cbcvebase.

Debian Wireshark vulnerabilities

668 known vulnerabilities affecting debian/wireshark.

Total CVEs
668
CISA KEV
0
Public exploits
50
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH129MEDIUM276LOW255

Vulnerabilities

Page 20 of 34
CVE-2013-4080P4LOWCVSS 5.0fixed in wireshark 1.10.0-1 (bookworm)2013
CVE-2013-4080 [MEDIUM] CVE-2013-4080: wireshark - The dissect_r3_upstreamcommand_queryconfig function in epan/dissectors/packet-as... The dissect_r3_upstreamcommand_queryconfig function in epan/dissectors/packet-assa_r3.c in the Assa Abloy R3 dissector in Wireshark 1.8.x before 1.8.8 does not properly handle a zero-length item, which allows remote attackers to cause a denial of service (infinite loop, and CPU and memory consumption) via a crafted packet. Scope: local bookworm: resolved (fixed in
debian
CVE-2013-4925P4MEDIUMCVSS 5.0fixed in wireshark 1.10.1-1 (bookworm)2013
CVE-2013-4925 [MEDIUM] CVE-2013-4925: wireshark - Integer signedness error in epan/dissectors/packet-dcom-sysact.c in the DCOM ISy... Integer signedness error in epan/dissectors/packet-dcom-sysact.c in the DCOM ISystemActivator dissector in Wireshark 1.10.x before 1.10.1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted packet. Scope: local bookworm: resolved (fixed in 1.10.1-1) bullseye: resolved (fixed in 1.10.1-1) forky: resolved (fixed in
debian
CVE-2015-0564P4MEDIUMCVSS 5.0fixed in wireshark 1.12.1+g01b65bf-3 (bookworm)2015
CVE-2015-0564 [MEDIUM] CVE-2015-0564: wireshark - Buffer underflow in the ssl_decrypt_record function in epan/dissectors/packet-ss... Buffer underflow in the ssl_decrypt_record function in epan/dissectors/packet-ssl-utils.c in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 allows remote attackers to cause a denial of service (application crash) via a crafted packet that is improperly handled during decryption of an SSL session. Scope: local bookworm: resolved (fixed in 1.12.1+g01b65bf-
debian
CVE-2015-2187P4MEDIUMCVSS 5.0fixed in wireshark 1.12.1+g01b65bf-4 (bookworm)2015
CVE-2015-2187 [MEDIUM] CVE-2015-2187: wireshark - The dissect_atn_cpdlc_heur function in asn1/atn-cpdlc/packet-atn-cpdlc-template.... The dissect_atn_cpdlc_heur function in asn1/atn-cpdlc/packet-atn-cpdlc-template.c in the ATN-CPDLC dissector in Wireshark 1.12.x before 1.12.4 does not properly follow the TRY/ENDTRY code requirements, which allows remote attackers to cause a denial of service (stack memory corruption and application crash) via a crafted packet. Scope: local bookworm: resolved (fi
debian
CVE-2014-6426P4MEDIUMCVSS 5.0fixed in wireshark 1.12.1+g01b65bf-1 (bookworm)2014
CVE-2014-6426 [MEDIUM] CVE-2014-6426: wireshark - The dissect_hip_tlv function in epan/dissectors/packet-hip.c in the HIP dissecto... The dissect_hip_tlv function in epan/dissectors/packet-hip.c in the HIP dissector in Wireshark 1.12.x before 1.12.1 does not properly handle a NULL tree, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet. Scope: local bookworm: resolved (fixed in 1.12.1+g01b65bf-1) bullseye: resolved (fixed in 1.12.1+g01b65bf-1) forky:
debian
CVE-2009-2563P4HIGHCVSS 7.1fixed in wireshark 1.2.1-1 (bookworm)2009
CVE-2009-2563 [HIGH] CVE-2009-2563: wireshark - Unspecified vulnerability in the Infiniband dissector in Wireshark 1.0.6 through... Unspecified vulnerability in the Infiniband dissector in Wireshark 1.0.6 through 1.2.0, when running on unspecified platforms, allows remote attackers to cause a denial of service (crash) via unknown vectors. Scope: local bookworm: resolved (fixed in 1.2.1-1) bullseye: resolved (fixed in 1.2.1-1) forky: resolved (fixed in 1.2.1-1) sid: resolved (fixed in 1.2.1-1) tr
