Skip to content
Noroxi

sourcefire records

8 published records for vendor sourcefire.

Researcher profile

Entered KEV
0 · 0%
Weaponized
2 · 25%
Pre-auth RCE
3
With a fix record
25%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    Recurring classes

    The weakness classes this vendor ships most often: where to look.

    CWE

    All records

    8 records
    • CVE-2006-5276
      64This week

      Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire Intrusion Sensor; all

      CriticalCVSS 10.0WeaponizedEPSS 79%

      snort · snortFeb 19, 2007

    • Stack-based buffer overflow in the Back Orifice (BO) preprocessor for Snort before 2.4.3 allows remote attackers to execute arbitrary code v

      HighCVSS 7.5WeaponizedEPSS 84%

      sourcefire · snortOct 18, 2005

    • Integer overflow in the TCP stream reassembly module (stream4) for Snort 2.0 and earlier allows remote attackers to execute arbitrary code v

      CriticalCVSS 10.0Proof of conceptEPSS 39%

      smoothwall · smoothwallMay 5, 2003

    • CVE-2009-2344
      39Monitor

      The web-based management interfaces in Sourcefire Defense Center (DC) and 3D Sensor before 4.8.2 allow remote authenticated users to gain pr

      CriticalCVSS 9.0Proof of conceptEPSS 9%

      sourcefire · 3d sensorJul 7, 2009

    • CVE-2004-2652
      34Monitor

      The DecodeTCPOptions function in decode.c in Snort before 2.3.0, when printing TCP/IP options using FAST output or verbose mode, allows remo

      HighCVSS 7.8Proof of conceptEPSS 11%

      sourcefire · snortDec 31, 2004

    • CVE-2006-2769
      23Monitor

      The HTTP Inspect preprocessor (http_inspect) in Snort 2.4.0 through 2.4.4 allows remote attackers to bypass "uricontent" rules via a carriag

      MediumCVSS 5.0Proof of conceptEPSS 11%

      sourcefire · snortJun 2, 2006

    • CVE-2006-0839
      20Monitor

      The frag3 preprocessor in Sourcefire Snort 2.4.3 does not properly reassemble certain fragmented packets with IP options, which allows remot

      MediumCVSS 5.0No exploitEPSS 1%

      sourcefire · snortFeb 21, 2006

    • CVE-2010-2306
      17Monitor

      The default installation of Sourcefire 3D Sensor 1000, 2000, and 9900; and Defense Center 1000; uses the same static, private SSL keys for m

      MediumCVSS 4.3No exploitEPSS 1%

      sourcefire · 3d1000Jun 16, 2010