Debian Wireshark vulnerabilities
668 known vulnerabilities affecting debian/wireshark.
Total CVEs
668
CISA KEV
0
Public exploits
50
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH129MEDIUM276LOW255
Vulnerabilities
Page 25 of 34
CVE-2015-6248P4MEDIUMCVSS 4.3fixed in wireshark 1.12.7+g7fc8978-1 (bookworm)2015
CVE-2015-6248 [MEDIUM] CVE-2015-6248: wireshark - The ptvcursor_add function in the ptvcursor implementation in epan/proto.c in Wi...
The ptvcursor_add function in the ptvcursor implementation in epan/proto.c in Wireshark 1.12.x before 1.12.7 does not check whether the expected amount of data is available, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 1.12.7+g7fc8978-1)
bullseye: resolved (fixed in 1
debian
CVE-2014-2281P4MEDIUMCVSS 4.3fixed in wireshark 1.10.6-1 (bookworm)2014
CVE-2014-2281 [MEDIUM] CVE-2014-2281: wireshark - The nfs_name_snoop_add_name function in epan/dissectors/packet-nfs.c in the NFS ...
The nfs_name_snoop_add_name function in epan/dissectors/packet-nfs.c in the NFS dissector in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 does not validate a certain length value, which allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted NFS packet.
Scope: local
bookworm: resolved (fixed in 1.10.6-
debian
CVE-2015-6243P4MEDIUMCVSS 4.3fixed in wireshark 1.12.7+g7fc8978-1 (bookworm)2015
CVE-2015-6243 [MEDIUM] CVE-2015-6243: wireshark - The dissector-table implementation in epan/packet.c in Wireshark 1.12.x before 1...
The dissector-table implementation in epan/packet.c in Wireshark 1.12.x before 1.12.7 mishandles table searches for empty strings, which allows remote attackers to cause a denial of service (application crash) via a crafted packet, related to the (1) dissector_get_string_handle and (2) dissector_get_default_string_handle functions.
Scope: local
bookworm: resolved
debian
CVE-2015-6242P4MEDIUMCVSS 4.3fixed in wireshark 1.12.7+g7fc8978-1 (bookworm)2015
CVE-2015-6242 [MEDIUM] CVE-2015-6242: wireshark - The wmem_block_split_free_chunk function in epan/wmem/wmem_allocator_block.c in ...
The wmem_block_split_free_chunk function in epan/wmem/wmem_allocator_block.c in the wmem block allocator in the memory manager in Wireshark 1.12.x before 1.12.7 does not properly consider a certain case of multiple realloc operations that restore a memory chunk to its original size, which allows remote attackers to cause a denial of service (incorrect free operati
debian
CVE-2008-3141P4LOWCVSS 4.9fixed in wireshark 1.0.1-1 (bookworm)2008
CVE-2008-3141 [MEDIUM] CVE-2008-3141: wireshark - Unspecified vulnerability in the RMI dissector in Wireshark (formerly Ethereal) ...
Unspecified vulnerability in the RMI dissector in Wireshark (formerly Ethereal) 0.9.5 through 1.0.0 allows remote attackers to read system memory via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 1.0.1-1)
bullseye: resolved (fixed in 1.0.1-1)
forky: resolved (fixed in 1.0.1-1)
sid: resolved (fixed in 1.0.1-1)
trixie: resolved (fixed in 1.0.1-1)
debian
CVE-2013-6338P4MEDIUMCVSS 4.3fixed in wireshark 1.10.3-1 (bookworm)2013
CVE-2013-6338 [MEDIUM] CVE-2013-6338: wireshark - The dissect_sip_common function in epan/dissectors/packet-sip.c in the SIP disse...
The dissect_sip_common function in epan/dissectors/packet-sip.c in the SIP dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 does not properly initialize a data structure, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 1.10.3-1)
bullseye: resolved (fix
debian
CVE-2013-2485P4LOWCVSS 6.1fixed in wireshark 1.8.6-1 (bookworm)2013
CVE-2013-2485 [MEDIUM] CVE-2013-2485: wireshark - The FCSP dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allow...
