cbcvebase.

Debian Wireshark vulnerabilities

668 known vulnerabilities affecting debian/wireshark.

Total CVEs
668
CISA KEV
0
Public exploits
50
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH129MEDIUM276LOW255

Vulnerabilities

Page 21 of 34
CVE-2014-8710P4MEDIUMCVSS 5.0fixed in wireshark 1.12.1+g01b65bf-2 (bookworm)2014
CVE-2014-8710 [MEDIUM] CVE-2014-8710: wireshark - The decompress_sigcomp_message function in epan/sigcomp-udvm.c in the SigComp UD... The decompress_sigcomp_message function in epan/sigcomp-udvm.c in the SigComp UDVM dissector in Wireshark 1.10.x before 1.10.11 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in 1.12.1+g01b65bf-2) bullseye: resolved (fixed in 1.12.1+g01b65bf-2) forky: resolv
debian
CVE-2014-6430P4MEDIUMCVSS 5.0fixed in wireshark 1.12.1+g01b65bf-1 (bookworm)2014
CVE-2014-6430 [MEDIUM] CVE-2014-6430: wireshark - The SnifferDecompress function in wiretap/ngsniffer.c in the DOS Sniffer file pa... The SnifferDecompress function in wiretap/ngsniffer.c in the DOS Sniffer file parser in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 does not validate bitmask data, which allows remote attackers to cause a denial of service (application crash) via a crafted file. Scope: local bookworm: resolved (fixed in 1.12.1+g01b65bf-1) bullseye: resolved (fixed in
debian
CVE-2014-6429P4MEDIUMCVSS 5.0fixed in wireshark 1.12.1+g01b65bf-1 (bookworm)2014
CVE-2014-6429 [MEDIUM] CVE-2014-6429: wireshark - The SnifferDecompress function in wiretap/ngsniffer.c in the DOS Sniffer file pa... The SnifferDecompress function in wiretap/ngsniffer.c in the DOS Sniffer file parser in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 does not properly handle empty input data, which allows remote attackers to cause a denial of service (application crash) via a crafted file. Scope: local bookworm: resolved (fixed in 1.12.1+g01b65bf-1) bullseye: resolved
debian
CVE-2013-4923P4MEDIUMCVSS 5.0fixed in wireshark 1.10.1-1 (bookworm)2013
CVE-2013-4923 [MEDIUM] CVE-2013-4923: wireshark - Memory leak in the dissect_dcom_ActivationProperties function in epan/dissectors... Memory leak in the dissect_dcom_ActivationProperties function in epan/dissectors/packet-dcom-sysact.c in the DCOM ISystemActivator dissector in Wireshark 1.10.x before 1.10.1 allows remote attackers to cause a denial of service (memory consumption) via crafted packets. Scope: local bookworm: resolved (fixed in 1.10.1-1) bullseye: resolved (fixed in 1.10.1-1) forky
debian
CVE-2014-6424P4MEDIUMCVSS 5.0fixed in wireshark 1.12.1+g01b65bf-1 (bookworm)2014
CVE-2014-6424 [MEDIUM] CVE-2014-6424: wireshark - The dissect_v9_v10_pdu_data function in epan/dissectors/packet-netflow.c in the ... The dissect_v9_v10_pdu_data function in epan/dissectors/packet-netflow.c in the Netflow dissector in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 refers to incorrect offset and start variables, which allows remote attackers to cause a denial of service (uninitialized memory read and application crash) via a crafted packet. Scope: local bookworm: resolv
debian
CVE-2012-6062P4LOWCVSS 5.0fixed in wireshark 1.8.6-1 (bookworm)2012
CVE-2012-6062 [MEDIUM] CVE-2012-6062: wireshark - The dissect_rtcp_app function in epan/dissectors/packet-rtcp.c in the RTCP disse... The dissect_rtcp_app function in epan/dissectors/packet-rtcp.c in the RTCP dissector in Wireshark 1.6.x before 1.6.12 and 1.8.x before 1.8.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet. Scope: local bookworm: resolved (fixed in 1.8.6-1) bullseye: resolved (fixed in 1.8.6-1) forky: resolved (fixed in 1.8.6-1) sid: resol
debian
CVE-2014-5165P4MEDIUMCVSS 5.0fixed in wireshark 1.12.0+git+4fab41a1-1 (bookworm)2014
