Debian Wireshark vulnerabilities
668 known vulnerabilities affecting debian/wireshark.
Total CVEs
668
CISA KEV
0
Public exploits
50
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH129MEDIUM276LOW255
Vulnerabilities
Page 26 of 34
CVE-2012-6052P4LOWCVSS 5.0fixed in wireshark 1.8.6-1 (bookworm)2012
CVE-2012-6052 [MEDIUM] CVE-2012-6052: wireshark - Wireshark 1.8.x before 1.8.4 allows remote attackers to obtain sensitive hostnam...
Wireshark 1.8.x before 1.8.4 allows remote attackers to obtain sensitive hostname information by reading pcap-ng files.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1.8.6-1)
trixie: resolved (fixed in 1.8.6-1)
debian
CVE-2006-5469P4MEDIUMCVSS 5.0fixed in wireshark 0.99.4-1 (bookworm)2006
CVE-2006-5469 [MEDIUM] CVE-2006-5469: wireshark - Unspecified vulnerability in the WBXML dissector in Wireshark (formerly Ethereal...
Unspecified vulnerability in the WBXML dissector in Wireshark (formerly Ethereal) 0.10.11 through 0.99.3 allows remote attackers to cause a denial of service (crash) via certain vectors that trigger a null dereference.
Scope: local
bookworm: resolved (fixed in 0.99.4-1)
bullseye: resolved (fixed in 0.99.4-1)
forky: resolved (fixed in 0.99.4-1)
sid: resolved (fixed
debian
CVE-2006-5740P4MEDIUMCVSS 5.0fixed in wireshark 0.99.4-1 (bookworm)2006
CVE-2006-5740 [MEDIUM] CVE-2006-5740: wireshark - Unspecified vulnerability in the LDAP dissector in Wireshark (formerly Ethereal)...
Unspecified vulnerability in the LDAP dissector in Wireshark (formerly Ethereal) 0.99.3 allows remote attackers to cause a denial of service (crash) via a crafted LDAP packet.
Scope: local
bookworm: resolved (fixed in 0.99.4-1)
bullseye: resolved (fixed in 0.99.4-1)
forky: resolved (fixed in 0.99.4-1)
sid: resolved (fixed in 0.99.4-1)
trixie: resolved (fixed in 0.
debian
CVE-2012-1596P4LOWCVSS 5.0fixed in wireshark 1.6.6-1 (bookworm)2012
CVE-2012-1596 [MEDIUM] CVE-2012-1596: wireshark - The mp2t_process_fragmented_payload function in epan/dissectors/packet-mp2t.c in...
The mp2t_process_fragmented_payload function in epan/dissectors/packet-mp2t.c in the MP2T dissector in Wireshark 1.4.x before 1.4.12 and 1.6.x before 1.6.6 allows remote attackers to cause a denial of service (application crash) via a packet containing an invalid pointer value that triggers an incorrect memory-allocation attempt.
Scope: local
bookworm: resolved (f
debian
CVE-2008-1070P4LOWCVSS 5.0fixed in wireshark 0.99.8-1 (bookworm)2008
CVE-2008-1070 [MEDIUM] CVE-2008-1070: wireshark - The SCTP dissector in Wireshark (formerly Ethereal) 0.99.5 through 0.99.7 allows...
The SCTP dissector in Wireshark (formerly Ethereal) 0.99.5 through 0.99.7 allows remote attackers to cause a denial of service (crash) via a malformed packet.
Scope: local
bookworm: resolved (fixed in 0.99.8-1)
bullseye: resolved (fixed in 0.99.8-1)
forky: resolved (fixed in 0.99.8-1)
sid: resolved (fixed in 0.99.8-1)
trixie: resolved (fixed in 0.99.8-1)
debian
CVE-2007-6120P4LOWCVSS 5.0fixed in wireshark 0.99.7~pre1-1 (bookworm)2007
CVE-2007-6120 [MEDIUM] CVE-2007-6120: wireshark - The Bluetooth SDP dissector Wireshark (formerly Ethereal) 0.99.2 to 0.99.6 allow...
The Bluetooth SDP dissector Wireshark (formerly Ethereal) 0.99.2 to 0.99.6 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.
