cbcvebase.

Debian Wireshark vulnerabilities

668 known vulnerabilities affecting debian/wireshark.

Total CVEs
668
CISA KEV
0
Public exploits
50
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH129MEDIUM276LOW255

Vulnerabilities

Page 13 of 34
CVE-2023-0668P4MEDIUMCVSS 6.5fixed in wireshark 4.0.6-1~deb12u1 (bookworm)2023
CVE-2023-0668 [MEDIUM] CVE-2023-0668: wireshark - Due to failure in validating the length provided by an attacker-crafted IEEE-C37... Due to failure in validating the length provided by an attacker-crafted IEEE-C37.118 packet, Wireshark version 4.0.5 and prior, by default, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark. Scope: local bookworm: resolved (fixed in 4.0.6-1~deb12u1) bullseye: resolved (fixed in 3.4.16-0+deb1
debian
CVE-2023-0666P3MEDIUMCVSS 6.5fixed in wireshark 4.0.6-1~deb12u1 (bookworm)2023
CVE-2023-0666 [MEDIUM] CVE-2023-0666: wireshark - Due to failure in validating the length provided by an attacker-crafted RTPS pac... Due to failure in validating the length provided by an attacker-crafted RTPS packet, Wireshark version 4.0.5 and prior, by default, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark. Scope: local bookworm: resolved (fixed in 4.0.6-1~deb12u1) bullseye: resolved (fixed in 3.4.16-0+deb11u1) for
debian
CVE-2023-0667P4MEDIUMCVSS 6.5fixed in wireshark 4.0.6-1~deb12u1 (bookworm)2023
CVE-2023-0667 [MEDIUM] CVE-2023-0667: wireshark - Due to failure in validating the length provided by an attacker-crafted MSMMS pa... Due to failure in validating the length provided by an attacker-crafted MSMMS packet, Wireshark version 4.0.5 and prior, in an unusual configuration, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark Scope: local bookworm: resolved (fixed in 4.0.6-1~deb12u1) bullseye: resolved (fixed in 3.4.
debian
CVE-2021-22173P3LOWCVSS 3.7fixed in wireshark 3.4.3-1 (bookworm)2021
CVE-2021-22173 [LOW] CVE-2021-22173: wireshark - Memory leak in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of se... Memory leak in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved (fixed in 3.4.3-1) bullseye: resolved (fixed in 3.4.3-1) forky: resolved (fixed in 3.4.3-1) sid: resolved (fixed in 3.4.3-1) trixie: resolved (fixed in 3.4.3-1)
debian
CVE-2018-19628P4HIGHCVSS 7.5fixed in wireshark 2.6.5-1 (bookworm)2018
CVE-2018-19628 [HIGH] CVE-2018-19628: wireshark - In Wireshark 2.6.0 to 2.6.4, the ZigBee ZCL dissector could crash. This was addr... In Wireshark 2.6.0 to 2.6.4, the ZigBee ZCL dissector could crash. This was addressed in epan/dissectors/packet-zbee-zcl-lighting.c by preventing a divide-by-zero error. Scope: local bookworm: resolved (fixed in 2.6.5-1) bullseye: resolved (fixed in 2.6.5-1) forky: resolved (fixed in 2.6.5-1) sid: resolved (fixed in 2.6.5-1) trixie: resolved (fixed in 2.6.5-1)
debian
CVE-2018-11358P4HIGHCVSS 7.5fixed in wireshark 2.6.1-1 (bookworm)2018
CVE-2018-11358 [HIGH] CVE-2018-11358: wireshark - In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the Q.931 dissector cou... In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the Q.931 dissector could crash. This was addressed in epan/dissectors/packet-q931.c by avoiding a use-after-free after a malformed packet prevented certain cleanup. Scope: local bookworm: resolved (fixed in 2.6.1-1) bullseye: resolved (fixed in 2.6.1-1) forky: resolved (fixed in 2.6.1-1) sid: resolved (fixe
debian
CVE-2017-13765P4HIGHCVSS 7.5fixed in wireshark 2.4.1-1 (bookworm)2017
