Wireshark Foundation Wireshark vulnerabilities
138 known vulnerabilities affecting wireshark_foundation/wireshark.
Total CVEs
138
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH58MEDIUM78LOW1
Vulnerabilities
Page 3 of 7
CVE-2026-6519P3HIGHCVSS 7.5≥ 4.6.0, < 4.6.5≥ 4.4.0, < 4.4.152026-04-30
CVE-2026-6519 [HIGH] CWE-835 CVE-2026-6519: MBIM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial
MBIM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
nvd
CVE-2026-5403P4HIGHCVSS 7.8≥ 4.6.0, < 4.6.5≥ 4.4.0, < 4.4.152026-05-01
CVE-2026-5403 [HIGH] CWE-122 CVE-2026-5403: SBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possibl
SBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution
nvd
CVE-2024-0211P4HIGHCVSS 7.5≥ 4.2.0, < 4.2.12024-01-03
CVE-2024-0211 [HIGH] CWE-835 CVE-2024-0211: DOCSIS dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted c
DOCSIS dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file
nvd
CVE-2023-4512P4HIGHCVSS 7.5≥ 4.0.0, < 4.0.82023-08-24
CVE-2023-4512 [HIGH] CWE-674 CVE-2023-4512: CBOR dissector crash in Wireshark 4.0.0 to 4.0.6 allows denial of service via packet injection or cr
CBOR dissector crash in Wireshark 4.0.0 to 4.0.6 allows denial of service via packet injection or crafted capture file
nvd
CVE-2024-0210P4HIGHCVSS 7.5≥ 4.2.0, < 4.2.12024-01-03
CVE-2024-0210 [HIGH] CWE-674 CVE-2024-0210: Zigbee TLV dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or craft
Zigbee TLV dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file
nvd
CVE-2024-0207P4HIGHCVSS 7.5≥ 4.2.0, < 4.2.12024-01-03
CVE-2024-0207 [HIGH] CWE-125 CVE-2024-0207: HTTP3 dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted ca
HTTP3 dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file
nvd
CVE-2024-9781P4HIGHCVSS 7.5≥ 4.4.0, < 4.4.1≥ 4.2.0, < 4.2.82024-10-10
CVE-2024-9781 [HIGH] CWE-230 CVE-2024-9781: AppleTalk and RELOAD Framing dissector crash in Wireshark 4.4.0 and 4.2.0 to 4.2.7 allows denial of
AppleTalk and RELOAD Framing dissector crash in Wireshark 4.4.0 and 4.2.0 to 4.2.7 allows denial of service via packet injection or crafted capture file
nvd
CVE-2026-5655P4HIGHCVSS 7.5≥ 4.6.0, < 4.6.52026-04-30
CVE-2026-5655 [HIGH] CWE-416 CVE-2026-5655: SDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 allows denial of service
SDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 allows denial of service
nvd
CVE-2026-5654P4HIGHCVSS 7.5≥ 4.6.0, < 4.6.5≥ 4.4.0, < 4.4.152026-04-30
CVE-2026-5654 [HIGH] CWE-121 CVE-2026-5654: AMR-NB codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
AMR-NB codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
nvd
CVE-2026-5653P4HIGHCVSS 7.5≥ 4.6.0, < 4.6.5≥ 4.4.0, < 4.4.152026-04-30
CVE-2026-5653 [HIGH] CWE-122 CVE-2026-5653: DCP-ETSI protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of s
DCP-ETSI protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
nvd
CVE-2026-5657P4HIGHCVSS 7.5≥ 4.6.0, < 4.6.5≥ 4.4.0, < 4.4.152026-04-30
CVE-2026-5657 [HIGH] CWE-415 CVE-2026-5657: iLBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
iLBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
nvd
CVE-2026-3203P4HIGHCVSS 7.5≥ 4.6.0, < 4.6.4≥ 4.4.0, < 4.4.142026-02-25
CVE-2026-3203 [HIGH] CWE-126 CVE-2026-3203: RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial
RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
nvd
CVE-2023-0668P4MEDIUMCVSS 6.5≥ 4.0.0, ≤ 4.0.5≥ 3.6.0, ≤ 3.6.132023-06-07
CVE-2023-0668 [MEDIUM] CWE-125 CVE-2023-0668: Due to failure in validating the length provided by an attacker-crafted IEEE-C37.118 packet, Wiresha
Due to failure in validating the length provided by an attacker-crafted IEEE-C37.118 packet, Wireshark version 4.0.5 and prior, by default, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark.
nvd
CVE-2023-0666P3MEDIUMCVSS 6.5≥ 4.0.0, ≤ 4.0.52023-06-07
CVE-2023-0666 [MEDIUM] CWE-122 CVE-2023-0666: Due to failure in validating the length provided by an attacker-crafted RTPS packet, Wireshark versi
Due to failure in validating the length provided by an attacker-crafted RTPS packet, Wireshark version 4.0.5 and prior, by default, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark.
nvd
CVE-2023-0667P4MEDIUMCVSS 6.5≤ 4.0.52023-06-07
CVE-2023-0667 [MEDIUM] CWE-122 CVE-2023-0667: Due to failure in validating the length provided by an attacker-crafted MSMMS packet, Wireshark vers
Due to failure in validating the length provided by an attacker-crafted MSMMS packet, Wireshark version 4.0.5 and prior, in an unusual configuration, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark
nvd
CVE-2023-4513P4HIGHCVSS 7.5≥ 4.0.0, < 4.0.8≥ 3.6.0, < 3.6.162023-08-24
CVE-2023-4513 [HIGH] CWE-401 CVE-2023-4513: BT SDP dissector memory leak in Wireshark 4.0.0 to 4.0.7 and 3.6.0 to 3.6.15 allows denial of servic
BT SDP dissector memory leak in Wireshark 4.0.0 to 4.0.7 and 3.6.0 to 3.6.15 allows denial of service via packet injection or crafted capture file
nvd
CVE-2026-7378P4HIGHCVSS 7.5≥ 4.6.0, < 4.6.5≥ 4.4.0, < 4.4.152026-04-30
CVE-2026-7378 [HIGH] CWE-122 CVE-2026-7378: Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
nvd
CVE-2026-7376P4HIGHCVSS 7.5≥ 4.6.0, < 4.6.5≥ 4.4.0, < 4.4.152026-04-30
CVE-2026-7376 [HIGH] CWE-476 CVE-2026-7376: Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
nvd
CVE-2026-3202P4HIGHCVSS 7.5≥ 4.6.0, < 4.6.42026-02-25
CVE-2026-3202 [HIGH] CWE-476 CVE-2026-3202: NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of service
NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of service
nvd
CVE-2023-1993P4MEDIUMCVSS 6.5v>=4.0.0, <4.0.5v>=3.6.0, <3.6.132023-04-12
CVE-2023-1993 [MEDIUM] CWE-834 CVE-2023-1993: LISP dissector large loop in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service v
LISP dissector large loop in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file
nvd