Debian Wireshark vulnerabilities
668 known vulnerabilities affecting debian/wireshark.
Total CVEs
668
CISA KEV
0
Public exploits
50
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH129MEDIUM276LOW255
Vulnerabilities
Page 22 of 34
CVE-2013-4079P4LOWCVSS 5.0fixed in wireshark 1.10.0-1 (bookworm)2013
CVE-2013-4079 [MEDIUM] CVE-2013-4079: wireshark - The dissect_schedule_message function in epan/dissectors/packet-gsm_cbch.c in th...
The dissect_schedule_message function in epan/dissectors/packet-gsm_cbch.c in the GSM CBCH dissector in Wireshark 1.8.x before 1.8.8 allows remote attackers to cause a denial of service (infinite loop and application hang) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 1.10.0-1)
bullseye: resolved (fixed in 1.10.0-1)
forky: resolved (fixed in 1.10
debian
CVE-2013-4926P4MEDIUMCVSS 5.0fixed in wireshark 1.10.1-1 (bookworm)2013
CVE-2013-4926 [MEDIUM] CVE-2013-4926: wireshark - epan/dissectors/packet-dcom-sysact.c in the DCOM ISystemActivator dissector in W...
epan/dissectors/packet-dcom-sysact.c in the DCOM ISystemActivator dissector in Wireshark 1.10.x before 1.10.1 does not properly determine whether there is remaining packet data to process, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 1.10.1-1)
bullseye: resolved (fixe
debian
CVE-2013-5720P4MEDIUMCVSS 5.0fixed in wireshark 1.10.2-1 (bookworm)2013
CVE-2013-5720 [MEDIUM] CVE-2013-5720: wireshark - Buffer overflow in the RTPS dissector in Wireshark 1.8.x before 1.8.10 and 1.10....
Buffer overflow in the RTPS dissector in Wireshark 1.8.x before 1.8.10 and 1.10.x before 1.10.2 allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 1.10.2-1)
bullseye: resolved (fixed in 1.10.2-1)
forky: resolved (fixed in 1.10.2-1)
sid: resolved (fixed in 1.10.2-1)
trixie: resolv
debian
CVE-2015-8715P4MEDIUMCVSS 5.5fixed in wireshark 2.0.1+g59ea380-1 (bookworm)2015
CVE-2015-8715 [MEDIUM] CVE-2015-8715: wireshark - epan/dissectors/packet-alljoyn.c in the AllJoyn dissector in Wireshark 1.12.x be...
epan/dissectors/packet-alljoyn.c in the AllJoyn dissector in Wireshark 1.12.x before 1.12.9 does not check for empty arguments, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 2.0.1+g59ea380-1)
bullseye: resolved (fixed in 2.0.1+g59ea380-1)
forky: resolved (fixed in 2.0.1+g5
debian
CVE-2012-6057P4LOWCVSS 5.0fixed in wireshark 1.8.6-1 (bookworm)2012
CVE-2012-6057 [MEDIUM] CVE-2012-6057: wireshark - The dissect_eigrp_metric_comm function in epan/dissectors/packet-eigrp.c in the ...
The dissect_eigrp_metric_comm function in epan/dissectors/packet-eigrp.c in the EIGRP dissector in Wireshark 1.8.x before 1.8.4 uses the wrong data type for a certain offset value, which allows remote attackers to cause a denial of service (integer overflow and infinite loop) via a malformed packet.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: reso
debian
CVE-2012-6060P4LOWCVSS 5.0fixed in wireshark 1.8.6-1 (bookworm)2012
CVE-2012-6060 [MEDIUM] CVE-2012-6060: wireshark - Integer overflow in the dissect_iscsi_pdu function in epan/dissectors/packet-isc...
Integer overflow in the dissect_iscsi_pdu function in epan/dissectors/packet-iscsi.c in the iSCSI dissector in Wireshark 1.6.x before 1.6.12 and 1.8.x before 1.8.4 allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fix
debian
CVE-2019-9209P4MEDIUMCVSS 5.5fixed in wireshark 2.6.7-1 (bookworm)2019
CVE-2019-9209 [MEDIUM] CVE-2019-9209: wireshark - In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related disse...
