Msrc Azl3 Wireshark 4.4.7-1 On Azure Linux 3.0 vulnerabilities

10 known vulnerabilities affecting msrc/azl3_wireshark_4.4.7-1_on_azure_linux_3.0.

Total CVEs
10
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH7MEDIUM1LOW2

Vulnerabilities

Page 1 of 1
CVE-2024-8645MEDIUMCVSS 5.52024-09-10
CVE-2024-8645 [MEDIUM] CWE-824 Access of Uninitialized Pointer in Wireshark Access of Uninitialized Pointer in Wireshark FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed
msrc
CVE-2024-8250HIGHCVSS 7.82024-08-13
CVE-2024-8250 [HIGH] CWE-825 Expired Pointer Dereference in Wireshark Expired Pointer Dereference in Wireshark FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsof
msrc
CVE-2024-4853LOWCVSS 3.62024-05-14
CVE-2024-4853 [LOW] CWE-762 Mismatched Memory Management Routines in editcap Mismatched Memory Management Routines in editcap FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is com
msrc
CVE-2024-4855LOWCVSS 3.62024-05-14
CVE-2024-4855 [LOW] CWE-416 Use After Free in editcap Use After Free in editcap FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency
msrc
CVE-2024-2955HIGHCVSS 7.82024-03-12
CVE-2024-2955 [HIGH] CWE-762 Mismatched Memory Management Routines in Wireshark Mismatched Memory Management Routines in Wireshark FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro i
msrc
CVE-2024-24479HIGHCVSS 7.52024-02-13
CVE-2024-24479 [HIGH] CWE-120 A Buffer Overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the wsutil/to_str.c, and format_fractional_part_nsecs components. NOTE: this is disputed by the ve A Buffer Overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the wsutil/to_str.c, and format_fractional_part_nsecs components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected
msrc
CVE-2024-24478HIGHCVSS 7.52024-02-13
CVE-2024-24478 [HIGH] CWE-680 An issue in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the packet-bgp.c, dissect_bgp_open(tvbuff_t*tvb, proto_tree*tree, packet_info*pinfo), optlen components. NO An issue in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the packet-bgp.c, dissect_bgp_open(tvbuff_t*tvb, proto_tree*tree, packet_info*pinfo), optlen components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor
msrc
CVE-2024-24476HIGHCVSS 7.52024-02-13
CVE-2024-24476 [HIGH] CWE-119 A buffer overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the pan/addr_resolv.c, and ws_manuf_lookup_str(), size components. NOTE: this is disputed by the v A buffer overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the pan/addr_resolv.c, and ws_manuf_lookup_str(), size components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affecte
msrc
CVE-2024-0208HIGHCVSS 7.82024-01-09
CVE-2024-0208 [HIGH] CWE-230 Improper Handling of Missing Values in Wireshark Improper Handling of Missing Values in Wireshark FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is co
msrc
CVE-2024-0209HIGHCVSS 7.82024-01-09
CVE-2024-0209 [HIGH] CWE-476 NULL Pointer Dereference in Wireshark NULL Pointer Dereference in Wireshark FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is c
msrc