cbcvebase.

Debian Wireshark vulnerabilities

668 known vulnerabilities affecting debian/wireshark.

Total CVEs
668
CISA KEV
0
Public exploits
50
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH129MEDIUM276LOW255

Vulnerabilities

Page 27 of 34
CVE-2015-8716P4MEDIUMCVSS 5.5fixed in wireshark 2.0.1+g59ea380-1 (bookworm)2015
CVE-2015-8716 [MEDIUM] CVE-2015-8716: wireshark - The init_t38_info_conv function in epan/dissectors/packet-t38.c in the T.38 diss... The init_t38_info_conv function in epan/dissectors/packet-t38.c in the T.38 dissector in Wireshark 1.12.x before 1.12.9 does not ensure that a conversation exists, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in 2.0.1+g59ea380-1) bullseye: resolved (fixed in 2.0.1+g59ea3
debian
CVE-2015-8714P4MEDIUMCVSS 5.5fixed in wireshark 2.0.1+g59ea380-1 (bookworm)2015
CVE-2015-8714 [MEDIUM] CVE-2015-8714: wireshark - The dissect_dcom_OBJREF function in epan/dissectors/packet-dcom.c in the DCOM di... The dissect_dcom_OBJREF function in epan/dissectors/packet-dcom.c in the DCOM dissector in Wireshark 1.12.x before 1.12.9 does not initialize a certain IPv4 data structure, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in 2.0.1+g59ea380-1) bullseye: resolved (fixed in 2.0
debian
CVE-2015-8717P4MEDIUMCVSS 5.5fixed in wireshark 2.0.1+g59ea380-1 (bookworm)2015
CVE-2015-8717 [MEDIUM] CVE-2015-8717: wireshark - The dissect_sdp function in epan/dissectors/packet-sdp.c in the SDP dissector in... The dissect_sdp function in epan/dissectors/packet-sdp.c in the SDP dissector in Wireshark 1.12.x before 1.12.9 does not prevent use of a negative media count, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in 2.0.1+g59ea380-1) bullseye: resolved (fixed in 2.0.1+g59ea380-1
debian
CVE-2015-8719P4MEDIUMCVSS 5.5fixed in wireshark 2.0.1+g59ea380-1 (bookworm)2015
CVE-2015-8719 [MEDIUM] CVE-2015-8719: wireshark - The dissect_dns_answer function in epan/dissectors/packet-dns.c in the DNS disse... The dissect_dns_answer function in epan/dissectors/packet-dns.c in the DNS dissector in Wireshark 1.12.x before 1.12.9 mishandles the EDNS0 Client Subnet option, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in 2.0.1+g59ea380-1) bullseye: resolved (fixed in 2.0.1+g59ea380
debian
CVE-2018-19626P4MEDIUMCVSS 5.5fixed in wireshark 2.6.5-1 (bookworm)2018
CVE-2018-19626 [MEDIUM] CVE-2018-19626: wireshark - In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the DCOM dissector could crash.... In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the DCOM dissector could crash. This was addressed in epan/dissectors/packet-dcom.c by adding '\0' termination. Scope: local bookworm: resolved (fixed in 2.6.5-1) bullseye: resolved (fixed in 2.6.5-1) forky: resolved (fixed in 2.6.5-1) sid: resolved (fixed in 2.6.5-1) trixie: resolved (fixed in 2.6.5-1)
debian
CVE-2021-4183P4MEDIUMCVSS 5.5fixed in wireshark 3.6.2-1 (bookworm)2021
CVE-2021-4183 [MEDIUM] CVE-2021-4183: wireshark - Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via ... Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file Scope: local bookworm: resolved (fixed in 3.6.2-1) bullseye: resolved forky: resolved (fixed in 3.6.2-1) sid: resolved (fixed in 3.6.2-1) trixie: resolved (fixed in 3.6.2-1)
debian
CVE-2015-8741P4MEDIUMCVSS 5.5fixed in wireshark 2.0.1+g59ea380-1 (bookworm)2015
CVE-2015-8741 [MEDIUM] CVE-2015-8741: wireshark - The dissect_ppi function in epan/dissectors/packet-ppi.c in the PPI dissector in... The dissect_ppi function in epan/dissectors/packet-ppi.c in the PPI dissector in Wireshark 2.0.x before 2.0.1 does not initialize a packet-header data structure, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in 2.0.1+g59ea380-1) bullseye: resolved (fixed in 2.0.1+g59ea380
