cbcvebase.

Debian Wireshark vulnerabilities

668 known vulnerabilities affecting debian/wireshark.

Total CVEs
668
CISA KEV
0
Public exploits
50
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH129MEDIUM276LOW255

Vulnerabilities

Page 17 of 34
CVE-2007-6117P4MEDIUMCVSS 5.0fixed in wireshark 0.99.7~pre1-1 (bookworm)2007
CVE-2007-6117 [MEDIUM] CVE-2007-6117: wireshark - Unspecified vulnerability in the HTTP dissector for Wireshark (formerly Ethereal... Unspecified vulnerability in the HTTP dissector for Wireshark (formerly Ethereal) 0.10.14 to 0.99.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted chunked messages. Scope: local bookworm: resolved (fixed in 0.99.7~pre1-1) bullseye: resolved (fixed in 0.99.7~pre1-1) forky: resolved (fixed in 0.99.7~pre1-
debian
CVE-2013-4081P4LOWCVSS 5.0fixed in wireshark 1.10.0-1 (bookworm)2013
CVE-2013-4081 [MEDIUM] CVE-2013-4081: wireshark - The http_payload_subdissector function in epan/dissectors/packet-http.c in the H... The http_payload_subdissector function in epan/dissectors/packet-http.c in the HTTP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x before 1.8.8 does not properly determine when to use a recursive approach, which allows remote attackers to cause a denial of service (stack consumption) via a crafted packet. Scope: local bookworm: resolved (fixed in 1.10.0-1) b
debian
CVE-2023-2855P4MEDIUMCVSS 5.3fixed in wireshark 4.0.6-1~deb12u1 (bookworm)2023
CVE-2023-2855 [MEDIUM] CVE-2023-2855: wireshark - Candump log parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows ... Candump log parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file Scope: local bookworm: resolved (fixed in 4.0.6-1~deb12u1) bullseye: resolved (fixed in 3.4.16-0+deb11u1) forky: resolved (fixed in 4.0.6-1) sid: resolved (fixed in 4.0.6-1) trixie: resolved (fixed in 4.0.6-1)
debian
CVE-2006-3630P4HIGHCVSS 7.5fixed in wireshark 0.99.2-1 (bookworm)2006
CVE-2006-3630 [HIGH] CVE-2006-3630: wireshark - Multiple off-by-one errors in Wireshark (aka Ethereal) 0.9.7 to 0.99.0 have unkn... Multiple off-by-one errors in Wireshark (aka Ethereal) 0.9.7 to 0.99.0 have unknown impact and remote attack vectors via the (1) NCP NMAS and (2) NDPS dissectors. Scope: local bookworm: resolved (fixed in 0.99.2-1) bullseye: resolved (fixed in 0.99.2-1) forky: resolved (fixed in 0.99.2-1) sid: resolved (fixed in 0.99.2-1) trixie: resolved (fixed in 0.99.2-1)
debian
CVE-2026-0959P4LOWCVSS 5.3fixed in wireshark 4.6.3-1 (forky)2026
CVE-2026-0959 [MEDIUM] CVE-2026-0959: wireshark - IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.... IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 4.6.3-1) sid: resolved (fixed in 4.6.3-1) trixie: resolved (fixed in 4.4.13-0+deb13u1)
debian
CVE-2018-5334P4MEDIUMCVSS 6.5fixed in wireshark 2.4.4-1 (bookworm)2018
CVE-2018-5334 [MEDIUM] CVE-2018-5334: wireshark - In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the IxVeriWave file parser coul... In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the IxVeriWave file parser could crash. This was addressed in wiretap/vwr.c by correcting the signature timestamp bounds checks. Scope: local bookworm: resolved (fixed in 2.4.4-1) bullseye: resolved (fixed in 2.4.4-1) forky: resolved (fixed in 2.4.4-1) sid: resolved (fixed in 2.4.4-1) trixie: resolved (fixed in 2.4.
debian
CVE-2016-2525P4MEDIUMCVSS 5.9fixed in wireshark 2.0.2+ga16e22e-1 (bookworm)2016
