pkg:Debian/wireshark
796 total CVEsCRITICAL1HIGH236MEDIUM206
✅ Check your installed version
All known vulnerabilities
- CRITICAL9.8CVE-2022-0582Unaligned access in the CSN.1 protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet inject…from 0, < 3.4.16-0+deb11u1
- HIGH8.8CVE-2026-5402TLS protocol dissector heap overflow in Wireshark 4.6.0 to 4.6.4 allows denial of service and possible code executionfrom 0
- from 0, < 3.4.4-1
- from 0, < 2.6.20-0+deb9u3
- HIGH7.8CVE-2026-5656Profile import path traversal in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code executionfrom 0
- HIGH7.8CVE-2026-5405RDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code executionfrom 0
- HIGH7.8CVE-2026-5403SBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code executionfrom 0
- HIGH7.8CVE-2023-6175NetScreen file parser crash in Wireshark 4.0.0 to 4.0.10 and 3.6.0 to 3.6.18 allows denial of service via crafted capture filefrom 0, < 3.4.16-0+deb11u1
- HIGH7.5CVE-2026-6520OpenFlow v6 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of servicefrom 0
- HIGH7.5CVE-2026-6519MBIM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of servicefrom 0
- HIGH7.5CVE-2026-5657iLBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of servicefrom 0
- HIGH7.5CVE-2026-5655SDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 allows denial of servicefrom 0
- HIGH7.5CVE-2026-5654AMR-NB codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of servicefrom 0
- HIGH7.5CVE-2026-5653DCP-ETSI protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of servicefrom 0
- HIGH7.5CVE-2026-7379Memory leak in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of servicefrom 0
- from 0
- from 0
- HIGH7.5CVE-2026-7375UDS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of servicefrom 0
- HIGH7.5CVE-2026-6868HTTP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of servicefrom 0
- HIGH7.5CVE-2026-3203RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of servicefrom 0
- HIGH7.5CVE-2026-3202NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of servicefrom 0, < 4.6.4-1
- HIGH7.5CVE-2026-3201USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of servicefrom 0
- from 0, < 4.0.17-0+deb12u2
- HIGH7.5CVE-2025-1492Bundle Protocol and CBOR dissector crashes in Wireshark 4.4.0 to 4.4.3 and 4.2.0 to 4.2.10 allows denial of service via packet injection or…from 0, < 4.0.17-0+deb12u2
- HIGH7.5CVE-2024-9781AppleTalk and RELOAD Framing dissector crash in Wireshark 4.4.0 and 4.2.0 to 4.2.7 allows denial of service via packet injection or crafted…from 0, < 3.4.16-0+deb11u2
- HIGH7.5CVE-2024-4854MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via…from 0, < 3.4.16-0+deb11u1
- HIGH7.5CVE-2024-2955T.38 dissector crash in Wireshark 4.2.0 to 4.0.3 and 4.0.0 to 4.0.13 allows denial of service via packet injection or crafted capture filefrom 0, < 3.4.16-0+deb11u1
- HIGH7.5CVE-2024-0211DOCSIS dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture filefrom 0, < 3.4.16-0+deb11u1
- HIGH7.5CVE-2024-0210Zigbee TLV dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture filefrom 0, < 4.2.2-1
- HIGH7.5CVE-2024-0209IEEE 1609.2 dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or craft…from 0, < 3.4.16-0+deb11u1
- HIGH7.5CVE-2024-0208GVCP dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capt…from 0, < 3.4.16-0+deb11u1
- HIGH7.5CVE-2024-0207HTTP3 dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture filefrom 0, < 4.2.2-1
- HIGH7.5CVE-2023-4513BT SDP dissector memory leak in Wireshark 4.0.0 to 4.0.7 and 3.6.0 to 3.6.15 allows denial of service via packet injection or crafted captu…from 0, < 3.4.16-0+deb11u1
- HIGH7.5CVE-2023-4512CBOR dissector crash in Wireshark 4.0.0 to 4.0.6 allows denial of service via packet injection or crafted capture filefrom 0, < 3.4.16-0+deb11u1
- from 0, < 3.4.16-0+deb11u1
- from 0, < 2.6.20-0+deb10u8
- HIGH7.5CVE-2023-2879GDSDB infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or crafted capture filefrom 0, < 3.4.16-0+deb11u1
- HIGH7.5CVE-2023-1992RPCoRDMA dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture f…from 0, < 3.4.16-0+deb11u1
- HIGH7.5CVE-2022-3725Crash in the OPUS protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or crafted capture filefrom 0, < 4.0.0-1
- HIGH7.5CVE-2022-0586Infinite loop in RTMPT protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or…from 0, < 3.4.16-0+deb11u1
- HIGH7.5CVE-2022-0583Crash in the PVFS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or craft…from 0, < 3.4.16-0+deb11u1
- HIGH7.5CVE-2022-0581Crash in the CMS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafte…from 0, < 3.4.16-0+deb11u1
- HIGH7.5CVE-2021-4190Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service via packet injection or crafted capture filefrom 0, < 3.4.16-0+deb11u1
- HIGH7.5CVE-2021-4186Crash in the Gryphon dissector in Wireshark 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture filefrom 0, < 3.4.16-0+deb11u1
- HIGH7.5CVE-2021-4185Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted captur…from 0, < 3.4.16-0+deb11u1
- HIGH7.5CVE-2021-4184Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or craft…from 0, < 3.4.16-0+deb11u1
- HIGH7.5CVE-2021-4182Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture filefrom 0, < 3.4.16-0+deb11u1
- from 0, < 3.4.16-0+deb11u1
- from 0, < 3.4.16-0+deb11u1
- HIGH7.5CVE-2021-39929Uncontrolled Recursion in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet i…from 0, < 3.4.10-0+deb11u1
- HIGH7.5CVE-2021-39926Buffer overflow in the Bluetooth HCI_ISO dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted cap…from 0, < 3.4.10-0+deb11u1
- HIGH7.5CVE-2021-39925Buffer overflow in the Bluetooth SDP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injectio…from 0, < 3.4.10-0+deb11u1
- HIGH7.5CVE-2021-39924Large loop in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or…from 0, < 3.4.10-0+deb11u1
- HIGH7.5CVE-2021-39923Large loop in the PNRP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted c…from 0, < 3.4.10-0+deb11u1
- HIGH7.5CVE-2021-39922Buffer overflow in the C12.22 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or cr…from 0, < 3.4.10-0+deb11u1
- HIGH7.5CVE-2021-39921NULL pointer exception in the Modbus dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injectio…from 0, < 3.4.10-0+deb11u1
- HIGH7.5CVE-2021-39928NULL pointer exception in the IEEE 802.11 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet inj…from 0, < 3.4.10-0+deb11u1
- HIGH7.5CVE-2021-39920NULL pointer exception in the IPPUSB dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture…from 0, < 3.4.10-0+deb11u1
- HIGH7.5CVE-2021-22235Crash in DNP dissector in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 allows denial of service via packet injection or crafted capture filefrom 0, < 3.4.10-0+deb11u1
- HIGH7.5CVE-2021-22222Infinite loop in DVB-S2-BB dissector in Wireshark 3.4.0 to 3.4.5 allows denial of service via packet injection or crafted capture filefrom 0, < 3.4.10-0+deb11u1
- HIGH7.5CVE-2021-22174Crash in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture filefrom 0, < 3.4.3-1
- HIGH7.5CVE-2021-22173Memory leak in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture filefrom 0, < 3.4.3-1
- from 0, < 3.2.8-0.1
- HIGH7.5CVE-2020-26575In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector could enter an infinite loop.from 0, < 3.2.8-0.1
- HIGH7.5CVE-2020-25866In Wireshark 3.2.0 to 3.2.6 and 3.0.0 to 3.0.13, the BLIP protocol dissector has a NULL pointer dereference because a buffer was sized for…from 0, < 3.2.7-1
- HIGH7.5CVE-2020-25863In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the MIME Multipart dissector could crash.from 0, < 3.2.7-1
- HIGH7.5CVE-2020-25862In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the TCP dissector could crash.from 0, < 3.2.7-1
- HIGH7.5CVE-2020-15466In Wireshark 3.2.0 to 3.2.4, the GVCP dissector could go into an infinite loop.from 0, < 3.2.5-1
- HIGH7.5CVE-2020-13164In Wireshark 3.2.0 to 3.2.3, 3.0.0 to 3.0.10, and 2.6.0 to 2.6.16, the NFS dissector could crash.from 0, < 3.2.4-1
- HIGH7.5CVE-2020-11647In Wireshark 3.2.0 to 3.2.2, 3.0.0 to 3.0.9, and 2.6.0 to 2.6.15, the BACapp dissector could crash.from 0, < 3.2.3-1
- HIGH7.5CVE-2020-9431In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the LTE RRC dissector could leak memory.from 0, < 3.2.2-1
- HIGH7.5CVE-2020-9430In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the WiMax DLMAP dissector could crash.from 0, < 3.2.2-1
- from 0, < 3.2.2-1
- HIGH7.5CVE-2020-9428In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the EAP dissector could crash.from 0, < 3.2.2-1
- from 0, < 3.2.1-1
- HIGH7.5CVE-2019-19553In Wireshark 3.0.0 to 3.0.6 and 2.6.0 to 2.6.12, the CMS dissector could crash.from 0, < 3.0.7-1
- HIGH7.5CVE-2019-16319In Wireshark 3.0.0 to 3.0.3 and 2.6.0 to 2.6.10, the Gryphon dissector could go into an infinite loop.from 0, < 3.0.4-1
- HIGH7.5CVE-2019-13619In Wireshark 3.0.0 to 3.0.2, 2.6.0 to 2.6.9, and 2.4.0 to 2.4.15, the ASN.1 BER dissector and related dissectors could crash.from 0, < 2.6.10-1
- from 0, < 2.6.8-1.1
- from 0, < 2.6.20-0+deb9u1
- HIGH7.5CVE-2019-10903In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DCERPC SPOOLSS dissector could crash.from 0, < 2.6.8-1
- HIGH7.5CVE-2019-10901In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the LDSS dissector could crash.from 0, < 2.6.8-1
- HIGH7.5CVE-2019-10899In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the SRVLOC dissector could crash.from 0, < 2.6.8-1
- HIGH7.5CVE-2019-10896In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DOF dissector could crash.from 0, < 2.6.8-1
- HIGH7.5CVE-2019-10895In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the NetScaler file parser could crash.from 0, < 2.6.8-1
- from 0, < 2.6.8-1
- from 0, < 2.6.8-1.1~deb9u1
- from 0, < 1.12.1+g01b65bf-4+deb8u19
- HIGH7.5CVE-2019-9214In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the RPCAP dissector could crash.from 0, < 2.6.7-1
- HIGH7.5CVE-2019-9208In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the TCAP dissector could crash.from 0, < 2.6.7-1
- from 0, < 2.6.5-1
- HIGH7.5CVE-2018-19627In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the IxVeriWave file parser could crash.from 0, < 2.6.5-1
- HIGH7.5CVE-2018-19623In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the LBMPDM dissector could crash.from 0, < 2.6.5-1
- HIGH7.5CVE-2018-19622In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the MMSE dissector could go into an infinite loop.from 0, < 2.6.5-1
- from 0, < 2.6.5-1~deb9u1
- from 0, < 2.6.4-1
- HIGH7.5CVE-2018-18227In Wireshark 2.6.0 to 2.6.3 and 2.4.0 to 2.4.9, the MS-WSP protocol dissector could crash.from 0, < 2.6.4-1
- HIGH7.5CVE-2018-18226In Wireshark 2.6.0 to 2.6.3, the Steam IHS Discovery dissector could consume system memory.from 0, < 2.6.4-1
- from 0, < 2.6.4-1
- HIGH7.5CVE-2018-16058In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Bluetooth AVDTP dissector could crash.from 0, < 2.6.3-1
- HIGH7.5CVE-2018-16057In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Radiotap dissector could crash.from 0, < 2.6.3-1
- from 0, < 2.6.3-1~deb9u1
- from 0, < 2.6.3-1
- HIGH7.5CVE-2018-14370In Wireshark 2.6.0 to 2.6.1 and 2.4.0 to 2.4.7, the IEEE 802.11 protocol dissector could crash.from 0, < 2.6.2-1
- HIGH7.5CVE-2018-14369In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the HTTP2 dissector could crash.from 0, < 2.6.2-1
- HIGH7.5CVE-2018-14368In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the Bazaar protocol dissector could go into an infinite loop.from 0, < 2.6.2-1
- HIGH7.5CVE-2018-14367In Wireshark 2.6.0 to 2.6.1 and 2.4.0 to 2.4.7, the CoAP protocol dissector could crash.from 0, < 2.6.2-1
- HIGH7.5CVE-2018-14344In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the ISMP dissector could crash.from 0, < 2.6.2-1
- HIGH7.5CVE-2018-14343In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the ASN.1 BER dissector could crash.from 0, < 2.6.2-1
- HIGH7.5CVE-2018-14342In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the BGP protocol dissector could go into a large loop.from 0, < 2.6.2-1
- HIGH7.5CVE-2018-14341In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the DICOM dissector could go into a large or infinite loop.from 0, < 2.6.2-1
- HIGH7.5CVE-2018-14340In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, dissectors that support zlib decompression could crash.from 0, < 2.6.2-1
- from 0, < 2.6.2-1
- from 0, < 1.12.1+g01b65bf-4+deb8u15
- HIGH7.5CVE-2018-11362In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LDSS dissector could crash.from 0, < 2.6.1-1
- from 0, < 2.6.1-1
- HIGH7.5CVE-2018-11360In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the GSM A DTAP dissector could crash.from 0, < 2.6.1-1
- HIGH7.5CVE-2018-11359In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the RRC dissector and other dissectors could crash.from 0, < 2.6.1-1