CVE-2014-5165 [MEDIUM] CVE-2014-5165: wireshark - The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber.c i... The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.10.x before 1.10.9 does not properly validate padding values, which allows remote attackers to cause a denial of service (buffer underflow and application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in 1.12.0+git+4fab41a1
debian
CVE-2012-6054P4LOWCVSS 5.0fixed in wireshark 1.8.6-1 (bookworm)2012
CVE-2012-6054 [MEDIUM] CVE-2012-6054: wireshark - The dissect_sflow_245_address_type function in epan/dissectors/packet-sflow.c in... The dissect_sflow_245_address_type function in epan/dissectors/packet-sflow.c in the sFlow dissector in Wireshark 1.8.x before 1.8.4 does not properly handle length calculations for an invalid IP address type, which allows remote attackers to cause a denial of service (infinite loop) via a packet that is neither IPv4 nor IPv6. Scope: local bookworm: resolved (fixe
debian
CVE-2012-6061P4LOWCVSS 5.0fixed in wireshark 1.8.6-1 (bookworm)2012
CVE-2012-6061 [MEDIUM] CVE-2012-6061: wireshark - The dissect_wtp_common function in epan/dissectors/packet-wtp.c in the WTP disse... The dissect_wtp_common function in epan/dissectors/packet-wtp.c in the WTP dissector in Wireshark 1.6.x before 1.6.12 and 1.8.x before 1.8.4 uses an incorrect data type for a certain length field, which allows remote attackers to cause a denial of service (integer overflow and infinite loop) via a crafted value in a packet. Scope: local bookworm: resolved (fixed i
debian
CVE-2015-0562P4MEDIUMCVSS 5.0fixed in wireshark 1.12.1+g01b65bf-3 (bookworm)2015
CVE-2015-0562 [MEDIUM] CVE-2015-0562: wireshark - Multiple use-after-free vulnerabilities in epan/dissectors/packet-dec-dnart.c in... Multiple use-after-free vulnerabilities in epan/dissectors/packet-dec-dnart.c in the DEC DNA Routing Protocol dissector in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 allow remote attackers to cause a denial of service (application crash) via a crafted packet, related to the use of packet-scope memory instead of pinfo-scope memory. Scope: local bookwo
debian
CVE-2015-2192P4MEDIUMCVSS 5.0fixed in wireshark 1.12.1+g01b65bf-4 (bookworm)2015
CVE-2015-2192 [MEDIUM] CVE-2015-2192: wireshark - Integer overflow in the dissect_osd2_cdb_continuation function in epan/dissector... Integer overflow in the dissect_osd2_cdb_continuation function in epan/dissectors/packet-scsi-osd.c in the SCSI OSD dissector in Wireshark 1.12.x before 1.12.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted length field in a packet. Scope: local bookworm: resolved (fixed in 1.12.1+g01b65bf-4) bullseye: resolved (fixed in 1.12.1+
debian
CVE-2013-6339P4LOWCVSS 4.3fixed in wireshark 1.10.3-1 (bookworm)2013
CVE-2013-6339 [MEDIUM] CVE-2013-6339: wireshark - The dissect_openwire_type function in epan/dissectors/packet-openwire.c in the O... The dissect_openwire_type function in epan/dissectors/packet-openwire.c in the OpenWire dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 allows remote attackers to cause a denial of service (loop) via a crafted packet. Scope: local bookworm: resolved (fixed in 1.10.3-1) bullseye: resolved (fixed in 1.10.3-1) forky: resolved (fixed in 1.10.3-1) s
debian
CVE-2022-3190P4MEDIUMCVSS 6.3fixed in wireshark 3.6.8-1 (bookworm)2022
CVE-2022-3190 [MEDIUM] CVE-2022-3190: wireshark - Infinite loop in the F5 Ethernet Trailer protocol dissector in Wireshark 3.6.0 t... Infinite loop in the F5 Ethernet Trailer protocol dissector in Wireshark 3.6.0 to 3.6.7 and 3.4.0 to 3.4.15 allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved (fixed in 3.6.8-1) bullseye: resolved (fixed in 3.4.16-0+deb11u1) forky: resolved (fixed in 3.6.8-1) sid: resolved (fixed in 3.6.8-1) trixie: resolved (fixe
debian
CVE-2013-4076P4MEDIUMCVSS 5.0fixed in wireshark 1.10.0-1 (bookworm)2013