Scope: local
bookworm: resolved (fixed in 0.99.7~pre1-1)
bullseye: resolved (fixed in 0.99.7~pre1-1)
forky: resolved (fixed in 0.99.7~pre1-1)
sid: resolved (fixed in 0.99.7~pre1-1)
trixie: resolved (fi
debian
CVE-2025-13946P4MEDIUMCVSS 5.5fixed in wireshark 3.4.16-0+deb11u2 (bullseye)2025
CVE-2025-13946 [MEDIUM] CVE-2025-13946: wireshark - MEGACO dissector infinite loop in Wireshark 4.6.0 to 4.6.1 and 4.4.0 to 4.4.11 a...
MEGACO dissector infinite loop in Wireshark 4.6.0 to 4.6.1 and 4.4.0 to 4.4.11 allows denial of service
Scope: local
bookworm: open
bullseye: resolved (fixed in 3.4.16-0+deb11u2)
forky: resolved (fixed in 4.6.2-1)
sid: resolved (fixed in 4.6.2-1)
trixie: resolved (fixed in 4.4.13-0+deb13u1)
debian
CVE-2015-7830P4MEDIUMCVSS 4.3fixed in wireshark 1.12.8+g5b6e543-1 (bookworm)2015
CVE-2015-7830 [MEDIUM] CVE-2015-7830: wireshark - The pcapng_read_if_descr_block function in wiretap/pcapng.c in the pcapng parser...
The pcapng_read_if_descr_block function in wiretap/pcapng.c in the pcapng parser in Wireshark 1.12.x before 1.12.8 uses too many levels of pointer indirection, which allows remote attackers to cause a denial of service (incorrect free and application crash) via a crafted packet that triggers interface-filter copying.
Scope: local
bookworm: resolved (fixed in 1.12.
debian
CVE-2025-13499P4HIGHCVSS 7.8fixed in wireshark 3.4.16-0+deb11u2 (bullseye)2025
CVE-2025-13499 [HIGH] CVE-2025-13499: wireshark - Kafka dissector crash in Wireshark 4.6.0 and 4.4.0 to 4.4.10 allows denial of se...
Kafka dissector crash in Wireshark 4.6.0 and 4.4.0 to 4.4.10 allows denial of service
Scope: local
bookworm: open
bullseye: resolved (fixed in 3.4.16-0+deb11u2)
forky: resolved (fixed in 4.6.1-1)
sid: resolved (fixed in 4.6.1-1)
trixie: resolved (fixed in 4.4.13-0+deb13u1)
debian
CVE-2015-6241P4MEDIUMCVSS 4.3fixed in wireshark 1.12.7+g7fc8978-1 (bookworm)2015
CVE-2015-6241 [MEDIUM] CVE-2015-6241: wireshark - The proto_tree_add_bytes_item function in epan/proto.c in the protocol-tree impl...
The proto_tree_add_bytes_item function in epan/proto.c in the protocol-tree implementation in Wireshark 1.12.x before 1.12.7 does not properly terminate a data structure after a failure to locate a number within a string, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 1
debian
CVE-2013-4935P4MEDIUMCVSS 4.3fixed in wireshark 1.10.1-1 (bookworm)2013
CVE-2013-4935 [MEDIUM] CVE-2013-4935: wireshark - The dissect_per_length_determinant function in epan/dissectors/packet-per.c in t...
The dissect_per_length_determinant function in epan/dissectors/packet-per.c in the ASN.1 PER dissector in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 does not initialize a length field in certain abnormal situations, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed
debian
CVE-2014-2283P4MEDIUMCVSS 4.3fixed in wireshark 1.10.6-1 (bookworm)2014
CVE-2014-2283 [MEDIUM] CVE-2014-2283: wireshark - epan/dissectors/packet-rlc in the RLC dissector in Wireshark 1.8.x before 1.8.13...
epan/dissectors/packet-rlc in the RLC dissector in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 uses inconsistent memory-management approaches, which allows remote attackers to cause a denial of service (use-after-free error and application crash) via a crafted UMTS Radio Link Control packet.
Scope: local
bookworm: resolved (fixed in 1.10.6-1)
bullseye:
debian
CVE-2011-1957P4LOWCVSS 4.3fixed in wireshark 1.6.0-1 (bookworm)2011
CVE-2011-1957 [MEDIUM] CVE-2011-1957: wireshark - The dissect_dcm_main function in epan/dissectors/packet-dcm.c in the DICOM disse...
The dissect_dcm_main function in epan/dissectors/packet-dcm.c in the DICOM dissector in Wireshark 1.2.x before 1.2.17 and 1.4.x before 1.4.7 allows remote attackers to cause a denial of service (infinite loop) via an invalid PDU length.
