📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Patch & vulnerability status

Wireshark 4.6.7

Latest tracked version 4.6.7. Release status, tracked CVEs, and automated cross-platform patching for Wireshark.

PlatformLatest versionCVEs trackedLast checked
Linux4.6.702026-08-10
Mac4.6.702026-08-10
Windows4.6.76542026-08-10

Known vulnerabilities (CVEs) in Wireshark

Lavawall tracks 654 published CVEs affecting Wireshark, and deploys the versions that fix them automatically across your fleet.

CVEPublishedSeverityDetailsVector
CVE-2026-97592026-05-27 20:16:47MEDIUM (6)ROHC protocol dissector crash in Wireshark 4.6.0 to 4.6.5 and 4.4.0 to 4.4.15 allows denial of serviceLOCAL
CVE-2026-73752026-04-30 06:16:17MEDIUM (6)UDS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of serviceLOCAL
CVE-2026-68702026-04-30 07:16:42MEDIUM (6)GSM RP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of serviceLOCAL
CVE-2026-68692026-04-30 07:16:41MEDIUM (6)WebSocket protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of serviceLOCAL
CVE-2026-68682026-04-30 06:16:17MEDIUM (6)HTTP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of serviceLOCAL
CVE-2026-68672026-04-30 07:16:41MEDIUM (6)SMB2 protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of serviceLOCAL
CVE-2026-65382026-04-30 07:16:41MEDIUM (6)BEEP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of serviceLOCAL
CVE-2026-65372026-04-30 07:16:41MEDIUM (6)ZigBee protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of serviceLOCAL
CVE-2026-65362026-04-30 07:16:41MEDIUM (6)DLMS/COSEM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4LOCAL
CVE-2026-65352026-04-30 07:16:41MEDIUM (6)Dissection engine zlib decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of serviceLOCAL
CVE-2026-65342026-04-30 07:16:41MEDIUM (6)USB HID protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of serviceLOCAL
CVE-2026-65332026-04-30 07:16:41MEDIUM (6)Dissection engine LZ77 decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of serviceLOCAL
CVE-2026-65322026-04-30 07:16:41MEDIUM (6)Kismet protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of serviceLOCAL
CVE-2026-65312026-04-30 07:16:40MEDIUM (6)SANE protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of serviceLOCAL
CVE-2026-65302026-04-30 07:16:40MEDIUM (6)DCP-ETSI protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of serviceLOCAL
CVE-2026-65292026-04-30 07:16:40MEDIUM (6)iLBC audio codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of serviceLOCAL
CVE-2026-65282026-04-30 07:16:40MEDIUM (6)TLS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 allows denial of serviceLOCAL
CVE-2026-65272026-04-30 07:16:40MEDIUM (6)ASN.1 PER protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of serviceLOCAL
CVE-2026-65262026-04-30 07:16:40MEDIUM (6)RTSP protocol dissector crash in Wireshark 4.6.0 to 4.6.4LOCAL
CVE-2026-65252026-05-02 12:16:17MEDIUM (6)IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.4LOCAL
CVE-2026-65242026-04-30 07:16:40MEDIUM (6)MySQL protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of serviceLOCAL
CVE-2026-65232026-04-30 07:16:40MEDIUM (6)GNW protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of serviceLOCAL
CVE-2026-65222026-04-30 07:16:39MEDIUM (6)RPKI-Router protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of serviceLOCAL
CVE-2026-65212026-04-30 07:16:39MEDIUM (6)OpenFlow v5 protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of serviceLOCAL
CVE-2026-65202026-04-30 07:16:39MEDIUM (6)OpenFlow v6 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of serviceLOCAL
CVE-2026-65192026-04-30 07:16:39MEDIUM (6)MBIM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of serviceLOCAL
CVE-2026-56572026-04-30 07:16:39MEDIUM (6)iLBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of serviceLOCAL
CVE-2026-56562026-05-01 00:16:25HIGH (7)Profile import path traversal in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code executionLOCAL
CVE-2026-56552026-04-30 07:16:39MEDIUM (6)SDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 allows denial of serviceLOCAL
CVE-2026-56542026-04-30 07:16:39MEDIUM (6)AMR-NB codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of serviceLOCAL
CVE-2026-56532026-04-30 07:16:39MEDIUM (6)DCP-ETSI protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of serviceLOCAL
CVE-2026-54092026-04-30 07:16:38MEDIUM (6)Monero protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of serviceLOCAL
CVE-2026-54082026-04-30 07:16:38MEDIUM (6)BT-DHT protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of serviceLOCAL
CVE-2026-54072026-04-30 07:16:38MEDIUM (6)SMB2 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of serviceLOCAL
CVE-2026-54062026-04-30 07:16:38MEDIUM (6)FC-SWILS protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of serviceLOCAL
CVE-2026-54052026-05-01 00:16:25HIGH (8)RDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code executionLOCAL
CVE-2026-54042026-05-01 00:16:25MEDIUM (5)K12 RF5 file parser crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of serviceLOCAL
CVE-2026-54032026-05-01 00:16:25HIGH (8)SBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code executionLOCAL
CVE-2026-54022026-04-30 07:16:38HIGH (9)TLS protocol dissector heap overflow in Wireshark 4.6.0 to 4.6.4 allows denial of service and possible code executionNETWORK
CVE-2026-54012026-04-30 07:16:38MEDIUM (6)AFP Spotlight protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of serviceLOCAL
CVE-2026-52992026-04-30 07:16:38MEDIUM (6)ICMPv6 PvD protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of serviceLOCAL
CVE-2026-32032026-02-25 15:20:56MEDIUM (6)RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of serviceLOCAL
CVE-2026-32022026-02-25 15:20:56MEDIUM (5)NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of serviceLOCAL
CVE-2026-32012026-02-25 15:20:56MEDIUM (5)USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of serviceLOCAL
CVE-2026-151742026-07-08 21:16:48MEDIUM (6)Catapult DCT2000 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of serviceLOCAL
CVE-2026-151732026-07-08 21:16:48MEDIUM (5)pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial of serviceLOCAL
CVE-2026-151722026-07-08 21:16:48MEDIUM (6)FMP/NOTIFY protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of serviceLOCAL
CVE-2026-151712026-07-08 21:16:48MEDIUM (6)SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of serviceLOCAL
CVE-2026-151702026-07-08 21:16:48MEDIUM (6)Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of serviceLOCAL
CVE-2026-151692026-07-08 21:16:48MEDIUM (6)UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of serviceLOCAL
CVE-2026-151682026-07-08 22:17:14LOW (3)BLF file parser in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows possible information disclosureLOCAL
CVE-2026-151672026-07-08 21:16:48HIGH (8)DBS Etherwatch file parser crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of serviceNETWORK
CVE-2026-151662026-07-08 21:16:48MEDIUM (6)IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of serviceLOCAL
CVE-2026-151652026-07-08 21:16:47MEDIUM (6)TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of serviceLOCAL
CVE-2026-151632026-07-08 21:16:47MEDIUM (6)Multiple protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allow denial of serviceLOCAL
CVE-2026-09622026-01-14 21:15:53MEDIUM (5)SOME/IP-SD protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of serviceNETWORK
CVE-2026-09612026-01-14 21:15:53MEDIUM (6)BLF file parser crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of serviceLOCAL
CVE-2026-09602026-01-14 21:15:53MEDIUM (5)HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of serviceLOCAL
CVE-2026-09592026-01-14 21:15:53MEDIUM (5)IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of serviceNETWORK
CVE-2025-98172025-09-03 08:15:32HIGH (8)SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial of serviceLOCAL
CVE-2025-56012025-06-04 11:15:22HIGH (8)Column handling crashes in Wireshark 4.4.0 to 4.4.6 and 4.2.0 to 4.2.12 allows denial of service via packet injection or crafted capture fileLOCAL
CVE-2025-14922025-02-20 02:15:39HIGH (8)Bundle Protocol and CBOR dissector crashes in Wireshark 4.4.0 to 4.4.3 and 4.2.0 to 4.2.10 allows denial of service via packet injection or crafted capture fileLOCAL
CVE-2025-139462025-12-03 08:15:48MEDIUM (6)MEGACO dissector infinite loop in Wireshark 4.6.0 to 4.6.1 and 4.4.0 to 4.4.11 allows denial of serviceLOCAL
CVE-2025-139452025-12-03 08:15:48MEDIUM (6)HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of serviceLOCAL
CVE-2025-136742025-11-26 12:15:46MEDIUM (6)BPv7 dissector crash in Wireshark 4.6.0 allows denial of serviceLOCAL
CVE-2025-134992025-11-21 06:15:48HIGH (8)Kafka dissector crash in Wireshark 4.6.0 and 4.4.0 to 4.4.10 allows denial of serviceLOCAL
CVE-2024-97812024-10-10 07:15:04HIGH (8)AppleTalk and RELOAD Framing dissector crash in Wireshark 4.4.0 and 4.2.0 to 4.2.7 allows denial of service via packet injection or crafted capture fileLOCAL
CVE-2024-97802024-10-10 07:15:04MEDIUM (8)ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capture fileLOCAL
