Oisf

Suricata

100 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.4%
  • Veröffentlicht 20.09.2026 01:20:20
  • Zuletzt bearbeitet 28.09.2026 18:29:51

Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.

  • EPSS 0.4%
  • Veröffentlicht 20.09.2026 01:18:05
  • Zuletzt bearbeitet 28.09.2026 18:30:00

Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires ap...

  • EPSS 0.31%
  • Veröffentlicht 18.09.2026 20:25:58
  • Zuletzt bearbeitet 28.09.2026 18:39:08

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, src/flow-hash.c can treat an IPv4 and IPv6 flow as equal without comparing the IP family when their raw a...

  • EPSS 0.35%
  • Veröffentlicht 18.09.2026 20:24:28
  • Zuletzt bearbeitet 28.09.2026 18:39:56

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, DNS-over-HTTP/2 processing in rust/src/http2/http2.rs retains previously processed HTTP/2 DATA frame content...

  • EPSS 0.15%
  • Veröffentlicht 18.09.2026 20:23:28
  • Zuletzt bearbeitet 29.09.2026 12:48:12

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, the Windows service installation and parameter-update logic in src/win32-service.c can pass an unquoted s...

  • EPSS 0.39%
  • Veröffentlicht 18.09.2026 20:22:15
  • Zuletzt bearbeitet 28.09.2026 18:34:40

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, AppLayerParserSetTransactionInspectId() in src/app-layer-parser.c uses an inverted guard and marks only alre...

  • EPSS 0.36%
  • Veröffentlicht 18.09.2026 20:21:06
  • Zuletzt bearbeitet 28.09.2026 18:34:20

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.5 until 8.0.6, the FTP parser in src/app-layer-ftp.c can continue allocating transactions after app-layer.protocols.ftp.max...

  • EPSS 0.44%
  • Veröffentlicht 18.09.2026 20:20:01
  • Zuletzt bearbeitet 28.09.2026 18:33:31

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, the SMB parser can retain force-completed transactions on flows where Suricata sees payload in only one d...

  • EPSS 0.41%
  • Veröffentlicht 18.09.2026 20:18:38
  • Zuletzt bearbeitet 28.09.2026 18:35:07

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the SMTP MIME parser in rust/src/mime/smtp.rs does not fully reset state when processing Content-Type: messa...

Exploit
  • EPSS 0.12%
  • Veröffentlicht 18.09.2026 20:17:48
  • Zuletzt bearbeitet 28.09.2026 18:35:19

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, src/datasets-context-json.c assumes that a configured JSON or NDJSON dataset value_key resolves to a string....