cbcvebase.

Debian Wireshark vulnerabilities

668 known vulnerabilities affecting debian/wireshark.

Total CVEs
668
CISA KEV
0
Public exploits
50
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH129MEDIUM276LOW255

Vulnerabilities

Page 16 of 34
CVE-2017-7700P4LOWCVSS 6.5fixed in wireshark 2.2.6+g32dac6a-1 (bookworm)2017
CVE-2017-7700 [MEDIUM] CVE-2017-7700: wireshark - In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the NetScaler file parser could... In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the NetScaler file parser could go into an infinite loop, triggered by a malformed capture file. This was addressed in wiretap/netscaler.c by ensuring a nonzero record size. Scope: local bookworm: resolved (fixed in 2.2.6+g32dac6a-1) bullseye: resolved (fixed in 2.2.6+g32dac6a-1) forky: resolved (fixed in 2.2.6+g32d
debian
CVE-2018-5335P4MEDIUMCVSS 6.5fixed in wireshark 2.4.4-1 (bookworm)2018
CVE-2018-5335 [MEDIUM] CVE-2018-5335: wireshark - In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the WCP dissector could crash. ... In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the WCP dissector could crash. This was addressed in epan/dissectors/packet-wcp.c by validating the available buffer length. Scope: local bookworm: resolved (fixed in 2.4.4-1) bullseye: resolved (fixed in 2.4.4-1) forky: resolved (fixed in 2.4.4-1) sid: resolved (fixed in 2.4.4-1) trixie: resolved (fixed in 2.4.4-1)
debian
CVE-2016-2530P4MEDIUMCVSS 5.9fixed in wireshark 2.0.2+ga16e22e-1 (bookworm)2016
CVE-2016-2530 [MEDIUM] CVE-2016-2530: wireshark - The dissct_rsl_ipaccess_msg function in epan/dissectors/packet-rsl.c in the RSL ... The dissct_rsl_ipaccess_msg function in epan/dissectors/packet-rsl.c in the RSL dissector in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 mishandles the case of an unrecognized TLV type, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet, a different vulnerability than CVE-2016-2531.
debian
CVE-2016-5359P4MEDIUMCVSS 5.9fixed in wireshark 2.0 (bookworm)2016
CVE-2016-5359 [MEDIUM] CVE-2016-5359: wireshark - epan/dissectors/packet-wbxml.c in the WBXML dissector in Wireshark 1.12.x before... epan/dissectors/packet-wbxml.c in the WBXML dissector in Wireshark 1.12.x before 1.12.12 mishandles offsets, which allows remote attackers to cause a denial of service (integer overflow and infinite loop) via a crafted packet. Scope: local bookworm: resolved (fixed in 2.0) bullseye: resolved (fixed in 2.0) forky: resolved (fixed in 2.0) sid: resolved (fixed in 2.0
debian
CVE-2016-6506P4MEDIUMCVSS 5.9fixed in wireshark 2.0.5+ga3be9c6-1 (bookworm)2016
CVE-2016-6506 [MEDIUM] CVE-2016-6506: wireshark - epan/dissectors/packet-wsp.c in the WSP dissector in Wireshark 1.12.x before 1.1... epan/dissectors/packet-wsp.c in the WSP dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet. Scope: local bookworm: resolved (fixed in 2.0.5+ga3be9c6-1) bullseye: resolved (fixed in 2.0.5+ga3be9c6-1) forky: resolved (fixed in 2.0.5+ga3be9c6-1) sid: resolved (fix
debian
CVE-2016-4079P4LOWCVSS 5.9fixed in wireshark 2.0.3+geed34f0-1 (bookworm)2016
CVE-2016-4079 [MEDIUM] CVE-2016-4079: wireshark - epan/dissectors/packet-pktc.c in the PKTC dissector in Wireshark 1.12.x before 1... epan/dissectors/packet-pktc.c in the PKTC dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 does not verify BER identifiers, which allows remote attackers to cause a denial of service (out-of-bounds write and application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in 2.0.3+geed34f0-1) bullseye: resolved (fixed in 2.0.3+gee
debian
CVE-2016-6511P4MEDIUMCVSS 5.9fixed in wireshark 2.0.5+ga3be9c6-1 (bookworm)2016
