Debian Wireshark vulnerabilities
668 known vulnerabilities affecting debian/wireshark.
Total CVEs
668
CISA KEV
0
Public exploits
50
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH129MEDIUM276LOW255
Vulnerabilities
Page 29 of 34
CVE-2015-8734P4MEDIUMCVSS 5.5fixed in wireshark 2.0.1+g59ea380-1 (bookworm)2015
CVE-2015-8734 [MEDIUM] CVE-2015-8734: wireshark - The dissect_nwp function in epan/dissectors/packet-nwp.c in the NWP dissector in...
The dissect_nwp function in epan/dissectors/packet-nwp.c in the NWP dissector in Wireshark 2.0.x before 2.0.1 mishandles the packet type, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 2.0.1+g59ea380-1)
bullseye: resolved (fixed in 2.0.1+g59ea380-1)
forky: resolved (fix
debian
CVE-2009-3549P4LOWCVSS 5.0fixed in wireshark 1.2.3-1 (bookworm)2009
CVE-2009-3549 [MEDIUM] CVE-2009-3549: wireshark - packet-paltalk.c in the Paltalk dissector in Wireshark 1.2.0 through 1.2.2, on S...
packet-paltalk.c in the Paltalk dissector in Wireshark 1.2.0 through 1.2.2, on SPARC and certain other platforms, allows remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace.
Scope: local
bookworm: resolved (fixed in 1.2.3-1)
bullseye: resolved (fixed in 1.2.3-1)
forky: resolved (fixed in 1.2.3-1)
sid:
debian
CVE-2013-3562P4MEDIUMCVSS 5.0fixed in wireshark 1.8.7-1 (bookworm)2013
CVE-2013-3562 [MEDIUM] CVE-2013-3562: wireshark - Multiple integer signedness errors in the tvb_unmasked function in epan/dissecto...
Multiple integer signedness errors in the tvb_unmasked function in epan/dissectors/packet-websocket.c in the Websocket dissector in Wireshark 1.8.x before 1.8.7 allow remote attackers to cause a denial of service (application crash) via a malformed packet.
Scope: local
bookworm: resolved (fixed in 1.8.7-1)
bullseye: resolved (fixed in 1.8.7-1)
forky: resolved (fix
debian
CVE-2016-2529P4MEDIUMCVSS 5.5fixed in wireshark 2.0.2+ga16e22e-1 (bookworm)2016
CVE-2016-2529 [MEDIUM] CVE-2016-2529: wireshark - The iseries_check_file_type function in wiretap/iseries.c in the iSeries file pa...
The iseries_check_file_type function in wiretap/iseries.c in the iSeries file parser in Wireshark 2.0.x before 2.0.2 does not consider that a line may lack the "OBJECT PROTOCOL" substring, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file.
Scope: local
bookworm: resolved (fixed in 2.0.2+ga16e22
debian
CVE-2009-2559P4MEDIUMCVSS 5.0fixed in wireshark 1.2.1-1 (bookworm)2009
CVE-2009-2559 [MEDIUM] CVE-2009-2559: wireshark - Buffer overflow in the IPMI dissector in Wireshark 1.2.0 allows remote attackers...
Buffer overflow in the IPMI dissector in Wireshark 1.2.0 allows remote attackers to cause a denial of service (crash) via unspecified vectors related to an array index error. NOTE: some of these details are obtained from third party information.
Scope: local
bookworm: resolved (fixed in 1.2.1-1)
bullseye: resolved (fixed in 1.2.1-1)
forky: resolved (fixed in 1.2.1
debian
CVE-2009-2560P4MEDIUMCVSS 5.0fixed in wireshark 1.2.1-1 (bookworm)2009
CVE-2009-2560 [MEDIUM] CVE-2009-2560: wireshark - Multiple unspecified vulnerabilities in Wireshark 1.2.0 allow remote attackers t...
Multiple unspecified vulnerabilities in Wireshark 1.2.0 allow remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace and is processed by the (1) Bluetooth L2CAP, (2) RADIUS, or (3) MIOP dissector. NOTE: it was later reported that the RADIUS issue also affects 0.10.13 through 1.0.9.
Scope: local
bookworm:
debian
CVE-2008-4685P4LOWCVSS 5.0fixed in wireshark 1.0.4-1 (bookworm)2008
CVE-2008-4685 [MEDIUM] CVE-2008-4685: wireshark - Use-after-free vulnerability in the dissect_q931_cause_ie function in packet-q93...
Use-after-free vulnerability in the dissect_q931_cause_ie function in packet-q931.c in the Q.931 dissector in Wireshark 0.10.3 through 1.0.3 allows remote attackers to cause a denial of service (application crash or abort) via certain packets that trigger an exception.