Scope: local
bookworm: resolved (fixed in 1.6.0-1)
bullseye: resolved (fixed in 1.6.0-1)
forky: resolved (fixed in 1.6.0-1)
sid:
debian
CVE-2015-4652P4MEDIUMCVSS 4.3fixed in wireshark 1.12.6+gee1fce6-1 (bookworm)2015
CVE-2015-4652 [MEDIUM] CVE-2015-4652: wireshark - epan/dissectors/packet-gsm_a_dtap.c in the GSM DTAP dissector in Wireshark 1.12....
epan/dissectors/packet-gsm_a_dtap.c in the GSM DTAP dissector in Wireshark 1.12.x before 1.12.6 does not properly validate digit characters, which allows remote attackers to cause a denial of service (application crash) via a crafted packet, related to the de_emerg_num_list and de_bcd_num functions.
Scope: local
bookworm: resolved (fixed in 1.12.6+gee1fce6-1)
bull
debian
CVE-2013-6340P4MEDIUMCVSS 4.3fixed in wireshark 1.10.3-1 (bookworm)2013
CVE-2013-6340 [MEDIUM] CVE-2013-6340: wireshark - epan/dissectors/packet-tcp.c in the TCP dissector in Wireshark 1.8.x before 1.8....
epan/dissectors/packet-tcp.c in the TCP dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 does not properly determine the amount of remaining data, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 1.10.3-1)
bullseye: resolved (fixed in 1.10.3-1)
forky: r
debian
CVE-2006-4331P4MEDIUMCVSS 5.0fixed in wireshark 0.99.2-5.1 (bookworm)2006
CVE-2006-4331 [MEDIUM] CVE-2006-4331: wireshark - Multiple off-by-one errors in the IPSec ESP preference parser in Wireshark (form...
Multiple off-by-one errors in the IPSec ESP preference parser in Wireshark (formerly Ethereal) 0.99.2 allow remote attackers to cause a denial of service (crash) via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 0.99.2-5.1)
bullseye: resolved (fixed in 0.99.2-5.1)
forky: resolved (fixed in 0.99.2-5.1)
sid: resolved (fixed in 0.99.2-5.1)
trixie: re
debian
CVE-2007-3392P4MEDIUMCVSS 5.0fixed in wireshark 0.99.6pre1-1 (bookworm)2007
CVE-2007-3392 [MEDIUM] CVE-2007-3392: wireshark - Wireshark before 0.99.6 allows remote attackers to cause a denial of service via...
Wireshark before 0.99.6 allows remote attackers to cause a denial of service via malformed (1) SSL or (2) MMS packets that trigger an infinite loop.
Scope: local
bookworm: resolved (fixed in 0.99.6pre1-1)
bullseye: resolved (fixed in 0.99.6pre1-1)
forky: resolved (fixed in 0.99.6pre1-1)
sid: resolved (fixed in 0.99.6pre1-1)
trixie: resolved (fixed in 0.99.6pre1-1)
debian
CVE-2024-4855P4LOWCVSS 3.6fixed in wireshark 4.0.17-0+deb12u1 (bookworm)2024
CVE-2024-4855 [LOW] CVE-2024-4855: wireshark - Use after free issue in editcap could cause denial of service via crafted captur...
Use after free issue in editcap could cause denial of service via crafted capture file
Scope: local
bookworm: resolved (fixed in 4.0.17-0+deb12u1)
bullseye: open
forky: resolved (fixed in 4.2.5-1)
sid: resolved (fixed in 4.2.5-1)
trixie: resolved (fixed in 4.2.5-1)
debian
CVE-2015-8720P4MEDIUMCVSS 5.5fixed in wireshark 2.0.1+g59ea380-1 (bookworm)2015
CVE-2015-8720 [MEDIUM] CVE-2015-8720: wireshark - The dissect_ber_GeneralizedTime function in epan/dissectors/packet-ber.c in the ...
The dissect_ber_GeneralizedTime function in epan/dissectors/packet-ber.c in the BER dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 improperly checks an sscanf return value, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 2.0.1+g59ea380-1)
bullseye: re
debian
CVE-2015-8712P4MEDIUMCVSS 5.5fixed in wireshark 2.0.1+g59ea380-1 (bookworm)2015
CVE-2015-8712 [MEDIUM] CVE-2015-8712: wireshark - The dissect_hsdsch_channel_info function in epan/dissectors/packet-umts_fp.c in ...
The dissect_hsdsch_channel_info function in epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 1.12.x before 1.12.9 does not validate the number of PDUs, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 2.0.1+g59ea380-1)
bullseye: resolved (fixed in 2.
debian