snort records
19 published records for vendor snort.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 5.3%
- Pre-auth RCE
- 3
- With a fix record
- 52.6%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-693 Protection Mechanism Failure3
- CWE-290 Authentication Bypass by Spoofing1
- CWE-426 Untrusted Search Path1
- CWE-1039 Inadequate Detection or Handling of Adversarial Input Perturbations in Automated Recognition Mechanism1
- CWE-755 Improper Handling of Exceptional Conditions1
- CWE-770 Allocation of Resources Without Limits or Throttling1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
19 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
64This week | CVE-2006-5276Weaponized | Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire Intrusion Sensor; allsnort · snort | Critical10.0 | — | 79.4% | Feb 19, 2007 |
44Plan | CVE-2003-0033No exploit | Buffer overflow in the RPC preprocessor for Snort 1.8 and 1.9.x before 1.9.1 allows remote attackers to execute arbitrary code via fragmentesnort · snort | Critical10.0 | — | 11.9% | Mar 7, 2003 |
36Monitor | CVE-2016-1417No exploit | Untrusted search path vulnerability in Snort 2.9.7.0-WIN32 allows remote attackers to execute arbitrary code and conduct DLL hijacking attacsnort · snort · CWE-426 | High8.8 | — | 4.4% | Jan 23, 2017 |
32Monitor | CVE-2007-0251No exploit | Integer underflow in the DecodeGRE function in src/decode.c in Snort 2.6.1.2 allows remote attackers to trigger dereferencing of certain memsnort · snort | High7.8 | — | 2.4% | Jan 16, 2007 |
31Monitor | CVE-2001-0669Proof of concept | Various Intrusion Detection Systems (IDS) including (1) Cisco Secure Intrusion Detection System, (2) Cisco Catalyst 6000 Intrusion Detectioncisco · catalyst 6000 intrusion detection system module | High7.5 | — | 4.4% | Oct 30, 2001 |
31Monitor | CVE-2021-40114No exploit | Multiple Cisco Products Snort Memory Leak Denial of Service Vulnerabilitycisco · secure firewall management center · CWE-770 | High7.5 | — | 2.4% | Oct 27, 2021 |
31Monitor | CVE-2021-1223No exploit | Multiple Cisco Products Snort HTTP Detection Engine File Policy Bypass Vulnerabilitycisco · secure firewall management center · CWE-693 | High7.5 | — | 2.0% | Jan 13, 2021 |
30Monitor | CVE-2007-1398Proof of concept | The frag3 preprocessor in Snort 2.6.1.1, 2.6.1.2, and 2.7.0 beta, when configured for inline use on Linux without the ip_conntrack module lolinux · linux kernel | High7.1 | — | 5.9% | Mar 10, 2007 |
29Monitor | CVE-2009-3641Proof of concept | Snort before 2.8.5.1, when the -v option is enabled, allows remote attackers to cause a denial of service (application crash) via a crafted snort · snort | Medium4.3 | — | 38.8% | Oct 28, 2009 |
28Monitor | CVE-2008-1804No exploit | preprocessors/spp_frag3.c in Sourcefire Snort before 2.8.1 does not properly identify packet fragments that have dissimilar TTL values, whicsnort · snort | Medium6.8 | — | 2.3% | May 22, 2008 |
24Monitor | CVE-2020-3299No exploit | Multiple Cisco Products SNORT HTTP Detection Engine File Policy Bypass Vulnerabilitycisco · secure firewall threat defense · CWE-693 | Medium5.8 | — | 2.3% | Oct 21, 2020 |
23Monitor | CVE-2023-20071No exploit | Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker tcisco · secure firewall threat defense · CWE-1039 | Medium5.8 | — | 0.5% | Nov 1, 2023 |
22Monitor | CVE-2021-1236No exploit | Multiple Cisco Products Snort Application Detection Engine Policy Bypass Vulnerabilitycisco · ios xe · CWE-670 | Medium5.3 | — | 2.2% | Jan 13, 2021 |
22Monitor | CVE-2021-1224No exploit | Multiple Cisco Products Snort TCP Fast Open File Policy Bypass Vulnerabilitycisco · secure firewall management center · CWE-693 | Medium5.3 | — | 2.0% | Jan 13, 2021 |
22Monitor | CVE-2021-1495No exploit | Multiple Cisco Products Snort HTTP Detection Engine File Policy Bypass Vulnerabilitycisco · secure firewall threat defense · CWE-755 | Medium5.3 | — | 1.7% | Apr 29, 2021 |
21Monitor | CVE-2006-6931No exploit | Algorithmic complexity vulnerability in Snort before 2.6.1, during predicate evaluation in rule matching for certain rules, allows remote atsnort · snort | Medium5.0 | — | 2.4% | Jan 16, 2007 |
21Monitor | CVE-2023-20246No exploit | Multiple Cisco products are affected by a vulnerability in Snort access control policies that could allow an unauthenticated, remote attackesnort · snort · CWE-290 | Medium5.3 | — | 0.6% | Nov 1, 2023 |
