Debian Wireshark vulnerabilities
668 known vulnerabilities affecting debian/wireshark.
Total CVEs
668
CISA KEV
0
Public exploits
50
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH129MEDIUM276LOW255
Vulnerabilities
Page 32 of 34
CVE-2013-1578P4LOWCVSS 2.9fixed in wireshark 1.8.6-1 (bookworm)2013
CVE-2013-1578 [LOW] CVE-2013-1578: wireshark - The dissect_pw_eth_heuristic function in epan/dissectors/packet-pw-eth.c in Wire...
The dissect_pw_eth_heuristic function in epan/dissectors/packet-pw-eth.c in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly handle apparent Ethernet address values at the beginning of MPLS data, which allows remote attackers to cause a denial of service (loop) via a malformed packet.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye:
debian
CVE-2012-4286P4MEDIUMCVSS 4.3fixed in wireshark 1.8.2-1 (bookworm)2012
CVE-2012-4286 [MEDIUM] CVE-2012-4286: wireshark - The pcapng_read_packet_block function in wiretap/pcapng.c in the pcap-ng file pa...
The pcapng_read_packet_block function in wiretap/pcapng.c in the pcap-ng file parser in Wireshark 1.8.x before 1.8.2 allows user-assisted remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted pcap-ng file.
Scope: local
bookworm: resolved (fixed in 1.8.2-1)
bullseye: resolved (fixed in 1.8.2-1)
forky: resolved (fix
debian
CVE-2012-4289P4LOWCVSS 3.3fixed in wireshark 1.8.2-1 (bookworm)2012
CVE-2012-4289 [LOW] CVE-2012-4289: wireshark - epan/dissectors/packet-afp.c in the AFP dissector in Wireshark 1.4.x before 1.4....
epan/dissectors/packet-afp.c in the AFP dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (loop and CPU consumption) via a large number of ACL entries.
Scope: local
bookworm: resolved (fixed in 1.8.2-1)
bullseye: resolved (fixed in 1.8.2-1)
forky: resolved (fixed in 1.8.2-1)
si
debian
CVE-2012-4291P4LOWCVSS 3.3fixed in wireshark 1.8.2-1 (bookworm)2012
CVE-2012-4291 [LOW] CVE-2012-4291: wireshark - The CIP dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8...
The CIP dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (memory consumption) via a malformed packet.
Scope: local
bookworm: resolved (fixed in 1.8.2-1)
bullseye: resolved (fixed in 1.8.2-1)
forky: resolved (fixed in 1.8.2-1)
sid: resolved (fixed in 1.8.2-1)
trixie: resolved (
debian
CVE-2012-4290P4LOWCVSS 3.3fixed in wireshark 1.8.2-1 (bookworm)2012
CVE-2012-4290 [LOW] CVE-2012-4290: wireshark - The CTDB dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1....
The CTDB dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (loop and CPU consumption) via a malformed packet.
Scope: local
bookworm: resolved (fixed in 1.8.2-1)
bullseye: resolved (fixed in 1.8.2-1)
forky: resolved (fixed in 1.8.2-1)
sid: resolved (fixed in 1.8.2-1)
trixie: res
debian
CVE-2012-4293P4LOWCVSS 3.3fixed in wireshark 1.8.2-1 (bookworm)2012
CVE-2012-4293 [LOW] CVE-2012-4293: wireshark - plugins/ethercat/packet-ecatmb.c in the EtherCAT Mailbox dissector in Wireshark ...
plugins/ethercat/packet-ecatmb.c in the EtherCAT Mailbox dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 does not properly handle certain integer fields, which allows remote attackers to cause a denial of service (application exit) via a malformed packet.
Scope: local
bookworm: resolved (fixed in 1.8.2-1)
bullseye: resolved (fi
debian
CVE-2013-2479P4LOWCVSS 3.3fixed in wireshark 1.8.6-1 (bookworm)2013
CVE-2013-2479 [LOW] CVE-2013-2479: wireshark - The dissect_mpls_echo_tlv_dd_map function in epan/dissectors/packet-mpls-echo.c ...
The dissect_mpls_echo_tlv_dd_map function in epan/dissectors/packet-mpls-echo.c in the MPLS Echo dissector in Wireshark 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (infinite loop) via invalid Sub-tlv data.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolv
debian
CVE-2012-5238P4LOWCVSS 3.3fixed in wireshark 1.8.2-2 (bookworm)2012
CVE-2012-5238 [LOW] CVE-2012-5238: wireshark - epan/dissectors/packet-ppp.c in the PPP dissector in Wireshark 1.8.x before 1.8....
epan/dissectors/packet-ppp.c in the PPP dissector in Wireshark 1.8.x before 1.8.3 uses incorrect OUI data structures during the decoding of (1) PPP and (2) LCP data, which allows remote attackers to cause a denial of service (assertion failure and application exit) via a malformed packet.
Scope: local
bookworm: resolved (fixed in 1.8.2-2)
bullseye: resolved (fixed in
debian
CVE-2013-1573P4LOWCVSS 2.9fixed in wireshark 1.8.6-1 (bookworm)2013
CVE-2013-1573 [LOW] CVE-2013-1573: wireshark - The csnStreamDissector function in epan/dissectors/packet-csn1.c in the CSN.1 di...
The csnStreamDissector function in epan/dissectors/packet-csn1.c in the CSN.1 dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly handle a large number of padding bits, which allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved
debian
CVE-2013-1574P4LOWCVSS 2.9fixed in wireshark 1.8.6-1 (bookworm)2013
CVE-2013-1574 [LOW] CVE-2013-1574: wireshark - The dissect_bthci_eir_ad_data function in epan/dissectors/packet-bthci_cmd.c in ...
