cbcvebase.

Debian Wireshark vulnerabilities

668 known vulnerabilities affecting debian/wireshark.

Total CVEs
668
CISA KEV
0
Public exploits
50
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH129MEDIUM276LOW255

Vulnerabilities

Page 24 of 34
CVE-2013-4932P4MEDIUMCVSS 5.0fixed in wireshark 1.10.1-1 (bookworm)2013
CVE-2013-4932 [MEDIUM] CVE-2013-4932: wireshark - Multiple array index errors in epan/dissectors/packet-gsm_a_common.c in the GSM ... Multiple array index errors in epan/dissectors/packet-gsm_a_common.c in the GSM A Common dissector in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 allow remote attackers to cause a denial of service (application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in 1.10.1-1) bullseye: resolved (fixed in 1.10.1-1) forky: resolved (fixed in
debian
CVE-2006-3627P4HIGHCVSS 5.0fixed in wireshark 0.99.2-1 (bookworm)2006
CVE-2006-3627 [MEDIUM] CVE-2006-3627: wireshark - Unspecified vulnerability in the GSM BSSMAP dissector in Wireshark (aka Ethereal... Unspecified vulnerability in the GSM BSSMAP dissector in Wireshark (aka Ethereal) 0.10.11 to 0.99.0 allows remote attackers to cause a denial of service (crash) via unspecified vectors. Scope: local bookworm: resolved (fixed in 0.99.2-1) bullseye: resolved (fixed in 0.99.2-1) forky: resolved (fixed in 0.99.2-1) sid: resolved (fixed in 0.99.2-1) trixie: resolved (f
debian
CVE-2009-2562P4LOWCVSS 5.0fixed in wireshark 1.2.1-1 (bookworm)2009
CVE-2009-2562 [MEDIUM] CVE-2009-2562: wireshark - Unspecified vulnerability in the AFS dissector in Wireshark 0.9.2 through 1.2.0 ... Unspecified vulnerability in the AFS dissector in Wireshark 0.9.2 through 1.2.0 allows remote attackers to cause a denial of service (crash) via unknown vectors. Scope: local bookworm: resolved (fixed in 1.2.1-1) bullseye: resolved (fixed in 1.2.1-1) forky: resolved (fixed in 1.2.1-1) sid: resolved (fixed in 1.2.1-1) trixie: resolved (fixed in 1.2.1-1)
debian
CVE-2014-6421P4MEDIUMCVSS 5.0fixed in wireshark 1.12.0~rc1-1 (bookworm)2014
CVE-2014-6421 [MEDIUM] CVE-2014-6421: wireshark - Use-after-free vulnerability in the SDP dissector in Wireshark 1.10.x before 1.1... Use-after-free vulnerability in the SDP dissector in Wireshark 1.10.x before 1.10.10 allows remote attackers to cause a denial of service (application crash) via a crafted packet that leverages split memory ownership between the SDP and RTP dissectors. Scope: local bookworm: resolved (fixed in 1.12.0~rc1-1) bullseye: resolved (fixed in 1.12.0~rc1-1) forky: resolve
debian
CVE-2013-2488P4MEDIUMCVSS 5.0fixed in wireshark 1.8.2-5 (bookworm)2013
CVE-2013-2488 [MEDIUM] CVE-2013-2488: wireshark - The DTLS dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 does ... The DTLS dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 does not validate the fragment offset before invoking the reassembly state machine, which allows remote attackers to cause a denial of service (application crash) via a large offset value that triggers write access to an invalid memory location. Scope: local bookworm: resolved (fixed in 1.8
debian
CVE-2012-6059P4LOWCVSS 5.0fixed in wireshark 1.8.6-1 (bookworm)2012
CVE-2012-6059 [MEDIUM] CVE-2012-6059: wireshark - The dissect_isakmp function in epan/dissectors/packet-isakmp.c in the ISAKMP dis... The dissect_isakmp function in epan/dissectors/packet-isakmp.c in the ISAKMP dissector in Wireshark 1.6.x before 1.6.12 and 1.8.x before 1.8.4 uses an incorrect data structure to determine IKEv2 decryption parameters, which allows remote attackers to cause a denial of service (application crash) via a malformed packet. Scope: local bookworm: resolved (fixed in 1.8