Scope: local
bookworm: resolved (fixed in 1.0.4-1)
bullseye: resolved (fixed in 1.0.4-1)
forky:
debian
CVE-2007-3390P4MEDIUMCVSS 5.0fixed in wireshark 0.99.6pre1-1 (bookworm)2007
CVE-2007-3390 [MEDIUM] CVE-2007-3390: wireshark - Wireshark 0.99.5 and 0.10.x up to 0.10.14, when running on certain systems, allo...
Wireshark 0.99.5 and 0.10.x up to 0.10.14, when running on certain systems, allows remote attackers to cause a denial of service (crash) via crafted iSeries capture files that trigger a SIGTRAP.
Scope: local
bookworm: resolved (fixed in 0.99.6pre1-1)
bullseye: resolved (fixed in 0.99.6pre1-1)
forky: resolved (fixed in 0.99.6pre1-1)
sid: resolved (fixed in 0.99.6pr
debian
CVE-2009-2561P4MEDIUMCVSS 5.0fixed in wireshark 1.2.1-1 (bookworm)2009
CVE-2009-2561 [MEDIUM] CVE-2009-2561: wireshark - Unspecified vulnerability in the sFlow dissector in Wireshark 1.2.0 allows remot...
Unspecified vulnerability in the sFlow dissector in Wireshark 1.2.0 allows remote attackers to cause a denial of service (CPU and memory consumption) via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 1.2.1-1)
bullseye: resolved (fixed in 1.2.1-1)
forky: resolved (fixed in 1.2.1-1)
sid: resolved (fixed in 1.2.1-1)
trixie: resolved (fixed in 1.2.1-1
debian
CVE-2011-1138P4MEDIUMCVSS 4.3fixed in wireshark 1.4.4-1 (bookworm)2011
CVE-2011-1138 [MEDIUM] CVE-2011-1138: wireshark - Off-by-one error in the dissect_6lowpan_iphc function in packet-6lowpan.c in Wir...
Off-by-one error in the dissect_6lowpan_iphc function in packet-6lowpan.c in Wireshark 1.4.0 through 1.4.3 on 32-bit platforms allows remote attackers to cause a denial of service (application crash) via a malformed 6LoWPAN IPv6 packet.
Scope: local
bookworm: resolved (fixed in 1.4.4-1)
bullseye: resolved (fixed in 1.4.4-1)
forky: resolved (fixed in 1.4.4-1)
sid:
debian
CVE-2024-8645P4MEDIUMCVSS 5.5fixed in wireshark 4.0.17-0+deb12u1 (bookworm)2024
CVE-2024-8645 [MEDIUM] CVE-2024-8645: wireshark - SPRT dissector crash in Wireshark 4.2.0 to 4.0.5 and 4.0.0 to 4.0.15 allows deni...
SPRT dissector crash in Wireshark 4.2.0 to 4.0.5 and 4.0.0 to 4.0.15 allows denial of service via packet injection or crafted capture file
Scope: local
bookworm: resolved (fixed in 4.0.17-0+deb12u1)
bullseye: resolved (fixed in 3.4.16-0+deb11u1)
forky: resolved (fixed in 4.2.6-1)
sid: resolved (fixed in 4.2.6-1)
trixie: resolved (fixed in 4.2.6-1)
debian
CVE-2007-6439P4MEDIUMCVSS 5.0fixed in wireshark 0.99.7-1 (bookworm)2007
CVE-2007-6439 [MEDIUM] CVE-2007-6439: wireshark - Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial o...
Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (infinite or large loop) via the (1) IPv6 or (2) USB dissector, which can trigger resource consumption or a crash. NOTE: this identifier originally included Firebird/Interbase, but it is already covered by CVE-2007-6116. The DCP ETSI issue is already covered by CVE-2007-6119.
debian
CVE-2023-3648P4MEDIUMCVSS 5.3fixed in wireshark 4.0.11-1~deb12u1 (bookworm)2023
CVE-2023-3648 [MEDIUM] CVE-2023-3648: wireshark - Kafka dissector crash in Wireshark 4.0.0 to 4.0.6 and 3.6.0 to 3.6.14 allows den...
Kafka dissector crash in Wireshark 4.0.0 to 4.0.6 and 3.6.0 to 3.6.14 allows denial of service via packet injection or crafted capture file
Scope: local
bookworm: resolved (fixed in 4.0.11-1~deb12u1)
bullseye: resolved (fixed in 3.4.16-0+deb11u1)
forky: resolved (fixed in 4.0.7-1)
sid: resolved (fixed in 4.0.7-1)
trixie: resolved (fixed in 4.0.7-1)
debian
CVE-2009-4377P4MEDIUMCVSS 4.3fixed in wireshark 1.2.5-1 (bookworm)2009
CVE-2009-4377 [MEDIUM] CVE-2009-4377: wireshark - The (1) SMB and (2) SMB2 dissectors in Wireshark 0.9.0 through 1.2.4 allow remot...
