Msrc Azl3 Wireshark 4.4.7-1 On Azure Linux 3.0 vulnerabilities
10 known vulnerabilities affecting msrc/azl3_wireshark_4.4.7-1_on_azure_linux_3.0.
Total CVEs
10
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH7MEDIUM1LOW2
Vulnerabilities
Page 1 of 1
CVE-2024-8645MEDIUMCVSS 5.52024-09-10
CVE-2024-8645 [MEDIUM] CWE-824 Access of Uninitialized Pointer in Wireshark
Access of Uninitialized Pointer in Wireshark
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed
msrc
CVE-2024-8250HIGHCVSS 7.82024-08-13
CVE-2024-8250 [HIGH] CWE-825 Expired Pointer Dereference in Wireshark
Expired Pointer Dereference in Wireshark
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsof
msrc
CVE-2024-4853LOWCVSS 3.62024-05-14
CVE-2024-4853 [LOW] CWE-762 Mismatched Memory Management Routines in editcap
Mismatched Memory Management Routines in editcap
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is com
msrc
CVE-2024-4855LOWCVSS 3.62024-05-14
CVE-2024-4855 [LOW] CWE-416 Use After Free in editcap
Use After Free in editcap
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency
msrc
CVE-2024-2955HIGHCVSS 7.82024-03-12
CVE-2024-2955 [HIGH] CWE-762 Mismatched Memory Management Routines in Wireshark
Mismatched Memory Management Routines in Wireshark
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro i
msrc
CVE-2024-24479HIGHCVSS 7.52024-02-13
CVE-2024-24479 [HIGH] CWE-120 A Buffer Overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the wsutil/to_str.c, and format_fractional_part_nsecs components. NOTE: this is disputed by the ve
A Buffer Overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the wsutil/to_str.c, and format_fractional_part_nsecs components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected
msrc
CVE-2024-24478HIGHCVSS 7.52024-02-13
CVE-2024-24478 [HIGH] CWE-680 An issue in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the packet-bgp.c, dissect_bgp_open(tvbuff_t*tvb, proto_tree*tree, packet_info*pinfo), optlen components. NO
An issue in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the packet-bgp.c, dissect_bgp_open(tvbuff_t*tvb, proto_tree*tree, packet_info*pinfo), optlen components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor
msrc
CVE-2024-24476HIGHCVSS 7.52024-02-13
CVE-2024-24476 [HIGH] CWE-119 A buffer overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the pan/addr_resolv.c, and ws_manuf_lookup_str(), size components. NOTE: this is disputed by the v
A buffer overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the pan/addr_resolv.c, and ws_manuf_lookup_str(), size components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affecte
msrc
CVE-2024-0208HIGHCVSS 7.82024-01-09
CVE-2024-0208 [HIGH] CWE-230 Improper Handling of Missing Values in Wireshark
Improper Handling of Missing Values in Wireshark
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is co
msrc
CVE-2024-0209HIGHCVSS 7.82024-01-09
CVE-2024-0209 [HIGH] CWE-476 NULL Pointer Dereference in Wireshark
NULL Pointer Dereference in Wireshark
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is c
msrc