cbcvebase.

Debian Tcpdump vulnerabilities

185 known vulnerabilities affecting debian/tcpdump.

Total CVEs
185
CISA KEV
0
Public exploits
10
Exploited in wild
0
Severity breakdown
CRITICAL132HIGH30MEDIUM17LOW6

Vulnerabilities

Page 9 of 10
CVE-2018-14461P3HIGHCVSS 7.5fixed in tcpdump 4.9.3-1 (bookworm)2018
CVE-2018-14461 [HIGH] CVE-2018-14461: tcpdump - The LDP parser in tcpdump before 4.9.3 has a buffer over-read in print-ldp.c:ldp... The LDP parser in tcpdump before 4.9.3 has a buffer over-read in print-ldp.c:ldp_tlv_print(). Scope: local bookworm: resolved (fixed in 4.9.3-1) bullseye: resolved (fixed in 4.9.3-1) forky: resolved (fixed in 4.9.3-1) sid: resolved (fixed in 4.9.3-1) trixie: resolved (fixed in 4.9.3-1)
debian
CVE-2018-14462P3HIGHCVSS 7.5fixed in tcpdump 4.9.3-1 (bookworm)2018
CVE-2018-14462 [HIGH] CVE-2018-14462: tcpdump - The ICMP parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp.c:i... The ICMP parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp.c:icmp_print(). Scope: local bookworm: resolved (fixed in 4.9.3-1) bullseye: resolved (fixed in 4.9.3-1) forky: resolved (fixed in 4.9.3-1) sid: resolved (fixed in 4.9.3-1) trixie: resolved (fixed in 4.9.3-1)
debian
CVE-2018-14467P3HIGHCVSS 7.5fixed in tcpdump 4.9.3-1 (bookworm)2018
CVE-2018-14467 [HIGH] CVE-2018-14467: tcpdump - The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp... The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_MP). Scope: local bookworm: resolved (fixed in 4.9.3-1) bullseye: resolved (fixed in 4.9.3-1) forky: resolved (fixed in 4.9.3-1) sid: resolved (fixed in 4.9.3-1) trixie: resolved (fixed in 4.9.3-1)
debian
CVE-2018-16230P3HIGHCVSS 7.5fixed in tcpdump 4.9.3-1 (bookworm)2018
CVE-2018-16230 [HIGH] CVE-2018-16230: tcpdump - The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp... The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_attr_print() (MP_REACH_NLRI). Scope: local bookworm: resolved (fixed in 4.9.3-1) bullseye: resolved (fixed in 4.9.3-1) forky: resolved (fixed in 4.9.3-1) sid: resolved (fixed in 4.9.3-1) trixie: resolved (fixed in 4.9.3-1)
debian
CVE-2018-14882P3HIGHCVSS 7.5fixed in tcpdump 4.9.3-1 (bookworm)2018
CVE-2018-14882 [HIGH] CVE-2018-14882: tcpdump - The ICMPv6 parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp6.... The ICMPv6 parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp6.c. Scope: local bookworm: resolved (fixed in 4.9.3-1) bullseye: resolved (fixed in 4.9.3-1) forky: resolved (fixed in 4.9.3-1) sid: resolved (fixed in 4.9.3-1) trixie: resolved (fixed in 4.9.3-1)
debian
CVE-2017-11108P3HIGHCVSS 7.5fixed in tcpdump 4.9.1-1 (bookworm)2017
CVE-2017-11108 [HIGH] CVE-2017-11108: tcpdump - tcpdump 4.9.0 allows remote attackers to cause a denial of service (heap-based b... tcpdump 4.9.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via crafted packet data. The crash occurs in the EXTRACT_16BITS function, called from the stp_print function for the Spanning Tree Protocol. Scope: local bookworm: resolved (fixed in 4.9.1-1) bullseye: resolved (fixed in 4.9.1-1) forky: resolved (fi
debian
CVE-2018-16228P3HIGHCVSS 7.5fixed in tcpdump 4.9.3-1 (bookworm)2018
CVE-2018-16228 [HIGH] CVE-2018-16228: tcpdump - The HNCP parser in tcpdump before 4.9.3 has a buffer over-read in print-hncp.c:p... The HNCP parser in tcpdump before 4.9.3 has a buffer over-read in print-hncp.c:print_prefix(). Scope: local bookworm: resolved (fixed in 4.9.3-1) bullseye: resolved (fixed in 4.9.3-1) forky: resolved (fixed in 4.9.3-1) sid: resolved (fixed in 4.9.3-1) trixie: resolved (fixed in 4.9.3-1)
