Show filters
58 Total Results
Displaying 51-58 of 58
Sort by:
Attacker Value
Unknown
CVE-2017-15377
Disclosure Date: October 23, 2017 (last updated November 26, 2024)
In Suricata before 4.x, it was possible to trigger lots of redundant checks on the content of crafted network traffic with a certain signature, because of DetectEngineContentInspection in detect-engine-content-inspection.c. The search engine doesn't stop when it should after no match is found; instead, it stops only upon reaching inspection-recursion-limit (3000 by default).
0
Attacker Value
Unknown
CVE-2015-8954
Disclosure Date: March 20, 2017 (last updated November 26, 2024)
The MemcmpLowercase function in Suricata before 2.0.6 improperly excludes the first byte from comparisons, which might allow remote attackers to bypass intrusion-prevention functionality via a crafted HTTP request.
0
Attacker Value
Unknown
CVE-2017-7177
Disclosure Date: March 18, 2017 (last updated November 26, 2024)
Suricata before 3.2.1 has an IPv4 defragmentation evasion issue caused by lack of a check for the IP protocol during fragment matching.
0
Attacker Value
Unknown
CVE-2015-0971
Disclosure Date: May 14, 2015 (last updated October 05, 2023)
The DER parser in Suricata before 2.0.8 allows remote attackers to cause a denial of service (crash) via vectors related to SSL/TLS certificates.
0
Attacker Value
Unknown
CVE-2014-6603
Disclosure Date: October 07, 2014 (last updated October 05, 2023)
The SSHParseBanner function in SSH parser (app-layer-ssh.c) in Suricata before 2.0.4 allows remote attackers to bypass SSH rules, cause a denial of service (crash), or possibly have unspecified other impact via a crafted banner, which triggers a large memory allocation or an out-of-bounds write.
0
Attacker Value
Unknown
CVE-2014-4694
Disclosure Date: July 02, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in suricata_select_alias.php in the Suricata package before 1.0.6 for pfSense through 2.1.4 allow remote attackers to inject arbitrary web script or HTML via unspecified variables.
0
Attacker Value
Unknown
CVE-2014-4696
Disclosure Date: July 02, 2014 (last updated October 05, 2023)
Multiple open redirect vulnerabilities in the Suricata package before 1.0.6 for pfSense through 2.1.4 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via (1) the referer parameter to suricata_rules_flowbits.php or (2) the returl parameter to suricata_select_alias.php.
0
Attacker Value
Unknown
CVE-2013-5919
Disclosure Date: May 30, 2014 (last updated October 29, 2024)
Suricata before 1.4.6 allows remote attackers to cause a denial of service (crash) via a malformed SSL record.
0