- from 0, < 1.12.1+g01b65bf-4+deb8u6~deb7u11
- from 0, < 1.12.1+g01b65bf-4+deb8u14
- from 0, < 2.6.1-1
- HIGH7.5CVE-2018-11357In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LTP dissector and other dissectors could consume excessive memory.from 0, < 2.6.1-1
- HIGH7.5CVE-2018-11356In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the DNS dissector could crash.from 0, < 2.6.1-1
- HIGH7.5CVE-2018-9274In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, ui/failure_message.c has a memory leak.from 0, < 2.4.6-1
- HIGH7.5CVE-2018-9273In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-pcp.c has a memory leak.from 0, < 2.4.6-1
- HIGH7.5CVE-2018-9272In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-h223.c has a memory leak.from 0, < 2.4.6-1
- HIGH7.5CVE-2018-9271In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-multipart.c has a memory leak.from 0, < 2.4.6-1
- from 0, < 2.4.6-1
- HIGH7.5CVE-2018-9269In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-giop.c has a memory leak.from 0, < 2.4.6-1
- HIGH7.5CVE-2018-9268In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-smb2.c has a memory leak.from 0, < 2.4.6-1
- HIGH7.5CVE-2018-9267In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-lapd.c has a memory leak.from 0, < 2.4.6-1
- HIGH7.5CVE-2018-9266In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-isup.c has a memory leak.from 0, < 2.4.6-1
- HIGH7.5CVE-2018-9265In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-tn3270.c has a memory leak.from 0, < 2.4.6-1
- HIGH7.5CVE-2018-9264In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the ADB dissector could crash with a heap-based buffer overflow.from 0, < 2.4.6-1
- HIGH7.5CVE-2018-9263In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the Kerberos dissector could crash.from 0, < 2.4.6-1
- HIGH7.5CVE-2018-9262In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the VLAN dissector could crash.from 0, < 2.4.6-1
- HIGH7.5CVE-2018-9261In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the NBAP dissector could crash with a large loop that ends with a heap-based buffer overfl…from 0, < 2.4.6-1
- HIGH7.5CVE-2018-9260In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the IEEE 802.15.4 dissector could crash.from 0, < 2.4.6-1
- from 0, < 2.4.6-1
- from 0, < 2.4.6-1
- from 0, < 2.4.6-1
- HIGH7.5CVE-2018-9256In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the LWAPP dissector could crash.from 0, < 2.4.6-1
- HIGH7.5CVE-2018-7421In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the DMP dissector could go into an infinite loop.from 0, < 2.4.5-1
- HIGH7.5CVE-2018-7420In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the pcapng file parser could crash.from 0, < 2.4.5-1
- HIGH7.5CVE-2018-7419In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the NBAP dissector could crash.from 0, < 2.4.5-1
- HIGH7.5CVE-2018-7418In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the SIGCOMP dissector could crash.from 0, < 2.4.5-1
- HIGH7.5CVE-2018-7417In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the IPMI dissector could crash.from 0, < 2.4.5-1
- from 0, < 2.4.5-1
- HIGH7.5CVE-2018-7336In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the FCP protocol dissector could crash.from 0, < 2.4.5-1
- HIGH7.5CVE-2018-7335In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the IEEE 802.11 dissector could crash.from 0, < 2.4.5-1
- HIGH7.5CVE-2018-7334In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the UMTS MAC dissector could crash.from 0, < 2.4.5-1
- HIGH7.5CVE-2018-7333In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-rpcrdma.c had an infinite loop that was addressed by validating a c…from 0, < 2.4.5-1
- HIGH7.5CVE-2018-7332In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-reload.c had an infinite loop that was addressed by validating a le…from 0, < 2.4.5-1
- HIGH7.5CVE-2018-7331In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-ber.c had an infinite loop that was addressed by validating a lengt…from 0, < 2.4.5-1
- HIGH7.5CVE-2018-7330In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-thread.c had an infinite loop that was addressed by using a correct…from 0, < 2.4.5-1
- HIGH7.5CVE-2018-7329In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-s7comm.c had an infinite loop that was addressed by correcting off-…from 0, < 2.4.5-1
- HIGH7.5CVE-2018-7328In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-usb.c had an infinite loop that was addressed by rejecting short fr…from 0, < 2.4.5-1
- HIGH7.5CVE-2018-7327In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-openflow_v6.c had an infinite loop that was addressed by validating…from 0, < 2.4.5-1
- HIGH7.5CVE-2018-7326In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-lltd.c had an infinite loop that was addressed by using a correct i…from 0, < 2.4.5-1
- HIGH7.5CVE-2018-7325In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-rpki-rtr.c had an infinite loop that was addressed by validating a…from 0, < 2.4.5-1
- HIGH7.5CVE-2018-7324In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-sccp.c had an infinite loop that was addressed by using a correct i…from 0, < 2.4.5-1
- HIGH7.5CVE-2018-7323In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-wccp.c had a large loop that was addressed by ensuring that a calcu…from 0, < 2.4.5-1
- from 0, < 1.12.1+g01b65bf-4+deb8u6~deb7u10
- from 0, < 2.4.5-1
- HIGH7.5CVE-2018-7321In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-thrift.c had a large loop that was addressed by not proceeding with…from 0, < 2.4.5-1
- HIGH7.5CVE-2018-7320In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the SIGCOMP protocol dissector could crash.from 0, < 2.4.5-1
- HIGH7.5CVE-2018-5336In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the JSON, XML, NTP, XMPP, and GDB dissectors could crash.from 0, < 2.4.4-1
- HIGH7.5CVE-2017-17997In Wireshark before 2.2.12, the MRDISC dissector misuses a NULL pointer and crashes.from 0, < 2.4.0-1
- HIGH7.5CVE-2017-17935The File_read_line function in epan/wslua/wslua_file.c in Wireshark through 2.2.11 does not properly strip '\n' characters, which allows re…from 0, < 2.4.4-1
- HIGH7.5CVE-2017-17085In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the CIP Safety dissector could crash.from 0, < 2.4.3-1
- HIGH7.5CVE-2017-17084In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the IWARP_MPA dissector could crash.from 0, < 2.4.3-1
- HIGH7.5CVE-2017-17083In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the NetBIOS dissector could crash.from 0, < 2.4.3-1
- HIGH7.5CVE-2017-15193In Wireshark 2.4.0 to 2.4.1 and 2.2.0 to 2.2.9, the MBIM dissector could crash or exhaust system memory.from 0, < 2.4.2-1
- HIGH7.5CVE-2017-15192In Wireshark 2.4.0 to 2.4.1 and 2.2.0 to 2.2.9, the BT ATT dissector could crash.from 0, < 2.4.2-1
- HIGH7.5CVE-2017-15191In Wireshark 2.4.0 to 2.4.1, 2.2.0 to 2.2.9, and 2.0.0 to 2.0.15, the DMP dissector could crash.from 0, < 2.4.2-1
- from 0, < 2.4.2-1
- HIGH7.5CVE-2017-15189In Wireshark 2.4.0 to 2.4.1, the DOCSIS dissector could go into an infinite loop.from 0, < 2.4.2-1
- HIGH7.5CVE-2017-13767In Wireshark 2.4.0, 2.2.0 to 2.2.8, and 2.0.0 to 2.0.14, the MSDP dissector could go into an infinite loop.from 0, < 2.4.1-1
- HIGH7.5CVE-2017-13766In Wireshark 2.4.0 and 2.2.0 to 2.2.8, the Profinet I/O dissector could crash with an out-of-bounds write.from 0, < 2.4.1-1
- HIGH7.5CVE-2017-13765In Wireshark 2.4.0, 2.2.0 to 2.2.8, and 2.0.0 to 2.0.14, the IrCOMM dissector has a buffer over-read and application crash.from 0, < 2.4.1-1
- HIGH7.5CVE-2017-13764In Wireshark 2.4.0, the Modbus dissector could crash with a NULL pointer dereference.from 0, < 2.4.1-1
- HIGH7.5CVE-2017-11411In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the openSAFETY dissector could crash or exhaust system memory.from 0, < 2.4.0-1
- HIGH7.5CVE-2017-11410In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the WBXML dissector could go into an infinite loop, triggered by packet injection or a…from 0, < 2.4.0-1
- HIGH7.5CVE-2017-11409In Wireshark 2.0.0 to 2.0.13, the GPRS LLC dissector could go into a large loop.from 0, < 2.2.0~rc1+g438c022-1
- from 0, < 1.12.1+g01b65bf-4+deb8u6~deb7u8
- from 0, < 2.4.0-1
- from 0, < 1.12.1+g01b65bf-4+deb8u12
- from 0, < 2.4.0-1
- from 0, < 2.4.0-1
- from 0, < 1.12.1+g01b65bf-4+deb8u16
- HIGH7.5CVE-2017-9766In Wireshark 2.2.7, PROFINET IO data with a high recursion depth allows remote attackers to cause a denial of service (stack exhaustion) in…from 0, < 2.4.0-1
- HIGH7.5CVE-2017-9354In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the RGMP dissector could crash.from 0, < 2.2.7-1
- from 0, < 2.2.7-1
- HIGH7.5CVE-2017-9352In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the Bazaar dissector could go into an infinite loop.from 0, < 2.2.7-1
- HIGH7.5CVE-2017-9351In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DHCP dissector could read past the end of a buffer.from 0, < 2.2.7-1
- HIGH7.5CVE-2017-9350In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the openSAFETY dissector could crash or exhaust system memory.from 0, < 2.2.7-1
- HIGH7.5CVE-2017-9349In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DICOM dissector has an infinite loop.from 0, < 2.2.7-1
- HIGH7.5CVE-2017-9348In Wireshark 2.2.0 to 2.2.6, the DOF dissector could read past the end of a buffer.from 0, < 2.2.7-1
- HIGH7.5CVE-2017-9347In Wireshark 2.2.0 to 2.2.6, the ROS dissector could crash with a NULL pointer dereference.from 0, < 2.2.7-1
- HIGH7.5CVE-2017-9346In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the SoulSeek dissector could go into an infinite loop.from 0, < 2.2.7-1
- HIGH7.5CVE-2017-9345In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DNS dissector could go into an infinite loop.from 0, < 2.2.7-1
- from 0, < 1.12.1+g01b65bf-4+deb8u18
- from 0, < 2.2.7-1
- HIGH7.5CVE-2017-9343In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the MSNIP dissector misuses a NULL pointer.from 0, < 2.2.7-1
- HIGH7.5CVE-2017-7748In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the WSP dissector could go into an infinite loop, triggered by packet injection or a malfo…from 0, < 2.2.6+g32dac6a-1
- HIGH7.5CVE-2017-7747In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the PacketBB dissector could crash, triggered by packet injection or a malformed capture f…from 0, < 2.2.6+g32dac6a-1
- HIGH7.5CVE-2017-7746In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the SLSK dissector could go into an infinite loop, triggered by packet injection or a malf…from 0, < 2.2.6+g32dac6a-1
- HIGH7.5CVE-2017-7745In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the SIGCOMP dissector could go into an infinite loop, triggered by packet injection or a m…from 0, < 2.2.6+g32dac6a-1
- HIGH7.5CVE-2017-7705In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the RPC over RDMA dissector could go into an infinite loop, triggered by packet injection…from 0, < 2.2.6+g32dac6a-1
- HIGH7.5CVE-2017-7704In Wireshark 2.2.0 to 2.2.5, the DOF dissector could go into an infinite loop, triggered by packet injection or a malformed capture file.from 0, < 2.2.6+g32dac6a-1
- HIGH7.5CVE-2017-7703In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the IMAP dissector could crash, triggered by packet injection or a malformed capture file.from 0, < 2.2.6+g32dac6a-1
- HIGH7.5CVE-2017-7702In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the WBXML dissector could go into an infinite loop, triggered by packet injection or a mal…from 0, < 2.2.6+g32dac6a-1
- HIGH7.5CVE-2017-7701In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the BGP dissector could go into an infinite loop, triggered by packet injection or a malfo…from 0, < 2.2.6+g32dac6a-1
- HIGH7.5CVE-2016-7958In Wireshark 2.2.0, the NCP dissector could crash, triggered by packet injection or a malformed capture file.from 0, < 2.2.1+ga6fbd27-1
- HIGH7.5CVE-2016-7957In Wireshark 2.2.0, the Bluetooth L2CAP dissector could crash, triggered by packet injection or a malformed capture file.from 0, < 2.2.1+ga6fbd27-1
- HIGH7.5CVE-2017-6474In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a NetScaler file parser infinite loop, triggered by a malformed capture file.from 0, < 2.2.5+g440fd4d-2
- HIGH7.5CVE-2017-6473In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a K12 file parser crash, triggered by a malformed capture file.from 0, < 2.2.5+g440fd4d-2
- HIGH7.5CVE-2017-6472In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an RTMPT dissector infinite loop, triggered by packet injection or a malformed ca…from 0, < 2.2.5+g440fd4d-2
- HIGH7.5CVE-2017-6471In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a WSP infinite loop, triggered by packet injection or a malformed capture file.from 0, < 2.2.5+g440fd4d-2
