OISF kayıtları
oisf üreticisine ait 108 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %99,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-400 Uncontrolled Resource Consumption16
- CWE-770 Allocation of Resources Without Limits or Throttling11
- CWE-476 NULL Pointer Dereference8
- CWE-121 Stack-based Buffer Overflow6
- CWE-407 Inefficient Algorithmic Complexity6
- CWE-416 Use After Free5
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
108 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2018-10243İstismar yok | htp_parse_authorization_digest in htp_parsers.c in LibHTP 0.5.26 allows remote attackers to cause a heap-based buffer over-read via an authooisf · libhtp · CWE-125 | Kritik9,8 | — | %2,3 | 4 Nis 2019 |
39İzleyin | CVE-2018-10244İstismar yok | Suricata version 4.0.4 incorrectly handles the parsing of an EtherNet/IP PDU.oisf · suricata · CWE-190 | Kritik9,8 | — | %1,7 | 4 Nis 2019 |
39İzleyin | CVE-2021-37592İstismar yok | Suricata before 5.0.8 and 6.x before 6.0.4 allows TCP evasion via a client with a crafted TCP/IP stack that can send a certain sequence of soisf · suricata · CWE-787 | Kritik9,8 | — | %1,6 | 19 Kas 2021 |
39İzleyin | CVE-2023-35853İstismar yok | In Suricata before 6.0.13, an adversary who controls an external source of Lua rules may be able to execute Lua code.oisf · suricata · CWE-94 | Kritik9,8 | — | %1,0 | 19 Haz 2023 |
39İzleyin | CVE-2026-22262İstismar yok | Suricata datasets: stack overflow when saving a setoisf · suricata · CWE-121 | Kritik9,8 | — | %0,5 | 27 Oca 2026 |
37İzleyin | CVE-2019-18792İstismar yok | An issue was discovered in Suricata 5.0.0.oisf · suricata · CWE-436 | Kritik9,1 | — | %2,5 | 6 Oca 2020 |
37İzleyin | CVE-2026-94084İstismar yok | Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with oisf · suricata · CWE-416 | Kritik9,4 | — | %0,5 | 20 Eyl 2026 |
37İzleyin | CVE-2026-94083İstismar yok | Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even thoisf · suricata · CWE-843 | Kritik9,4 | — | %0,5 | 20 Eyl 2026 |
36İzleyin | CVE-2026-45764İstismar yok | Suricata http2: protocol-change type confusion can lead to denial of serviceoisf · suricata · CWE-843 | Kritik9,1 | — | %0,6 | 10 Eyl 2026 |
36İzleyin | CVE-2026-57228İstismar yok | Suricata smtp/mime: heap out-of-bounds read quoted-printable decoderoisf · suricata · CWE-125 | Kritik9,1 | — | %0,6 | 18 Eyl 2026 |
36İzleyin | CVE-2026-22264İstismar yok | Suricata detect/alert: heap-use-after-free on alert queue expansionoisf · suricata · CWE-416 | Kritik9,1 | — | %0,4 | 27 Oca 2026 |
32İzleyin | CVE-2018-1000167İstismar yok | OISF suricata-update version 1.0.0a1 contains an Insecure Deserialization vulnerability in the insecure yaml.load-Function as used in the fooisf · suricata-update · CWE-502 | Yüksek7,8 | — | %4,1 | 18 Nis 2018 |
32İzleyin | CVE-2024-23839İstismar yok | Suricata http: heap use after free with http.request_header and http.response_header keywordsoisf · suricata · CWE-416 | Yüksek8,1 | — | %0,8 | 26 Şub 2024 |
