cbcvebase.

Debian Wireshark vulnerabilities

668 known vulnerabilities affecting debian/wireshark.

Total CVEs
668
CISA KEV
0
Public exploits
50
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH129MEDIUM276LOW255

Vulnerabilities

Page 7 of 34
CVE-2017-9351P3LOWCVSS 7.5fixed in wireshark 2.2.7-1 (bookworm)2017
CVE-2017-9351 [HIGH] CVE-2017-9351: wireshark - In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DHCP dissector could read p... In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DHCP dissector could read past the end of a buffer. This was addressed in epan/dissectors/packet-bootp.c by extracting the Vendor Class Identifier more carefully. Scope: local bookworm: resolved (fixed in 2.2.7-1) bullseye: resolved (fixed in 2.2.7-1) forky: resolved (fixed in 2.2.7-1) sid: resolved (fixed in 2.2.
debian
CVE-2017-17083P3HIGHCVSS 7.5fixed in wireshark 2.4.3-1 (bookworm)2017
CVE-2017-17083 [HIGH] CVE-2017-17083: wireshark - In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the NetBIOS dissector could cra... In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the NetBIOS dissector could crash. This was addressed in epan/dissectors/packet-netbios.c by ensuring that write operations are bounded by the beginning of a buffer. Scope: local bookworm: resolved (fixed in 2.4.3-1) bullseye: resolved (fixed in 2.4.3-1) forky: resolved (fixed in 2.4.3-1) sid: resolved (fixed in 2.4
debian
CVE-2017-7705P3HIGHCVSS 7.5fixed in wireshark 2.2.6+g32dac6a-1 (bookworm)2017
CVE-2017-7705 [HIGH] CVE-2017-7705: wireshark - In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the RPC over RDMA dissector cou... In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the RPC over RDMA dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-rpcrdma.c by correctly checking for going beyond the maximum offset. Scope: local bookworm: resolved (fixed in 2.2.6+g32dac6a-1) bullseye: resolved (fixed
debian
CVE-2017-7702P3LOWCVSS 7.5fixed in wireshark 2.2.6+g32dac6a-1 (bookworm)2017
CVE-2017-7702 [HIGH] CVE-2017-7702: wireshark - In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the WBXML dissector could go in... In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the WBXML dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-wbxml.c by adding length validation. Scope: local bookworm: resolved (fixed in 2.2.6+g32dac6a-1) bullseye: resolved (fixed in 2.2.6+g32dac6a-1) forky: resolved (fi
debian
CVE-2017-7701P3HIGHCVSS 7.5fixed in wireshark 2.2.6+g32dac6a-1 (bookworm)2017
CVE-2017-7701 [HIGH] CVE-2017-7701: wireshark - In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the BGP dissector could go into... In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the BGP dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-bgp.c by using a different integer data type. Scope: local bookworm: resolved (fixed in 2.2.6+g32dac6a-1) bullseye: resolved (fixed in 2.2.6+g32dac6a-1) forky: resol
debian
CVE-2018-7417P3LOWCVSS 7.5fixed in wireshark 2.4.5-1 (bookworm)2018
CVE-2018-7417 [HIGH] CVE-2018-7417: wireshark - In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the IPMI dissector could crash.... In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the IPMI dissector could crash. This was addressed in epan/dissectors/packet-ipmi-picmg.c by adding support for crafted packets that lack an IPMI header. Scope: local bookworm: resolved (fixed in 2.4.5-1) bullseye: resolved (fixed in 2.4.5-1) forky: resolved (fixed in 2.4.5-1) sid: resolved (fixed in 2.4.5-1) trixie:
debian
CVE-2017-7747P3HIGHCVSS 7.5fixed in wireshark 2.2.6+g32dac6a-1 (bookworm)2017