debian
CVE-2015-8738P4MEDIUMCVSS 5.5fixed in wireshark 2.0.1+g59ea380-1 (bookworm)2015
CVE-2015-8738 [MEDIUM] CVE-2015-8738: wireshark - The s7comm_decode_ud_cpu_szl_subfunc function in epan/dissectors/packet-s7comm_s... The s7comm_decode_ud_cpu_szl_subfunc function in epan/dissectors/packet-s7comm_szl_ids.c in the S7COMM dissector in Wireshark 2.0.x before 2.0.1 does not validate the list count in an SZL response, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in
debian
CVE-2019-5718P4LOWCVSS 5.5fixed in wireshark 2.6.6-1 (bookworm)2019
CVE-2019-5718 [MEDIUM] CVE-2019-5718: wireshark - In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the RTSE dissector and other AS... In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the RTSE dissector and other ASN.1 dissectors could crash. This was addressed in epan/charsets.c by adding a get_t61_string length check. Scope: local bookworm: resolved (fixed in 2.6.6-1) bullseye: resolved (fixed in 2.6.6-1) forky: resolved (fixed in 2.6.6-1) sid: resolved (fixed in 2.6.6-1) trixie: resolved (fixe
debian
CVE-2010-2992P4MEDIUMCVSS 5.0fixed in wireshark 1.2.10-1 (bookworm)2010
CVE-2010-2992 [MEDIUM] CVE-2010-2992: wireshark - packet-gsm_a_rr.c in the GSM A RR dissector in Wireshark 1.2.2 through 1.2.9 all... packet-gsm_a_rr.c in the GSM A RR dissector in Wireshark 1.2.2 through 1.2.9 allows remote attackers to cause a denial of service (crash) via unknown vectors that trigger a NULL pointer dereference. Scope: local bookworm: resolved (fixed in 1.2.10-1) bullseye: resolved (fixed in 1.2.10-1) forky: resolved (fixed in 1.2.10-1) sid: resolved (fixed in 1.2.10-1) trixie
debian
CVE-2013-3560P4LOWCVSS 5.0fixed in wireshark 1.8.7-1 (bookworm)2013
CVE-2013-3560 [MEDIUM] CVE-2013-3560: wireshark - The dissect_dsmcc_un_download function in epan/dissectors/packet-mpeg-dsmcc.c in... The dissect_dsmcc_un_download function in epan/dissectors/packet-mpeg-dsmcc.c in the MPEG DSM-CC dissector in Wireshark 1.8.x before 1.8.7 uses an incorrect format string, which allows remote attackers to cause a denial of service (application crash) via a malformed packet. Scope: local bookworm: resolved (fixed in 1.8.7-1) bullseye: resolved (fixed in 1.8.7-1) fo
debian
CVE-2010-2993P4MEDIUMCVSS 5.0fixed in wireshark 1.2.10-1 (bookworm)2010
CVE-2010-2993 [MEDIUM] CVE-2010-2993: wireshark - The IPMI dissector in Wireshark 1.2.0 through 1.2.9 allows remote attackers to c... The IPMI dissector in Wireshark 1.2.0 through 1.2.9 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors. Scope: local bookworm: resolved (fixed in 1.2.10-1) bullseye: resolved (fixed in 1.2.10-1) forky: resolved (fixed in 1.2.10-1) sid: resolved (fixed in 1.2.10-1) trixie: resolved (fixed in 1.2.10-1)
debian
CVE-2013-7113P4MEDIUMCVSS 5.0fixed in wireshark 1.10.4-1 (bookworm)2013
CVE-2013-7113 [MEDIUM] CVE-2013-7113: wireshark - epan/dissectors/packet-bssgp.c in the BSSGP dissector in Wireshark 1.10.x before... epan/dissectors/packet-bssgp.c in the BSSGP dissector in Wireshark 1.10.x before 1.10.4 incorrectly relies on a global variable, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. Scope: local bookworm: resolved (fixed in 1.10.4-1) bullseye: resolved (fixed in 1.10.4-1) forky: resolved (fixed in 1.10.4-1) sid: reso
debian
CVE-2019-5721P4MEDIUMCVSS 5.5fixed in wireshark 2.6.1-1 (bookworm)2019
CVE-2019-5721 [MEDIUM] CVE-2019-5721: wireshark - In Wireshark 2.4.0 to 2.4.11, the ENIP dissector could crash. This was addressed... In Wireshark 2.4.0 to 2.4.11, the ENIP dissector could crash. This was addressed in epan/dissectors/packet-enip.c by changing the memory-management approach so that a use-after-free is avoided. Scope: local bookworm: resolved (fixed in 2.6.1-1) bullseye: resolved (fixed in 2.6.1-1) forky: resolved (fixed in 2.6.1-1) sid: resolved (fixed in 2.6.1-1) trixie: resolve
