Wireshark Foundation Wireshark vulnerabilities
138 known vulnerabilities affecting wireshark_foundation/wireshark.
Total CVEs
138
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH58MEDIUM78LOW1
Vulnerabilities
Page 1 of 7
CVE-2022-0582P3CRITICALCVSS 9.8v>=3.6.0, <3.6.2v>=3.4.0, <3.4.122022-02-14
CVE-2022-0582 [CRITICAL] CWE-476 CVE-2022-0582: Unaligned access in the CSN.1 protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 all
Unaligned access in the CSN.1 protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file
nvd
CVE-2026-5402P3HIGHCVSS 8.8≥ 4.6.0, < 4.6.52026-04-30
CVE-2026-5402 [HIGH] CWE-122 CVE-2026-5402: TLS protocol dissector heap overflow in Wireshark 4.6.0 to 4.6.4 allows denial of service and possib
TLS protocol dissector heap overflow in Wireshark 4.6.0 to 4.6.4 allows denial of service and possible code execution
nvd
CVE-2021-39925P3HIGHCVSS 7.5v>=3.4.0, <3.4.10v>=3.2.0, <3.2.182021-11-19
CVE-2021-39925 [HIGH] CWE-120 CVE-2021-39925: Buffer overflow in the Bluetooth SDP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allow
Buffer overflow in the Bluetooth SDP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
nvd
CVE-2021-39926P3HIGHCVSS 7.5v>=3.4.0, <3.4.102021-11-19
CVE-2021-39926 [HIGH] CWE-120 CVE-2021-39926: Buffer overflow in the Bluetooth HCI_ISO dissector in Wireshark 3.4.0 to 3.4.9 allows denial of serv
Buffer overflow in the Bluetooth HCI_ISO dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file
nvd
CVE-2021-39922P3HIGHCVSS 7.5v>=3.4.0, <3.4.10v>=3.2.0, <3.2.182021-11-19
CVE-2021-39922 [HIGH] CWE-120 CVE-2021-39922: Buffer overflow in the C12.22 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denia
Buffer overflow in the C12.22 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
nvd
CVE-2023-1992P3HIGHCVSS 7.5v>=4.0.0, <4.0.5v>=3.6.0, <3.6.132023-04-12
CVE-2023-1992 [HIGH] CWE-400 CVE-2023-1992: RPCoRDMA dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service vi
RPCoRDMA dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file
nvd
CVE-2021-39928P3HIGHCVSS 7.5v>=3.4.0, <3.4.10v>=3.2.0, <3.2.182021-11-18
CVE-2021-39928 [HIGH] CWE-476 CVE-2021-39928: NULL pointer exception in the IEEE 802.11 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17
NULL pointer exception in the IEEE 802.11 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
nvd
CVE-2021-4185P3HIGHCVSS 7.5v=3.6.0v>=3.4.0, <3.4.102021-12-30
CVE-2021-4185 [HIGH] CWE-835 CVE-2021-4185: Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service
Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
nvd
CVE-2021-4184P3HIGHCVSS 7.5v=3.6.0v>=3.4.0, <3.4.102021-12-30
CVE-2021-4184 [HIGH] CWE-835 CVE-2021-4184: Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial o
Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
nvd
CVE-2021-4181P3HIGHCVSS 7.5v=3.6.0v>=3.4.0, <3.4.102021-12-30
CVE-2021-4181 [HIGH] CWE-125 CVE-2021-4181: Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service
Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
nvd
CVE-2021-4190P3HIGHCVSS 7.5v=3.6.02021-12-30
CVE-2021-4190 [HIGH] CWE-834 CVE-2021-4190: Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service via packet injection o
Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service via packet injection or crafted capture file
nvd
CVE-2021-39924P3HIGHCVSS 7.5v>=3.4.0, <3.4.10v>=3.2.0, <3.2.182021-11-19
CVE-2021-39924 [HIGH] CWE-834 CVE-2021-39924: Large loop in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows den
Large loop in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
nvd
CVE-2021-39929P3HIGHCVSS 7.5v>=3.4.0, <3.4.10v>=3.2.0, <3.2.182021-11-19
CVE-2021-39929 [HIGH] CWE-674 CVE-2021-39929: Uncontrolled Recursion in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.1
Uncontrolled Recursion in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
nvd
CVE-2021-4182P3HIGHCVSS 7.5v=3.6.0v>=3.4.0, <3.4.102021-12-30
CVE-2021-4182 [HIGH] CWE-835 CVE-2021-4182: Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via
Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
nvd
CVE-2022-0586P3HIGHCVSS 7.5v>=3.6.0, <3.6.2v>=3.4.0, <3.4.122022-02-14
CVE-2022-0586 [HIGH] CWE-835 CVE-2022-0586: Infinite loop in RTMPT protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows den
Infinite loop in RTMPT protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file
nvd
CVE-2022-0583P3HIGHCVSS 7.5v>=3.6.0, <3.6.2v>=3.4.0, <3.4.122022-02-14
CVE-2022-0583 [HIGH] CWE-787 CVE-2022-0583: Crash in the PVFS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial o
Crash in the PVFS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file
nvd
CVE-2024-0208P3HIGHCVSS 7.5≥ 4.2.0, < 4.2.1≥ 4.0.0, < 4.0.12+1 more2024-01-03
CVE-2024-0208 [HIGH] CWE-230 CVE-2024-0208: GVCP dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of servi
GVCP dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture file
nvd
CVE-2023-2879P3HIGHCVSS 7.5v>=4.0.0, <4.0.6v>=3.6.0, <3.6.142023-05-26
CVE-2023-2879 [HIGH] CWE-835 CVE-2023-2879: GDSDB infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via pac
GDSDB infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or crafted capture file
nvd
CVE-2021-39921P3HIGHCVSS 7.5v>=3.4.0, <3.4.10v>=3.2.0, <3.2.182021-11-19
CVE-2021-39921 [HIGH] CWE-476 CVE-2021-39921: NULL pointer exception in the Modbus dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allow
NULL pointer exception in the Modbus dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
nvd
CVE-2021-39920P3HIGHCVSS 7.5v>=3.4.0, <3.4.102021-11-18
CVE-2021-39920 [HIGH] CWE-476 CVE-2021-39920: NULL pointer exception in the IPPUSB dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service
NULL pointer exception in the IPPUSB dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file
nvd
1 / 7Next →