CVEs (65)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Open Information Security Foundation Suricata prior to version 4.1.2 is affected by: Denial of Service - DNS detection bypass. The impact is: An attacker can evade a signature detection with a specialy formed network pac...Show more |
A buffer over-read issue was discovered in Suricata 4.1.x before 4.1.4. If the input of the decode-mpls.c function DecodeMPLS is composed only of a packet of source address and destination address plus the correct type f...Show more |
Suricata version 4.0.4 incorrectly handles the parsing of an EtherNet/IP PDU. A malformed PDU can cause the parsing code to read beyond the allocated data because DecodeENIPPDU in app-layer-enip-commmon.c has an integer...Show more |
2Debian Oisf2Debian Linux SuricataNov 21, 2024 Apr 4, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Suricata version 4.0.4 incorrectly handles the parsing of the SSH banner. A malformed SSH banner can cause the parsing code to read beyond the allocated data because SSHParseBanner in app-layer-ssh.c lacks a length check...Show more |
2Oisf Openinfosecfoundation2Suricata SuricataMay 6, 2026 May 30, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Suricata before 1.4.6 allows remote attackers to cause a denial of service (crash) via a malformed SSL record. |