CVE-2016-2525 [MEDIUM] CVE-2016-2525: wireshark - epan/dissectors/packet-http2.c in the HTTP/2 dissector in Wireshark 2.0.x before... epan/dissectors/packet-http2.c in the HTTP/2 dissector in Wireshark 2.0.x before 2.0.2 does not limit the amount of header data, which allows remote attackers to cause a denial of service (memory consumption or application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in 2.0.2+ga16e22e-1) bullseye: resolved (fixed in 2.0.2+ga16e22e-1) forky:
debian
CVE-2016-2531P4MEDIUMCVSS 5.9fixed in wireshark 2.0.2+ga16e22e-1 (bookworm)2016
CVE-2016-2531 [MEDIUM] CVE-2016-2531: wireshark - Off-by-one error in epan/dissectors/packet-rsl.c in the RSL dissector in Wiresha... Off-by-one error in epan/dissectors/packet-rsl.c in the RSL dissector in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet that triggers a 0xff tag value, a different vulnerability than CVE-2016-2530. Scope: local bookworm: resolved (fixed in 2
debian
CVE-2016-4006P4LOWCVSS 5.9fixed in wireshark 2.0.3+geed34f0-1 (bookworm)2016
CVE-2016-4006 [MEDIUM] CVE-2016-4006: wireshark - epan/proto.c in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 does not ... epan/proto.c in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 does not limit the protocol-tree depth, which allows remote attackers to cause a denial of service (stack memory consumption and application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in 2.0.3+geed34f0-1) bullseye: resolved (fixed in 2.0.3+geed34f0-1) forky: resolved (f
debian
CVE-2015-2188P4MEDIUMCVSS 5.0fixed in wireshark 1.12.1+g01b65bf-4 (bookworm)2015
CVE-2015-2188 [MEDIUM] CVE-2015-2188: wireshark - epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.1... epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 does not properly initialize a data structure, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet that is improperly handled during decompression. Scope: local bookworm: resolved (fixe
debian
CVE-2016-4078P4LOWCVSS 5.9fixed in wireshark 2.0.3+geed34f0-1 (bookworm)2016
CVE-2016-4078 [MEDIUM] CVE-2016-4078: wireshark - The IEEE 802.11 dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.... The IEEE 802.11 dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 does not properly restrict element lists, which allows remote attackers to cause a denial of service (deep recursion and application crash) via a crafted packet, related to epan/dissectors/packet-capwap.c and epan/dissectors/packet-ieee80211.c. Scope: local bookworm: resolved (fixe
debian
CVE-2023-0417P4MEDIUMCVSS 6.3fixed in wireshark 4.0.3-1 (bookworm)2023
CVE-2023-0417 [MEDIUM] CVE-2023-0417: wireshark - Memory leak in the NFS dissector in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10... Memory leak in the NFS dissector in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved (fixed in 4.0.3-1) bullseye: resolved (fixed in 3.4.16-0+deb11u1) forky: resolved (fixed in 4.0.3-1) sid: resolved (fixed in 4.0.3-1) trixie: resolved (fixed in 4.0.3-1)
debian
CVE-2023-0415P4MEDIUMCVSS 6.3fixed in wireshark 4.0.3-1 (bookworm)2023
CVE-2023-0415 [MEDIUM] CVE-2023-0415: wireshark - iSCSI dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows... iSCSI dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved (fixed in 4.0.3-1) bullseye: resolved (fixed in 3.4.16-0+deb11u1) forky: resolved (fixed in 4.0.3-1) sid: resolved (fixed in 4.0.3-1) trixie: resolved (fixed in 4.0.3-1)
debian
CVE-2023-0416P4MEDIUMCVSS 6.3fixed in wireshark 4.0.3-1 (bookworm)2023