- HIGH7.5CVE-2017-6470In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an IAX2 infinite loop, triggered by packet injection or a malformed capture file.from 0, < 2.2.5+g440fd4d-2
- HIGH7.5CVE-2017-6469In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an LDSS dissector crash, triggered by packet injection or a malformed capture fil…from 0, < 2.2.5+g440fd4d-2
- HIGH7.5CVE-2017-6468In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a NetScaler file parser crash, triggered by a malformed capture file.from 0, < 2.2.5+g440fd4d-2
- HIGH7.5CVE-2017-6467In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a Netscaler file parser infinite loop, triggered by a malformed capture file.from 0, < 2.2.5+g440fd4d-2
- from 0, < 1.12.1+g01b65bf-4+deb8u6~deb7u6
- from 0, < 2.2.5+g440fd4d-2
- HIGH7.5CVE-2017-5597In Wireshark 2.2.0 to 2.2.3 and 2.0.0 to 2.0.9, the DHCPv6 dissector could go into a large loop, triggered by packet injection or a malform…from 0, < 2.2.4+gcc3dc1b-1
- from 0, < 1.12.1+g01b65bf-4+deb8u6~deb7u7
- from 0, < 2.2.4+gcc3dc1b-1
- from 0, < 1.12.1+g01b65bf-4+deb8u11
- from 0, < 1.12.1+g01b65bf-4+deb8u7
- from 0, < 1.12.1+g01b65bf-4+deb8u6~deb7u2
- from 0, < 2.0.4+gdd7746e-1
- HIGH7.5CVE-2011-1142Stack consumption vulnerability in the dissect_ber_choice function in the BER dissector in Wireshark 1.2.x through 1.2.15 and 1.4.x through…from 0, < 1.4.4-1
- HIGH7.5CVE-2006-4574Off-by-one error in the MIME Multipart dissector in Wireshark (formerly Ethereal) 0.10.1 through 0.99.3 allows remote attackers to cause a…from 0, < 0.99.4-1
- from 0, < 3.4.16-0+deb11u1
- from 0, < 2.6.20-0+deb10u6
- HIGH7.1CVE-2023-0412TIPC dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture f…from 0, < 3.4.16-0+deb11u1
- MEDIUM6.5CVE-2026-0962SOME/IP-SD protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of servicefrom 0, < 4.4.13-0+deb13u1
- MEDIUM6.5CVE-2026-0961BLF file parser crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of servicefrom 0, < 4.4.13-0+deb13u1
- MEDIUM6.5CVE-2026-0959IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of servicefrom 0, < 4.4.13-0+deb13u1
- MEDIUM6.5CVE-2025-5601Column handling crashes in Wireshark 4.4.0 to 4.4.6 and 4.2.0 to 4.2.12 allows denial of service via packet injection or crafted capture fi…from 0, < 3.4.16-0+deb11u2
- MEDIUM6.5CVE-2023-6174SSH dissector crash in Wireshark 4.0.0 to 4.0.10 allows denial of service via packet injection or crafted capture filefrom 0, < 4.0.11-1~deb12u1
- MEDIUM6.5CVE-2023-5371RTPS dissector memory leak in Wireshark 4.0.0 to 4.0.8 and 3.6.0 to 3.6.16 allows denial of service via packet injection or crafted capture…from 0, < 4.0.11-1~deb12u1
- from 0, < 3.4.16-0+deb11u1
- from 0, < 4.0.11-1~deb12u1
- MEDIUM6.5CVE-2023-0668Due to failure in validating the length provided by an attacker-crafted IEEE-C37.118 packet, Wireshark version 4.0.5 and prior, by default,…from 0, < 3.4.16-0+deb11u1
- MEDIUM6.5CVE-2023-0667Due to failure in validating the length provided by an attacker-crafted MSMMS packet, Wireshark version 4.0.5 and prior, in an unusual conf…from 0, < 3.4.16-0+deb11u1
- from 0, < 3.4.16-0+deb11u1
- from 0, < 4.0.6-1~deb12u1
- MEDIUM6.5CVE-2023-2952XRA dissector infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or crafted captur…from 0, < 3.4.16-0+deb11u1
- MEDIUM6.5CVE-2023-2858NetScaler file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture filefrom 0, < 3.4.16-0+deb11u1
- MEDIUM6.5CVE-2023-2857BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture filefrom 0, < 4.0.6-1~deb12u1
- from 0, < 2.6.20-0+deb10u7
- from 0, < 3.4.16-0+deb11u1
- MEDIUM6.5CVE-2023-2855Candump log parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture filefrom 0, < 3.4.16-0+deb11u1
- MEDIUM6.5CVE-2023-2854BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture filefrom 0, < 4.0.6-1~deb12u1
- MEDIUM6.5CVE-2023-1994GQUIC dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture filefrom 0, < 3.4.16-0+deb11u1
- MEDIUM6.5CVE-2023-1993LISP dissector large loop in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture…from 0, < 3.4.16-0+deb11u1
- MEDIUM6.5CVE-2023-0417Memory leak in the NFS dissector in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or craft…from 0, < 3.4.16-0+deb11u1
- MEDIUM6.5CVE-2023-0416GNW dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture fi…from 0, < 3.4.16-0+deb11u1
- MEDIUM6.5CVE-2023-0415iSCSI dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture…from 0, < 3.4.16-0+deb11u1
- MEDIUM6.5CVE-2023-0414Crash in the EAP dissector in Wireshark 4.0.0 to 4.0.2 allows denial of service via packet injection or crafted capture filefrom 0, < 4.0.3-1
- MEDIUM6.5CVE-2023-0413Dissection engine bug in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture…from 0, < 3.4.16-0+deb11u1
- MEDIUM6.5CVE-2023-0411Excessive loops in multiple dissectors in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or…from 0, < 3.4.16-0+deb11u1
- from 0, < 2.6.20-0+deb10u5
- from 0, < 3.4.16-0+deb11u1
- MEDIUM6.5CVE-2022-0585Large loops in multiple protocol dissectors in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allow denial of service via packet injection or…from 0, < 3.4.16-0+deb11u1
- from 0, < 2.6.20-0+deb9u2
- from 0, < 3.4.10-0+deb11u1
- from 0, < 3.4.10-0+deb11u1
- from 0, < 3.2.6-1
- from 0, < 3.2.0-1
- MEDIUM6.5CVE-2018-5335In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the WCP dissector could crash.from 0, < 2.4.4-1
- from 0, < 2.4.4-1
- from 0, < 1.12.1+g01b65bf-4+deb8u6~deb7u9
- from 0, < 1.12.1+g01b65bf-4+deb8u13
- MEDIUM6.5CVE-2017-7700In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the NetScaler file parser could go into an infinite loop, triggered by a malformed capture…from 0, < 2.2.6+g32dac6a-1
- MEDIUM5.9CVE-2016-9376In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the OpenFlow dissector could crash with memory exhaustion, triggered by network traffic or…from 0, < 2.2.2+g9c5aae3-1
- MEDIUM5.9CVE-2016-9375In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the DTN dissector could go into an infinite loop, triggered by network traffic or a capture…from 0, < 2.2.2+g9c5aae3-1
- MEDIUM5.9CVE-2016-9374In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the AllJoyn dissector could crash with a buffer over-read, triggered by network traffic or…from 0, < 2.2.2+g9c5aae3-1
- from 0, < 1.12.1+g01b65bf-4+deb8u10
- from 0, < 1.12.1+g01b65bf-4+deb8u6~deb7u5
- from 0, < 2.2.2+g9c5aae3-1
- MEDIUM5.9CVE-2016-9372In Wireshark 2.2.0 to 2.2.1, the Profinet I/O dissector could loop excessively, triggered by network traffic or a capture file.from 0, < 2.2.2+g9c5aae3-1
- MEDIUM5.9CVE-2016-7180epan/dissectors/packet-ipmi-trace.c in the IPMI trace dissector in Wireshark 2.x before 2.0.6 does not properly consider whether a string i…from 0, < 2.2.0~rc1+g438c022-1
- MEDIUM5.9CVE-2016-7179Stack-based buffer overflow in epan/dissectors/packet-catapult-dct2000.c in the Catapult DCT2000 dissector in Wireshark 2.x before 2.0.6 al…from 0, < 2.2.0~rc1+g438c022-1
- MEDIUM5.9CVE-2016-7178epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 2.x before 2.0.6 does not ensure that memory is allocated for certai…from 0, < 2.2.0~rc1+g438c022-1
- MEDIUM5.9CVE-2016-7177epan/dissectors/packet-catapult-dct2000.c in the Catapult DCT2000 dissector in Wireshark 2.x before 2.0.6 does not restrict the number of c…from 0, < 2.2.0~rc1+g438c022-1
- from 0, < 1.12.1+g01b65bf-4+deb8u9
- from 0, < 1.12.1+g01b65bf-4+deb8u6~deb7u4
- from 0, < 2.2.0~rc1+g438c022-1
- MEDIUM5.9CVE-2016-7175epan/dissectors/packet-qnet6.c in the QNX6 QNET dissector in Wireshark 2.x before 2.0.6 mishandles MAC address data, which allows remote at…from 0, < 2.2.0~rc1+g438c022-1
- MEDIUM5.9CVE-2016-5359epan/dissectors/packet-wbxml.c in the WBXML dissector in Wireshark 1.12.x before 1.12.12 mishandles offsets, which allows remote attackers…from 0, < 2.0
- MEDIUM5.9CVE-2016-5358epan/dissectors/packet-pktap.c in the Ethernet dissector in Wireshark 2.x before 2.0.4 mishandles the packet-header data type, which allows…from 0, < 2.0.4+gdd7746e-1
- MEDIUM5.9CVE-2016-5357wiretap/netscreen.c in the NetScreen file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer…from 0, < 2.0.4+gdd7746e-1
- MEDIUM5.9CVE-2016-5356wiretap/cosine.c in the CoSine file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer proce…from 0, < 2.0.4+gdd7746e-1
- MEDIUM5.9CVE-2016-5355wiretap/toshiba.c in the Toshiba file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer pro…from 0, < 2.0.4+gdd7746e-1
- MEDIUM5.9CVE-2016-5354The USB subsystem in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles class types, which allows remote attackers to cause a…from 0, < 2.0.4+gdd7746e-1
- MEDIUM5.9CVE-2016-5353epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles the reserved C…from 0, < 2.0.4+gdd7746e-1
- MEDIUM5.9CVE-2016-5352epan/crypt/airpdcap.c in the IEEE 802.11 dissector in Wireshark 2.x before 2.0.4 mishandles certain length values, which allows remote atta…from 0, < 2.0.4+gdd7746e-1
- MEDIUM5.9CVE-2016-5351epan/crypt/airpdcap.c in the IEEE 802.11 dissector in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles the lack of an EAPOL_…from 0, < 2.0.4+gdd7746e-1
- MEDIUM5.9CVE-2016-6513epan/dissectors/packet-wbxml.c in the WBXML dissector in Wireshark 2.x before 2.0.5 does not restrict the recursion depth, which allows rem…from 0, < 2.0.5+ga3be9c6-1
- MEDIUM5.9CVE-2016-6512epan/dissectors/packet-wap.c in Wireshark 2.x before 2.0.5 omits an overflow check in the tvb_get_guintvar function, which allows remote at…from 0, < 2.0.5+ga3be9c6-1
- MEDIUM5.9CVE-2016-6511epan/proto.c in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause a denial of service (OpenFlow dissect…from 0, < 2.0.5+ga3be9c6-1
- MEDIUM5.9CVE-2016-6510Off-by-one error in epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote…from 0, < 2.0.5+ga3be9c6-1
- MEDIUM5.9CVE-2016-6509epan/dissectors/packet-ldss.c in the LDSS dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 mishandles conversations, which…from 0, < 2.0.5+ga3be9c6-1
- MEDIUM5.9CVE-2016-6508epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 uses an incorrect integer data ty…from 0, < 2.0.5+ga3be9c6-1
- MEDIUM5.9CVE-2016-6507epan/dissectors/packet-mmse.c in the MMSE dissector in Wireshark 1.12.x before 1.12.13 allows remote attackers to cause a denial of service…from 0, < 2.0
- MEDIUM5.9CVE-2016-6506epan/dissectors/packet-wsp.c in the WSP dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause…from 0, < 2.0.5+ga3be9c6-1
- MEDIUM5.9CVE-2016-6505epan/dissectors/packet-packetbb.c in the PacketBB dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers…from 0, < 2.0.5+ga3be9c6-1
- from 0, < 1.12.1+g01b65bf-4+deb8u8
- from 0, < 1.12.1+g01b65bf-4+deb8u6~deb7u3
- from 0, < 2.0
- MEDIUM5.9CVE-2016-4421epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.12.x before 1.12.10 and 2.x before 2.0.2 allows remote attackers to…from 0, < 2.0.2+ga16e22e-1
- MEDIUM5.9CVE-2016-4420The NFS dissector in Wireshark 2.x before 2.0.2 allows remote attackers to cause a denial of service (application crash) via a crafted pack…from 0, < 2.0.2+ga16e22e-1
- MEDIUM5.9CVE-2016-4419epan/dissectors/packet-spice.c in the SPICE dissector in Wireshark 2.x before 2.0.2 mishandles capability data, which allows remote attacke…from 0, < 2.0.2+ga16e22e-1
- MEDIUM5.9CVE-2016-4418epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.12.x before 1.12.10 and 2.x before 2.0.2 allows remote attackers to…from 0, < 2.0.2+ga16e22e-1
- MEDIUM5.9CVE-2016-4417Off-by-one error in epan/dissectors/packet-gsm_abis_oml.c in the GSM A-bis OML dissector in Wireshark 1.12.x before 1.12.10 and 2.x before…from 0, < 2.0.2+ga16e22e-1
- MEDIUM5.9CVE-2016-4416epan/dissectors/packet-ieee80211.c in the IEEE 802.11 dissector in Wireshark 2.x before 2.0.2 mishandles the Grouping subfield, which allow…from 0, < 2.0.2+ga16e22e-1
- MEDIUM5.9CVE-2016-4415wiretap/vwr.c in the Ixia IxVeriWave file parser in Wireshark 2.x before 2.0.2 incorrectly increases a certain octet count, which allows re…from 0, < 2.0.2+ga16e22e-1
- MEDIUM5.9CVE-2016-4085Stack-based buffer overflow in epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 1.12.x before 1.12.11 allows remote att…from 0, < 2.0.0~rc2+g74e5b56-1
- MEDIUM5.9CVE-2016-4084Integer signedness error in epan/dissectors/packet-mswsp.c in the MS-WSP dissector in Wireshark 2.0.x before 2.0.3 allows remote attackers…from 0, < 2.0.3+geed34f0-1
- MEDIUM5.9CVE-2016-4083epan/dissectors/packet-mswsp.c in the MS-WSP dissector in Wireshark 2.0.x before 2.0.3 does not ensure that data is available before array…from 0, < 2.0.3+geed34f0-1
- MEDIUM5.9CVE-2016-4082epan/dissectors/packet-gsm_cbch.c in the GSM CBCH dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 uses the wrong variab…from 0, < 2.0.3+geed34f0-1
- MEDIUM5.9CVE-2016-4081epan/dissectors/packet-iax2.c in the IAX2 dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 uses an incorrect integer dat…from 0, < 2.0.3+geed34f0-1
