Debian Wireshark vulnerabilities
668 known vulnerabilities affecting debian/wireshark.
Total CVEs
668
CISA KEV
0
Public exploits
50
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH129MEDIUM276LOW255
Vulnerabilities
Page 19 of 34
CVE-2016-7176P4MEDIUMCVSS 5.9fixed in wireshark 2.2.0~rc1+g438c022-1 (bookworm)2016
CVE-2016-7176 [MEDIUM] CVE-2016-7176: wireshark - epan/dissectors/packet-h225.c in the H.225 dissector in Wireshark 2.x before 2.0...
epan/dissectors/packet-h225.c in the H.225 dissector in Wireshark 2.x before 2.0.6 calls snprintf with one of its input buffers as the output buffer, which allows remote attackers to cause a denial of service (copy overlap and application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 2.2.0~rc1+g438c022-1)
bullseye: resolved (fixed in 2.2.0
debian
CVE-2016-5357P4MEDIUMCVSS 5.9fixed in wireshark 2.0.4+gdd7746e-1 (bookworm)2016
CVE-2016-5357 [MEDIUM] CVE-2016-5357: wireshark - wiretap/netscreen.c in the NetScreen file parser in Wireshark 1.12.x before 1.12...
wiretap/netscreen.c in the NetScreen file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, which allows remote attackers to cause a denial of service (application crash) via a crafted file.
Scope: local
bookworm: resolved (fixed in 2.0.4+gdd7746e-1)
bullseye: resolved (fixed in 2.0.4+gdd7746e-1)
forky: r
debian
CVE-2016-5355P4MEDIUMCVSS 5.9fixed in wireshark 2.0.4+gdd7746e-1 (bookworm)2016
CVE-2016-5355 [MEDIUM] CVE-2016-5355: wireshark - wiretap/toshiba.c in the Toshiba file parser in Wireshark 1.12.x before 1.12.12 ...
wiretap/toshiba.c in the Toshiba file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, which allows remote attackers to cause a denial of service (application crash) via a crafted file.
Scope: local
bookworm: resolved (fixed in 2.0.4+gdd7746e-1)
bullseye: resolved (fixed in 2.0.4+gdd7746e-1)
forky: resol
debian
CVE-2016-5356P4MEDIUMCVSS 5.9fixed in wireshark 2.0.4+gdd7746e-1 (bookworm)2016
CVE-2016-5356 [MEDIUM] CVE-2016-5356: wireshark - wiretap/cosine.c in the CoSine file parser in Wireshark 1.12.x before 1.12.12 an...
wiretap/cosine.c in the CoSine file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, which allows remote attackers to cause a denial of service (application crash) via a crafted file.
Scope: local
bookworm: resolved (fixed in 2.0.4+gdd7746e-1)
bullseye: resolved (fixed in 2.0.4+gdd7746e-1)
forky: resolve
debian
CVE-2016-4082P4LOWCVSS 5.9fixed in wireshark 2.0.3+geed34f0-1 (bookworm)2016
CVE-2016-4082 [MEDIUM] CVE-2016-4082: wireshark - epan/dissectors/packet-gsm_cbch.c in the GSM CBCH dissector in Wireshark 1.12.x ...
epan/dissectors/packet-gsm_cbch.c in the GSM CBCH dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 uses the wrong variable to index an array, which allows remote attackers to cause a denial of service (out-of-bounds access and application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 2.0.3+geed34f0-1)
bullseye: resolved
debian
CVE-2016-5353P4MEDIUMCVSS 5.9fixed in wireshark 2.0.4+gdd7746e-1 (bookworm)2016
CVE-2016-5353 [MEDIUM] CVE-2016-5353: wireshark - epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 1.12.x be...
epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles the reserved C/T value, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 2.0.4+gdd7746e-1)
bullseye: resolved (fixed in 2.0.4+gdd7746e-1)
forky: re
debian
CVE-2013-4082P4MEDIUMCVSS 5.0fixed in wireshark 1.10.0-1 (bookworm)2013
CVE-2013-4082 [MEDIUM] CVE-2013-4082: wireshark - The vwr_read function in wiretap/vwr.c in the Ixia IxVeriWave file parser in Wir...
