Wireshark Foundation Wireshark vulnerabilities
138 known vulnerabilities affecting wireshark_foundation/wireshark.
Total CVEs
138
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH58MEDIUM78LOW1
Vulnerabilities
Page 4 of 7
CVE-2023-2906P4MEDIUMCVSS 6.5≥ 2.0.0, ≤ 4.0.72023-08-25
CVE-2023-2906 [MEDIUM] CWE-369 CVE-2023-2906: Due to a failure in validating the length provided by an attacker-crafted CP2179 packet, Wireshark v
Due to a failure in validating the length provided by an attacker-crafted CP2179 packet, Wireshark versions 2.0.0 through 4.0.7 is susceptible to a divide by zero allowing for a denial of service attack.
nvd
CVE-2025-9817P4HIGHCVSS 7.5≥ 4.4.0, < 4.4.92025-09-03
CVE-2025-9817 [HIGH] CWE-476 CVE-2025-9817: SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial of service
SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial of service
nvd
CVE-2022-0585P4MEDIUMCVSS 6.5v>=3.6.0, <3.6.2v>=3.4.0, <3.4.122022-02-18
CVE-2022-0585 [MEDIUM] CWE-834 CVE-2022-0585: Large loops in multiple protocol dissectors in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allow de
Large loops in multiple protocol dissectors in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allow denial of service via packet injection or crafted capture file
nvd
CVE-2023-1161P4HIGHCVSS 7.1v>=4.0.0, <4.0.4v>=3.6.0, <3.6.122023-03-06
CVE-2023-1161 [HIGH] CWE-120 CVE-2023-1161: ISO 15765 and ISO 10681 dissector crash in Wireshark 4.0.0 to 4.0.3 and 3.6.0 to 3.6.11 allows denia
ISO 15765 and ISO 10681 dissector crash in Wireshark 4.0.0 to 4.0.3 and 3.6.0 to 3.6.11 allows denial of service via packet injection or crafted capture file
nvd
CVE-2023-0412P4HIGHCVSS 7.1v>=4.0.0, <4.0.3v>=3.6.0, <3.6.112023-01-26
CVE-2023-0412 [HIGH] CWE-404 CVE-2023-0412: TIPC dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service vi
TIPC dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file
nvd
CVE-2023-2856P4MEDIUMCVSS 6.5v>=4.0.0, <4.0.6v>=3.6.0, <3.6.142023-05-26
CVE-2023-2856 [MEDIUM] CWE-787 CVE-2023-2856: VMS TCPIPtrace file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of se
VMS TCPIPtrace file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
nvd
CVE-2023-2858P4MEDIUMCVSS 6.5v>=4.0.0, <4.0.6v>=3.6.0, <3.6.142023-05-26
CVE-2023-2858 [MEDIUM] CWE-787 CVE-2023-2858: NetScaler file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service
NetScaler file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
nvd
CVE-2023-2952P4MEDIUMCVSS 6.5v>=4.0.0, <4.0.6v>=3.6.0, <3.6.142023-05-30
CVE-2023-2952 [MEDIUM] CWE-835 CVE-2023-2952: XRA dissector infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service
XRA dissector infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or crafted capture file
nvd
CVE-2025-5601P4MEDIUMCVSS 6.5≥ 4.4.0, < 4.4.7≥ 4.2.0, < 4.2.132025-06-04
CVE-2025-5601 [MEDIUM] CWE-120 CVE-2025-5601: Column handling crashes in Wireshark 4.4.0 to 4.4.6 and 4.2.0 to 4.2.12 allows denial of service via
Column handling crashes in Wireshark 4.4.0 to 4.4.6 and 4.2.0 to 4.2.12 allows denial of service via packet injection or crafted capture file
nvd
CVE-2026-0962P4MEDIUMCVSS 6.5≥ 4.6.0, < 4.6.3≥ 4.4.0, < 4.4.132026-01-14
CVE-2026-0962 [MEDIUM] CWE-787 CVE-2026-0962: SOME/IP-SD protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of
SOME/IP-SD protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
nvd
CVE-2023-2855P4MEDIUMCVSS 6.5v>=4.0.0, <4.0.6v>=3.6.0, <3.6.142023-05-26
CVE-2023-2855 [MEDIUM] CWE-787 CVE-2023-2855: Candump log parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service vi
Candump log parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
nvd
CVE-2023-1994P4MEDIUMCVSS 6.5v>=4.0.0, <4.0.5v>=3.6.0, <3.6.132023-04-12
CVE-2023-1994 [MEDIUM] CWE-400 CVE-2023-1994: GQUIC dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via p
GQUIC dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file
nvd
CVE-2023-0411P4MEDIUMCVSS 6.5v>=4.0.0, <4.0.3v>=3.6.0, <3.6.112023-01-26
CVE-2023-0411 [MEDIUM] CWE-834 CVE-2023-0411: Excessive loops in multiple dissectors in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows de
Excessive loops in multiple dissectors in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file
nvd
CVE-2023-0413P4MEDIUMCVSS 6.5v>=4.0.0, <4.0.3v>=3.6.0, <3.6.112023-01-26
CVE-2023-0413 [MEDIUM] CWE-404 CVE-2023-0413: Dissection engine bug in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service v
Dissection engine bug in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file
nvd
CVE-2023-6174P4MEDIUMCVSS 6.5≥ 4.0.0, < 4.0.112023-11-16
CVE-2023-6174 [MEDIUM] CWE-125 CVE-2023-6174: SSH dissector crash in Wireshark 4.0.0 to 4.0.10 allows denial of service via packet injection or cr
SSH dissector crash in Wireshark 4.0.0 to 4.0.10 allows denial of service via packet injection or crafted capture file
nvd
CVE-2022-4345P4MEDIUMCVSS 6.5v>=4.0.0, <4.0.2v>=3.6.0, <3.6.102023-01-12
CVE-2022-4345 [MEDIUM] CWE-835 CVE-2022-4345: Infinite loops in the BPv6, OpenFlow, and Kafka protocol dissectors in Wireshark 4.0.0 to 4.0.1 and
Infinite loops in the BPv6, OpenFlow, and Kafka protocol dissectors in Wireshark 4.0.0 to 4.0.1 and 3.6.0 to 3.6.9 allows denial of service via packet injection or crafted capture file
nvd
CVE-2026-0959P4MEDIUMCVSS 6.5≥ 4.6.0, < 4.6.3≥ 4.4.0, < 4.4.132026-01-14
CVE-2026-0959 [MEDIUM] CWE-787 CVE-2026-0959: IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial o
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
nvd
CVE-2023-2854P4MEDIUMCVSS 6.5v>=4.0.0, <4.0.6v>=3.6.0, <3.6.142023-05-26
CVE-2023-2854 [MEDIUM] CWE-787 CVE-2023-2854: BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via c
BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
nvd
CVE-2023-2857P4MEDIUMCVSS 6.5v>=4.0.0, <4.0.6v>=3.6.0, <3.6.142023-05-26
CVE-2023-2857 [MEDIUM] CWE-787 CVE-2023-2857: BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via c
BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
nvd
CVE-2023-0415P4MEDIUMCVSS 6.5v>=4.0.0, <4.0.3v>=3.6.0, <3.6.112023-01-26
CVE-2023-0415 [MEDIUM] CWE-404 CVE-2023-0415: iSCSI dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service v
iSCSI dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file
nvd