CVE-2017-13765 [HIGH] CVE-2017-13765: wireshark - In Wireshark 2.4.0, 2.2.0 to 2.2.8, and 2.0.0 to 2.0.14, the IrCOMM dissector ha... In Wireshark 2.4.0, 2.2.0 to 2.2.8, and 2.0.0 to 2.0.14, the IrCOMM dissector has a buffer over-read and application crash. This was addressed in plugins/irda/packet-ircomm.c by adding length validation. Scope: local bookworm: resolved (fixed in 2.4.1-1) bullseye: resolved (fixed in 2.4.1-1) forky: resolved (fixed in 2.4.1-1) sid: resolved (fixed in 2.4.1-1) trixi
debian
CVE-2018-9259P4LOWCVSS 7.5fixed in wireshark 2.4.6-1 (bookworm)2018
CVE-2018-9259 [HIGH] CVE-2018-9259: wireshark - In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the MP4 dissector could crash. ... In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the MP4 dissector could crash. This was addressed in epan/dissectors/file-mp4.c by restricting the box recursion depth. Scope: local bookworm: resolved (fixed in 2.4.6-1) bullseye: resolved (fixed in 2.4.6-1) forky: resolved (fixed in 2.4.6-1) sid: resolved (fixed in 2.4.6-1) trixie: resolved (fixed in 2.4.6-1)
debian
CVE-2017-15190P4LOWCVSS 7.5fixed in wireshark 2.4.2-1 (bookworm)2017
CVE-2017-15190 [HIGH] CVE-2017-15190: wireshark - In Wireshark 2.4.0 to 2.4.1, the RTSP dissector could crash. This was addressed ... In Wireshark 2.4.0 to 2.4.1, the RTSP dissector could crash. This was addressed in epan/dissectors/packet-rtsp.c by correcting the scope of a variable. Scope: local bookworm: resolved (fixed in 2.4.2-1) bullseye: resolved (fixed in 2.4.2-1) forky: resolved (fixed in 2.4.2-1) sid: resolved (fixed in 2.4.2-1) trixie: resolved (fixed in 2.4.2-1)
debian
CVE-2017-11411P4HIGHCVSS 7.5fixed in wireshark 2.4.0-1 (bookworm)2017
CVE-2017-11411 [HIGH] CVE-2017-11411: wireshark - In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the openSAFETY dissector co... In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the openSAFETY dissector could crash or exhaust system memory. This was addressed in epan/dissectors/packet-opensafety.c by adding length validation. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-9350. Scope: local bookworm: resolved (fixed in 2.4.0-1) bullseye: resolved (fixed in 2.4
debian
CVE-2026-3203P4MEDIUMCVSS 5.5fixed in wireshark 4.6.4-1 (forky)2026
CVE-2026-3203 [MEDIUM] CVE-2026-3203: wireshark - RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to ... RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service Scope: local bookworm: open bullseye: open forky: resolved (fixed in 4.6.4-1) sid: resolved (fixed in 4.6.4-1) trixie: resolved (fixed in 4.4.14-0+deb13u1)
debian
CVE-2023-4512P4MEDIUMCVSS 5.3fixed in wireshark 4.0.11-1~deb12u1 (bookworm)2023
CVE-2023-4512 [MEDIUM] CVE-2023-4512: wireshark - CBOR dissector crash in Wireshark 4.0.0 to 4.0.6 allows denial of service via pa... CBOR dissector crash in Wireshark 4.0.0 to 4.0.6 allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved (fixed in 4.0.11-1~deb12u1) bullseye: resolved (fixed in 3.4.16-0+deb11u1) forky: resolved (fixed in 4.0.8-1) sid: resolved (fixed in 4.0.8-1) trixie: resolved (fixed in 4.0.8-1)
debian
CVE-2012-4298P4MEDIUMCVSS 5.4fixed in wireshark 1.8.2-1 (bookworm)2012
CVE-2012-4298 [MEDIUM] CVE-2012-4298: wireshark - Integer signedness error in the vwr_read_rec_data_ethernet function in wiretap/v... Integer signedness error in the vwr_read_rec_data_ethernet function in wiretap/vwr.c in the Ixia IxVeriWave file parser in Wireshark 1.8.x before 1.8.2 allows user-assisted remote attackers to execute arbitrary code via a crafted packet-trace file that triggers a buffer overflow. Scope: local bookworm: resolved (fixed in 1.8.2-1) bullseye: resolved (fixed in 1.8.2