debian
CVE-2007-0459P4LOWCVSS 5.0fixed in wireshark 0.99.4-5 (bookworm)2007
CVE-2007-0459 [MEDIUM] CVE-2007-0459: wireshark - packet-tcp.c in the TCP dissector in Wireshark (formerly Ethereal) 0.99.2 throug... packet-tcp.c in the TCP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.4 allows remote attackers to cause a denial of service (application crash or hang) via fragmented HTTP packets. Scope: local bookworm: resolved (fixed in 0.99.4-5) bullseye: resolved (fixed in 0.99.4-5) forky: resolved (fixed in 0.99.4-5) sid: resolved (fixed in 0.99.4-5) trixie
debian
CVE-2013-3558P4MEDIUMCVSS 5.0fixed in wireshark 1.8.7-1 (bookworm)2013
CVE-2013-3558 [MEDIUM] CVE-2013-3558: wireshark - The dissect_ccp_bsdcomp_opt function in epan/dissectors/packet-ppp.c in the PPP ... The dissect_ccp_bsdcomp_opt function in epan/dissectors/packet-ppp.c in the PPP CCP dissector in Wireshark 1.8.x before 1.8.7 does not terminate a bit-field list, which allows remote attackers to cause a denial of service (application crash) via a malformed packet. Scope: local bookworm: resolved (fixed in 1.8.7-1) bullseye: resolved (fixed in 1.8.7-1) forky: reso
debian
CVE-2019-5719P4LOWCVSS 5.5fixed in wireshark 2.6.6-1 (bookworm)2019
CVE-2019-5719 [MEDIUM] CVE-2019-5719: wireshark - In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the ISAKMP dissector could cras... In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the ISAKMP dissector could crash. This was addressed in epan/dissectors/packet-isakmp.c by properly handling the case of a missing decryption data block. Scope: local bookworm: resolved (fixed in 2.6.6-1) bullseye: resolved (fixed in 2.6.6-1) forky: resolved (fixed in 2.6.6-1) sid: resolved (fixed in 2.6.6-1) trixie
debian
CVE-2009-1269P4LOWCVSS 5.0fixed in wireshark 1.0.7-1 (bookworm)2009
CVE-2009-1269 [MEDIUM] CVE-2009-1269: wireshark - Unspecified vulnerability in Wireshark 0.99.6 through 1.0.6 allows remote attack... Unspecified vulnerability in Wireshark 0.99.6 through 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted Tektronix .rf5 file. Scope: local bookworm: resolved (fixed in 1.0.7-1) bullseye: resolved (fixed in 1.0.7-1) forky: resolved (fixed in 1.0.7-1) sid: resolved (fixed in 1.0.7-1) trixie: resolved (fixed in 1.0.7-1)
debian
CVE-2007-3393P4MEDIUMCVSS 5.0fixed in wireshark 0.99.6pre1-1 (bookworm)2007
CVE-2007-3393 [MEDIUM] CVE-2007-3393: wireshark - Off-by-one error in the DHCP/BOOTP dissector in Wireshark before 0.99.6 allows r... Off-by-one error in the DHCP/BOOTP dissector in Wireshark before 0.99.6 allows remote attackers to cause a denial of service (crash) via crafted DHCP-over-DOCSIS packets. Scope: local bookworm: resolved (fixed in 0.99.6pre1-1) bullseye: resolved (fixed in 0.99.6pre1-1) forky: resolved (fixed in 0.99.6pre1-1) sid: resolved (fixed in 0.99.6pre1-1) trixie: resolved (
debian
CVE-2011-1141P4LOWCVSS 4.3fixed in wireshark 1.4.4-1 (bookworm)2011
CVE-2011-1141 [MEDIUM] CVE-2011-1141: wireshark - epan/dissectors/packet-ldap.c in Wireshark 1.0.x, 1.2.0 through 1.2.14, and 1.4.... epan/dissectors/packet-ldap.c in Wireshark 1.0.x, 1.2.0 through 1.2.14, and 1.4.0 through 1.4.3 allows remote attackers to cause a denial of service (memory consumption) via (1) a long LDAP filter string or (2) an LDAP filter string containing many elements. Scope: local bookworm: resolved (fixed in 1.4.4-1) bullseye: resolved (fixed in 1.4.4-1) forky: resolved (f
debian
Debian Wireshark vulnerabilities | cvebase