VYPR

Vendor CVEs

Wireshark

All CVEs

777 total · sorted by risk
  • CVE-2023-0666MedJun 7, 2023
    risk 0.42cvss 6.5epss 0.02

    Due to failure in validating the length provided by an attacker-crafted RTPS packet, Wireshark version 4.0.5 and prior, by default, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark.

  • CVE-2020-17498MedAug 13, 2020
    risk 0.42cvss 6.5epss 0.03

    In Wireshark 3.2.0 to 3.2.5, the Kafka protocol dissector could crash. This was addressed in epan/dissectors/packet-kafka.c by avoiding a double free during LZ4 decompression.

  • CVE-2020-7045MedJan 16, 2020
    risk 0.42cvss 6.5epss 0.01

    In Wireshark 3.0.x before 3.0.8, the BT ATT dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by validating opcodes.

  • CVE-2018-5335MedJan 11, 2018
    risk 0.42cvss 6.5epss 0.02

    In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the WCP dissector could crash. This was addressed in epan/dissectors/packet-wcp.c by validating the available buffer length.

  • CVE-2018-5334MedJan 11, 2018
    risk 0.42cvss 6.5epss 0.02

    In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the IxVeriWave file parser could crash. This was addressed in wiretap/vwr.c by correcting the signature timestamp bounds checks.

  • CVE-2017-7700MedApr 12, 2017
    risk 0.42cvss 6.5epss 0.02

    In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the NetScaler file parser could go into an infinite loop, triggered by a malformed capture file. This was addressed in wiretap/netscaler.c by ensuring a nonzero record size.

  • CVE-2016-6512MedAug 6, 2016
    risk 0.42cvss 5.9epss 0.07

    epan/dissectors/packet-wap.c in Wireshark 2.x before 2.0.5 omits an overflow check in the tvb_get_guintvar function, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet, related to the MMSE, WAP, WBXML, and WSP dissectors.

  • CVE-2016-6505MedAug 6, 2016
    risk 0.42cvss 5.9epss 0.07

    epan/dissectors/packet-packetbb.c in the PacketBB dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted packet.

  • CVE-2016-6504MedAug 6, 2016
    risk 0.42cvss 5.9epss 0.06

    epan/dissectors/packet-ncp2222.inc in the NDS dissector in Wireshark 1.12.x before 1.12.13 does not properly maintain a ptvc data structure, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted packet.

  • CVE-2016-6503MedAug 6, 2016
    risk 0.42cvss 5.9epss 0.06

    The CORBA IDL dissectors in Wireshark 2.x before 2.0.5 on 64-bit Windows platforms do not properly interact with Visual C++ compiler options, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

  • CVE-2023-6174MedNov 16, 2023
    risk 0.41cvss 6.3epss 0.01

    SSH dissector crash in Wireshark 4.0.0 to 4.0.10 allows denial of service via packet injection or crafted capture file

  • CVE-2023-2879MedMay 26, 2023
    risk 0.41cvss 6.3epss 0.02

    GDSDB infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or crafted capture file

  • CVE-2023-1994MedApr 12, 2023
    risk 0.41cvss 6.3epss 0.01

    GQUIC dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file

  • CVE-2023-1993MedApr 12, 2023
    risk 0.41cvss 6.3epss 0.04

    LISP dissector large loop in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file

  • CVE-2023-1992MedApr 12, 2023
    risk 0.41cvss 6.3epss 0.05

    RPCoRDMA dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file

  • CVE-2023-1161MedMar 6, 2023
    risk 0.41cvss 6.3epss 0.01

    ISO 15765 and ISO 10681 dissector crash in Wireshark 4.0.0 to 4.0.3 and 3.6.0 to 3.6.11 allows denial of service via packet injection or crafted capture file

  • CVE-2023-0417MedJan 26, 2023
    risk 0.41cvss 6.3epss 0.01

    Memory leak in the NFS dissector in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file

  • CVE-2023-0416MedJan 26, 2023
    risk 0.41cvss 6.3epss 0.01

    GNW dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file

  • CVE-2023-0415MedJan 26, 2023
    risk 0.41cvss 6.3epss 0.01

    iSCSI dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file

  • CVE-2023-0414MedJan 26, 2023
    risk 0.41cvss 6.3epss 0.01

    Crash in the EAP dissector in Wireshark 4.0.0 to 4.0.2 allows denial of service via packet injection or crafted capture file

  • CVE-2023-0413MedJan 26, 2023
    risk 0.41cvss 6.3epss 0.01

    Dissection engine bug in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file

  • CVE-2023-0412MedJan 26, 2023
    risk 0.41cvss 6.3epss 0.01

    TIPC dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file

  • CVE-2023-0411MedJan 26, 2023
    risk 0.41cvss 6.3epss 0.01

    Excessive loops in multiple dissectors in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file

  • CVE-2022-4345MedJan 12, 2023
    risk 0.41cvss 6.3epss 0.01

    Infinite loops in the BPv6, OpenFlow, and Kafka protocol dissectors in Wireshark 4.0.0 to 4.0.1 and 3.6.0 to 3.6.9 allows denial of service via packet injection or crafted capture file

  • CVE-2022-4344MedJan 12, 2023
    risk 0.41cvss 6.3epss 0.01

    Memory exhaustion in the Kafka protocol dissector in Wireshark 4.0.0 to 4.0.1 and 3.6.0 to 3.6.9 allows denial of service via packet injection or crafted capture file

  • CVE-2022-3724MedDec 9, 2022
    risk 0.41cvss 6.3epss 0.02

    Crash in the USB HID protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or crafted capture file on Windows

