CVEs we hold for Oisf
Records whose assigning authority named Oisf as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-71855Suricata flow: IPv4/IPv6 hash collision can reuse wrong flow stateOISF suricata CVE-2026-71418Suricata doh2: crafted HTTP/2 DATA frames can cause quadratic CPU consumptionOISF suricata CVE-2026-63452Suricata http1: repeated brotli compression bombs can cause excessive CPU consumptionOISF suricata CVE-2026-63451Suricata detect: frame rules without content and with transform can cause heap buffer overflow during rule loadOISF suricata CVE-2026-63450Suricata ftp: RETR/STOR before PORT/PASV can disable further IDS app-layer detectionOISF suricata CVE-2026-63449Suricata sip: large SIP message bodies can evade detection with frame keywordOISF suricata CVE-2026-63448Suricata smb: some SMB flows can cause resource exhaustionOISF suricata CVE-2026-63447Suricata ftp: crafted FTP traffic can cause quadratic CPU consumptionOISF suricata CVE-2026-63446Suricata app-layer: passed flows can retain transactions, causing resource exhaustionOISF suricata CVE-2026-57229Suricata smtp/mime: incomplete state reset allows detection bypassOISF suricata CVE-2026-57228Suricata smtp/mime: heap out-of-bounds read quoted-printable decoderOISF suricata CVE-2026-57227Suricata mqtt: unbounded resource consumption from repeated pubrec and pubrel messagesOISF suricata CVE-2026-57226Suricata swf: heap buffer overflow in SWF decompression depth handlingOISF suricata CVE-2026-57225Suricata datasets: NULL pointer dereference in JSON/NDJSON dataset loadingOISF suricata CVE-2026-57224Suricata dhcp: unbounded transactions in unidirectional traffic can lead to resource exhaustionOISF suricata CVE-2026-57223Suricata windows: unquoted LocalSystem service ImagePath can allow local privilege escalationOISF suricata CVE-2026-57222Suricata ippair: hash collision can cause incorrect state reuse across IPv4 and IPv6OISF suricata CVE-2026-46387Suricata http2: decompression bomb can cause denial of service in SuricataOISF suricata CVE-2026-46352Suricata defrag: fragmented encapsulated traffic with fragments can lead to deadlockOISF suricata CVE-2026-45770Suricata lua: excessive flow variable registration can bypass sandboxOISF suricata CVE-2026-45769ikev2: unbounded client transform storage can lead to resource exhaustionOISF suricata CVE-2026-45768Suricata ldap: unbounded responses per transaction can lead to resource exhaustionOISF suricata CVE-2026-45767Suricata datasets: save to absolute filename can be bypassed when combined with load commandOISF suricata CVE-2026-45766Suricata nfs: unbounded stateful structures can lead to resource exhaustionOISF suricata CVE-2026-45765Suricata dnp3: unbounded reassembly can lead to resource exhaustionOISF suricata CVE-2026-45764Suricata http2: protocol-change type confusion can lead to denial of serviceOISF suricata CVE-2026-45763Suricata lua: sandbox allocation limit not enforced for new allocationsOISF suricata CVE-2026-45762Suricata defrag: missing address-family check can lead to remote crashOISF suricata CVE-2026-45761Suricata detect: case-insensitive frame handling can cause heap buffer overflow during rule loadOISF suricata CVE-2026-45759Suricata http1: quadratic Content-Disposition processing can lead to denial of serviceOISF suricata CVE-2026-45752Suricata detect/transform: use-after-free in decompress transformsOISF suricata CVE-2026-45751Suricata detect/transform: use-after-free in dotprefix transformOISF suricata CVE-2026-45747Suricata lua/tls: null dereference in TlsGetCertInfoOISF suricata CVE-2026-31937Suricata dcerpc: quadratic complexity in dcerpc bufferingOISF suricata CVE-2026-31935Suricata http2: unbounded resource consumptionOISF suricata CVE-2026-31934Suricata smtp/mine: quadratic complexity in extracting urlsOISF suricata CVE-2026-31933Suricata stream: quadratic complexity in stream inspectionOISF suricata CVE-2026-31932Suricata krb5: quadratic complexity in krb5 bufferingOISF suricata CVE-2026-31931Suricata tls: null dereference in tls.alpn rule keywordOISF suricata CVE-2026-22264Suricata detect/alert: heap-use-after-free on alert queue expansionOISF suricata CVE-2026-22263Suricata http1: