Oisf Suricata vulnerabilities

85 known vulnerabilities affecting oisf/suricata.

Total CVEs
85
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL12HIGH58MEDIUM15

Vulnerabilities

Page 5 of 5
CVE-2015-8954CRITICALCVSS 9.8≥ 0, < 2.0.6-12017-03-20
CVE-2015-8954 [CRITICAL] CVE-2015-8954: The MemcmpLowercase function in Suricata before 2 The MemcmpLowercase function in Suricata before 2.0.6 improperly excludes the first byte from comparisons, which might allow remote attackers to bypass intrusion-prevention functionality via a crafted HTTP request.
osv
CVE-2017-7177HIGHCVSS 7.5≥ 0, < 3.2.1-12017-03-18
CVE-2017-7177 [HIGH] CVE-2017-7177: Suricata before 3 Suricata before 3.2.1 has an IPv4 defragmentation evasion issue caused by lack of a check for the IP protocol during fragment matching.
osv
CVE-2015-0971MEDIUMCVSS 5.0≥ 0, < 2.0.8-12015-05-14
CVE-2015-0971 [MEDIUM] CVE-2015-0971: The DER parser in Suricata before 2 The DER parser in Suricata before 2.0.8 allows remote attackers to cause a denial of service (crash) via vectors related to SSL/TLS certificates.
osv
CVE-2014-6603MEDIUMCVSS 5.0≥ 0, < 2.0.4-12014-10-07
CVE-2014-6603 [MEDIUM] CVE-2014-6603: The SSHParseBanner function in SSH parser (app-layer-ssh The SSHParseBanner function in SSH parser (app-layer-ssh.c) in Suricata before 2.0.4 allows remote attackers to bypass SSH rules, cause a denial of service (crash), or possibly have unspecified other impact via a crafted banner, which triggers a large memory allocation or an out-of-bounds write.
osv
CVE-2013-5919MEDIUMCVSS 5.0v1.3v1.3.1+10 more2014-05-30
CVE-2013-5919 [MEDIUM] CWE-20 CVE-2013-5919: Suricata before 1.4.6 allows remote attackers to cause a denial of service (crash) via a malformed S Suricata before 1.4.6 allows remote attackers to cause a denial of service (crash) via a malformed SSL record.
nvdosv