cbcvebase.

Debian Wireshark vulnerabilities

668 known vulnerabilities affecting debian/wireshark.

Total CVEs
668
CISA KEV
0
Public exploits
50
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH129MEDIUM276LOW255

Vulnerabilities

Page 18 of 34
CVE-2026-0961P4LOWCVSS 5.5fixed in wireshark 4.6.3-1 (forky)2026
CVE-2026-0961 [MEDIUM] CVE-2026-0961: wireshark - BLF file parser crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows den... BLF file parser crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 4.6.3-1) sid: resolved (fixed in 4.6.3-1) trixie: resolved (fixed in 4.4.13-0+deb13u1)
debian
CVE-2020-26421P4MEDIUMCVSS 4.2fixed in wireshark 3.4.1-1 (bookworm)2020
CVE-2020-26421 [MEDIUM] CVE-2020-26421: wireshark - Crash in USB HID protocol dissector and possibly other dissectors in Wireshark 3... Crash in USB HID protocol dissector and possibly other dissectors in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file. Scope: local bookworm: resolved (fixed in 3.4.1-1) bullseye: resolved (fixed in 3.4.1-1) forky: resolved (fixed in 3.4.1-1) sid: resolved (fixed in 3.4.1-1) trixie: resolved (fixed in 3.4.1
debian
CVE-2015-0561P4MEDIUMCVSS 5.0fixed in wireshark 1.12.1+g01b65bf-3 (bookworm)2015
CVE-2015-0561 [MEDIUM] CVE-2015-0561: wireshark - asn1/lpp/lpp.cnf in the LPP dissector in Wireshark 1.10.x before 1.10.12 and 1.1... asn1/lpp/lpp.cnf in the LPP dissector in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 does not validate a certain index value, which allows remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in 1.12.1+g01b65bf-3) bullseye: resolved (fixed in 1.12
debian
CVE-2016-2532P4MEDIUMCVSS 5.9fixed in wireshark 2.0.2+ga16e22e-1 (bookworm)2016
CVE-2016-2532 [MEDIUM] CVE-2016-2532: wireshark - The dissect_llrp_parameters function in epan/dissectors/packet-llrp.c in the LLR... The dissect_llrp_parameters function in epan/dissectors/packet-llrp.c in the LLRP dissector in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 does not limit the recursion depth, which allows remote attackers to cause a denial of service (memory consumption or application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in 2.0.2+ga16e22e-
debian
CVE-2016-5351P4MEDIUMCVSS 5.9fixed in wireshark 2.0.4+gdd7746e-1 (bookworm)2016
CVE-2016-5351 [MEDIUM] CVE-2016-5351: wireshark - epan/crypt/airpdcap.c in the IEEE 802.11 dissector in Wireshark 1.12.x before 1.... epan/crypt/airpdcap.c in the IEEE 802.11 dissector in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles the lack of an EAPOL_RSN_KEY, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in 2.0.4+gdd7746e-1) bullseye: resolved (fixed in 2.0.4+gdd7746e-1) forky: res
debian
CVE-2016-7177P4MEDIUMCVSS 5.9fixed in wireshark 2.2.0~rc1+g438c022-1 (bookworm)2016
CVE-2016-7177 [MEDIUM] CVE-2016-7177: wireshark - epan/dissectors/packet-catapult-dct2000.c in the Catapult DCT2000 dissector in W... epan/dissectors/packet-catapult-dct2000.c in the Catapult DCT2000 dissector in Wireshark 2.x before 2.0.6 does not restrict the number of channels, which allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in 2.2.0~rc1+g438c022-1) bullseye: resolved (fixed in 2.2
debian
CVE-2015-2189P4MEDIUMCVSS 5.0fixed in wireshark 1.12.1+g01b65bf-4 (bookworm)2015
CVE-2015-2189 [MEDIUM] CVE-2015-2189: wireshark - Off-by-one error in the pcapng_read function in wiretap/pcapng.c in the pcapng f... Off-by-one error in the pcapng_read function in wiretap/pcapng.c in the pcapng file parser in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via an invalid Interface Statistics Block (ISB) interface ID in a crafted packet. Scope: local bookworm: resolved (fixe