CVE-2017-7747 [HIGH] CVE-2017-7747: wireshark - In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the PacketBB dissector could cr... In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the PacketBB dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-packetbb.c by restricting additions to the protocol tree. Scope: local bookworm: resolved (fixed in 2.2.6+g32dac6a-1) bullseye: resolved (fixed in 2.2.6+g32dac6a-1) forky: resolve
debian
CVE-2024-2955P3HIGHCVSS 7.8fixed in wireshark 4.0.17-0+deb12u1 (bookworm)2024
CVE-2024-2955 [HIGH] CVE-2024-2955: wireshark - T.38 dissector crash in Wireshark 4.2.0 to 4.0.3 and 4.0.0 to 4.0.13 allows deni... T.38 dissector crash in Wireshark 4.2.0 to 4.0.3 and 4.0.0 to 4.0.13 allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved (fixed in 4.0.17-0+deb12u1) bullseye: resolved (fixed in 3.4.16-0+deb11u1) forky: resolved (fixed in 4.2.4-1) sid: resolved (fixed in 4.2.4-1) trixie: resolved (fixed in 4.2.4-1)
debian
CVE-2025-1492P3HIGHCVSS 7.8fixed in wireshark 4.4.4-1 (forky)2025
CVE-2025-1492 [HIGH] CVE-2025-1492: wireshark - Bundle Protocol and CBOR dissector crashes in Wireshark 4.4.0 to 4.4.3 and 4.2.0... Bundle Protocol and CBOR dissector crashes in Wireshark 4.4.0 to 4.4.3 and 4.2.0 to 4.2.10 allows denial of service via packet injection or crafted capture file Scope: local bookworm: open bullseye: resolved forky: resolved (fixed in 4.4.4-1) sid: resolved (fixed in 4.4.4-1) trixie: resolved (fixed in 4.4.4-1)
debian
CVE-2021-4186P3MEDIUMCVSS 6.3fixed in wireshark 3.6.0-1 (bookworm)2021
CVE-2021-4186 [MEDIUM] CVE-2021-4186: wireshark - Crash in the Gryphon dissector in Wireshark 3.4.0 to 3.4.10 allows denial of ser... Crash in the Gryphon dissector in Wireshark 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved (fixed in 3.6.0-1) bullseye: resolved (fixed in 3.4.16-0+deb11u1) forky: resolved (fixed in 3.6.0-1) sid: resolved (fixed in 3.6.0-1) trixie: resolved (fixed in 3.6.0-1)
debian
CVE-2015-3812P3HIGHCVSS 7.8fixed in wireshark 1.12.5+g5819e5b-1 (bookworm)2015
CVE-2015-3812 [HIGH] CVE-2015-3812: wireshark - Multiple memory leaks in the x11_init_protocol function in epan/dissectors/packe... Multiple memory leaks in the x11_init_protocol function in epan/dissectors/packet-x11.c in the X11 dissector in Wireshark 1.10.x before 1.10.14 and 1.12.x before 1.12.5 allow remote attackers to cause a denial of service (memory consumption) via a crafted packet. Scope: local bookworm: resolved (fixed in 1.12.5+g5819e5b-1) bullseye: resolved (fixed in 1.12.5+g5819e5
debian
CVE-2012-2393P4LOWCVSS 3.3PoCfixed in wireshark 1.6.8-1 (bookworm)2012
CVE-2012-2393 [LOW] CVE-2012-2393: wireshark - epan/dissectors/packet-diameter.c in the DIAMETER dissector in Wireshark 1.4.x b... epan/dissectors/packet-diameter.c in the DIAMETER dissector in Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 does not properly construct certain array data structures, which allows remote attackers to cause a denial of service (application crash) via a crafted packet that triggers incorrect memory allocation. Scope: local bookworm: resolved (fixed in 1.6.8-1)
debian
CVE-2023-6175P3HIGHCVSS 7.8fixed in wireshark 4.0.11-1~deb12u1 (bookworm)2023
CVE-2023-6175 [HIGH] CVE-2023-6175: wireshark - NetScreen file parser crash in Wireshark 4.0.0 to 4.0.10 and 3.6.0 to 3.6.18 all... NetScreen file parser crash in Wireshark 4.0.0 to 4.0.10 and 3.6.0 to 3.6.18 allows denial of service via crafted capture file Scope: local bookworm: resolved (fixed in 4.0.11-1~deb12u1) bullseye: resolved (fixed in 3.4.16-0+deb11u1) forky: resolved (fixed in 4.0.11-1) sid: resolved (fixed in 4.0.11-1) trixie: resolved (fixed in 4.0.11-1)
debian
CVE-2019-19553P3LOWCVSS 7.5fixed in wireshark 3.0.7-1 (bookworm)2019
