Debian Wireshark vulnerabilities
668 known vulnerabilities affecting debian/wireshark.
Total CVEs
668
CISA KEV
0
Public exploits
50
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH129MEDIUM276LOW255
Vulnerabilities
Page 2 of 34
CVE-2015-8725P4MEDIUMCVSS 5.5PoCfixed in wireshark 2.0.1+g59ea380-1 (bookworm)2015
CVE-2015-8725 [MEDIUM] CVE-2015-8725: wireshark - The dissect_diameter_base_framed_ipv6_prefix function in epan/dissectors/packet-...
The dissect_diameter_base_framed_ipv6_prefix function in epan/dissectors/packet-diameter.c in the DIAMETER dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the IPv6 prefix length, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted packet.
Scope: local
book
debian
CVE-2011-0444P3CRITICALCVSS 10.0fixed in wireshark 1.2.11-6 (bookworm)2011
CVE-2011-0444 [CRITICAL] CVE-2011-0444: wireshark - Buffer overflow in the MAC-LTE dissector (epan/dissectors/packet-mac-lte.c) in W...
Buffer overflow in the MAC-LTE dissector (epan/dissectors/packet-mac-lte.c) in Wireshark 1.2.0 through 1.2.13 and 1.4.0 through 1.4.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of RARs.
Scope: local
bookworm: resolved (fixed in 1.2.11-6)
bullseye: resolved (fixed in 1.2.11-6)
forky: resolve
debian
CVE-2015-8728P4MEDIUMCVSS 5.5PoCfixed in wireshark 2.0.1+g59ea380-1 (bookworm)2015
CVE-2015-8728 [MEDIUM] CVE-2015-8728: wireshark - The Mobile Identity parser in (1) epan/dissectors/packet-ansi_a.c in the ANSI A ...
The Mobile Identity parser in (1) epan/dissectors/packet-ansi_a.c in the ANSI A dissector and (2) epan/dissectors/packet-gsm_a_common.c in the GSM A dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 improperly uses the tvb_bcd_dig_to_wmem_packet_str function, which allows remote attackers to cause a denial of service (buffer overflow and applicati
debian
CVE-2011-1140P4LOWCVSS 4.3PoCfixed in wireshark 1.4.4-1 (bookworm)2011
CVE-2011-1140 [MEDIUM] CVE-2011-1140: wireshark - Multiple stack consumption vulnerabilities in the dissect_ms_compressed_string a...
Multiple stack consumption vulnerabilities in the dissect_ms_compressed_string and dissect_mscldap_string functions in Wireshark 1.0.x, 1.2.0 through 1.2.14, and 1.4.0 through 1.4.3 allow remote attackers to cause a denial of service (infinite recursion) via a crafted (1) SMB or (2) Connection-less LDAP (CLDAP) packet.
Scope: local
bookworm: resolved (fixed in 1.4
debian
CVE-2018-12086P3HIGHCVSS 7.5fixed in wireshark 2.6.4-1 (bookworm)2018
CVE-2018-12086 [HIGH] CVE-2018-12086: wireshark - Buffer overflow in OPC UA applications allows remote attackers to trigger a stac...
Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured requests.
Scope: local
bookworm: resolved (fixed in 2.6.4-1)
bullseye: resolved (fixed in 2.6.4-1)
forky: resolved (fixed in 2.6.4-1)
sid: resolved (fixed in 2.6.4-1)
trixie: resolved (fixed in 2.6.4-1)
debian
CVE-2022-0582P3MEDIUMCVSS 6.3fixed in wireshark 3.6.2-1 (bookworm)2022
CVE-2022-0582 [MEDIUM] CVE-2022-0582: wireshark - Unaligned access in the CSN.1 protocol dissector in Wireshark 3.6.0 to 3.6.1 and...
Unaligned access in the CSN.1 protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file
Scope: local
bookworm: resolved (fixed in 3.6.2-1)
bullseye: resolved (fixed in 3.4.16-0+deb11u1)
forky: resolved (fixed in 3.6.2-1)
sid: resolved (fixed in 3.6.2-1)
trixie: resolved (fixed in 3.6.2-
debian
CVE-2015-8736P4MEDIUMCVSS 5.5PoCfixed in wireshark 2.0.1+g59ea380-1 (bookworm)2015
CVE-2015-8736 [MEDIUM] CVE-2015-8736: wireshark - The mp2t_find_next_pcr function in wiretap/mp2t.c in the MP2T file parser in Wir...
