Ettercap is a network analysis and penetration-testing tool focused on man-in-the-middle and protocol analysis capabilities, with a narrow product footprint centered on the tool itself. Vulnerability disclosures for this project reflect the tool's packet-handling and parsing scope; current severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ettercap over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-6395HIGH Heap-based buffer overflow in the dissector_postgresql function in dissectors/ec_postgresql.c in Ettercap before 0.8.1 allows remote attackers to cause a denial of service or possi | Dec 19, 2014 | 7.5 | 42 | NO | YES |
CVE-2017-8366CRITICAL The strescape function in ec_strings.c in Ettercap 0.8.2 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have un | Apr 30, 2017 | 9.8 | 32 | NO | NO |
CVE-2002-0276HIGH Buffer overflow in various decoders in Ettercap 0.6.3.1 and earlier, when running on networks with an MTU greater than 2000, allows remote attackers to execute arbitrary code via l | May 31, 2002 | 7.5 | 30 | NO | YES |
CVE-2010-3844HIGH An unchecked sscanf() call in ettercap before 0.7.5 allows an insecure temporary settings file to overflow a static-sized buffer on the stack. | Nov 12, 2019 | 8.8 | 27 | NO | NO |
CVE-2014-6396HIGH The dissector_postgresql function in dissectors/ec_postgresql.c in Ettercap before 0.8.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code vi | Dec 19, 2014 | 7.5 | 26 | NO | NO |
CVE-2010-3843HIGH The GTK version of ettercap uses a global settings file at /tmp/.ettercap_gtk and does not verify ownership of this file. When parsing this file for settings in gtkui_conf_read() ( | May 28, 2021 | 7.8 | 25 | NO | NO |
CVE-2013-0722MEDIUM Stack-based buffer overflow in the scan_load_hosts function in ec_scan.c in Ettercap 0.7.5.1 and earlier might allow local users to gain privileges via a Trojan horse hosts list co | Jan 11, 2013 | 4.4 | 25 | NO | YES |
CVE-2005-1796HIGH Format string vulnerability in the curses_msg function in the Ncurses interface (ec_curses.c) for Ettercap before 0.7.3 allows remote attackers to execute arbitrary code. | May 31, 2005 | 7.5 | 25 | NO | NO |
CVE-2014-9379HIGH The radius_get_attribute function in dissectors/ec_radius.c in Ettercap 0.8.1 performs an incorrect cast, which allows remote attackers to cause a denial of service (crash) or poss | Dec 19, 2014 | 7.5 | 24 | NO | NO |
CVE-2014-9378HIGH Ettercap 0.8.1 does not validate certain return values, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted (1) name | Dec 19, 2014 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ettercap.
Media articles that mention a CVE ID that affects a product developed by Ettercap — matched by CVE ID, not by vendor name.