VYPR

Vendor CVEs

Wireshark

All CVEs

777 total · sorted by risk
  • CVE-2018-6836CriFeb 8, 2018
    risk 0.64cvss 9.8epss 0.03

    The netmonrec_comment_destroy function in wiretap/netmon.c in Wireshark through 2.4.4 performs a free operation on an uninitialized memory address, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

  • CVE-2026-76886HigAug 19, 2026
    risk 0.53cvss 8.1epss 0.00

    C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

  • CVE-2018-19627HigNov 29, 2018
    risk 0.53cvss 7.5epss 0.18

    In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the IxVeriWave file parser could crash. This was addressed in wiretap/vwr.c by adjusting a buffer boundary.

  • CVE-2017-17085HigDec 1, 2017
    risk 0.53cvss 7.5epss 0.17

    In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the CIP Safety dissector could crash. This was addressed in epan/dissectors/packet-cipsafety.c by validating the packet length.

  • CVE-2017-9353HigJun 2, 2017
    risk 0.53cvss 7.5epss 0.14

    In Wireshark 2.2.0 to 2.2.6, the IPv6 dissector could crash. This was addressed in epan/dissectors/packet-ipv6.c by validating an IPv6 address.

  • CVE-2017-9347HigJun 2, 2017
    risk 0.53cvss 7.5epss 0.14

    In Wireshark 2.2.0 to 2.2.6, the ROS dissector could crash with a NULL pointer dereference. This was addressed in epan/dissectors/asn1/ros/packet-ros-template.c by validating an OID.

  • CVE-2025-13499HigNov 21, 2025
    risk 0.51cvss 7.8epss 0.00

    Kafka dissector crash in Wireshark 4.6.0 and 4.4.0 to 4.4.10 allows denial of service

  • CVE-2025-9817HigSep 3, 2025
    risk 0.51cvss 7.8epss 0.00

    SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial of service

  • CVE-2025-5601HigJun 4, 2025
    risk 0.51cvss 7.8epss 0.00

    Column handling crashes in Wireshark 4.4.0 to 4.4.6 and 4.2.0 to 4.2.12 allows denial of service via packet injection or crafted capture file

  • CVE-2025-1492HigFeb 20, 2025
    risk 0.51cvss 7.8epss 0.00

    Bundle Protocol and CBOR dissector crashes in Wireshark 4.4.0 to 4.4.3 and 4.2.0 to 4.2.10 allows denial of service via packet injection or crafted capture file

  • CVE-2024-11596HigNov 21, 2024
    risk 0.51cvss 7.8epss 0.00

    ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file

  • CVE-2024-11595HigNov 21, 2024
    risk 0.51cvss 7.8epss 0.00

    FiveCo RAP dissector infinite loop in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file

  • CVE-2024-9781HigOct 10, 2024
    risk 0.51cvss 7.8epss 0.00

    AppleTalk and RELOAD Framing dissector crash in Wireshark 4.4.0 and 4.2.0 to 4.2.7 allows denial of service via packet injection or crafted capture file

  • CVE-2024-9780HigOct 10, 2024
    risk 0.51cvss 7.8epss 0.00

    ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capture file

  • CVE-2024-8250HigAug 29, 2024
    risk 0.51cvss 7.8epss 0.00

    NTLMSSP dissector crash in Wireshark 4.2.0 to 4.0.6 and 4.0.0 to 4.0.16 allows denial of service via packet injection or crafted capture file

  • CVE-2023-6175HigMar 26, 2024
    risk 0.51cvss 7.8epss 0.03

    NetScreen file parser crash in Wireshark 4.0.0 to 4.0.10 and 3.6.0 to 3.6.18 allows denial of service via crafted capture file

  • CVE-2024-0211HigJan 3, 2024
    risk 0.51cvss 7.8epss 0.01

    DOCSIS dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file

  • CVE-2024-0210HigJan 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Zigbee TLV dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file

  • CVE-2024-0209HigJan 3, 2024
    risk 0.51cvss 7.8epss 0.01

    IEEE 1609.2 dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture file

  • CVE-2024-0208HigJan 3, 2024
    risk 0.51cvss 7.8epss 0.02

    GVCP dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture file

  • CVE-2024-0207HigJan 3, 2024
    risk 0.51cvss 7.8epss 0.00

    HTTP3 dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file

  • CVE-2016-2521HigFeb 28, 2016
    risk 0.51cvss 7.8epss 0.00

    Untrusted search path vulnerability in the WiresharkApplication class in ui/qt/wireshark_application.cpp in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 on Windows allows local users to gain privileges via a Trojan horse riched20.dll.dll file in the current working…

  • CVE-2026-5402HigApr 30, 2026
    risk 0.50cvss 8.8epss 0.01

    TLS protocol dissector heap overflow in Wireshark 4.6.0 to 4.6.4 allows denial of service and possible code execution

