VYPR

Vendor CVEs

Wireshark

All CVEs

777 total · sorted by risk
  • CVE-2016-4083MedApr 25, 2016
    risk 0.38cvss 5.9epss 0.02

    epan/dissectors/packet-mswsp.c in the MS-WSP dissector in Wireshark 2.0.x before 2.0.3 does not ensure that data is available before array allocation, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

  • CVE-2016-4076MedApr 25, 2016
    risk 0.38cvss 5.9epss 0.02

    epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 2.0.x before 2.0.3 does not properly initialize memory for search patterns, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

  • CVE-2016-2524MedFeb 28, 2016
    risk 0.38cvss 5.9epss 0.02

    epan/dissectors/packet-x509af.c in the X.509AF dissector in Wireshark 2.0.x before 2.0.2 mishandles the algorithm ID, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

  • CVE-2015-8740MedJan 4, 2016
    risk 0.38cvss 5.3epss 0.07

    The dissect_tds7_colmetadata_token function in epan/dissectors/packet-tds.c in the TDS dissector in Wireshark 2.0.x before 2.0.1 does not validate the number of columns, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application…

  • CVE-2026-76924MedAug 19, 2026
    risk 0.36cvss 5.5epss 0.00

    Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

  • CVE-2026-76923MedAug 19, 2026
    risk 0.36cvss 5.5epss 0.00

    Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

  • CVE-2026-76922MedAug 19, 2026
    risk 0.36cvss 5.5epss 0.00

    Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

  • CVE-2026-76921MedAug 19, 2026
    risk 0.36cvss 5.5epss 0.00

    CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

  • CVE-2026-76918MedAug 19, 2026
    risk 0.36cvss 5.5epss 0.00

    SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

  • CVE-2026-76917MedAug 19, 2026
    risk 0.36cvss 5.5epss 0.00

    Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

  • CVE-2026-9759MedMay 27, 2026
    risk 0.36cvss 5.5epss 0.00

    ROHC protocol dissector crash in Wireshark 4.6.0 to 4.6.5 and 4.4.0 to 4.4.15 allows denial of service

  • CVE-2026-3203MedFeb 25, 2026
    risk 0.36cvss 5.5epss 0.00

    RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service

  • CVE-2026-0961MedJan 14, 2026
    risk 0.36cvss 5.5epss 0.00

    BLF file parser crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service

  • CVE-2025-13946MedDec 3, 2025
    risk 0.36cvss 5.5epss 0.00

    MEGACO dissector infinite loop in Wireshark 4.6.0 to 4.6.1 and 4.4.0 to 4.4.11 allows denial of service

  • CVE-2025-13945MedDec 3, 2025
    risk 0.36cvss 5.5epss 0.00

    HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service

  • CVE-2025-13674MedNov 26, 2025
    risk 0.36cvss 5.5epss 0.00

    BPv7 dissector crash in Wireshark 4.6.0 allows denial of service

  • CVE-2025-11626MedOct 10, 2025
    risk 0.36cvss 5.5epss 0.00

    MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13 allows denial of service

  • CVE-2024-8645MedSep 10, 2024
    risk 0.36cvss 5.5epss 0.00

    SPRT dissector crash in Wireshark 4.2.0 to 4.0.5 and 4.0.0 to 4.0.15 allows denial of service via packet injection or crafted capture file

  • CVE-2021-4183MedDec 30, 2021
    risk 0.36cvss 5.5epss 0.01

    Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file

  • CVE-2021-22207MedApr 23, 2021
    risk 0.36cvss 5.5epss 0.02

    Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of service via packet injection or crafted capture file

  • CVE-2019-9209MedFeb 28, 2019
    risk 0.36cvss 5.5epss 0.01

    In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash. This was addressed in epan/dissectors/packet-ber.c by preventing a buffer overflow associated with excessive digits in time values.

  • CVE-2019-5721MedJan 8, 2019
    risk 0.36cvss 5.5epss 0.01

    In Wireshark 2.4.0 to 2.4.11, the ENIP dissector could crash. This was addressed in epan/dissectors/packet-enip.c by changing the memory-management approach so that a use-after-free is avoided.