CVE-2023-0416 [MEDIUM] CVE-2023-0416: wireshark - GNW dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows d... GNW dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved (fixed in 4.0.3-1) bullseye: resolved (fixed in 3.4.16-0+deb11u1) forky: resolved (fixed in 4.0.3-1) sid: resolved (fixed in 4.0.3-1) trixie: resolved (fixed in 4.0.3-1)
debian
CVE-2023-0414P4MEDIUMCVSS 6.3fixed in wireshark 4.0.3-1 (bookworm)2023
CVE-2023-0414 [MEDIUM] CVE-2023-0414: wireshark - Crash in the EAP dissector in Wireshark 4.0.0 to 4.0.2 allows denial of service ... Crash in the EAP dissector in Wireshark 4.0.0 to 4.0.2 allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved (fixed in 4.0.3-1) bullseye: resolved forky: resolved (fixed in 4.0.3-1) sid: resolved (fixed in 4.0.3-1) trixie: resolved (fixed in 4.0.3-1)
debian
CVE-2016-9374P4MEDIUMCVSS 5.9fixed in wireshark 2.2.2+g9c5aae3-1 (bookworm)2016
CVE-2016-9374 [MEDIUM] CVE-2016-9374: wireshark - In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the AllJoyn dissector could cras... In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the AllJoyn dissector could crash with a buffer over-read, triggered by network traffic or a capture file. This was addressed in epan/dissectors/packet-alljoyn.c by ensuring that a length variable properly tracked the state of a signature variable. Scope: local bookworm: resolved (fixed in 2.2.2+g9c5aae3-1) bullseye:
debian
CVE-2015-3814P4MEDIUMCVSS 5.0fixed in wireshark 1.12.5+g5819e5b-1 (bookworm)2015
CVE-2015-3814 [MEDIUM] CVE-2015-3814: wireshark - The (1) dissect_tfs_request and (2) dissect_tfs_response functions in epan/disse... The (1) dissect_tfs_request and (2) dissect_tfs_response functions in epan/dissectors/packet-ieee80211.c in the IEEE 802.11 dissector in Wireshark 1.10.x before 1.10.14 and 1.12.x before 1.12.5 interpret a zero value as a length rather than an error condition, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet. Scope: l
debian
CVE-2013-7112P4LOWCVSS 5.0fixed in wireshark 1.10.4-1 (bookworm)2013
CVE-2013-7112 [MEDIUM] CVE-2013-7112: wireshark - The dissect_sip_common function in epan/dissectors/packet-sip.c in the SIP disse... The dissect_sip_common function in epan/dissectors/packet-sip.c in the SIP dissector in Wireshark 1.8.x before 1.8.12 and 1.10.x before 1.10.4 does not check for empty lines, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet. Scope: local bookworm: resolved (fixed in 1.10.4-1) bullseye: resolved (fixed in 1.10.4-1) for
debian
CVE-2023-2857P4MEDIUMCVSS 5.3fixed in wireshark 4.0.6-1~deb12u1 (bookworm)2023
CVE-2023-2857 [MEDIUM] CVE-2023-2857: wireshark - BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows den... BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file Scope: local bookworm: resolved (fixed in 4.0.6-1~deb12u1) bullseye: resolved forky: resolved (fixed in 4.0.6-1) sid: resolved (fixed in 4.0.6-1) trixie: resolved (fixed in 4.0.6-1)
debian
CVE-2023-2854P4MEDIUMCVSS 5.3fixed in wireshark 4.0.6-1~deb12u1 (bookworm)2023
CVE-2023-2854 [MEDIUM] CVE-2023-2854: wireshark - BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows den... BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file Scope: local bookworm: resolved (fixed in 4.0.6-1~deb12u1) bullseye: resolved forky: resolved (fixed in 4.0.6-1) sid: resolved (fixed in 4.0.6-1) trixie: resolved (fixed in 4.0.6-1)
debian
Debian Wireshark vulnerabilities | cvebase