Vendor CVEs
Wireshark
All CVEs
777 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2015-3182 | Med | 0.36 | 5.5 | 0.02 | Jan 4, 2016 | epan/dissectors/packet-dec-dnart.c in the DECnet NSP/RT dissector in Wireshark 1.10.12 through 1.10.14 mishandles a certain strdup return value, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. | ||
| CVE-2026-15167 | Hig | 0.35 | 7.5 | 0.00 | Jul 8, 2026 | DBS Etherwatch file parser crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service | ||
| CVE-2026-15165 | Med | 0.35 | 5.5 | 0.00 | Jul 8, 2026 | TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of service | ||
| CVE-2024-4854 | Med | 0.35 | 6.4 | 0.01 | May 14, 2024 | MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet injection or crafted capture file | ||
| CVE-2023-2952 | Med | 0.35 | 5.3 | 0.01 | May 30, 2023 | XRA dissector infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or crafted capture file | ||
| CVE-2023-2858 | Med | 0.35 | 5.3 | 0.02 | May 26, 2023 | NetScaler file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file | ||
| CVE-2023-2857 | Med | 0.35 | 5.3 | 0.01 | May 26, 2023 | BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file | ||
| CVE-2023-2856 | Med | 0.35 | 5.3 | 0.02 | May 26, 2023 | VMS TCPIPtrace file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file | ||
| CVE-2023-2855 | Med | 0.35 | 5.3 | 0.02 | May 26, 2023 | Candump log parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file | ||
| CVE-2023-2854 | Med | 0.35 | 5.3 | 0.01 | May 26, 2023 | BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file | ||
| CVE-2026-76919 | Med | 0.34 | 5.3 | 0.00 | Aug 19, 2026 | ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | ||
| CVE-2026-0962 | Med | 0.34 | 5.3 | 0.00 | Jan 14, 2026 | SOME/IP-SD protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service | ||
| CVE-2026-0959 | Med | 0.34 | 5.3 | 0.00 | Jan 14, 2026 | IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service | ||
| CVE-2023-5371 | Med | 0.34 | 5.3 | 0.00 | Oct 4, 2023 | RTPS dissector memory leak in Wireshark 4.0.0 to 4.0.8 and 3.6.0 to 3.6.16 allows denial of service via packet injection or crafted capture file | ||
| CVE-2023-4513 | Med | 0.34 | 5.3 | 0.01 | Aug 24, 2023 | BT SDP dissector memory leak in Wireshark 4.0.0 to 4.0.7 and 3.6.0 to 3.6.15 allows denial of service via packet injection or crafted capture file | ||
| CVE-2023-4512 | Med | 0.34 | 5.3 | 0.01 | Aug 24, 2023 | CBOR dissector crash in Wireshark 4.0.0 to 4.0.6 allows denial of service via packet injection or crafted capture file | ||
| CVE-2023-4511 | Med | 0.34 | 5.3 | 0.00 | Aug 24, 2023 | BT SDP dissector infinite loop in Wireshark 4.0.0 to 4.0.7 and 3.6.0 to 3.6.15 allows denial of service via packet injection or crafted capture file | ||
| CVE-2023-3649 | Med | 0.34 | 5.3 | 0.00 | Jul 14, 2023 | iSCSI dissector crash in Wireshark 4.0.0 to 4.0.6 allows denial of service via packet injection or crafted capture file | ||
| CVE-2023-3648 | Med | 0.34 | 5.3 | 0.00 | Jul 14, 2023 | Kafka dissector crash in Wireshark 4.0.0 to 4.0.6 and 3.6.0 to 3.6.14 allows denial of service via packet injection or crafted capture file | ||
| CVE-2026-76929 | Med | 0.31 | 4.7 | 0.00 | Aug 19, 2026 | Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | ||
| CVE-2026-76927 | Med | 0.31 | 4.7 | 0.00 | Aug 19, 2026 | H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | ||
| CVE-2026-76920 | Med | 0.31 | 4.7 | 0.00 | Aug 19, 2026 | 3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | ||
| CVE-2026-76889 | Med | 0.31 | 4.7 | 0.00 | Aug 19, 2026 | UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | ||
| CVE-2026-76882 | Med | 0.31 | 4.7 | 0.00 | Aug 19, 2026 | Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | ||
| CVE-2026-76881 | Med | 0.31 | 4.7 | 0.00 | Aug 19, 2026 | CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | ||
| CVE-2026-19695 | Med | 0.31 | 4.7 | 0.00 | Aug 13, 2026 | Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows denial of service | ||
| CVE-2026-19694 | Med | 0.31 | 4.7 | 0.00 | Aug 13, 2026 | TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial of service | ||
