Debian Wireshark vulnerabilities
668 known vulnerabilities affecting debian/wireshark.
Total CVEs
668
CISA KEV
0
Public exploits
50
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH129MEDIUM276LOW255
Vulnerabilities
Page 30 of 34
CVE-2012-3548P4LOWCVSS 4.3fixed in wireshark 1.8.2-2 (bookworm)2012
CVE-2012-3548 [MEDIUM] CVE-2012-3548: wireshark - The dissect_drda function in epan/dissectors/packet-drda.c in Wireshark 1.6.x th...
The dissect_drda function in epan/dissectors/packet-drda.c in Wireshark 1.6.x through 1.6.10 and 1.8.x through 1.8.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a small value for a certain length field in a capture file.
Scope: local
bookworm: resolved (fixed in 1.8.2-2)
bullseye: resolved (fixed in 1.8.2-2)
forky:
debian
CVE-2013-6337P4MEDIUMCVSS 4.3fixed in wireshark 1.10.3-1 (bookworm)2013
CVE-2013-6337 [MEDIUM] CVE-2013-6337: wireshark - Unspecified vulnerability in the NBAP dissector in Wireshark 1.8.x before 1.8.11...
Unspecified vulnerability in the NBAP dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 1.10.3-1)
bullseye: resolved (fixed in 1.10.3-1)
forky: resolved (fixed in 1.10.3-1)
sid: resolved (fixed in 1.10.3-1)
trix
debian
CVE-2026-0960P4MEDIUMCVSS 4.7fixed in wireshark 3.4.16-0+deb11u2 (bullseye)2026
CVE-2026-0960 [MEDIUM] CVE-2026-0960: wireshark - HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial...
HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of service
Scope: local
bookworm: open
bullseye: resolved (fixed in 3.4.16-0+deb11u2)
forky: resolved (fixed in 4.6.3-1)
sid: resolved (fixed in 4.6.3-1)
trixie: resolved (fixed in 4.4.13-0+deb13u1)
debian
CVE-2024-4853P4LOWCVSS 3.6fixed in wireshark 4.0.17-0+deb12u1 (bookworm)2024
CVE-2024-4853 [LOW] CVE-2024-4853: wireshark - Memory handling issue in editcap could cause denial of service via crafted captu...
Memory handling issue in editcap could cause denial of service via crafted capture file
Scope: local
bookworm: resolved (fixed in 4.0.17-0+deb12u1)
bullseye: resolved (fixed in 3.4.16-0+deb11u1)
forky: resolved (fixed in 4.2.5-1)
sid: resolved (fixed in 4.2.5-1)
trixie: resolved (fixed in 4.2.5-1)
debian
CVE-2008-4683P4LOWCVSS 5.0fixed in wireshark 1.0.4-1 (bookworm)2008
CVE-2008-4683 [MEDIUM] CVE-2008-4683: wireshark - The dissect_btacl function in packet-bthci_acl.c in the Bluetooth ACL dissector ...
The dissect_btacl function in packet-bthci_acl.c in the Bluetooth ACL dissector in Wireshark 0.99.2 through 1.0.3 allows remote attackers to cause a denial of service (application crash or abort) via a packet with an invalid length, related to an erroneous tvb_memcpy call.
Scope: local
bookworm: resolved (fixed in 1.0.4-1)
bullseye: resolved (fixed in 1.0.4-1)
for
debian
CVE-2008-3138P4LOWCVSS 5.0fixed in wireshark 1.0.1-1 (bookworm)2008
CVE-2008-3138 [MEDIUM] CVE-2008-3138: wireshark - The (1) PANA and (2) KISMET dissectors in Wireshark (formerly Ethereal) 0.99.3 t...
The (1) PANA and (2) KISMET dissectors in Wireshark (formerly Ethereal) 0.99.3 through 1.0.0 allow remote attackers to cause a denial of service (application stop) via unknown vectors.
Scope: local
bookworm: resolved (fixed in 1.0.1-1)
bullseye: resolved (fixed in 1.0.1-1)
forky: resolved (fixed in 1.0.1-1)
sid: resolved (fixed in 1.0.1-1)
trixie: resolved (fixed
debian
CVE-2011-1139P4LOWCVSS 4.3fixed in wireshark 1.4.4-1 (bookworm)2011
CVE-2011-1139 [MEDIUM] CVE-2011-1139: wireshark - wiretap/pcapng.c in Wireshark 1.2.0 through 1.2.14 and 1.4.0 through 1.4.3 allow...
wiretap/pcapng.c in Wireshark 1.2.0 through 1.2.14 and 1.4.0 through 1.4.3 allows remote attackers to cause a denial of service (application crash) via a pcap-ng file that contains a large packet-length field.
