Wireshark
Wireshark is free and open-source packet analyzer software. It is used for computer network analysis and troubleshooting, software and communications protocol development, and education. Originally named Ethereal, the project was renamed Wireshark in May 2006 due to trademark issues.
Products
3- 752 CVEs
- 4 CVEs
- 3 CVEs
Recent CVEs
752| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-6836 | Cri | 0.64 | 9.8 | 0.03 | Feb 8, 2018 | The netmonrec_comment_destroy function in wiretap/netmon.c in Wireshark through 2.4.4 performs a free operation on an uninitialized memory address, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact. | ||
| CVE-2018-19627 | Hig | 0.53 | 7.5 | 0.18 | Nov 29, 2018 | In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the IxVeriWave file parser could crash. This was addressed in wiretap/vwr.c by adjusting a buffer boundary. | ||
| CVE-2017-17085 | Hig | 0.53 | 7.5 | 0.17 | Dec 1, 2017 | In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the CIP Safety dissector could crash. This was addressed in epan/dissectors/packet-cipsafety.c by validating the packet length. | ||
| CVE-2017-9353 | Hig | 0.53 | 7.5 | 0.14 | Jun 2, 2017 | In Wireshark 2.2.0 to 2.2.6, the IPv6 dissector could crash. This was addressed in epan/dissectors/packet-ipv6.c by validating an IPv6 address. | ||
| CVE-2017-9347 | Hig | 0.53 | 7.5 | 0.14 | Jun 2, 2017 | In Wireshark 2.2.0 to 2.2.6, the ROS dissector could crash with a NULL pointer dereference. This was addressed in epan/dissectors/asn1/ros/packet-ros-template.c by validating an OID. | ||
| CVE-2025-13499 | Hig | 0.51 | 7.8 | 0.00 | Nov 21, 2025 | Kafka dissector crash in Wireshark 4.6.0 and 4.4.0 to 4.4.10 allows denial of service | ||
| CVE-2025-9817 | Hig | 0.51 | 7.8 | 0.00 | Sep 3, 2025 | SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial of service | ||
| CVE-2025-5601 | Hig | 0.51 | 7.8 | 0.00 | Jun 4, 2025 | Column handling crashes in Wireshark 4.4.0 to 4.4.6 and 4.2.0 to 4.2.12 allows denial of service via packet injection or crafted capture file | ||
| CVE-2025-1492 | Hig | 0.51 | 7.8 | 0.00 | Feb 20, 2025 | Bundle Protocol and CBOR dissector crashes in Wireshark 4.4.0 to 4.4.3 and 4.2.0 to 4.2.10 allows denial of service via packet injection or crafted capture file | ||
| CVE-2024-11596 | Hig | 0.51 | 7.8 | 0.00 | Nov 21, 2024 | ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file | ||
| CVE-2024-11595 | Hig | 0.51 | 7.8 | 0.00 | Nov 21, 2024 | FiveCo RAP dissector infinite loop in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file | ||
| CVE-2024-9781 | Hig | 0.51 | 7.8 | 0.00 | Oct 10, 2024 | AppleTalk and RELOAD Framing dissector crash in Wireshark 4.4.0 and 4.2.0 to 4.2.7 allows denial of service via packet injection or crafted capture file | ||
| CVE-2024-9780 | Hig | 0.51 | 7.8 | 0.00 | Oct 10, 2024 | ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capture file | ||
| CVE-2024-8250 | Hig | 0.51 | 7.8 | 0.00 | Aug 29, 2024 | NTLMSSP dissector crash in Wireshark 4.2.0 to 4.0.6 and 4.0.0 to 4.0.16 allows denial of service via packet injection or crafted capture file | ||
| CVE-2023-6175 | Hig | 0.51 | 7.8 | 0.03 | Mar 26, 2024 | NetScreen file parser crash in Wireshark 4.0.0 to 4.0.10 and 3.6.0 to 3.6.18 allows denial of service via crafted capture file | ||
| CVE-2024-0211 | Hig | 0.51 | 7.8 | 0.01 | Jan 3, 2024 | DOCSIS dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file | ||
| CVE-2024-0210 | Hig | 0.51 | 7.8 | 0.00 | Jan 3, 2024 | Zigbee TLV dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file | ||
| CVE-2024-0209 | Hig | 0.51 | 7.8 | 0.01 | Jan 3, 2024 | IEEE 1609.2 dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture file | ||
| CVE-2024-0208 | Hig | 0.51 | 7.8 | 0.02 | Jan 3, 2024 | GVCP dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture file | ||
| CVE-2024-0207 | Hig | 0.51 | 7.8 | 0.00 | Jan 3, 2024 | HTTP3 dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file |
- risk 0.64cvss 9.8epss 0.03
The netmonrec_comment_destroy function in wiretap/netmon.c in Wireshark through 2.4.4 performs a free operation on an uninitialized memory address, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
- risk 0.53cvss 7.5epss 0.18
In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the IxVeriWave file parser could crash. This was addressed in wiretap/vwr.c by adjusting a buffer boundary.
- risk 0.53cvss 7.5epss 0.17
In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the CIP Safety dissector could crash. This was addressed in epan/dissectors/packet-cipsafety.c by validating the packet length.
- risk 0.53cvss 7.5epss 0.14
In Wireshark 2.2.0 to 2.2.6, the IPv6 dissector could crash. This was addressed in epan/dissectors/packet-ipv6.c by validating an IPv6 address.
- risk 0.53cvss 7.5epss 0.14
In Wireshark 2.2.0 to 2.2.6, the ROS dissector could crash with a NULL pointer dereference. This was addressed in epan/dissectors/asn1/ros/packet-ros-template.c by validating an OID.
- risk 0.51cvss 7.8epss 0.00
Kafka dissector crash in Wireshark 4.6.0 and 4.4.0 to 4.4.10 allows denial of service
- risk 0.51cvss 7.8epss 0.00
SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial of service
- risk 0.51cvss 7.8epss 0.00
Column handling crashes in Wireshark 4.4.0 to 4.4.6 and 4.2.0 to 4.2.12 allows denial of service via packet injection or crafted capture file
- risk 0.51cvss 7.8epss 0.00
Bundle Protocol and CBOR dissector crashes in Wireshark 4.4.0 to 4.4.3 and 4.2.0 to 4.2.10 allows denial of service via packet injection or crafted capture file
- risk 0.51cvss 7.8epss 0.00
ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file
- risk 0.51cvss 7.8epss 0.00
FiveCo RAP dissector infinite loop in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file
- risk 0.51cvss 7.8epss 0.00
AppleTalk and RELOAD Framing dissector crash in Wireshark 4.4.0 and 4.2.0 to 4.2.7 allows denial of service via packet injection or crafted capture file
- risk 0.51cvss 7.8epss 0.00
ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capture file
- risk 0.51cvss 7.8epss 0.00
NTLMSSP dissector crash in Wireshark 4.2.0 to 4.0.6 and 4.0.0 to 4.0.16 allows denial of service via packet injection or crafted capture file
- risk 0.51cvss 7.8epss 0.03
NetScreen file parser crash in Wireshark 4.0.0 to 4.0.10 and 3.6.0 to 3.6.18 allows denial of service via crafted capture file
- risk 0.51cvss 7.8epss 0.01
DOCSIS dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file
- risk 0.51cvss 7.8epss 0.00
Zigbee TLV dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file
- risk 0.51cvss 7.8epss 0.01
IEEE 1609.2 dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture file
- risk 0.51cvss 7.8epss 0.02
GVCP dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture file
- risk 0.51cvss 7.8epss 0.00
HTTP3 dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file