In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpisearchh323 in lib/protocols/h323.c, as demonstrated by a payload packet length that is too short.
In nDPI through 3.2, ndpiresetpacketlineinfo in lib/ndpimain.c omits certain reinitialization, leading to a use-after-free.
In nDPI through 3.2, there is a stack overflow in extractRDNSequence in lib/protocols/tls.c.
In nDPI through 3.2, the Oracle protocol dissector has a heap-based buffer over-read in ndpisearchoracle in lib/protocols/oracle.c.
ntop nDPI 3.4 has a stack-based buffer overflow in processClientServerHello.