In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash. This was addressed in epan/dissectors/packet-ber.c by preventing a buffer overflow associated with excessive digits in time values.
Scope: local
bookworm: resolved (fixed in 2.6.7-1)
bullseye: resolved (fixed in 2.6.7-1)
forky: resolved (fixed in 2.6.7-1)
sid: resolv
debian
CVE-2015-3815P4MEDIUMCVSS 5.0fixed in wireshark 1.12.5+g5819e5b-1 (bookworm)2015
CVE-2015-3815 [MEDIUM] CVE-2015-3815: wireshark - The detect_version function in wiretap/logcat.c in the Android Logcat file parse...
The detect_version function in wiretap/logcat.c in the Android Logcat file parser in Wireshark 1.12.x before 1.12.5 does not check the length of the payload, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a packet with a crafted payload, as demonstrated by a length of zero, a different vulnerability than C
debian
CVE-2014-5161P4MEDIUMCVSS 5.0fixed in wireshark 1.12.0+git+4fab41a1-1 (bookworm)2014
CVE-2014-5161 [MEDIUM] CVE-2014-5161: wireshark - The dissect_log function in plugins/irda/packet-irda.c in the IrDA dissector in ...
The dissect_log function in plugins/irda/packet-irda.c in the IrDA dissector in Wireshark 1.10.x before 1.10.9 does not properly strip '\n' characters, which allows remote attackers to cause a denial of service (buffer underflow and application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 1.12.0+git+4fab41a1-1)
bullseye: resolved (fixed i
debian
CVE-2015-0563P4MEDIUMCVSS 5.0fixed in wireshark 1.12.1+g01b65bf-3 (bookworm)2015
CVE-2015-0563 [MEDIUM] CVE-2015-0563: wireshark - epan/dissectors/packet-smtp.c in the SMTP dissector in Wireshark 1.10.x before 1...
epan/dissectors/packet-smtp.c in the SMTP dissector in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 uses an incorrect length value for certain string-append operations, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 1.12.1+g01b65bf-3)
bullseye: resolved (fix
debian
CVE-2015-3906P4MEDIUMCVSS 5.0fixed in wireshark 1.12.5+g5819e5b-1 (bookworm)2015
CVE-2015-3906 [MEDIUM] CVE-2015-3906: wireshark - The logcat_dump_text function in wiretap/logcat.c in the Android Logcat file par...
The logcat_dump_text function in wiretap/logcat.c in the Android Logcat file parser in Wireshark 1.12.x before 1.12.5 does not properly handle a lack of \0 termination, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted message in a packet, a different vulnerability than CVE-2015-3815.
Scope: local
b
debian
CVE-2015-0560P4MEDIUMCVSS 5.0fixed in wireshark 1.12.1+g01b65bf-3 (bookworm)2015
CVE-2015-0560 [MEDIUM] CVE-2015-0560: wireshark - The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c...
The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 does not initialize certain data structures, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 1.12.1+g01b65bf
debian
CVE-2015-6245P4MEDIUMCVSS 4.3fixed in wireshark 1.12.7+g7fc8978-1 (bookworm)2015
CVE-2015-6245 [MEDIUM] CVE-2015-6245: wireshark - epan/dissectors/packet-gsm_rlcmac.c in the GSM RLC/MAC dissector in Wireshark 1....
epan/dissectors/packet-gsm_rlcmac.c in the GSM RLC/MAC dissector in Wireshark 1.12.x before 1.12.7 uses incorrect integer data types, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 1.12.7+g7fc8978-1)
bullseye: resolved (fixed in 1.12.7+g7fc8978-1)
forky: resolved (fixed in
debian
CVE-2015-6247P4MEDIUMCVSS 4.3fixed in wireshark 1.12.7+g7fc8978-1 (bookworm)2015
CVE-2015-6247 [MEDIUM] CVE-2015-6247: wireshark - The dissect_openflow_tablemod_v5 function in epan/dissectors/packet-openflow_v5....
