Wireshark
by Wireshark
Source repositories
CVEs (775)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-4083 | Med | 0.38 | 5.9 | 0.02 | Apr 25, 2016 | epan/dissectors/packet-mswsp.c in the MS-WSP dissector in Wireshark 2.0.x before 2.0.3 does not ensure that data is available before array allocation, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. | ||
| CVE-2016-4076 | Med | 0.38 | 5.9 | 0.02 | Apr 25, 2016 | epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 2.0.x before 2.0.3 does not properly initialize memory for search patterns, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. | ||
| CVE-2016-2524 | Med | 0.38 | 5.9 | 0.02 | Feb 28, 2016 | epan/dissectors/packet-x509af.c in the X.509AF dissector in Wireshark 2.0.x before 2.0.2 mishandles the algorithm ID, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. | ||
| CVE-2015-8740 | Med | 0.38 | 5.3 | 0.07 | Jan 4, 2016 | The dissect_tds7_colmetadata_token function in epan/dissectors/packet-tds.c in the TDS dissector in Wireshark 2.0.x before 2.0.1 does not validate the number of columns, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application… | ||
| CVE-2026-76924 | Med | 0.36 | 5.5 | 0.00 | Aug 19, 2026 | Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | ||
| CVE-2026-76923 | Med | 0.36 | 5.5 | 0.00 | Aug 19, 2026 | Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | ||
| CVE-2026-76922 | Med | 0.36 | 5.5 | 0.00 | Aug 19, 2026 | Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | ||
| CVE-2026-76921 | Med | 0.36 | 5.5 | 0.00 | Aug 19, 2026 | CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | ||
| CVE-2026-76918 | Med | 0.36 | 5.5 | 0.00 | Aug 19, 2026 | SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | ||
| CVE-2026-76917 | Med | 0.36 | 5.5 | 0.00 | Aug 19, 2026 | Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | ||
| CVE-2026-9759 | Med | 0.36 | 5.5 | 0.00 | May 27, 2026 | ROHC protocol dissector crash in Wireshark 4.6.0 to 4.6.5 and 4.4.0 to 4.4.15 allows denial of service | ||
| CVE-2026-3203 | Med | 0.36 | 5.5 | 0.00 | Feb 25, 2026 | RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service | ||
| CVE-2026-0961 | Med | 0.36 | 5.5 | 0.00 | Jan 14, 2026 | BLF file parser crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service | ||
| CVE-2025-13946 | Med | 0.36 | 5.5 | 0.00 | Dec 3, 2025 | MEGACO dissector infinite loop in Wireshark 4.6.0 to 4.6.1 and 4.4.0 to 4.4.11 allows denial of service | ||
| CVE-2025-13945 | Med | 0.36 | 5.5 | 0.00 | Dec 3, 2025 | HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service | ||
| CVE-2025-13674 | Med | 0.36 | 5.5 | 0.00 | Nov 26, 2025 | BPv7 dissector crash in Wireshark 4.6.0 allows denial of service | ||
| CVE-2025-11626 | Med | 0.36 | 5.5 | 0.00 | Oct 10, 2025 | MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13 allows denial of service | ||
| CVE-2024-8645 | Med | 0.36 | 5.5 | 0.00 | Sep 10, 2024 | SPRT dissector crash in Wireshark 4.2.0 to 4.0.5 and 4.0.0 to 4.0.15 allows denial of service via packet injection or crafted capture file | ||
| CVE-2021-4183 | Med | 0.36 | 5.5 | 0.01 | Dec 30, 2021 | Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file | ||
| CVE-2021-22207 | Med | 0.36 | 5.5 | 0.02 | Apr 23, 2021 | Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of service via packet injection or crafted capture file |
- risk 0.38cvss 5.9epss 0.02
epan/dissectors/packet-mswsp.c in the MS-WSP dissector in Wireshark 2.0.x before 2.0.3 does not ensure that data is available before array allocation, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
- risk 0.38cvss 5.9epss 0.02
epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 2.0.x before 2.0.3 does not properly initialize memory for search patterns, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
- risk 0.38cvss 5.9epss 0.02
epan/dissectors/packet-x509af.c in the X.509AF dissector in Wireshark 2.0.x before 2.0.2 mishandles the algorithm ID, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
- risk 0.38cvss 5.3epss 0.07
The dissect_tds7_colmetadata_token function in epan/dissectors/packet-tds.c in the TDS dissector in Wireshark 2.0.x before 2.0.1 does not validate the number of columns, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application…
- risk 0.36cvss 5.5epss 0.00
Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- risk 0.36cvss 5.5epss 0.00
Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- risk 0.36cvss 5.5epss 0.00
Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- risk 0.36cvss 5.5epss 0.00
CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- risk 0.36cvss 5.5epss 0.00
SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- risk 0.36cvss 5.5epss 0.00
Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- risk 0.36cvss 5.5epss 0.00
ROHC protocol dissector crash in Wireshark 4.6.0 to 4.6.5 and 4.4.0 to 4.4.15 allows denial of service
- risk 0.36cvss 5.5epss 0.00
RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
- risk 0.36cvss 5.5epss 0.00
BLF file parser crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
- risk 0.36cvss 5.5epss 0.00
MEGACO dissector infinite loop in Wireshark 4.6.0 to 4.6.1 and 4.4.0 to 4.4.11 allows denial of service
- risk 0.36cvss 5.5epss 0.00
HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service
- risk 0.36cvss 5.5epss 0.00
BPv7 dissector crash in Wireshark 4.6.0 allows denial of service
- risk 0.36cvss 5.5epss 0.00
MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13 allows denial of service
- risk 0.36cvss 5.5epss 0.00
SPRT dissector crash in Wireshark 4.2.0 to 4.0.5 and 4.0.0 to 4.0.15 allows denial of service via packet injection or crafted capture file
- risk 0.36cvss 5.5epss 0.01
Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file
- risk 0.36cvss 5.5epss 0.02
Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of service via packet injection or crafted capture file
Page 16 of 39