CVE-2016-6511 [MEDIUM] CVE-2016-6511: wireshark - epan/proto.c in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remo... epan/proto.c in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause a denial of service (OpenFlow dissector large loop) via a crafted packet. Scope: local bookworm: resolved (fixed in 2.0.5+ga3be9c6-1) bullseye: resolved (fixed in 2.0.5+ga3be9c6-1) forky: resolved (fixed in 2.0.5+ga3be9c6-1) sid: resolved (fixed in 2.0.5+ga3be9c6-
debian
CVE-2016-6507P4MEDIUMCVSS 5.9fixed in wireshark 2.0 (bookworm)2016
CVE-2016-6507 [MEDIUM] CVE-2016-6507: wireshark - epan/dissectors/packet-mmse.c in the MMSE dissector in Wireshark 1.12.x before 1... epan/dissectors/packet-mmse.c in the MMSE dissector in Wireshark 1.12.x before 1.12.13 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet. Scope: local bookworm: resolved (fixed in 2.0) bullseye: resolved (fixed in 2.0) forky: resolved (fixed in 2.0) sid: resolved (fixed in 2.0) trixie: resolved (fixed in 2.0)
debian
CVE-2016-9372P4MEDIUMCVSS 5.9fixed in wireshark 2.2.2+g9c5aae3-1 (bookworm)2016
CVE-2016-9372 [MEDIUM] CVE-2016-9372: wireshark - In Wireshark 2.2.0 to 2.2.1, the Profinet I/O dissector could loop excessively, ... In Wireshark 2.2.0 to 2.2.1, the Profinet I/O dissector could loop excessively, triggered by network traffic or a capture file. This was addressed in plugins/profinet/packet-pn-rtc-one.c by rejecting input with too many I/O objects. Scope: local bookworm: resolved (fixed in 2.2.2+g9c5aae3-1) bullseye: resolved (fixed in 2.2.2+g9c5aae3-1) forky: resolved (fixed in
debian
CVE-2016-4081P4LOWCVSS 5.9fixed in wireshark 2.0.3+geed34f0-1 (bookworm)2016
CVE-2016-4081 [MEDIUM] CVE-2016-4081: wireshark - epan/dissectors/packet-iax2.c in the IAX2 dissector in Wireshark 1.12.x before 1... epan/dissectors/packet-iax2.c in the IAX2 dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet. Scope: local bookworm: resolved (fixed in 2.0.3+geed34f0-1) bullseye: resolved (fixed in 2.0.3+geed34f0-1) forky: resolved
debian
CVE-2023-1994P4MEDIUMCVSS 6.3fixed in wireshark 4.0.6-1~deb12u1 (bookworm)2023
CVE-2023-1994 [MEDIUM] CVE-2023-1994: wireshark - GQUIC dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows den... GQUIC dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved (fixed in 4.0.6-1~deb12u1) bullseye: resolved (fixed in 3.4.16-0+deb11u1) forky: resolved (fixed in 4.0.6-1) sid: resolved (fixed in 4.0.6-1) trixie: resolved (fixed in 4.0.6-1)
debian
CVE-2023-0411P4MEDIUMCVSS 6.3fixed in wireshark 4.0.3-1 (bookworm)2023
CVE-2023-0411 [MEDIUM] CVE-2023-0411: wireshark - Excessive loops in multiple dissectors in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to ... Excessive loops in multiple dissectors in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved (fixed in 4.0.3-1) bullseye: resolved (fixed in 3.4.16-0+deb11u1) forky: resolved (fixed in 4.0.3-1) sid: resolved (fixed in 4.0.3-1) trixie: resolved (fixed in 4.0.3-1)
debian
CVE-2023-0413P4MEDIUMCVSS 6.3fixed in wireshark 4.0.3-1 (bookworm)2023
CVE-2023-0413 [MEDIUM] CVE-2023-0413: wireshark - Dissection engine bug in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows... Dissection engine bug in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved (fixed in 4.0.3-1) bullseye: resolved (fixed in 3.4.16-0+deb11u1) forky: resolved (fixed in 4.0.3-1) sid: resolved (fixed in 4.0.3-1) trixie: resolved (fixed in 4.0.3-1)
debian
CVE-2023-6174P4MEDIUMCVSS 6.3fixed in wireshark 4.0.11-1~deb12u1 (bookworm)2023