CVE-2019-19553 [HIGH] CVE-2019-19553: wireshark - In Wireshark 3.0.0 to 3.0.6 and 2.6.0 to 2.6.12, the CMS dissector could crash. ... In Wireshark 3.0.0 to 3.0.6 and 2.6.0 to 2.6.12, the CMS dissector could crash. This was addressed in epan/dissectors/asn1/cms/packet-cms-template.c by ensuring that an object identifier is set to NULL after a ContentInfo dissection. Scope: local bookworm: resolved (fixed in 3.0.7-1) bullseye: resolved (fixed in 3.0.7-1) forky: resolved (fixed in 3.0.7-1) sid: res
debian
CVE-2012-3826P4LOWCVSS 3.3PoCfixed in wireshark 1.6.8-1 (bookworm)2012
CVE-2012-3826 [LOW] CVE-2012-3826: wireshark - Multiple integer underflows in Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.... Multiple integer underflows in Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 allow remote attackers to cause a denial of service (loop) via vectors related to the R3 dissector, a different vulnerability than CVE-2012-2392. Scope: local bookworm: resolved (fixed in 1.6.8-1) bullseye: resolved (fixed in 1.6.8-1) forky: resolved (fixed in 1.6.8-1) sid: resolved (
debian
CVE-2018-14342P3HIGHCVSS 7.5fixed in wireshark 2.6.2-1 (bookworm)2018
CVE-2018-14342 [HIGH] CVE-2018-14342: wireshark - In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the BGP protoc... In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the BGP protocol dissector could go into a large loop. This was addressed in epan/dissectors/packet-bgp.c by validating Path Attribute lengths. Scope: local bookworm: resolved (fixed in 2.6.2-1) bullseye: resolved (fixed in 2.6.2-1) forky: resolved (fixed in 2.6.2-1) sid: resolved (fixed in 2.6.2-1)
debian
CVE-2015-3809P3HIGHCVSS 7.8fixed in wireshark 1.12.5+g5819e5b-1 (bookworm)2015
CVE-2015-3809 [HIGH] CVE-2015-3809: wireshark - The dissect_lbmr_pser function in epan/dissectors/packet-lbmr.c in the LBMR diss... The dissect_lbmr_pser function in epan/dissectors/packet-lbmr.c in the LBMR dissector in Wireshark 1.12.x before 1.12.5 does not properly track the current offset, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet. Scope: local bookworm: resolved (fixed in 1.12.5+g5819e5b-1) bullseye: resolved (fixed in 1.12.5+g5819e5b-1
debian
CVE-2018-11360P3HIGHCVSS 7.5fixed in wireshark 2.6.1-1 (bookworm)2018
CVE-2018-11360 [HIGH] CVE-2018-11360: wireshark - In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the GSM A DTAP dissecto... In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the GSM A DTAP dissector could crash. This was addressed in epan/dissectors/packet-gsm_a_dtap.c by fixing an off-by-one error that caused a buffer overflow. Scope: local bookworm: resolved (fixed in 2.6.1-1) bullseye: resolved (fixed in 2.6.1-1) forky: resolved (fixed in 2.6.1-1) sid: resolved (fixed in 2.6.
debian
CVE-2018-16057P3LOWCVSS 7.5fixed in wireshark 2.6.3-1 (bookworm)2018
CVE-2018-16057 [HIGH] CVE-2018-16057: wireshark - In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Radiotap d... In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Radiotap dissector could crash. This was addressed in epan/dissectors/packet-ieee80211-radiotap-iter.c by validating iterator operations. Scope: local bookworm: resolved (fixed in 2.6.3-1) bullseye: resolved (fixed in 2.6.3-1) forky: resolved (fixed in 2.6.3-1) sid: resolved (fixed in 2.6.3-1) t
debian
CVE-2017-9346P3LOWCVSS 7.5fixed in wireshark 2.2.7-1 (bookworm)2017
CVE-2017-9346 [HIGH] CVE-2017-9346: wireshark - In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the SoulSeek dissector could go... In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the SoulSeek dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-slsk.c by making loop bounds more explicit. Scope: local bookworm: resolved (fixed in 2.2.7-1) bullseye: resolved (fixed in 2.2.7-1) forky: resolved (fixed in 2.2.7-1) sid: resolved (fixed in 2.2.7-1) trixie: resolved (
debian
Debian Wireshark vulnerabilities | cvebase