The FCSP dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1.8.6-1)
trixie: resolved (fixed in 1.8.6-1)
debian
CVE-2013-2482P4LOWCVSS 6.1fixed in wireshark 1.8.6-1 (bookworm)2013
CVE-2013-2482 [MEDIUM] CVE-2013-2482: wireshark - The AMPQ dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allow...
The AMPQ dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1.8.6-1)
trixie: resolved (fixed in 1.8.6-1)
debian
CVE-2015-8722P4MEDIUMCVSS 5.5fixed in wireshark 2.0.1+g59ea380-1 (bookworm)2015
CVE-2015-8722 [MEDIUM] CVE-2015-8722: wireshark - epan/dissectors/packet-sctp.c in the SCTP dissector in Wireshark 1.12.x before 1...
epan/dissectors/packet-sctp.c in the SCTP dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the frame pointer, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 2.0.1+g59ea380-1)
bullseye: resolved (fixed in 2
debian
CVE-2013-4077P4MEDIUMCVSS 5.0fixed in wireshark 1.10.0-1 (bookworm)2013
CVE-2013-4077 [MEDIUM] CVE-2013-4077: wireshark - Array index error in the NBAP dissector in Wireshark 1.8.x before 1.8.8 allows r...
Array index error in the NBAP dissector in Wireshark 1.8.x before 1.8.8 allows remote attackers to cause a denial of service (application crash) via a crafted packet, related to nbap.cnf and packet-nbap.c.
Scope: local
bookworm: resolved (fixed in 1.10.0-1)
bullseye: resolved (fixed in 1.10.0-1)
forky: resolved (fixed in 1.10.0-1)
sid: resolved (fixed in 1.10.0-1)
debian
CVE-2007-6450P4MEDIUMCVSS 5.0fixed in wireshark 0.99.7-1 (bookworm)2007
CVE-2007-6450 [MEDIUM] CVE-2007-6450: wireshark - The RPL dissector in Wireshark (formerly Ethereal) 0.9.8 to 0.99.6 allows remote...
The RPL dissector in Wireshark (formerly Ethereal) 0.9.8 to 0.99.6 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.
Scope: local
bookworm: resolved (fixed in 0.99.7-1)
bullseye: resolved (fixed in 0.99.7-1)
forky: resolved (fixed in 0.99.7-1)
sid: resolved (fixed in 0.99.7-1)
trixie: resolved (fixed in 0.99.7-1)
debian
CVE-2008-3139P4LOWCVSS 5.0fixed in wireshark 1.0.1-1 (bookworm)2008
CVE-2008-3139 [MEDIUM] CVE-2008-3139: wireshark - The RTMPT dissector in Wireshark (formerly Ethereal) 0.99.8 through 1.0.0 allows...
The RTMPT dissector in Wireshark (formerly Ethereal) 0.99.8 through 1.0.0 allows remote attackers to cause a denial of service (crash) via unknown vectors. NOTE: this might be due to a use-after-free error.
Scope: local
bookworm: resolved (fixed in 1.0.1-1)
bullseye: resolved (fixed in 1.0.1-1)
forky: resolved (fixed in 1.0.1-1)
sid: resolved (fixed in 1.0.1-1)
tr
debian
CVE-2007-6116P4LOWCVSS 5.0fixed in wireshark 0.99.7~pre1-1 (bookworm)2007
CVE-2007-6116 [MEDIUM] CVE-2007-6116: wireshark - The Firebird/Interbase dissector in Wireshark (formerly Ethereal) 0.99.6 allows ...
The Firebird/Interbase dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (infinite loop or crash) via unknown vectors.
Scope: local
bookworm: resolved (fixed in 0.99.7~pre1-1)
bullseye: resolved (fixed in 0.99.7~pre1-1)
forky: resolved (fixed in 0.99.7~pre1-1)
sid: resolved (fixed in 0.99.7~pre1-1)
trixie: resol
debian
CVE-2015-8718P4MEDIUMCVSS 5.5fixed in wireshark 2.0.1+g59ea380-1 (bookworm)2015
CVE-2015-8718 [MEDIUM] CVE-2015-8718: wireshark - Double free vulnerability in epan/dissectors/packet-nlm.c in the NLM dissector i...