The mp2t_find_next_pcr function in wiretap/mp2t.c in the MP2T file parser in Wireshark 2.0.x before 2.0.1 does not reserve memory for a trailer, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted file.
Scope: local
bookworm: resolved (fixed in 2.0.1+g59ea380-1)
bullseye: resolved (fixed in 2
debian
CVE-2015-8739P4MEDIUMCVSS 5.5PoCfixed in wireshark 2.0.1+g59ea380-1 (bookworm)2015
CVE-2015-8739 [MEDIUM] CVE-2015-8739: wireshark - The ipmi_fmt_udpport function in epan/dissectors/packet-ipmi.c in the IPMI disse...
The ipmi_fmt_udpport function in epan/dissectors/packet-ipmi.c in the IPMI dissector in Wireshark 2.0.x before 2.0.1 improperly attempts to access a packet scope, which allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 2.0.1+g59ea380-1)
bullseye: resolved (f
debian
CVE-2015-8727P4MEDIUMCVSS 5.5PoCfixed in wireshark 2.0.1+g59ea380-1 (bookworm)2015
CVE-2015-8727 [MEDIUM] CVE-2015-8727: wireshark - The dissect_rsvp_common function in epan/dissectors/packet-rsvp.c in the RSVP di...
The dissect_rsvp_common function in epan/dissectors/packet-rsvp.c in the RSVP dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not properly maintain request-key data, which allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 2.0.1+g59ea380
debian
CVE-2007-3389P4MEDIUMCVSS 5.0PoCfixed in wireshark 0.99.6pre1-1 (bookworm)2007
CVE-2007-3389 [MEDIUM] CVE-2007-3389: wireshark - Wireshark before 0.99.6 allows remote attackers to cause a denial of service (cr...
Wireshark before 0.99.6 allows remote attackers to cause a denial of service (crash) via a crafted chunked encoding in an HTTP response, possibly related to a zero-length payload.
Scope: local
bookworm: resolved (fixed in 0.99.6pre1-1)
bullseye: resolved (fixed in 0.99.6pre1-1)
forky: resolved (fixed in 0.99.6pre1-1)
sid: resolved (fixed in 0.99.6pre1-1)
trixie: r
debian
CVE-2009-3242P4LOWCVSS 5.0PoCfixed in wireshark 1.2.2-1 (bookworm)2009
CVE-2009-3242 [MEDIUM] CVE-2009-3242: wireshark - Unspecified vulnerability in packet.c in the GSM A RR dissector in Wireshark 1.2...
Unspecified vulnerability in packet.c in the GSM A RR dissector in Wireshark 1.2.0 and 1.2.1 allows remote attackers to cause a denial of service (application crash) via unknown vectors related to "an uninitialized dissector handle," which triggers an assertion failure.
Scope: local
bookworm: resolved (fixed in 1.2.2-1)
bullseye: resolved (fixed in 1.2.2-1)
forky:
debian
CVE-2015-8732P4MEDIUMCVSS 5.5PoCfixed in wireshark 2.0.1+g59ea380-1 (bookworm)2015
CVE-2015-8732 [MEDIUM] CVE-2015-8732: wireshark - The dissect_zcl_pwr_prof_pwrprofstatersp function in epan/dissectors/packet-zbee...
The dissect_zcl_pwr_prof_pwrprofstatersp function in epan/dissectors/packet-zbee-zcl-general.c in the ZigBee ZCL dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the Total Profile Number field, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet.
Scope: local
debian
CVE-2015-8724P4LOWCVSS 5.5PoCfixed in wireshark 2.0.1+g59ea380-1 (bookworm)2015
CVE-2015-8724 [MEDIUM] CVE-2015-8724: wireshark - The AirPDcapDecryptWPABroadcastKey function in epan/crypt/airpdcap.c in the 802....
