Search CVE reports
1 – 10 of 22 results
ntopng is a web-based network traffic monitoring application. Prior to 6.7.260718, scripts/lua/rest/v2/get/system/configurations/list_available_backups.lua and scripts/lua/rest/v2/get/system/configurations/download_backup.lua...
1 affected package
ntopng
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| ntopng | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, POST /lua/rest/v2/edit/system/edit_blacklist.lua in scripts/lua/rest/v2/edit/system/edit_blacklist.lua lacks an administrator check and calls...
1 affected package
ntopng
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| ntopng | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, the vulnerability-scan endpoints scripts/lua/rest/v2/add/host/to_scan.lua and scripts/lua/rest/v2/exec/host/schedule_vulnerability_scan.lua accept...
1 affected package
ntopng
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| ntopng | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bindings. Attackers can issue POST requests to the delete...
1 affected package
ntopng
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| ntopng | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST requests to irreversibly delete all configured...
1 affected package
ntopng
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| ntopng | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
ntopng is a web-based network traffic monitoring application. In versions 6.7.0 through 6.7.260717, two REST v2 endpoints that manage ntopng's tag/badge feature — `POST /lua/rest/v2/delete/tag/tag.lua` and...
1 affected package
ntopng
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| ntopng | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result,...
1 affected package
ntopng
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| ntopng | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
CWE-601 URL redirection to untrusted site ('open redirect')
1 affected package
ntopng
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| ntopng | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
A heap-buffer-overflow vulnerability has been identified in ntopng 6.2 in the Flow::dissectMDNS function.
1 affected package
ntopng
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| ntopng | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Some fixes available 4 of 118
moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. Affected versions of moment were found to use an inefficient parsing algorithm. Specifically using string-to-date parsing in moment...
11 affected packages
node-moment, wordpress, mediawiki, syncthing, omnidb...
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| node-moment | Not affected | Not affected | Fixed | Fixed | Fixed |
| wordpress | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| mediawiki | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| syncthing | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| omnidb | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Not in release |
| postfixadmin | Vulnerable | Vulnerable | Fixed | Not affected | Not affected |
| sabnzbdplus | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| gnucash | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| ntopng | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| odoo | Needs evaluation | Needs evaluation | Needs evaluation | Not in release | Not in release |
| ruby-momentjs-rails | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Not in release |