Wireshark Foundation Wireshark vulnerabilities
138 known vulnerabilities affecting wireshark_foundation/wireshark.
Total CVEs
138
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH58MEDIUM78LOW1
Vulnerabilities
Page 5 of 7
CVE-2023-0416P4MEDIUMCVSS 6.5v>=4.0.0, <4.0.3v>=3.6.0, <3.6.112023-01-26
CVE-2023-0416 [MEDIUM] CWE-404 CVE-2023-0416: GNW dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via
GNW dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file
nvd
CVE-2023-0417P4MEDIUMCVSS 6.5v>=4.0.0, <4.0.3v>=3.6.0, <3.6.112023-01-26
CVE-2023-0417 [MEDIUM] CWE-404 CVE-2023-0417: Memory leak in the NFS dissector in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial o
Memory leak in the NFS dissector in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file
nvd
CVE-2023-0414P4MEDIUMCVSS 6.5v>=4.0.0, <4.0.32023-01-26
CVE-2023-0414 [MEDIUM] CWE-404 CVE-2023-0414: Crash in the EAP dissector in Wireshark 4.0.0 to 4.0.2 allows denial of service via packet injection
Crash in the EAP dissector in Wireshark 4.0.0 to 4.0.2 allows denial of service via packet injection or crafted capture file
nvd
CVE-2026-0961P4MEDIUMCVSS 6.5≥ 4.6.0, < 4.6.3≥ 4.4.0, < 4.4.132026-01-14
CVE-2026-0961 [MEDIUM] CWE-787 CVE-2026-0961: BLF file parser crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
BLF file parser crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
nvd
CVE-2023-5371P4MEDIUMCVSS 6.5≥ 4.0.0, < 4.0.9≥ 3.6.0, < 3.6.172023-10-04
CVE-2023-5371 [MEDIUM] CWE-789 CVE-2023-5371: RTPS dissector memory leak in Wireshark 4.0.0 to 4.0.8 and 3.6.0 to 3.6.16 allows denial of service
RTPS dissector memory leak in Wireshark 4.0.0 to 4.0.8 and 3.6.0 to 3.6.16 allows denial of service via packet injection or crafted capture file
nvd
CVE-2026-6525P4MEDIUMCVSS 5.5≥ 4.6.0, < 4.6.52026-05-02
CVE-2026-6525 [MEDIUM] CWE-476 CVE-2026-6525: IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.4
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.4
nvd
CVE-2024-8250P4MEDIUMCVSS 5.5≥ 4.2.0, < 4.2.7≥ 4.0.0, < 4.0.172024-08-29
CVE-2024-8250 [MEDIUM] CWE-825 CVE-2024-8250: NTLMSSP dissector crash in Wireshark 4.2.0 to 4.0.6 and 4.0.0 to 4.0.16 allows denial of service via
NTLMSSP dissector crash in Wireshark 4.2.0 to 4.0.6 and 4.0.0 to 4.0.16 allows denial of service via packet injection or crafted capture file
nvd
CVE-2024-11596P4MEDIUMCVSS 5.5≥ 4.4.0, < 4.4.2≥ 4.2.0, < 4.2.92024-11-21
CVE-2024-11596 [MEDIUM] CWE-126 CVE-2024-11596: ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via pac
ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file
nvd
CVE-2024-11595P4MEDIUMCVSS 5.5≥ 4.4.0, < 4.4.2≥ 4.2.0, < 4.2.92024-11-21
CVE-2024-11595 [MEDIUM] CWE-835 CVE-2024-11595: FiveCo RAP dissector infinite loop in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of s
FiveCo RAP dissector infinite loop in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file
nvd
CVE-2024-9780P4MEDIUMCVSS 5.5≥ 4.4.0, < 4.4.12024-10-10
CVE-2024-9780 [MEDIUM] CWE-456 CVE-2024-9780: ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capt
ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capture file
nvd
CVE-2026-6531P4MEDIUMCVSS 5.5≥ 4.6.0, < 4.6.5≥ 4.4.0, < 4.4.152026-04-30
CVE-2026-6531 [MEDIUM] CWE-835 CVE-2026-6531: SANE protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial
SANE protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
nvd
CVE-2026-6536P4MEDIUMCVSS 5.5≥ 4.6.0, < 4.6.52026-04-30
CVE-2026-6536 [MEDIUM] CWE-835 CVE-2026-6536: DLMS/COSEM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4
DLMS/COSEM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4
nvd
CVE-2026-6534P4MEDIUMCVSS 5.5≥ 4.6.0, < 4.6.5≥ 4.4.0, < 4.4.152026-04-30
CVE-2026-6534 [MEDIUM] CWE-835 CVE-2026-6534: USB HID protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows deni
USB HID protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
nvd
CVE-2026-15170P4MEDIUMCVSS 5.5≥ 4.6.0, < 4.6.7≥ 4.4.0, < 4.4.172026-07-08
CVE-2026-15170 [MEDIUM] CWE-122 CVE-2026-15170: Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of ser
Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
nvd
CVE-2026-15166P4MEDIUMCVSS 5.5≥ 4.6.0, < 4.6.7≥ 4.4.0, < 4.4.172026-07-08
CVE-2026-15166 [MEDIUM] CWE-121 CVE-2026-15166: IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial o
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
nvd
CVE-2026-6521P4MEDIUMCVSS 5.5≥ 4.6.0, < 4.6.5≥ 4.4.0, < 4.4.152026-04-30
CVE-2026-6521 [MEDIUM] CWE-835 CVE-2026-6521: OpenFlow v5 protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows
OpenFlow v5 protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
nvd
CVE-2025-13946P4MEDIUMCVSS 5.5≥ 4.6.0, < 4.6.1≥ 4.4.0, < 4.4.112025-12-03
CVE-2025-13946 [MEDIUM] CWE-835 CVE-2025-13946: MEGACO dissector infinite loop in Wireshark 4.6.0 to 4.6.1 and 4.4.0 to 4.4.11 allows denial of serv
MEGACO dissector infinite loop in Wireshark 4.6.0 to 4.6.1 and 4.4.0 to 4.4.11 allows denial of service
nvd
CVE-2026-15171P4MEDIUMCVSS 5.5≥ 4.6.0, < 4.6.7≥ 4.4.0, < 4.4.172026-07-08
CVE-2026-15171 [MEDIUM] CWE-476 CVE-2026-15171: SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of servic
SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
nvd
CVE-2026-6522P4MEDIUMCVSS 5.5≥ 4.6.0, < 4.6.5≥ 4.4.0, < 4.4.152026-04-30
CVE-2026-6522 [MEDIUM] CWE-835 CVE-2026-6522: RPKI-Router protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows
RPKI-Router protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
nvd
CVE-2021-4183P4MEDIUMCVSS 5.5v=3.6.02021-12-30
CVE-2021-4183 [MEDIUM] CWE-125 CVE-2021-4183: Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file
Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file
nvd