debian
CVE-2016-4077P4LOWCVSS 5.9fixed in wireshark 2.0.3+geed34f0-1 (bookworm)2016
CVE-2016-4077 [MEDIUM] CVE-2016-4077: wireshark - epan/reassemble.c in TShark in Wireshark 2.0.x before 2.0.3 relies on incorrect ... epan/reassemble.c in TShark in Wireshark 2.0.x before 2.0.3 relies on incorrect special-case handling of truncated Tvb data structures, which allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in 2.0.3+geed34f0-1) bullseye: resolved (fixed in 2.0.3+geed34f0-1) for
debian
CVE-2010-3445P4LOWCVSS 5.0fixed in wireshark 1.2.11-3 (bookworm)2010
CVE-2010-3445 [MEDIUM] CVE-2010-3445: wireshark - Stack consumption vulnerability in the dissect_ber_unknown function in epan/diss... Stack consumption vulnerability in the dissect_ber_unknown function in epan/dissectors/packet-ber.c in the BER dissector in Wireshark 1.4.x before 1.4.1 and 1.2.x before 1.2.12 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a long string in an unknown ASN.1/BER encoded packet, as demonstrated using SNMP. Scope: local
debian
CVE-2016-4415P4MEDIUMCVSS 5.9fixed in wireshark 2.0.2+ga16e22e-1 (bookworm)2016
CVE-2016-4415 [MEDIUM] CVE-2016-4415: wireshark - wiretap/vwr.c in the Ixia IxVeriWave file parser in Wireshark 2.x before 2.0.2 i... wiretap/vwr.c in the Ixia IxVeriWave file parser in Wireshark 2.x before 2.0.2 incorrectly increases a certain octet count, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a crafted file. Scope: local bookworm: resolved (fixed in 2.0.2+ga16e22e-1) bullseye: resolved (fixed in 2.0.2+ga16e22e-1) forky
debian
CVE-2016-4421P4MEDIUMCVSS 5.9fixed in wireshark 2.0.2+ga16e22e-1 (bookworm)2016
CVE-2016-4421 [MEDIUM] CVE-2016-4421: wireshark - epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.12.x befo... epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.12.x before 1.12.10 and 2.x before 2.0.2 allows remote attackers to cause a denial of service (deep recursion, stack consumption, and application crash) via a packet that specifies deeply nested data. Scope: local bookworm: resolved (fixed in 2.0.2+ga16e22e-1) bullseye: resolved (fixed in 2.0.2
debian
CVE-2015-2190P4MEDIUMCVSS 5.0fixed in wireshark 1.12.1+g01b65bf-4 (bookworm)2015
CVE-2015-2190 [MEDIUM] CVE-2015-2190: wireshark - epan/proto.c in Wireshark 1.12.x before 1.12.4 does not properly handle integer ... epan/proto.c in Wireshark 1.12.x before 1.12.4 does not properly handle integer data types greater than 32 bits in size, which allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted packet that is improperly handled by the LLDP dissector. Scope: local bookworm: resolved (fixed in 1.12.1+g01b65bf-4) bullseye: res
debian
CVE-2014-6431P4MEDIUMCVSS 5.0fixed in wireshark 1.12.1+g01b65bf-1 (bookworm)2014
CVE-2014-6431 [MEDIUM] CVE-2014-6431: wireshark - Buffer overflow in the SnifferDecompress function in wiretap/ngsniffer.c in the ... Buffer overflow in the SnifferDecompress function in wiretap/ngsniffer.c in the DOS Sniffer file parser in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 allows remote attackers to cause a denial of service (application crash) via a crafted file that triggers writes of uncompressed bytes beyond the end of the output buffer. Scope: local bookworm: resolve
debian
CVE-2013-4931P4LOWCVSS 5.0fixed in wireshark 1.10.1-1 (bookworm)2013
