Snort is a widely deployed open-source intrusion-detection and prevention engine whose vulnerability profile concentrates in a single product core that sits on the critical path of network monitoring and inline security operations. The vendor's disclosures cluster around resource-handling and control-flow weaknesses such as improper resource allocation, throttling failures, and incorrect execution paths that can disrupt detection capability or availability, and the vulnerabilities frequently acquire public exploit code. Defenders should monitor this vendor's releases closely given Snort's presence in SOC and perimeter defense architectures; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Snort over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-5276HIGH Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire Intrusion Sensor; allows remote attackers to execute arbitrar | Feb 20, 2007 | 10.0 | 86 | NO | YES |
CVE-2009-3641MEDIUM Snort before 2.8.5.1, when the -v option is enabled, allows remote attackers to cause a denial of service (application crash) via a crafted IPv6 packet that uses the (1) TCP or (2) | Oct 28, 2009 | 4.3 | 45 | NO | YES |
CVE-2003-0033HIGH Buffer overflow in the RPC preprocessor for Snort 1.8 and 1.9.x before 1.9.1 allows remote attackers to execute arbitrary code via fragmented RPC packets. | Mar 7, 2003 | 10.0 | 33 | NO | NO |
CVE-2016-1417HIGH Untrusted search path vulnerability in Snort 2.9.7.0-WIN32 allows remote attackers to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse tcapi.dll that is | Jan 23, 2017 | 8.8 | 29 | NO | NO |
CVE-2007-1398HIGH The frag3 preprocessor in Snort 2.6.1.1, 2.6.1.2, and 2.7.0 beta, when configured for inline use on Linux without the ip_conntrack module loaded, allows remote attackers to cause a | Mar 10, 2007 | 7.1 | 29 | NO | YES |
CVE-2001-0669HIGH Various Intrusion Detection Systems (IDS) including (1) Cisco Secure Intrusion Detection System, (2) Cisco Catalyst 6000 Intrusion Detection System Module, (3) Dragon Sensor 4.x, ( | Oct 30, 2001 | 7.5 | 29 | NO | YES |
CVE-2021-40114HIGH Multiple Cisco products are affected by a vulnerability in the way the Snort detection engine processes ICMP traffic that could allow an unauthenticated, remote attacker to cause a | Oct 27, 2021 | 7.5 | 26 | NO | NO |
CVE-2021-1223HIGH Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HT | Jan 13, 2021 | 7.5 | 25 | NO | NO |
CVE-2007-0251HIGH Integer underflow in the DecodeGRE function in src/decode.c in Snort 2.6.1.2 allows remote attackers to trigger dereferencing of certain memory locations via crafted GRE packets, w | Jan 16, 2007 | 7.8 | 22 | NO | NO |
CVE-2023-20071MEDIUM Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an a | Nov 1, 2023 | 5.8 | 21 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Snort.
Media articles that mention a CVE ID that affects a product developed by Snort — matched by CVE ID, not by vendor name.