bro records
5 published records for vendor bro.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-20 Improper Input Validation1
- CWE-772 Missing Release of Resource after Effective Lifetime1
- CWE-787 Out-of-bounds Write1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2017-1000458No exploit | Bro before Bro v2.5.2 is vulnerable to an out of bounds write in the ContentLine analyzer allowing remote attackers to cause a denial of serbro · bro · CWE-787 | Critical9.8 | — | 2.3% | Jan 2, 2018 |
31Monitor | CVE-2015-1521No exploit | analyzer/protocol/dnp3/DNP3.cc in Bro before 2.3.2 does not properly handle zero values of a packet length, which allows remote attackers tobro · bro · CWE-119 | High7.5 | — | 1.8% | Apr 24, 2017 |
31Monitor | CVE-2015-1522No exploit | analyzer/protocol/dnp3/DNP3.cc in Bro before 2.3.2 does not reject certain non-zero values of a packet length, which allows remote attackersbro · bro · CWE-119 | High7.5 | — | 1.8% | Apr 24, 2017 |
30Monitor | CVE-2018-16807No exploit | In Bro through 2.5.5, there is a memory leak potentially leading to DoS in scripts/base/protocols/krb/main.bro in the Kerberos protocol parsbro · bro · CWE-772 | High7.5 | — | 1.4% | Sep 10, 2018 |
30Monitor | CVE-2018-17019No exploit | In Bro through 2.5.5, there is a DoS in IRC protocol names command parsing in analyzer/protocol/irc/IRC.cc.bro · bro · CWE-20 | High7.5 | — | 1.4% | Sep 13, 2018 |
- CVE-2017-100045840Plan
Bro before Bro v2.5.2 is vulnerable to an out of bounds write in the ContentLine analyzer allowing remote attackers to cause a denial of ser
CriticalCVSS 9.8No exploitEPSS 2%bro · broJan 2, 2018
- CVE-2015-152131Monitor
analyzer/protocol/dnp3/DNP3.cc in Bro before 2.3.2 does not properly handle zero values of a packet length, which allows remote attackers to
HighCVSS 7.5No exploitEPSS 2%bro · broApr 24, 2017
- CVE-2015-152231Monitor
analyzer/protocol/dnp3/DNP3.cc in Bro before 2.3.2 does not reject certain non-zero values of a packet length, which allows remote attackers
HighCVSS 7.5No exploitEPSS 2%bro · broApr 24, 2017
- CVE-2018-1680730Monitor
In Bro through 2.5.5, there is a memory leak potentially leading to DoS in scripts/base/protocols/krb/main.bro in the Kerberos protocol pars
HighCVSS 7.5No exploitEPSS 1%bro · broSep 10, 2018
- CVE-2018-1701930Monitor
In Bro through 2.5.5, there is a DoS in IRC protocol names command parsing in analyzer/protocol/irc/IRC.cc.
HighCVSS 7.5No exploitEPSS 1%bro · broSep 13, 2018