Wireshark
by Wireshark
Source repositories
CVEs (791)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-26418 | Low | 0.20 | 3.1 | 0.03 | Dec 11, 2020 | Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file. | ||
| CVE-2026-15173 | Med | 0.19 | 4.7 | 0.00 | Jul 8, 2026 | pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial of service | ||
| CVE-2024-4855 | Low | 0.16 | 3.6 | 0.00 | May 14, 2024 | Use after free issue in editcap could cause denial of service via crafted capture file | ||
| CVE-2024-4853 | Low | 0.16 | 3.6 | 0.00 | May 14, 2024 | Memory handling issue in editcap could cause denial of service via crafted capture file | ||
| CVE-2026-15168 | Low | 0.09 | 2.5 | 0.00 | Jul 8, 2026 | BLF file parser in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows possible information disclosure | ||
| CVE-2010-0304 | 0.09 | — | 0.74 | Feb 3, 2010 | Multiple buffer overflows in the LWRES dissector in Wireshark 0.9.15 through 1.0.10 and 1.2.0 through 1.2.5 allow remote attackers to cause a denial of service (crash) via a malformed packet, as demonstrated using a stack-based buffer overflow to the… | |||
| CVE-2013-4074 | 0.08 | — | 0.61 | Jun 9, 2013 | The dissect_capwap_data function in epan/dissectors/packet-capwap.c in the CAPWAP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x before 1.8.8 incorrectly uses a -1 data value to represent an error condition, which allows remote attackers to cause a denial of service… | |||
| CVE-2014-2299 | 0.07 | — | 0.47 | Mar 11, 2014 | Buffer overflow in the mpeg_read function in wiretap/mpeg.c in the MPEG parser in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a large record in MPEG data. | |||
| CVE-2008-1562 | 0.07 | — | 0.51 | Mar 31, 2008 | The LDAP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.8 allows remote attackers to cause a denial of service (application crash) via a malformed packet, a different vulnerability than CVE-2006-5740. | |||
| CVE-2011-3360 | 0.06 | — | 0.35 | Sep 20, 2011 | Untrusted search path vulnerability in Wireshark 1.4.x before 1.4.9 and 1.6.x before 1.6.2 allows local users to gain privileges via a Trojan horse Lua script in an unspecified directory. | |||
| CVE-2011-1591 | 0.06 | — | 0.42 | Apr 29, 2011 | Stack-based buffer overflow in the DECT dissector in epan/dissectors/packet-dect.c in Wireshark 1.4.x before 1.4.5 allows remote attackers to execute arbitrary code via a crafted .pcap file. | |||
| CVE-2010-4538 | 0.05 | — | 0.29 | Jan 7, 2011 | Buffer overflow in the sect_enttec_dmx_da function in epan/dissectors/packet-enttec.c in Wireshark 1.4.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ENTTEC DMX packet with Run Length Encoding (RLE)… | |||
| CVE-2012-1593 | 0.04 | — | 0.11 | Apr 11, 2012 | epan/dissectors/packet-ansi_a.c in the ANSI A dissector in Wireshark 1.4.x before 1.4.12 and 1.6.x before 1.6.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed packet. | |||
| CVE-2012-0067 | 0.04 | — | 0.07 | Apr 11, 2012 | wiretap/iptrace.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a long packet in an AIX iptrace file. | |||
| CVE-2011-1143 | 0.04 | — | 0.09 | Mar 3, 2011 | epan/dissectors/packet-ntlmssp.c in the NTLMSSP dissector in Wireshark before 1.4.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted .pcap file. | |||
| CVE-2011-1140 | 0.04 | — | 0.13 | Mar 3, 2011 | Multiple stack consumption vulnerabilities in the dissect_ms_compressed_string and dissect_mscldap_string functions in Wireshark 1.0.x, 1.2.0 through 1.2.14, and 1.4.0 through 1.4.3 allow remote attackers to cause a denial of service (infinite recursion) via a crafted (1) SMB or… | |||
| CVE-2011-0538 | 0.04 | — | 0.08 | Feb 8, 2011 | Wireshark 1.2.0 through 1.2.14, 1.4.0 through 1.4.3, and 1.5.0 frees an uninitialized pointer during processing of a .pcap file in the pcap-ng format, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a… | |||
| CVE-2010-4301 | 0.04 | — | 0.09 | Nov 26, 2010 | epan/dissectors/packet-zbee-zcl.c in the ZigBee ZCL dissector in Wireshark 1.4.0 through 1.4.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted ZCL packet, related to Discover Attributes. | |||
| CVE-2010-4300 | 0.04 | — | 0.14 | Nov 26, 2010 | Heap-based buffer overflow in the dissect_ldss_transfer function (epan/dissectors/packet-ldss.c) in the LDSS dissector in Wireshark 1.2.0 through 1.2.12 and 1.4.0 through 1.4.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via… | |||