31İzleyin | CVE-2020-19678İstismar yok | Directory Traversal vulnerability found in Pfsense v.2.1.3 and Pfsense Suricata v.1.4.6 pkg v.1.0.1 allows a remote attacker to obtain sensipfsense · pfsense · CWE-22 | Yüksek7,5 | — | %3,5 | 6 Nis 2023 |
31İzleyin | CVE-2015-0928İstismar yok | libhtp 0.5.15 allows remote attackers to cause a denial of service (NULL pointer dereference).oisf · libhtp · CWE-476 | Yüksek7,5 | — | %2,3 | 28 Ağu 2017 |
31İzleyin | CVE-2019-1010251İstismar yok | Open Information Security Foundation Suricata prior to version 4.1.2 is affected by: Denial of Service - DNS detection bypass.oisf · suricata · CWE-20 | Yüksek7,5 | — | %2,1 | 18 Tem 2019 |
31İzleyin | CVE-2021-35063İstismar yok | Suricata before 5.0.7 and 6.x before 6.0.3 has a "critical evasion."oisf · suricata | Yüksek7,5 | — | %2,1 | 22 Tem 2021 |
31İzleyin | CVE-2021-45098İstismar yok | An issue was discovered in Suricata before 6.0.4.oisf · suricata | Yüksek7,5 | — | %1,8 | 16 Ara 2021 |
31İzleyin | CVE-2026-45769İstismar yok | ikev2: unbounded client transform storage can lead to resource exhaustionoisf · suricata · CWE-400 | Yüksek7,5 | — | %1,8 | 10 Eyl 2026 |
31İzleyin | CVE-2019-18625İstismar yok | An issue was discovered in Suricata 5.0.0.oisf · suricata | Yüksek7,5 | — | %1,7 | 6 Oca 2020 |
30İzleyin | CVE-2018-10242İstismar yok | Suricata version 4.0.4 incorrectly handles the parsing of the SSH banner.oisf · suricata · CWE-125 | Yüksek7,5 | — | %1,6 | 4 Nis 2019 |
30İzleyin | CVE-2019-1010279İstismar yok | Open Information Security Foundation Suricata prior to version 4.1.3 is affected by: Denial of Service - TCP/HTTP detection bypass.oisf · suricata · CWE-347 | Yüksek7,5 | — | %1,5 | 18 Tem 2019 |
30İzleyin | CVE-2019-10050İstismar yok | A buffer over-read issue was discovered in Suricata 4.1.x before 4.1.4.oisf · suricata · CWE-125 | Yüksek7,5 | — | %1,5 | 13 May 2019 |
30İzleyin | CVE-2024-23837İstismar yok | LibHTP unbounded folded header handling leads to denial serviceoisf · libhtp · CWE-770 | Yüksek7,5 | — | %1,2 | 26 Şub 2024 |
30İzleyin | CVE-2024-38535İstismar yok | Suricata http2: oom from duplicate headersoisf · suricata · CWE-770 | Yüksek7,5 | — | %1,2 | 11 Tem 2024 |
- CVE-2018-1024340Planlayın
htp_parse_authorization_digest in htp_parsers.c in LibHTP 0.5.26 allows remote attackers to cause a heap-based buffer over-read via an autho
KritikCVSS 9,8İstismar yokEPSS %2oisf · libhtp4 Nis 2019
- CVE-2018-1024439İzleyin
Suricata version 4.0.4 incorrectly handles the parsing of an EtherNet/IP PDU.
KritikCVSS 9,8İstismar yokEPSS %2oisf · suricata4 Nis 2019
- CVE-2021-3759239İzleyin
Suricata before 5.0.8 and 6.x before 6.0.4 allows TCP evasion via a client with a crafted TCP/IP stack that can send a certain sequence of s
KritikCVSS 9,8İstismar yokEPSS %2oisf · suricata19 Kas 2021
- CVE-2023-3585339İzleyin
In Suricata before 6.0.13, an adversary who controls an external source of Lua rules may be able to execute Lua code.
KritikCVSS 9,8İstismar yokEPSS %1oisf · suricata19 Haz 2023
- CVE-2026-2226239İzleyin
Suricata datasets: stack overflow when saving a set
KritikCVSS 9,8İstismar yokEPSS %1oisf · suricata27 Oca 2026
- CVE-2019-1879237İzleyin
An issue was discovered in Suricata 5.0.0.