CVE-2013-4931 [MEDIUM] CVE-2013-4931: wireshark - epan/proto.c in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 allows rem... epan/proto.c in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 allows remote attackers to cause a denial of service (loop) via a crafted packet that is not properly handled by the GSM RR dissector. Scope: local bookworm: resolved (fixed in 1.10.1-1) bullseye: resolved (fixed in 1.10.1-1) forky: resolved (fixed in 1.10.1-1) sid: resolved (fixed in 1.10.1-1)
debian
CVE-2014-6423P4MEDIUMCVSS 5.0fixed in wireshark 1.12.1+g01b65bf-1 (bookworm)2014
CVE-2014-6423 [MEDIUM] CVE-2014-6423: wireshark - The tvb_raw_text_add function in epan/dissectors/packet-megaco.c in the MEGACO d... The tvb_raw_text_add function in epan/dissectors/packet-megaco.c in the MEGACO dissector in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 allows remote attackers to cause a denial of service (infinite loop) via an empty line. Scope: local bookworm: resolved (fixed in 1.12.1+g01b65bf-1) bullseye: resolved (fixed in 1.12.1+g01b65bf-1) forky: resolved (fix
debian
CVE-2013-4924P4MEDIUMCVSS 5.0fixed in wireshark 1.10.1-1 (bookworm)2013
CVE-2013-4924 [MEDIUM] CVE-2013-4924: wireshark - epan/dissectors/packet-dcom-sysact.c in the DCOM ISystemActivator dissector in W... epan/dissectors/packet-dcom-sysact.c in the DCOM ISystemActivator dissector in Wireshark 1.10.x before 1.10.1 does not properly validate certain index values, which allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted packet. Scope: local bookworm: resolved (fixed in 1.10.1-1) bullseye: resolved (fixed in 1.10
debian
CVE-2015-3813P4MEDIUMCVSS 5.0fixed in wireshark 1.12.5+g5819e5b-1 (bookworm)2015
CVE-2015-3813 [MEDIUM] CVE-2015-3813: wireshark - The fragment_add_work function in epan/reassemble.c in the packet-reassembly fea... The fragment_add_work function in epan/reassemble.c in the packet-reassembly feature in Wireshark 1.12.x before 1.12.5 does not properly determine the defragmentation state in a case of an insufficient snapshot length, which allows remote attackers to cause a denial of service (memory consumption) via a crafted packet. Scope: local bookworm: resolved (fixed in 1.1
debian
CVE-2023-5371P4MEDIUMCVSS 5.3fixed in wireshark 4.0.11-1~deb12u1 (bookworm)2023
CVE-2023-5371 [MEDIUM] CVE-2023-5371: wireshark - RTPS dissector memory leak in Wireshark 4.0.0 to 4.0.8 and 3.6.0 to 3.6.16 allow... RTPS dissector memory leak in Wireshark 4.0.0 to 4.0.8 and 3.6.0 to 3.6.16 allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved (fixed in 4.0.11-1~deb12u1) bullseye: resolved forky: resolved (fixed in 4.0.10-1) sid: resolved (fixed in 4.0.10-1) trixie: resolved (fixed in 4.0.10-1)
debian
CVE-2016-5354P4MEDIUMCVSS 5.9fixed in wireshark 2.0.4+gdd7746e-1 (bookworm)2016
CVE-2016-5354 [MEDIUM] CVE-2016-5354: wireshark - The USB subsystem in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishan... The USB subsystem in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles class types, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in 2.0.4+gdd7746e-1) bullseye: resolved (fixed in 2.0.4+gdd7746e-1) forky: resolved (fixed in 2.0.4+gdd7746e-1) sid: resolved (f
debian
CVE-2016-5352P4MEDIUMCVSS 5.9fixed in wireshark 2.0.4+gdd7746e-1 (bookworm)2016
CVE-2016-5352 [MEDIUM] CVE-2016-5352: wireshark - epan/crypt/airpdcap.c in the IEEE 802.11 dissector in Wireshark 2.x before 2.0.4... epan/crypt/airpdcap.c in the IEEE 802.11 dissector in Wireshark 2.x before 2.0.4 mishandles certain length values, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in 2.0.4+gdd7746e-1) bullseye: resolved (fixed in 2.0.4+gdd7746e-1) forky: resolved (fixed in 2.0.4+gdd7746e-1)
debian
Debian Wireshark vulnerabilities | cvebase