quadratic complexity in headers parsing over multiple packetsOISF suricata CVE-2026-22262Suricata datasets: stack overflow when saving a setOISF suricata CVE-2026-22261Suricata eve/alert: http1 xff handling can lead to denial of serviceOISF suricata CVE-2026-22260Suricata http1: infinite recursion in decompressionOISF suricata CVE-2026-22259Suricata dnp3: unbounded transaction growthOISF suricata CVE-2026-22258Suricata DCERPC: unbounded fragment buffering leads to memory exhaustionOISF suricata CVE-2025-64344Suricata is vulnerable to a stack overflow from unbounded stack allocation in LuaPushStringBufferOISF suricata CVE-2025-64335Suricata is vulnerable to a null deref when used with base64_dataOISF suricata CVE-2025-64334Suricata is vulnerable to unbounded memory growth for decompressionOISF suricata CVE-2025-64333Suricata is vulnerable to a stack overflow from big content-typeOISF suricata CVE-2025-64332Suricata is vulnerable to a stack overflow on larger compressed dataOISF suricata CVE-2025-64331Suricata is vulnerable to a stack overflow on large file transfers with http-body-printableOISF suricata CVE-2025-64330Suricata is vulnerable to a heap buffer overflow on verdictOISF suricata CVE-2025-59150Suricata: Keyword tls.subjectaltname can lead to NULL-ptr derefOISF suricata CVE-2025-59149Suricata: Stack buffer overflow in rule parser when processing long keywords with transformsOISF suricata CVE-2025-59148Suricata's improper use of entropy keyword can lead to a NULL-ptr derefOISF suricata CVE-2025-59147Suricata is Vulnerable to Detection Bypass via Crafted Multiple SYN PacketsOISF suricata CVE-2025-53538Suricata's mishandling of data on HTTP2 stream 0 can lead to resource starvationOISF suricata CVE-2025-53537LibHTP's memory leak with lzma can lead to resource starvationOISF libhtp CVE-2025-29918Suricata pcre: negated pcr can cause infinite loopOISF suricata CVE-2025-29917Suricata decode_base64: signature can do large memory allocationOISF suricata CVE-2025-29916Suricata datasets: ruleset declared settings can lead to resource starvationOISF suricata CVE-2025-29915Suricata af-packet: defrag option can lead to truncated packets affecting visibilityOISF suricata CVE-2024-55629Suricata generic detection bypass using TCP urgent supportOISF suricata CVE-2024-55628Suricata oversized resource names utilizing DNS name compression can lead to resource starvationOISF suricata CVE-2024-55627Suricata segfault on StreamingBufferSlideToOffsetWithRegionsOISF suricata CVE-2024-55626Suricata oversized bpf file can lead to buffer overflowOISF suricata CVE-2024-55605Suricata allows stack overflow in transformsOISF suricata CVE-2024-47188Suricata http/byte-ranges: missing hashtable random seed leads to potential DoSOISF suricata CVE-2024-47187Suricata datasets: missing hashtable random seed leads to potential DoSOISF suricata CVE-2024-45797LibHTP's unbounded header handling leads to denial serviceOISF libhtp CVE-2024-45796Suricata defrag: off by one can lead to policy bypassOISF suricata CVE-2024-45795Suricata detect/datasets: reachable assertion with unimplemented rule optionOISF suricata CVE-2024-38536Suricata http/range: NULL-ptr deref when http.memcap is reachedOISF suricata CVE-2024-38534Suricata modbus: txs without responses are never freedOISF suricata CVE-2024-37151Suricata defrag: IP ID reuse can lead to policy bypassOISF suricata CVE-2024-32867Suricata's defrag contains various issues leading to policy bypassOISF suricata CVE-2024-32664Suricata's base64 contains an out of bounds writeOISF suricata CVE-2024-32663Suricata 's http2 parser contains an improper compressed header handling can lead to resource starvationOISF suricata CVE-2024-28870Suricata uses excessive resource use in malformed ssh traffic parsingOISF suricata CVE-2024-23839Suricata http: heap use after free with http.request_header and http.response_header keywordsOISF suricata CVE-2024-23837LibHTP unbounded folded header handling leads to denial serviceOISF libhtp CVE-2024-23836crafted traffic can cause denial of serviceOISF suricata CVE-2024-23835Suricata's pgsql: memory exhaustion use on record parsingOISF suricata 88 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.