Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

124 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.4%—Suricata-ids Suricata28/8/201917/6/2026
An issue was discovered in Suricata 4.1.3. The code mishandles the case of sending a network packet with the right type, such that the function DecodeEthernet in decode-ethernet.c is executed a second time. At this point, the algorithm cuts the first part of the packet and doesn't determine the current length.…
ModificadaAlta (7.5)1.5%—Suricata-ids Suricata28/8/201917/6/2026
An issue was discovered in Suricata 4.1.3. The function ftp_pasv_response lacks a check for the length of part1 and part2, leading to a crash within the ftp/mod.rs file.
ModificadaAlta (7.5)1.4%—Suricata-ids Suricata28/8/201917/6/2026
An issue was discovered in Suricata 4.1.3. The function process_reply_record_v3 lacks a check for the length of reply.data. It causes an invalid memory access and the program crashes within the nfs/nfs3.rs file.
ModificadaAlta (7.5)2.1%—Suricata-ids Suricata28/8/201917/6/2026
An issue was discovered in Suricata 4.1.3. If the network packet does not have the right length, the parser tries to access a part of a DHCP packet. At this point, the Rust environment runs into a panic in parse_clientid_option in the dhcp/parser.rs file.
ModificadaAlta (7.5)2.1%—Suricata-ids Suricata28/8/201917/6/2026
An issue was discovered in Suricata 4.1.3. If the function filetracker_newchunk encounters an unsafe "Some(sfcm) => { ft.new_chunk }" item, then the program enters an smb/files.rs error condition and crashes.
ModificadaAlta (7.5)1.5%—Oisf Suricata18/7/201917/6/2026
Open Information Security Foundation Suricata prior to version 4.1.3 is affected by: Denial of Service - TCP/HTTP detection bypass. The impact is: An attacker can evade a signature detection with a specialy formed sequence of network packets. The component is: detect.c…
ModificadaAlta (7.5)2.1%—Oisf Suricata18/7/201917/6/2026
Open Information Security Foundation Suricata prior to version 4.1.2 is affected by: Denial of Service - DNS detection bypass. The impact is: An attacker can evade a signature detection with a specialy formed network packet. The component is: app-layer-detect-proto.c, decode.c, decode-teredo.c and decode-ipv6.c…
ModificadaCrítica (9.8)1.7%—Suricata-ids Suricata13/5/201917/6/2026
An issue was discovered in Suricata 4.1.x before 4.1.4. If the input of the function SSHParseBanner is composed only of a \n character, then the program runs into a heap-based buffer over-read. This occurs because the erroneous search for \r results in an integer underflow.
ModificadaAlta (7.5)1.5%—Oisf Suricata13/5/201917/6/2026
A buffer over-read issue was discovered in Suricata 4.1.x before 4.1.4. If the input of the decode-mpls.c function DecodeMPLS is composed only of a packet of source address and destination address plus the correct type field and the right number for shim, an attacker can manipulate the control flow, such that the…
ModificadaCrítica (9.8)1.7%—Oisf Suricata4/4/201917/6/2026
Suricata version 4.0.4 incorrectly handles the parsing of an EtherNet/IP PDU. A malformed PDU can cause the parsing code to read beyond the allocated data because DecodeENIPPDU in app-layer-enip-commmon.c has an integer overflow during a length check.
ModificadaAlta (7.5)1.6%—Oisf SuricataDebian Linux4/4/201917/6/2026
Suricata version 4.0.4 incorrectly handles the parsing of the SSH banner. A malformed SSH banner can cause the parsing code to read beyond the allocated data because SSHParseBanner in app-layer-ssh.c lacks a length check.
ModificadaAlta (7.5)2.8%—Suricata-ids Suricata5/11/201817/6/2026
The ProcessMimeEntity function in util-decode-mime.c in Suricata 4.x before 4.0.6 allows remote attackers to cause a denial of service (segfault and daemon crash) via crafted input to the SMTP parser, as exploited in the wild in November 2018.