KritikCVSS 9,1İstismar yokEPSS %3oisf · suricata6 Oca 2020
- CVE-2026-9408437İzleyin
Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with
KritikCVSS 9,4İstismar yokEPSS %1oisf · suricata20 Eyl 2026
- CVE-2026-9408337İzleyin
Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even th
KritikCVSS 9,4İstismar yokEPSS %1oisf · suricata20 Eyl 2026
- CVE-2026-4576436İzleyin
Suricata http2: protocol-change type confusion can lead to denial of service
KritikCVSS 9,1İstismar yokEPSS %1oisf · suricata10 Eyl 2026
- CVE-2026-5722836İzleyin
Suricata smtp/mime: heap out-of-bounds read quoted-printable decoder
KritikCVSS 9,1İstismar yokEPSS %1oisf · suricata18 Eyl 2026
- CVE-2026-2226436İzleyin
Suricata detect/alert: heap-use-after-free on alert queue expansion
KritikCVSS 9,1İstismar yokEPSS %0oisf · suricata27 Oca 2026
- CVE-2018-100016732İzleyin
OISF suricata-update version 1.0.0a1 contains an Insecure Deserialization vulnerability in the insecure yaml.load-Function as used in the fo
YüksekCVSS 7,8İstismar yokEPSS %4oisf · suricata-update18 Nis 2018
- CVE-2024-2383932İzleyin
Suricata http: heap use after free with http.request_header and http.response_header keywords
YüksekCVSS 8,1İstismar yokEPSS %1oisf · suricata26 Şub 2024
- CVE-2020-1967831İzleyin
Directory Traversal vulnerability found in Pfsense v.2.1.3 and Pfsense Suricata v.1.4.6 pkg v.1.0.1 allows a remote attacker to obtain sensi
YüksekCVSS 7,5İstismar yokEPSS %3pfsense · pfsense6 Nis 2023
- CVE-2015-092831İzleyin
libhtp 0.5.15 allows remote attackers to cause a denial of service (NULL pointer dereference).
YüksekCVSS 7,5İstismar yokEPSS %2oisf · libhtp28 Ağu 2017
- CVE-2019-101025131İzleyin
Open Information Security Foundation Suricata prior to version 4.1.2 is affected by: Denial of Service - DNS detection bypass.
YüksekCVSS 7,5İstismar yokEPSS %2oisf · suricata18 Tem 2019
- CVE-2021-3506331İzleyin
Suricata before 5.0.7 and 6.x before 6.0.3 has a "critical evasion."
YüksekCVSS 7,5İstismar yokEPSS %2oisf · suricata22 Tem 2021
- CVE-2021-4509831İzleyin
An issue was discovered in Suricata before 6.0.4.
YüksekCVSS 7,5İstismar yokEPSS %2oisf · suricata16 Ara 2021
- CVE-2026-4576931İzleyin
ikev2: unbounded client transform storage can lead to resource exhaustion
YüksekCVSS 7,5İstismar yokEPSS %2oisf · suricata10 Eyl 2026
- CVE-2019-1862531İzleyin
An issue was discovered in Suricata 5.0.0.
YüksekCVSS 7,5İstismar yokEPSS %2oisf · suricata6 Oca 2020
- CVE-2018-1024230İzleyin
Suricata version 4.0.4 incorrectly handles the parsing of the SSH banner.
YüksekCVSS 7,5İstismar yokEPSS %2oisf · suricata4 Nis 2019
- CVE-2019-101027930İzleyin
Open Information Security Foundation Suricata prior to version 4.1.3 is affected by: Denial of Service - TCP/HTTP detection bypass.
YüksekCVSS 7,5İstismar yokEPSS %1oisf · suricata18 Tem 2019
- CVE-2019-1005030İzleyin
A buffer over-read issue was discovered in Suricata 4.1.x before 4.1.4.
YüksekCVSS 7,5İstismar yokEPSS %1oisf · suricata13 May 2019
- CVE-2024-2383730İzleyin
LibHTP unbounded folded header handling leads to denial service
YüksekCVSS 7,5İstismar yokEPSS %1oisf · libhtp26 Şub 2024
- CVE-2024-3853530İzleyin
Suricata http2: oom from duplicate headers
YüksekCVSS 7,5İstismar yokEPSS %1oisf · suricata11 Tem 2024