cbcvebase.

Debian Wireshark vulnerabilities

668 known vulnerabilities affecting debian/wireshark.

Total CVEs
668
CISA KEV
0
Public exploits
50
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH129MEDIUM276LOW255

Vulnerabilities

Page 23 of 34
CVE-2014-6422P4MEDIUMCVSS 5.0fixed in wireshark 1.12.0+git+4fab41a1-1 (bookworm)2014
CVE-2014-6422 [MEDIUM] CVE-2014-6422: wireshark - The SDP dissector in Wireshark 1.10.x before 1.10.10 creates duplicate hashtable... The SDP dissector in Wireshark 1.10.x before 1.10.10 creates duplicate hashtables for a media channel, which allows remote attackers to cause a denial of service (application crash) via a crafted packet to the RTP dissector. Scope: local bookworm: resolved (fixed in 1.12.0+git+4fab41a1-1) bullseye: resolved (fixed in 1.12.0+git+4fab41a1-1) forky: resolved (fixed i
debian
CVE-2013-4922P4MEDIUMCVSS 5.0fixed in wireshark 1.10.1-1 (bookworm)2013
CVE-2013-4922 [MEDIUM] CVE-2013-4922: wireshark - Double free vulnerability in the dissect_dcom_ActivationProperties function in e... Double free vulnerability in the dissect_dcom_ActivationProperties function in epan/dissectors/packet-dcom-sysact.c in the DCOM ISystemActivator dissector in Wireshark 1.10.x before 1.10.1 allows remote attackers to cause a denial of service (application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in 1.10.1-1) bullseye: resolved (fixed in 1
debian
CVE-2013-4921P4MEDIUMCVSS 5.0fixed in wireshark 1.10.1-1 (bookworm)2013
CVE-2013-4921 [MEDIUM] CVE-2013-4921: wireshark - Off-by-one error in the dissect_radiotap function in epan/dissectors/packet-ieee... Off-by-one error in the dissect_radiotap function in epan/dissectors/packet-ieee80211-radiotap.c in the Radiotap dissector in Wireshark 1.10.x before 1.10.1 allows remote attackers to cause a denial of service (application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in 1.10.1-1) bullseye: resolved (fixed in 1.10.1-1) forky: resolved (fixed
debian
CVE-2015-8711P4MEDIUMCVSS 5.5fixed in wireshark 2.0.1+g59ea380-1 (bookworm)2015
CVE-2015-8711 [MEDIUM] CVE-2015-8711: wireshark - epan/dissectors/packet-nbap.c in the NBAP dissector in Wireshark 1.12.x before 1... epan/dissectors/packet-nbap.c in the NBAP dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate conversation data, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in 2.0.1+g59ea380-1) bullseye: resolved (fixed in 2
debian
CVE-2013-4936P4MEDIUMCVSS 5.0fixed in wireshark 1.10.1-1 (bookworm)2013
CVE-2013-4936 [MEDIUM] CVE-2013-4936: wireshark - The IsDFP_Frame function in plugins/profinet/packet-pn-rt.c in the PROFINET Real... The IsDFP_Frame function in plugins/profinet/packet-pn-rt.c in the PROFINET Real-Time dissector in Wireshark 1.10.x before 1.10.1 does not validate MAC addresses, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in 1.10.1-1) bullseye: resolved (f
debian
CVE-2015-8721P4MEDIUMCVSS 5.5fixed in wireshark 2.0.1+g59ea380-1 (bookworm)2015
CVE-2015-8721 [MEDIUM] CVE-2015-8721: wireshark - Buffer overflow in the tvb_uncompress function in epan/tvbuff_zlib.c in Wireshar... Buffer overflow in the tvb_uncompress function in epan/tvbuff_zlib.c in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 allows remote attackers to cause a denial of service (application crash) via a crafted packet with zlib compression. Scope: local bookworm: resolved (fixed in 2.0.1+g59ea380-1) bullseye: resolved (fixed in 2.0.1+g59ea380-1) forky: resolved
debian
CVE-2012-6055P4LOWCVSS 5.0fixed in wireshark 1.8.6-1 (bookworm)2012
CVE-2012-6055 [MEDIUM] CVE-2012-6055: wireshark - epan/dissectors/packet-3g-a11.c in the 3GPP2 A11 dissector in Wireshark 1.8.x be... epan/dissectors/packet-3g-a11.c in the 3GPP2 A11 dissector in Wireshark 1.8.x before 1.8.4 allows remote attackers to cause a denial of service (infinite loop) via a zero value in a sub-type length field. Scope: local bookworm: resolved (fixed in 1.8.6-1) bullseye: resolved (fixed in 1.8.6-1) forky: resolved (fixed in 1.8.6-1) sid: resolved (fixed in 1.8.6-1) trix
