Wireshark Foundation Wireshark vulnerabilities
138 known vulnerabilities affecting wireshark_foundation/wireshark.
Total CVEs
138
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH58MEDIUM78LOW1
Vulnerabilities
Page 2 of 7
CVE-2022-3724P3HIGHCVSS 7.5v>=3.6.0, <3.6.82022-12-09
CVE-2022-3724 [HIGH] CWE-134 CVE-2022-3724: Crash in the USB HID protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via pac
Crash in the USB HID protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or crafted capture file on Windows
nvd
CVE-2021-4186P3HIGHCVSS 7.5v>=3.4.0, <3.4.102021-12-30
CVE-2021-4186 [HIGH] CWE-476 CVE-2021-4186: Crash in the Gryphon dissector in Wireshark 3.4.0 to 3.4.10 allows denial of service via packet inje
Crash in the Gryphon dissector in Wireshark 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
nvd
CVE-2024-2955P3HIGHCVSS 7.5≥ 4.2.0, < 4.2.4≥ 4.0.0, < 4.0.142024-03-26
CVE-2024-2955 [HIGH] CWE-762 CVE-2024-2955: T.38 dissector crash in Wireshark 4.2.0 to 4.0.3 and 4.0.0 to 4.0.13 allows denial of service via pa
T.38 dissector crash in Wireshark 4.2.0 to 4.0.3 and 4.0.0 to 4.0.13 allows denial of service via packet injection or crafted capture file
nvd
CVE-2026-5656P3HIGHCVSS 7.8≥ 4.6.0, < 4.6.5≥ 4.4.0, < 4.4.152026-05-01
CVE-2026-5656 [HIGH] CWE-22 CVE-2026-5656: Profile import path traversal in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of servi
Profile import path traversal in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution
nvd
CVE-2025-1492P3HIGHCVSS 7.5≥ 4.4.0, < 4.4.4≥ 4.2.0, < 4.2.112025-02-20
CVE-2025-1492 [HIGH] CWE-674 CVE-2025-1492: Bundle Protocol and CBOR dissector crashes in Wireshark 4.4.0 to 4.4.3 and 4.2.0 to 4.2.10 allows de
Bundle Protocol and CBOR dissector crashes in Wireshark 4.4.0 to 4.4.3 and 4.2.0 to 4.2.10 allows denial of service via packet injection or crafted capture file
nvd
CVE-2026-15163P3HIGHCVSS 7.5≥ 4.6.0, < 4.6.7≥ 4.4.0, < 4.4.172026-07-08
CVE-2026-15163 [HIGH] CWE-835 CVE-2026-15163: Multiple protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allow den
Multiple protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allow denial of service
nvd
CVE-2026-3201P3HIGHCVSS 7.5≥ 4.6.0, < 4.6.4≥ 4.4.0, < 4.4.142026-02-25
CVE-2026-3201 [HIGH] CWE-1325 CVE-2026-3201: USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows
USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
nvd
CVE-2023-6175P3HIGHCVSS 7.8≥ 4.0.0, < 4.0.11≥ 3.6.0, < 3.6.192024-03-26
CVE-2023-6175 [HIGH] CWE-120 CVE-2023-6175: NetScreen file parser crash in Wireshark 4.0.0 to 4.0.10 and 3.6.0 to 3.6.18 allows denial of servic
NetScreen file parser crash in Wireshark 4.0.0 to 4.0.10 and 3.6.0 to 3.6.18 allows denial of service via crafted capture file
nvd
CVE-2022-0581P3HIGHCVSS 7.5v>=3.6.0, <3.6.2v>=3.4.0, <3.4.122022-02-14
CVE-2022-0581 [HIGH] CWE-416 CVE-2022-0581: Crash in the CMS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of
Crash in the CMS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file
nvd
CVE-2024-4854P3HIGHCVSS 7.5≥ 4.2.0, < 4.2.5≥ 4.0.0, < 4.0.15+1 more2024-05-14
CVE-2024-4854 [HIGH] CWE-835 CVE-2024-4854: MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.
MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet injection or crafted capture file
nvd
CVE-2024-0209P3HIGHCVSS 7.5≥ 4.2.0, < 4.2.1≥ 4.0.0, < 4.0.12+1 more2024-01-03
CVE-2024-0209 [HIGH] CWE-476 CVE-2024-0209: IEEE 1609.2 dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial o
IEEE 1609.2 dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture file
nvd
CVE-2026-6868P3HIGHCVSS 7.5≥ 4.6.0, < 4.6.5≥ 4.4.0, < 4.4.152026-04-30
CVE-2026-6868 [HIGH] CWE-121 CVE-2026-6868: HTTP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of servi
HTTP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
nvd
CVE-2021-39923P3HIGHCVSS 7.5v>=3.2.0, <3.2.18v>=3.4.0, <3.4.102021-11-19
CVE-2021-39923 [HIGH] CWE-834 CVE-2021-39923: Large loop in the PNRP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of se
Large loop in the PNRP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
nvd
CVE-2026-5405P3HIGHCVSS 7.8≥ 4.6.0, < 4.6.5≥ 4.4.0, < 4.4.152026-05-01
CVE-2026-5405 [HIGH] CWE-122 CVE-2026-5405: RDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of servic
RDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution
nvd
CVE-2022-3725P3HIGHCVSS 7.5v>=3.6.0, <3.6.82022-10-27
CVE-2022-3725 [HIGH] CWE-787 CVE-2022-3725: Crash in the OPUS protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet
Crash in the OPUS protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or crafted capture file
nvd
CVE-2023-4511P3HIGHCVSS 7.5≥ 4.0.0, < 4.0.8≥ 3.6.0, < 3.6.162023-08-24
CVE-2023-4511 [HIGH] CWE-835 CVE-2023-4511: BT SDP dissector infinite loop in Wireshark 4.0.0 to 4.0.7 and 3.6.0 to 3.6.15 allows denial of serv
BT SDP dissector infinite loop in Wireshark 4.0.0 to 4.0.7 and 3.6.0 to 3.6.15 allows denial of service via packet injection or crafted capture file
nvd
CVE-2026-15169P3HIGHCVSS 7.5≥ 4.6.0, < 4.6.7≥ 4.4.0, < 4.4.172026-07-08
CVE-2026-15169 [HIGH] CWE-122 CVE-2026-15169: UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of se
UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
nvd
CVE-2026-7379P3HIGHCVSS 7.5≥ 4.6.0, < 4.6.5≥ 4.4.0, < 4.4.152026-04-30
CVE-2026-7379 [HIGH] CWE-401 CVE-2026-7379: Memory leak in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Memory leak in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
nvd
CVE-2026-7375P3HIGHCVSS 7.5≥ 4.6.0, < 4.6.5≥ 4.4.0, < 4.4.152026-04-30
CVE-2026-7375 [HIGH] CWE-835 CVE-2026-7375: UDS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial o
UDS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
nvd
CVE-2026-6520P3HIGHCVSS 7.5≥ 4.6.0, < 4.6.5≥ 4.4.0, < 4.4.152026-04-30
CVE-2026-6520 [HIGH] CWE-835 CVE-2026-6520: OpenFlow v6 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows
OpenFlow v6 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
nvd