Scope: local
bookworm: resolved (fixed in 1.4.4-1)
bullseye: resolved (fixed in 1.4.4-1)
forky: resolved (fixed in 1.4.4-1)
sid: resolved (fixed in 1.4.4-1)
debian
CVE-2012-0066P4LOWCVSS 4.3fixed in wireshark 1.6.5-1 (bookworm)2012
CVE-2012-0066 [MEDIUM] CVE-2012-0066: wireshark - Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to ...
Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a long packet in a (1) Accellent 5Views (aka .5vw) file, (2) I4B trace file, or (3) NETMON 2 capture file.
Scope: local
bookworm: resolved (fixed in 1.6.5-1)
bullseye: resolved (fixed in 1.6.5-1)
forky: resolved (fixed in 1.6.5-1)
sid:
debian
CVE-2025-13945P4MEDIUMCVSS 5.5fixed in wireshark 3.4.16-0+deb11u2 (bullseye)2025
CVE-2025-13945 [MEDIUM] CVE-2025-13945: wireshark - HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service
HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service
Scope: local
bookworm: open
bullseye: resolved (fixed in 3.4.16-0+deb11u2)
forky: resolved (fixed in 4.6.2-1)
sid: resolved (fixed in 4.6.2-1)
trixie: resolved (fixed in 4.4.13-0+deb13u1)
debian
CVE-2025-13674P4LOWCVSS 5.5fixed in wireshark 4.6.1-1 (forky)2025
CVE-2025-13674 [MEDIUM] CVE-2025-13674: wireshark - BPv7 dissector crash in Wireshark 4.6.0 allows denial of service
BPv7 dissector crash in Wireshark 4.6.0 allows denial of service
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 4.6.1-1)
sid: resolved (fixed in 4.6.1-1)
trixie: resolved
debian
CVE-2011-2597P4LOWCVSS 4.3fixed in wireshark 1.6.1-1 (bookworm)2011
CVE-2011-2597 [MEDIUM] CVE-2011-2597: wireshark - The Lucent/Ascend file parser in Wireshark 1.2.x before 1.2.18, 1.4.x through 1....
The Lucent/Ascend file parser in Wireshark 1.2.x before 1.2.18, 1.4.x through 1.4.7, and 1.6.0 allows remote attackers to cause a denial of service (infinite loop) via malformed packets.
Scope: local
bookworm: resolved (fixed in 1.6.1-1)
bullseye: resolved (fixed in 1.6.1-1)
forky: resolved (fixed in 1.6.1-1)
sid: resolved (fixed in 1.6.1-1)
trixie: resolved (fixe
debian
CVE-2011-4100P4MEDIUMCVSS 4.3fixed in wireshark 1.6.3-1 (bookworm)2011
CVE-2011-4100 [MEDIUM] CVE-2011-4100: wireshark - The csnStreamDissector function in epan/dissectors/packet-csn1.c in the CSN.1 di...
The csnStreamDissector function in epan/dissectors/packet-csn1.c in the CSN.1 dissector in Wireshark 1.6.x before 1.6.3 does not initialize a certain variable, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.
Scope: local
bookworm: resolved (fixed in 1.6.3-1)
bullseye: resolved (fixed in 1.6.3-1)
forky: resolve
debian
CVE-2012-0041P4LOWCVSS 4.3fixed in wireshark 1.6.5-1 (bookworm)2012
CVE-2012-0041 [MEDIUM] CVE-2012-0041: wireshark - The dissect_packet function in epan/packet.c in Wireshark 1.4.x before 1.4.11 an...
The dissect_packet function in epan/packet.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a long packet in a capture file, as demonstrated by an airopeek file.
Scope: local
bookworm: resolved (fixed in 1.6.5-1)
bullseye: resolved (fixed in 1.6.5-1)
forky: resolved (fixed in 1.6
debian
CVE-2011-1590P4LOWCVSS 4.3fixed in wireshark 1.4.5-1 (bookworm)2011
CVE-2011-1590 [MEDIUM] CVE-2011-1590: wireshark - The X.509if dissector in Wireshark 1.2.x before 1.2.16 and 1.4.x before 1.4.5 do...