debian
CVE-2017-12989P4HIGHCVSS 7.5fixed in tcpdump 4.9.2-1 (bookworm)2017
CVE-2017-12989 [HIGH] CVE-2017-12989: tcpdump - The RESP parser in tcpdump before 4.9.2 could enter an infinite loop due to a bu... The RESP parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-resp.c:resp_get_length(). Scope: local bookworm: resolved (fixed in 4.9.2-1) bullseye: resolved (fixed in 4.9.2-1) forky: resolved (fixed in 4.9.2-1) sid: resolved (fixed in 4.9.2-1) trixie: resolved (fixed in 4.9.2-1)
debian
CVE-2018-16301P4LOWCVSS 7.8fixed in tcpdump 4.99.0-1 (bookworm)2018
CVE-2018-16301 [HIGH] CVE-2018-16301: tcpdump - The command-line argument parser in tcpdump before 4.99.0 has a buffer overflow ... The command-line argument parser in tcpdump before 4.99.0 has a buffer overflow in tcpdump.c:read_infile(). To trigger this vulnerability the attacker needs to create a 4GB file on the local filesystem and to specify the file name as the value of the -F command-line argument of tcpdump. Scope: local bookworm: resolved (fixed in 4.99.0-1) bullseye: resolved (fixed in
debian
CVE-2018-14879P4HIGHCVSS 7.0fixed in tcpdump 4.9.3-1 (bookworm)2018
CVE-2018-14879 [HIGH] CVE-2018-14879: tcpdump - The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow i... The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow in tcpdump.c:get_next_file(). Scope: local bookworm: resolved (fixed in 4.9.3-1) bullseye: resolved (fixed in 4.9.3-1) forky: resolved (fixed in 4.9.3-1) sid: resolved (fixed in 4.9.3-1) trixie: resolved (fixed in 4.9.3-1)
debian
CVE-2014-8769P4MEDIUMCVSS 6.4fixed in tcpdump 4.6.2-2 (bookworm)2014
CVE-2014-8769 [MEDIUM] CVE-2014-8769: tcpdump - tcpdump 3.8 through 4.6.2 might allow remote attackers to obtain sensitive infor... tcpdump 3.8 through 4.6.2 might allow remote attackers to obtain sensitive information from memory or cause a denial of service (packet loss or segmentation fault) via a crafted Ad hoc On-Demand Distance Vector (AODV) packet, which triggers an out-of-bounds memory access. Scope: local bookworm: resolved (fixed in 4.6.2-2) bullseye: resolved (fixed in 4.6.2-2) forky:
debian
CVE-2002-0380P4HIGHCVSS 7.5fixed in tcpdump 3.7.1-1.2 (bookworm)2002
CVE-2002-0380 [HIGH] CVE-2002-0380: tcpdump - Buffer overflow in tcpdump 3.6.2 and earlier allows remote attackers to cause a ... Buffer overflow in tcpdump 3.6.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via an NFS packet. Scope: local bookworm: resolved (fixed in 3.7.1-1.2) bullseye: resolved (fixed in 3.7.1-1.2) forky: resolved (fixed in 3.7.1-1.2) sid: resolved (fixed in 3.7.1-1.2) trixie: resolved (fixed in 3.7.1-1.2)
debian
CVE-2007-1218P4LOWCVSS 6.8fixed in tcpdump 3.9.5-2 (bookworm)2007
CVE-2007-1218 [MEDIUM] CVE-2007-1218: tcpdump - Off-by-one buffer overflow in the parse_elements function in the 802.11 printer ... Off-by-one buffer overflow in the parse_elements function in the 802.11 printer code (print-802_11.c) for tcpdump 3.9.5 and earlier allows remote attackers to cause a denial of service (crash) via a crafted 802.11 frame. NOTE: this was originally referred to as heap-based, but it might be stack-based. Scope: local bookworm: resolved (fixed in 3.9.5-2) bullseye: reso
debian
CVE-2023-1801P4LOWCVSS 6.5fixed in tcpdump 4.99.4-2 (forky)2023
CVE-2023-1801 [MEDIUM] CVE-2023-1801: tcpdump - The SMB protocol decoder in tcpdump version 4.99.3 can perform an out-of-bounds ... The SMB protocol decoder in tcpdump version 4.99.3 can perform an out-of-bounds write when decoding a crafted network packet. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 4.99.4-2) sid: resolved (fixed in 4.99.4-2) trixie: resolved (fixed in 4.99.4-2)