The (1) SMB and (2) SMB2 dissectors in Wireshark 0.9.0 through 1.2.4 allow remote attackers to cause a denial of service (crash) via a crafted packet that triggers a NULL pointer dereference, as demonstrated by fuzz-2009-12-07-11141.pcap.
Scope: local
bookworm: resolved (fixed in 1.2.5-1)
bullseye: resolved (fixed in 1.2.5-1)
forky: resolved (fixed in 1.2.5-1)
sid
debian
CVE-2011-4101P4LOWCVSS 4.3fixed in wireshark 1.6.3-1 (bookworm)2011
CVE-2011-4101 [MEDIUM] CVE-2011-4101: wireshark - The dissect_infiniband_common function in epan/dissectors/packet-infiniband.c in...
The dissect_infiniband_common function in epan/dissectors/packet-infiniband.c in the Infiniband dissector in Wireshark 1.4.0 through 1.4.9 and 1.6.x before 1.6.3 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed packet.
Scope: local
bookworm: resolved (fixed in 1.6.3-1)
bullseye: resolved (fixed i
debian
CVE-2011-2175P4LOWCVSS 4.3fixed in wireshark 1.6.0-1 (bookworm)2011
CVE-2011-2175 [MEDIUM] CVE-2011-2175: wireshark - Integer underflow in the visual_read function in wiretap/visual.c in Wireshark 1...
Integer underflow in the visual_read function in wiretap/visual.c in Wireshark 1.2.x before 1.2.17 and 1.4.x before 1.4.7 allows remote attackers to cause a denial of service (application crash) via a malformed Visual Networks file that triggers a heap-based buffer over-read.
Scope: local
bookworm: resolved (fixed in 1.6.0-1)
bullseye: resolved (fixed in 1.6.0-1)
debian
CVE-2008-6472P4LOWCVSS 4.3fixed in wireshark 1.0.5-1 (bookworm)2008
CVE-2008-6472 [MEDIUM] CVE-2008-6472: wireshark - The WLCCP dissector in Wireshark 0.99.7 through 1.0.4 allows remote attackers to...
The WLCCP dissector in Wireshark 0.99.7 through 1.0.4 allows remote attackers to cause a denial of service (infinite loop) via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 1.0.5-1)
bullseye: resolved (fixed in 1.0.5-1)
forky: resolved (fixed in 1.0.5-1)
sid: resolved (fixed in 1.0.5-1)
trixie: resolved (fixed in 1.0.5-1)
debian
CVE-2013-6336P4MEDIUMCVSS 4.3fixed in wireshark 1.10.3-1 (bookworm)2013
CVE-2013-6336 [MEDIUM] CVE-2013-6336: wireshark - The ieee802154_map_rec function in epan/dissectors/packet-ieee802154.c in the IE...
The ieee802154_map_rec function in epan/dissectors/packet-ieee802154.c in the IEEE 802.15.4 dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 uses an incorrect pointer chain, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 1.10.3-1)
bullseye: resolved (
debian
CVE-2012-1595P4MEDIUMCVSS 4.3fixed in wireshark 1.6.6-1 (bookworm)2012
CVE-2012-1595 [MEDIUM] CVE-2012-1595: wireshark - The pcap_process_pseudo_header function in wiretap/pcap-common.c in Wireshark 1....
The pcap_process_pseudo_header function in wiretap/pcap-common.c in Wireshark 1.4.x before 1.4.12 and 1.6.x before 1.6.6 allows remote attackers to cause a denial of service (application crash) via a WTAP_ENCAP_ERF file containing an Extension or Multi-Channel header with an invalid pseudoheader size, related to the pcap and pcap-ng file parsers.
Scope: local
book
debian
CVE-2009-1268P4LOWCVSS 4.3fixed in wireshark 1.0.7-1 (bookworm)2009
CVE-2009-1268 [MEDIUM] CVE-2009-1268: wireshark - The Check Point High-Availability Protocol (CPHAP) dissector in Wireshark 0.9.6 ...
The Check Point High-Availability Protocol (CPHAP) dissector in Wireshark 0.9.6 through 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted FWHA_MY_STATE packet.
Scope: local
bookworm: resolved (fixed in 1.0.7-1)
bullseye: resolved (fixed in 1.0.7-1)
forky: resolved (fixed in 1.0.7-1)
sid: resolved (fixed in 1.0.7-1)
trixie: resolved (
debian