  • CVE-2022-3725MedOct 27, 2022
    risk 0.41cvss 6.3epss 0.01

    Crash in the OPUS protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or crafted capture file

  • CVE-2022-3190MedSep 13, 2022
    risk 0.41cvss 6.3epss 0.02

    Infinite loop in the F5 Ethernet Trailer protocol dissector in Wireshark 3.6.0 to 3.6.7 and 3.4.0 to 3.4.15 allows denial of service via packet injection or crafted capture file

  • CVE-2022-0586MedFeb 14, 2022
    risk 0.41cvss 6.3epss 0.02

    Infinite loop in RTMPT protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file

  • CVE-2022-0583MedFeb 14, 2022
    risk 0.41cvss 6.3epss 0.02

    Crash in the PVFS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file

  • CVE-2022-0582MedFeb 14, 2022
    risk 0.41cvss 6.3epss 0.02

    Unaligned access in the CSN.1 protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file

  • CVE-2022-0581MedFeb 14, 2022
    risk 0.41cvss 6.3epss 0.02

    Crash in the CMS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file

  • CVE-2021-4186MedDec 30, 2021
    risk 0.41cvss 6.3epss 0.02

    Crash in the Gryphon dissector in Wireshark 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

  • CVE-2021-22191MedMar 15, 2021
    risk 0.41cvss 6.3epss 0.04

    Improper URL handling in Wireshark 3.4.0 to 3.4.3 and 3.2.0 to 3.2.11 could allow remote code execution via via packet injection or crafted capture file.

  • CVE-2026-5656HigMay 1, 2026
    risk 0.39cvss 7.0epss 0.00

    Profile import path traversal in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution

  • CVE-2016-9372MedNov 17, 2016
    risk 0.39cvss 5.9epss 0.02

    In Wireshark 2.2.0 to 2.2.1, the Profinet I/O dissector could loop excessively, triggered by network traffic or a capture file. This was addressed in plugins/profinet/packet-pn-rtc-one.c by rejecting input with too many I/O objects.

  • CVE-2016-7180MedSep 9, 2016
    risk 0.39cvss 5.9epss 0.02

    epan/dissectors/packet-ipmi-trace.c in the IPMI trace dissector in Wireshark 2.x before 2.0.6 does not properly consider whether a string is constant, which allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted packet.

  • CVE-2016-7179MedSep 9, 2016
    risk 0.39cvss 5.9epss 0.03

    Stack-based buffer overflow in epan/dissectors/packet-catapult-dct2000.c in the Catapult DCT2000 dissector in Wireshark 2.x before 2.0.6 allows remote attackers to cause a denial of service (application crash) via a crafted packet.

  • CVE-2016-7178MedSep 9, 2016
    risk 0.39cvss 5.9epss 0.02

    epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 2.x before 2.0.6 does not ensure that memory is allocated for certain data structures, which allows remote attackers to cause a denial of service (invalid write access and application crash) via a crafted…

  • CVE-2016-7177MedSep 9, 2016
    risk 0.39cvss 5.9epss 0.02

    epan/dissectors/packet-catapult-dct2000.c in the Catapult DCT2000 dissector in Wireshark 2.x before 2.0.6 does not restrict the number of channels, which allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet.

  • CVE-2016-7176MedSep 9, 2016
    risk 0.39cvss 5.9epss 0.02

    epan/dissectors/packet-h225.c in the H.225 dissector in Wireshark 2.x before 2.0.6 calls snprintf with one of its input buffers as the output buffer, which allows remote attackers to cause a denial of service (copy overlap and application crash) via a crafted packet.

  • CVE-2016-5359MedAug 7, 2016
    risk 0.39cvss 5.9epss 0.02

    epan/dissectors/packet-wbxml.c in the WBXML dissector in Wireshark 1.12.x before 1.12.12 mishandles offsets, which allows remote attackers to cause a denial of service (integer overflow and infinite loop) via a crafted packet.

  • CVE-2016-5358MedAug 7, 2016
    risk 0.39cvss 5.9epss 0.02

    epan/dissectors/packet-pktap.c in the Ethernet dissector in Wireshark 2.x before 2.0.4 mishandles the packet-header data type, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

  • CVE-2016-5357MedAug 7, 2016
    risk 0.39cvss 5.9epss 0.02

    wiretap/netscreen.c in the NetScreen file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, which allows remote attackers to cause a denial of service (application crash) via a crafted file.

  • CVE-2016-5356MedAug 7, 2016
    risk 0.39cvss 5.9epss 0.02

    wiretap/cosine.c in the CoSine file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, which allows remote attackers to cause a denial of service (application crash) via a crafted file.

  • CVE-2016-5355MedAug 7, 2016
    risk 0.39cvss 5.9epss 0.02

    wiretap/toshiba.c in the Toshiba file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, which allows remote attackers to cause a denial of service (application crash) via a crafted file.

  • CVE-2016-5354MedAug 7, 2016
    risk 0.39cvss 5.9epss 0.03

    The USB subsystem in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles class types, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

  • CVE-2016-5353MedAug 7, 2016
    risk 0.39cvss 5.9epss 0.02

    epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles the reserved C/T value, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

  • CVE-2016-5352MedAug 7, 2016
    risk 0.39cvss 5.9epss 0.03

    epan/crypt/airpdcap.c in the IEEE 802.11 dissector in Wireshark 2.x before 2.0.4 mishandles certain length values, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

  • CVE-2016-5351MedAug 7, 2016
    risk 0.39cvss 5.9epss 0.02

    epan/crypt/airpdcap.c in the IEEE 802.11 dissector in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles the lack of an EAPOL_RSN_KEY, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

Page 5 of 16