cbcvebase.

Debian Wireshark vulnerabilities

668 known vulnerabilities affecting debian/wireshark.

Total CVEs
668
CISA KEV
0
Public exploits
50
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH129MEDIUM276LOW255

Vulnerabilities

Page 9 of 34
CVE-2018-7331P3LOWCVSS 7.5fixed in wireshark 2.4.5-1 (bookworm)2018
CVE-2018-7331 [HIGH] CVE-2018-7331: wireshark - In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-ber.c ha... In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-ber.c had an infinite loop that was addressed by validating a length. Scope: local bookworm: resolved (fixed in 2.4.5-1) bullseye: resolved (fixed in 2.4.5-1) forky: resolved (fixed in 2.4.5-1) sid: resolved (fixed in 2.4.5-1) trixie: resolved (fixed in 2.4.5-1)
debian
CVE-2018-9256P3LOWCVSS 7.5fixed in wireshark 2.4.6-1 (bookworm)2018
CVE-2018-9256 [HIGH] CVE-2018-9256: wireshark - In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the LWAPP dissector could crash... In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the LWAPP dissector could crash. This was addressed in epan/dissectors/packet-lwapp.c by limiting the encapsulation levels to restrict the recursion depth. Scope: local bookworm: resolved (fixed in 2.4.6-1) bullseye: resolved (fixed in 2.4.6-1) forky: resolved (fixed in 2.4.6-1) sid: resolved (fixed in 2.4.6-1) trixie
debian
CVE-2018-7326P3LOWCVSS 7.5fixed in wireshark 2.4.5-1 (bookworm)2018
CVE-2018-7326 [HIGH] CVE-2018-7326: wireshark - In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-lltd.c h... In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-lltd.c had an infinite loop that was addressed by using a correct integer data type. Scope: local bookworm: resolved (fixed in 2.4.5-1) bullseye: resolved (fixed in 2.4.5-1) forky: resolved (fixed in 2.4.5-1) sid: resolved (fixed in 2.4.5-1) trixie: resolved (fixed in 2.4.5-1)
debian
CVE-2018-7327P3LOWCVSS 7.5fixed in wireshark 2.4.5-1 (bookworm)2018
CVE-2018-7327 [HIGH] CVE-2018-7327: wireshark - In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-openflow... In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-openflow_v6.c had an infinite loop that was addressed by validating property lengths. Scope: local bookworm: resolved (fixed in 2.4.5-1) bullseye: resolved (fixed in 2.4.5-1) forky: resolved (fixed in 2.4.5-1) sid: resolved (fixed in 2.4.5-1) trixie: resolved (fixed in 2.4.5-1)
debian
CVE-2016-7958P3HIGHCVSS 7.5fixed in wireshark 2.2.1+ga6fbd27-1 (bookworm)2016
CVE-2016-7958 [HIGH] CVE-2016-7958: wireshark - In Wireshark 2.2.0, the NCP dissector could crash, triggered by packet injection... In Wireshark 2.2.0, the NCP dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/CMakeLists.txt by registering this dissector. Scope: local bookworm: resolved (fixed in 2.2.1+ga6fbd27-1) bullseye: resolved (fixed in 2.2.1+ga6fbd27-1) forky: resolved (fixed in 2.2.1+ga6fbd27-1) sid: resolved (fixed in
debian
CVE-2018-7333P3LOWCVSS 7.5fixed in wireshark 2.4.5-1 (bookworm)2018
CVE-2018-7333 [HIGH] CVE-2018-7333: wireshark - In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-rpcrdma.... In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-rpcrdma.c had an infinite loop that was addressed by validating a chunk size. Scope: local bookworm: resolved (fixed in 2.4.5-1) bullseye: resolved (fixed in 2.4.5-1) forky: resolved (fixed in 2.4.5-1) sid: resolved (fixed in 2.4.5-1) trixie: resolved (fixed in 2.4.5-1)
debian
CVE-2018-7328P3LOWCVSS 7.5fixed in wireshark 2.4.5-1 (bookworm)2018