debian
CVE-2016-2527P4MEDIUMCVSS 5.5fixed in wireshark 2.0.2+ga16e22e-1 (bookworm)2016
CVE-2016-2527 [MEDIUM] CVE-2016-2527: wireshark - wiretap/nettrace_3gpp_32_423.c in the 3GPP TS 32.423 Trace file parser in Wiresh... wiretap/nettrace_3gpp_32_423.c in the 3GPP TS 32.423 Trace file parser in Wireshark 2.0.x before 2.0.2 does not ensure that a '\0' character is present at the end of certain strings, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted file. Scope: local bookworm: resolved (fixed in 2.0.2+ga16
debian
CVE-2012-4287P4MEDIUMCVSS 5.0fixed in wireshark 1.8.2-1 (bookworm)2012
CVE-2012-4287 [MEDIUM] CVE-2012-4287: wireshark - epan/dissectors/packet-mongo.c in the MongoDB dissector in Wireshark 1.8.x befor... epan/dissectors/packet-mongo.c in the MongoDB dissector in Wireshark 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (loop and CPU consumption) via a small value for a BSON document length. Scope: local bookworm: resolved (fixed in 1.8.2-1) bullseye: resolved (fixed in 1.8.2-1) forky: resolved (fixed in 1.8.2-1) sid: resolved (fixed in 1.8.
debian
CVE-2017-9617P4LOWCVSS 5.5fixed in wireshark 2.4.0-1 (bookworm)2017
CVE-2017-9617 [MEDIUM] CVE-2017-9617: wireshark - In Wireshark 2.2.7, deeply nested DAAP data may cause stack exhaustion (uncontro... In Wireshark 2.2.7, deeply nested DAAP data may cause stack exhaustion (uncontrolled recursion) in the dissect_daap_one_tag function in epan/dissectors/packet-daap.c in the DAAP dissector. Scope: local bookworm: resolved (fixed in 2.4.0-1) bullseye: resolved (fixed in 2.4.0-1) forky: resolved (fixed in 2.4.0-1) sid: resolved (fixed in 2.4.0-1) trixie: resolved (fi
debian
CVE-2013-7114P4MEDIUMCVSS 5.0fixed in wireshark 1.10.4-1 (bookworm)2013
CVE-2013-7114 [MEDIUM] CVE-2013-7114: wireshark - Multiple buffer overflows in the create_ntlmssp_v2_key function in epan/dissecto... Multiple buffer overflows in the create_ntlmssp_v2_key function in epan/dissectors/packet-ntlmssp.c in the NTLMSSP v2 dissector in Wireshark 1.8.x before 1.8.12 and 1.10.x before 1.10.4 allow remote attackers to cause a denial of service (application crash) via a long domain name in a packet. Scope: local bookworm: resolved (fixed in 1.10.4-1) bullseye: resolved (
debian
CVE-2008-3145P4LOWCVSS 5.0fixed in wireshark 1.0.2-1 (bookworm)2008
CVE-2008-3145 [MEDIUM] CVE-2008-3145: wireshark - The fragment_add_work function in epan/reassemble.c in Wireshark 0.8.19 through ... The fragment_add_work function in epan/reassemble.c in Wireshark 0.8.19 through 1.0.1 allows remote attackers to cause a denial of service (crash) via a series of fragmented packets with non-sequential fragmentation offset values, which lead to a buffer over-read. Scope: local bookworm: resolved (fixed in 1.0.2-1) bullseye: resolved (fixed in 1.0.2-1) forky: resol
debian
CVE-2007-6121P4LOWCVSS 5.0fixed in wireshark 0.99.7~pre1-1 (bookworm)2007
CVE-2007-6121 [MEDIUM] CVE-2007-6121: wireshark - Wireshark (formerly Ethereal) 0.8.16 to 0.99.6 allows remote attackers to cause ... Wireshark (formerly Ethereal) 0.8.16 to 0.99.6 allows remote attackers to cause a denial of service (crash) via a malformed RPC Portmap packet. Scope: local bookworm: resolved (fixed in 0.99.7~pre1-1) bullseye: resolved (fixed in 0.99.7~pre1-1) forky: resolved (fixed in 0.99.7~pre1-1) sid: resolved (fixed in 0.99.7~pre1-1) trixie: resolved (fixed in 0.99.7~pre1-1)
debian
CVE-2015-6244P4MEDIUMCVSS 4.3fixed in wireshark 1.12.7+g7fc8978-1 (bookworm)2015