The dissect_bthci_eir_ad_data function in epan/dissectors/packet-bthci_cmd.c in the Bluetooth HCI dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 uses an incorrect data type for a counter variable, which allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bul
debian
CVE-2013-1572P4LOWCVSS 2.9fixed in wireshark 1.8.6-1 (bookworm)2013
CVE-2013-1572 [LOW] CVE-2013-1572: wireshark - The dissect_oampdu_event_notification function in epan/dissectors/packet-slowpro...
The dissect_oampdu_event_notification function in epan/dissectors/packet-slowprotocols.c in the IEEE 802.3 Slow Protocols dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly handle certain short lengths, which allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.
Scope: local
bookworm: resolved (f
debian
CVE-2013-1581P4LOWCVSS 2.9fixed in wireshark 1.8.6-1 (bookworm)2013
CVE-2013-1581 [LOW] CVE-2013-1581: wireshark - The dissect_pft_fec_detailed function in epan/dissectors/packet-dcp-etsi.c in th...
The dissect_pft_fec_detailed function in epan/dissectors/packet-dcp-etsi.c in the DCP-ETSI dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly handle fragment gaps, which allows remote attackers to cause a denial of service (loop) via a malformed packet.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.
debian
CVE-2013-1577P4LOWCVSS 2.9fixed in wireshark 1.8.6-1 (bookworm)2013
CVE-2013-1577 [LOW] CVE-2013-1577: wireshark - The dissect_sip_p_charging_func_addresses function in epan/dissectors/packet-sip...
The dissect_sip_p_charging_func_addresses function in epan/dissectors/packet-sip.c in the SIP dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly handle offset data associated with a quoted string, which allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.
Scope: local
bookworm: resolved (fixed i
debian
CVE-2013-1576P4LOWCVSS 2.9fixed in wireshark 1.8.6-1 (bookworm)2013
CVE-2013-1576 [LOW] CVE-2013-1576: wireshark - The dissect_sdp_media_attribute function in epan/dissectors/packet-sdp.c in the ...
The dissect_sdp_media_attribute function in epan/dissectors/packet-sdp.c in the SDP dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly process crypto-suite parameters, which allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved
debian
CVE-2013-1579P4LOWCVSS 2.9fixed in wireshark 1.8.6-1 (bookworm)2013
CVE-2013-1579 [LOW] CVE-2013-1579: wireshark - The rtps_util_add_bitmap function in epan/dissectors/packet-rtps.c in the RTPS d...
The rtps_util_add_bitmap function in epan/dissectors/packet-rtps.c in the RTPS dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly implement certain nested loops for processing bitmap data, which allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.
Scope: local
bookworm: resolved (fixed in 1.8.6-
debian
CVE-2012-4288P4LOWCVSS 3.3fixed in wireshark 1.8.2-1 (bookworm)2012
CVE-2012-4288 [LOW] CVE-2012-4288: wireshark - Integer overflow in the dissect_xtp_ecntl function in epan/dissectors/packet-xtp...
Integer overflow in the dissect_xtp_ecntl function in epan/dissectors/packet-xtp.c in the XTP dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (loop or application crash) via a large value for a span length.
Scope: local
bookworm: resolved (fixed in 1.8.2-1)
bullseye: resolved
debian
CVE-2010-2286P4LOWCVSS 3.3fixed in wireshark 1.2.9-1 (bookworm)2010
CVE-2010-2286 [LOW] CVE-2010-2286: wireshark - The SigComp Universal Decompressor Virtual Machine dissector in Wireshark 0.10.7...
The SigComp Universal Decompressor Virtual Machine dissector in Wireshark 0.10.7 through 1.0.13 and 1.2.0 through 1.2.8 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.
Scope: local
bookworm: resolved (fixed in 1.2.9-1)
bullseye: resolved (fixed in 1.2.9-1)
forky: resolved (fixed in 1.2.9-1)
sid: resolved (fixed in 1.2.9-1)
tr
debian
CVE-2012-5237P4LOWCVSS 3.3fixed in wireshark 1.8.2-2 (bookworm)2012
CVE-2012-5237 [LOW] CVE-2012-5237: wireshark - The dissect_hsrp function in epan/dissectors/packet-hsrp.c in the HSRP dissector...
The dissect_hsrp function in epan/dissectors/packet-hsrp.c in the HSRP dissector in Wireshark 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.
Scope: local
bookworm: resolved (fixed in 1.8.2-2)
bullseye: resolved (fixed in 1.8.2-2)
forky: resolved (fixed in 1.8.2-2)
sid: resolved (fixed in 1.8.2-2)
trixie
debian
CVE-2012-0042P4LOWCVSS 2.9fixed in wireshark 1.6.5-1 (bookworm)2012
CVE-2012-0042 [LOW] CVE-2012-0042: wireshark - Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 does not properly perform c...
Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 does not properly perform certain string conversions, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted packet, related to epan/to_str.c.
Scope: local
bookworm: resolved (fixed in 1.6.5-1)
bullseye: resolved (fixed in 1.6.5-1)
forky: resolved (
debian
CVE-2013-1575P4LOWCVSS 2.9fixed in wireshark 1.8.6-1 (bookworm)2013
CVE-2013-1575 [LOW] CVE-2013-1575: wireshark - The dissect_r3_cmd_alarmconfigure function in epan/dissectors/packet-assa_r3.c i...
The dissect_r3_cmd_alarmconfigure function in epan/dissectors/packet-assa_r3.c in the R3 dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly handle a certain alarm length, which allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resol
debian