| CVE-2010-3133 | 0.04 | — | 0.09 | Aug 26, 2010 | Untrusted search path vulnerability in Wireshark 0.8.4 through 1.0.15 and 1.2.0 through 1.2.10 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse airpcap.dll, and possibly other DLLs, that is located… |
- risk 0.20cvss 3.1epss 0.03
Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
- risk 0.19cvss 4.7epss 0.00
pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial of service
- risk 0.16cvss 3.6epss 0.00
Use after free issue in editcap could cause denial of service via crafted capture file
- risk 0.16cvss 3.6epss 0.00
Memory handling issue in editcap could cause denial of service via crafted capture file
- risk 0.09cvss 2.5epss 0.00
BLF file parser in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows possible information disclosure
- CVE-2010-0304Feb 3, 2010risk 0.09cvss —epss 0.74
Multiple buffer overflows in the LWRES dissector in Wireshark 0.9.15 through 1.0.10 and 1.2.0 through 1.2.5 allow remote attackers to cause a denial of service (crash) via a malformed packet, as demonstrated using a stack-based buffer overflow to the…
- CVE-2013-4074Jun 9, 2013risk 0.08cvss —epss 0.61
The dissect_capwap_data function in epan/dissectors/packet-capwap.c in the CAPWAP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x before 1.8.8 incorrectly uses a -1 data value to represent an error condition, which allows remote attackers to cause a denial of service…
- CVE-2014-2299Mar 11, 2014risk 0.07cvss —epss 0.47
Buffer overflow in the mpeg_read function in wiretap/mpeg.c in the MPEG parser in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a large record in MPEG data.
- CVE-2008-1562Mar 31, 2008risk 0.07cvss —epss 0.51
The LDAP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.8 allows remote attackers to cause a denial of service (application crash) via a malformed packet, a different vulnerability than CVE-2006-5740.
- CVE-2011-3360Sep 20, 2011risk 0.06cvss —epss 0.35
Untrusted search path vulnerability in Wireshark 1.4.x before 1.4.9 and 1.6.x before 1.6.2 allows local users to gain privileges via a Trojan horse Lua script in an unspecified directory.
- CVE-2011-1591Apr 29, 2011risk 0.06cvss —epss 0.42
Stack-based buffer overflow in the DECT dissector in epan/dissectors/packet-dect.c in Wireshark 1.4.x before 1.4.5 allows remote attackers to execute arbitrary code via a crafted .pcap file.
- CVE-2010-4538Jan 7, 2011risk 0.05cvss —epss 0.29
Buffer overflow in the sect_enttec_dmx_da function in epan/dissectors/packet-enttec.c in Wireshark 1.4.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ENTTEC DMX packet with Run Length Encoding (RLE)…
- CVE-2012-1593Apr 11, 2012risk 0.04cvss —epss 0.11
epan/dissectors/packet-ansi_a.c in the ANSI A dissector in Wireshark 1.4.x before 1.4.12 and 1.6.x before 1.6.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed packet.
- CVE-2012-0067Apr 11, 2012risk 0.04cvss —epss 0.07
wiretap/iptrace.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a long packet in an AIX iptrace file.
- CVE-2011-1143Mar 3, 2011risk 0.04cvss —epss 0.09
epan/dissectors/packet-ntlmssp.c in the NTLMSSP dissector in Wireshark before 1.4.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted .pcap file.
- CVE-2011-1140Mar 3, 2011risk 0.04cvss —epss 0.13
Multiple stack consumption vulnerabilities in the dissect_ms_compressed_string and dissect_mscldap_string functions in Wireshark 1.0.x, 1.2.0 through 1.2.14, and 1.4.0 through 1.4.3 allow remote attackers to cause a denial of service (infinite recursion) via a crafted (1) SMB or…
- CVE-2011-0538Feb 8, 2011risk 0.04cvss —epss 0.08
Wireshark 1.2.0 through 1.2.14, 1.4.0 through 1.4.3, and 1.5.0 frees an uninitialized pointer during processing of a .pcap file in the pcap-ng format, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a…
- CVE-2010-4301Nov 26, 2010risk 0.04cvss —epss 0.09
epan/dissectors/packet-zbee-zcl.c in the ZigBee ZCL dissector in Wireshark 1.4.0 through 1.4.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted ZCL packet, related to Discover Attributes.
- CVE-2010-4300Nov 26, 2010risk 0.04cvss —epss 0.14
Heap-based buffer overflow in the dissect_ldss_transfer function (epan/dissectors/packet-ldss.c) in the LDSS dissector in Wireshark 1.2.0 through 1.2.12 and 1.4.0 through 1.4.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via…
- CVE-2010-3133Aug 26, 2010risk 0.04cvss —epss 0.09
Untrusted search path vulnerability in Wireshark 0.8.4 through 1.0.15 and 1.2.0 through 1.2.10 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse airpcap.dll, and possibly other DLLs, that is located…
Page 24 of 40