CVE-2024-86452024-09-10 10:15:14MEDIUM (6)SPRT dissector crash in Wireshark 4.2.0 to 4.0.5 and 4.0.0 to 4.0.15 allows denial of service via packet injection or crafted capture fileLOCAL
CVE-2024-82502024-08-29 00:15:09MEDIUM (8)NTLMSSP dissector crash in Wireshark 4.2.0 to 4.0.6 and 4.0.0 to 4.0.16 allows denial of service via packet injection or crafted capture fileLOCAL
CVE-2024-48542024-05-14 15:45:19MEDIUM (6)MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet injection or crafted capture fileNETWORK
CVE-2024-29552024-03-26 20:15:12HIGH (8)T.38 dissector crash in Wireshark 4.2.0 to 4.0.3 and 4.0.0 to 4.0.13 allows denial of service via packet injection or crafted capture fileLOCAL
CVE-2024-244792024-02-21 19:15:09HIGH (8)A Buffer Overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the wsutil/to_str.c, and format_fractional_part_nsecs components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.NETWORK
CVE-2024-244782024-02-21 17:15:10HIGH (8)An issue in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the packet-bgp.c, dissect_bgp_open(tvbuff_t*tvb, proto_tree*tree, packet_info*pinfo), optlen components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.NETWORK
CVE-2024-244762024-02-21 19:15:09HIGH (8)A buffer overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the pan/addr_resolv.c, and ws_manuf_lookup_str(), size components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.NETWORK
CVE-2024-115962024-11-21 11:15:33HIGH (8)ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture fileLOCAL
CVE-2024-115952024-11-21 11:15:33HIGH (8)FiveCo RAP dissector infinite loop in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture fileLOCAL
CVE-2024-02112024-01-03 08:15:11HIGH (8)DOCSIS dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2024-02102024-01-03 08:15:11HIGH (8)Zigbee TLV dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2024-02092024-01-03 08:15:11HIGH (8)IEEE 1609.2 dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2024-02082024-01-03 08:15:10HIGH (8)GVCP dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2024-02072024-01-03 08:15:10HIGH (8)HTTP3 dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2023-61752024-03-26 08:15:36HIGH (8)NetScreen file parser crash in Wireshark 4.0.0 to 4.0.10 and 3.6.0 to 3.6.18 allows denial of service via crafted capture fileLOCAL
CVE-2023-61742023-11-16 12:15:07MEDIUM (7)SSH dissector crash in Wireshark 4.0.0 to 4.0.10 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2023-53712023-10-04 17:15:10MEDIUM (7)RTPS dissector memory leak in Wireshark 4.0.0 to 4.0.8 and 3.6.0 to 3.6.16 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2023-45132023-08-24 07:15:12MEDIUM (8)BT SDP dissector memory leak in Wireshark 4.0.0 to 4.0.7 and 3.6.0 to 3.6.15 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2023-45122023-08-24 07:15:12MEDIUM (8)CBOR dissector crash in Wireshark 4.0.0 to 4.0.6 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2023-45112023-08-24 07:15:12MEDIUM (8)BT SDP dissector infinite loop in Wireshark 4.0.0 to 4.0.7 and 3.6.0 to 3.6.15 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2023-36492023-07-14 07:15:09MEDIUM (6)iSCSI dissector crash in Wireshark 4.0.0 to 4.0.6 allows denial of service via packet injection or crafted capture fileLOCAL
CVE-2023-36482023-07-14 07:15:08MEDIUM (6)Kafka dissector crash in Wireshark 4.0.0 to 4.0.6 and 3.6.0 to 3.6.14 allows denial of service via packet injection or crafted capture fileLOCAL
CVE-2023-29522023-05-30 23:15:10MEDIUM (7)XRA dissector infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2023-29062023-08-25 21:15:08MEDIUM (7)Due to a failure in validating the length provided by an attacker-crafted CP2179 packet, Wireshark versions 2.0.0 through 4.0.7 is susceptible to a divide by zero allowing for a denial of service attack. NETWORK
CVE-2023-28792023-05-26 21:15:19MEDIUM (8)GDSDB infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2023-28582023-05-26 21:15:19MEDIUM (7)NetScaler file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture fileNETWORK
CVE-2023-28572023-05-26 21:15:18MEDIUM (7)BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture fileNETWORK
CVE-2023-28562023-05-26 21:15:18MEDIUM (7)VMS TCPIPtrace file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture fileNETWORK
CVE-2023-28552023-05-26 21:15:18MEDIUM (7)Candump log parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture fileNETWORK
CVE-2023-28542023-05-26 21:15:18MEDIUM (7)BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture fileNETWORK
CVE-2023-19942023-04-12 22:15:14MEDIUM (7)GQUIC dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2023-19932023-04-12 21:15:16MEDIUM (7)LISP dissector large loop in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2023-19922023-04-12 21:15:15MEDIUM (8)RPCoRDMA dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2023-11612023-03-06 21:15:11MEDIUM (7)ISO 15765 and ISO 10681 dissector crash in Wireshark 4.0.0 to 4.0.3 and 3.6.0 to 3.6.11 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2023-06682023-06-07 03:15:09MEDIUM (7)Due to failure in validating the length provided by an attacker-crafted IEEE-C37.118 packet, Wireshark version 4.0.5 and prior, by default, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark.NETWORK
CVE-2023-06672023-06-07 03:15:09MEDIUM (7)Due to failure in validating the length provided by an attacker-crafted MSMMS packet, Wireshark version 4.0.5 and prior, in an unusual configuration, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running WiresharkNETWORK
CVE-2023-06662023-06-07 03:15:09MEDIUM (7)Due to failure in validating the length provided by an attacker-crafted RTPS packet, Wireshark version 4.0.5 and prior, by default, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark.NETWORK
CVE-2023-04172023-01-26 21:18:08MEDIUM (7)Memory leak in the NFS dissector in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2023-04162023-01-26 21:18:08MEDIUM (7)GNW dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2023-04152023-01-26 21:18:08MEDIUM (7)iSCSI dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2023-04142023-01-26 21:18:08MEDIUM (7)Crash in the EAP dissector in Wireshark 4.0.0 to 4.0.2 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2023-04132023-01-26 21:18:08MEDIUM (7)Dissection engine bug in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2023-04122023-01-26 21:18:08MEDIUM (7)TIPC dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2023-04112023-01-26 21:18:08MEDIUM (7)Excessive loops in multiple dissectors in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2022-43452023-01-12 04:15:11MEDIUM (7)Infinite loops in the BPv6, OpenFlow, and Kafka protocol dissectors in Wireshark 4.0.0 to 4.0.1 and 3.6.0 to 3.6.9 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2022-43442023-01-12 00:15:09MEDIUM (6)Memory exhaustion in the Kafka protocol dissector in Wireshark 4.0.0 to 4.0.1 and 3.6.0 to 3.6.9 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2022-37252022-10-27 17:15:10MEDIUM (8)Crash in the OPUS protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2022-37242022-12-09 18:15:20MEDIUM (8)Crash in the USB HID protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or crafted capture file on WindowsNETWORK
CVE-2022-31902022-09-13 15:15:09MEDIUM (6)Infinite loop in the F5 Ethernet Trailer protocol dissector in Wireshark 3.6.0 to 3.6.7 and 3.4.0 to 3.4.15 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2022-05862022-02-14 22:15:08MEDIUM (8)Infinite loop in RTMPT protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2022-05852022-02-18 18:15:12MEDIUM (7)Large loops in multiple protocol dissectors in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allow denial of service via packet injection or crafted capture fileNETWORK
CVE-2022-05832022-02-14 22:15:08MEDIUM (8)Crash in the PVFS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2022-05822022-02-14 22:15:08MEDIUM (10)Unaligned access in the CSN.1 protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2022-05812022-02-14 22:15:08MEDIUM (8)Crash in the CMS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2021-41902021-12-30 22:15:10HIGH (8)Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2021-41862021-12-30 22:15:10MEDIUM (8)Crash in the Gryphon dissector in Wireshark 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2021-41852021-12-30 22:15:10HIGH (8)Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2021-41842021-12-30 22:15:10HIGH (8)Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2021-41832021-12-30 22:15:10MEDIUM (6)Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture fileLOCAL