CVE-2023-6174 [MEDIUM] CVE-2023-6174: wireshark - SSH dissector crash in Wireshark 4.0.0 to 4.0.10 allows denial of service via pa... SSH dissector crash in Wireshark 4.0.0 to 4.0.10 allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved (fixed in 4.0.11-1~deb12u1) bullseye: resolved forky: resolved (fixed in 4.0.11-1) sid: resolved (fixed in 4.0.11-1) trixie: resolved (fixed in 4.0.11-1)
debian
CVE-2016-9373P4MEDIUMCVSS 5.9fixed in wireshark 2.2.2+g9c5aae3-1 (bookworm)2016
CVE-2016-9373 [MEDIUM] CVE-2016-9373: wireshark - In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the DCERPC dissector could crash... In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the DCERPC dissector could crash with a use-after-free, triggered by network traffic or a capture file. This was addressed in epan/dissectors/packet-dcerpc-nt.c and epan/dissectors/packet-dcerpc-spoolss.c by using the wmem file scope for private strings. Scope: local bookworm: resolved (fixed in 2.2.2+g9c5aae3-1) bul
debian
CVE-2022-4345P4MEDIUMCVSS 6.3fixed in wireshark 4.0.2-1 (bookworm)2022
CVE-2022-4345 [MEDIUM] CVE-2022-4345: wireshark - Infinite loops in the BPv6, OpenFlow, and Kafka protocol dissectors in Wireshark... Infinite loops in the BPv6, OpenFlow, and Kafka protocol dissectors in Wireshark 4.0.0 to 4.0.1 and 3.6.0 to 3.6.9 allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved (fixed in 4.0.2-1) bullseye: resolved (fixed in 3.4.16-0+deb11u1) forky: resolved (fixed in 4.0.2-1) sid: resolved (fixed in 4.0.2-1) trixie: resolve
debian
CVE-2015-2191P4MEDIUMCVSS 5.0fixed in wireshark 1.12.1+g01b65bf-4 (bookworm)2015
CVE-2015-2191 [MEDIUM] CVE-2015-2191: wireshark - Integer overflow in the dissect_tnef function in epan/dissectors/packet-tnef.c i... Integer overflow in the dissect_tnef function in epan/dissectors/packet-tnef.c in the TNEF dissector in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted length field in a packet. Scope: local bookworm: resolved (fixed in 1.12.1+g01b65bf-4) bullseye: resolved (fixed in 1.12.1
debian
CVE-2016-9375P4MEDIUMCVSS 5.9fixed in wireshark 2.2.2+g9c5aae3-1 (bookworm)2016
CVE-2016-9375 [MEDIUM] CVE-2016-9375: wireshark - In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the DTN dissector could go into ... In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the DTN dissector could go into an infinite loop, triggered by network traffic or a capture file. This was addressed in epan/dissectors/packet-dtn.c by checking whether SDNV evaluation was successful. Scope: local bookworm: resolved (fixed in 2.2.2+g9c5aae3-1) bullseye: resolved (fixed in 2.2.2+g9c5aae3-1) forky: res
debian
CVE-2016-9376P4MEDIUMCVSS 5.9fixed in wireshark 2.2.2+g9c5aae3-1 (bookworm)2016
CVE-2016-9376 [MEDIUM] CVE-2016-9376: wireshark - In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the OpenFlow dissector could cra... In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the OpenFlow dissector could crash with memory exhaustion, triggered by network traffic or a capture file. This was addressed in epan/dissectors/packet-openflow_v5.c by ensuring that certain length values were sufficiently large. Scope: local bookworm: resolved (fixed in 2.2.2+g9c5aae3-1) bullseye: resolved (fixed in
debian
CVE-2016-4419P4MEDIUMCVSS 5.9fixed in wireshark 2.0.2+ga16e22e-1 (bookworm)2016
CVE-2016-4419 [MEDIUM] CVE-2016-4419: wireshark - epan/dissectors/packet-spice.c in the SPICE dissector in Wireshark 2.x before 2.... epan/dissectors/packet-spice.c in the SPICE dissector in Wireshark 2.x before 2.0.2 mishandles capability data, which allows remote attackers to cause a denial of service (large loop) via a crafted packet. Scope: local bookworm: resolved (fixed in 2.0.2+ga16e22e-1) bullseye: resolved (fixed in 2.0.2+ga16e22e-1) forky: resolved (fixed in 2.0.2+ga16e22e-1) sid: reso
debian
Debian Wireshark vulnerabilities | cvebase