Debian Wireshark vulnerabilities
668 known vulnerabilities affecting debian/wireshark.
Total CVEs
668
CISA KEV
0
Public exploits
50
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH129MEDIUM276LOW255
Vulnerabilities
Page 33 of 34
CVE-2013-1580P4LOWCVSS 2.9fixed in wireshark 1.8.6-1 (bookworm)2013
CVE-2013-1580 [LOW] CVE-2013-1580: wireshark - The dissect_cmstatus_tlv function in plugins/docsis/packet-cmstatus.c in the DOC...
The dissect_cmstatus_tlv function in plugins/docsis/packet-cmstatus.c in the DOCSIS CM-STATUS dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 uses an incorrect data type for a position variable, which allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullse
debian
CVE-2009-0600P4MEDIUMCVSS 4.3fixed in wireshark 1.0.6-1 (bookworm)2009
CVE-2009-0600 [MEDIUM] CVE-2009-0600: wireshark - Wireshark 0.99.6 through 1.0.5 allows user-assisted remote attackers to cause a ...
Wireshark 0.99.6 through 1.0.5 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted Tektronix K12 text capture file, as demonstrated by a file with exactly one frame.
Scope: local
bookworm: resolved (fixed in 1.0.6-1)
bullseye: resolved (fixed in 1.0.6-1)
forky: resolved (fixed in 1.0.6-1)
sid: resolved (fixed in 1.0
debian
CVE-2013-2478P4LOWCVSS 3.3fixed in wireshark 1.8.2-5 (bookworm)2013
CVE-2013-2478 [LOW] CVE-2013-2478: wireshark - The dissect_server_info function in epan/dissectors/packet-ms-mms.c in the MS-MM...
The dissect_server_info function in epan/dissectors/packet-ms-mms.c in the MS-MMS dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 does not properly manage string lengths, which allows remote attackers to cause a denial of service (application crash) via a malformed packet that (1) triggers an integer overflow or (2) has embedded '\0' characters in a
debian
CVE-2007-6441P4LOWCVSS 3.3fixed in wireshark 0.99.7-1 (bookworm)2007
CVE-2007-6441 [LOW] CVE-2007-6441: wireshark - The WiMAX dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attack...
The WiMAX dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (crash) via unknown vectors related to "unaligned access on some platforms."
Scope: local
bookworm: resolved (fixed in 0.99.7-1)
bullseye: resolved (fixed in 0.99.7-1)
forky: resolved (fixed in 0.99.7-1)
sid: resolved (fixed in 0.99.7-1)
trixie: resolved (
debian
CVE-2012-4285P4LOWCVSS 3.3fixed in wireshark 1.8.2-1 (bookworm)2012
CVE-2012-4285 [LOW] CVE-2012-4285: wireshark - The dissect_pft function in epan/dissectors/packet-dcp-etsi.c in the DCP ETSI di...
The dissect_pft function in epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a zero-length message.
Scope: local
bookworm: resolved (fixed in 1.8.2-1)
bullseye: resolved (fixed i
debian
CVE-2010-2285P4LOWCVSS 3.3fixed in wireshark 1.2.9-1 (bookworm)2010
CVE-2010-2285 [LOW] CVE-2010-2285: wireshark - The SMB PIPE dissector in Wireshark 0.8.20 through 1.0.13 and 1.2.0 through 1.2....
The SMB PIPE dissector in Wireshark 0.8.20 through 1.0.13 and 1.2.0 through 1.2.8 allows remote attackers to cause a denial of service (NULL pointer dereference) via unknown vectors.
Scope: local
bookworm: resolved (fixed in 1.2.9-1)
bullseye: resolved (fixed in 1.2.9-1)
forky: resolved (fixed in 1.2.9-1)
sid: resolved (fixed in 1.2.9-1)
trixie: resolved (fixed in 1.
debian
CVE-2010-2283P4LOWCVSS 3.3fixed in wireshark 1.2.9-1 (bookworm)2010
CVE-2010-2283 [LOW] CVE-2010-2283: wireshark - The SMB dissector in Wireshark 0.99.6 through 1.0.13, and 1.2.0 through 1.2.8 al...