CVE-2015-6244 [MEDIUM] CVE-2015-6244: wireshark - The dissect_zbee_secure function in epan/dissectors/packet-zbee-security.c in th... The dissect_zbee_secure function in epan/dissectors/packet-zbee-security.c in the ZigBee dissector in Wireshark 1.12.x before 1.12.7 improperly relies on length fields contained in packet data, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in 1.12.7+g7fc8978-1) bullseye:
debian
CVE-2011-4102P4MEDIUMCVSS 4.3fixed in wireshark 1.6.3-1 (bookworm)2011
CVE-2011-4102 [MEDIUM] CVE-2011-4102: wireshark - Heap-based buffer overflow in the erf_read_header function in wiretap/erf.c in t... Heap-based buffer overflow in the erf_read_header function in wiretap/erf.c in the ERF file parser in Wireshark 1.4.0 through 1.4.9 and 1.6.x before 1.6.3 allows remote attackers to cause a denial of service (application crash) via a malformed file. Scope: local bookworm: resolved (fixed in 1.6.3-1) bullseye: resolved (fixed in 1.6.3-1) forky: resolved (fixed in 1
debian
CVE-2024-8250P4HIGHCVSS 7.8fixed in wireshark 4.0.17-0+deb12u1 (bookworm)2024
CVE-2024-8250 [HIGH] CVE-2024-8250: wireshark - NTLMSSP dissector crash in Wireshark 4.2.0 to 4.0.6 and 4.0.0 to 4.0.16 allows d... NTLMSSP dissector crash in Wireshark 4.2.0 to 4.0.6 and 4.0.0 to 4.0.16 allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved (fixed in 4.0.17-0+deb12u1) bullseye: resolved (fixed in 3.4.16-0+deb11u1) forky: resolved (fixed in 4.4.0-1) sid: resolved (fixed in 4.4.0-1) trixie: resolved (fixed in 4.4.0-1)
debian
CVE-2024-11596P4HIGHCVSS 7.8fixed in wireshark 3.4.16-0+deb11u2 (bullseye)2024
CVE-2024-11596 [HIGH] CVE-2024-11596: wireshark - ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denia... ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file Scope: local bookworm: open bullseye: resolved (fixed in 3.4.16-0+deb11u2) forky: resolved (fixed in 4.4.2-1) sid: resolved (fixed in 4.4.2-1) trixie: resolved (fixed in 4.4.2-1)
debian
CVE-2011-1959P4LOWCVSS 4.3fixed in wireshark 1.6.0-1 (bookworm)2011
CVE-2011-1959 [MEDIUM] CVE-2011-1959: wireshark - The snoop_read function in wiretap/snoop.c in Wireshark 1.2.x before 1.2.17 and ... The snoop_read function in wiretap/snoop.c in Wireshark 1.2.x before 1.2.17 and 1.4.x before 1.4.7 does not properly handle certain virtualizable buffers, which allows remote attackers to cause a denial of service (application crash) via a large length value in a snoop file that triggers a stack-based buffer over-read. Scope: local bookworm: resolved (fixed in 1.6
debian
CVE-2024-11595P4LOWCVSS 7.8fixed in wireshark 4.4.2-1 (forky)2024
CVE-2024-11595 [HIGH] CVE-2024-11595: wireshark - FiveCo RAP dissector infinite loop in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.... FiveCo RAP dissector infinite loop in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 4.4.2-1) sid: resolved (fixed in 4.4.2-1) trixie: resolved (fixed in 4.4.2-1)
debian
CVE-2007-6438P4HIGHCVSS 7.1fixed in wireshark 0.99.7-1 (bookworm)2007
CVE-2007-6438 [HIGH] CVE-2007-6438: wireshark - Unspecified vulnerability in the SMB dissector in Wireshark (formerly Ethereal) ... Unspecified vulnerability in the SMB dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service via unknown vectors. NOTE: this identifier originally included MP3 and NCP, but those issues are already covered by CVE-2007-6111. Scope: local bookworm: resolved (fixed in 0.99.7-1) bullseye: resolved (fixed in 0.99.7-1) forky:
debian
CVE-2024-9780P4LOWCVSS 7.8fixed in wireshark 4.4.1-1 (forky)2024
CVE-2024-9780 [HIGH] CVE-2024-9780: wireshark - ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injec... ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 4.4.1-1) sid: resolved (fixed in 4.4.1-1) trixie: resolved (fixed in 4.4.1-1)
debian
Debian Wireshark vulnerabilities | cvebase