- MEDIUM5.9CVE-2016-4080epan/dissectors/packet-pktc.c in the PKTC dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 misparses timestamp fields, w…from 0, < 2.0.3+geed34f0-1
- MEDIUM5.9CVE-2016-4079epan/dissectors/packet-pktc.c in the PKTC dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 does not verify BER identifie…from 0, < 2.0.3+geed34f0-1
- MEDIUM5.9CVE-2016-4078The IEEE 802.11 dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 does not properly restrict element lists, which allows…from 0, < 2.0.3+geed34f0-1
- MEDIUM5.9CVE-2016-4077epan/reassemble.c in TShark in Wireshark 2.0.x before 2.0.3 relies on incorrect special-case handling of truncated Tvb data structures, whi…from 0, < 2.0.3+geed34f0-1
- MEDIUM5.9CVE-2016-4076epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 2.0.x before 2.0.3 does not properly initialize memory for search patt…from 0, < 2.0.3+geed34f0-1
- from 0, < 1.12.1+g01b65bf-4+deb8u6
- from 0, < 2.0.3+geed34f0-1
- MEDIUM5.9CVE-2016-2532The dissect_llrp_parameters function in epan/dissectors/packet-llrp.c in the LLRP dissector in Wireshark 1.12.x before 1.12.10 and 2.0.x be…from 0, < 2.0.2+ga16e22e-1
- MEDIUM5.9CVE-2016-2531Off-by-one error in epan/dissectors/packet-rsl.c in the RSL dissector in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 allows remo…from 0, < 2.0.2+ga16e22e-1
- MEDIUM5.9CVE-2016-2530The dissct_rsl_ipaccess_msg function in epan/dissectors/packet-rsl.c in the RSL dissector in Wireshark 1.12.x before 1.12.10 and 2.0.x befo…from 0, < 2.0.2+ga16e22e-1
- MEDIUM5.9CVE-2016-2528The dissect_nhdr_extopt function in epan/dissectors/packet-lbmc.c in the LBMC dissector in Wireshark 2.0.x before 2.0.2 does not validate l…from 0, < 2.0.2+ga16e22e-1
- MEDIUM5.9CVE-2016-2526epan/dissectors/packet-hiqnet.c in the HiQnet dissector in Wireshark 2.0.x before 2.0.2 does not validate the data type, which allows remot…from 0, < 2.0.2+ga16e22e-1
- MEDIUM5.9CVE-2016-2525epan/dissectors/packet-http2.c in the HTTP/2 dissector in Wireshark 2.0.x before 2.0.2 does not limit the amount of header data, which allo…from 0, < 2.0.2+ga16e22e-1
- MEDIUM5.9CVE-2016-2524epan/dissectors/packet-x509af.c in the X.509AF dissector in Wireshark 2.0.x before 2.0.2 mishandles the algorithm ID, which allows remote a…from 0, < 2.0.2+ga16e22e-1
- MEDIUM5.9CVE-2016-2523The dnp3_al_process_object function in epan/dissectors/packet-dnp.c in the DNP3 dissector in Wireshark 1.12.x before 1.12.10 and 2.0.x befo…from 0, < 2.0.2+ga16e22e-1
- MEDIUM5.9CVE-2016-2522The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 2.0.x before 2.0.2 d…from 0, < 2.0.2+ga16e22e-1
- MEDIUM5.5CVE-2026-9759ROHC protocol dissector crash in Wireshark 4.6.0 to 4.6.5 and 4.4.0 to 4.4.15 allows denial of servicefrom 0
- from 0, < 4.6.5-1
- MEDIUM5.5CVE-2026-5404K12 RF5 file parser crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of servicefrom 0
- MEDIUM5.5CVE-2026-6870GSM RP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of servicefrom 0
- MEDIUM5.5CVE-2026-6869WebSocket protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of servicefrom 0
- MEDIUM5.5CVE-2026-6867SMB2 protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of servicefrom 0
- MEDIUM5.5CVE-2026-6538BEEP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of servicefrom 0
- MEDIUM5.5CVE-2026-6537ZigBee protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of servicefrom 0
- from 0
- MEDIUM5.5CVE-2026-6535Dissection engine zlib decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of servicefrom 0
- MEDIUM5.5CVE-2026-6534USB HID protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of servicefrom 0
- MEDIUM5.5CVE-2026-6533Dissection engine LZ77 decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of servicefrom 0
- MEDIUM5.5CVE-2026-6532Kismet protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of servicefrom 0
- MEDIUM5.5CVE-2026-6531SANE protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of servicefrom 0
- MEDIUM5.5CVE-2026-6530DCP-ETSI protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of servicefrom 0
- MEDIUM5.5CVE-2026-6529iLBC audio codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of servicefrom 0
- MEDIUM5.5CVE-2026-6528TLS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 allows denial of servicefrom 0
- MEDIUM5.5CVE-2026-6527ASN.1 PER protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of servicefrom 0
- from 0
- MEDIUM5.5CVE-2026-6524MySQL protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of servicefrom 0
- MEDIUM5.5CVE-2026-6523GNW protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of servicefrom 0
- MEDIUM5.5CVE-2026-6522RPKI-Router protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of servicefrom 0
- MEDIUM5.5CVE-2026-6521OpenFlow v5 protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of servicefrom 0
- MEDIUM5.5CVE-2026-5409Monero protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of servicefrom 0
- MEDIUM5.5CVE-2026-5408BT-DHT protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of servicefrom 0
- MEDIUM5.5CVE-2026-5407SMB2 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of servicefrom 0
- MEDIUM5.5CVE-2026-5406FC-SWILS protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of servicefrom 0
- MEDIUM5.5CVE-2026-5401AFP Spotlight protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of servicefrom 0
- MEDIUM5.5CVE-2026-5299ICMPv6 PvD protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of servicefrom 0
- MEDIUM5.5CVE-2026-0960HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of servicefrom 0, < 3.4.16-0+deb11u2
- MEDIUM5.5CVE-2025-13946MEGACO dissector infinite loop in Wireshark 4.6.0 to 4.6.1 and 4.4.0 to 4.4.11 allows denial of servicefrom 0, < 3.4.16-0+deb11u2
- from 0, < 3.4.16-0+deb11u2
- from 0, < 4.6.1-1
- MEDIUM5.5CVE-2025-13499Kafka dissector crash in Wireshark 4.6.0 and 4.4.0 to 4.4.10 allows denial of servicefrom 0, < 3.4.16-0+deb11u2
- from 0, < 3.4.16-0+deb11u2
- from 0, < 4.4.13-0+deb13u1
- from 0, < 3.4.16-0+deb11u2
- from 0, < 3.4.16-0+deb11u2
- MEDIUM5.5CVE-2024-11595FiveCo RAP dissector infinite loop in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted…from 0, < 4.4.2-1
- MEDIUM5.5CVE-2024-9780ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capture filefrom 0, < 4.4.1-1
- MEDIUM5.5CVE-2024-8645SPRT dissector crash in Wireshark 4.2.0 to 4.0.5 and 4.0.0 to 4.0.15 allows denial of service via packet injection or crafted capture filefrom 0, < 3.4.16-0+deb11u1
- MEDIUM5.5CVE-2024-8250NTLMSSP dissector crash in Wireshark 4.2.0 to 4.0.6 and 4.0.0 to 4.0.16 allows denial of service via packet injection or crafted capture fi…from 0, < 3.4.16-0+deb11u1
- MEDIUM5.5CVE-2024-4855Use after free issue in editcap could cause denial of service via crafted capture filefrom 0
- MEDIUM5.5CVE-2024-4853Memory handling issue in editcap could cause denial of service via crafted capture filefrom 0, < 3.4.16-0+deb11u1
- MEDIUM5.5CVE-2023-3649iSCSI dissector crash in Wireshark 4.0.0 to 4.0.6 allows denial of service via packet injection or crafted capture filefrom 0, < 3.4.16-0+deb11u1
- MEDIUM5.5CVE-2023-3648Kafka dissector crash in Wireshark 4.0.0 to 4.0.6 and 3.6.0 to 3.6.14 allows denial of service via packet injection or crafted capture filefrom 0, < 3.4.16-0+deb11u1
- MEDIUM5.5CVE-2022-3190Infinite loop in the F5 Ethernet Trailer protocol dissector in Wireshark 3.6.0 to 3.6.7 and 3.4.0 to 3.4.15 allows denial of service via pa…from 0, < 3.4.16-0+deb11u1
- MEDIUM5.5CVE-2021-4183Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture filefrom 0, < 3.6.2-1
- MEDIUM5.5CVE-2019-9209In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash.from 0, < 2.6.7-1
- from 0, < 2.6.1-1
- MEDIUM5.5CVE-2019-5719In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the ISAKMP dissector could crash.from 0, < 2.6.6-1
- MEDIUM5.5CVE-2019-5718In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the RTSE dissector and other ASN.1 dissectors could crash.from 0, < 2.6.6-1
- MEDIUM5.5CVE-2019-5717In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the P_MUL dissector could crash.from 0, < 2.6.6-1
- from 0, < 1.12.1+g01b65bf-4+deb8u17
- from 0, < 2.6.6-1
- from 0, < 2.6.7-1~deb9u1
- MEDIUM5.5CVE-2018-19626In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the DCOM dissector could crash.from 0, < 2.6.5-1
- MEDIUM5.5CVE-2018-19625In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the dissection engine could crash.from 0, < 2.6.5-1
- MEDIUM5.5CVE-2018-19624In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the PVFS dissector could crash.from 0, < 2.6.5-1
- MEDIUM5.5CVE-2017-9617In Wireshark 2.2.7, deeply nested DAAP data may cause stack exhaustion (uncontrolled recursion) in the dissect_daap_one_tag function in epa…from 0, < 2.4.0-1
- MEDIUM5.5CVE-2017-9616In Wireshark 2.2.7, overly deep mp4 chunks may cause stack exhaustion (uncontrolled recursion) in the dissect_mp4_box function in epan/diss…from 0, < 2.4.0-1
- MEDIUM5.5CVE-2016-2529The iseries_check_file_type function in wiretap/iseries.c in the iSeries file parser in Wireshark 2.0.x before 2.0.2 does not consider that…from 0, < 2.0.2+ga16e22e-1
- MEDIUM5.5CVE-2016-2527wiretap/nettrace_3gpp_32_423.c in the 3GPP TS 32.423 Trace file parser in Wireshark 2.0.x before 2.0.2 does not ensure that a '\0' characte…from 0, < 2.0.2+ga16e22e-1
- MEDIUM5.5CVE-2015-8742The dissect_CPMSetBindings function in epan/dissectors/packet-mswsp.c in the MS-WSP dissector in Wireshark 2.0.x before 2.0.1 does not vali…from 0, < 2.0.1+g59ea380-1
- MEDIUM5.5CVE-2015-8741The dissect_ppi function in epan/dissectors/packet-ppi.c in the PPI dissector in Wireshark 2.0.x before 2.0.1 does not initialize a packet-…from 0, < 2.0.1+g59ea380-1
- MEDIUM5.5CVE-2015-8739The ipmi_fmt_udpport function in epan/dissectors/packet-ipmi.c in the IPMI dissector in Wireshark 2.0.x before 2.0.1 improperly attempts to…from 0, < 2.0.1+g59ea380-1
- MEDIUM5.5CVE-2015-8738The s7comm_decode_ud_cpu_szl_subfunc function in epan/dissectors/packet-s7comm_szl_ids.c in the S7COMM dissector in Wireshark 2.0.x before…from 0, < 2.0.1+g59ea380-1
- MEDIUM5.5CVE-2015-8737The mp2t_open function in wiretap/mp2t.c in the MP2T file parser in Wireshark 2.0.x before 2.0.1 does not validate the bit rate, which allo…from 0, < 2.0.1+g59ea380-1
- MEDIUM5.5CVE-2015-8736The mp2t_find_next_pcr function in wiretap/mp2t.c in the MP2T file parser in Wireshark 2.0.x before 2.0.1 does not reserve memory for a tra…from 0, < 2.0.1+g59ea380-1
- MEDIUM5.5CVE-2015-8735The get_value function in epan/dissectors/packet-btatt.c in the Bluetooth Attribute (aka BT ATT) dissector in Wireshark 2.0.x before 2.0.1…from 0, < 2.0.1+g59ea380-1
- MEDIUM5.5CVE-2015-8734The dissect_nwp function in epan/dissectors/packet-nwp.c in the NWP dissector in Wireshark 2.0.x before 2.0.1 mishandles the packet type, w…from 0, < 2.0.1+g59ea380-1
- MEDIUM5.5CVE-2015-8733The ngsniffer_process_record function in wiretap/ngsniffer.c in the Sniffer file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before…from 0, < 2.0.1+g59ea380-1
- MEDIUM5.5CVE-2015-8732The dissect_zcl_pwr_prof_pwrprofstatersp function in epan/dissectors/packet-zbee-zcl-general.c in the ZigBee ZCL dissector in Wireshark 1.1…from 0, < 2.0.1+g59ea380-1
- from 0, < 2.0.1+g59ea380-1
- from 0, < 1.8.2-5wheezy18
- MEDIUM5.5CVE-2015-8730epan/dissectors/packet-nbap.c in the NBAP dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the number o…from 0, < 2.0.1+g59ea380-1
- MEDIUM5.5CVE-2015-8729The ascend_seek function in wiretap/ascendtext.c in the Ascend file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does no…from 0, < 2.0.1+g59ea380-1
- MEDIUM5.5CVE-2015-8728The Mobile Identity parser in (1) epan/dissectors/packet-ansi_a.c in the ANSI A dissector and (2) epan/dissectors/packet-gsm_a_common.c in…from 0, < 2.0.1+g59ea380-1
- MEDIUM5.5CVE-2015-8727The dissect_rsvp_common function in epan/dissectors/packet-rsvp.c in the RSVP dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before…from 0, < 2.0.1+g59ea380-1
- MEDIUM5.5CVE-2015-8726wiretap/vwr.c in the VeriWave file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate certain signature and…from 0, < 2.0.1+g59ea380-1
- MEDIUM5.5CVE-2015-8725The dissect_diameter_base_framed_ipv6_prefix function in epan/dissectors/packet-diameter.c in the DIAMETER dissector in Wireshark 1.12.x be…from 0, < 2.0.1+g59ea380-1
- MEDIUM5.5CVE-2015-8724The AirPDcapDecryptWPABroadcastKey function in epan/crypt/airpdcap.c in the 802.11 dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x be…from 0, < 2.0.1+g59ea380-1
- MEDIUM5.5CVE-2015-8723The AirPDcapPacketProcess function in epan/crypt/airpdcap.c in the 802.11 dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.…from 0, < 2.0.1+g59ea380-1
- MEDIUM5.5CVE-2015-8722epan/dissectors/packet-sctp.c in the SCTP dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the frame po…from 0, < 2.0.1+g59ea380-1