ModificadaAlta (7.5)2.0%—Suricata-ids Suricata23/7/201817/6/2026
Suricata before 4.0.5 stops TCP stream inspection upon a TCP RST from a server. This allows detection bypass because Windows TCP clients proceed with normal processing of TCP data that arrives shortly after an RST (i.e., they act as if the RST had not yet been received).
ModificadaMedia (5.3)2.1%—Suricata-ids Suricata23/7/201817/6/2026
An issue was discovered in Suricata before 3.1.2. If an ICMPv4 error packet is received as the first packet on a flow in the to_client direction, it confuses the rule grouping lookup logic. The toclient inspection will then continue with the wrong rule group. This can lead to missed detection.
ModificadaAlta (7.8)4.1%—Oisf Suricata-update18/4/201817/6/2026
OISF suricata-update version 1.0.0a1 contains an Insecure Deserialization vulnerability in the insecure yaml.load-Function as used in the following files: config.py:136, config.py:142, sources.py:99 and sources.py:131. The "list-sources"-command is affected by this bug. that can result in Remote Code Execution(even as…
ModificadaMedia (5.3)24%💥 ExploitSuricata-ids SuricataDebian Linux7/2/201817/6/2026
Suricata before 4.0.4 is prone to an HTTP detection bypass vulnerability in detect.c and stream-tcp.c. If a malicious server breaks a normal TCP flow and sends data before the 3-way handshake is complete, then the data sent by the malicious server will be accepted by web clients such as a web browser or Linux CLI…
ModificadaAlta (7.5)2.0%—Openinfosecfoundation Suricata23/10/201717/6/2026
In Suricata before 4.x, it was possible to trigger lots of redundant checks on the content of crafted network traffic with a certain signature, because of DetectEngineContentInspection in detect-engine-content-inspection.c. The search engine doesn't stop when it should after no match is found; instead, it stops only…
ModificadaCrítica (9.8)3.3%—Openinfosecfoundation Suricata20/3/201717/6/2026
The MemcmpLowercase function in Suricata before 2.0.6 improperly excludes the first byte from comparisons, which might allow remote attackers to bypass intrusion-prevention functionality via a crafted HTTP request.
ModificadaAlta (7.5)1.3%—Openinfosecfoundation Suricata18/3/201717/6/2026
Suricata before 3.2.1 has an IPv4 defragmentation evasion issue caused by lack of a check for the IP protocol during fragment matching.
ModificadaMedia (5)1.1%—Debian LinuxOpeninfosecfoundation Suricata14/5/201517/6/2026
The DER parser in Suricata before 2.0.8 allows remote attackers to cause a denial of service (crash) via vectors related to SSL/TLS certificates.
ModificadaMedia (5)3.2%—Openinfosecfoundation Suricata7/10/201417/6/2026
The SSHParseBanner function in SSH parser (app-layer-ssh.c) in Suricata before 2.0.4 allows remote attackers to bypass SSH rules, cause a denial of service (crash), or possibly have unspecified other impact via a crafted banner, which triggers a large memory allocation or an out-of-bounds write.
ModificadaMedia (5.8)2.1%—Netgate PfsensePfsense Suricata Package2/7/201417/6/2026
Multiple open redirect vulnerabilities in the Suricata package before 1.0.6 for pfSense through 2.1.4 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via (1) the referer parameter to suricata_rules_flowbits.php or (2) the returl parameter to suricata_select_alias.php.
ModificadaMedia (4.3)1.7%—Netgate PfsensePfsense Suricata Package2/7/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in suricata_select_alias.php in the Suricata package before 1.0.6 for pfSense through 2.1.4 allow remote attackers to inject arbitrary web script or HTML via unspecified variables.
ModificadaMedia (5)1.6%—Oisf SuricataOpeninfosecfoundation Suricata30/5/201416/6/2026
Suricata before 1.4.6 allows remote attackers to cause a denial of service (crash) via a malformed SSL record.
Orbitaley — Vulnerabilidades