VYPR

Wireshark

by Wireshark

Source repositories

CVEs (775)

  • CVE-2009-4378Dec 21, 2009
    risk 0.00cvss —epss 0.02

    The IPMI dissector in Wireshark 1.2.0 through 1.2.4 on Windows allows remote attackers to cause a denial of service (crash) via a crafted packet, related to "formatting a date/time using strftime."

  • CVE-2009-4377Dec 21, 2009
    risk 0.00cvss —epss 0.03

    The (1) SMB and (2) SMB2 dissectors in Wireshark 0.9.0 through 1.2.4 allow remote attackers to cause a denial of service (crash) via a crafted packet that triggers a NULL pointer dereference, as demonstrated by fuzz-2009-12-07-11141.pcap.

  • CVE-2009-3829Oct 30, 2009
    risk 0.00cvss —epss 0.06

    Integer overflow in wiretap/erf.c in Wireshark before 1.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted erf file, related to an "unsigned integer wrap vulnerability."

  • CVE-2009-3551Oct 30, 2009
    risk 0.00cvss —epss 0.02

    Off-by-one error in the dissect_negprot_response function in packet-smb.c in the SMB dissector in Wireshark 1.2.0 through 1.2.2 allows remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace. NOTE: some of these details…

  • CVE-2009-3550Oct 30, 2009
    risk 0.00cvss —epss 0.02

    The DCERPC/NT dissector in Wireshark 0.10.10 through 1.0.9 and 1.2.0 through 1.2.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a file that records a malformed packet trace. NOTE: some of these details are obtained…

  • CVE-2009-3549Oct 30, 2009
    risk 0.00cvss —epss 0.03

    packet-paltalk.c in the Paltalk dissector in Wireshark 1.2.0 through 1.2.2, on SPARC and certain other platforms, allows remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace.

  • CVE-2009-2563Jul 21, 2009
    risk 0.00cvss —epss 0.03

    Unspecified vulnerability in the Infiniband dissector in Wireshark 1.0.6 through 1.2.0, when running on unspecified platforms, allows remote attackers to cause a denial of service (crash) via unknown vectors.

  • CVE-2009-2562Jul 21, 2009
    risk 0.00cvss —epss 0.03

    Unspecified vulnerability in the AFS dissector in Wireshark 0.9.2 through 1.2.0 allows remote attackers to cause a denial of service (crash) via unknown vectors.

  • CVE-2009-2561Jul 21, 2009
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in the sFlow dissector in Wireshark 1.2.0 allows remote attackers to cause a denial of service (CPU and memory consumption) via unspecified vectors.

  • CVE-2009-2560Jul 21, 2009
    risk 0.00cvss —epss 0.02

    Multiple unspecified vulnerabilities in Wireshark 1.2.0 allow remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace and is processed by the (1) Bluetooth L2CAP, (2) RADIUS, or (3) MIOP dissector. NOTE: it was later…

  • CVE-2009-2559Jul 21, 2009
    risk 0.00cvss —epss 0.02

    Buffer overflow in the IPMI dissector in Wireshark 1.2.0 allows remote attackers to cause a denial of service (crash) via unspecified vectors related to an array index error. NOTE: some of these details are obtained from third party information.

  • CVE-2009-1829May 29, 2009
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in the PCNFSD dissector in Wireshark 0.8.20 through 1.0.7 allows remote attackers to cause a denial of service (crash) via crafted PCNFSD packets.

  • CVE-2009-1266Apr 21, 2009
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in Wireshark before 1.0.7 has unknown impact and attack vectors.

  • CVE-2009-1269Apr 13, 2009
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in Wireshark 0.99.6 through 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted Tektronix .rf5 file.

  • CVE-2009-1268Apr 13, 2009
    risk 0.00cvss —epss 0.02

    The Check Point High-Availability Protocol (CPHAP) dissector in Wireshark 0.9.6 through 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted FWHA_MY_STATE packet.

  • CVE-2009-1267Apr 13, 2009
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in the LDAP dissector in Wireshark 0.99.2 through 1.0.6, when running on Windows, allows remote attackers to cause a denial of service (crash) via unknown attack vectors.

  • CVE-2008-6472Mar 14, 2009
    risk 0.00cvss —epss 0.02

    The WLCCP dissector in Wireshark 0.99.7 through 1.0.4 allows remote attackers to cause a denial of service (infinite loop) via unspecified vectors.

  • CVE-2009-0601Feb 16, 2009
    risk 0.00cvss —epss 0.00

    Format string vulnerability in Wireshark 0.99.8 through 1.0.5 on non-Windows platforms allows local users to cause a denial of service (application crash) via format string specifiers in the HOME environment variable.

  • CVE-2009-0600Feb 16, 2009
    risk 0.00cvss —epss 0.02

    Wireshark 0.99.6 through 1.0.5 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted Tektronix K12 text capture file, as demonstrated by a file with exactly one frame.

  • CVE-2009-0599Feb 16, 2009
    risk 0.00cvss —epss 0.03

    Buffer overflow in wiretap/netscreen.c in Wireshark 0.99.7 through 1.0.5 allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed NetScreen snoop file.

Page 36 of 39