- MEDIUM5.5CVE-2015-8721Buffer overflow in the tvb_uncompress function in epan/tvbuff_zlib.c in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 allows remote…from 0, < 2.0.1+g59ea380-1
- MEDIUM5.5CVE-2015-8720The dissect_ber_GeneralizedTime function in epan/dissectors/packet-ber.c in the BER dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x b…from 0, < 2.0.1+g59ea380-1
- MEDIUM5.5CVE-2015-8719The dissect_dns_answer function in epan/dissectors/packet-dns.c in the DNS dissector in Wireshark 1.12.x before 1.12.9 mishandles the EDNS0…from 0, < 2.0.1+g59ea380-1
- MEDIUM5.5CVE-2015-8718Double free vulnerability in epan/dissectors/packet-nlm.c in the NLM dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1, wh…from 0, < 2.0.1+g59ea380-1
- MEDIUM5.5CVE-2015-8717The dissect_sdp function in epan/dissectors/packet-sdp.c in the SDP dissector in Wireshark 1.12.x before 1.12.9 does not prevent use of a n…from 0, < 2.0.1+g59ea380-1
- MEDIUM5.5CVE-2015-8716The init_t38_info_conv function in epan/dissectors/packet-t38.c in the T.38 dissector in Wireshark 1.12.x before 1.12.9 does not ensure tha…from 0, < 2.0.1+g59ea380-1
- MEDIUM5.5CVE-2015-8715epan/dissectors/packet-alljoyn.c in the AllJoyn dissector in Wireshark 1.12.x before 1.12.9 does not check for empty arguments, which allow…from 0, < 2.0.1+g59ea380-1
- MEDIUM5.5CVE-2015-8714The dissect_dcom_OBJREF function in epan/dissectors/packet-dcom.c in the DCOM dissector in Wireshark 1.12.x before 1.12.9 does not initiali…from 0, < 2.0.1+g59ea380-1
- MEDIUM5.5CVE-2015-8713epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 1.12.x before 1.12.9 does not properly reserve memory for channel ID…from 0, < 2.0.1+g59ea380-1
- MEDIUM5.5CVE-2015-8712The dissect_hsdsch_channel_info function in epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 1.12.x before 1.12.9 doe…from 0, < 2.0.1+g59ea380-1
- MEDIUM5.5CVE-2015-8711epan/dissectors/packet-nbap.c in the NBAP dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate conversation…from 0, < 2.0.1+g59ea380-1
- MEDIUM5.5CVE-2015-3182epan/dissectors/packet-dec-dnart.c in the DECnet NSP/RT dissector in Wireshark 1.10.12 through 1.10.14 mishandles a certain strdup return v…from 0, < 1.12.0~rc1-1
- MEDIUM5.3CVE-2020-26421Crash in USB HID protocol dissector and possibly other dissectors in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet…from 0, < 3.4.1-1
- MEDIUM5.3CVE-2020-26420Memory leak in RTPS protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted captu…from 0, < 3.4.1-1
- MEDIUM5.3CVE-2020-26419Memory leak in the dissection engine in Wireshark 3.4.0 allows denial of service via packet injection or crafted capture file.from 0, < 3.4.1-1
- MEDIUM5.3CVE-2020-26418Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capt…from 0, < 3.4.1-1
- MEDIUM5.3CVE-2015-8740The dissect_tds7_colmetadata_token function in epan/dissectors/packet-tds.c in the TDS dissector in Wireshark 2.0.x before 2.0.1 does not v…from 0, < 2.0.1+g59ea380-1
- MEDIUM4.3CVE-2022-4344Memory exhaustion in the Kafka protocol dissector in Wireshark 4.0.0 to 4.0.1 and 3.6.0 to 3.6.9 allows denial of service via packet inject…from 0, < 3.4.16-0+deb11u1
- from 0, < 1.8.2-5wheezy17
- from 0, < 1.12.8+g5b6e543-1
- —CVE-2015-6249The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.12.x before 1.12.7 do…from 0, < 1.12.7+g7fc8978-1
- —CVE-2015-6248The ptvcursor_add function in the ptvcursor implementation in epan/proto.c in Wireshark 1.12.x before 1.12.7 does not check whether the exp…from 0, < 1.12.7+g7fc8978-1
- —CVE-2015-6247The dissect_openflow_tablemod_v5 function in epan/dissectors/packet-openflow_v5.c in the OpenFlow dissector in Wireshark 1.12.x before 1.12…from 0, < 1.12.7+g7fc8978-1
- —CVE-2015-6246The dissect_wa_payload function in epan/dissectors/packet-waveagent.c in the WaveAgent dissector in Wireshark 1.12.x before 1.12.7 mishandl…from 0, < 1.12.7+g7fc8978-1
- —CVE-2015-6245epan/dissectors/packet-gsm_rlcmac.c in the GSM RLC/MAC dissector in Wireshark 1.12.x before 1.12.7 uses incorrect integer data types, which…from 0, < 1.12.7+g7fc8978-1
- —CVE-2015-6244The dissect_zbee_secure function in epan/dissectors/packet-zbee-security.c in the ZigBee dissector in Wireshark 1.12.x before 1.12.7 improp…from 0, < 1.12.7+g7fc8978-1
- —CVE-2015-6243The dissector-table implementation in epan/packet.c in Wireshark 1.12.x before 1.12.7 mishandles table searches for empty strings, which al…from 0, < 1.12.7+g7fc8978-1
- —CVE-2015-6242The wmem_block_split_free_chunk function in epan/wmem/wmem_allocator_block.c in the wmem block allocator in the memory manager in Wireshark…from 0, < 1.12.7+g7fc8978-1
- from 0, < 1.12.7+g7fc8978-1
- from 0, < 1.12.1+g01b65bf-4+deb8u3
- —CVE-2015-4652epan/dissectors/packet-gsm_a_dtap.c in the GSM DTAP dissector in Wireshark 1.12.x before 1.12.6 does not properly validate digit characters…from 0, < 1.12.6+gee1fce6-1
- from 0, < 1.12.1+g01b65bf-4+deb8u2
- from 0, < 1.12.6+gee1fce6-1
- —CVE-2015-3906The logcat_dump_text function in wiretap/logcat.c in the Android Logcat file parser in Wireshark 1.12.x before 1.12.5 does not properly han…from 0, < 1.12.5+g5819e5b-1
- —CVE-2015-3815The detect_version function in wiretap/logcat.c in the Android Logcat file parser in Wireshark 1.12.x before 1.12.5 does not check the leng…from 0, < 1.12.5+g5819e5b-1
- —CVE-2015-3814The (1) dissect_tfs_request and (2) dissect_tfs_response functions in epan/dissectors/packet-ieee80211.c in the IEEE 802.11 dissector in Wi…from 0, < 1.12.5+g5819e5b-1
- —CVE-2015-3813The fragment_add_work function in epan/reassemble.c in the packet-reassembly feature in Wireshark 1.12.x before 1.12.5 does not properly de…from 0, < 1.12.5+g5819e5b-1
- —CVE-2015-3812Multiple memory leaks in the x11_init_protocol function in epan/dissectors/packet-x11.c in the X11 dissector in Wireshark 1.10.x before 1.1…from 0, < 1.12.5+g5819e5b-1
- from 0, < 1.12.5+g5819e5b-1
- from 0, < 1.8.2-5wheezy16~deb6u1
- —CVE-2015-3810epan/dissectors/packet-websocket.c in the WebSocket dissector in Wireshark 1.12.x before 1.12.5 uses a recursive algorithm, which allows re…from 0, < 1.12.5+g5819e5b-1
- —CVE-2015-3809The dissect_lbmr_pser function in epan/dissectors/packet-lbmr.c in the LBMR dissector in Wireshark 1.12.x before 1.12.5 does not properly t…from 0, < 1.12.5+g5819e5b-1
- from 0, < 1.12.1+g01b65bf-4+deb8u1
- from 0, < 1.12.5+g5819e5b-1
- —CVE-2015-2192Integer overflow in the dissect_osd2_cdb_continuation function in epan/dissectors/packet-scsi-osd.c in the SCSI OSD dissector in Wireshark…from 0, < 1.12.1+g01b65bf-4
- —CVE-2015-2191Integer overflow in the dissect_tnef function in epan/dissectors/packet-tnef.c in the TNEF dissector in Wireshark 1.10.x before 1.10.13 and…from 0, < 1.12.1+g01b65bf-4
- —CVE-2015-2190epan/proto.c in Wireshark 1.12.x before 1.12.4 does not properly handle integer data types greater than 32 bits in size, which allows remot…from 0, < 1.12.1+g01b65bf-4
- —CVE-2015-2189Off-by-one error in the pcapng_read function in wiretap/pcapng.c in the pcapng file parser in Wireshark 1.10.x before 1.10.13 and 1.12.x be…from 0, < 1.12.1+g01b65bf-4
- from 0, < 1.8.2-5wheezy15
- from 0, < 1.12.1+g01b65bf-4
- —CVE-2015-2187The dissect_atn_cpdlc_heur function in asn1/atn-cpdlc/packet-atn-cpdlc-template.c in the ATN-CPDLC dissector in Wireshark 1.12.x before 1.1…from 0, < 1.12.1+g01b65bf-4
- —CVE-2015-0564Buffer underflow in the ssl_decrypt_record function in epan/dissectors/packet-ssl-utils.c in Wireshark 1.10.x before 1.10.12 and 1.12.x bef…from 0, < 1.12.1+g01b65bf-3
- —CVE-2015-0563epan/dissectors/packet-smtp.c in the SMTP dissector in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 uses an incorrect length va…from 0, < 1.12.1+g01b65bf-3
- from 0, < 1.8.2-5wheezy14
- from 0, < 1.12.1+g01b65bf-3
- —CVE-2015-0561asn1/lpp/lpp.cnf in the LPP dissector in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 does not validate a certain index value,…from 0, < 1.12.1+g01b65bf-3
- —CVE-2015-0560The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.10.x before 1.10.12 a…from 0, < 1.12.1+g01b65bf-3
- —CVE-2015-0559Multiple use-after-free vulnerabilities in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.10.x before 1.10.12 and 1.12.…from 0, < 1.12.1+g01b65bf-3
- —CVE-2014-8714The dissect_write_structured_field function in epan/dissectors/packet-tn5250.c in the TN5250 dissector in Wireshark 1.10.x before 1.10.11 a…from 0, < 1.12.1+g01b65bf-2
- —CVE-2014-8713Stack-based buffer overflow in the build_expert_data function in epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 1.10.…from 0, < 1.12.1+g01b65bf-2
- —CVE-2014-8712The build_expert_data function in epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 1.10.x before 1.10.11 and 1.12.x bef…from 0, < 1.12.1+g01b65bf-2
- —CVE-2014-8711Multiple integer overflows in epan/dissectors/packet-amqp.c in the AMQP dissector in Wireshark 1.10.x before 1.10.11 and 1.12.x before 1.12…from 0, < 1.12.1+g01b65bf-2
- from 0, < 1.8.2-5wheezy13
- from 0, < 1.12.1+g01b65bf-2
- —CVE-2014-6432The SnifferDecompress function in wiretap/ngsniffer.c in the DOS Sniffer file parser in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1…from 0, < 1.12.1+g01b65bf-1
- —CVE-2014-6431Buffer overflow in the SnifferDecompress function in wiretap/ngsniffer.c in the DOS Sniffer file parser in Wireshark 1.10.x before 1.10.10…from 0, < 1.12.1+g01b65bf-1
- —CVE-2014-6430The SnifferDecompress function in wiretap/ngsniffer.c in the DOS Sniffer file parser in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1…from 0, < 1.12.1+g01b65bf-1
- —CVE-2014-6429The SnifferDecompress function in wiretap/ngsniffer.c in the DOS Sniffer file parser in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1…from 0, < 1.12.1+g01b65bf-1
- —CVE-2014-6428The dissect_spdu function in epan/dissectors/packet-ses.c in the SES dissector in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1…from 0, < 1.12.1+g01b65bf-1
- —CVE-2014-6427Off-by-one error in the is_rtsp_request_or_reply function in epan/dissectors/packet-rtsp.c in the RTSP dissector in Wireshark 1.10.x before…from 0, < 1.12.1+g01b65bf-1
- —CVE-2014-6426The dissect_hip_tlv function in epan/dissectors/packet-hip.c in the HIP dissector in Wireshark 1.12.x before 1.12.1 does not properly handl…from 0, < 1.12.1+g01b65bf-1
- —CVE-2014-6425The (1) get_quoted_string and (2) get_unquoted_string functions in epan/dissectors/packet-cups.c in the CUPS dissector in Wireshark 1.12.x…from 0, < 1.12.1+g01b65bf-1
- —CVE-2014-6424The dissect_v9_v10_pdu_data function in epan/dissectors/packet-netflow.c in the Netflow dissector in Wireshark 1.10.x before 1.10.10 and 1.…from 0, < 1.12.1+g01b65bf-1
- —CVE-2014-6423The tvb_raw_text_add function in epan/dissectors/packet-megaco.c in the MEGACO dissector in Wireshark 1.10.x before 1.10.10 and 1.12.x befo…from 0, < 1.12.1+g01b65bf-1
- from 0, < 1.12.0+git+4fab41a1-1
- from 0, < 1.8.2-5wheezy15~deb6u1
- from 0, < 1.8.2-5wheezy12
- —CVE-2014-6421Use-after-free vulnerability in the SDP dissector in Wireshark 1.10.x before 1.10.10 allows remote attackers to cause a denial of service (…from 0, < 1.12.0~rc1-1
- —CVE-2014-5165The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.10.x before 1.10.9…from 0, < 1.12.0+git+4fab41a1-1
- —CVE-2014-5164The rlc_decode_li function in epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.10.x before 1.10.9 initializes a certain str…from 0, < 1.12.0+git+4fab41a1-1
- —CVE-2014-5163The APN decode functionality in (1) epan/dissectors/packet-gtp.c and (2) epan/dissectors/packet-gsm_a_gm.c in the GTP and GSM Management di…from 0, < 1.12.0+git+4fab41a1-1
- —CVE-2014-5162The read_new_line function in wiretap/catapult_dct2000.c in the Catapult DCT2000 dissector in Wireshark 1.10.x before 1.10.9 does not prope…from 0, < 1.12.0+git+4fab41a1-1
- from 0, < 1.2.11-6+squeeze15
- from 0, < 1.12.0+git+4fab41a1-1
- from 0, < 1.8.2-5wheezy11
- —CVE-2014-4174wiretap/libpcap.c in the libpcap file parser in Wireshark 1.10.x before 1.10.4 allows remote attackers to execute arbitrary code or cause a…from 0, < 1.10.4-1
- —CVE-2014-4020The dissect_frame function in epan/dissectors/packet-frame.c in the frame metadissector in Wireshark 1.10.x before 1.10.8 interprets a nega…from 0, < 1.10.8-1
- —CVE-2014-2907The srtp_add_address function in epan/dissectors/packet-rtp.c in the RTP dissector in Wireshark 1.10.x before 1.10.7 does not properly upda…from 0, < 1.10.7-1
- —CVE-2014-2299Buffer overflow in the mpeg_read function in wiretap/mpeg.c in the MPEG parser in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 al…from 0, < 1.10.6-1
- —CVE-2014-2283epan/dissectors/packet-rlc in the RLC dissector in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 uses inconsistent memory-manageme…from 0, < 1.10.6-1