CVE-2021-41822021-12-30 22:15:10HIGH (8)Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2021-41812021-12-30 22:15:10HIGH (8)Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2021-399292021-11-19 17:15:09HIGH (8)Uncontrolled Recursion in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2021-399282021-11-18 19:15:08HIGH (8)NULL pointer exception in the IEEE 802.11 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2021-399262021-11-19 17:15:09HIGH (8)Buffer overflow in the Bluetooth HCI_ISO dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2021-399252021-11-19 17:15:09HIGH (8)Buffer overflow in the Bluetooth SDP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2021-399242021-11-19 17:15:09HIGH (8)Large loop in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2021-399232021-11-19 17:15:08HIGH (8)Large loop in the PNRP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2021-399222021-11-19 17:15:08HIGH (8)Buffer overflow in the C12.22 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2021-399212021-11-19 17:15:08HIGH (8)NULL pointer exception in the Modbus dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2021-399202021-11-18 19:15:08HIGH (8)NULL pointer exception in the IPPUSB dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2021-222352021-07-20 12:15:08HIGH (8)Crash in DNP dissector in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2021-222222021-06-07 13:15:08HIGH (8)Infinite loop in DVB-S2-BB dissector in Wireshark 3.4.0 to 3.4.5 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2021-222072021-04-23 18:15:08MEDIUM (7)Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2021-221912021-03-15 18:15:18MEDIUM (9)Improper URL handling in Wireshark 3.4.0 to 3.4.3 and 3.2.0 to 3.2.11 could allow remote code execution via via packet injection or crafted capture file.NETWORK
CVE-2021-221742021-02-17 15:15:13LOW (8)Crash in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2021-221732021-02-17 15:15:13LOW (8)Memory leak in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2020-94312020-02-27 23:15:13HIGH (8)In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the LTE RRC dissector could leak memory. This was addressed in epan/dissectors/packet-lte-rrc.c by adjusting certain append operations.NETWORK
CVE-2020-94302020-02-27 23:15:13HIGH (8)In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the WiMax DLMAP dissector could crash. This was addressed in plugins/epan/wimax/msg_dlmap.c by validating a length field.NETWORK
CVE-2020-94292020-02-27 23:15:13HIGH (8)In Wireshark 3.2.0 to 3.2.1, the WireGuard dissector could crash. This was addressed in epan/dissectors/packet-wireguard.c by handling the situation where a certain data structure intentionally has a NULL value.NETWORK
CVE-2020-94282020-02-27 23:15:13HIGH (8)In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the EAP dissector could crash. This was addressed in epan/dissectors/packet-eap.c by using more careful sscanf parsing.NETWORK
CVE-2020-70452020-01-16 04:15:11MEDIUM (7)In Wireshark 3.0.x before 3.0.8, the BT ATT dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by validating opcodes.ADJACENT_NETWORK
CVE-2020-70442020-01-16 04:15:11HIGH (8)In Wireshark 3.2.x before 3.2.1, the WASSP dissector could crash. This was addressed in epan/dissectors/packet-wassp.c by using >= and <= to resolve off-by-one errors.NETWORK
CVE-2020-280302020-11-02 21:15:30HIGH (8)In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed in epan/dissectors/packet-gquic.c by correcting the implementation of offset advancement.NETWORK
CVE-2020-265752020-10-06 15:15:16HIGH (8)In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector could enter an infinite loop. This was addressed in epan/dissectors/packet-fbzero.c by correcting the implementation of offset advancement.NETWORK
CVE-2020-264222020-12-21 18:15:15MEDIUM (5)Buffer overflow in QUIC dissector in Wireshark 3.4.0 to 3.4.1 allows denial of service via packet injection or crafted capture fileNETWORK
CVE-2020-264212020-12-11 19:15:12MEDIUM (5)Crash in USB HID protocol dissector and possibly other dissectors in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.NETWORK
CVE-2020-264202020-12-11 19:15:12MEDIUM (5)Memory leak in RTPS protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.NETWORK
CVE-2020-264192020-12-11 19:15:12MEDIUM (5)Memory leak in the dissection engine in Wireshark 3.4.0 allows denial of service via packet injection or crafted capture file.NETWORK
CVE-2020-264182020-12-11 19:15:12MEDIUM (5)Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.NETWORK
CVE-2020-258662020-10-06 15:15:15HIGH (8)In Wireshark 3.2.0 to 3.2.6 and 3.0.0 to 3.0.13, the BLIP protocol dissector has a NULL pointer dereference because a buffer was sized for compressed (not uncompressed) messages. This was addressed in epan/dissectors/packet-blip.c by allowing reasonable compression ratios and rejecting ZIP bombs.NETWORK
CVE-2020-258632020-10-06 15:15:15HIGH (8)In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the MIME Multipart dissector could crash. This was addressed in epan/dissectors/packet-multipart.c by correcting the deallocation of invalid MIME parts.NETWORK
CVE-2020-258622020-10-06 15:15:15HIGH (8)In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by changing the handling of the invalid 0xFFFF checksum.NETWORK
CVE-2020-174982020-08-13 16:15:13MEDIUM (7)In Wireshark 3.2.0 to 3.2.5, the Kafka protocol dissector could crash. This was addressed in epan/dissectors/packet-kafka.c by avoiding a double free during LZ4 decompression.NETWORK
CVE-2020-154662020-07-05 11:15:10HIGH (8)In Wireshark 3.2.0 to 3.2.4, the GVCP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-gvcp.c by ensuring that an offset increases in all situations.NETWORK
CVE-2020-131642020-05-19 22:15:12HIGH (8)In Wireshark 3.2.0 to 3.2.3, 3.0.0 to 3.0.10, and 2.6.0 to 2.6.16, the NFS dissector could crash. This was addressed in epan/dissectors/packet-nfs.c by preventing excessive recursion, such as for a cycle in the directory graph on a filesystem.NETWORK
CVE-2020-116472020-04-10 21:15:12HIGH (8)In Wireshark 3.2.0 to 3.2.2, 3.0.0 to 3.0.9, and 2.6.0 to 2.6.15, the BACapp dissector could crash. This was addressed in epan/dissectors/packet-bacapp.c by limiting the amount of recursion.NETWORK
CVE-2019-92142019-02-28 04:29:00MEDIUM (5)In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the RPCAP dissector could crash. This was addressed in epan/dissectors/packet-rpcap.c by avoiding an attempted dereference of a NULL conversation.NETWORK
CVE-2019-92092019-02-28 04:29:00MEDIUM (6)In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash. This was addressed in epan/dissectors/packet-ber.c by preventing a buffer overflow associated with excessive digits in time values.LOCAL
CVE-2019-92082019-02-28 04:29:00MEDIUM (5)In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the TCAP dissector could crash. This was addressed in epan/dissectors/asn1/tcap/tcap.cnf by avoiding NULL pointer dereferences.NETWORK
CVE-2019-57212019-01-08 23:29:01MEDIUM (4)In Wireshark 2.4.0 to 2.4.11, the ENIP dissector could crash. This was addressed in epan/dissectors/packet-enip.c by changing the memory-management approach so that a use-after-free is avoided.NETWORK
CVE-2019-57192019-01-08 23:29:01MEDIUM (4)In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the ISAKMP dissector could crash. This was addressed in epan/dissectors/packet-isakmp.c by properly handling the case of a missing decryption data block.NETWORK
CVE-2019-57182019-01-08 23:29:00MEDIUM (4)In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the RTSE dissector and other ASN.1 dissectors could crash. This was addressed in epan/charsets.c by adding a get_t61_string length check.NETWORK
CVE-2019-57172019-01-08 23:29:00MEDIUM (4)In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the P_MUL dissector could crash. This was addressed in epan/dissectors/packet-p_mul.c by rejecting the invalid sequence number of zero.NETWORK
CVE-2019-57162019-01-08 23:29:00MEDIUM (4)In Wireshark 2.6.0 to 2.6.5, the 6LoWPAN dissector could crash. This was addressed in epan/dissectors/packet-6lowpan.c by avoiding use of a TVB before its creation.NETWORK
CVE-2019-195532019-12-05 01:15:14HIGH (8)In Wireshark 3.0.0 to 3.0.6 and 2.6.0 to 2.6.12, the CMS dissector could crash. This was addressed in epan/dissectors/asn1/cms/packet-cms-template.c by ensuring that an object identifier is set to NULL after a ContentInfo dissection.NETWORK
CVE-2019-163192019-09-15 16:15:13HIGH (8)In Wireshark 3.0.0 to 3.0.3 and 2.6.0 to 2.6.10, the Gryphon dissector could go into an infinite loop. This was addressed in plugins/epan/gryphon/packet-gryphon.c by checking for a message length of zero.NETWORK
CVE-2019-136192019-07-17 20:15:12HIGH (8)In Wireshark 3.0.0 to 3.0.2, 2.6.0 to 2.6.9, and 2.4.0 to 2.4.15, the ASN.1 BER dissector and related dissectors could crash. This was addressed in epan/asn1.c by properly restricting buffer increments.NETWORK
CVE-2019-122952019-05-23 12:29:00HIGH (8)In Wireshark 3.0.0 to 3.0.1, 2.6.0 to 2.6.8, and 2.4.0 to 2.4.14, the dissection engine could crash. This was addressed in epan/packet.c by restricting the number of layers and consequently limiting recursion.NETWORK
CVE-2019-109032019-04-09 04:29:02HIGH (8)In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DCERPC SPOOLSS dissector could crash. This was addressed in epan/dissectors/packet-dcerpc-spoolss.c by adding a boundary check.NETWORK
