cbcvebase.

Debian Wireshark vulnerabilities

668 known vulnerabilities affecting debian/wireshark.

Total CVEs
668
CISA KEV
0
Public exploits
50
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH129MEDIUM276LOW255

Vulnerabilities

Page 3 of 34
CVE-2015-8729P4MEDIUMCVSS 5.5PoCfixed in wireshark 2.0.1+g59ea380-1 (bookworm)2015
CVE-2015-8729 [MEDIUM] CVE-2015-8729: wireshark - The ascend_seek function in wiretap/ascendtext.c in the Ascend file parser in Wi... The ascend_seek function in wiretap/ascendtext.c in the Ascend file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not ensure the presence of a '\0' character at the end of a date string, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file. Scope: local bookworm: resolved (f
debian
CVE-2021-39925P3HIGHCVSS 7.5fixed in wireshark 3.6.0-1 (bookworm)2021
CVE-2021-39925 [HIGH] CVE-2021-39925: wireshark - Buffer overflow in the Bluetooth SDP dissector in Wireshark 3.4.0 to 3.4.9 and 3... Buffer overflow in the Bluetooth SDP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved (fixed in 3.6.0-1) bullseye: resolved (fixed in 3.4.10-0+deb11u1) forky: resolved (fixed in 3.6.0-1) sid: resolved (fixed in 3.6.0-1) trixie: resolved (fixed in 3.6.0-1)
debian
CVE-2021-39926P3HIGHCVSS 7.5fixed in wireshark 3.6.0-1 (bookworm)2021
CVE-2021-39926 [HIGH] CVE-2021-39926: wireshark - Buffer overflow in the Bluetooth HCI_ISO dissector in Wireshark 3.4.0 to 3.4.9 a... Buffer overflow in the Bluetooth HCI_ISO dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved (fixed in 3.6.0-1) bullseye: resolved (fixed in 3.4.10-0+deb11u1) forky: resolved (fixed in 3.6.0-1) sid: resolved (fixed in 3.6.0-1) trixie: resolved (fixed in 3.6.0-1)
debian
CVE-2007-6115P3MEDIUMCVSS 10.0fixed in wireshark 0.99.7~pre1-1 (bookworm)2007
CVE-2007-6115 [CRITICAL] CVE-2007-6115: wireshark - Buffer overflow in the ANSI MAP dissector for Wireshark (formerly Ethereal) 0.99... Buffer overflow in the ANSI MAP dissector for Wireshark (formerly Ethereal) 0.99.5 to 0.99.6, when running on unspecified platforms, allows remote attackers to cause a denial of service and possibly execute arbitrary code via unknown vectors. Scope: local bookworm: resolved (fixed in 0.99.7~pre1-1) bullseye: resolved (fixed in 0.99.7~pre1-1) forky: resolved (fix
debian
CVE-2014-4174P3CRITICALCVSS 9.3fixed in wireshark 1.10.4-1 (bookworm)2014
CVE-2014-4174 [CRITICAL] CVE-2014-4174: wireshark - wiretap/libpcap.c in the libpcap file parser in Wireshark 1.10.x before 1.10.4 a... wiretap/libpcap.c in the libpcap file parser in Wireshark 1.10.x before 1.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted packet-trace file that includes a large packet. Scope: local bookworm: resolved (fixed in 1.10.4-1) bullseye: resolved (fixed in 1.10.4-1) forky: reso
debian
CVE-2010-2995P3HIGHCVSS 8.3fixed in wireshark 1.2.10-1 (bookworm)2010
CVE-2010-2995 [HIGH] CVE-2010-2995: wireshark - The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0.10.8 th... The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0.10.8 through 1.0.14 and 1.2.0 through 1.2.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to sigcomp-udvm.c and an off-by-one error, which triggers a buffer overflow, different vulnerabilities than CVE-2010-2287. Scope: loca
debian
CVE-2007-6112P3MEDIUMCVSS 10.0fixed in wireshark 0.99.7~pre1-1 (bookworm)2007
CVE-2007-6112 [CRITICAL] CVE-2007-6112: wireshark - Buffer overflow in the PPP dissector Wireshark (formerly Ethereal) 0.99.6 allows... Buffer overflow in the PPP dissector Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors. Scope: local bookworm: resolved (fixed in 0.99.7~pre1-1) bullseye: resolved (fixed in 0.99.7~pre1-1) forky: resolved (fixed in 0.99.7~pre1-1) sid: resolved (fixed in 0.99.7
