Oisf
oisf
73 CVEs • 3 products
Products (3)
Click to collapseToggle
Products (3)
Click to collapse
CVEs (73)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectOisf3Debian Linux FedoraSuricataJun 17, 2026 Jul 22, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Suricata before 5.0.7 and 6.x before 6.0.3 has a "critical evasion." |
2Debian Oisf2Debian Linux SuricataJun 17, 2026 Jan 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Suricata 5.0.0. It was possible to bypass/evade any tcp based signature by faking a closed TCP session using an evil server. After the TCP SYN packet, it is possible to inject a RST ACK and a F...Show more |
2Debian Oisf2Debian Linux SuricataJun 17, 2026 Jan 6, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An issue was discovered in Suricata 5.0.0. It is possible to bypass/evade any tcp based signature by overlapping a TCP segment with a fake FIN packet. The fake FIN packet is injected just before the PUSH ACK packet we wa...Show more |
2Oisf Suricata Ids2Libhtp SuricataJun 17, 2026 Oct 10, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In OISF LibHTP before 0.5.31, as used in Suricata 4.1.4 and other products, an HTTP protocol parsing error causes the http_header signature to not alert on a response with a single \r\n ending. |
Open Information Security Foundation Suricata prior to version 4.1.3 is affected by: Denial of Service - TCP/HTTP detection bypass. The impact is: An attacker can evade a signature detection with a specialy formed sequen...Show more |
Open Information Security Foundation Suricata prior to version 4.1.2 is affected by: Denial of Service - DNS detection bypass. The impact is: An attacker can evade a signature detection with a specialy formed network pac...Show more |
A buffer over-read issue was discovered in Suricata 4.1.x before 4.1.4. If the input of the decode-mpls.c function DecodeMPLS is composed only of a packet of source address and destination address plus the correct type f...Show more |
Suricata version 4.0.4 incorrectly handles the parsing of an EtherNet/IP PDU. A malformed PDU can cause the parsing code to read beyond the allocated data because DecodeENIPPDU in app-layer-enip-commmon.c has an integer...Show more |
htp_parse_authorization_digest in htp_parsers.c in LibHTP 0.5.26 allows remote attackers to cause a heap-based buffer over-read via an authorization digest header. |
2Debian Oisf2Debian Linux SuricataNov 21, 2024 Apr 4, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Suricata version 4.0.4 incorrectly handles the parsing of the SSH banner. A malformed SSH banner can cause the parsing code to read beyond the allocated data because SSHParseBanner in app-layer-ssh.c lacks a length check...Show more |
OISF suricata-update version 1.0.0a1 contains an Insecure Deserialization vulnerability in the insecure yaml.load-Function as used in the following files: config.py:136, config.py:142, sources.py:99 and sources.py:131. T...Show more |
libhtp 0.5.15 allows remote attackers to cause a denial of service (NULL pointer dereference). |
2Oisf Openinfosecfoundation2Suricata SuricataMay 6, 2026 May 30, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Suricata before 1.4.6 allows remote attackers to cause a denial of service (crash) via a malformed SSL record. |