CVE-2013-4076 [MEDIUM] CVE-2013-4076: wireshark - Buffer overflow in the dissect_iphc_crtp_fh function in epan/dissectors/packet-p... Buffer overflow in the dissect_iphc_crtp_fh function in epan/dissectors/packet-ppp.c in the PPP dissector in Wireshark 1.8.x before 1.8.8 allows remote attackers to cause a denial of service (application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in 1.10.0-1) bullseye: resolved (fixed in 1.10.0-1) forky: resolved (fixed in 1.10.0-1) sid: r
debian
CVE-2012-5240P4MEDIUMCVSS 5.8fixed in wireshark 1.8.2-2 (bookworm)2012
CVE-2012-5240 [MEDIUM] CVE-2012-5240: wireshark - Buffer overflow in the dissect_tlv function in epan/dissectors/packet-ldp.c in t... Buffer overflow in the dissect_tlv function in epan/dissectors/packet-ldp.c in the LDP dissector in Wireshark 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a malformed packet. Scope: local bookworm: resolved (fixed in 1.8.2-2) bullseye: resolved (fixed in 1.8.2-2) forky: re
debian
CVE-2013-3557P4LOWCVSS 5.0fixed in wireshark 1.8.7-1 (bookworm)2013
CVE-2013-3557 [MEDIUM] CVE-2013-3557: wireshark - The dissect_ber_choice function in epan/dissectors/packet-ber.c in the ASN.1 BER... The dissect_ber_choice function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.6.x before 1.6.15 and 1.8.x before 1.8.7 does not properly initialize a certain variable, which allows remote attackers to cause a denial of service (application crash) via a malformed packet. Scope: local bookworm: resolved (fixed in 1.8.7-1) bullseye: resolv
debian
CVE-2013-3559P4MEDIUMCVSS 5.0fixed in wireshark 1.8.7-1 (bookworm)2013
CVE-2013-3559 [MEDIUM] CVE-2013-3559: wireshark - epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark 1.8.x b... epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark 1.8.x before 1.8.7 uses incorrect integer data types, which allows remote attackers to cause a denial of service (integer overflow, and heap memory corruption or NULL pointer dereference, and application crash) via a malformed packet. Scope: local bookworm: resolved (fixed in 1.8.7-1) bullsey
debian
CVE-2014-5163P4MEDIUMCVSS 5.0fixed in wireshark 1.12.0+git+4fab41a1-1 (bookworm)2014
CVE-2014-5163 [MEDIUM] CVE-2014-5163: wireshark - The APN decode functionality in (1) epan/dissectors/packet-gtp.c and (2) epan/di... The APN decode functionality in (1) epan/dissectors/packet-gtp.c and (2) epan/dissectors/packet-gsm_a_gm.c in the GTP and GSM Management dissectors in Wireshark 1.10.x before 1.10.9 does not completely initialize a certain buffer, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. Scope: local bookworm: resolved (f
debian
CVE-2013-4075P4MEDIUMCVSS 5.0fixed in wireshark 1.10.0-1 (bookworm)2013
CVE-2013-4075 [MEDIUM] CVE-2013-4075: wireshark - epan/dissectors/packet-gmr1_bcch.c in the GMR-1 BCCH dissector in Wireshark 1.8.... epan/dissectors/packet-gmr1_bcch.c in the GMR-1 BCCH dissector in Wireshark 1.8.x before 1.8.8 does not properly initialize memory, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in 1.10.0-1) bullseye: resolved (fixed in 1.10.0-1) forky: resolved (fixed in 1.10.0-1) sid: r
debian
CVE-2014-6432P4MEDIUMCVSS 5.0fixed in wireshark 1.12.1+g01b65bf-1 (bookworm)2014
CVE-2014-6432 [MEDIUM] CVE-2014-6432: wireshark - The SnifferDecompress function in wiretap/ngsniffer.c in the DOS Sniffer file pa... The SnifferDecompress function in wiretap/ngsniffer.c in the DOS Sniffer file parser in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 does not prevent data overwrites during copy operations, which allows remote attackers to cause a denial of service (application crash) via a crafted file. Scope: local bookworm: resolved (fixed in 1.12.1+g01b65bf-1) bull
debian
Debian Wireshark vulnerabilities | cvebase