ntop nDPI 在 6.0 版本之前包含一个堆缓冲区溢出漏洞。该漏洞位于 函数中,该函数会在调用者提供的缓冲区边界之外写入数据。攻击者可通过提供特制的网络数据包数据(包括 TLS SNI、HTTP 请求头或 DNS 名称)来触发此溢出,这些数据若到达存在漏洞的函数,将导致堆内存损坏。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86091 | 7.1 HIGH | ntopng before 6.7.260717 Missing Authorization on the Host Pool Bulk Delete Handler |
| CVE-2026-86090 | 7.1 HIGH | ntopng before 6.7.260717 Missing Authorization on the Notification Endpoint and Recipient |
No comments yet