CVE-2026-60109
- EPSS 0.5%
- Veröffentlicht 09.07.2026 14:19:17
- Zuletzt bearbeitet 14.07.2026 23:17:35
Zeek before 8.0.9 contains a null pointer dereference vulnerability in its Kerberos protocol analyzer that allows unauthenticated remote attackers to crash the sensor by sending a crafted KRB_ERROR message with error-code 25 (KDC_ERR_PREAUTH_REQUIRED...
CVE-2026-60108
- EPSS 0.44%
- Veröffentlicht 09.07.2026 14:16:57
- Zuletzt bearbeitet 14.07.2026 23:17:35
Zeek before 8.0.9 contains an uncontrolled memory consumption vulnerability in the FTP analyzer that allows unauthenticated remote attackers to cause process termination by sending a crafted FTP control session negotiating AUTH GSSAPI followed by a l...
CVE-2021-41732
- EPSS 0.88%
- Veröffentlicht 29.09.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:26:40
An issue was discovered in zeek version 4.1.0. There is a HTTP request splitting vulnerability that will invalidate any ZEEK HTTP based security analysis. NOTE: the vendor's position is that the observed behavior is intended
CVE-2019-12175
- EPSS 1.41%
- Veröffentlicht 17.07.2019 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:22:22
In Zeek Network Security Monitor (formerly known as Bro) before 2.6.2, a NULL pointer dereference in the Kerberos (aka KRB) protocol parser leads to DoS because a case-type index is mishandled.