CVE-2019-109022019-04-09 04:29:02MEDIUM (5)In Wireshark 3.0.0, the TSDNS dissector could crash. This was addressed in epan/dissectors/packet-tsdns.c by splitting strings safely.NETWORK
CVE-2019-109012019-04-09 04:29:01HIGH (8)In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the LDSS dissector could crash. This was addressed in epan/dissectors/packet-ldss.c by handling file digests properly.NETWORK
CVE-2019-109002019-04-09 04:29:01MEDIUM (5)In Wireshark 3.0.0, the Rbm dissector could go into an infinite loop. This was addressed in epan/dissectors/file-rbm.c by handling unknown object types safely.NETWORK
CVE-2019-108992019-04-09 04:29:01HIGH (8)In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the SRVLOC dissector could crash. This was addressed in epan/dissectors/packet-srvloc.c by preventing a heap-based buffer under-read.NETWORK
CVE-2019-108982019-04-09 04:29:01MEDIUM (5)In Wireshark 3.0.0, the GSUP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-gsm_gsup.c by rejecting an invalid Information Element length.NETWORK
CVE-2019-108972019-04-09 04:29:01MEDIUM (5)In Wireshark 3.0.0, the IEEE 802.11 dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-ieee80211.c by detecting cases in which the bit offset does not advance.NETWORK
CVE-2019-108962019-04-09 04:29:01HIGH (8)In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DOF dissector could crash. This was addressed in epan/dissectors/packet-dof.c by properly handling generated IID and OID bytes.NETWORK
CVE-2019-108952019-04-09 04:29:01HIGH (8)In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the NetScaler file parser could crash. This was addressed in wiretap/netscaler.c by improving data validation.NETWORK
CVE-2019-108942019-04-09 04:29:01HIGH (8)In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the GSS-API dissector could crash. This was addressed in epan/dissectors/packet-gssapi.c by ensuring that a valid dissector is called.NETWORK
CVE-2018-92742018-04-04 07:29:02MEDIUM (5)In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, ui/failure_message.c has a memory leak.NETWORK
CVE-2018-92732018-04-04 07:29:02MEDIUM (5)In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-pcp.c has a memory leak.NETWORK
CVE-2018-92722018-04-04 07:29:01MEDIUM (5)In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-h223.c has a memory leak.NETWORK
CVE-2018-92712018-04-04 07:29:01MEDIUM (5)In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-multipart.c has a memory leak.NETWORK
CVE-2018-92702018-04-04 07:29:01MEDIUM (5)In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/oids.c has a memory leak.NETWORK
CVE-2018-92692018-04-04 07:29:01MEDIUM (5)In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-giop.c has a memory leak.NETWORK
CVE-2018-92682018-04-04 07:29:01MEDIUM (5)In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-smb2.c has a memory leak.NETWORK
CVE-2018-92672018-04-04 07:29:01MEDIUM (5)In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-lapd.c has a memory leak.NETWORK
CVE-2018-92662018-04-04 07:29:01MEDIUM (5)In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-isup.c has a memory leak.NETWORK
CVE-2018-92652018-04-04 07:29:01MEDIUM (5)In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-tn3270.c has a memory leak.NETWORK
CVE-2018-92642018-04-04 07:29:01MEDIUM (5)In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the ADB dissector could crash with a heap-based buffer overflow. This was addressed in epan/dissectors/packet-adb.c by checking for a length inconsistency.NETWORK
CVE-2018-92632018-04-04 07:29:01MEDIUM (5)In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the Kerberos dissector could crash. This was addressed in epan/dissectors/packet-kerberos.c by ensuring a nonzero key length.NETWORK
CVE-2018-92622018-04-04 07:29:01MEDIUM (5)In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the VLAN dissector could crash. This was addressed in epan/dissectors/packet-vlan.c by limiting VLAN tag nesting to restrict the recursion depth.NETWORK
CVE-2018-92612018-04-04 07:29:01MEDIUM (5)In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the NBAP dissector could crash with a large loop that ends with a heap-based buffer overflow. This was addressed in epan/dissectors/packet-nbap.c by prohibiting the self-linking of DCH-IDs.NETWORK
CVE-2018-92602018-04-04 07:29:01MEDIUM (5)In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the IEEE 802.15.4 dissector could crash. This was addressed in epan/dissectors/packet-ieee802154.c by ensuring that an allocation step occurs.NETWORK
CVE-2018-92592018-04-04 07:29:01MEDIUM (5)In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the MP4 dissector could crash. This was addressed in epan/dissectors/file-mp4.c by restricting the box recursion depth.NETWORK
CVE-2018-92582018-04-04 07:29:01MEDIUM (5)In Wireshark 2.4.0 to 2.4.5, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by preserving valid data sources.NETWORK
CVE-2018-92572018-04-04 07:29:01MEDIUM (5)In Wireshark 2.4.0 to 2.4.5, the CQL dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-cql.c by checking for a nonzero number of columns.NETWORK
CVE-2018-92562018-04-04 07:29:00MEDIUM (5)In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the LWAPP dissector could crash. This was addressed in epan/dissectors/packet-lwapp.c by limiting the encapsulation levels to restrict the recursion depth.NETWORK
CVE-2018-74212018-02-23 22:29:02HIGH (8)In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the DMP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-dmp.c by correctly supporting a bounded number of Security Categories for a DMP Security Classification.NETWORK
CVE-2018-74202018-02-23 22:29:02MEDIUM (5)In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the pcapng file parser could crash. This was addressed in wiretap/pcapng.c by adding a block-size check for sysdig event blocks.NETWORK
CVE-2018-74192018-02-23 22:29:02MEDIUM (5)In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the NBAP dissector could crash. This was addressed in epan/dissectors/asn1/nbap/nbap.cnf by ensuring DCH ID initialization.NETWORK
CVE-2018-74182018-02-23 22:29:02MEDIUM (5)In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the SIGCOMP dissector could crash. This was addressed in epan/dissectors/packet-sigcomp.c by correcting the extraction of the length value.NETWORK
CVE-2018-74172018-02-23 22:29:02MEDIUM (5)In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the IPMI dissector could crash. This was addressed in epan/dissectors/packet-ipmi-picmg.c by adding support for crafted packets that lack an IPMI header.NETWORK
CVE-2018-73372018-02-23 22:29:01MEDIUM (5)In Wireshark 2.4.0 to 2.4.4, the DOCSIS protocol dissector could crash. This was addressed in plugins/docsis/packet-docsis.c by removing the recursive algorithm that had been used for concatenated PDUs.NETWORK
CVE-2018-73362018-02-23 22:29:01MEDIUM (5)In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the FCP protocol dissector could crash. This was addressed in epan/dissectors/packet-fcp.c by checking for a NULL pointer.NETWORK
CVE-2018-73352018-02-23 22:29:01MEDIUM (5)In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the IEEE 802.11 dissector could crash. This was addressed in epan/crypt/airpdcap.c by rejecting lengths that are too small.NETWORK
CVE-2018-73342018-02-23 22:29:01MEDIUM (5)In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the UMTS MAC dissector could crash. This was addressed in epan/dissectors/packet-umts_mac.c by rejecting a certain reserved value.NETWORK
CVE-2018-73332018-02-23 22:29:01MEDIUM (5)In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-rpcrdma.c had an infinite loop that was addressed by validating a chunk size.NETWORK
CVE-2018-73322018-02-23 22:29:01MEDIUM (5)In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-reload.c had an infinite loop that was addressed by validating a length.NETWORK
CVE-2018-73312018-02-23 22:29:01MEDIUM (5)In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-ber.c had an infinite loop that was addressed by validating a length.NETWORK
CVE-2018-73302018-02-23 22:29:01MEDIUM (5)In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-thread.c had an infinite loop that was addressed by using a correct integer data type.NETWORK
CVE-2018-73292018-02-23 22:29:01MEDIUM (5)In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-s7comm.c had an infinite loop that was addressed by correcting off-by-one errors.NETWORK
CVE-2018-73282018-02-23 22:29:01MEDIUM (5)In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-usb.c had an infinite loop that was addressed by rejecting short frame header lengths.NETWORK
CVE-2018-73272018-02-23 22:29:01MEDIUM (5)In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-openflow_v6.c had an infinite loop that was addressed by validating property lengths.NETWORK
CVE-2018-73262018-02-23 22:29:01MEDIUM (5)In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-lltd.c had an infinite loop that was addressed by using a correct integer data type.NETWORK
