Show filters
21 Total Results
Displaying 11-20 of 21
Sort by:
Attacker Value
Unknown
CVE-2009-3641
Disclosure Date: October 28, 2009 (last updated October 04, 2023)
Snort before 2.8.5.1, when the -v option is enabled, allows remote attackers to cause a denial of service (application crash) via a crafted IPv6 packet that uses the (1) TCP or (2) ICMP protocol.
0
Attacker Value
Unknown
CVE-2008-1804
Disclosure Date: May 22, 2008 (last updated October 04, 2023)
preprocessors/spp_frag3.c in Sourcefire Snort before 2.8.1 does not properly identify packet fragments that have dissimilar TTL values, which allows remote attackers to bypass detection rules by using a different TTL for each fragment.
0
Attacker Value
Unknown
CVE-2007-1398
Disclosure Date: March 10, 2007 (last updated October 04, 2023)
The frag3 preprocessor in Snort 2.6.1.1, 2.6.1.2, and 2.7.0 beta, when configured for inline use on Linux without the ip_conntrack module loaded, allows remote attackers to cause a denial of service (segmentation fault and application crash) via certain UDP packets produced by send_morefrag_packet and send_overlap_packet.
0
Attacker Value
Unknown
CVE-2006-5276
Disclosure Date: February 20, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire Intrusion Sensor; allows remote attackers to execute arbitrary code via crafted SMB traffic.
0
Attacker Value
Unknown
CVE-2006-6931
Disclosure Date: January 16, 2007 (last updated October 04, 2023)
Algorithmic complexity vulnerability in Snort before 2.6.1, during predicate evaluation in rule matching for certain rules, allows remote attackers to cause a denial of service (CPU consumption and detection outage) via crafted network traffic, aka a "backtracking attack."
0
Attacker Value
Unknown
CVE-2007-0251
Disclosure Date: January 16, 2007 (last updated October 04, 2023)
Integer underflow in the DecodeGRE function in src/decode.c in Snort 2.6.1.2 allows remote attackers to trigger dereferencing of certain memory locations via crafted GRE packets, which may cause corruption of log files or writing of sensitive information into log files.
0
Attacker Value
Unknown
CVE-2003-0033
Disclosure Date: March 07, 2003 (last updated February 22, 2025)
Buffer overflow in the RPC preprocessor for Snort 1.8 and 1.9.x before 1.9.1 allows remote attackers to execute arbitrary code via fragmented RPC packets.
0
Attacker Value
Unknown
CVE-2002-1970
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
SnortCenter 0.9.5, when configured to push Snort rules, stores the rules in a temporary file with world-readable and world-writable permissions, which allows local users to obtain usernames and passwords for the alert database servers.
0
Attacker Value
Unknown
CVE-2001-1558
Disclosure Date: December 31, 2001 (last updated February 22, 2025)
Unknown vulnerability in IP defragmenter (frag2) in Snort before 1.8.3 allows attackers to cause a denial of service (crash).
0
Attacker Value
Unknown
CVE-2001-0669
Disclosure Date: October 30, 2001 (last updated February 22, 2025)
Various Intrusion Detection Systems (IDS) including (1) Cisco Secure Intrusion Detection System, (2) Cisco Catalyst 6000 Intrusion Detection System Module, (3) Dragon Sensor 4.x, (4) Snort before 1.8.1, (5) ISS RealSecure Network Sensor 5.x and 6.x before XPU 3.2, and (6) ISS RealSecure Server Sensor 5.5 and 6.0 for Windows, allow remote attackers to evade detection of HTTP attacks via non-standard "%u" Unicode encoding of ASCII characters in the requested URL.
0