Vulnerabilities > Suricata IDS > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-10-10 CVE-2019-17420 Incomplete Cleanup vulnerability in multiple products
In OISF LibHTP before 0.5.31, as used in Suricata 4.1.4 and other products, an HTTP protocol parsing error causes the http_header signature to not alert on a response with a single \r\n ending.
network
low complexity
suricata-ids oisf CWE-459
5.3
2018-07-23 CVE-2016-10728 Improper Input Validation vulnerability in Suricata-Ids Suricata
An issue was discovered in Suricata before 3.1.2.
network
low complexity
suricata-ids CWE-20
5.3
2018-02-07 CVE-2018-6794 Protection Mechanism Failure vulnerability in multiple products
Suricata before 4.0.4 is prone to an HTTP detection bypass vulnerability in detect.c and stream-tcp.c.
network
low complexity
suricata-ids debian CWE-693
5.3