VYPR

Vendor CVEs

Oisf

All CVEs

114 total · sorted by risk
  • CVE-2024-32867MedMay 7, 2024
    risk 0.00cvss 5.3epss 0.01

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.5 and 6.0.19, various problems in handling of fragmentation anomalies can lead to mis-detection of rules and policy. This vulnerability is fixed in…

  • CVE-2024-32664MedMay 7, 2024
    risk 0.00cvss 5.3epss 0.01

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.5 and 6.0.19, specially crafted traffic or datasets can cause a limited buffer overflow. This vulnerability is fixed in 7.0.5 and 6.0.19.…

  • CVE-2024-32663HigMay 7, 2024
    risk 0.00cvss 7.5epss 0.01

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.5 and 6.0.19, a small amount of HTTP/2 traffic can lead to Suricata using a large amount of memory. The issue has been addressed in Suricata 7.0.5…

  • CVE-2024-28871HigApr 4, 2024
    risk 0.00cvss 7.5epss 0.01

    LibHTP is a security-aware parser for the HTTP protocol and the related bits and pieces. Version 0.5.46 may parse malformed request traffic, leading to excessive CPU usage. Version 0.5.47 contains a patch for the issue. No known workarounds are available.

  • CVE-2024-24568MedFeb 26, 2024
    risk 0.00cvss 5.3epss 0.01

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, the rules inspecting HTTP2 headers can get bypassed by crafted traffic. The vulnerability has been patched in 7.0.3.

  • CVE-2024-23839HigFeb 26, 2024
    risk 0.00cvss 7.1epss 0.01

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, specially crafted traffic can cause a heap use after free if the ruleset uses the http.request_header or http.response_header keyword. The…

  • CVE-2024-23837HigFeb 26, 2024
    risk 0.00cvss 7.5epss 0.01

    LibHTP is a security-aware parser for the HTTP protocol. Crafted traffic can cause excessive processing time of HTTP headers, leading to denial of service. This issue is addressed in 0.5.46.

  • CVE-2024-23836HigFeb 26, 2024
    risk 0.00cvss 7.5epss 0.01

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 6.0.16 and 7.0.3, an attacker can craft traffic to cause Suricata to use far more CPU and memory for processing the traffic than needed, which…

  • CVE-2024-23835HigFeb 26, 2024
    risk 0.00cvss 7.5epss 0.01

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.3, excessive memory use during pgsql parsing could lead to OOM-related crashes. This vulnerability is patched in 7.0.3. As workaround,…

  • CVE-2023-35853CriJun 19, 2023
    risk 0.00cvss 9.8epss 0.01

    In Suricata before 6.0.13, an adversary who controls an external source of Lua rules may be able to execute Lua code. This is addressed in 6.0.13 by disabling Lua unless allow-rules is true in the security lua configuration section.

  • CVE-2023-35852HigJun 19, 2023
    risk 0.00cvss 7.5epss 0.01

    In Suricata before 6.0.13 (when there is an adversary who controls an external source of rules), a dataset filename, that comes from a rule, may trigger absolute or relative directory traversal, and lead to write access to a local filesystem. This is addressed in 6.0.13 by…

  • CVE-2015-0971May 14, 2015
    risk 0.00cvss —epss 0.01

    The DER parser in Suricata before 2.0.8 allows remote attackers to cause a denial of service (crash) via vectors related to SSL/TLS certificates.

  • CVE-2014-6603Oct 7, 2014
    risk 0.00cvss —epss 0.03

    The SSHParseBanner function in SSH parser (app-layer-ssh.c) in Suricata before 2.0.4 allows remote attackers to bypass SSH rules, cause a denial of service (crash), or possibly have unspecified other impact via a crafted banner, which triggers a large memory allocation or an…

  • CVE-2013-5919May 30, 2014
    risk 0.00cvss —epss 0.02

    Suricata before 1.4.6 allows remote attackers to cause a denial of service (crash) via a malformed SSL record.

Page 3 of 3