Vulnerabilities > Snort

DATE CVE VULNERABILITY TITLE RISK
2008-05-22 CVE-2008-1804 Unspecified vulnerability in Snort
preprocessors/spp_frag3.c in Sourcefire Snort before 2.8.1 does not properly identify packet fragments that have dissimilar TTL values, which allows remote attackers to bypass detection rules by using a different TTL for each fragment.
network
snort
6.8
2007-03-10 CVE-2007-1398 Denial of Service vulnerability in Snort 2.6.1.1/2.6.1.2/2.7Beta1
The frag3 preprocessor in Snort 2.6.1.1, 2.6.1.2, and 2.7.0 beta, when configured for inline use on Linux without the ip_conntrack module loaded, allows remote attackers to cause a denial of service (segmentation fault and application crash) via certain UDP packets produced by send_morefrag_packet and send_overlap_packet.
network
linux snort
7.1
2007-02-20 CVE-2006-5276 Stack Buffer Overflow vulnerability in Snort/Sourcefire DCE/RPC Packet Reassembly
Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire Intrusion Sensor; allows remote attackers to execute arbitrary code via crafted SMB traffic.
network
low complexity
snort sourcefire
critical
10.0
2007-01-16 CVE-2007-0251 Unspecified vulnerability in Snort 2.6.1.2
Integer underflow in the DecodeGRE function in src/decode.c in Snort 2.6.1.2 allows remote attackers to trigger dereferencing of certain memory locations via crafted GRE packets, which may cause corruption of log files or writing of sensitive information into log files.
network
low complexity
snort
7.8
2007-01-16 CVE-2006-6931 Denial of Service vulnerability in Snort Backtracking
Algorithmic complexity vulnerability in Snort before 2.6.1, during predicate evaluation in rule matching for certain rules, allows remote attackers to cause a denial of service (CPU consumption and detection outage) via crafted network traffic, aka a "backtracking attack."
network
low complexity
snort
5.0
2003-03-07 CVE-2003-0033 Buffer Overflow vulnerability in Snort RPC Preprocessor Fragment Reassembly
Buffer overflow in the RPC preprocessor for Snort 1.8 and 1.9.x before 1.9.1 allows remote attackers to execute arbitrary code via fragmented RPC packets.
network
low complexity
snort
critical
10.0
2001-12-31 CVE-2001-1558 Denial-Of-Service vulnerability in Snort 1.8.0/1.8.1/1.8.2
Unknown vulnerability in IP defragmenter (frag2) in Snort before 1.8.3 allows attackers to cause a denial of service (crash).
network
low complexity
snort
5.0
2001-10-30 CVE-2001-0669 Various Intrusion Detection Systems (IDS) including (1) Cisco Secure Intrusion Detection System, (2) Cisco Catalyst 6000 Intrusion Detection System Module, (3) Dragon Sensor 4.x, (4) Snort before 1.8.1, (5) ISS RealSecure Network Sensor 5.x and 6.x before XPU 3.2, and (6) ISS RealSecure Server Sensor 5.5 and 6.0 for Windows, allow remote attackers to evade detection of HTTP attacks via non-standard "%u" Unicode encoding of ASCII characters in the requested URL.
network
low complexity
cisco iss snort enterasys
7.5
2000-12-31 CVE-2000-1226 Unspecified vulnerability in Snort 1.6
Snort 1.6, when running in straight ASCII packet logging mode or IDS mode with straight decoded ASCII packet logging selected, allows remote attackers to cause a denial of service (crash) by sending non-IP protocols that Snort does not know about, as demonstrated by an nmap protocol scan.
network
low complexity
snort
5.0