debian
CVE-2021-22207P4MEDIUMCVSS 5.5fixed in wireshark 3.4.7-1 (bookworm)2021
CVE-2021-22207 [MEDIUM] CVE-2021-22207: wireshark - Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and... Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved (fixed in 3.4.7-1) bullseye: resolved (fixed in 3.4.10-0+deb11u1) forky: resolved (fixed in 3.4.7-1) sid: resolved (fixed in 3.4.7-1) trixie: resolved (fixed in 3.4.
debian
CVE-2018-11356P4HIGHCVSS 7.5fixed in wireshark 2.6.1-1 (bookworm)2018
CVE-2018-11356 [HIGH] CVE-2018-11356: wireshark - In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the DNS dissector could... In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the DNS dissector could crash. This was addressed in epan/dissectors/packet-dns.c by avoiding a NULL pointer dereference for an empty name in an SRV record. Scope: local bookworm: resolved (fixed in 2.6.1-1) bullseye: resolved (fixed in 2.6.1-1) forky: resolved (fixed in 2.6.1-1) sid: resolved (fixed in 2.6.
debian
CVE-2018-9274P4HIGHCVSS 7.5fixed in wireshark 2.4.6-1 (bookworm)2018
CVE-2018-9274 [HIGH] CVE-2018-9274: wireshark - In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, ui/failure_message.c has a memo... In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, ui/failure_message.c has a memory leak. Scope: local bookworm: resolved (fixed in 2.4.6-1) bullseye: resolved (fixed in 2.4.6-1) forky: resolved (fixed in 2.4.6-1) sid: resolved (fixed in 2.4.6-1) trixie: resolved (fixed in 2.4.6-1)
debian
CVE-2023-1993P4MEDIUMCVSS 6.3fixed in wireshark 4.0.6-1~deb12u1 (bookworm)2023
CVE-2023-1993 [MEDIUM] CVE-2023-1993: wireshark - LISP dissector large loop in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows... LISP dissector large loop in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved (fixed in 4.0.6-1~deb12u1) bullseye: resolved (fixed in 3.4.16-0+deb11u1) forky: resolved (fixed in 4.0.6-1) sid: resolved (fixed in 4.0.6-1) trixie: resolved (fixed in 4.0.6-1)
debian
CVE-2023-4513P4MEDIUMCVSS 5.3fixed in wireshark 4.0.11-1~deb12u1 (bookworm)2023
CVE-2023-4513 [MEDIUM] CVE-2023-4513: wireshark - BT SDP dissector memory leak in Wireshark 4.0.0 to 4.0.7 and 3.6.0 to 3.6.15 all... BT SDP dissector memory leak in Wireshark 4.0.0 to 4.0.7 and 3.6.0 to 3.6.15 allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved (fixed in 4.0.11-1~deb12u1) bullseye: resolved (fixed in 3.4.16-0+deb11u1) forky: resolved (fixed in 4.0.8-1) sid: resolved (fixed in 4.0.8-1) trixie: resolved (fixed in 4.0.8-1)
debian
CVE-2025-9817P4HIGHCVSS 7.8fixed in wireshark 4.4.9-1 (forky)2025
CVE-2025-9817 [HIGH] CVE-2025-9817: wireshark - SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial of service SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial of service Scope: local bookworm: open bullseye: resolved forky: resolved (fixed in 4.4.9-1) sid: resolved (fixed in 4.4.9-1) trixie: resolved (fixed in 4.4.13-0+deb13u1)
debian
CVE-2023-2906P4MEDIUMCVSS 6.5fixed in wireshark 4.0.11-1~deb12u1 (bookworm)2023
CVE-2023-2906 [MEDIUM] CVE-2023-2906: wireshark - Due to a failure in validating the length provided by an attacker-crafted CP2179... Due to a failure in validating the length provided by an attacker-crafted CP2179 packet, Wireshark versions 2.0.0 through 4.0.7 is susceptible to a divide by zero allowing for a denial of service attack. Scope: local bookworm: resolved (fixed in 4.0.11-1~deb12u1) bullseye: resolved (fixed in 3.4.16-0+deb11u1) forky: resolved (fixed in 4.0.8-1) sid: resolved (fixed
debian
Debian Wireshark vulnerabilities | cvebase