The vwr_read function in wiretap/vwr.c in the Ixia IxVeriWave file parser in Wireshark 1.8.x before 1.8.8 does not validate the relationship between a record length and a trailer length, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 1.10.
debian
CVE-2016-7178P4MEDIUMCVSS 5.9fixed in wireshark 2.2.0~rc1+g438c022-1 (bookworm)2016
CVE-2016-7178 [MEDIUM] CVE-2016-7178: wireshark - epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 2.x befor...
epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 2.x before 2.0.6 does not ensure that memory is allocated for certain data structures, which allows remote attackers to cause a denial of service (invalid write access and application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 2.2.0~rc1+g438c022-1)
bullseye: resolved
debian
CVE-2016-4080P4LOWCVSS 5.9fixed in wireshark 2.0.3+geed34f0-1 (bookworm)2016
CVE-2016-4080 [MEDIUM] CVE-2016-4080: wireshark - epan/dissectors/packet-pktc.c in the PKTC dissector in Wireshark 1.12.x before 1...
epan/dissectors/packet-pktc.c in the PKTC dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 misparses timestamp fields, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 2.0.3+geed34f0-1)
bullseye: resolved (fixed in 2.0.3+geed34f0-
debian
CVE-2016-6509P4MEDIUMCVSS 5.9fixed in wireshark 2.0.5+ga3be9c6-1 (bookworm)2016
CVE-2016-6509 [MEDIUM] CVE-2016-6509: wireshark - epan/dissectors/packet-ldss.c in the LDSS dissector in Wireshark 1.12.x before 1...
epan/dissectors/packet-ldss.c in the LDSS dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 mishandles conversations, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 2.0.5+ga3be9c6-1)
bullseye: resolved (fixed in 2.0.5+ga3be9c6-1)
forky: resolved (fixed i
debian
CVE-2016-2522P4MEDIUMCVSS 5.9fixed in wireshark 2.0.2+ga16e22e-1 (bookworm)2016
CVE-2016-2522 [MEDIUM] CVE-2016-2522: wireshark - The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber.c i...
The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 2.0.x before 2.0.2 does not verify that a certain length is nonzero, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 2.0.2+ga16e2
debian
CVE-2016-2526P4MEDIUMCVSS 5.9fixed in wireshark 2.0.2+ga16e22e-1 (bookworm)2016
CVE-2016-2526 [MEDIUM] CVE-2016-2526: wireshark - epan/dissectors/packet-hiqnet.c in the HiQnet dissector in Wireshark 2.0.x befor...
epan/dissectors/packet-hiqnet.c in the HiQnet dissector in Wireshark 2.0.x before 2.0.2 does not validate the data type, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 2.0.2+ga16e22e-1)
bullseye: resolved (fixed in 2.0.2+ga16e22e-1)
forky: resolve
debian
CVE-2020-26418P4LOWCVSS 3.1fixed in wireshark 3.4.1-1 (bookworm)2020
CVE-2020-26418 [LOW] CVE-2020-26418: wireshark - Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 al...
Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
Scope: local
bookworm: resolved (fixed in 3.4.1-1)
bullseye: resolved (fixed in 3.4.1-1)
forky: resolved (fixed in 3.4.1-1)
sid: resolved (fixed in 3.4.1-1)
trixie: resolved (fixed in 3.4.1-1)
debian
CVE-2016-2524P4MEDIUMCVSS 5.9fixed in wireshark 2.0.2+ga16e22e-1 (bookworm)2016
CVE-2016-2524 [MEDIUM] CVE-2016-2524: wireshark - epan/dissectors/packet-x509af.c in the X.509AF dissector in Wireshark 2.0.x befo...
