Oisf
Oisf Libhtp: vulnerabilidades y CVE
Oisf Libhtp tiene 7 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-53537 | Alta (7.5) | 0.44% | — | 23 jul 2025 | LibHTP is a security-aware parser for the HTTP protocol and its related bits and pieces. In versions 0.5.50 and below, there is a traffic-induced memory leak that can starve the process of memory, leading to loss of… |
| CVE-2024-45797 | Alta (7.5) | 0.73% | — | 16 oct 2024 | LibHTP is a security-aware parser for the HTTP protocol and the related bits and pieces. Prior to version 0.5.49, unbounded processing of HTTP request and response headers can lead to excessive CPU time and memory… |
| CVE-2024-28871 | Alta (7.5) | 0.84% | — | 4 abr 2024 | LibHTP is a security-aware parser for the HTTP protocol and the related bits and pieces. Version 0.5.46 may parse malformed request traffic, leading to excessive CPU usage. Version 0.5.47 contains a patch for the issue.… |
| CVE-2024-23837 | Alta (7.5) | 1.2% | — | 26 feb 2024 | LibHTP is a security-aware parser for the HTTP protocol. Crafted traffic can cause excessive processing time of HTTP headers, leading to denial of service. This issue is addressed in 0.5.46. |
| CVE-2019-17420 | Media (5.3) | 1.4% | — | 10 oct 2019 | In OISF LibHTP before 0.5.31, as used in Suricata 4.1.4 and other products, an HTTP protocol parsing error causes the http_header signature to not alert on a response with a single \r\n ending. |
| CVE-2018-10243 | Crítica (9.8) | 2.3% | — | 4 abr 2019 | htp_parse_authorization_digest in htp_parsers.c in LibHTP 0.5.26 allows remote attackers to cause a heap-based buffer over-read via an authorization digest header. |
| CVE-2015-0928 | Alta (7.5) | 2.3% | — | 28 ago 2017 | libhtp 0.5.15 allows remote attackers to cause a denial of service (NULL pointer dereference). |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.