The dissect_openflow_tablemod_v5 function in epan/dissectors/packet-openflow_v5.c in the OpenFlow dissector in Wireshark 1.12.x before 1.12.7 does not validate a certain offset value, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 1.12.7+g7fc8978-1)
bullseye: resolved (fixe
debian
CVE-2013-5719P4LOWCVSS 4.3fixed in wireshark 1.10.2-1 (bookworm)2013
CVE-2013-5719 [MEDIUM] CVE-2013-5719: wireshark - epan/dissectors/packet-assa_r3.c in the ASSA R3 dissector in Wireshark 1.8.x bef...
epan/dissectors/packet-assa_r3.c in the ASSA R3 dissector in Wireshark 1.8.x before 1.8.10 and 1.10.x before 1.10.2 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 1.10.2-1)
bullseye: resolved (fixed in 1.10.2-1)
forky: resolved (fixed in 1.10.2-1)
sid: resolved (fixed in 1.10.2-1
debian
CVE-2015-8713P4MEDIUMCVSS 5.5fixed in wireshark 2.0.1+g59ea380-1 (bookworm)2015
CVE-2015-8713 [MEDIUM] CVE-2015-8713: wireshark - epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 1.12.x be...
epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 1.12.x before 1.12.9 does not properly reserve memory for channel ID mappings, which allows remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 2.0.1+g59ea380-1)
bullseye: resolved (fix
debian
CVE-2013-2486P4LOWCVSS 6.1fixed in wireshark 1.8.6-1 (bookworm)2013
CVE-2013-2486 [MEDIUM] CVE-2013-2486: wireshark - The dissect_diagnosticrequest function in epan/dissectors/packet-reload.c in the...
The dissect_diagnosticrequest function in epan/dissectors/packet-reload.c in the REsource LOcation And Discovery (aka RELOAD) dissector in Wireshark 1.8.x before 1.8.6 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (infinite loop) via crafted integer values in a packet.
Scope: local
bookworm: resolved (fixed in 1.8.
debian
CVE-2016-4420P4MEDIUMCVSS 5.9fixed in wireshark 2.0.2+ga16e22e-1 (bookworm)2016
CVE-2016-4420 [MEDIUM] CVE-2016-4420: wireshark - The NFS dissector in Wireshark 2.x before 2.0.2 allows remote attackers to cause...
The NFS dissector in Wireshark 2.x before 2.0.2 allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 2.0.2+ga16e22e-1)
bullseye: resolved (fixed in 2.0.2+ga16e22e-1)
forky: resolved (fixed in 2.0.2+ga16e22e-1)
sid: resolved (fixed in 2.0.2+ga16e22e-1)
trixie: resolved (fixed in 2.0
debian
CVE-2013-4078P4MEDIUMCVSS 5.0fixed in wireshark 1.10.0-1 (bookworm)2013
CVE-2013-4078 [MEDIUM] CVE-2013-4078: wireshark - epan/dissectors/packet-rdp.c in the RDP dissector in Wireshark 1.8.x before 1.8....
epan/dissectors/packet-rdp.c in the RDP dissector in Wireshark 1.8.x before 1.8.8 does not validate return values during checks for data availability, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 1.10.0-1)
bullseye: resolved (fixed in 1.10.0-1)
forky: resolved (fixed
debian
CVE-2013-4933P4MEDIUMCVSS 5.0fixed in wireshark 1.10.1-1 (bookworm)2013
CVE-2013-4933 [MEDIUM] CVE-2013-4933: wireshark - The netmon_open function in wiretap/netmon.c in the Netmon file parser in Wiresh...
The netmon_open function in wiretap/netmon.c in the Netmon file parser in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 does not properly allocate memory, which allows remote attackers to cause a denial of service (application crash) via a crafted packet-trace file.
Scope: local
bookworm: resolved (fixed in 1.10.1-1)
bullseye: resolved (fixed in 1.10.1-1)
debian