CVE-2018-7328 [HIGH] CVE-2018-7328: wireshark - In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-usb.c ha... In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-usb.c had an infinite loop that was addressed by rejecting short frame header lengths. Scope: local bookworm: resolved (fixed in 2.4.5-1) bullseye: resolved (fixed in 2.4.5-1) forky: resolved (fixed in 2.4.5-1) sid: resolved (fixed in 2.4.5-1) trixie: resolved (fixed in 2.4.5-1)
debian
CVE-2020-28030P3HIGHCVSS 7.5fixed in wireshark 3.2.8-0.1 (bookworm)2020
CVE-2020-28030 [HIGH] CVE-2020-28030: wireshark - In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed... In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed in epan/dissectors/packet-gquic.c by correcting the implementation of offset advancement. Scope: local bookworm: resolved (fixed in 3.2.8-0.1) bullseye: resolved (fixed in 3.2.8-0.1) forky: resolved (fixed in 3.2.8-0.1) sid: resolved (fixed in 3.2.8-0.1) trixie: resolved (fixed in 3.2
debian
CVE-2017-13766P3HIGHCVSS 7.5fixed in wireshark 2.4.1-1 (bookworm)2017
CVE-2017-13766 [HIGH] CVE-2017-13766: wireshark - In Wireshark 2.4.0 and 2.2.0 to 2.2.8, the Profinet I/O dissector could crash wi... In Wireshark 2.4.0 and 2.2.0 to 2.2.8, the Profinet I/O dissector could crash with an out-of-bounds write. This was addressed in plugins/profinet/packet-dcerpc-pn-io.c by adding string validation. Scope: local bookworm: resolved (fixed in 2.4.1-1) bullseye: resolved (fixed in 2.4.1-1) forky: resolved (fixed in 2.4.1-1) sid: resolved (fixed in 2.4.1-1) trixie: reso
debian
CVE-2018-9258P3LOWCVSS 7.5fixed in wireshark 2.4.6-1 (bookworm)2018
CVE-2018-9258 [HIGH] CVE-2018-9258: wireshark - In Wireshark 2.4.0 to 2.4.5, the TCP dissector could crash. This was addressed i... In Wireshark 2.4.0 to 2.4.5, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by preserving valid data sources. Scope: local bookworm: resolved (fixed in 2.4.6-1) bullseye: resolved (fixed in 2.4.6-1) forky: resolved (fixed in 2.4.6-1) sid: resolved (fixed in 2.4.6-1) trixie: resolved (fixed in 2.4.6-1)
debian
CVE-2021-22222P3HIGHCVSS 7.5fixed in wireshark 3.4.7-1 (bookworm)2021
CVE-2021-22222 [HIGH] CVE-2021-22222: wireshark - Infinite loop in DVB-S2-BB dissector in Wireshark 3.4.0 to 3.4.5 allows denial o... Infinite loop in DVB-S2-BB dissector in Wireshark 3.4.0 to 3.4.5 allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved (fixed in 3.4.7-1) bullseye: resolved (fixed in 3.4.10-0+deb11u1) forky: resolved (fixed in 3.4.7-1) sid: resolved (fixed in 3.4.7-1) trixie: resolved (fixed in 3.4.7-1)
debian
CVE-2018-7321P3LOWCVSS 7.5fixed in wireshark 2.4.5-1 (bookworm)2018
CVE-2018-7321 [HIGH] CVE-2018-7321: wireshark - In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-thrift.c... In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-thrift.c had a large loop that was addressed by not proceeding with dissection after encountering an unexpected type. Scope: local bookworm: resolved (fixed in 2.4.5-1) bullseye: resolved (fixed in 2.4.5-1) forky: resolved (fixed in 2.4.5-1) sid: resolved (fixed in 2.4.5-1) trixie: resolved (fix
debian
CVE-2024-0209P3HIGHCVSS 7.8fixed in wireshark 4.0.17-0+deb12u1 (bookworm)2024
CVE-2024-0209 [HIGH] CVE-2024-0209: wireshark - IEEE 1609.2 dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.... IEEE 1609.2 dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved (fixed in 4.0.17-0+deb12u1) bullseye: resolved (fixed in 3.4.16-0+deb11u1) forky: resolved (fixed in 4.2.2-1) sid: resolved (fixed in 4.2.2-1) trixie: resolved (fixed in 4.2.2-1)