debian
CVE-2020-7045P4MEDIUMCVSS 6.5fixed in wireshark 3.2.0-1 (bookworm)2020
CVE-2020-7045 [MEDIUM] CVE-2020-7045: wireshark - In Wireshark 3.0.x before 3.0.8, the BT ATT dissector could crash. This was addr... In Wireshark 3.0.x before 3.0.8, the BT ATT dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by validating opcodes. Scope: local bookworm: resolved (fixed in 3.2.0-1) bullseye: resolved (fixed in 3.2.0-1) forky: resolved (fixed in 3.2.0-1) sid: resolved (fixed in 3.2.0-1) trixie: resolved (fixed in 3.2.0-1)
debian
CVE-2016-5358P4MEDIUMCVSS 5.9fixed in wireshark 2.0.4+gdd7746e-1 (bookworm)2016
CVE-2016-5358 [MEDIUM] CVE-2016-5358: wireshark - epan/dissectors/packet-pktap.c in the Ethernet dissector in Wireshark 2.x before... epan/dissectors/packet-pktap.c in the Ethernet dissector in Wireshark 2.x before 2.0.4 mishandles the packet-header data type, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in 2.0.4+gdd7746e-1) bullseye: resolved (fixed in 2.0.4+gdd7746e-1) forky: resolved (fixed in 2.0.4
debian
CVE-2016-7180P4MEDIUMCVSS 5.9fixed in wireshark 2.2.0~rc1+g438c022-1 (bookworm)2016
CVE-2016-7180 [MEDIUM] CVE-2016-7180: wireshark - epan/dissectors/packet-ipmi-trace.c in the IPMI trace dissector in Wireshark 2.x... epan/dissectors/packet-ipmi-trace.c in the IPMI trace dissector in Wireshark 2.x before 2.0.6 does not properly consider whether a string is constant, which allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in 2.2.0~rc1+g438c022-1) bullseye: resolved (fixed in 2.
debian
CVE-2016-6513P4MEDIUMCVSS 5.9fixed in wireshark 2.0.5+ga3be9c6-1 (bookworm)2016
CVE-2016-6513 [MEDIUM] CVE-2016-6513: wireshark - epan/dissectors/packet-wbxml.c in the WBXML dissector in Wireshark 2.x before 2.... epan/dissectors/packet-wbxml.c in the WBXML dissector in Wireshark 2.x before 2.0.5 does not restrict the recursion depth, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in 2.0.5+ga3be9c6-1) bullseye: resolved (fixed in 2.0.5+ga3be9c6-1) forky: resolved (fixed in 2.0.5+ga3
debian
CVE-2016-4084P4LOWCVSS 5.9fixed in wireshark 2.0.3+geed34f0-1 (bookworm)2016
CVE-2016-4084 [MEDIUM] CVE-2016-4084: wireshark - Integer signedness error in epan/dissectors/packet-mswsp.c in the MS-WSP dissect... Integer signedness error in epan/dissectors/packet-mswsp.c in the MS-WSP dissector in Wireshark 2.0.x before 2.0.3 allows remote attackers to cause a denial of service (integer overflow and application crash) via a crafted packet that triggers an unexpected array size. Scope: local bookworm: resolved (fixed in 2.0.3+geed34f0-1) bullseye: resolved (fixed in 2.0.3+g
debian
CVE-2020-26419P4LOWCVSS 3.1fixed in wireshark 3.4.1-1 (bookworm)2020
CVE-2020-26419 [LOW] CVE-2020-26419: wireshark - Memory leak in the dissection engine in Wireshark 3.4.0 allows denial of service... Memory leak in the dissection engine in Wireshark 3.4.0 allows denial of service via packet injection or crafted capture file. Scope: local bookworm: resolved (fixed in 3.4.1-1) bullseye: resolved (fixed in 3.4.1-1) forky: resolved (fixed in 3.4.1-1) sid: resolved (fixed in 3.4.1-1) trixie: resolved (fixed in 3.4.1-1)
debian
CVE-2016-4076P4LOWCVSS 5.9fixed in wireshark 2.0.3+geed34f0-1 (bookworm)2016
CVE-2016-4076 [MEDIUM] CVE-2016-4076: wireshark - epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 2.0.x befor... epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 2.0.x before 2.0.3 does not properly initialize memory for search patterns, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in 2.0.3+geed34f0-1) bullseye: resolved (fixed in 2.0.3+geed34f0-1) forky: resolv