epan/dissectors/packet-x509af.c in the X.509AF dissector in Wireshark 2.0.x before 2.0.2 mishandles the algorithm ID, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 2.0.2+ga16e22e-1)
bullseye: resolved (fixed in 2.0.2+ga16e22e-1)
forky: resolved (fixed in 2.0.2+ga16e22e
debian
CVE-2016-4083P4LOWCVSS 5.9fixed in wireshark 2.0.3+geed34f0-1 (bookworm)2016
CVE-2016-4083 [MEDIUM] CVE-2016-4083: wireshark - epan/dissectors/packet-mswsp.c in the MS-WSP dissector in Wireshark 2.0.x before...
epan/dissectors/packet-mswsp.c in the MS-WSP dissector in Wireshark 2.0.x before 2.0.3 does not ensure that data is available before array allocation, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 2.0.3+geed34f0-1)
bullseye: resolved (fixed in 2.0.3+geed34f0-1)
forky:
debian
CVE-2014-6427P4MEDIUMCVSS 5.0fixed in wireshark 1.12.1+g01b65bf-1 (bookworm)2014
CVE-2014-6427 [MEDIUM] CVE-2014-6427: wireshark - Off-by-one error in the is_rtsp_request_or_reply function in epan/dissectors/pac...
Off-by-one error in the is_rtsp_request_or_reply function in epan/dissectors/packet-rtsp.c in the RTSP dissector in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 allows remote attackers to cause a denial of service (application crash) via a crafted packet that triggers parsing of a token located one position beyond the current position.
Scope: local
boo
debian
CVE-2016-4416P4MEDIUMCVSS 5.9fixed in wireshark 2.0.2+ga16e22e-1 (bookworm)2016
CVE-2016-4416 [MEDIUM] CVE-2016-4416: wireshark - epan/dissectors/packet-ieee80211.c in the IEEE 802.11 dissector in Wireshark 2.x...
epan/dissectors/packet-ieee80211.c in the IEEE 802.11 dissector in Wireshark 2.x before 2.0.2 mishandles the Grouping subfield, which allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 2.0.2+ga16e22e-1)
bullseye: resolved (fixed in 2.0.2+ga16e22e-1)
forky: re
debian
CVE-2014-8711P4MEDIUMCVSS 5.0fixed in wireshark 1.12.1+g01b65bf-2 (bookworm)2014
CVE-2014-8711 [MEDIUM] CVE-2014-8711: wireshark - Multiple integer overflows in epan/dissectors/packet-amqp.c in the AMQP dissecto...
Multiple integer overflows in epan/dissectors/packet-amqp.c in the AMQP dissector in Wireshark 1.10.x before 1.10.11 and 1.12.x before 1.12.2 allow remote attackers to cause a denial of service (application crash) via a crafted amqp_0_10 PDU in a packet.
Scope: local
bookworm: resolved (fixed in 1.12.1+g01b65bf-2)
bullseye: resolved (fixed in 1.12.1+g01b65bf-2)
fo
debian
CVE-2014-8712P4MEDIUMCVSS 5.0fixed in wireshark 1.12.1+g01b65bf-2 (bookworm)2014
CVE-2014-8712 [MEDIUM] CVE-2014-8712: wireshark - The build_expert_data function in epan/dissectors/packet-ncp2222.inc in the NCP ...
The build_expert_data function in epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 1.10.x before 1.10.11 and 1.12.x before 1.12.2 does not properly initialize a data structure, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 1.12.1+g01b65bf-2)
bullsey
debian
CVE-2015-3811P4MEDIUMCVSS 5.0fixed in wireshark 1.12.5+g5819e5b-1 (bookworm)2015
CVE-2015-3811 [MEDIUM] CVE-2015-3811: wireshark - epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.1...
epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.14 and 1.12.x before 1.12.5 improperly refers to previously processed bytes, which allows remote attackers to cause a denial of service (application crash) via a crafted packet, a different vulnerability than CVE-2015-2188.
Scope: local
bookworm: resolved (fixed in 1.12.5+g5819e5b-1)
debian