CVE-2018-73252018-02-23 22:29:01MEDIUM (5)In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-rpki-rtr.c had an infinite loop that was addressed by validating a length field.NETWORK
CVE-2018-73242018-02-23 22:29:01MEDIUM (5)In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-sccp.c had an infinite loop that was addressed by using a correct integer data type.NETWORK
CVE-2018-73232018-02-23 22:29:00MEDIUM (5)In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-wccp.c had a large loop that was addressed by ensuring that a calculated length was monotonically increasing.NETWORK
CVE-2018-73222018-02-23 22:29:00MEDIUM (5)In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-dcm.c had an infinite loop that was addressed by checking for integer wraparound.NETWORK
CVE-2018-73212018-02-23 22:29:00MEDIUM (5)In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-thrift.c had a large loop that was addressed by not proceeding with dissection after encountering an unexpected type.NETWORK
CVE-2018-73202018-02-23 22:29:00MEDIUM (5)In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the SIGCOMP protocol dissector could crash. This was addressed in epan/dissectors/packet-sigcomp.c by validating operand offsets.NETWORK
CVE-2018-68362018-02-08 07:29:01HIGH (8)The netmonrec_comment_destroy function in wiretap/netmon.c in Wireshark through 2.4.4 performs a free operation on an uninitialized memory address, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.NETWORK
CVE-2018-53362018-01-11 21:29:00MEDIUM (5)In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the JSON, XML, NTP, XMPP, and GDB dissectors could crash. This was addressed in epan/tvbparse.c by limiting the recursion depth.NETWORK
CVE-2018-53352018-01-11 21:29:00MEDIUM (4)In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the WCP dissector could crash. This was addressed in epan/dissectors/packet-wcp.c by validating the available buffer length.NETWORK
CVE-2018-53342018-01-11 21:29:00MEDIUM (4)In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the IxVeriWave file parser could crash. This was addressed in wiretap/vwr.c by correcting the signature timestamp bounds checks.NETWORK
CVE-2018-196282018-11-29 04:29:01MEDIUM (5)In Wireshark 2.6.0 to 2.6.4, the ZigBee ZCL dissector could crash. This was addressed in epan/dissectors/packet-zbee-zcl-lighting.c by preventing a divide-by-zero error.NETWORK
CVE-2018-196272018-11-29 04:29:01MEDIUM (5)In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the IxVeriWave file parser could crash. This was addressed in wiretap/vwr.c by adjusting a buffer boundary.NETWORK
CVE-2018-196262018-11-29 04:29:01MEDIUM (4)In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the DCOM dissector could crash. This was addressed in epan/dissectors/packet-dcom.c by adding '\0' termination.NETWORK
CVE-2018-196252018-11-29 04:29:01MEDIUM (4)In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the dissection engine could crash. This was addressed in epan/tvbuff_composite.c by preventing a heap-based buffer over-read.NETWORK
CVE-2018-196242018-11-29 04:29:00MEDIUM (4)In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the PVFS dissector could crash. This was addressed in epan/dissectors/packet-pvfs2.c by preventing a NULL pointer dereference.NETWORK
CVE-2018-196232018-11-29 04:29:00MEDIUM (5)In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the LBMPDM dissector could crash. In addition, a remote attacker could write arbitrary data to any memory locations before the packet-scoped memory. This was addressed in epan/dissectors/packet-lbmpdm.c by disallowing certain negative values.NETWORK
CVE-2018-196222018-11-29 04:29:00MEDIUM (5)In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the MMSE dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-mmse.c by preventing length overflows.NETWORK
CVE-2018-182272018-10-12 06:29:01MEDIUM (5)In Wireshark 2.6.0 to 2.6.3 and 2.4.0 to 2.4.9, the MS-WSP protocol dissector could crash. This was addressed in epan/dissectors/packet-mswsp.c by properly handling NULL return values.NETWORK
CVE-2018-182262018-10-12 06:29:01HIGH (8)In Wireshark 2.6.0 to 2.6.3, the Steam IHS Discovery dissector could consume system memory. This was addressed in epan/dissectors/packet-steam-ihs-discovery.c by changing the memory-management approach.NETWORK
CVE-2018-182252018-10-12 06:29:01HIGH (8)In Wireshark 2.6.0 to 2.6.3, the CoAP dissector could crash. This was addressed in epan/dissectors/packet-coap.c by ensuring that the piv length is correctly computed.NETWORK
CVE-2018-160582018-08-30 01:29:01MEDIUM (5)In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Bluetooth AVDTP dissector could crash. This was addressed in epan/dissectors/packet-btavdtp.c by properly initializing a data structure.NETWORK
CVE-2018-160572018-08-30 01:29:00HIGH (8)In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Radiotap dissector could crash. This was addressed in epan/dissectors/packet-ieee80211-radiotap-iter.c by validating iterator operations.NETWORK
CVE-2018-160562018-08-30 01:29:00MEDIUM (5)In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Bluetooth Attribute Protocol dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by verifying that a dissector for a specific UUID exists.NETWORK
CVE-2018-144382018-07-20 00:29:00MEDIUM (5)In Wireshark through 2.6.2, the create_app_running_mutex function in wsutil/file_util.c calls SetSecurityDescriptorDacl to set a NULL DACL, which allows attackers to modify the access control arbitrarily.NETWORK
CVE-2018-143702018-07-19 02:29:01MEDIUM (5)In Wireshark 2.6.0 to 2.6.1 and 2.4.0 to 2.4.7, the IEEE 802.11 protocol dissector could crash. This was addressed in epan/crypt/airpdcap.c via bounds checking that prevents a buffer over-read.NETWORK
CVE-2018-143692018-07-19 02:29:01MEDIUM (5)In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the HTTP2 dissector could crash. This was addressed in epan/dissectors/packet-http2.c by verifying that header data was found before proceeding to header decompression.NETWORK
CVE-2018-143682018-07-19 02:29:01HIGH (8)In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the Bazaar protocol dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-bzr.c by properly handling items that are too long.NETWORK
CVE-2018-143672018-07-19 02:29:01MEDIUM (5)In Wireshark 2.6.0 to 2.6.1 and 2.4.0 to 2.4.7, the CoAP protocol dissector could crash. This was addressed in epan/dissectors/packet-coap.c by properly checking for a NULL condition.NETWORK
CVE-2018-143442018-07-19 02:29:00MEDIUM (5)In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the ISMP dissector could crash. This was addressed in epan/dissectors/packet-ismp.c by validating the IPX address length to avoid a buffer over-read.NETWORK
CVE-2018-143432018-07-19 02:29:00MEDIUM (5)In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the ASN.1 BER dissector could crash. This was addressed in epan/dissectors/packet-ber.c by ensuring that length values do not exceed the maximum signed integer.NETWORK
CVE-2018-143422018-07-19 02:29:00HIGH (8)In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the BGP protocol dissector could go into a large loop. This was addressed in epan/dissectors/packet-bgp.c by validating Path Attribute lengths.NETWORK
CVE-2018-143412018-07-19 02:29:00HIGH (8)In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the DICOM dissector could go into a large or infinite loop. This was addressed in epan/dissectors/packet-dcm.c by preventing an offset overflow.NETWORK
CVE-2018-143402018-07-19 02:29:00MEDIUM (5)In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, dissectors that support zlib decompression could crash. This was addressed in epan/tvbuff_zlib.c by rejecting negative lengths to avoid a buffer over-read.NETWORK
CVE-2018-143392018-07-19 02:29:00MEDIUM (5)In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the MMSE dissector could go into an infinite loop. This was addressed in epan/proto.c by adding offset and length validation.NETWORK
CVE-2018-113622018-05-22 21:29:01MEDIUM (5)In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LDSS dissector could crash. This was addressed in epan/dissectors/packet-ldss.c by avoiding a buffer over-read upon encountering a missing '\0' character.NETWORK
CVE-2018-113612018-05-22 21:29:01MEDIUM (5)In Wireshark 2.6.0, the IEEE 802.11 protocol dissector could crash. This was addressed in epan/crypt/dot11decrypt.c by avoiding a buffer overflow during FTE processing in Dot11DecryptTDLSDeriveKey.NETWORK
CVE-2018-113602018-05-22 21:29:00MEDIUM (5)In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the GSM A DTAP dissector could crash. This was addressed in epan/dissectors/packet-gsm_a_dtap.c by fixing an off-by-one error that caused a buffer overflow.NETWORK
CVE-2018-113592018-05-22 21:29:00MEDIUM (5)In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the RRC dissector and other dissectors could crash. This was addressed in epan/proto.c by avoiding a NULL pointer dereference.NETWORK
