Sngrep
Vendor:
First CVE: May 9, 2023 · Active for 3 years
6
Total CVEs
More Total CVEs than 80% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
8.4
Avg CVSS
Higher Avg CVSS than 75% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Sngrep over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 9, 2023
3 years ago
Most Recent CVE
May 29, 2024
788 days ago
CVE Severity & Scoring
Sngrep6 CVEs
67%
33%
All CVEs352,719 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local3 (50.0%)
Network3 (50.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (50.0%)
Unknown0 (0.0%)
Required3 (50.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None6 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-3120CRITICAL A stack-buffer overflow vulnerability exists in all versions of sngrep since v1.4.1. The flaw is due to inadequate bounds checking when copying 'Content-Length' and 'Warning' heade | Apr 10, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-3119CRITICAL A buffer overflow vulnerability exists in all versions of sngrep since v0.4.2, due to improper handling of 'Call-ID' and 'X-Call-ID' SIP headers. The functions sip_get_callid and s | Apr 10, 2024 | 9.8 | 27 | NO | NO |
CVE-2023-31982HIGH Sngrep v1.6.0 was discovered to contain a heap buffer overflow via the function capture_packet_reasm_ip at /src/capture.c. | May 9, 2023 | 7.8 | 24 | NO | NO |
CVE-2023-31981HIGH Sngrep v1.6.0 was discovered to contain a stack buffer overflow via the function packet_set_payload at /src/packet.c. | May 9, 2023 | 7.8 | 24 | NO | NO |
CVE-2023-36192HIGH Sngrep v1.6.0 was discovered to contain a heap buffer overflow via the function capture_ws_check_packet at /src/capture.c. | Jun 23, 2023 | 7.8 | 22 | NO | NO |
CVE-2024-35434HIGH Irontec Sngrep v1.8.1 was discovered to contain a heap buffer overflow via the function rtp_check_packet at /sngrep/src/rtp.c. This vulnerability allows attackers to cause a Denial | May 29, 2024 | 7.5 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Sngrep
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.8.1 | 1 | 7.5 | 0.6% | 0 | 0 |
| 1.6.0 | 3 | 7.8 | 0.3% | 0 | 0 |