debian
CVE-2014-6425P4MEDIUMCVSS 5.0fixed in wireshark 1.12.1+g01b65bf-1 (bookworm)2014
CVE-2014-6425 [MEDIUM] CVE-2014-6425: wireshark - The (1) get_quoted_string and (2) get_unquoted_string functions in epan/dissecto... The (1) get_quoted_string and (2) get_unquoted_string functions in epan/dissectors/packet-cups.c in the CUPS dissector in Wireshark 1.12.x before 1.12.1 allow remote attackers to cause a denial of service (buffer over-read and application crash) via a CUPS packet that lacks a trailing '\0' character. Scope: local bookworm: resolved (fixed in 1.12.1+g01b65bf-1) bul
debian
CVE-2014-5164P4MEDIUMCVSS 5.0fixed in wireshark 1.12.0+git+4fab41a1-1 (bookworm)2014
CVE-2014-5164 [MEDIUM] CVE-2014-5164: wireshark - The rlc_decode_li function in epan/dissectors/packet-rlc.c in the RLC dissector ... The rlc_decode_li function in epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.10.x before 1.10.9 initializes a certain structure member only after this member is used, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in 1.12.0+git+4fab41a1-1) bullseye: resol
debian
CVE-2012-6053P4LOWCVSS 5.0fixed in wireshark 1.8.6-1 (bookworm)2012
CVE-2012-6053 [MEDIUM] CVE-2012-6053: wireshark - epan/dissectors/packet-usb.c in the USB dissector in Wireshark 1.6.x before 1.6.... epan/dissectors/packet-usb.c in the USB dissector in Wireshark 1.6.x before 1.6.12 and 1.8.x before 1.8.4 relies on a length field to calculate an offset value, which allows remote attackers to cause a denial of service (infinite loop) via a zero value for this field. Scope: local bookworm: resolved (fixed in 1.8.6-1) bullseye: resolved (fixed in 1.8.6-1) forky: r
debian
CVE-2012-6056P4LOWCVSS 5.0fixed in wireshark 1.8.6-1 (bookworm)2012
CVE-2012-6056 [MEDIUM] CVE-2012-6056: wireshark - Integer overflow in the dissect_sack_chunk function in epan/dissectors/packet-sc... Integer overflow in the dissect_sack_chunk function in epan/dissectors/packet-sctp.c in the SCTP dissector in Wireshark 1.8.x before 1.8.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted Duplicate TSN count. Scope: local bookworm: resolved (fixed in 1.8.6-1) bullseye: resolved (fixed in 1.8.6-1) forky: resolved (fixed in 1.8.6-1)
debian
CVE-2012-6058P4LOWCVSS 5.0fixed in wireshark 1.8.6-1 (bookworm)2012
CVE-2012-6058 [MEDIUM] CVE-2012-6058: wireshark - Integer overflow in the dissect_icmpv6 function in epan/dissectors/packet-icmpv6... Integer overflow in the dissect_icmpv6 function in epan/dissectors/packet-icmpv6.c in the ICMPv6 dissector in Wireshark 1.6.x before 1.6.12 and 1.8.x before 1.8.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted Number of Sources value. Scope: local bookworm: resolved (fixed in 1.8.6-1) bullseye: resolved (fixed in 1.8.6-1) forky:
debian
CVE-2014-5162P4MEDIUMCVSS 5.0fixed in wireshark 1.12.0+git+4fab41a1-1 (bookworm)2014
CVE-2014-5162 [MEDIUM] CVE-2014-5162: wireshark - The read_new_line function in wiretap/catapult_dct2000.c in the Catapult DCT2000... The read_new_line function in wiretap/catapult_dct2000.c in the Catapult DCT2000 dissector in Wireshark 1.10.x before 1.10.9 does not properly strip '\n' and '\r' characters, which allows remote attackers to cause a denial of service (off-by-one buffer underflow and application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in 1.12.0+git+4fab4
debian
CVE-2009-1829P4LOWCVSS 5.0fixed in wireshark 1.0.8-1 (bookworm)2009
