Bro is a network security monitoring and analysis platform whose vulnerability profile concentrates in its core packet-analysis and protocol-parsing engine, where the durable signal centers on memory-safety and input-handling weaknesses including buffer-boundary violations, improper input validation, resource-management flaws, and out-of-bounds writes. Treat this as a compact vendor footprint reflecting the complexity of parsing untrusted network traffic; current severity, exploitation, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bro over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-1000458CRITICAL Bro before Bro v2.5.2 is vulnerable to an out of bounds write in the ContentLine analyzer allowing remote attackers to cause a denial of service (crash) and possibly other exploita | Jan 2, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-17019HIGH In Bro through 2.5.5, there is a DoS in IRC protocol names command parsing in analyzer/protocol/irc/IRC.cc. | Sep 13, 2018 | 7.5 | 25 | NO | NO |
CVE-2018-16807HIGH In Bro through 2.5.5, there is a memory leak potentially leading to DoS in scripts/base/protocols/krb/main.bro in the Kerberos protocol parser. | Sep 11, 2018 | 7.5 | 24 | NO | NO |
CVE-2015-1522HIGH analyzer/protocol/dnp3/DNP3.cc in Bro before 2.3.2 does not reject certain non-zero values of a packet length, which allows remote attackers to cause a denial of service (buffer ov | Apr 24, 2017 | 7.5 | 21 | NO | NO |
CVE-2015-1521HIGH analyzer/protocol/dnp3/DNP3.cc in Bro before 2.3.2 does not properly handle zero values of a packet length, which allows remote attackers to cause a denial of service (buffer overf | Apr 24, 2017 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bro.
Media articles that mention a CVE ID that affects a product developed by Bro — matched by CVE ID, not by vendor name.