CVE-2018-113582018-05-22 21:29:00MEDIUM (5)In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the Q.931 dissector could crash. This was addressed in epan/dissectors/packet-q931.c by avoiding a use-after-free after a malformed packet prevented certain cleanup.NETWORK
CVE-2018-113572018-05-22 21:29:00MEDIUM (5)In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LTP dissector and other dissectors could consume excessive memory. This was addressed in epan/tvbuff.c by rejecting negative lengths.NETWORK
CVE-2018-113562018-05-22 21:29:00MEDIUM (5)In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the DNS dissector could crash. This was addressed in epan/dissectors/packet-dns.c by avoiding a NULL pointer dereference for an empty name in an SRV record.NETWORK
CVE-2018-113552018-05-22 21:29:00MEDIUM (5)In Wireshark 2.6.0, the RTCP dissector could crash. This was addressed in epan/dissectors/packet-rtcp.c by avoiding a buffer overflow for packet status chunks.NETWORK
CVE-2018-113542018-05-22 21:29:00MEDIUM (5)In Wireshark 2.6.0, the IEEE 1905.1a dissector could crash. This was addressed in epan/dissectors/packet-ieee1905.c by making a certain correction to string handling.NETWORK
CVE-2017-97662017-06-21 07:29:00MEDIUM (5)In Wireshark 2.2.7, PROFINET IO data with a high recursion depth allows remote attackers to cause a denial of service (stack exhaustion) in the dissect_IODWriteReq function in plugins/profinet/packet-dcerpc-pn-io.c.NETWORK
CVE-2017-96172017-06-14 20:29:00MEDIUM (4)In Wireshark 2.2.7, deeply nested DAAP data may cause stack exhaustion (uncontrolled recursion) in the dissect_daap_one_tag function in epan/dissectors/packet-daap.c in the DAAP dissector.NETWORK
CVE-2017-96162017-06-14 20:29:00MEDIUM (4)In Wireshark 2.2.7, overly deep mp4 chunks may cause stack exhaustion (uncontrolled recursion) in the dissect_mp4_box function in epan/dissectors/file-mp4.c.NETWORK
CVE-2017-93542017-06-02 05:29:01MEDIUM (5)In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the RGMP dissector could crash. This was addressed in epan/dissectors/packet-rgmp.c by validating an IPv4 address.NETWORK
CVE-2017-93532017-06-02 05:29:01MEDIUM (5)In Wireshark 2.2.0 to 2.2.6, the IPv6 dissector could crash. This was addressed in epan/dissectors/packet-ipv6.c by validating an IPv6 address.NETWORK
CVE-2017-93522017-06-02 05:29:01HIGH (8)In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the Bazaar dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-bzr.c by ensuring that backwards parsing cannot occur.NETWORK
CVE-2017-93512017-06-02 05:29:01MEDIUM (5)In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DHCP dissector could read past the end of a buffer. This was addressed in epan/dissectors/packet-bootp.c by extracting the Vendor Class Identifier more carefully.NETWORK
CVE-2017-93502017-06-02 05:29:00HIGH (8)In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the openSAFETY dissector could crash or exhaust system memory. This was addressed in epan/dissectors/packet-opensafety.c by checking for a negative length.NETWORK
CVE-2017-93492017-06-02 05:29:00HIGH (8)In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DICOM dissector has an infinite loop. This was addressed in epan/dissectors/packet-dcm.c by validating a length value.NETWORK
CVE-2017-93482017-06-02 05:29:00MEDIUM (5)In Wireshark 2.2.0 to 2.2.6, the DOF dissector could read past the end of a buffer. This was addressed in epan/dissectors/packet-dof.c by validating a size value.NETWORK
CVE-2017-93472017-06-02 05:29:00MEDIUM (5)In Wireshark 2.2.0 to 2.2.6, the ROS dissector could crash with a NULL pointer dereference. This was addressed in epan/dissectors/asn1/ros/packet-ros-template.c by validating an OID.NETWORK
CVE-2017-93462017-06-02 05:29:00HIGH (8)In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the SoulSeek dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-slsk.c by making loop bounds more explicit.NETWORK
CVE-2017-93452017-06-02 05:29:00HIGH (8)In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DNS dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-dns.c by trying to detect self-referencing pointers.NETWORK
CVE-2017-93442017-06-02 05:29:00MEDIUM (5)In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the Bluetooth L2CAP dissector could divide by zero. This was addressed in epan/dissectors/packet-btl2cap.c by validating an interval value.NETWORK
CVE-2017-93432017-06-02 05:29:00MEDIUM (5)In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the MSNIP dissector misuses a NULL pointer. This was addressed in epan/dissectors/packet-msnip.c by validating an IPv4 address.NETWORK
CVE-2017-77482017-04-12 23:59:00HIGH (8)In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the WSP dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-wsp.c by adding a length check.NETWORK
CVE-2017-77472017-04-12 23:59:00MEDIUM (5)In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the PacketBB dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-packetbb.c by restricting additions to the protocol tree.NETWORK
CVE-2017-77462017-04-12 23:59:00MEDIUM (5)In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the SLSK dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-slsk.c by adding checks for the remaining length.NETWORK
CVE-2017-77452017-04-12 23:59:00HIGH (8)In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the SIGCOMP dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-sigcomp.c by correcting a memory-size check.NETWORK
CVE-2017-77052017-04-12 23:59:00HIGH (8)In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the RPC over RDMA dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-rpcrdma.c by correctly checking for going beyond the maximum offset.NETWORK
CVE-2017-77042017-04-12 23:59:00HIGH (8)In Wireshark 2.2.0 to 2.2.5, the DOF dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-dof.c by using a different integer data type and adjusting a return value.NETWORK
CVE-2017-77032017-04-12 23:59:00MEDIUM (5)In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the IMAP dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-imap.c by calculating a line's end correctly.NETWORK
CVE-2017-77022017-04-12 23:59:00HIGH (8)In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the WBXML dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-wbxml.c by adding length validation.NETWORK
CVE-2017-77012017-04-12 23:59:00HIGH (8)In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the BGP dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-bgp.c by using a different integer data type.NETWORK
CVE-2017-77002017-04-12 23:59:00HIGH (7)In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the NetScaler file parser could go into an infinite loop, triggered by a malformed capture file. This was addressed in wiretap/netscaler.c by ensuring a nonzero record size.NETWORK
CVE-2017-64742017-03-04 03:59:00MEDIUM (5)In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a NetScaler file parser infinite loop, triggered by a malformed capture file. This was addressed in wiretap/netscaler.c by validating record sizes.NETWORK
CVE-2017-64732017-03-04 03:59:00MEDIUM (5)In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a K12 file parser crash, triggered by a malformed capture file. This was addressed in wiretap/k12.c by validating the relationships between lengths and offsets.NETWORK
CVE-2017-64722017-03-04 03:59:00MEDIUM (5)In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an RTMPT dissector infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-rtmpt.c by properly incrementing a certain sequence value.NETWORK
CVE-2017-64712017-03-04 03:59:00MEDIUM (5)In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a WSP infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-wsp.c by validating the capability length.NETWORK
CVE-2017-64702017-03-04 03:59:00HIGH (8)In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an IAX2 infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-iax2.c by constraining packet lateness.NETWORK
CVE-2017-64692017-03-04 03:59:00MEDIUM (5)In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an LDSS dissector crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-ldss.c by ensuring that memory is allocated for a certain data structure.NETWORK
CVE-2017-64682017-03-04 03:59:00MEDIUM (5)In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a NetScaler file parser crash, triggered by a malformed capture file. This was addressed in wiretap/netscaler.c by validating the relationship between pages and records.NETWORK
CVE-2017-64672017-03-04 03:59:00MEDIUM (5)In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a Netscaler file parser infinite loop, triggered by a malformed capture file. This was addressed in wiretap/netscaler.c by changing the restrictions on file size.NETWORK
CVE-2017-60142017-02-17 07:59:01HIGH (8)In Wireshark 2.2.4 and earlier, a crafted or malformed STANAG 4607 capture file will cause an infinite loop and memory exhaustion. If the packet size field in a packet header is null, the offset to read from will not advance, causing continuous attempts to read the same zero length packet. This will quickly exhaust all system memory.NETWORK
