Skip to content
Noroxi

snort records

19 published records for vendor snort.

Researcher profile

Entered KEV
0 · 0%
Weaponized
1 · 5.3%
Pre-auth RCE
3
With a fix record
52.6%
Median publish → KEV
No record has entered KEV

All records

19 records
  • CVE-2006-5276
    64This week

    Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire Intrusion Sensor; all

    CriticalCVSS 10.0WeaponizedEPSS 79%

    snort · snortFeb 19, 2007

  • Buffer overflow in the RPC preprocessor for Snort 1.8 and 1.9.x before 1.9.1 allows remote attackers to execute arbitrary code via fragmente

    CriticalCVSS 10.0No exploitEPSS 12%

    snort · snortMar 7, 2003

  • CVE-2016-1417
    36Monitor

    Untrusted search path vulnerability in Snort 2.9.7.0-WIN32 allows remote attackers to execute arbitrary code and conduct DLL hijacking attac

    HighCVSS 8.8No exploitEPSS 4%

    snort · snortJan 23, 2017

  • CVE-2007-0251
    32Monitor

    Integer underflow in the DecodeGRE function in src/decode.c in Snort 2.6.1.2 allows remote attackers to trigger dereferencing of certain mem

    HighCVSS 7.8No exploitEPSS 2%

    snort · snortJan 16, 2007

  • CVE-2001-0669
    31Monitor

    Various Intrusion Detection Systems (IDS) including (1) Cisco Secure Intrusion Detection System, (2) Cisco Catalyst 6000 Intrusion Detection

    HighCVSS 7.5Proof of conceptEPSS 4%

    cisco · catalyst 6000 intrusion detection system moduleOct 30, 2001

  • Multiple Cisco Products Snort Memory Leak Denial of Service Vulnerability

    HighCVSS 7.5No exploitEPSS 2%

    cisco · secure firewall management centerOct 27, 2021

  • CVE-2021-1223
    31Monitor

    Multiple Cisco Products Snort HTTP Detection Engine File Policy Bypass Vulnerability

    HighCVSS 7.5No exploitEPSS 2%

    cisco · secure firewall management centerJan 13, 2021

  • CVE-2007-1398
    30Monitor

    The frag3 preprocessor in Snort 2.6.1.1, 2.6.1.2, and 2.7.0 beta, when configured for inline use on Linux without the ip_conntrack module lo

    HighCVSS 7.1Proof of conceptEPSS 6%

    linux · linux kernelMar 10, 2007

  • CVE-2009-3641
    29Monitor

    Snort before 2.8.5.1, when the -v option is enabled, allows remote attackers to cause a denial of service (application crash) via a crafted

    MediumCVSS 4.3Proof of conceptEPSS 39%

    snort · snortOct 28, 2009

  • CVE-2008-1804
    28Monitor

    preprocessors/spp_frag3.c in Sourcefire Snort before 2.8.1 does not properly identify packet fragments that have dissimilar TTL values, whic

    MediumCVSS 6.8No exploitEPSS 2%

    snort · snortMay 22, 2008

  • CVE-2020-3299
    24Monitor

    Multiple Cisco Products SNORT HTTP Detection Engine File Policy Bypass Vulnerability

    MediumCVSS 5.8No exploitEPSS 2%

    cisco · secure firewall threat defenseOct 21, 2020

  • Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker t

    MediumCVSS 5.8No exploitEPSS 1%

    cisco · secure firewall threat defenseNov 1, 2023

  • CVE-2021-1236
    22Monitor

    Multiple Cisco Products Snort Application Detection Engine Policy Bypass Vulnerability

    MediumCVSS 5.3No exploitEPSS 2%

    cisco · ios xeJan 13, 2021

  • CVE-2021-1224
    22Monitor

    Multiple Cisco Products Snort TCP Fast Open File Policy Bypass Vulnerability

    MediumCVSS 5.3No exploitEPSS 2%

    cisco · secure firewall management centerJan 13, 2021

  • CVE-2021-1495
    22Monitor

    Multiple Cisco Products Snort HTTP Detection Engine File Policy Bypass Vulnerability

    MediumCVSS 5.3No exploitEPSS 2%

    cisco · secure firewall threat defenseApr 29, 2021

  • CVE-2006-6931
    21Monitor

    Algorithmic complexity vulnerability in Snort before 2.6.1, during predicate evaluation in rule matching for certain rules, allows remote at

    MediumCVSS 5.0No exploitEPSS 2%

    snort · snortJan 16, 2007

  • Multiple Cisco products are affected by a vulnerability in Snort access control policies that could allow an unauthenticated, remote attacke

    MediumCVSS 5.3No exploitEPSS 1%

    snort · snortNov 1, 2023

  • CVE-2000-1226
    20Monitor

    Snort 1.6, when running in straight ASCII packet logging mode or IDS mode with straight decoded ASCII packet logging selected, allows remote

    MediumCVSS 5.0No exploitEPSS 1%

    snort · snortDec 31, 2000

  • CVE-2001-1558
    20Monitor

    Unknown vulnerability in IP defragmenter (frag2) in Snort before 1.8.3 allows attackers to cause a denial of service (crash).

    MediumCVSS 5.0No exploitEPSS 1%

    snort · snortDec 31, 2001