Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Suricata CRITICAL 9.8
CVE-2019-16411

An issue was discovered in Suricata 4.1.4. By sending multiple IPv4 packets that have invalid IPv4Options, the function IPV4OptValidateTimestamp in d…

Mitigation only
Fix from $2,300 2019-09-24
Suricata CRITICAL 9.1
CVE-2019-15699

An issue was discovered in app-layer-ssl.c in Suricata 4.1.4. Upon receiving a corrupted SSLv3 (TLS 1.2) packet, the parser function TLSDecodeHSHello…

Mitigation only
Fix from $2,300 2019-09-24
Suricata CRITICAL 9.1
CVE-2019-16410

An issue was discovered in Suricata 4.1.4. By sending multiple fragmented IPv4 packets, the function Defrag4Reassemble in defrag.c tries to access a …

Mitigation only
Fix from $2,300 2019-09-24
Suricata HIGH 7.5
CVE-2019-10054

An issue was discovered in Suricata 4.1.3. The function process_reply_record_v3 lacks a check for the length of reply.data. It causes an invalid memo…

No fix yet
Fix from $1,950 2019-08-28
Suricata HIGH 7.5
CVE-2019-10055

An issue was discovered in Suricata 4.1.3. The function ftp_pasv_response lacks a check for the length of part1 and part2, leading to a crash within …

No fix yet
Fix from $1,950 2019-08-28
Suricata HIGH 7.5
CVE-2019-10056

An issue was discovered in Suricata 4.1.3. The code mishandles the case of sending a network packet with the right type, such that the function Decod…

No fix yet
Fix from $1,950 2019-08-28
Suricata HIGH 7.5
CVE-2019-10051

An issue was discovered in Suricata 4.1.3. If the function filetracker_newchunk encounters an unsafe "Some(sfcm) => { ft.new_chunk }" item, then the …

Patch available
Fix from $1,950 2019-08-28
Suricata HIGH 7.5
CVE-2019-10052

An issue was discovered in Suricata 4.1.3. If the network packet does not have the right length, the parser tries to access a part of a DHCP packet. …

No fix yet
Fix from $1,950 2019-08-28
Suricata CRITICAL 9.8
CVE-2019-10053

An issue was discovered in Suricata 4.1.x before 4.1.4. If the input of the function SSHParseBanner is composed only of a \n character, then the prog…

Fix: 4.1.4+
Fix from $2,300 2019-05-13
Suricata HIGH 7.5
CVE-2018-18956

The ProcessMimeEntity function in util-decode-mime.c in Suricata 4.x before 4.0.6 allows remote attackers to cause a denial of service (segfault and …

Fix: 4.0.6+
Fix from $1,950 2018-11-05
Suricata HIGH 7.5
CVE-2018-14568

Suricata before 4.0.5 stops TCP stream inspection upon a TCP RST from a server. This allows detection bypass because Windows TCP clients proceed with…

Fix: 4.0.5+
Fix from $1,950 2018-07-23
Suricata MEDIUM 5.3
CVE-2016-10728

An issue was discovered in Suricata before 3.1.2. If an ICMPv4 error packet is received as the first packet on a flow in the to_client direction, it …

Fix: 3.1.2+
Fix from $1,600 2018-07-23