- —CVE-2014-2282The dissect_protocol_data_parameter function in epan/dissectors/packet-m3ua.c in the M3UA dissector in Wireshark 1.10.x before 1.10.6 does…from 0, < 1.10.6-1
- from 0, < 1.10.6-1
- from 0, < 1.2.11-6+squeeze14
- —CVE-2013-7114Multiple buffer overflows in the create_ntlmssp_v2_key function in epan/dissectors/packet-ntlmssp.c in the NTLMSSP v2 dissector in Wireshar…from 0, < 1.10.4-1
- from 0, < 1.10.4-1
- from 0, < 1.8.2-5wheezy9
- —CVE-2013-7112The dissect_sip_common function in epan/dissectors/packet-sip.c in the SIP dissector in Wireshark 1.8.x before 1.8.12 and 1.10.x before 1.1…from 0, < 1.10.4-1
- —CVE-2013-6340epan/dissectors/packet-tcp.c in the TCP dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 does not properly determine the…from 0, < 1.10.3-1
- —CVE-2013-6339The dissect_openwire_type function in epan/dissectors/packet-openwire.c in the OpenWire dissector in Wireshark 1.8.x before 1.8.11 and 1.10…from 0, < 1.10.3-1
- —CVE-2013-6338The dissect_sip_common function in epan/dissectors/packet-sip.c in the SIP dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.1…from 0, < 1.10.3-1
- —CVE-2013-6337Unspecified vulnerability in the NBAP dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 allows remote attackers to cause…from 0, < 1.10.3-1
- from 0, < 1.2.11-6+squeeze13
- from 0, < 1.10.3-1
- —CVE-2013-5722Unspecified vulnerability in the LDAP dissector in Wireshark 1.8.x before 1.8.10 and 1.10.x before 1.10.2 allows remote attackers to cause…from 0, < 1.10.2-1
- —CVE-2013-5721The dissect_mq_rr function in epan/dissectors/packet-mq.c in the MQ dissector in Wireshark 1.8.x before 1.8.10 and 1.10.x before 1.10.2 doe…from 0, < 1.10.2-1
- —CVE-2013-5719epan/dissectors/packet-assa_r3.c in the ASSA R3 dissector in Wireshark 1.8.x before 1.8.10 and 1.10.x before 1.10.2 allows remote attackers…from 0, < 1.10.2-1
- —CVE-2013-5720Buffer overflow in the RTPS dissector in Wireshark 1.8.x before 1.8.10 and 1.10.x before 1.10.2 allows remote attackers to cause a denial o…from 0, < 1.10.2-1
- from 0, < 1.2.11-6+squeeze12
- from 0, < 1.10.2-1
- —CVE-2013-5717The Bluetooth HCI ACL dissector in Wireshark 1.10.x before 1.10.2 does not properly maintain a certain free list, which allows remote attac…from 0, < 1.10.2-1
- —CVE-2013-4936The IsDFP_Frame function in plugins/profinet/packet-pn-rt.c in the PROFINET Real-Time dissector in Wireshark 1.10.x before 1.10.1 does not…from 0, < 1.10.1-1
- —CVE-2013-4935The dissect_per_length_determinant function in epan/dissectors/packet-per.c in the ASN.1 PER dissector in Wireshark 1.8.x before 1.8.9 and…from 0, < 1.10.1-1
- —CVE-2013-4934The netmon_open function in wiretap/netmon.c in the Netmon file parser in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 does not in…from 0, < 1.10.1-1
- —CVE-2013-4933The netmon_open function in wiretap/netmon.c in the Netmon file parser in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 does not pr…from 0, < 1.10.1-1
- —CVE-2013-4932Multiple array index errors in epan/dissectors/packet-gsm_a_common.c in the GSM A Common dissector in Wireshark 1.8.x before 1.8.9 and 1.10…from 0, < 1.10.1-1
- —CVE-2013-4931epan/proto.c in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 allows remote attackers to cause a denial of service (loop) via a cra…from 0, < 1.10.1-1
- from 0, < 1.2.11-6+squeeze11
- from 0, < 1.10.1-1
- —CVE-2013-4929The parseFields function in epan/dissectors/packet-dis-pdus.c in the DIS dissector in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1…from 0, < 1.10.1-1
- —CVE-2013-4928Integer signedness error in the dissect_headers function in epan/dissectors/packet-btobex.c in the Bluetooth OBEX dissector in Wireshark 1.…from 0, < 1.10.1-1
- —CVE-2013-4927Integer signedness error in the get_type_length function in epan/dissectors/packet-btsdp.c in the Bluetooth SDP dissector in Wireshark 1.8.…from 0, < 1.10.1-1
- —CVE-2013-4926epan/dissectors/packet-dcom-sysact.c in the DCOM ISystemActivator dissector in Wireshark 1.10.x before 1.10.1 does not properly determine w…from 0, < 1.10.1-1
- —CVE-2013-4925Integer signedness error in epan/dissectors/packet-dcom-sysact.c in the DCOM ISystemActivator dissector in Wireshark 1.10.x before 1.10.1 a…from 0, < 1.10.1-1
- —CVE-2013-4924epan/dissectors/packet-dcom-sysact.c in the DCOM ISystemActivator dissector in Wireshark 1.10.x before 1.10.1 does not properly validate ce…from 0, < 1.10.1-1
- —CVE-2013-4923Memory leak in the dissect_dcom_ActivationProperties function in epan/dissectors/packet-dcom-sysact.c in the DCOM ISystemActivator dissecto…from 0, < 1.10.1-1
- —CVE-2013-4922Double free vulnerability in the dissect_dcom_ActivationProperties function in epan/dissectors/packet-dcom-sysact.c in the DCOM ISystemActi…from 0, < 1.10.1-1
- —CVE-2013-4921Off-by-one error in the dissect_radiotap function in epan/dissectors/packet-ieee80211-radiotap.c in the Radiotap dissector in Wireshark 1.1…from 0, < 1.10.1-1
- —CVE-2013-4920The P1 dissector in Wireshark 1.10.x before 1.10.1 does not properly initialize a global variable, which allows remote attackers to cause a…from 0, < 1.10.1-1
- —CVE-2013-4083The dissect_pft function in epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark 1.6.x before 1.6.16, 1.8.x before 1.8.…from 0, < 1.10.0-1
- —CVE-2013-4082The vwr_read function in wiretap/vwr.c in the Ixia IxVeriWave file parser in Wireshark 1.8.x before 1.8.8 does not validate the relationshi…from 0, < 1.10.0-1
- —CVE-2013-4081The http_payload_subdissector function in epan/dissectors/packet-http.c in the HTTP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x be…from 0, < 1.10.0-1
- —CVE-2013-4080The dissect_r3_upstreamcommand_queryconfig function in epan/dissectors/packet-assa_r3.c in the Assa Abloy R3 dissector in Wireshark 1.8.x b…from 0, < 1.10.0-1
- —CVE-2013-4079The dissect_schedule_message function in epan/dissectors/packet-gsm_cbch.c in the GSM CBCH dissector in Wireshark 1.8.x before 1.8.8 allows…from 0, < 1.10.0-1
- —CVE-2013-4078epan/dissectors/packet-rdp.c in the RDP dissector in Wireshark 1.8.x before 1.8.8 does not validate return values during checks for data av…from 0, < 1.10.0-1
- —CVE-2013-4077Array index error in the NBAP dissector in Wireshark 1.8.x before 1.8.8 allows remote attackers to cause a denial of service (application c…from 0, < 1.10.0-1
- —CVE-2013-4076Buffer overflow in the dissect_iphc_crtp_fh function in epan/dissectors/packet-ppp.c in the PPP dissector in Wireshark 1.8.x before 1.8.8 a…from 0, < 1.10.0-1
- —CVE-2013-4075epan/dissectors/packet-gmr1_bcch.c in the GMR-1 BCCH dissector in Wireshark 1.8.x before 1.8.8 does not properly initialize memory, which a…from 0, < 1.10.0-1
- from 0, < 1.8.2-5wheezy4
- from 0, < 1.10.0-1
- —CVE-2013-3562Multiple integer signedness errors in the tvb_unmasked function in epan/dissectors/packet-websocket.c in the Websocket dissector in Wiresha…from 0, < 1.8.7-1
- —CVE-2013-3560The dissect_dsmcc_un_download function in epan/dissectors/packet-mpeg-dsmcc.c in the MPEG DSM-CC dissector in Wireshark 1.8.x before 1.8.7…from 0, < 1.8.7-1
- —CVE-2013-3559epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark 1.8.x before 1.8.7 uses incorrect integer data types, which allows…from 0, < 1.8.7-1
- —CVE-2013-3558The dissect_ccp_bsdcomp_opt function in epan/dissectors/packet-ppp.c in the PPP CCP dissector in Wireshark 1.8.x before 1.8.7 does not term…from 0, < 1.8.7-1
- —CVE-2013-3557The dissect_ber_choice function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.6.x before 1.6.15 and 1.8.x befor…from 0, < 1.8.7-1
- from 0, < 1.8.2-5wheezy3
- from 0, < 1.8.7-1
- —CVE-2013-2488The DTLS dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 does not validate the fragment offset before invoking the reasse…from 0, < 1.8.2-5
- —CVE-2013-2487epan/dissectors/packet-reload.c in the REsource LOcation And Discovery (aka RELOAD) dissector in Wireshark 1.8.x before 1.8.6 uses incorrec…from 0, < 1.8.6-1
- —CVE-2013-2486The dissect_diagnosticrequest function in epan/dissectors/packet-reload.c in the REsource LOcation And Discovery (aka RELOAD) dissector in…from 0, < 1.8.6-1
- —CVE-2013-2485The FCSP dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (infinite l…from 0, < 1.8.6-1
- —CVE-2013-2484The CIMD dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (applicatio…from 0, < 1.8.2-5
- —CVE-2013-2483The acn_add_dmp_data function in epan/dissectors/packet-acn.c in the ACN dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6…from 0, < 1.8.2-5
- —CVE-2013-2482The AMPQ dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (infinite l…from 0, < 1.8.6-1
- —CVE-2013-2481Integer signedness error in the dissect_mount_dirpath_call function in epan/dissectors/packet-mount.c in the Mount dissector in Wireshark 1…from 0, < 1.8.2-5
- —CVE-2013-2480The RTPS and RTPS2 dissectors in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allow remote attackers to cause a denial of service (…from 0, < 1.8.2-5
- —CVE-2013-2479The dissect_mpls_echo_tlv_dd_map function in epan/dissectors/packet-mpls-echo.c in the MPLS Echo dissector in Wireshark 1.8.x before 1.8.6…from 0, < 1.8.6-1
- from 0, < 1.2.11-6+squeeze10
- from 0, < 1.8.2-5
- —CVE-2013-2477The CSN.1 dissector in Wireshark 1.8.x before 1.8.6 does not properly manage function pointers, which allows remote attackers to cause a de…from 0, < 1.8.2-5
- —CVE-2013-2476The dissect_hartip function in epan/dissectors/packet-hartip.c in the HART/IP dissector in Wireshark 1.8.x before 1.8.6 allows remote attac…from 0, < 1.8.6-1
- —CVE-2013-2475The TCP dissector in Wireshark 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (application crash) via a malformed…from 0, < 1.8.2-5
- —CVE-2013-1590Buffer overflow in the NTLMSSP dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 allows remote attackers to cause a denial…from 0, < 1.8.6-1
- —CVE-2013-1589Double free vulnerability in epan/proto.c in the dissection engine in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 allows remote at…from 0, < 1.8.6-1
- —CVE-2013-1588Multiple buffer overflows in the dissect_pft_fec_detailed function in the DCP-ETSI dissector in epan/dissectors/packet-dcp-etsi.c in Wiresh…from 0, < 1.8.6-1
- —CVE-2013-1587The dissect_rohc_ir_packet function in epan/dissectors/packet-rohc.c in the ROHC dissector in Wireshark 1.8.x before 1.8.5 does not properl…from 0, < 1.8.6-1
- —CVE-2013-1586The fragment_set_tot_len function in epan/reassemble.c in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly determine…from 0, < 1.8.6-1
- —CVE-2013-1585epan/tvbuff.c in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly validate certain length values for the MS-MMC disse…from 0, < 1.8.6-1
- —CVE-2013-1584The dissect_version_5_and_6_primary_header function in epan/dissectors/packet-dtn.c in the DTN dissector in Wireshark 1.6.x before 1.6.13 a…from 0, < 1.8.6-1
- —CVE-2013-1583The dissect_version_4_primary_header function in epan/dissectors/packet-dtn.c in the DTN dissector in Wireshark 1.6.x before 1.6.13 and 1.8…from 0, < 1.8.6-1
- from 0, < 1.8.6-1
- from 0, < 1.2.11-6+squeeze9
- —CVE-2013-1581The dissect_pft_fec_detailed function in epan/dissectors/packet-dcp-etsi.c in the DCP-ETSI dissector in Wireshark 1.6.x before 1.6.13 and 1…from 0, < 1.8.6-1
- —CVE-2013-1580The dissect_cmstatus_tlv function in plugins/docsis/packet-cmstatus.c in the DOCSIS CM-STATUS dissector in Wireshark 1.6.x before 1.6.13 an…from 0, < 1.8.6-1
- —CVE-2013-1579The rtps_util_add_bitmap function in epan/dissectors/packet-rtps.c in the RTPS dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before…from 0, < 1.8.6-1
- —CVE-2013-1578The dissect_pw_eth_heuristic function in epan/dissectors/packet-pw-eth.c in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not p…from 0, < 1.8.6-1
- —CVE-2013-1577The dissect_sip_p_charging_func_addresses function in epan/dissectors/packet-sip.c in the SIP dissector in Wireshark 1.6.x before 1.6.13 an…from 0, < 1.8.6-1
- —CVE-2013-1576The dissect_sdp_media_attribute function in epan/dissectors/packet-sdp.c in the SDP dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x be…from 0, < 1.8.6-1
- —CVE-2013-1575The dissect_r3_cmd_alarmconfigure function in epan/dissectors/packet-assa_r3.c in the R3 dissector in Wireshark 1.6.x before 1.6.13 and 1.8…from 0, < 1.8.6-1
- —CVE-2013-1574The dissect_bthci_eir_ad_data function in epan/dissectors/packet-bthci_cmd.c in the Bluetooth HCI dissector in Wireshark 1.6.x before 1.6.1…from 0, < 1.8.6-1
- —CVE-2013-1573The csnStreamDissector function in epan/dissectors/packet-csn1.c in the CSN.1 dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1…from 0, < 1.8.6-1
- —CVE-2013-1572The dissect_oampdu_event_notification function in epan/dissectors/packet-slowprotocols.c in the IEEE 802.3 Slow Protocols dissector in Wire…from 0, < 1.8.6-1
- —CVE-2012-6062The dissect_rtcp_app function in epan/dissectors/packet-rtcp.c in the RTCP dissector in Wireshark 1.6.x before 1.6.12 and 1.8.x before 1.8.…from 0, < 1.8.6-1
