Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-38535


Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Suricata can run out of memory when parsing crafted HTTP/2 traffic. Upgrade to 6.0.20 or 7.0.6.


Published

2024-07-11T15:15:12.557

Last Modified

2024-11-21T09:26:14.610

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-770
  • Type: Primary
    CWE-770

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application oisf suricata < 6.0.20 Yes
Application oisf suricata < 7.0.6 Yes

References