The X.509if dissector in Wireshark 1.2.x before 1.2.16 and 1.4.x before 1.4.5 does not properly initialize certain global variables, which allows remote attackers to cause a denial of service (application crash) via a crafted .pcap file.
Scope: local
bookworm: resolved (fixed in 1.4.5-1)
bullseye: resolved (fixed in 1.4.5-1)
forky: resolved (fixed in 1.4.5-1)
sid:
debian
CVE-2008-1071P4LOWCVSS 4.3fixed in wireshark 0.99.8-1 (bookworm)2008
CVE-2008-1071 [MEDIUM] CVE-2008-1071: wireshark - The SNMP dissector in Wireshark (formerly Ethereal) 0.99.6 through 0.99.7 allows...
The SNMP dissector in Wireshark (formerly Ethereal) 0.99.6 through 0.99.7 allows remote attackers to cause a denial of service (crash) via a malformed packet.
Scope: local
bookworm: resolved (fixed in 0.99.8-1)
bullseye: resolved (fixed in 0.99.8-1)
forky: resolved (fixed in 0.99.8-1)
sid: resolved (fixed in 0.99.8-1)
trixie: resolved (fixed in 0.99.8-1)
debian
CVE-2011-3482P4MEDIUMCVSS 4.3fixed in wireshark 1.6.2-1 (bookworm)2011
CVE-2011-3482 [MEDIUM] CVE-2011-3482: wireshark - The csnStreamDissector function in epan/dissectors/packet-csn1.c in the CSN.1 di...
The csnStreamDissector function in epan/dissectors/packet-csn1.c in the CSN.1 dissector in Wireshark 1.6.x before 1.6.2 does not initialize a certain structure member, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.
Scope: local
bookworm: resolved (fixed in 1.6.2-1)
bullseye: resolved (fixed in 1.6.2-1)
forky:
debian
CVE-2013-5722P4MEDIUMCVSS 4.3fixed in wireshark 1.10.2-1 (bookworm)2013
CVE-2013-5722 [MEDIUM] CVE-2013-5722: wireshark - Unspecified vulnerability in the LDAP dissector in Wireshark 1.8.x before 1.8.10...
Unspecified vulnerability in the LDAP dissector in Wireshark 1.8.x before 1.8.10 and 1.10.x before 1.10.2 allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 1.10.2-1)
bullseye: resolved (fixed in 1.10.2-1)
forky: resolved (fixed in 1.10.2-1)
sid: resolved (fixed in 1.10.2-1)
trix
debian
CVE-2014-4020P4MEDIUMCVSS 4.3fixed in wireshark 1.10.8-1 (bookworm)2014
CVE-2014-4020 [MEDIUM] CVE-2014-4020: wireshark - The dissect_frame function in epan/dissectors/packet-frame.c in the frame metadi...
The dissect_frame function in epan/dissectors/packet-frame.c in the frame metadissector in Wireshark 1.10.x before 1.10.8 interprets a negative integer as a length value even though it was intended to represent an error condition, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Scope: local
bookworm: resolved (f
debian
CVE-2009-0599P4MEDIUMCVSS 5.0fixed in wireshark 1.0.6-1 (bookworm)2009
CVE-2009-0599 [MEDIUM] CVE-2009-0599: wireshark - Buffer overflow in wiretap/netscreen.c in Wireshark 0.99.7 through 1.0.5 allows ...
Buffer overflow in wiretap/netscreen.c in Wireshark 0.99.7 through 1.0.5 allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed NetScreen snoop file.
Scope: local
bookworm: resolved (fixed in 1.0.6-1)
bullseye: resolved (fixed in 1.0.6-1)
forky: resolved (fixed in 1.0.6-1)
sid: resolved (fixed in 1.0.6-1)
trixie: res
debian
CVE-2015-8737P4MEDIUMCVSS 5.5fixed in wireshark 2.0.1+g59ea380-1 (bookworm)2015
CVE-2015-8737 [MEDIUM] CVE-2015-8737: wireshark - The mp2t_open function in wiretap/mp2t.c in the MP2T file parser in Wireshark 2....
The mp2t_open function in wiretap/mp2t.c in the MP2T file parser in Wireshark 2.0.x before 2.0.1 does not validate the bit rate, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted file.
Scope: local
bookworm: resolved (fixed in 2.0.1+g59ea380-1)
bullseye: resolved (fixed in 2.0.1+g59ea380-1)
forky:
debian