- —CVE-2012-6061The dissect_wtp_common function in epan/dissectors/packet-wtp.c in the WTP dissector in Wireshark 1.6.x before 1.6.12 and 1.8.x before 1.8.…from 0, < 1.8.6-1
- —CVE-2012-6060Integer overflow in the dissect_iscsi_pdu function in epan/dissectors/packet-iscsi.c in the iSCSI dissector in Wireshark 1.6.x before 1.6.1…from 0, < 1.8.6-1
- —CVE-2012-6059The dissect_isakmp function in epan/dissectors/packet-isakmp.c in the ISAKMP dissector in Wireshark 1.6.x before 1.6.12 and 1.8.x before 1.…from 0, < 1.8.6-1
- —CVE-2012-6058Integer overflow in the dissect_icmpv6 function in epan/dissectors/packet-icmpv6.c in the ICMPv6 dissector in Wireshark 1.6.x before 1.6.12…from 0, < 1.8.6-1
- —CVE-2012-6057The dissect_eigrp_metric_comm function in epan/dissectors/packet-eigrp.c in the EIGRP dissector in Wireshark 1.8.x before 1.8.4 uses the wr…from 0, < 1.8.6-1
- —CVE-2012-6056Integer overflow in the dissect_sack_chunk function in epan/dissectors/packet-sctp.c in the SCTP dissector in Wireshark 1.8.x before 1.8.4…from 0, < 1.8.6-1
- —CVE-2012-6055epan/dissectors/packet-3g-a11.c in the 3GPP2 A11 dissector in Wireshark 1.8.x before 1.8.4 allows remote attackers to cause a denial of ser…from 0, < 1.8.6-1
- —CVE-2012-6054The dissect_sflow_245_address_type function in epan/dissectors/packet-sflow.c in the sFlow dissector in Wireshark 1.8.x before 1.8.4 does n…from 0, < 1.8.6-1
- —CVE-2012-6053epan/dissectors/packet-usb.c in the USB dissector in Wireshark 1.6.x before 1.6.12 and 1.8.x before 1.8.4 relies on a length field to calcu…from 0, < 1.8.6-1
- from 0, < 1.12.1+g01b65bf-4+deb8u6~deb7u1
- from 0, < 1.8.6-1
- —CVE-2012-5240Buffer overflow in the dissect_tlv function in epan/dissectors/packet-ldp.c in the LDP dissector in Wireshark 1.8.x before 1.8.3 allows rem…from 0, < 1.8.2-2
- —CVE-2012-5238epan/dissectors/packet-ppp.c in the PPP dissector in Wireshark 1.8.x before 1.8.3 uses incorrect OUI data structures during the decoding of…from 0, < 1.8.2-2
- —CVE-2012-5237The dissect_hsrp function in epan/dissectors/packet-hsrp.c in the HSRP dissector in Wireshark 1.8.x before 1.8.3 allows remote attackers to…from 0, < 1.8.2-2
- —CVE-2012-3548The dissect_drda function in epan/dissectors/packet-drda.c in Wireshark 1.6.x through 1.6.10 and 1.8.x through 1.8.2 allows remote attacker…from 0, < 1.8.2-2
- —CVE-2012-4298Integer signedness error in the vwr_read_rec_data_ethernet function in wiretap/vwr.c in the Ixia IxVeriWave file parser in Wireshark 1.8.x…from 0, < 1.8.2-1
- —CVE-2012-4297Buffer overflow in the dissect_gsm_rlcmac_downlink function in epan/dissectors/packet-gsm_rlcmac.c in the GSM RLC MAC dissector in Wireshar…from 0, < 1.8.2-1
- —CVE-2012-4296Buffer overflow in epan/dissectors/packet-rtps2.c in the RTPS2 dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x b…from 0, < 1.8.2-1
- —CVE-2012-4295Array index error in the channelised_fill_sdh_g707_format function in epan/dissectors/packet-erf.c in the ERF dissector in Wireshark 1.8.x…from 0, < 1.8.2-1
- —CVE-2012-4294Buffer overflow in the channelised_fill_sdh_g707_format function in epan/dissectors/packet-erf.c in the ERF dissector in Wireshark 1.8.x be…from 0, < 1.8.2-1
- —CVE-2012-4293plugins/ethercat/packet-ecatmb.c in the EtherCAT Mailbox dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before…from 0, < 1.8.2-1
- —CVE-2012-4292The dissect_stun_message function in epan/dissectors/packet-stun.c in the STUN dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6…from 0, < 1.8.2-1
- —CVE-2012-4291The CIP dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial o…from 0, < 1.8.2-1
- —CVE-2012-4290The CTDB dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial…from 0, < 1.8.2-1
- —CVE-2012-4289epan/dissectors/packet-afp.c in the AFP dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remo…from 0, < 1.8.2-1
- —CVE-2012-4288Integer overflow in the dissect_xtp_ecntl function in epan/dissectors/packet-xtp.c in the XTP dissector in Wireshark 1.4.x before 1.4.15, 1…from 0, < 1.8.2-1
- —CVE-2012-4287epan/dissectors/packet-mongo.c in the MongoDB dissector in Wireshark 1.8.x before 1.8.2 allows remote attackers to cause a denial of servic…from 0, < 1.8.2-1
- —CVE-2012-4286The pcapng_read_packet_block function in wiretap/pcapng.c in the pcap-ng file parser in Wireshark 1.8.x before 1.8.2 allows user-assisted r…from 0, < 1.8.2-1
- —CVE-2012-4285The dissect_pft function in epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.…from 0, < 1.8.2-1
- —CVE-2012-4049epan/dissectors/packet-nfs.c in the NFS dissector in Wireshark 1.4.x before 1.4.14, 1.6.x before 1.6.9, and 1.8.x before 1.8.1 allows remot…from 0, < 1.8.2-1
- from 0, < 1.8.2-1
- from 0, < 1.2.11-6+squeeze8
- —CVE-2012-3826Multiple integer underflows in Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 allow remote attackers to cause a denial of service (lo…from 0, < 1.6.8-1
- —CVE-2012-3825Multiple integer overflows in Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 allow remote attackers to cause a denial of service (inf…from 0, < 1.6.8-1
- —CVE-2012-2394Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 on the SPARC and Itanium platforms does not properly perform data alignment for a cert…from 0, < 1.6.8-1
- —CVE-2012-2393epan/dissectors/packet-diameter.c in the DIAMETER dissector in Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 does not properly const…from 0, < 1.6.8-1
- —CVE-2012-2392Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 allows remote attackers to cause a denial of service (infinite loop) via vectors relat…from 0, < 1.6.8-1
- —CVE-2012-1596The mp2t_process_fragmented_payload function in epan/dissectors/packet-mp2t.c in the MP2T dissector in Wireshark 1.4.x before 1.4.12 and 1.…from 0, < 1.6.6-1
- —CVE-2012-1595The pcap_process_pseudo_header function in wiretap/pcap-common.c in Wireshark 1.4.x before 1.4.12 and 1.6.x before 1.6.6 allows remote atta…from 0, < 1.6.6-1
- —CVE-2012-1594epan/dissectors/packet-ieee80211.c in the IEEE 802.11 dissector in Wireshark 1.6.x before 1.6.6 allows remote attackers to cause a denial o…from 0, < 1.6.6-1
- —CVE-2012-1593epan/dissectors/packet-ansi_a.c in the ANSI A dissector in Wireshark 1.4.x before 1.4.12 and 1.6.x before 1.6.6 allows remote attackers to…from 0, < 1.6.6-1
- —CVE-2012-0068The lanalyzer_read function in wiretap/lanalyzer.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause…from 0, < 1.6.5-1
- —CVE-2012-0067wiretap/iptrace.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application…from 0, < 1.6.5-1
- —CVE-2012-0066Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a long pa…from 0, < 1.6.5-1
- —CVE-2012-0043Buffer overflow in the reassemble_message function in epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.4.x before 1.4.11 an…from 0, < 1.6.5-1
- —CVE-2012-0042Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 does not properly perform certain string conversions, which allows remote attackers to…from 0, < 1.6.5-1
- —CVE-2012-0041The dissect_packet function in epan/packet.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a den…from 0, < 1.6.5-1
- from 0, < 1.2.11-6+squeeze5
- from 0, < 1.6.3-1
- —CVE-2011-4101The dissect_infiniband_common function in epan/dissectors/packet-infiniband.c in the Infiniband dissector in Wireshark 1.4.0 through 1.4.9…from 0, < 1.6.3-1
- —CVE-2011-4100The csnStreamDissector function in epan/dissectors/packet-csn1.c in the CSN.1 dissector in Wireshark 1.6.x before 1.6.3 does not initialize…from 0, < 1.6.3-1
- —CVE-2011-3484The unxorFrame function in epan/dissectors/packet-opensafety.c in the OpenSafety dissector in Wireshark 1.6.x before 1.6.2 does not properl…from 0, < 1.6.2-1
- from 0, < 1.2.11-6+squeeze6
- from 0, < 1.6.2-1
- —CVE-2011-3482The csnStreamDissector function in epan/dissectors/packet-csn1.c in the CSN.1 dissector in Wireshark 1.6.x before 1.6.2 does not initialize…from 0, < 1.6.2-1
- from 0, < 1.6.2-1
- from 0, < 1.2.11-6+squeeze4
- —CVE-2011-3266The proto_tree_add_item function in Wireshark 1.6.0 through 1.6.1 and 1.4.0 through 1.4.8, when the IKEv1 protocol dissector is used, allow…from 0, < 1.6.2-1
- —CVE-2011-2698Off-by-one error in the elem_cell_id_aux function in epan/dissectors/packet-ansi_a.c in the ANSI MAP dissector in Wireshark 1.4.x before 1.…from 0, < 1.6.1-1
- —CVE-2011-2597The Lucent/Ascend file parser in Wireshark 1.2.x before 1.2.18, 1.4.x through 1.4.7, and 1.6.0 allows remote attackers to cause a denial of…from 0, < 1.6.1-1
- —CVE-2011-2175Integer underflow in the visual_read function in wiretap/visual.c in Wireshark 1.2.x before 1.2.17 and 1.4.x before 1.4.7 allows remote att…from 0, < 1.6.0-1
- —CVE-2011-2174Double free vulnerability in the tvb_uncompress function in epan/tvbuff.c in Wireshark 1.2.x before 1.2.17 and 1.4.x before 1.4.7 allows re…from 0, < 1.6.0-1
- —CVE-2011-1959The snoop_read function in wiretap/snoop.c in Wireshark 1.2.x before 1.2.17 and 1.4.x before 1.4.7 does not properly handle certain virtual…from 0, < 1.6.0-1
- —CVE-2011-1958Wireshark 1.2.x before 1.2.17 and 1.4.x before 1.4.7 allows user-assisted remote attackers to cause a denial of service (NULL pointer deref…from 0, < 1.6.0-1
- —CVE-2011-1957The dissect_dcm_main function in epan/dissectors/packet-dcm.c in the DICOM dissector in Wireshark 1.2.x before 1.2.17 and 1.4.x before 1.4.…from 0, < 1.6.0-1
- —CVE-2011-1956The bytes_repr_len function in Wireshark 1.4.5 uses an incorrect pointer argument, which allows remote attackers to cause a denial of servi…from 0, < 1.4.6-1
- —CVE-2011-1591Stack-based buffer overflow in the DECT dissector in epan/dissectors/packet-dect.c in Wireshark 1.4.x before 1.4.5 allows remote attackers…from 0, < 1.4.5-1
- from 0, < 1.4.5-1
- from 0, < 1.2.11-6+squeeze2
- —CVE-2011-0024Heap-based buffer overflow in wiretap/pcapng.c in Wireshark before 1.2 allows remote attackers to cause a denial of service (application cr…from 0, < 1.2-0-1
- —CVE-2011-1143epan/dissectors/packet-ntlmssp.c in the NTLMSSP dissector in Wireshark before 1.4.4 allows remote attackers to cause a denial of service (N…from 0, < 1.4.4-1
- —CVE-2011-1141epan/dissectors/packet-ldap.c in Wireshark 1.0.x, 1.2.0 through 1.2.14, and 1.4.0 through 1.4.3 allows remote attackers to cause a denial o…from 0, < 1.4.4-1
- —CVE-2011-1140Multiple stack consumption vulnerabilities in the dissect_ms_compressed_string and dissect_mscldap_string functions in Wireshark 1.0.x, 1.2…from 0, < 1.4.4-1
- —CVE-2011-1139wiretap/pcapng.c in Wireshark 1.2.0 through 1.2.14 and 1.4.0 through 1.4.3 allows remote attackers to cause a denial of service (applicatio…from 0, < 1.4.4-1
- —CVE-2011-1138Off-by-one error in the dissect_6lowpan_iphc function in packet-6lowpan.c in Wireshark 1.4.0 through 1.4.3 on 32-bit platforms allows remot…from 0, < 1.4.4-1
- —CVE-2011-0713Heap-based buffer overflow in wiretap/dct3trace.c in Wireshark 1.2.0 through 1.2.14 and 1.4.0 through 1.4.3 allows remote attackers to caus…from 0, < 1.4.4-1
- from 0, < 1.4.3-3
- from 0, < 1.0.2-3+lenny13
- —CVE-2011-0444Buffer overflow in the MAC-LTE dissector (epan/dissectors/packet-mac-lte.c) in Wireshark 1.2.0 through 1.2.13 and 1.4.0 through 1.4.2 allow…from 0, < 1.2.11-6
- from 0, < 1.2.11-6
- from 0, < 1.0.2-3+lenny12
- —CVE-2010-4300Heap-based buffer overflow in the dissect_ldss_transfer function (epan/dissectors/packet-ldss.c) in the LDSS dissector in Wireshark 1.2.0 t…from 0, < 1.2.11-4
- from 0, < 1.2.11-3
- from 0, < 1.0.2-3+lenny11
- —CVE-2010-2995The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0.10.8 through 1.0.14 and 1.2.0 through 1.2.9 allows remote attacker…from 0, < 1.2.10-1
- from 0, < 1.0.2-3+lenny10
- from 0, < 1.2.10-1
- —CVE-2010-2993The IPMI dissector in Wireshark 1.2.0 through 1.2.9 allows remote attackers to cause a denial of service (infinite loop) via unknown vector…from 0, < 1.2.10-1
- —CVE-2010-2992packet-gsm_a_rr.c in the GSM A RR dissector in Wireshark 1.2.2 through 1.2.9 allows remote attackers to cause a denial of service (crash) v…from 0, < 1.2.10-1
- —CVE-2010-2287Buffer overflow in the SigComp Universal Decompressor Virtual Machine dissector in Wireshark 0.10.8 through 1.0.13 and 1.2.0 through 1.2.8…from 0, < 1.2.9-1
- —CVE-2010-2286The SigComp Universal Decompressor Virtual Machine dissector in Wireshark 0.10.7 through 1.0.13 and 1.2.0 through 1.2.8 allows remote attac…from 0, < 1.2.9-1
- —CVE-2010-2285The SMB PIPE dissector in Wireshark 0.8.20 through 1.0.13 and 1.2.0 through 1.2.8 allows remote attackers to cause a denial of service (NUL…from 0, < 1.2.9-1
- —CVE-2010-2284Buffer overflow in the ASN.1 BER dissector in Wireshark 0.10.13 through 1.0.13 and 1.2.0 through 1.2.8 has unknown impact and remote attack…from 0, < 1.2.9-1
- from 0, < 1.0.2-3+lenny9
- from 0, < 1.2.9-1
- —CVE-2010-1455The DOCSIS dissector in Wireshark 0.9.6 through 1.0.12 and 1.2.0 through 1.2.7 allows user-assisted remote attackers to cause a denial of s…from 0, < 1.2.8-1