debian
CVE-2011-1143P4LOWCVSS 4.3PoCfixed in wireshark 1.4.4-1 (bookworm)2011
CVE-2011-1143 [MEDIUM] CVE-2011-1143: wireshark - epan/dissectors/packet-ntlmssp.c in the NTLMSSP dissector in Wireshark before 1.... epan/dissectors/packet-ntlmssp.c in the NTLMSSP dissector in Wireshark before 1.4.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted .pcap file. Scope: local bookworm: resolved (fixed in 1.4.4-1) bullseye: resolved (fixed in 1.4.4-1) forky: resolved (fixed in 1.4.4-1) sid: resolved (fixed in 1.4.4-
debian
CVE-2018-19623P3HIGHCVSS 7.5fixed in wireshark 2.6.5-1 (bookworm)2018
CVE-2018-19623 [HIGH] CVE-2018-19623: wireshark - In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the LBMPDM dissector could cras... In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the LBMPDM dissector could crash. In addition, a remote attacker could write arbitrary data to any memory locations before the packet-scoped memory. This was addressed in epan/dissectors/packet-lbmpdm.c by disallowing certain negative values. Scope: local bookworm: resolved (fixed in 2.6.5-1) bullseye: resolved (fix
debian
CVE-2008-3140P4LOWCVSS 5.0PoCfixed in wireshark 1.0.1-1 (bookworm)2008
CVE-2008-3140 [MEDIUM] CVE-2008-3140: wireshark - The syslog dissector in Wireshark (formerly Ethereal) 1.0.0 allows remote attack... The syslog dissector in Wireshark (formerly Ethereal) 1.0.0 allows remote attackers to cause a denial of service (application crash) via unknown vectors, possibly related to an "incomplete SS7 MSU syslog encapsulated packet." Scope: local bookworm: resolved (fixed in 1.0.1-1) bullseye: resolved (fixed in 1.0.1-1) forky: resolved (fixed in 1.0.1-1) sid: resolved (f
debian
CVE-2008-1561P4LOWCVSS 5.0PoCfixed in wireshark 1.0.0-1 (bookworm)2008
CVE-2008-1561 [MEDIUM] CVE-2008-1561: wireshark - Multiple unspecified vulnerabilities in Wireshark (formerly Ethereal) 0.99.5 thr... Multiple unspecified vulnerabilities in Wireshark (formerly Ethereal) 0.99.5 through 0.99.8 allow remote attackers to cause a denial of service (application crash) via a malformed packet to the (1) X.509sat or (2) Roofnet dissectors. NOTE: Vector 2 might also lead to a hang. Scope: local bookworm: resolved (fixed in 1.0.0-1) bullseye: resolved (fixed in 1.0.0-1) f
debian
CVE-2007-6114P3MEDIUMCVSS 10.0fixed in wireshark 0.99.7~pre1-1 (bookworm)2007
CVE-2007-6114 [CRITICAL] CVE-2007-6114: wireshark - Multiple buffer overflows in Wireshark (formerly Ethereal) 0.99.0 through 0.99.6... Multiple buffer overflows in Wireshark (formerly Ethereal) 0.99.0 through 0.99.6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) the SSL dissector or (2) the iSeries (OS/400) Communication trace file parser. Scope: local bookworm: resolved (fixed in 0.99.7~pre1-1) bullseye: resolved (fixed in 0.99.7~pre1-1)
debian
CVE-2019-13619P3LOWCVSS 7.5fixed in wireshark 2.6.10-1 (bookworm)2019
CVE-2019-13619 [HIGH] CVE-2019-13619: wireshark - In Wireshark 3.0.0 to 3.0.2, 2.6.0 to 2.6.9, and 2.4.0 to 2.4.15, the ASN.1 BER ... In Wireshark 3.0.0 to 3.0.2, 2.6.0 to 2.6.9, and 2.4.0 to 2.4.15, the ASN.1 BER dissector and related dissectors could crash. This was addressed in epan/asn1.c by properly restricting buffer increments. Scope: local bookworm: resolved (fixed in 2.6.10-1) bullseye: resolved (fixed in 2.6.10-1) forky: resolved (fixed in 2.6.10-1) sid: resolved (fixed in 2.6.10-1) tr
debian
CVE-2009-4376P3CRITICALCVSS 9.3fixed in wireshark 1.2.5-1 (bookworm)2009