CVE-2017-55972017-01-25 21:59:00MEDIUM (5)In Wireshark 2.2.0 to 2.2.3 and 2.0.0 to 2.0.9, the DHCPv6 dissector could go into a large loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-dhcpv6.c by changing a data type to avoid an integer overflow.NETWORK
CVE-2017-55962017-01-25 21:59:00MEDIUM (5)In Wireshark 2.2.0 to 2.2.3 and 2.0.0 to 2.0.9, the ASTERIX dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-asterix.c by changing a data type to avoid an integer overflow.NETWORK
CVE-2017-179972017-12-30 07:29:01MEDIUM (5)In Wireshark before 2.2.12, the MRDISC dissector misuses a NULL pointer and crashes. This was addressed in epan/dissectors/packet-mrdisc.c by validating an IPv4 address. This vulnerability is similar to CVE-2017-9343.NETWORK
CVE-2017-179352017-12-27 17:08:23MEDIUM (5)The File_read_line function in epan/wslua/wslua_file.c in Wireshark through 2.2.11 does not properly strip '\n' characters, which allows remote attackers to cause a denial of service (buffer underflow and application crash) via a crafted packet that triggers the attempted processing of an empty line.NETWORK
CVE-2017-170852017-12-01 08:29:01MEDIUM (5)In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the CIP Safety dissector could crash. This was addressed in epan/dissectors/packet-cipsafety.c by validating the packet length.NETWORK
CVE-2017-170842017-12-01 08:29:01MEDIUM (5)In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the IWARP_MPA dissector could crash. This was addressed in epan/dissectors/packet-iwarp-mpa.c by validating a ULPDU length.NETWORK
CVE-2017-170832017-12-01 08:29:00MEDIUM (5)In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the NetBIOS dissector could crash. This was addressed in epan/dissectors/packet-netbios.c by ensuring that write operations are bounded by the beginning of a buffer.NETWORK
CVE-2017-151932017-10-10 21:29:00HIGH (8)In Wireshark 2.4.0 to 2.4.1 and 2.2.0 to 2.2.9, the MBIM dissector could crash or exhaust system memory. This was addressed in epan/dissectors/packet-mbim.c by changing the memory-allocation approach.NETWORK
CVE-2017-151922017-10-10 21:29:00MEDIUM (5)In Wireshark 2.4.0 to 2.4.1 and 2.2.0 to 2.2.9, the BT ATT dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by considering a case where not all of the BTATT packets have the same encapsulation level.NETWORK
CVE-2017-151912017-10-10 21:29:00MEDIUM (5)In Wireshark 2.4.0 to 2.4.1, 2.2.0 to 2.2.9, and 2.0.0 to 2.0.15, the DMP dissector could crash. This was addressed in epan/dissectors/packet-dmp.c by validating a string length.NETWORK
CVE-2017-151902017-10-10 21:29:00MEDIUM (5)In Wireshark 2.4.0 to 2.4.1, the RTSP dissector could crash. This was addressed in epan/dissectors/packet-rtsp.c by correcting the scope of a variable.NETWORK
CVE-2017-151892017-10-10 21:29:00MEDIUM (5)In Wireshark 2.4.0 to 2.4.1, the DOCSIS dissector could go into an infinite loop. This was addressed in plugins/docsis/packet-docsis.c by adding decrements.NETWORK
CVE-2017-137672017-08-30 09:29:01HIGH (8)In Wireshark 2.4.0, 2.2.0 to 2.2.8, and 2.0.0 to 2.0.14, the MSDP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-msdp.c by adding length validation.NETWORK
CVE-2017-137662017-08-30 09:29:00MEDIUM (5)In Wireshark 2.4.0 and 2.2.0 to 2.2.8, the Profinet I/O dissector could crash with an out-of-bounds write. This was addressed in plugins/profinet/packet-dcerpc-pn-io.c by adding string validation.NETWORK
CVE-2017-137652017-08-30 09:29:00MEDIUM (5)In Wireshark 2.4.0, 2.2.0 to 2.2.8, and 2.0.0 to 2.0.14, the IrCOMM dissector has a buffer over-read and application crash. This was addressed in plugins/irda/packet-ircomm.c by adding length validation.NETWORK
CVE-2017-137642017-08-30 09:29:00MEDIUM (5)In Wireshark 2.4.0, the Modbus dissector could crash with a NULL pointer dereference. This was addressed in epan/dissectors/packet-mbtcp.c by adding length validation.NETWORK
CVE-2017-114112017-07-18 21:29:00HIGH (8)In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the openSAFETY dissector could crash or exhaust system memory. This was addressed in epan/dissectors/packet-opensafety.c by adding length validation. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-9350.NETWORK
CVE-2017-114102017-07-18 21:29:00HIGH (8)In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the WBXML dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-wbxml.c by adding validation of the relationships between indexes and lengths. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-7702.NETWORK
CVE-2017-114092017-07-18 21:29:00HIGH (8)In Wireshark 2.0.0 to 2.0.13, the GPRS LLC dissector could go into a large loop. This was addressed in epan/dissectors/packet-gprs-llc.c by using a different integer data type.NETWORK
CVE-2017-114082017-07-18 21:29:00MEDIUM (5)In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the AMQP dissector could crash. This was addressed in epan/dissectors/packet-amqp.c by checking for successful list dissection.NETWORK
CVE-2017-114072017-07-18 21:29:00MEDIUM (5)In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the MQ dissector could crash. This was addressed in epan/dissectors/packet-mq.c by validating the fragment length before a reassembly attempt.NETWORK
CVE-2017-114062017-07-18 21:29:00HIGH (8)In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the DOCSIS dissector could go into an infinite loop. This was addressed in plugins/docsis/packet-docsis.c by rejecting invalid Frame Control parameter values.NETWORK
CVE-2016-93762016-11-17 05:59:05MEDIUM (4)In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the OpenFlow dissector could crash with memory exhaustion, triggered by network traffic or a capture file. This was addressed in epan/dissectors/packet-openflow_v5.c by ensuring that certain length values were sufficiently large.NETWORK
CVE-2016-93752016-11-17 05:59:04MEDIUM (4)In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the DTN dissector could go into an infinite loop, triggered by network traffic or a capture file. This was addressed in epan/dissectors/packet-dtn.c by checking whether SDNV evaluation was successful.NETWORK
CVE-2016-93742016-11-17 05:59:03MEDIUM (4)In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the AllJoyn dissector could crash with a buffer over-read, triggered by network traffic or a capture file. This was addressed in epan/dissectors/packet-alljoyn.c by ensuring that a length variable properly tracked the state of a signature variable.NETWORK
CVE-2016-93732016-11-17 05:59:02MEDIUM (4)In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the DCERPC dissector could crash with a use-after-free, triggered by network traffic or a capture file. This was addressed in epan/dissectors/packet-dcerpc-nt.c and epan/dissectors/packet-dcerpc-spoolss.c by using the wmem file scope for private strings.NETWORK
CVE-2016-93722016-11-17 05:59:00MEDIUM (4)In Wireshark 2.2.0 to 2.2.1, the Profinet I/O dissector could loop excessively, triggered by network traffic or a capture file. This was addressed in plugins/profinet/packet-pn-rtc-one.c by rejecting input with too many I/O objects.NETWORK
CVE-2016-79582017-04-12 10:59:00MEDIUM (5)In Wireshark 2.2.0, the NCP dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/CMakeLists.txt by registering this dissector.NETWORK
CVE-2016-79572017-04-12 10:59:00MEDIUM (5)In Wireshark 2.2.0, the Bluetooth L2CAP dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-btl2cap.c by avoiding use of a seven-byte memcmp for potentially shorter strings.NETWORK
CVE-2016-71802016-09-09 10:59:06MEDIUM (4)epan/dissectors/packet-ipmi-trace.c in the IPMI trace dissector in Wireshark 2.x before 2.0.6 does not properly consider whether a string is constant, which allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted packet.NETWORK
CVE-2016-71792016-09-09 10:59:05MEDIUM (4)Stack-based buffer overflow in epan/dissectors/packet-catapult-dct2000.c in the Catapult DCT2000 dissector in Wireshark 2.x before 2.0.6 allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2016-71782016-09-09 10:59:04MEDIUM (4)epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 2.x before 2.0.6 does not ensure that memory is allocated for certain data structures, which allows remote attackers to cause a denial of service (invalid write access and application crash) via a crafted packet.NETWORK
CVE-2016-71772016-09-09 10:59:03MEDIUM (4)epan/dissectors/packet-catapult-dct2000.c in the Catapult DCT2000 dissector in Wireshark 2.x before 2.0.6 does not restrict the number of channels, which allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet.NETWORK
CVE-2016-71762016-09-09 10:59:02MEDIUM (4)epan/dissectors/packet-h225.c in the H.225 dissector in Wireshark 2.x before 2.0.6 calls snprintf with one of its input buffers as the output buffer, which allows remote attackers to cause a denial of service (copy overlap and application crash) via a crafted packet.NETWORK
CVE-2016-71752016-09-09 10:59:00MEDIUM (4)epan/dissectors/packet-qnet6.c in the QNX6 QNET dissector in Wireshark 2.x before 2.0.6 mishandles MAC address data, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet.NETWORK
