pkg:Debian/suricata
88 total CVEsCRITICAL12HIGH60MEDIUM12
✅ Check your installed version
All known vulnerabilities
- from 0
- CRITICAL9.8CVE-2023-35853In Suricata before 6.0.13, an adversary who controls an external source of Lua rules may be able to execute Lua code.from 0
- CRITICAL9.8CVE-2021-37592Suricata before 5.0.8 and 6.x before 6.0.4 allows TCP evasion via a client with a crafted TCP/IP stack that can send a certain sequence of…from 0
- from 0, < 1:4.1.5-1
- from 0, < 1:4.1.4-1
- CRITICAL9.8CVE-2018-10244Suricata version 4.0.4 incorrectly handles the parsing of an EtherNet/IP PDU.from 0, < 1:4.0.5-1
- CRITICAL9.8CVE-2018-10243htp_parse_authorization_digest in htp_parsers.c in LibHTP 0.5.26 allows remote attackers to cause a heap-based buffer over-read via an auth…from 0, < 1:4.0.0-1
- CRITICAL9.8CVE-2015-8954The MemcmpLowercase function in Suricata before 2.0.6 improperly excludes the first byte from comparisons, which might allow remote attacke…from 0, < 2.0.6-1
- from 0
- from 0, < 1:5.0.2-1
- from 0, < 1:4.1.5-1
- from 0, < 1:4.1.5-1
- HIGH8.1CVE-2024-23839Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine.from 0, < 1:7.0.3-1
- from 0
- from 0
- from 0, < 1:8.0.4-1
- from 0
- from 0
- from 0, < 1:8.0.4-1
- from 0, < 1:8.0.3-1
- from 0
- from 0
- HIGH7.5CVE-2025-64344Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community.from 0
- HIGH7.5CVE-2025-64335Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community.from 0, < 1:8.0.2-1
- HIGH7.5CVE-2025-64334Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community.from 0, < 1:8.0.2-1
- HIGH7.5CVE-2025-64333Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community.from 0
- HIGH7.5CVE-2025-64332Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community.from 0
- HIGH7.5CVE-2025-64331Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community.from 0
- HIGH7.5CVE-2025-64330Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community.from 0, < 1:7.0.10-1+deb13u2
- HIGH7.5CVE-2025-59147Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community.from 0
- HIGH7.5CVE-2025-53538Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community.from 0
- HIGH7.5CVE-2025-29915Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine.from 0
- HIGH7.5CVE-2024-55629Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine.from 0
- HIGH7.5CVE-2024-55628Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine.from 0
- HIGH7.5CVE-2024-55627Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine.from 0
- HIGH7.5CVE-2024-55605Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine.from 0
- HIGH7.5CVE-2024-47522Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine.from 0
- HIGH7.5CVE-2024-47188Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine.from 0
- HIGH7.5CVE-2024-47187Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine.from 0
- HIGH7.5CVE-2024-45795Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine.from 0
- HIGH7.5CVE-2024-38536Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine.from 0
- HIGH7.5CVE-2024-38535Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine.from 0
- HIGH7.5CVE-2024-38534Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine.from 0
- HIGH7.5CVE-2024-37151Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine.from 0, < 1:6.0.1-3+deb11u1
- HIGH7.5CVE-2024-32663Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine.from 0, < 1:6.0.1-3+deb11u1
- HIGH7.5CVE-2024-28870Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine developed by the OISF…from 0
- HIGH7.5CVE-2024-23836Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine.from 0
- HIGH7.5CVE-2024-23835Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine.from 0, < 1:7.0.3-1
- HIGH7.5CVE-2023-35852In Suricata before 6.0.13 (when there is an adversary who controls an external source of rules), a dataset filename, that comes from a rule…from 0, < 1:6.0.1-3+deb11u1
- from 0, < 1:6.0.1-3+deb11u1
- from 0, < 1:6.0.1-3+deb11u1
- from 0, < 1:6.0.1-3
- from 0, < 1:5.0.2-1
- from 0, < 2.0.7-2+deb8u5
- from 0, < 1:4.1.4-1
- from 0, < 1:4.1.4-1
- from 0, < 1:4.1.4-1
- from 0, < 1:4.1.4-1
- from 0, < 1:4.1.4-1
- HIGH7.5CVE-2019-1010279Open Information Security Foundation Suricata prior to version 4.1.3 is affected by: Denial of Service - TCP/HTTP detection bypass.from 0, < 1:4.1.3-1
- HIGH7.5CVE-2019-1010251Open Information Security Foundation Suricata prior to version 4.1.2 is affected by: Denial of Service - DNS detection bypass.from 0, < 1:4.1.2-2
- from 0, < 1:4.1.4-1
- from 0, < 1:4.0.5-1
- from 0, < 2.0.7-2+deb8u4
- HIGH7.5CVE-2018-18956The ProcessMimeEntity function in util-decode-mime.c in Suricata 4.x before 4.0.6 allows remote attackers to cause a denial of service (seg…from 0, < 1:4.0.6-1
- HIGH7.5CVE-2018-14568Suricata before 4.0.5 stops TCP stream inspection upon a TCP RST from a server.from 0, < 1:4.0.5-1
- from 0, < 1:4.0.0-1
- from 0, < 2.0.7-2+deb8u3
- HIGH7.5CVE-2015-0928libhtp 0.5.15 allows remote attackers to cause a denial of service (NULL pointer dereference).from 0, < 2.0.7-1
- from 0, < 3.2.1-1
- from 0, < 1.2.1-2+deb7u1
- HIGH7.3CVE-2024-32664Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine.from 0
- MEDIUM5.5CVE-2025-29918Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine.from 0, < 1:6.0.1-3+deb11u1
- MEDIUM5.5CVE-2025-29917Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine.from 0
- MEDIUM5.5CVE-2025-29916Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine.from 0
- MEDIUM5.5CVE-2024-55626Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine.from 0, < 1:6.0.1-3+deb11u1
- from 0, < 1:8.0.3-1
- from 0
- MEDIUM5.3CVE-2024-45796Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine.from 0, < 1:6.0.1-3+deb11u1
- MEDIUM5.3CVE-2024-32867Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine.from 0
- MEDIUM5.3CVE-2024-24568Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine.from 0, < 1:7.0.3-1
- from 0, < 2.0.7-2+deb8u2
- from 0, < 3.1.2-1
- MEDIUM5.3CVE-2018-6794Suricata before 4.0.4 is prone to an HTTP detection bypass vulnerability in detect.c and stream-tcp.c.from 0, < 1:4.0.4-1
- from 0, < 2.0.8-1
- from 0, < 2.0.7-2+deb8u1
- —CVE-2014-6603The SSHParseBanner function in SSH parser (app-layer-ssh.c) in Suricata before 2.0.4 allows remote attackers to bypass SSH rules, cause a d…from 0, < 2.0.4-1
- —CVE-2013-5919Suricata before 1.4.6 allows remote attackers to cause a denial of service (crash) via a malformed SSL record.from 0, < 2.0-1