CVE-2006-1937

6 documents5 sources
Severity
5.0MEDIUM
EPSS
3.8%
top 11.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 25
Latest updateMay 3

Description

Multiple unspecified vulnerabilities in Ethereal 0.10.x up to 0.10.14 allow remote attackers to cause a denial of service (crash from null dereference) via (1) multiple vectors in H.248, and the (2) X.509if, (3) SRVLOC, (4) H.245, (5) AIM, and (6) general packet dissectors; and (7) the statistics counter.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDethereal_group/ethereal16 versions+15

Patches

🔴Vulnerability Details

2
GHSA
GHSA-g6hg-gvcc-35fg: Multiple unspecified vulnerabilities in Ethereal 02022-05-03
CVEList
CVE-2006-1937: Multiple unspecified vulnerabilities in Ethereal 02006-04-25

📋Vendor Advisories

1
Red Hat
security flaw2006-04-24

💬Community

2
Bugzilla
CVE-2006-1937 security flaw2018-08-16
Bugzilla
CVE-2006-1932 Multiple ethereal issues (CVE-2006-1933, CVE-2006-1934, CVE-2006-1935, CVE-2006-1936, CVE-2006-1937, CVE-2006-1938, CVE-2006-1939, CVE-2006-1940, VE-2006-4805, CVE-2006-5468, CVE-2006-542006-05-12