Записи sourcefire
8 опубликованных записей вендора sourcefire.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 2 · 25 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 25 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
64На этой неделе | CVE-2006-5276Готовый эксплойт | Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire Intrusion Sensor; allsnort · snort | Критическая10,0 | — | 79,4 % | 19 февр. 2007 г. |
55В плане | CVE-2005-3252Готовый эксплойт | Stack-based buffer overflow in the Back Orifice (BO) preprocessor for Snort before 2.4.3 allows remote attackers to execute arbitrary code vsourcefire · snort | Высокая7,5 | — | 83,6 % | 18 окт. 2005 г. |
52В плане | CVE-2003-0209Proof of concept | Integer overflow in the TCP stream reassembly module (stream4) for Snort 2.0 and earlier allows remote attackers to execute arbitrary code vsmoothwall · smoothwall | Критическая10,0 | — | 38,6 % | 5 мая 2003 г. |
39Наблюдать | CVE-2009-2344Proof of concept | The web-based management interfaces in Sourcefire Defense Center (DC) and 3D Sensor before 4.8.2 allow remote authenticated users to gain prsourcefire · 3d sensor · CWE-264 | Критическая9,0 | — | 9,3 % | 7 июл. 2009 г. |
34Наблюдать | CVE-2004-2652Proof of concept | The DecodeTCPOptions function in decode.c in Snort before 2.3.0, when printing TCP/IP options using FAST output or verbose mode, allows remosourcefire · snort | Высокая7,8 | — | 11,2 % | 31 дек. 2004 г. |
23Наблюдать | CVE-2006-2769Proof of concept | The HTTP Inspect preprocessor (http_inspect) in Snort 2.4.0 through 2.4.4 allows remote attackers to bypass "uricontent" rules via a carriagsourcefire · snort · CWE-264 | Средняя5,0 | — | 10,8 % | 2 июн. 2006 г. |
20Наблюдать | CVE-2006-0839Эксплойта нет | The frag3 preprocessor in Sourcefire Snort 2.4.3 does not properly reassemble certain fragmented packets with IP options, which allows remotsourcefire · snort | Средняя5,0 | — | 1,4 % | 21 февр. 2006 г. |
17Наблюдать | CVE-2010-2306Эксплойта нет | The default installation of Sourcefire 3D Sensor 1000, 2000, and 9900; and Defense Center 1000; uses the same static, private SSL keys for msourcefire · 3d1000 · CWE-16 | Средняя4,3 | — | 1,5 % | 16 июн. 2010 г. |
- CVE-2006-527664На этой неделе
Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire Intrusion Sensor; all
КритическаяCVSS 10,0Готовый эксплойтEPSS 79 %snort · snort19 февр. 2007 г.
- CVE-2005-325255В плане
Stack-based buffer overflow in the Back Orifice (BO) preprocessor for Snort before 2.4.3 allows remote attackers to execute arbitrary code v
ВысокаяCVSS 7,5Готовый эксплойтEPSS 84 %sourcefire · snort18 окт. 2005 г.
- CVE-2003-020952В плане
Integer overflow in the TCP stream reassembly module (stream4) for Snort 2.0 and earlier allows remote attackers to execute arbitrary code v
КритическаяCVSS 10,0Proof of conceptEPSS 39 %smoothwall · smoothwall5 мая 2003 г.
- CVE-2009-234439Наблюдать
The web-based management interfaces in Sourcefire Defense Center (DC) and 3D Sensor before 4.8.2 allow remote authenticated users to gain pr
КритическаяCVSS 9,0Proof of conceptEPSS 9 %sourcefire · 3d sensor7 июл. 2009 г.
- CVE-2004-265234Наблюдать
The DecodeTCPOptions function in decode.c in Snort before 2.3.0, when printing TCP/IP options using FAST output or verbose mode, allows remo
ВысокаяCVSS 7,8Proof of conceptEPSS 11 %sourcefire · snort31 дек. 2004 г.
- CVE-2006-276923Наблюдать
The HTTP Inspect preprocessor (http_inspect) in Snort 2.4.0 through 2.4.4 allows remote attackers to bypass "uricontent" rules via a carriag
СредняяCVSS 5,0Proof of conceptEPSS 11 %sourcefire · snort2 июн. 2006 г.
- CVE-2006-083920Наблюдать
The frag3 preprocessor in Sourcefire Snort 2.4.3 does not properly reassemble certain fragmented packets with IP options, which allows remot
СредняяCVSS 5,0Эксплойта нетEPSS 1 %sourcefire · snort21 февр. 2006 г.
- CVE-2010-230617Наблюдать
The default installation of Sourcefire 3D Sensor 1000, 2000, and 9900; and Defense Center 1000; uses the same static, private SSL keys for m
СредняяCVSS 4,3Эксплойта нетEPSS 1 %sourcefire · 3d100016 июн. 2010 г.