20Monitor | CVE-2000-1226No exploit | Snort 1.6, when running in straight ASCII packet logging mode or IDS mode with straight decoded ASCII packet logging selected, allows remotesnort · snort | Medium5.0 | — | 1.3% | Dec 31, 2000 |
20Monitor | CVE-2001-1558No exploit | Unknown vulnerability in IP defragmenter (frag2) in Snort before 1.8.3 allows attackers to cause a denial of service (crash).snort · snort | Medium5.0 | — | 1.1% | Dec 31, 2001 |
- CVE-2006-527664This week
Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire Intrusion Sensor; all
CriticalCVSS 10.0WeaponizedEPSS 79%snort · snortFeb 19, 2007
- CVE-2003-003344Plan
Buffer overflow in the RPC preprocessor for Snort 1.8 and 1.9.x before 1.9.1 allows remote attackers to execute arbitrary code via fragmente
CriticalCVSS 10.0No exploitEPSS 12%snort · snortMar 7, 2003
- CVE-2016-141736Monitor
Untrusted search path vulnerability in Snort 2.9.7.0-WIN32 allows remote attackers to execute arbitrary code and conduct DLL hijacking attac
HighCVSS 8.8No exploitEPSS 4%snort · snortJan 23, 2017
- CVE-2007-025132Monitor
Integer underflow in the DecodeGRE function in src/decode.c in Snort 2.6.1.2 allows remote attackers to trigger dereferencing of certain mem
HighCVSS 7.8No exploitEPSS 2%snort · snortJan 16, 2007
- CVE-2001-066931Monitor
Various Intrusion Detection Systems (IDS) including (1) Cisco Secure Intrusion Detection System, (2) Cisco Catalyst 6000 Intrusion Detection
HighCVSS 7.5Proof of conceptEPSS 4%cisco · catalyst 6000 intrusion detection system moduleOct 30, 2001
- CVE-2021-4011431Monitor
Multiple Cisco Products Snort Memory Leak Denial of Service Vulnerability
HighCVSS 7.5No exploitEPSS 2%cisco · secure firewall management centerOct 27, 2021
- CVE-2021-122331Monitor
Multiple Cisco Products Snort HTTP Detection Engine File Policy Bypass Vulnerability
HighCVSS 7.5No exploitEPSS 2%cisco · secure firewall management centerJan 13, 2021
- CVE-2007-139830Monitor
The frag3 preprocessor in Snort 2.6.1.1, 2.6.1.2, and 2.7.0 beta, when configured for inline use on Linux without the ip_conntrack module lo
HighCVSS 7.1Proof of conceptEPSS 6%linux · linux kernelMar 10, 2007
- CVE-2009-364129Monitor
Snort before 2.8.5.1, when the -v option is enabled, allows remote attackers to cause a denial of service (application crash) via a crafted
MediumCVSS 4.3Proof of conceptEPSS 39%snort · snortOct 28, 2009
- CVE-2008-180428Monitor
preprocessors/spp_frag3.c in Sourcefire Snort before 2.8.1 does not properly identify packet fragments that have dissimilar TTL values, whic
MediumCVSS 6.8No exploitEPSS 2%snort · snortMay 22, 2008
- CVE-2020-329924Monitor
Multiple Cisco Products SNORT HTTP Detection Engine File Policy Bypass Vulnerability
MediumCVSS 5.8No exploitEPSS 2%cisco · secure firewall threat defenseOct 21, 2020
- CVE-2023-2007123Monitor
Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker t
MediumCVSS 5.8No exploitEPSS 1%cisco · secure firewall threat defenseNov 1, 2023
- CVE-2021-123622Monitor
Multiple Cisco Products Snort Application Detection Engine Policy Bypass Vulnerability
MediumCVSS 5.3No exploitEPSS 2%cisco · ios xeJan 13, 2021
- CVE-2021-122422Monitor
Multiple Cisco Products Snort TCP Fast Open File Policy Bypass Vulnerability
MediumCVSS 5.3No exploitEPSS 2%cisco · secure firewall management centerJan 13, 2021
- CVE-2021-149522Monitor
Multiple Cisco Products Snort HTTP Detection Engine File Policy Bypass Vulnerability
MediumCVSS 5.3No exploitEPSS 2%cisco · secure firewall threat defenseApr 29, 2021
- CVE-2006-693121Monitor
Algorithmic complexity vulnerability in Snort before 2.6.1, during predicate evaluation in rule matching for certain rules, allows remote at
MediumCVSS 5.0No exploitEPSS 2%snort · snortJan 16, 2007
- CVE-2023-2024621Monitor
Multiple Cisco products are affected by a vulnerability in Snort access control policies that could allow an unauthenticated, remote attacke
MediumCVSS 5.3No exploitEPSS 1%snort · snortNov 1, 2023
- CVE-2000-122620Monitor
Snort 1.6, when running in straight ASCII packet logging mode or IDS mode with straight decoded ASCII packet logging selected, allows remote
MediumCVSS 5.0No exploitEPSS 1%snort · snortDec 31, 2000
- CVE-2001-155820Monitor
Unknown vulnerability in IP defragmenter (frag2) in Snort before 1.8.3 allows attackers to cause a denial of service (crash).
MediumCVSS 5.0No exploitEPSS 1%snort · snortDec 31, 2001