  • CVE-2026-76928HigAug 19, 2026
    risk 0.49cvss 7.5epss 0.00

    X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

  • CVE-2026-76880HigAug 19, 2026
    risk 0.49cvss 7.5epss 0.00

    RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

  • CVE-2026-76879HigAug 19, 2026
    risk 0.49cvss 7.5epss 0.00

    C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

  • CVE-2021-4190HigDec 30, 2021
    risk 0.49cvss 7.5epss 0.03

    Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service via packet injection or crafted capture file

  • CVE-2021-4185HigDec 30, 2021
    risk 0.49cvss 7.5epss 0.04

    Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

  • CVE-2021-4184HigDec 30, 2021
    risk 0.49cvss 7.5epss 0.04

    Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

  • CVE-2021-4182HigDec 30, 2021
    risk 0.49cvss 7.5epss 0.03

    Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

  • CVE-2021-4181HigDec 30, 2021
    risk 0.49cvss 7.5epss 0.04

    Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

  • CVE-2021-39929HigNov 19, 2021
    risk 0.49cvss 7.5epss 0.04

    Uncontrolled Recursion in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file

  • CVE-2021-39926HigNov 19, 2021
    risk 0.49cvss 7.5epss 0.08

    Buffer overflow in the Bluetooth HCI_ISO dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file

  • CVE-2021-39925HigNov 19, 2021
    risk 0.49cvss 7.5epss 0.08

    Buffer overflow in the Bluetooth SDP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file

  • CVE-2021-39924HigNov 19, 2021
    risk 0.49cvss 7.5epss 0.05

    Large loop in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file

  • CVE-2021-39923HigNov 19, 2021
    risk 0.49cvss 7.5epss 0.02

    Large loop in the PNRP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file

  • CVE-2021-39922HigNov 19, 2021
    risk 0.49cvss 7.5epss 0.05

    Buffer overflow in the C12.22 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file

  • CVE-2021-39921HigNov 19, 2021
    risk 0.49cvss 7.5epss 0.03

    NULL pointer exception in the Modbus dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file

  • CVE-2021-39928HigNov 18, 2021
    risk 0.49cvss 7.5epss 0.06

    NULL pointer exception in the IEEE 802.11 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file

  • CVE-2021-39920HigNov 18, 2021
    risk 0.49cvss 7.5epss 0.03

    NULL pointer exception in the IPPUSB dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file

  • CVE-2021-22235HigJul 20, 2021
    risk 0.49cvss 7.5epss 0.03

    Crash in DNP dissector in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 allows denial of service via packet injection or crafted capture file

  • CVE-2021-22222HigJun 7, 2021
    risk 0.49cvss 7.5epss 0.02

    Infinite loop in DVB-S2-BB dissector in Wireshark 3.4.0 to 3.4.5 allows denial of service via packet injection or crafted capture file

  • CVE-2020-15466HigJul 5, 2020
    risk 0.49cvss 7.5epss 0.03

    In Wireshark 3.2.0 to 3.2.4, the GVCP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-gvcp.c by ensuring that an offset increases in all situations.

  • CVE-2020-13164HigMay 19, 2020
    risk 0.49cvss 7.5epss 0.03

    In Wireshark 3.2.0 to 3.2.3, 3.0.0 to 3.0.10, and 2.6.0 to 2.6.16, the NFS dissector could crash. This was addressed in epan/dissectors/packet-nfs.c by preventing excessive recursion, such as for a cycle in the directory graph on a filesystem.

  • CVE-2020-11647HigApr 10, 2020
    risk 0.49cvss 7.5epss 0.03

    In Wireshark 3.2.0 to 3.2.2, 3.0.0 to 3.0.9, and 2.6.0 to 2.6.15, the BACapp dissector could crash. This was addressed in epan/dissectors/packet-bacapp.c by limiting the amount of recursion.

  • CVE-2020-9431HigFeb 27, 2020
    risk 0.49cvss 7.5epss 0.03

    In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the LTE RRC dissector could leak memory. This was addressed in epan/dissectors/packet-lte-rrc.c by adjusting certain append operations.

  • CVE-2020-9430HigFeb 27, 2020
    risk 0.49cvss 7.5epss 0.03

    In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the WiMax DLMAP dissector could crash. This was addressed in plugins/epan/wimax/msg_dlmap.c by validating a length field.

  • CVE-2020-9429HigFeb 27, 2020
    risk 0.49cvss 7.5epss 0.02

    In Wireshark 3.2.0 to 3.2.1, the WireGuard dissector could crash. This was addressed in epan/dissectors/packet-wireguard.c by handling the situation where a certain data structure intentionally has a NULL value.

  • CVE-2020-9428HigFeb 27, 2020
    risk 0.49cvss 7.5epss 0.03

    In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the EAP dissector could crash. This was addressed in epan/dissectors/packet-eap.c by using more careful sscanf parsing.

  • CVE-2020-7044HigJan 16, 2020
    risk 0.49cvss 7.5epss 0.03

    In Wireshark 3.2.x before 3.2.1, the WASSP dissector could crash. This was addressed in epan/dissectors/packet-wassp.c by using >= and <= to resolve off-by-one errors.

Page 1 of 16