Search CVE reports


Toggle filters

11 – 20 of 22 results


CVE-2018-12520

High priority

Some fixes available 2 of 5

An issue was discovered in ntopng 3.4 before 3.4.180617. The PRNG involved in the generation of session IDs is not seeded at program startup. This results in deterministic session IDs being allocated for active user sessions. An...

1 affected package

ntopng

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ntopng — Not affected Not affected Not affected Fixed
Show less packages

CVE-2017-7458

Low priority
Vulnerable

The NetworkInterface::getHost function in NetworkInterface.cpp in ntopng before 3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty field that should have...

1 affected package

ntopng

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ntopng Not in release Not affected Needs evaluation Not affected Not affected
Show less packages

CVE-2017-7459

Medium priority
Vulnerable

ntopng before 3.0 allows HTTP Response Splitting.

1 affected package

ntopng

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ntopng Not in release Not affected Needs evaluation Not affected Not affected
Show less packages

CVE-2017-7416

Medium priority
Vulnerable

ntopng before 3.0 allows XSS because GET and POST parameters are improperly validated.

1 affected package

ntopng

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ntopng Not in release Not affected Needs evaluation Not affected Not affected
Show less packages

CVE-2017-5473

Medium priority
Vulnerable

Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authentication of arbitrary users, as demonstrated by admin/add_user.lua,...

1 affected package

ntopng

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ntopng Not in release Not affected Needs evaluation Not affected Not affected
Show less packages

CVE-2015-8368

Medium priority
Ignored

ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and username parameter to admin/password_reset.lua.

1 affected package

ntopng

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ntopng — — — — —
Show less packages

CVE-2014-5515

Medium priority
Ignored

ntopng: Several vulnerabilities fixed upstream in 1.2.1

1 affected package

ntopng

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ntopng — — — — —
Show less packages

CVE-2014-5514

Medium priority
Ignored

ntopng: Several vulnerabilities fixed upstream in 1.2.1

1 affected package

ntopng

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ntopng — — — — —
Show less packages

CVE-2014-5513

Medium priority
Ignored

ntopng: Several vulnerabilities fixed upstream in 1.2.1

1 affected package

ntopng

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ntopng — — — — —
Show less packages

CVE-2014-5512

Medium priority
Ignored

ntopng: Several vulnerabilities fixed upstream in 1.2.1

1 affected package

ntopng

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ntopng — — — — —
Show less packages