  • CVE-2019-5719MedJan 8, 2019
    risk 0.36cvss 5.5epss 0.01

    In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the ISAKMP dissector could crash. This was addressed in epan/dissectors/packet-isakmp.c by properly handling the case of a missing decryption data block.

  • CVE-2019-5718MedJan 8, 2019
    risk 0.36cvss 5.5epss 0.03

    In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the RTSE dissector and other ASN.1 dissectors could crash. This was addressed in epan/charsets.c by adding a get_t61_string length check.

  • CVE-2019-5717MedJan 8, 2019
    risk 0.36cvss 5.5epss 0.02

    In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the P_MUL dissector could crash. This was addressed in epan/dissectors/packet-p_mul.c by rejecting the invalid sequence number of zero.

  • CVE-2019-5716MedJan 8, 2019
    risk 0.36cvss 5.5epss 0.02

    In Wireshark 2.6.0 to 2.6.5, the 6LoWPAN dissector could crash. This was addressed in epan/dissectors/packet-6lowpan.c by avoiding use of a TVB before its creation.

  • CVE-2018-19626MedNov 29, 2018
    risk 0.36cvss 5.5epss 0.03

    In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the DCOM dissector could crash. This was addressed in epan/dissectors/packet-dcom.c by adding '\0' termination.

  • CVE-2018-19625MedNov 29, 2018
    risk 0.36cvss 5.5epss 0.03

    In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the dissection engine could crash. This was addressed in epan/tvbuff_composite.c by preventing a heap-based buffer over-read.

  • CVE-2018-19624MedNov 29, 2018
    risk 0.36cvss 5.5epss 0.03

    In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the PVFS dissector could crash. This was addressed in epan/dissectors/packet-pvfs2.c by preventing a NULL pointer dereference.

  • CVE-2017-9617MedJun 14, 2017
    risk 0.36cvss 5.5epss 0.02

    In Wireshark 2.2.7, deeply nested DAAP data may cause stack exhaustion (uncontrolled recursion) in the dissect_daap_one_tag function in epan/dissectors/packet-daap.c in the DAAP dissector.

  • CVE-2017-9616MedJun 14, 2017
    risk 0.36cvss 5.5epss 0.02

    In Wireshark 2.2.7, overly deep mp4 chunks may cause stack exhaustion (uncontrolled recursion) in the dissect_mp4_box function in epan/dissectors/file-mp4.c.

  • CVE-2016-2529MedFeb 28, 2016
    risk 0.36cvss 5.5epss 0.02

    The iseries_check_file_type function in wiretap/iseries.c in the iSeries file parser in Wireshark 2.0.x before 2.0.2 does not consider that a line may lack the "OBJECT PROTOCOL" substring, which allows remote attackers to cause a denial of service (out-of-bounds read and…

  • CVE-2016-2527MedFeb 28, 2016
    risk 0.36cvss 5.5epss 0.02

    wiretap/nettrace_3gpp_32_423.c in the 3GPP TS 32.423 Trace file parser in Wireshark 2.0.x before 2.0.2 does not ensure that a '\0' character is present at the end of certain strings, which allows remote attackers to cause a denial of service (stack-based buffer overflow and…

  • CVE-2015-8742MedJan 4, 2016
    risk 0.36cvss 5.5epss 0.02

    The dissect_CPMSetBindings function in epan/dissectors/packet-mswsp.c in the MS-WSP dissector in Wireshark 2.0.x before 2.0.1 does not validate the column size, which allows remote attackers to cause a denial of service (memory consumption or application crash) via a crafted…

  • CVE-2015-8741MedJan 4, 2016
    risk 0.36cvss 5.5epss 0.02

    The dissect_ppi function in epan/dissectors/packet-ppi.c in the PPI dissector in Wireshark 2.0.x before 2.0.1 does not initialize a packet-header data structure, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

  • CVE-2015-8738MedJan 4, 2016
    risk 0.36cvss 5.5epss 0.02

    The s7comm_decode_ud_cpu_szl_subfunc function in epan/dissectors/packet-s7comm_szl_ids.c in the S7COMM dissector in Wireshark 2.0.x before 2.0.1 does not validate the list count in an SZL response, which allows remote attackers to cause a denial of service (divide-by-zero error…

  • CVE-2015-8737MedJan 4, 2016
    risk 0.36cvss 5.5epss 0.02

    The mp2t_open function in wiretap/mp2t.c in the MP2T file parser in Wireshark 2.0.x before 2.0.1 does not validate the bit rate, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted file.