The SMB dissector in Wireshark 0.99.6 through 1.0.13, and 1.2.0 through 1.2.8 allows remote attackers to cause a denial of service (NULL pointer dereference) via unknown vectors.
Scope: local
bookworm: resolved (fixed in 1.2.9-1)
bullseye: resolved (fixed in 1.2.9-1)
forky: resolved (fixed in 1.2.9-1)
sid: resolved (fixed in 1.2.9-1)
trixie: resolved (fixed in 1.2.9-
debian
CVE-2008-3933P4LOWCVSS 3.3fixed in wireshark 1.0.3-1 (bookworm)2008
CVE-2008-3933 [LOW] CVE-2008-3933: wireshark - Wireshark (formerly Ethereal) 0.10.14 through 1.0.2 allows attackers to cause a ...
Wireshark (formerly Ethereal) 0.10.14 through 1.0.2 allows attackers to cause a denial of service (crash) via a packet with crafted zlib-compressed data that triggers an invalid read in the tvb_uncompress function.
Scope: local
bookworm: resolved (fixed in 1.0.3-1)
bullseye: resolved (fixed in 1.0.3-1)
forky: resolved (fixed in 1.0.3-1)
sid: resolved (fixed in 1.0.3-
debian
CVE-2011-3266P4LOWCVSS 2.6fixed in wireshark 1.6.2-1 (bookworm)2011
CVE-2011-3266 [LOW] CVE-2011-3266: wireshark - The proto_tree_add_item function in Wireshark 1.6.0 through 1.6.1 and 1.4.0 thro...
The proto_tree_add_item function in Wireshark 1.6.0 through 1.6.1 and 1.4.0 through 1.4.8, when the IKEv1 protocol dissector is used, allows user-assisted remote attackers to cause a denial of service (infinite loop) via vectors involving a malformed IKE packet and many items in a tree.
Scope: local
bookworm: resolved (fixed in 1.6.2-1)
bullseye: resolved (fixed in 1
debian
CVE-2013-2481P4LOWCVSS 2.9fixed in wireshark 1.8.2-5 (bookworm)2013
CVE-2013-2481 [LOW] CVE-2013-2481: wireshark - Integer signedness error in the dissect_mount_dirpath_call function in epan/diss...
Integer signedness error in the dissect_mount_dirpath_call function in epan/dissectors/packet-mount.c in the Mount dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6, when nfs_file_name_snooping is enabled, allows remote attackers to cause a denial of service (application crash) via a negative length value.
Scope: local
bookworm: resolved (fixed in 1.8
debian
CVE-2013-1582P4LOWCVSS 2.9fixed in wireshark 1.8.6-1 (bookworm)2013
CVE-2013-1582 [LOW] CVE-2013-1582: wireshark - The dissect_clnp function in epan/dissectors/packet-clnp.c in the CLNP dissector...
The dissect_clnp function in epan/dissectors/packet-clnp.c in the CLNP dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly manage an offset variable, which allows remote attackers to cause a denial of service (infinite loop or application crash) via a malformed packet.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolv
debian
CVE-2013-1585P4LOWCVSS 2.9fixed in wireshark 1.8.6-1 (bookworm)2013
CVE-2013-1585 [LOW] CVE-2013-1585: wireshark - epan/tvbuff.c in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not p...
epan/tvbuff.c in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly validate certain length values for the MS-MMC dissector, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-
debian
CVE-2013-1586P4LOWCVSS 2.9fixed in wireshark 1.8.6-1 (bookworm)2013
CVE-2013-1586 [LOW] CVE-2013-1586: wireshark - The fragment_set_tot_len function in epan/reassemble.c in Wireshark 1.6.x before...
