Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Openinfosecfoundation

First CVE: May 30, 2014Active for: 12 yearsTotal CVEs: 6

The Open Information Security Foundation maintains Suricata, a widely embedded open-source network intrusion detection and prevention engine that sits on the monitoring edge of many network defenses despite the vendor's focused product portfolio. Vulnerabilities affecting this project skew toward serious outcomes, with a meaningful share reaching critical severity and concentrating in parser-oriented and validation-layer weakness classes including improper input validation and inadequately implemented security checks that are inherent to processing untrusted network traffic. Defenders should treat Suricata updates as priority items for detection and prevention infrastructure; current severity, exploitation, and exposure figures are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Openinfosecfoundation over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 30, 2014
12 years ago
Most Recent CVE
Oct 23, 2017
3,196 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2015-8954CRITICAL
The MemcmpLowercase function in Suricata before 2.0.6 improperly excludes the first byte from comparisons, which might allow remote attackers to bypass intrusion-prevention functio
Mar 20, 20179.825NONO
CVE-2017-7177HIGH
Suricata before 3.2.1 has an IPv4 defragmentation evasion issue caused by lack of a check for the IP protocol during fragment matching.
Mar 18, 20177.525NONO
CVE-2017-15377HIGH
In Suricata before 4.x, it was possible to trigger lots of redundant checks on the content of crafted network traffic with a certain signature, because of DetectEngineContentInspec
Oct 23, 20177.524NONO
CVE-2014-6603MEDIUM
The SSHParseBanner function in SSH parser (app-layer-ssh.c) in Suricata before 2.0.4 allows remote attackers to bypass SSH rules, cause a denial of service (crash), or possibly hav
Oct 7, 20145.021NONO
CVE-2015-0971MEDIUM
The DER parser in Suricata before 2.0.8 allows remote attackers to cause a denial of service (crash) via vectors related to SSL/TLS certificates.
May 14, 20155.015NONO
CVE-2013-5919MEDIUM
Suricata before 1.4.6 allows remote attackers to cause a denial of service (crash) via a malformed SSL record.
May 30, 20145.015NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
50%
33%
17%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network3 (50.0%)
Unknown3 (50.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (50.0%)
High0 (0.0%)
Unknown3 (50.0%)
User Interaction
None3 (50.0%)
Unknown3 (50.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (50.0%)
Unknown3 (50.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Openinfosecfoundation.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Openinfosecfoundation — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Openinfosecfoundation's Products

View all 2 CNAs →

Top CWEs