VYPR

Wireshark

by Wireshark

Source repositories

CVEs (752)

  • CVE-2018-6836CriFeb 8, 2018
    risk 0.64cvss 9.8epss 0.03

    The netmonrec_comment_destroy function in wiretap/netmon.c in Wireshark through 2.4.4 performs a free operation on an uninitialized memory address, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

  • CVE-2018-19627HigNov 29, 2018
    risk 0.53cvss 7.5epss 0.18

    In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the IxVeriWave file parser could crash. This was addressed in wiretap/vwr.c by adjusting a buffer boundary.

  • CVE-2017-17085HigDec 1, 2017
    risk 0.53cvss 7.5epss 0.17

    In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the CIP Safety dissector could crash. This was addressed in epan/dissectors/packet-cipsafety.c by validating the packet length.

  • CVE-2017-9353HigJun 2, 2017
    risk 0.53cvss 7.5epss 0.14

    In Wireshark 2.2.0 to 2.2.6, the IPv6 dissector could crash. This was addressed in epan/dissectors/packet-ipv6.c by validating an IPv6 address.

  • CVE-2017-9347HigJun 2, 2017
    risk 0.53cvss 7.5epss 0.14

    In Wireshark 2.2.0 to 2.2.6, the ROS dissector could crash with a NULL pointer dereference. This was addressed in epan/dissectors/asn1/ros/packet-ros-template.c by validating an OID.

  • CVE-2025-13499HigNov 21, 2025
    risk 0.51cvss 7.8epss 0.00

    Kafka dissector crash in Wireshark 4.6.0 and 4.4.0 to 4.4.10 allows denial of service

  • CVE-2025-9817HigSep 3, 2025
    risk 0.51cvss 7.8epss 0.00

    SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial of service

  • CVE-2025-5601HigJun 4, 2025
    risk 0.51cvss 7.8epss 0.00

    Column handling crashes in Wireshark 4.4.0 to 4.4.6 and 4.2.0 to 4.2.12 allows denial of service via packet injection or crafted capture file

  • CVE-2025-1492HigFeb 20, 2025
    risk 0.51cvss 7.8epss 0.00

    Bundle Protocol and CBOR dissector crashes in Wireshark 4.4.0 to 4.4.3 and 4.2.0 to 4.2.10 allows denial of service via packet injection or crafted capture file

  • CVE-2024-11596HigNov 21, 2024
    risk 0.51cvss 7.8epss 0.00

    ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file

  • CVE-2024-11595HigNov 21, 2024
    risk 0.51cvss 7.8epss 0.00

    FiveCo RAP dissector infinite loop in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file

  • CVE-2024-9781HigOct 10, 2024
    risk 0.51cvss 7.8epss 0.00

    AppleTalk and RELOAD Framing dissector crash in Wireshark 4.4.0 and 4.2.0 to 4.2.7 allows denial of service via packet injection or crafted capture file

  • CVE-2024-9780HigOct 10, 2024
    risk 0.51cvss 7.8epss 0.00

    ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capture file

  • CVE-2024-8250HigAug 29, 2024
    risk 0.51cvss 7.8epss 0.00

    NTLMSSP dissector crash in Wireshark 4.2.0 to 4.0.6 and 4.0.0 to 4.0.16 allows denial of service via packet injection or crafted capture file

  • CVE-2023-6175HigMar 26, 2024
    risk 0.51cvss 7.8epss 0.03

    NetScreen file parser crash in Wireshark 4.0.0 to 4.0.10 and 3.6.0 to 3.6.18 allows denial of service via crafted capture file

  • CVE-2024-0211HigJan 3, 2024
    risk 0.51cvss 7.8epss 0.01

    DOCSIS dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file

  • CVE-2024-0210HigJan 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Zigbee TLV dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file

  • CVE-2024-0209HigJan 3, 2024
    risk 0.51cvss 7.8epss 0.01

    IEEE 1609.2 dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture file

  • CVE-2024-0208HigJan 3, 2024
    risk 0.51cvss 7.8epss 0.02

    GVCP dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture file

  • CVE-2024-0207HigJan 3, 2024
    risk 0.51cvss 7.8epss 0.00

    HTTP3 dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file

Page 1 of 38