The fragment_set_tot_len function in epan/reassemble.c in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly determine the length of a reassembled packet for the DTLS dissector, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolve
debian
CVE-2012-4048P4LOWCVSS 3.3fixed in wireshark 1.8.2-1 (bookworm)2012
CVE-2012-4048 [LOW] CVE-2012-4048: wireshark - The PPP dissector in Wireshark 1.4.x before 1.4.14, 1.6.x before 1.6.9, and 1.8....
The PPP dissector in Wireshark 1.4.x before 1.4.14, 1.6.x before 1.6.9, and 1.8.x before 1.8.1 allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) via a crafted packet, as demonstrated by a usbmon dump.
Scope: local
bookworm: resolved (fixed in 1.8.2-1)
bullseye: resolved (fixed in 1.8.2-1)
forky: resolved (fixed i
debian
CVE-2013-2483P4LOWCVSS 3.3fixed in wireshark 1.8.2-5 (bookworm)2013
CVE-2013-2483 [LOW] CVE-2013-2483: wireshark - The acn_add_dmp_data function in epan/dissectors/packet-acn.c in the ACN dissect...
The acn_add_dmp_data function in epan/dissectors/packet-acn.c in the ACN dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via an invalid count value in ACN_DMP_ADT_D_RE DMP data.
Scope: local
bookworm: resolved (fixed in 1.8.2-5)
bullseye: resolved (fixe
debian
CVE-2013-1590P4LOWCVSS 2.9fixed in wireshark 1.8.6-1 (bookworm)2013
CVE-2013-1590 [LOW] CVE-2013-1590: wireshark - Buffer overflow in the NTLMSSP dissector in Wireshark 1.6.x before 1.6.13 and 1....
Buffer overflow in the NTLMSSP dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 allows remote attackers to cause a denial of service (application crash) via a malformed packet.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1.8.6-1)
trixie: resolved (
debian
CVE-2013-1588P4LOWCVSS 2.9fixed in wireshark 1.8.6-1 (bookworm)2013
CVE-2013-1588 [LOW] CVE-2013-1588: wireshark - Multiple buffer overflows in the dissect_pft_fec_detailed function in the DCP-ET...
Multiple buffer overflows in the dissect_pft_fec_detailed function in the DCP-ETSI dissector in epan/dissectors/packet-dcp-etsi.c in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 allow remote attackers to cause a denial of service (application crash) via a malformed packet.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1
debian
CVE-2013-1583P4LOWCVSS 2.9fixed in wireshark 1.8.6-1 (bookworm)2013
CVE-2013-1583 [LOW] CVE-2013-1583: wireshark - The dissect_version_4_primary_header function in epan/dissectors/packet-dtn.c in...
The dissect_version_4_primary_header function in epan/dissectors/packet-dtn.c in the DTN dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 accesses an inappropriate pointer, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed
debian
CVE-2013-1584P4LOWCVSS 2.9fixed in wireshark 1.8.6-1 (bookworm)2013
CVE-2013-1584 [LOW] CVE-2013-1584: wireshark - The dissect_version_5_and_6_primary_header function in epan/dissectors/packet-dt...
The dissect_version_5_and_6_primary_header function in epan/dissectors/packet-dtn.c in the DTN dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 accesses an inappropriate pointer, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved
debian
CVE-2012-4295P4LOWCVSS 3.3fixed in wireshark 1.8.2-1 (bookworm)2012
CVE-2012-4295 [LOW] CVE-2012-4295: wireshark - Array index error in the channelised_fill_sdh_g707_format function in epan/disse...
Array index error in the channelised_fill_sdh_g707_format function in epan/dissectors/packet-erf.c in the ERF dissector in Wireshark 1.8.x before 1.8.2 might allow remote attackers to cause a denial of service (application crash) via a crafted speed (aka rate) value.
Scope: local
bookworm: resolved (fixed in 1.8.2-1)
bullseye: resolved (fixed in 1.8.2-1)
forky: resol
debian