  • CVE-2015-8734MedJan 4, 2016
    risk 0.36cvss 5.5epss 0.02

    The dissect_nwp function in epan/dissectors/packet-nwp.c in the NWP dissector in Wireshark 2.0.x before 2.0.1 mishandles the packet type, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

  • CVE-2015-8722MedJan 4, 2016
    risk 0.36cvss 5.5epss 0.03

    epan/dissectors/packet-sctp.c in the SCTP dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the frame pointer, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted packet.

  • CVE-2015-8721MedJan 4, 2016
    risk 0.36cvss 5.5epss 0.03

    Buffer overflow in the tvb_uncompress function in epan/tvbuff_zlib.c in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 allows remote attackers to cause a denial of service (application crash) via a crafted packet with zlib compression.

  • CVE-2015-8720MedJan 4, 2016
    risk 0.36cvss 5.5epss 0.02

    The dissect_ber_GeneralizedTime function in epan/dissectors/packet-ber.c in the BER dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 improperly checks an sscanf return value, which allows remote attackers to cause a denial of service (application crash) via a…

  • CVE-2015-8719MedJan 4, 2016
    risk 0.36cvss 5.5epss 0.03

    The dissect_dns_answer function in epan/dissectors/packet-dns.c in the DNS dissector in Wireshark 1.12.x before 1.12.9 mishandles the EDNS0 Client Subnet option, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

  • CVE-2015-8718MedJan 4, 2016
    risk 0.36cvss 5.5epss 0.02

    Double free vulnerability in epan/dissectors/packet-nlm.c in the NLM dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1, when the "Match MSG/RES packets for async NLM" option is enabled, allows remote attackers to cause a denial of service (application crash) via…

  • CVE-2015-8717MedJan 4, 2016
    risk 0.36cvss 5.5epss 0.03

    The dissect_sdp function in epan/dissectors/packet-sdp.c in the SDP dissector in Wireshark 1.12.x before 1.12.9 does not prevent use of a negative media count, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

  • CVE-2015-8716MedJan 4, 2016
    risk 0.36cvss 5.5epss 0.03

    The init_t38_info_conv function in epan/dissectors/packet-t38.c in the T.38 dissector in Wireshark 1.12.x before 1.12.9 does not ensure that a conversation exists, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

  • CVE-2015-8715MedJan 4, 2016
    risk 0.36cvss 5.5epss 0.03

    epan/dissectors/packet-alljoyn.c in the AllJoyn dissector in Wireshark 1.12.x before 1.12.9 does not check for empty arguments, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.

  • CVE-2015-8714MedJan 4, 2016
    risk 0.36cvss 5.5epss 0.03

    The dissect_dcom_OBJREF function in epan/dissectors/packet-dcom.c in the DCOM dissector in Wireshark 1.12.x before 1.12.9 does not initialize a certain IPv4 data structure, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

  • CVE-2015-8713MedJan 4, 2016
    risk 0.36cvss 5.5epss 0.05

    epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 1.12.x before 1.12.9 does not properly reserve memory for channel ID mappings, which allows remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted…

  • CVE-2015-8712MedJan 4, 2016
    risk 0.36cvss 5.5epss 0.03

    The dissect_hsdsch_channel_info function in epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 1.12.x before 1.12.9 does not validate the number of PDUs, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

  • CVE-2015-8711MedJan 4, 2016
    risk 0.36cvss 5.5epss 0.03

    epan/dissectors/packet-nbap.c in the NBAP dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate conversation data, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted packet.

Page 7 of 16