ntop CVE Vulnerabilities & Metrics

Focus on ntop vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About ntop Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with ntop. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total ntop CVEs: 15
Earliest CVE date: 21 Aug 2009, 11:02 UTC
Latest CVE date: 01 Jul 2021, 03:15 UTC

Latest CVE reference: CVE-2021-36082

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical ntop CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.81

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 0
4.0-6.9 16
7.0-8.9 3
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS ntop CVEs

These are the five CVEs with the highest CVSS scores for ntop, sorted by severity first and recency.

All CVEs for ntop

CVE-2021-36082 ntop vulnerability CVSS: 6.8 01 Jul 2021, 03:15 UTC

ntop nDPI 3.4 has a stack-based buffer overflow in processClientServerHello.

CVE-2020-15476 ntop vulnerability CVSS: 5.0 01 Jul 2020, 11:15 UTC

In nDPI through 3.2, the Oracle protocol dissector has a heap-based buffer over-read in ndpi_search_oracle in lib/protocols/oracle.c.

CVE-2020-15475 ntop vulnerability CVSS: 7.5 01 Jul 2020, 11:15 UTC

In nDPI through 3.2, ndpi_reset_packet_line_info in lib/ndpi_main.c omits certain reinitialization, leading to a use-after-free.

CVE-2020-15474 ntop vulnerability CVSS: 7.5 01 Jul 2020, 11:15 UTC

In nDPI through 3.2, there is a stack overflow in extractRDNSequence in lib/protocols/tls.c.

CVE-2020-15473 ntop vulnerability CVSS: 6.4 01 Jul 2020, 11:15 UTC

In nDPI through 3.2, the OpenVPN dissector is vulnerable to a heap-based buffer over-read in ndpi_search_openvpn in lib/protocols/openvpn.c.

CVE-2020-15472 ntop vulnerability CVSS: 6.4 01 Jul 2020, 11:15 UTC

In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/protocols/h323.c, as demonstrated by a payload packet length that is too short.

CVE-2020-15471 ntop vulnerability CVSS: 6.4 01 Jul 2020, 11:15 UTC

In nDPI through 3.2, the packet parsing code is vulnerable to a heap-based buffer over-read in ndpi_parse_packet_line_info in lib/ndpi_main.c.

CVE-2020-11940 ntop vulnerability CVSS: 5.0 23 Apr 2020, 15:15 UTC

In nDPI through 3.2 Stable, an out-of-bounds read in concat_hash_string in ssh.c can be exploited by a network-positioned attacker that can send malformed SSH protocol messages on a network segment monitored by nDPI's library.

CVE-2020-11939 ntop vulnerability CVSS: 7.5 23 Apr 2020, 15:15 UTC

In nDPI through 3.2 Stable, the SSH protocol dissector has multiple KEXINIT integer overflows that result in a controlled remote heap overflow in concat_hash_string in ssh.c. Due to the granular nature of the overflow primitive and the ability to control both the contents and layout of the nDPI library's heap memory through remote input, this vulnerability may be abused to achieve full Remote Code Execution against any network inspection stack that is linked against nDPI and uses it to perform network traffic analysis.

CVE-2018-12520 ntop vulnerability CVSS: 6.8 05 Jul 2018, 20:29 UTC

An issue was discovered in ntopng 3.4 before 3.4.180617. The PRNG involved in the generation of session IDs is not seeded at program startup. This results in deterministic session IDs being allocated for active user sessions. An attacker with foreknowledge of the operating system and standard library in use by the host running the service and the username of the user whose session they're targeting can abuse the deterministic random number generation in order to hijack the user's session, thus escalating their access.

CVE-2017-7458 ntop vulnerability CVSS: 5.0 26 Jun 2017, 23:29 UTC

The NetworkInterface::getHost function in NetworkInterface.cpp in ntopng before 3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty field that should have contained a hostname or IP address.

CVE-2017-7459 ntop vulnerability CVSS: 5.0 26 Jun 2017, 07:29 UTC

ntopng before 3.0 allows HTTP Response Splitting.

CVE-2017-7416 ntop vulnerability CVSS: 4.3 26 Jun 2017, 07:29 UTC

ntopng before 3.0 allows XSS because GET and POST parameters are improperly validated.

CVE-2017-5473 ntop vulnerability CVSS: 6.8 14 Jan 2017, 07:59 UTC

Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authentication of arbitrary users, as demonstrated by admin/add_user.lua, admin/change_user_prefs.lua, admin/delete_user.lua, and admin/password_reset.lua.

CVE-2015-8368 ntop vulnerability CVSS: 6.0 17 Dec 2015, 19:59 UTC

ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and username parameter to admin/password_reset.lua.

CVE-2014-5464 ntop vulnerability CVSS: 4.3 08 Sep 2014, 14:55 UTC

Cross-site scripting (XSS) vulnerability in the nDPI traffic classification library in ntopng (aka ntop) before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header.

CVE-2014-4329 ntop vulnerability CVSS: 4.3 19 Jun 2014, 10:50 UTC

Cross-site scripting (XSS) vulnerability in lua/host_details.lua in ntopng 1.1 allows remote attackers to inject arbitrary web script or HTML via the host parameter.

CVE-2014-4165 ntop vulnerability CVSS: 4.3 16 Jun 2014, 18:55 UTC

Cross-site scripting (XSS) vulnerability in ntop allows remote attackers to inject arbitrary web script or HTML via the title parameter in a list action to plugins/rrdPlugin.

CVE-2009-2732 ntop vulnerability CVSS: 5.0 21 Aug 2009, 11:02 UTC

The checkHTTPpassword function in http.c in ntop 3.3.10 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an Authorization HTTP header that lacks a : (colon) character in the base64-decoded string.