CVE-2009-4376 [CRITICAL] CVE-2009-4376: wireshark - Buffer overflow in the daintree_sna_read function in the Daintree SNA file parse... Buffer overflow in the daintree_sna_read function in the Daintree SNA file parser in Wireshark 1.2.0 through 1.2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet. Scope: local bookworm: resolved (fixed in 1.2.5-1) bullseye: resolved (fixed in 1.2.5-1) forky: resolved (fixed in 1.2.5-1) sid: r
debian
CVE-2012-4297P3HIGHCVSS 8.3fixed in wireshark 1.8.2-1 (bookworm)2012
CVE-2012-4297 [HIGH] CVE-2012-4297: wireshark - Buffer overflow in the dissect_gsm_rlcmac_downlink function in epan/dissectors/p... Buffer overflow in the dissect_gsm_rlcmac_downlink function in epan/dissectors/packet-gsm_rlcmac.c in the GSM RLC MAC dissector in Wireshark 1.6.x before 1.6.10 and 1.8.x before 1.8.2 allows remote attackers to execute arbitrary code via a malformed packet. Scope: local bookworm: resolved (fixed in 1.8.2-1) bullseye: resolved (fixed in 1.8.2-1) forky: resolved (fixe
debian
CVE-2007-6113P4LOWCVSS 4.3PoCfixed in wireshark 0.99.6pre1-1 (bookworm)2007
CVE-2007-6113 [MEDIUM] CVE-2007-6113: wireshark - Integer signedness error in the DNP3 dissector in Wireshark (formerly Ethereal) ... Integer signedness error in the DNP3 dissector in Wireshark (formerly Ethereal) 0.10.12 to 0.99.6 allows remote attackers to cause a denial of service (long loop) via a malformed DNP3 packet. Scope: local bookworm: resolved (fixed in 0.99.6pre1-1) bullseye: resolved (fixed in 0.99.6pre1-1) forky: resolved (fixed in 0.99.6pre1-1) sid: resolved (fixed in 0.99.6pre1-
debian
CVE-2019-10895P3LOWCVSS 7.5fixed in wireshark 2.6.8-1 (bookworm)2019
CVE-2019-10895 [HIGH] CVE-2019-10895: wireshark - In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the NetScaler file pars... In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the NetScaler file parser could crash. This was addressed in wiretap/netscaler.c by improving data validation. Scope: local bookworm: resolved (fixed in 2.6.8-1) bullseye: resolved (fixed in 2.6.8-1) forky: resolved (fixed in 2.6.8-1) sid: resolved (fixed in 2.6.8-1) trixie: resolved (fixed in 2.6.8-1)
debian
CVE-2021-39922P3HIGHCVSS 7.5fixed in wireshark 3.6.0-1 (bookworm)2021
CVE-2021-39922 [HIGH] CVE-2021-39922: wireshark - Buffer overflow in the C12.22 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to... Buffer overflow in the C12.22 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved (fixed in 3.6.0-1) bullseye: resolved (fixed in 3.4.10-0+deb11u1) forky: resolved (fixed in 3.6.0-1) sid: resolved (fixed in 3.6.0-1) trixie: resolved (fixed in 3.6.0-1)
debian
CVE-2012-0067P4LOWCVSS 4.3PoCfixed in wireshark 1.6.5-1 (bookworm)2012
CVE-2012-0067 [MEDIUM] CVE-2012-0067: wireshark - wiretap/iptrace.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows... wiretap/iptrace.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a long packet in an AIX iptrace file. Scope: local bookworm: resolved (fixed in 1.6.5-1) bullseye: resolved (fixed in 1.6.5-1) forky: resolved (fixed in 1.6.5-1) sid: resolved (fixed in 1.6.5-1) trixie: resolved (fi
debian
CVE-2018-9261P3HIGHCVSS 7.5fixed in wireshark 2.4.6-1 (bookworm)2018
CVE-2018-9261 [HIGH] CVE-2018-9261: wireshark - In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the NBAP dissector could crash ... In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the NBAP dissector could crash with a large loop that ends with a heap-based buffer overflow. This was addressed in epan/dissectors/packet-nbap.c by prohibiting the self-linking of DCH-IDs. Scope: local bookworm: resolved (fixed in 2.4.6-1) bullseye: resolved (fixed in 2.4.6-1) forky: resolved (fixed in 2.4.6-1) sid:
debian
Debian Wireshark vulnerabilities | cvebase