Double free vulnerability in epan/dissectors/packet-nlm.c in the NLM dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1, when the "Match MSG/RES packets for async NLM" option is enabled, allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 2.0.1+g59ea380-1)
bullseye
debian
CVE-2015-3182P4MEDIUMCVSS 5.5fixed in wireshark 1.12.0~rc1-1 (bookworm)2015
CVE-2015-3182 [MEDIUM] CVE-2015-3182: wireshark - epan/dissectors/packet-dec-dnart.c in the DECnet NSP/RT dissector in Wireshark 1...
epan/dissectors/packet-dec-dnart.c in the DECnet NSP/RT dissector in Wireshark 1.10.12 through 1.10.14 mishandles a certain strdup return value, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 1.12.0~rc1-1)
bullseye: resolved (fixed in 1.12.0~rc1-1)
forky: resolved (fixe
debian
CVE-2015-8742P4MEDIUMCVSS 5.5fixed in wireshark 2.0.1+g59ea380-1 (bookworm)2015
CVE-2015-8742 [MEDIUM] CVE-2015-8742: wireshark - The dissect_CPMSetBindings function in epan/dissectors/packet-mswsp.c in the MS-...
The dissect_CPMSetBindings function in epan/dissectors/packet-mswsp.c in the MS-WSP dissector in Wireshark 2.0.x before 2.0.1 does not validate the column size, which allows remote attackers to cause a denial of service (memory consumption or application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 2.0.1+g59ea380-1)
bullseye: resolved (fi
debian
CVE-2013-4920P4MEDIUMCVSS 5.0fixed in wireshark 1.10.1-1 (bookworm)2013
CVE-2013-4920 [MEDIUM] CVE-2013-4920: wireshark - The P1 dissector in Wireshark 1.10.x before 1.10.1 does not properly initialize ...
The P1 dissector in Wireshark 1.10.x before 1.10.1 does not properly initialize a global variable, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 1.10.1-1)
bullseye: resolved (fixed in 1.10.1-1)
forky: resolved (fixed in 1.10.1-1)
sid: resolved (fixed in 1.10.1-1)
trixi
debian
CVE-2013-3555P4MEDIUMCVSS 5.0fixed in wireshark 1.8.7-1 (bookworm)2013
CVE-2013-3555 [MEDIUM] CVE-2013-3555: wireshark - epan/dissectors/packet-gtpv2.c in the GTPv2 dissector in Wireshark 1.8.x before ...
epan/dissectors/packet-gtpv2.c in the GTPv2 dissector in Wireshark 1.8.x before 1.8.7 calls incorrect functions in certain contexts related to ciphers, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.
Scope: local
bookworm: resolved (fixed in 1.8.7-1)
bullseye: resolved (fixed in 1.8.7-1)
forky: resolved (fixed
debian
CVE-2017-9616P4LOWCVSS 5.5fixed in wireshark 2.4.0-1 (bookworm)2017
CVE-2017-9616 [MEDIUM] CVE-2017-9616: wireshark - In Wireshark 2.2.7, overly deep mp4 chunks may cause stack exhaustion (uncontrol...
In Wireshark 2.2.7, overly deep mp4 chunks may cause stack exhaustion (uncontrolled recursion) in the dissect_mp4_box function in epan/dissectors/file-mp4.c.
Scope: local
bookworm: resolved (fixed in 2.4.0-1)
bullseye: resolved (fixed in 2.4.0-1)
forky: resolved (fixed in 2.4.0-1)
sid: resolved (fixed in 2.4.0-1)
trixie: resolved (fixed in 2.4.0-1)
debian
CVE-2006-3631P4HIGHCVSS 5.0fixed in wireshark 0.99.2-1 (bookworm)2006
CVE-2006-3631 [MEDIUM] CVE-2006-3631: wireshark - Unspecified vulnerability in the SSH dissector in Wireshark (aka Ethereal) 0.9.1...
Unspecified vulnerability in the SSH dissector in Wireshark (aka Ethereal) 0.9.10 to 0.99.0 allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.
Scope: local
bookworm: resolved (fixed in 0.99.2-1)
bullseye: resolved (fixed in 0.99.2-1)
forky: resolved (fixed in 0.99.2-1)
sid: resolved (fixed in 0.99.2-1)
trixie: resolved
debian