debian
CVE-2014-9140P4MEDIUMCVSS 5.0fixed in tcpdump 4.6.2-3 (bookworm)2014
CVE-2014-9140 [MEDIUM] CVE-2014-9140: tcpdump - Buffer overflow in the ppp_hdlc function in print-ppp.c in tcpdump 4.6.2 and ear... Buffer overflow in the ppp_hdlc function in print-ppp.c in tcpdump 4.6.2 and earlier allows remote attackers to cause a denial of service (crash) cia a crafted PPP packet. Scope: local bookworm: resolved (fixed in 4.6.2-3) bullseye: resolved (fixed in 4.6.2-3) forky: resolved (fixed in 4.6.2-3) sid: resolved (fixed in 4.6.2-3) trixie: resolved (fixed in 4.6.2-3)
debian
CVE-2003-0989P4HIGHCVSS 7.5fixed in tcpdump 3.8.1 (bookworm)2003
CVE-2003-0989 [HIGH] CVE-2003-0989: tcpdump - tcpdump before 3.8.1 allows remote attackers to cause a denial of service (infin... tcpdump before 3.8.1 allows remote attackers to cause a denial of service (infinite loop) via certain ISAKMP packets, a different vulnerability than CVE-2004-0057. Scope: local bookworm: resolved (fixed in 3.8.1) bullseye: resolved (fixed in 3.8.1) forky: resolved (fixed in 3.8.1) sid: resolved (fixed in 3.8.1) trixie: resolved (fixed in 3.8.1)
debian
CVE-2015-2154P4MEDIUMCVSS 5.0fixed in tcpdump 4.6.2-4 (bookworm)2015
CVE-2015-2154 [MEDIUM] CVE-2015-2154: tcpdump - The osi_print_cksum function in print-isoclns.c in the ethernet printer in tcpdu... The osi_print_cksum function in print-isoclns.c in the ethernet printer in tcpdump before 4.7.2 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted (1) length, (2) offset, or (3) base pointer checksum value. Scope: local bookworm: resolved (fixed in 4.6.2-4) bullseye: resolved (fixed in 4.6.2-4) forky: resolved (fixed in
debian
CVE-2014-8767P4MEDIUMCVSS 5.0fixed in tcpdump 4.6.2-2 (bookworm)2014
CVE-2014-8767 [MEDIUM] CVE-2014-8767: tcpdump - Integer underflow in the olsr_print function in tcpdump 3.9.6 through 4.6.2, whe... Integer underflow in the olsr_print function in tcpdump 3.9.6 through 4.6.2, when in verbose mode, allows remote attackers to cause a denial of service (crash) via a crafted length value in an OLSR frame. Scope: local bookworm: resolved (fixed in 4.6.2-2) bullseye: resolved (fixed in 4.6.2-2) forky: resolved (fixed in 4.6.2-2) sid: resolved (fixed in 4.6.2-2) trixie
debian
CVE-2017-16808P4LOWCVSS 5.5fixed in tcpdump 4.9.3~git20190901-1 (bookworm)2017
CVE-2017-16808 [MEDIUM] CVE-2017-16808: tcpdump - tcpdump before 4.9.3 has a heap-based buffer over-read related to aoe_print in p... tcpdump before 4.9.3 has a heap-based buffer over-read related to aoe_print in print-aoe.c and lookup_emem in addrtoname.c. Scope: local bookworm: resolved (fixed in 4.9.3~git20190901-1) bullseye: resolved (fixed in 4.9.3~git20190901-1) forky: resolved (fixed in 4.9.3~git20190901-1) sid: resolved (fixed in 4.9.3~git20190901-1) trixie: resolved (fixed in 4.9.3~git2
debian
CVE-2004-0183P4MEDIUMCVSS 5.0fixed in tcpdump 3.7.2-4 (bookworm)2004
CVE-2004-0183 [MEDIUM] CVE-2004-0183: tcpdump - TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (... TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via ISAKMP packets containing a Delete payload with a large number of SPI's, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite. Scope: local bookworm: resolved (fixed in 3.7.2-4) bullseye: resolved (fixed in 3.7.2-4) forky: resolved (fix
debian
Debian Tcpdump vulnerabilities | cvebase