The AirPDcapDecryptWPABroadcastKey function in epan/crypt/airpdcap.c in the 802.11 dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not verify the WPA broadcast key length, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 2.0.
debian
CVE-2015-8731P4MEDIUMCVSS 5.5PoCfixed in wireshark 2.0.1+g59ea380-1 (bookworm)2015
CVE-2015-8731 [MEDIUM] CVE-2015-8731: wireshark - The dissct_rsl_ipaccess_msg function in epan/dissectors/packet-rsl.c in the RSL ...
The dissct_rsl_ipaccess_msg function in epan/dissectors/packet-rsl.c in the RSL dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not reject unknown TLV types, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 2.0.1+g59ea380-1)
debian
CVE-2015-8730P4MEDIUMCVSS 5.5PoCfixed in wireshark 2.0.1+g59ea380-1 (bookworm)2015
CVE-2015-8730 [MEDIUM] CVE-2015-8730: wireshark - epan/dissectors/packet-nbap.c in the NBAP dissector in Wireshark 1.12.x before 1...
epan/dissectors/packet-nbap.c in the NBAP dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the number of items, which allows remote attackers to cause a denial of service (invalid read operation and application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 2.0.1+g59ea380-1)
bullseye: resolved (fixed in 2
debian
CVE-2015-8735P4MEDIUMCVSS 5.5PoCfixed in wireshark 2.0.1+g59ea380-1 (bookworm)2015
CVE-2015-8735 [MEDIUM] CVE-2015-8735: wireshark - The get_value function in epan/dissectors/packet-btatt.c in the Bluetooth Attrib...
The get_value function in epan/dissectors/packet-btatt.c in the Bluetooth Attribute (aka BT ATT) dissector in Wireshark 2.0.x before 2.0.1 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (invalid write operation and application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 2.0.1+g59ea380-1)
b
debian
CVE-2011-1956P4LOWCVSS 4.3PoCfixed in wireshark 1.4.6-1 (bookworm)2011
CVE-2011-1956 [MEDIUM] CVE-2011-1956: wireshark - The bytes_repr_len function in Wireshark 1.4.5 uses an incorrect pointer argumen...
The bytes_repr_len function in Wireshark 1.4.5 uses an incorrect pointer argument, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via arbitrary TCP traffic.
Scope: local
bookworm: resolved (fixed in 1.4.6-1)
bullseye: resolved (fixed in 1.4.6-1)
forky: resolved (fixed in 1.4.6-1)
sid: resolved (fixed in
debian
CVE-2008-4682P4LOWCVSS 5.0PoCfixed in wireshark 1.0.4-1 (bookworm)2008
CVE-2008-4682 [MEDIUM] CVE-2008-4682: wireshark - wtap.c in Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a deni...
wtap.c in Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a denial of service (application abort) via a malformed Tamos CommView capture file (aka .ncf file) with an "unknown/unexpected packet type" that triggers a failed assertion.
Scope: local
bookworm: resolved (fixed in 1.0.4-1)
bullseye: resolved (fixed in 1.0.4-1)
forky: resolved (fixed in 1.
debian
CVE-2015-8726P4MEDIUMCVSS 5.5PoCfixed in wireshark 2.0.1+g59ea380-1 (bookworm)2015
CVE-2015-8726 [MEDIUM] CVE-2015-8726: wireshark - wiretap/vwr.c in the VeriWave file parser in Wireshark 1.12.x before 1.12.9 and ...
wiretap/vwr.c in the VeriWave file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate certain signature and Modulation and Coding Scheme (MCS) data, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file.
Scope: local
bookworm: resolved (fixed in 2.0.1+g59ea380-1)
bull
debian
CVE-2015-8733P4MEDIUMCVSS 5.5PoCfixed in wireshark 2.0.1+g59ea380-1 (bookworm)2015
CVE-2015-8733 [MEDIUM] CVE-2015-8733: wireshark - The ngsniffer_process_record function in wiretap/ngsniffer.c in the Sniffer file...
The ngsniffer_process_record function in wiretap/ngsniffer.c in the Sniffer file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the relationships between record lengths and record header lengths, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file.
Scope: local
debian