debian
CVE-2020-26420P4LOWCVSS 3.1fixed in wireshark 3.4.1-1 (bookworm)2020
CVE-2020-26420 [LOW] CVE-2020-26420: wireshark - Memory leak in RTPS protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 all... Memory leak in RTPS protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file. Scope: local bookworm: resolved (fixed in 3.4.1-1) bullseye: resolved (fixed in 3.4.1-1) forky: resolved (fixed in 3.4.1-1) sid: resolved (fixed in 3.4.1-1) trixie: resolved (fixed in 3.4.1-1)
debian
CVE-2016-4417P4MEDIUMCVSS 5.9fixed in wireshark 2.0.2+ga16e22e-1 (bookworm)2016
CVE-2016-4417 [MEDIUM] CVE-2016-4417: wireshark - Off-by-one error in epan/dissectors/packet-gsm_abis_oml.c in the GSM A-bis OML d... Off-by-one error in epan/dissectors/packet-gsm_abis_oml.c in the GSM A-bis OML dissector in Wireshark 1.12.x before 1.12.10 and 2.x before 2.0.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet that triggers a 0xff tag value. Scope: local bookworm: resolved (fixed in 2.0.2+ga16e22e-1) bullseye: reso
debian
CVE-2016-4418P4MEDIUMCVSS 5.9fixed in wireshark 2.0.2+ga16e22e-1 (bookworm)2016
CVE-2016-4418 [MEDIUM] CVE-2016-4418: wireshark - epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.12.x befo... epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.12.x before 1.12.10 and 2.x before 2.0.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet that triggers an empty set. Scope: local bookworm: resolved (fixed in 2.0.2+ga16e22e-1) bullseye: resolved (fixed in 2.0.2+ga16e22e-1) fork
debian
CVE-2016-7175P4MEDIUMCVSS 5.9fixed in wireshark 2.2.0~rc1+g438c022-1 (bookworm)2016
CVE-2016-7175 [MEDIUM] CVE-2016-7175: wireshark - epan/dissectors/packet-qnet6.c in the QNX6 QNET dissector in Wireshark 2.x befor... epan/dissectors/packet-qnet6.c in the QNX6 QNET dissector in Wireshark 2.x before 2.0.6 mishandles MAC address data, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in 2.2.0~rc1+g438c022-1) bullseye: resolved (fixed in 2.2.0~rc1+g438c022-1) forky: res
debian
CVE-2015-4651P4MEDIUMCVSS 5.0fixed in wireshark 1.12.6+gee1fce6-1 (bookworm)2015
CVE-2015-4651 [MEDIUM] CVE-2015-4651: wireshark - The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c... The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.12.x before 1.12.6 does not properly determine whether enough memory is available for storing IP address strings, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. Scope: local bookworm: resolved (
debian
CVE-2013-4083P4MEDIUMCVSS 5.0fixed in wireshark 1.10.0-1 (bookworm)2013
CVE-2013-4083 [MEDIUM] CVE-2013-4083: wireshark - The dissect_pft function in epan/dissectors/packet-dcp-etsi.c in the DCP ETSI di... The dissect_pft function in epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark 1.6.x before 1.6.16, 1.8.x before 1.8.8, and 1.10.0 does not validate a certain fragment length value, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in 1.10.0-1) bullseye:
debian
CVE-2014-6428P4MEDIUMCVSS 5.0fixed in wireshark 1.12.1+g01b65bf-1 (bookworm)2014
CVE-2014-6428 [MEDIUM] CVE-2014-6428: wireshark - The dissect_spdu function in epan/dissectors/packet-ses.c in the SES dissector i... The dissect_spdu function in epan/dissectors/packet-ses.c in the SES dissector in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 does not initialize a certain ID value, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in 1.12.1+g01b65bf-1) bullseye: resolved (fixed
debian
Debian Wireshark vulnerabilities | cvebase