- —CVE-2010-0304Multiple buffer overflows in the LWRES dissector in Wireshark 0.9.15 through 1.0.10 and 1.2.0 through 1.2.5 allow remote attackers to cause…from 0, < 1.2.6-1
- from 0, < 1.0.2-3+lenny8
- from 0, < 1.2.5-1
- —CVE-2009-4376Buffer overflow in the daintree_sna_read function in the Daintree SNA file parser in Wireshark 1.2.0 through 1.2.4 allows remote attackers…from 0, < 1.2.5-1
- —CVE-2009-3829Integer overflow in wiretap/erf.c in Wireshark before 1.2.2 allows remote attackers to execute arbitrary code or cause a denial of service…from 0, < 1.2.2-1
- —CVE-2009-3551Off-by-one error in the dissect_negprot_response function in packet-smb.c in the SMB dissector in Wireshark 1.2.0 through 1.2.2 allows remo…from 0, < 1.2.3-1
- —CVE-2009-3550The DCERPC/NT dissector in Wireshark 0.10.10 through 1.0.9 and 1.2.0 through 1.2.2 allows remote attackers to cause a denial of service (NU…from 0, < 1.2.3-1
- —CVE-2009-3549packet-paltalk.c in the Paltalk dissector in Wireshark 1.2.0 through 1.2.2, on SPARC and certain other platforms, allows remote attackers t…from 0, < 1.2.3-1
- —CVE-2009-3242Unspecified vulnerability in packet.c in the GSM A RR dissector in Wireshark 1.2.0 and 1.2.1 allows remote attackers to cause a denial of s…from 0, < 1.2.2-1
- —CVE-2009-3241Unspecified vulnerability in the OpcUa (OPC UA) dissector in Wireshark 0.99.6 through 1.0.8 and 1.2.0 through 1.2.1 allows remote attackers…from 0, < 1.2.2-1
- —CVE-2009-2563Unspecified vulnerability in the Infiniband dissector in Wireshark 1.0.6 through 1.2.0, when running on unspecified platforms, allows remot…from 0, < 1.2.1-1
- —CVE-2009-2562Unspecified vulnerability in the AFS dissector in Wireshark 0.9.2 through 1.2.0 allows remote attackers to cause a denial of service (crash…from 0, < 1.2.1-1
- —CVE-2009-2561Unspecified vulnerability in the sFlow dissector in Wireshark 1.2.0 allows remote attackers to cause a denial of service (CPU and memory co…from 0, < 1.2.1-1
- —CVE-2009-2560Multiple unspecified vulnerabilities in Wireshark 1.2.0 allow remote attackers to cause a denial of service (application crash) via a file…from 0, < 1.2.1-1
- —CVE-2009-2559Buffer overflow in the IPMI dissector in Wireshark 1.2.0 allows remote attackers to cause a denial of service (crash) via unspecified vecto…from 0, < 1.2.1-1
- from 0, < 0.99.4-5.etch.4
- from 0, < 1.0.8-1
- —CVE-2009-1269Unspecified vulnerability in Wireshark 0.99.6 through 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted Tekt…from 0, < 1.0.7-1
- —CVE-2009-1268The Check Point High-Availability Protocol (CPHAP) dissector in Wireshark 0.9.6 through 1.0.6 allows remote attackers to cause a denial of…from 0, < 1.0.7-1
- from 0, < 1.0.2-3+lenny5
- from 0, < 1.0.7-1
- —CVE-2008-6472The WLCCP dissector in Wireshark 0.99.7 through 1.0.4 allows remote attackers to cause a denial of service (infinite loop) via unspecified…from 0, < 1.0.5-1
- —CVE-2009-0601Format string vulnerability in Wireshark 0.99.8 through 1.0.5 on non-Windows platforms allows local users to cause a denial of service (app…from 0, < 1.0.6-1
- —CVE-2009-0600Wireshark 0.99.6 through 1.0.5 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted Tektron…from 0, < 1.0.6-1
- —CVE-2009-0599Buffer overflow in wiretap/netscreen.c in Wireshark 0.99.7 through 1.0.5 allows user-assisted remote attackers to cause a denial of service…from 0, < 1.0.6-1
- —CVE-2008-5285Wireshark 1.0.4 and earlier allows remote attackers to cause a denial of service via a long SMTP request, which triggers an infinite loop.from 0, < 1.0.5-1
- —CVE-2008-4685Use-after-free vulnerability in the dissect_q931_cause_ie function in packet-q931.c in the Q.931 dissector in Wireshark 0.10.3 through 1.0.…from 0, < 1.0.4-1
- —CVE-2008-4684packet-frame in Wireshark 0.99.2 through 1.0.3 does not properly handle exceptions thrown by post dissectors, which allows remote attackers…from 0, < 1.0.4-1
- —CVE-2008-4683The dissect_btacl function in packet-bthci_acl.c in the Bluetooth ACL dissector in Wireshark 0.99.2 through 1.0.3 allows remote attackers t…from 0, < 1.0.4-1
- —CVE-2008-4682wtap.c in Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a denial of service (application abort) via a malformed Tamos Com…from 0, < 1.0.4-1
- —CVE-2008-4681Unspecified vulnerability in the Bluetooth RFCOMM dissector in Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a denial of…from 0, < 1.0.4-1
- —CVE-2008-4680packet-usb.c in the USB dissector in Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a denial of service (application crash…from 0, < 1.0.4-1
- —CVE-2008-3934Unspecified vulnerability in Wireshark (formerly Ethereal) 0.99.6 through 1.0.2 allows attackers to cause a denial of service (crash) via a…from 0, < 1.0.3-1
- —CVE-2008-3932Wireshark (formerly Ethereal) 0.9.7 through 1.0.2 allows attackers to cause a denial of service (hang) via a crafted NCP packet that trigge…from 0, < 1.0.3-1
- —CVE-2008-3933Wireshark (formerly Ethereal) 0.10.14 through 1.0.2 allows attackers to cause a denial of service (crash) via a packet with crafted zlib-co…from 0, < 1.0.3-1
- from 0, < 1.0.3-1
- from 0, < 1.0.2-3+lenny1
- —CVE-2008-3145The fragment_add_work function in epan/reassemble.c in Wireshark 0.8.19 through 1.0.1 allows remote attackers to cause a denial of service…from 0, < 1.0.2-1
- —CVE-2008-3138The (1) PANA and (2) KISMET dissectors in Wireshark (formerly Ethereal) 0.99.3 through 1.0.0 allow remote attackers to cause a denial of se…from 0, < 1.0.1-1
- —CVE-2008-3141Unspecified vulnerability in the RMI dissector in Wireshark (formerly Ethereal) 0.9.5 through 1.0.0 allows remote attackers to read system…from 0, < 1.0.1-1
- from 0, < 0.99.4-5.etch.3
- —CVE-2008-3140The syslog dissector in Wireshark (formerly Ethereal) 1.0.0 allows remote attackers to cause a denial of service (application crash) via un…from 0, < 1.0.1-1
- from 0, < 1.0.1-1
- —CVE-2008-3139The RTMPT dissector in Wireshark (formerly Ethereal) 0.99.8 through 1.0.0 allows remote attackers to cause a denial of service (crash) via…from 0, < 1.0.1-1
- —CVE-2008-1561Multiple unspecified vulnerabilities in Wireshark (formerly Ethereal) 0.99.5 through 0.99.8 allow remote attackers to cause a denial of ser…from 0, < 1.0.0-1
- —CVE-2008-1563The "decode as" feature in packet-bssap.c in the SCCP dissector in Wireshark (formerly Ethereal) 0.99.6 through 0.99.8 allows remote attack…from 0, < 1.0.0-1
- —CVE-2008-1072The TFTP dissector in Wireshark (formerly Ethereal) 0.6.0 through 0.99.7, when running on Ubuntu 7.10, allows remote attackers to cause a d…from 0, < 0.99.8-1
- —CVE-2008-1070The SCTP dissector in Wireshark (formerly Ethereal) 0.99.5 through 0.99.7 allows remote attackers to cause a denial of service (crash) via…from 0, < 0.99.8-1
- —CVE-2008-1071The SNMP dissector in Wireshark (formerly Ethereal) 0.99.6 through 0.99.7 allows remote attackers to cause a denial of service (crash) via…from 0, < 0.99.8-1
- from 0, < 0.99.7-1~lenny1
- from 0, < 0.99.4-5.etch.2
- —CVE-2007-6439Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (infinite or large loop) via the (1) IPv6 or (2)…from 0, < 0.99.7-1
- —CVE-2007-6451Unspecified vulnerability in the CIP dissector in Wireshark (formerly Ethereal) 0.9.14 to 0.99.6 allows remote attackers to cause a denial…from 0, < 0.99.7-1
- —CVE-2007-6441The WiMAX dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (crash) via unknown vector…from 0, < 0.99.7-1
- from 0, < 0.99.7-1
- from 0, < 0.99.7-1
- —CVE-2007-6115Buffer overflow in the ANSI MAP dissector for Wireshark (formerly Ethereal) 0.99.5 to 0.99.6, when running on unspecified platforms, allows…from 0, < 0.99.7~pre1-1
- —CVE-2007-6119The DCP ETSI dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (long loop and resource…from 0, < 0.99.7~pre1-1
- from 0, < 0.99.4-5.etch.1
- —CVE-2007-6116The Firebird/Interbase dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (infinite loo…from 0, < 0.99.7~pre1-1
- from 0, < 0.99.7~pre1-1
- —CVE-2007-6120The Bluetooth SDP dissector Wireshark (formerly Ethereal) 0.99.2 to 0.99.6 allows remote attackers to cause a denial of service (infinite l…from 0, < 0.99.7~pre1-1
- from 0, < 0.99.7~pre1-1
- —CVE-2007-6118The MEGACO dissector in Wireshark (formerly Ethereal) 0.9.14 to 0.99.6 allows remote attackers to cause a denial of service (long loop and…from 0, < 0.99.7~pre1-1
- —CVE-2007-6112Buffer overflow in the PPP dissector Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (crash) and…from 0, < 0.99.7~pre1-1
- —CVE-2007-6117Unspecified vulnerability in the HTTP dissector for Wireshark (formerly Ethereal) 0.10.14 to 0.99.6 allows remote attackers to cause a deni…from 0, < 0.99.7~pre1-1
- —CVE-2007-6113Integer signedness error in the DNP3 dissector in Wireshark (formerly Ethereal) 0.10.12 to 0.99.6 allows remote attackers to cause a denial…from 0, < 0.99.6pre1-1
- —CVE-2007-6121Wireshark (formerly Ethereal) 0.8.16 to 0.99.6 allows remote attackers to cause a denial of service (crash) via a malformed RPC Portmap pac…from 0, < 0.99.7~pre1-1
- from 0, < 0.99.6rel-5+0.99.7~pre1-1+lenny1
- —CVE-2007-3393Off-by-one error in the DHCP/BOOTP dissector in Wireshark before 0.99.6 allows remote attackers to cause a denial of service (crash) via cr…from 0, < 0.99.6pre1-1
- —CVE-2007-3391Wireshark 0.99.5 allows remote attackers to cause a denial of service (memory consumption) via a malformed DCP ETSI packet that triggers an…from 0, < 0.99.6pre1-1
- from 0, < 0.99.6pre1-1
- from 0, < 0.99.4-5.etch.0
- —CVE-2007-3392Wireshark before 0.99.6 allows remote attackers to cause a denial of service via malformed (1) SSL or (2) MMS packets that trigger an infin…from 0, < 0.99.6pre1-1
- —CVE-2007-3389Wireshark before 0.99.6 allows remote attackers to cause a denial of service (crash) via a crafted chunked encoding in an HTTP response, po…from 0, < 0.99.6pre1-1
- —CVE-2007-0456Unspecified vulnerability in the LLT dissector in Wireshark (formerly Ethereal) 0.99.3 and 0.99.4 allows remote attackers to cause a denial…from 0, < 0.99.4-5
- —CVE-2007-0457Unspecified vulnerability in the IEEE 802.11 dissector in Wireshark (formerly Ethereal) 0.10.14 through 0.99.4 allows remote attackers to c…from 0, < 0.99.4-5
- —CVE-2007-0459packet-tcp.c in the TCP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.4 allows remote attackers to cause a denial of servi…from 0, < 0.99.4-5
- —CVE-2007-0458Unspecified vulnerability in the HTTP dissector in Wireshark (formerly Ethereal) 0.99.3 and 0.99.4 allows remote attackers to cause a denia…from 0, < 0.99.4-5
- —CVE-2006-5595Unspecified vulnerability in the AirPcap support in Wireshark (formerly Ethereal) 0.99.3 has unspecified attack vectors related to WEP key…from 0, < 0.99.4-1
- —CVE-2006-5469Unspecified vulnerability in the WBXML dissector in Wireshark (formerly Ethereal) 0.10.11 through 0.99.3 allows remote attackers to cause a…from 0, < 0.99.4-1
- —CVE-2006-5468Unspecified vulnerability in the HTTP dissector in Wireshark (formerly Ethereal) 0.99.3 allows remote attackers to cause a denial of servic…from 0, < 0.99.4-1
- —CVE-2006-4805epan/dissectors/packet-xot.c in the XOT dissector (dissect_xot_pdu) in Wireshark (formerly Ethereal) 0.9.8 through 0.99.3 allows remote att…from 0, < 0.99.4-1
- —CVE-2006-5740Unspecified vulnerability in the LDAP dissector in Wireshark (formerly Ethereal) 0.99.3 allows remote attackers to cause a denial of servic…from 0, < 0.99.4-1
- —CVE-2006-4330Unspecified vulnerability in the SCSI dissector in Wireshark (formerly Ethereal) 0.99.2 allows remote attackers to cause a denial of servic…from 0, < 0.99.2-5
- —CVE-2006-4331Multiple off-by-one errors in the IPSec ESP preference parser in Wireshark (formerly Ethereal) 0.99.2 allow remote attackers to cause a den…from 0, < 0.99.2-5.1
- —CVE-2006-4333The SSCOP dissector in Wireshark (formerly Ethereal) before 0.99.3 allows remote attackers to cause a denial of service (resource consumpti…from 0, < 0.99.2-5.1
- —CVE-2006-3629Unspecified vulnerability in the MOUNT dissector in Wireshark (aka Ethereal) 0.9.4 to 0.99.0 allows remote attackers to cause a denial of s…from 0, < 0.99.2-1
- —CVE-2006-3630Multiple off-by-one errors in Wireshark (aka Ethereal) 0.9.7 to 0.99.0 have unknown impact and remote attack vectors via the (1) NCP NMAS a…from 0, < 0.99.2-1
- —CVE-2006-3632Buffer overflow in Wireshark (aka Ethereal) 0.8.16 to 0.99.0 allows remote attackers to cause a denial of service and possibly execute arbi…from 0, < 0.99.2-1
- from 0, < 0.99.2-1
- —CVE-2006-3627Unspecified vulnerability in the GSM BSSMAP dissector in Wireshark (aka Ethereal) 0.10.11 to 0.99.0 allows remote attackers to cause a deni…from 0, < 0.99.2-1
- —CVE-2006-3631Unspecified vulnerability in the SSH dissector in Wireshark (aka Ethereal) 0.9.10 to 0.99.0 allows remote attackers to cause a denial of se…from 0, < 0.99.2-1