CVE-2009-1829 [MEDIUM] CVE-2009-1829: wireshark - Unspecified vulnerability in the PCNFSD dissector in Wireshark 0.8.20 through 1.... Unspecified vulnerability in the PCNFSD dissector in Wireshark 0.8.20 through 1.0.7 allows remote attackers to cause a denial of service (crash) via crafted PCNFSD packets. Scope: local bookworm: resolved (fixed in 1.0.8-1) bullseye: resolved (fixed in 1.0.8-1) forky: resolved (fixed in 1.0.8-1) sid: resolved (fixed in 1.0.8-1) trixie: resolved (fixed in 1.0.8-1)
debian
CVE-2008-5285P4LOWCVSS 5.0fixed in wireshark 1.0.5-1 (bookworm)2008
CVE-2008-5285 [MEDIUM] CVE-2008-5285: wireshark - Wireshark 1.0.4 and earlier allows remote attackers to cause a denial of service... Wireshark 1.0.4 and earlier allows remote attackers to cause a denial of service via a long SMTP request, which triggers an infinite loop. Scope: local bookworm: resolved (fixed in 1.0.5-1) bullseye: resolved (fixed in 1.0.5-1) forky: resolved (fixed in 1.0.5-1) sid: resolved (fixed in 1.0.5-1) trixie: resolved (fixed in 1.0.5-1)
debian
CVE-2015-0559P4MEDIUMCVSS 5.0fixed in wireshark 1.12.1+g01b65bf-3 (bookworm)2015
CVE-2015-0559 [MEDIUM] CVE-2015-0559: wireshark - Multiple use-after-free vulnerabilities in epan/dissectors/packet-wccp.c in the ... Multiple use-after-free vulnerabilities in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 allow remote attackers to cause a denial of service (application crash) via a crafted packet, related to the use of packet-scope memory instead of pinfo-scope memory. Scope: local bookworm: resolved (fixed in 1.
debian
CVE-2007-6111P4LOWCVSS 7.1fixed in wireshark 0.99.7~pre1-1 (bookworm)2007
CVE-2007-6111 [HIGH] CVE-2007-6111: wireshark - Multiple unspecified vulnerabilities in Wireshark (formerly Ethereal) allow remo... Multiple unspecified vulnerabilities in Wireshark (formerly Ethereal) allow remote attackers to cause a denial of service (crash) via (1) a crafted MP3 file or (2) unspecified vectors to the NCP dissector. Scope: local bookworm: resolved (fixed in 0.99.7~pre1-1) bullseye: resolved (fixed in 0.99.7~pre1-1) forky: resolved (fixed in 0.99.7~pre1-1) sid: resolved (fixed
debian
CVE-2006-4333P4LOWCVSS 5.4fixed in wireshark 0.99.2-5.1 (bookworm)2006
CVE-2006-4333 [MEDIUM] CVE-2006-4333: wireshark - The SSCOP dissector in Wireshark (formerly Ethereal) before 0.99.3 allows remote... The SSCOP dissector in Wireshark (formerly Ethereal) before 0.99.3 allows remote attackers to cause a denial of service (resource consumption) via malformed packets that cause the Q.2391 dissector to use excessive memory. Scope: local bookworm: resolved (fixed in 0.99.2-5.1) bullseye: resolved (fixed in 0.99.2-5.1) forky: resolved (fixed in 0.99.2-5.1) sid: resolv
debian
CVE-2006-4805P4MEDIUMCVSS 5.0fixed in wireshark 0.99.4-1 (bookworm)2006
CVE-2006-4805 [MEDIUM] CVE-2006-4805: wireshark - epan/dissectors/packet-xot.c in the XOT dissector (dissect_xot_pdu) in Wireshark... epan/dissectors/packet-xot.c in the XOT dissector (dissect_xot_pdu) in Wireshark (formerly Ethereal) 0.9.8 through 0.99.3 allows remote attackers to cause a denial of service (memory consumption and crash) via an encoded XOT packet that produces a zero length value when it is decoded. Scope: local bookworm: resolved (fixed in 0.99.4-1) bullseye: resolved (fixed in
debian
CVE-2013-2476P4LOWCVSS 6.1fixed in wireshark 1.8.6-1 (bookworm)2013
CVE-2013-2476 [MEDIUM] CVE-2013-2476: wireshark - The dissect_hartip function in epan/dissectors/packet-hartip.c in the HART/IP di... The dissect_hartip function in epan/dissectors/packet-hartip.c in the HART/IP dissector in Wireshark 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (infinite loop) via a packet with a header that is too short. Scope: local bookworm: resolved (fixed in 1.8.6-1) bullseye: resolved (fixed in 1.8.6-1) forky: resolved (fixed in 1.8.6-1) sid: re
debian
Debian Wireshark vulnerabilities | cvebase