Vulnerabilidades em OISF

90 resultados
Análise Vexday

Com 55 CVEs catalogadas e nenhuma registrada em exploração ativa pelo CISA KEV, a taxa de exploração do OISF situa-se abaixo da média geral do catálogo, o que indica um perfil de risco relativamente contido no momento. A ausência de vulnerabilidades de severidade crítica e de provas de conceito públicas reforça esse cenário, embora 6 CVEs tenham surgido nos últimos 90 dias, sinalizando atividade de descoberta recente que merece acompanhamento. O tipo de falha mais frequente é CWE-770 (alocação irrestrita de recursos), padrão que pode impactar a disponibilidade de sistemas de inspeção de tráfego em ambientes de alta carga. A CVE mais perigosa ativa no momento é CVE-2024-23837, com EPSS de 0,0119, indicando probabilidade de exploração ainda baixa, mas suficiente para justificar priorização nos ciclos regulares de patching.

CVE-2025-64334HIGHSuricata is vulnerable to unbounded memory growth for decompressionEPSS 0.4%CVE-2025-64344HIGHSuricata is vulnerable to a stack overflow from unbounded stack allocation in LuaPushStringBufferEPSS 0.4%CVE-2026-31931HIGHSuricata tls: null dereference in tls.alpn rule keywordEPSS 0.4%CVE-2026-31933HIGHSuricata stream: quadratic complexity in stream inspectionEPSS 0.4%CVE-2026-31937HIGHSuricata dcerpc: quadratic complexity in dcerpc bufferingEPSS 0.4%CVE-2026-71418HIGHSuricata doh2: crafted HTTP/2 DATA frames can cause quadratic CPU consumptionEPSS 0.4%CVE-2026-45747HIGHSuricata lua/tls: null dereference in TlsGetCertInfoEPSS 0.3%CVE-2026-45770HIGHSuricata lua: excessive flow variable registration can bypass sandboxEPSS 0.3%CVE-2026-22261LOWSuricata eve/alert: http1 xff handling can lead to denial of serviceEPSS 0.3%CVE-2025-64333HIGHSuricata is vulnerable to a stack overflow from big content-typeEPSS 0.3%CVE-2025-64331HIGHSuricata is vulnerable to a stack overflow on large file transfers with http-body-printableEPSS 0.3%CVE-2024-47187HIGHSuricata datasets: missing hashtable random seed leads to potential DoSEPSS 0.3%CVE-2026-45767MEDIUMSuricata datasets: save to absolute filename can be bypassed when combined with load commandEPSS 0.3%CVE-2026-71855MEDIUMSuricata flow: IPv4/IPv6 hash collision can reuse wrong flow stateEPSS 0.3%CVE-2024-47188HIGHSuricata http/byte-ranges: missing hashtable random seed leads to potential DoSEPSS 0.3%CVE-2026-31934HIGHSuricata smtp/mine: quadratic complexity in extracting urlsEPSS 0.3%CVE-2026-31935HIGHSuricata http2: unbounded resource consumptionEPSS 0.3%CVE-2025-29918MEDIUMSuricata pcre: negated pcr can cause infinite loopEPSS 0.3%CVE-2025-29915HIGHSuricata af-packet: defrag option can lead to truncated packets affecting visibilityEPSS 0.3%CVE-2025-29916MEDIUMSuricata datasets: ruleset declared settings can lead to resource starvationEPSS 0.3%