ettercap-project CVE Vulnerabilities & Metrics

Focus on ettercap-project vulnerabilities and metrics.

Last updated: 29 Mar 2026, 22:25 UTC

About ettercap-project Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with ettercap-project. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total ettercap-project CVEs: 4
Earliest CVE date: 11 Jan 2013, 22:55 UTC
Latest CVE date: 05 Mar 2026, 22:16 UTC

Latest CVE reference: CVE-2026-3606

Rolling Stats

30-day Count (Rolling): 1
365-day Count (Rolling): 1

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical ettercap-project CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.91

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 1
4.0-6.9 6
7.0-8.9 6
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS ettercap-project CVEs

These are the five CVEs with the highest CVSS scores for ettercap-project, sorted by severity first and recency.

All CVEs for ettercap-project

CVE-2026-3606 ettercap-project vulnerability CVSS: 1.7 05 Mar 2026, 22:16 UTC

A vulnerability has been found in Ettercap 0.8.4-Garofalo. Affected by this vulnerability is the function add_data_segment of the file src/ettercap/utils/etterfilter/ef_output.c of the component etterfilter. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

CVE-2010-3843 ettercap-project vulnerability CVSS: 4.6 28 May 2021, 13:15 UTC

The GTK version of ettercap uses a global settings file at /tmp/.ettercap_gtk and does not verify ownership of this file. When parsing this file for settings in gtkui_conf_read() (src/interfacesgtk/ec_gtk_conf.c), an unchecked sscanf() call allows a maliciously placed settings file to overflow a statically-sized buffer on the stack.

CVE-2010-3844 ettercap-project vulnerability CVSS: 6.8 12 Nov 2019, 22:15 UTC

An unchecked sscanf() call in ettercap before 0.7.5 allows an insecure temporary settings file to overflow a static-sized buffer on the stack.

CVE-2017-6430 ettercap-project vulnerability CVSS: 4.3 15 Mar 2017, 15:59 UTC

The compile_tree function in ef_compiler.c in the Etterfilter utility in Ettercap 0.8.2 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted filter.

CVE-2014-9381 ettercap-project vulnerability CVSS: 5.0 19 Dec 2014, 15:59 UTC

Integer signedness error in the dissector_cvs function in dissectors/ec_cvs.c in Ettercap 0.8.1 allows remote attackers to cause a denial of service (crash) via a crafted password, which triggers a large memory allocation.

CVE-2014-9380 ettercap-project vulnerability CVSS: 5.0 19 Dec 2014, 15:59 UTC

The dissector_cvs function in dissectors/ec_cvs.c in Ettercap 0.8.1 allows remote attackers to cause a denial of service (out-of-bounds read) via a packet containing only a CVS_LOGIN signature.

CVE-2014-9379 ettercap-project vulnerability CVSS: 7.5 19 Dec 2014, 15:59 UTC

The radius_get_attribute function in dissectors/ec_radius.c in Ettercap 0.8.1 performs an incorrect cast, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors, which triggers a stack-based buffer overflow.

CVE-2014-9378 ettercap-project vulnerability CVSS: 7.5 19 Dec 2014, 15:59 UTC

Ettercap 0.8.1 does not validate certain return values, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted (1) name to the parse_line function in mdns_spoof/mdns_spoof.c or (2) base64 encoded password to the dissector_imap function in dissectors/ec_imap.c.

CVE-2014-9377 ettercap-project vulnerability CVSS: 7.5 19 Dec 2014, 15:59 UTC

Heap-based buffer overflow in the nbns_spoof function in plug-ins/nbns_spoof/nbns_spoof.c in Ettercap 0.8.1 allows remote attackers to cause a denial of service or possibly execute arbitrary code via a large netbios packet.

CVE-2014-9376 ettercap-project vulnerability CVSS: 7.5 19 Dec 2014, 15:59 UTC

Integer underflow in Ettercap 0.8.1 allows remote attackers to cause a denial of service (out-of-bounds write) and possibly execute arbitrary code via a small (1) size variable value in the dissector_dhcp function in dissectors/ec_dhcp.c, (2) length value to the dissector_gg function in dissectors/ec_gg.c, or (3) string length to the get_decode_len function in ec_utils.c or a request without a (4) username or (5) password to the dissector_TN3270 function in dissectors/ec_TN3270.c.

CVE-2014-6396 ettercap-project vulnerability CVSS: 7.5 19 Dec 2014, 15:59 UTC

The dissector_postgresql function in dissectors/ec_postgresql.c in Ettercap before 0.8.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted password length, which triggers a 0 character to be written to an arbitrary memory location.

CVE-2014-6395 ettercap-project vulnerability CVSS: 7.5 19 Dec 2014, 15:59 UTC

Heap-based buffer overflow in the dissector_postgresql function in dissectors/ec_postgresql.c in Ettercap before 0.8.1 allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted password length value that is inconsistent with the actual length of the password.

CVE-2013-0722 ettercap-project vulnerability CVSS: 4.4 11 Jan 2013, 22:55 UTC

Stack-based buffer overflow in the scan_load_hosts function in ec_scan.c in Ettercap 0.7.5.1 and earlier might allow local users to gain privileges via a Trojan horse hosts list containing a long line.