RSS   Vulnerabilities for 'Snort'   RSS

2006-06-02
 
CVE-2006-2769

CWE-264
 

 
The HTTP Inspect preprocessor (http_inspect) in Snort 2.4.0 through 2.4.4 allows remote attackers to bypass "uricontent" rules via a carriage return (\r) after the URL and before the HTTP declaration.

 
2006-02-21
 
CVE-2006-0839

CWE-Other
 

 
The frag3 preprocessor in Sourcefire Snort 2.4.3 does not properly reassemble certain fragmented packets with IP options, which allows remote attackers to evade detection of certain attacks, possibly related to IP option lengths.

 
2005-10-18
 
CVE-2005-3252

 

 
Stack-based buffer overflow in the Back Orifice (BO) preprocessor for Snort before 2.4.3 allows remote attackers to execute arbitrary code via a crafted UDP packet.

 
2004-12-31
 
CVE-2004-2652

 

 
The DecodeTCPOptions function in decode.c in Snort before 2.3.0, when printing TCP/IP options using FAST output or verbose mode, allows remote attackers to cause a denial of service (crash) via packets with invalid TCP/IP options, which trigger a null dereference.

 
2003-05-05
 
CVE-2003-0209

 

 
Integer overflow in the TCP stream reassembly module (stream4) for Snort 2.0 and earlier allows remote attackers to execute arbitrary code via large sequence numbers in packets, which enable a heap-based buffer overflow.

 

 >>> Vendor: Sourcefire 8 Products
Snort
Intrusion sensor
3d sensor
Defense center
3d1000
3d2000
3d9900
Dc1000


Copyright 2024, cxsecurity.com

 

Back to Top