Medium | 4.2 | 02.11.2020 |
SB2020110219 |
||
| #VU48084 - Resource exhaustion |
CWE-400 | Medium | 4.2 | 02.11.2020 |
SB2020110219 |
||
| #VU48083 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') |
CWE-362 | Low | 4.2 | 02.11.2020 |
SB2020110219 |
||
| #VU26454 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
CWE-79 | Low | 4.0 | 29.03.2020 |
SB2020032901 |
||
| #VU13898 - Memory corruption CVE-2018-12520 |
CWE-119 | Low | 3.4.180617 | 12.07.2018 |
SB2018071713 |
||
| #VU41348 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2014-5464 |
CWE-79 | Low | 1.2.1 | 08.09.2014 |
SB2014061901 |
||
| #VU41542 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2014-4329 |
CWE-79 | Low | 1.2.1 | 19.06.2014 |
SB2014061901 |