sourcefire records
8 published records for vendor sourcefire.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 2 · 25%
- Pre-auth RCE
- 3
- With a fix record
- 25%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Attack profile
All records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
64This week | CVE-2006-5276Weaponized | Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire Intrusion Sensor; allsnort · snort | Critical10.0 | — | 79.4% | Feb 19, 2007 |
55Plan | CVE-2005-3252Weaponized | Stack-based buffer overflow in the Back Orifice (BO) preprocessor for Snort before 2.4.3 allows remote attackers to execute arbitrary code vsourcefire · snort | High7.5 | — | 83.6% | Oct 18, 2005 |
52Plan | CVE-2003-0209Proof of concept | Integer overflow in the TCP stream reassembly module (stream4) for Snort 2.0 and earlier allows remote attackers to execute arbitrary code vsmoothwall · smoothwall | Critical10.0 | — | 38.6% | May 5, 2003 |
39Monitor | CVE-2009-2344Proof of concept | The web-based management interfaces in Sourcefire Defense Center (DC) and 3D Sensor before 4.8.2 allow remote authenticated users to gain prsourcefire · 3d sensor · CWE-264 | Critical9.0 | — | 9.3% | Jul 7, 2009 |
34Monitor | CVE-2004-2652Proof of concept | The DecodeTCPOptions function in decode.c in Snort before 2.3.0, when printing TCP/IP options using FAST output or verbose mode, allows remosourcefire · snort | High7.8 | — | 11.2% | Dec 31, 2004 |
23Monitor | CVE-2006-2769Proof of concept | The HTTP Inspect preprocessor (http_inspect) in Snort 2.4.0 through 2.4.4 allows remote attackers to bypass "uricontent" rules via a carriagsourcefire · snort · CWE-264 | Medium5.0 | — | 10.8% | Jun 2, 2006 |
20Monitor | CVE-2006-0839No exploit | The frag3 preprocessor in Sourcefire Snort 2.4.3 does not properly reassemble certain fragmented packets with IP options, which allows remotsourcefire · snort | Medium5.0 | — | 1.4% | Feb 21, 2006 |
17Monitor | CVE-2010-2306No exploit | The default installation of Sourcefire 3D Sensor 1000, 2000, and 9900; and Defense Center 1000; uses the same static, private SSL keys for msourcefire · 3d1000 · CWE-16 | Medium4.3 | — | 1.5% | Jun 16, 2010 |
- CVE-2006-527664This week
Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire Intrusion Sensor; all
CriticalCVSS 10.0WeaponizedEPSS 79%snort · snortFeb 19, 2007
- CVE-2005-325255Plan
Stack-based buffer overflow in the Back Orifice (BO) preprocessor for Snort before 2.4.3 allows remote attackers to execute arbitrary code v
HighCVSS 7.5WeaponizedEPSS 84%sourcefire · snortOct 18, 2005
- CVE-2003-020952Plan
Integer overflow in the TCP stream reassembly module (stream4) for Snort 2.0 and earlier allows remote attackers to execute arbitrary code v
CriticalCVSS 10.0Proof of conceptEPSS 39%smoothwall · smoothwallMay 5, 2003
- CVE-2009-234439Monitor
The web-based management interfaces in Sourcefire Defense Center (DC) and 3D Sensor before 4.8.2 allow remote authenticated users to gain pr
CriticalCVSS 9.0Proof of conceptEPSS 9%sourcefire · 3d sensorJul 7, 2009
- CVE-2004-265234Monitor
The DecodeTCPOptions function in decode.c in Snort before 2.3.0, when printing TCP/IP options using FAST output or verbose mode, allows remo
HighCVSS 7.8Proof of conceptEPSS 11%sourcefire · snortDec 31, 2004
- CVE-2006-276923Monitor
The HTTP Inspect preprocessor (http_inspect) in Snort 2.4.0 through 2.4.4 allows remote attackers to bypass "uricontent" rules via a carriag
MediumCVSS 5.0Proof of conceptEPSS 11%sourcefire · snortJun 2, 2006
- CVE-2006-083920Monitor
The frag3 preprocessor in Sourcefire Snort 2.4.3 does not properly reassemble certain fragmented packets with IP options, which allows remot
MediumCVSS 5.0No exploitEPSS 1%sourcefire · snortFeb 21, 2006
- CVE-2010-230617Monitor
The default installation of Sourcefire 3D Sensor 1000, 2000, and 9900; and Defense Center 1000; uses the same static, private SSL keys for m
MediumCVSS 4.3No exploitEPSS 1%sourcefire · 3d1000Jun 16, 2010