debian
CVE-2013-2487P3LOWCVSS 6.1fixed in wireshark 1.8.6-1 (bookworm)2013
CVE-2013-2487 [MEDIUM] CVE-2013-2487: wireshark - epan/dissectors/packet-reload.c in the REsource LOcation And Discovery (aka RELO... epan/dissectors/packet-reload.c in the REsource LOcation And Discovery (aka RELOAD) dissector in Wireshark 1.8.x before 1.8.6 uses incorrect integer data types, which allows remote attackers to cause a denial of service (infinite loop) via crafted integer values in a packet, related to the (1) dissect_icecandidates, (2) dissect_kinddata, (3) dissect_nodeid_list, (
debian
CVE-2021-22174P3LOWCVSS 3.7fixed in wireshark 3.4.3-1 (bookworm)2021
CVE-2021-22174 [LOW] CVE-2021-22174: wireshark - Crash in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service ... Crash in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved (fixed in 3.4.3-1) bullseye: resolved (fixed in 3.4.3-1) forky: resolved (fixed in 3.4.3-1) sid: resolved (fixed in 3.4.3-1) trixie: resolved (fixed in 3.4.3-1)
debian
CVE-2026-3201P3MEDIUMCVSS 4.7fixed in wireshark 4.6.4-1 (forky)2026
CVE-2026-3201 [MEDIUM] CVE-2026-3201: wireshark - USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4... USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service Scope: local bookworm: open bullseye: resolved forky: resolved (fixed in 4.6.4-1) sid: resolved (fixed in 4.6.4-1) trixie: resolved (fixed in 4.4.14-0+deb13u1)
debian
CVE-2022-0581P3MEDIUMCVSS 6.3fixed in wireshark 3.6.2-1 (bookworm)2022
CVE-2022-0581 [MEDIUM] CVE-2022-0581: wireshark - Crash in the CMS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4... Crash in the CMS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved (fixed in 3.6.2-1) bullseye: resolved (fixed in 3.4.16-0+deb11u1) forky: resolved (fixed in 3.6.2-1) sid: resolved (fixed in 3.6.2-1) trixie: resolved (fixed in 3.6.2-1)
debian
CVE-2015-3810P3HIGHCVSS 7.8fixed in wireshark 1.12.5+g5819e5b-1 (bookworm)2015
CVE-2015-3810 [HIGH] CVE-2015-3810: wireshark - epan/dissectors/packet-websocket.c in the WebSocket dissector in Wireshark 1.12.... epan/dissectors/packet-websocket.c in the WebSocket dissector in Wireshark 1.12.x before 1.12.5 uses a recursive algorithm, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted packet. Scope: local bookworm: resolved (fixed in 1.12.5+g5819e5b-1) bullseye: resolved (fixed in 1.12.5+g5819e5b-1) forky: resolved (fixed in 1.12.5+g58
debian
CVE-2024-4854P3MEDIUMCVSS 6.4fixed in wireshark 4.0.17-0+deb12u1 (bookworm)2024
CVE-2024-4854 [MEDIUM] CVE-2024-4854: wireshark - MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0... MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet injection or crafted capture file Scope: local bookworm: resolved (fixed in 4.0.17-0+deb12u1) bullseye: resolved (fixed in 3.4.16-0+deb11u1) forky: resolved (fixed in 4.2.5-1) sid: resolved (fixed in 4.2.5-1) trixie: re
debian
CVE-2013-4928P3LOWCVSS 7.8fixed in wireshark 1.10.1-1 (bookworm)2013
CVE-2013-4928 [HIGH] CVE-2013-4928: wireshark - Integer signedness error in the dissect_headers function in epan/dissectors/pack... Integer signedness error in the dissect_headers function in epan/dissectors/packet-btobex.c in the Bluetooth OBEX dissector in Wireshark 1.10.x before 1.10.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet. Scope: local bookworm: resolved (fixed in 1.10.1-1) bullseye: resolved (fixed in 1.10.1-1) forky: resolved (fixed in 1.
debian
Debian Wireshark vulnerabilities | cvebase