| CVE-2026-3202 | Med | 0.31 | 4.7 | 0.00 | Feb 25, 2026 | NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of service | ||
| CVE-2026-3201 | Med | 0.31 | 4.7 | 0.00 | Feb 25, 2026 | USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service | ||
| CVE-2026-0960 | Med | 0.31 | 4.7 | 0.00 | Jan 14, 2026 | HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of service | ||
| CVE-2026-15166 | Med | 0.30 | 5.5 | 0.00 | Jul 8, 2026 | IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service | ||
| CVE-2026-15174 | Med | 0.29 | 5.5 | 0.00 | Jul 8, 2026 | Catapult DCT2000 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service | ||
| CVE-2026-15172 | Med | 0.29 | 5.5 | 0.00 | Jul 8, 2026 | FMP/NOTIFY protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service | ||
| CVE-2026-15171 | Med | 0.29 | 5.5 | 0.00 | Jul 8, 2026 | SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service | ||
| CVE-2026-15170 | Med | 0.29 | 5.5 | 0.00 | Jul 8, 2026 | Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service | ||
| CVE-2026-15169 | Med | 0.29 | 5.5 | 0.00 | Jul 8, 2026 | UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service | ||
| CVE-2026-15164 | Med | 0.29 | 5.5 | 0.00 | Jul 8, 2026 | Crash in ciscodump 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service | ||
| CVE-2026-15163 | Med | 0.29 | 5.5 | 0.00 | Jul 8, 2026 | Multiple protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allow denial of service | ||
| CVE-2026-6525 | Med | 0.29 | 5.5 | 0.00 | May 2, 2026 | IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.4 | ||
| CVE-2026-6870 | Med | 0.29 | 5.5 | 0.00 | Apr 30, 2026 | GSM RP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service | ||
| CVE-2026-6869 | Med | 0.29 | 5.5 | 0.00 | Apr 30, 2026 | WebSocket protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service | ||
| CVE-2026-6867 | Med | 0.29 | 5.5 | 0.00 | Apr 30, 2026 | SMB2 protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service | ||
| CVE-2026-6538 | Med | 0.29 | 5.5 | 0.00 | Apr 30, 2026 | BEEP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service | ||
| CVE-2026-6537 | Med | 0.29 | 5.5 | 0.00 | Apr 30, 2026 | ZigBee protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service | ||
| CVE-2026-6536 | Med | 0.29 | 5.5 | 0.00 | Apr 30, 2026 | DLMS/COSEM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 | ||
| CVE-2026-6535 | Med | 0.29 | 5.5 | 0.00 | Apr 30, 2026 | Dissection engine zlib decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service | ||
| CVE-2026-6534 | Med | 0.29 | 5.5 | 0.00 | Apr 30, 2026 | USB HID protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service | ||
| CVE-2026-6533 | Med | 0.29 | 5.5 | 0.00 | Apr 30, 2026 | Dissection engine LZ77 decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service | ||
| CVE-2026-6532 | Med | 0.29 | 5.5 | 0.00 | Apr 30, 2026 | Kismet protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service | ||
| CVE-2026-6531 | Med | 0.29 | 5.5 | 0.00 | Apr 30, 2026 | SANE protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service |
- risk 0.36cvss 5.5epss 0.02
epan/dissectors/packet-dec-dnart.c in the DECnet NSP/RT dissector in Wireshark 1.10.12 through 1.10.14 mishandles a certain strdup return value, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
- risk 0.35cvss 7.5epss 0.00
DBS Etherwatch file parser crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
- risk 0.35cvss 5.5epss 0.00
TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of service
- risk 0.35cvss 6.4epss 0.01
MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet injection or crafted capture file
- risk 0.35cvss 5.3epss 0.01
XRA dissector infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or crafted capture file
- risk 0.35cvss 5.3epss 0.02
NetScaler file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
- risk 0.35cvss 5.3epss 0.01
BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
- risk 0.35cvss 5.3epss 0.02
VMS TCPIPtrace file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
- risk 0.35cvss 5.3epss 0.02
Candump log parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
- risk 0.35cvss 5.3epss 0.01
BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
- risk 0.34cvss 5.3epss 0.00
ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- risk 0.34cvss 5.3epss 0.00
SOME/IP-SD protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
- risk 0.34cvss 5.3epss 0.00
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
- risk 0.34cvss 5.3epss 0.00
RTPS dissector memory leak in Wireshark 4.0.0 to 4.0.8 and 3.6.0 to 3.6.16 allows denial of service via packet injection or crafted capture file
- risk 0.34cvss 5.3epss 0.01
BT SDP dissector memory leak in Wireshark 4.0.0 to 4.0.7 and 3.6.0 to 3.6.15 allows denial of service via packet injection or crafted capture file
- risk 0.34cvss 5.3epss 0.01
CBOR dissector crash in Wireshark 4.0.0 to 4.0.6 allows denial of service via packet injection or crafted capture file
- risk 0.34cvss 5.3epss 0.00
BT SDP dissector infinite loop in Wireshark 4.0.0 to 4.0.7 and 3.6.0 to 3.6.15 allows denial of service via packet injection or crafted capture file
- risk 0.34cvss 5.3epss 0.00
iSCSI dissector crash in Wireshark 4.0.0 to 4.0.6 allows denial of service via packet injection or crafted capture file
- risk 0.34cvss 5.3epss 0.00
Kafka dissector crash in Wireshark 4.0.0 to 4.0.6 and 3.6.0 to 3.6.14 allows denial of service via packet injection or crafted capture file
- risk 0.31cvss 4.7epss 0.00
Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- risk 0.31cvss 4.7epss 0.00
H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- risk 0.31cvss 4.7epss 0.00
3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- risk 0.31cvss 4.7epss 0.00
UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- risk 0.31cvss 4.7epss 0.00
Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- risk 0.31cvss 4.7epss 0.00
CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- risk 0.31cvss 4.7epss 0.00
Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows denial of service
- risk 0.31cvss 4.7epss 0.00
TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial of service
- risk 0.31cvss 4.7epss 0.00
NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of service
- risk 0.31cvss 4.7epss 0.00
USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
- risk 0.31cvss 4.7epss 0.00
HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of service
- risk 0.30cvss 5.5epss 0.00
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
- risk 0.29cvss 5.5epss 0.00
Catapult DCT2000 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
- risk 0.29cvss 5.5epss 0.00
FMP/NOTIFY protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
- risk 0.29cvss 5.5epss 0.00
SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
- risk 0.29cvss 5.5epss 0.00
Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
- risk 0.29cvss 5.5epss 0.00
UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
- risk 0.29cvss 5.5epss 0.00
Crash in ciscodump 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
- risk 0.29cvss 5.5epss 0.00
Multiple protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allow denial of service
- risk 0.29cvss 5.5epss 0.00
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.4
- risk 0.29cvss 5.5epss 0.00
GSM RP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
- risk 0.29cvss 5.5epss 0.00
WebSocket protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
- risk 0.29cvss 5.5epss 0.00
SMB2 protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
- risk 0.29cvss 5.5epss 0.00
BEEP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
- risk 0.29cvss 5.5epss 0.00
ZigBee protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
- risk 0.29cvss 5.5epss 0.00
DLMS/COSEM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4
- risk 0.29cvss 5.5epss 0.00
Dissection engine zlib decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
- risk 0.29cvss 5.5epss 0.00
USB HID protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
- risk 0.29cvss 5.5epss 0.00
Dissection engine LZ77 decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
- risk 0.29cvss 5.5epss 0.00
Kismet protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
- risk 0.29cvss 5.5epss 0.00
SANE protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Page 8 of 16