Sourcefire's vulnerability footprint concentrates in intrusion-detection and network-security appliances, including the widely deployed Snort IDS platform and its proprietary 3D sensor line, which sit at critical chokepoints in network infrastructure. While the disclosed vulnerability volume remains modest, these products have a strong tendency to acquire public exploit code, making vendor advisories relevant to defenders operating or maintaining detection and enforcement infrastructure. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sourcefire over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-5276HIGH Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire Intrusion Sensor; allows remote attackers to execute arbitrar | Feb 20, 2007 | 10.0 | 86 | NO | YES |
CVE-2005-3252HIGH Stack-based buffer overflow in the Back Orifice (BO) preprocessor for Snort before 2.4.3 allows remote attackers to execute arbitrary code via a crafted UDP packet. | Oct 18, 2005 | 7.5 | 81 | NO | YES |
CVE-2003-0209HIGH Integer overflow in the TCP stream reassembly module (stream4) for Snort 2.0 and earlier allows remote attackers to execute arbitrary code via large sequence numbers in packets, wh | May 5, 2003 | 10.0 | 56 | NO | YES |
CVE-2009-2344HIGH The web-based management interfaces in Sourcefire Defense Center (DC) and 3D Sensor before 4.8.2 allow remote authenticated users to gain privileges via a $admin value for the admi | Jul 7, 2009 | 9.0 | 36 | NO | YES |
CVE-2004-2652HIGH The DecodeTCPOptions function in decode.c in Snort before 2.3.0, when printing TCP/IP options using FAST output or verbose mode, allows remote attackers to cause a denial of servic | Dec 31, 2004 | 7.8 | 34 | NO | YES |
CVE-2006-2769MEDIUM The HTTP Inspect preprocessor (http_inspect) in Snort 2.4.0 through 2.4.4 allows remote attackers to bypass "uricontent" rules via a carriage return (\r) after the URL and before t | Jun 2, 2006 | 5.0 | 26 | NO | YES |
CVE-2010-2306MEDIUM The default installation of Sourcefire 3D Sensor 1000, 2000, and 9900; and Defense Center 1000; uses the same static, private SSL keys for multiple devices and installations, which | Jun 16, 2010 | 4.3 | 16 | NO | NO |
CVE-2006-0839MEDIUM The frag3 preprocessor in Sourcefire Snort 2.4.3 does not properly reassemble certain fragmented packets with IP options, which allows remote attackers to evade detection of certai | Feb 22, 2006 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sourcefire.
Media articles that mention a CVE ID that affects a product developed by Sourcefire — matched by CVE ID, not by vendor name.