CVE-2016-65132016-08-06 23:59:14MEDIUM (4)epan/dissectors/packet-wbxml.c in the WBXML dissector in Wireshark 2.x before 2.0.5 does not restrict the recursion depth, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2016-65122016-08-06 23:59:12MEDIUM (4)epan/dissectors/packet-wap.c in Wireshark 2.x before 2.0.5 omits an overflow check in the tvb_get_guintvar function, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet, related to the MMSE, WAP, WBXML, and WSP dissectors.NETWORK
CVE-2016-65112016-08-06 23:59:11MEDIUM (4)epan/proto.c in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause a denial of service (OpenFlow dissector large loop) via a crafted packet.NETWORK
CVE-2016-65102016-08-06 23:59:09MEDIUM (4)Off-by-one error in epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted packet.NETWORK
CVE-2016-65092016-08-06 23:59:08MEDIUM (4)epan/dissectors/packet-ldss.c in the LDSS dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 mishandles conversations, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2016-65082016-08-06 23:59:07MEDIUM (4)epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (large loop) via a crafted packet.NETWORK
CVE-2016-65072016-08-06 23:59:05MEDIUM (4)epan/dissectors/packet-mmse.c in the MMSE dissector in Wireshark 1.12.x before 1.12.13 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.NETWORK
CVE-2016-65062016-08-06 23:59:04MEDIUM (4)epan/dissectors/packet-wsp.c in the WSP dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.NETWORK
CVE-2016-65052016-08-06 23:59:03MEDIUM (4)epan/dissectors/packet-packetbb.c in the PacketBB dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted packet.NETWORK
CVE-2016-65042016-08-06 23:59:01MEDIUM (4)epan/dissectors/packet-ncp2222.inc in the NDS dissector in Wireshark 1.12.x before 1.12.13 does not properly maintain a ptvc data structure, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted packet.NETWORK
CVE-2016-65032016-08-06 23:59:00MEDIUM (4)The CORBA IDL dissectors in Wireshark 2.x before 2.0.5 on 64-bit Windows platforms do not properly interact with Visual C++ compiler options, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2016-53592016-08-07 16:59:15MEDIUM (4)epan/dissectors/packet-wbxml.c in the WBXML dissector in Wireshark 1.12.x before 1.12.12 mishandles offsets, which allows remote attackers to cause a denial of service (integer overflow and infinite loop) via a crafted packet.NETWORK
CVE-2016-53582016-08-07 16:59:13MEDIUM (4)epan/dissectors/packet-pktap.c in the Ethernet dissector in Wireshark 2.x before 2.0.4 mishandles the packet-header data type, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2016-53572016-08-07 16:59:12MEDIUM (4)wiretap/netscreen.c in the NetScreen file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, which allows remote attackers to cause a denial of service (application crash) via a crafted file.NETWORK
CVE-2016-53562016-08-07 16:59:11MEDIUM (4)wiretap/cosine.c in the CoSine file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, which allows remote attackers to cause a denial of service (application crash) via a crafted file.NETWORK
CVE-2016-53552016-08-07 16:59:10MEDIUM (4)wiretap/toshiba.c in the Toshiba file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, which allows remote attackers to cause a denial of service (application crash) via a crafted file.NETWORK
CVE-2016-53542016-08-07 16:59:08MEDIUM (4)The USB subsystem in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles class types, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2016-53532016-08-07 16:59:06MEDIUM (4)epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles the reserved C/T value, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2016-53522016-08-07 16:59:05MEDIUM (4)epan/crypt/airpdcap.c in the IEEE 802.11 dissector in Wireshark 2.x before 2.0.4 mishandles certain length values, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2016-53512016-08-07 16:59:03MEDIUM (4)epan/crypt/airpdcap.c in the IEEE 802.11 dissector in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles the lack of an EAPOL_RSN_KEY, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2016-53502016-08-07 16:59:02MEDIUM (4)epan/dissectors/packet-dcerpc-spoolss.c in the SPOOLS component in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles unexpected offsets, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.NETWORK
CVE-2016-44212016-05-01 01:59:08MEDIUM (4)epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.12.x before 1.12.10 and 2.x before 2.0.2 allows remote attackers to cause a denial of service (deep recursion, stack consumption, and application crash) via a packet that specifies deeply nested data.NETWORK
CVE-2016-44202016-05-01 01:59:07MEDIUM (4)The NFS dissector in Wireshark 2.x before 2.0.2 allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2016-44192016-05-01 01:59:06MEDIUM (4)epan/dissectors/packet-spice.c in the SPICE dissector in Wireshark 2.x before 2.0.2 mishandles capability data, which allows remote attackers to cause a denial of service (large loop) via a crafted packet.NETWORK
CVE-2016-44182016-05-01 01:59:05MEDIUM (4)epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.12.x before 1.12.10 and 2.x before 2.0.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet that triggers an empty set.NETWORK
CVE-2016-44172016-05-01 01:59:04MEDIUM (4)Off-by-one error in epan/dissectors/packet-gsm_abis_oml.c in the GSM A-bis OML dissector in Wireshark 1.12.x before 1.12.10 and 2.x before 2.0.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet that triggers a 0xff tag value.NETWORK
CVE-2016-44162016-05-01 01:59:02MEDIUM (4)epan/dissectors/packet-ieee80211.c in the IEEE 802.11 dissector in Wireshark 2.x before 2.0.2 mishandles the Grouping subfield, which allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet.NETWORK
CVE-2016-44152016-05-01 01:59:01MEDIUM (4)wiretap/vwr.c in the Ixia IxVeriWave file parser in Wireshark 2.x before 2.0.2 incorrectly increases a certain octet count, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a crafted file.NETWORK
CVE-2016-40852016-04-25 10:59:10MEDIUM (4)Stack-based buffer overflow in epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 1.12.x before 1.12.11 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long string in a packet.NETWORK
CVE-2016-40842016-04-25 10:59:09MEDIUM (4)Integer signedness error in epan/dissectors/packet-mswsp.c in the MS-WSP dissector in Wireshark 2.0.x before 2.0.3 allows remote attackers to cause a denial of service (integer overflow and application crash) via a crafted packet that triggers an unexpected array size.NETWORK
CVE-2016-40832016-04-25 10:59:08MEDIUM (4)epan/dissectors/packet-mswsp.c in the MS-WSP dissector in Wireshark 2.0.x before 2.0.3 does not ensure that data is available before array allocation, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2016-40822016-04-25 10:59:07MEDIUM (4)epan/dissectors/packet-gsm_cbch.c in the GSM CBCH dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 uses the wrong variable to index an array, which allows remote attackers to cause a denial of service (out-of-bounds access and application crash) via a crafted packet.NETWORK
CVE-2016-40812016-04-25 10:59:06MEDIUM (4)epan/dissectors/packet-iax2.c in the IAX2 dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.NETWORK
CVE-2016-40802016-04-25 10:59:05MEDIUM (4)epan/dissectors/packet-pktc.c in the PKTC dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 misparses timestamp fields, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet.NETWORK
CVE-2016-40792016-04-25 10:59:04MEDIUM (4)epan/dissectors/packet-pktc.c in the PKTC dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 does not verify BER identifiers, which allows remote attackers to cause a denial of service (out-of-bounds write and application crash) via a crafted packet.NETWORK
CVE-2016-40782016-04-25 10:59:03MEDIUM (4)The IEEE 802.11 dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 does not properly restrict element lists, which allows remote attackers to cause a denial of service (deep recursion and application crash) via a crafted packet, related to epan/dissectors/packet-capwap.c and epan/dissectors/packet-ieee80211.c.NETWORK
CVE-2016-40772016-04-25 10:59:02MEDIUM (4)epan/reassemble.c in TShark in Wireshark 2.0.x before 2.0.3 relies on incorrect special-case handling of truncated Tvb data structures, which allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted packet.NETWORK
CVE-2016-40762016-04-25 10:59:01MEDIUM (4)epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 2.0.x before 2.0.3 does not properly initialize memory for search patterns, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2016-40062016-04-25 10:59:00MEDIUM (4)epan/proto.c in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 does not limit the protocol-tree depth, which allows remote attackers to cause a denial of service (stack memory consumption and application crash) via a crafted packet.NETWORK
CVE-2016-25322016-02-28 04:59:11MEDIUM (4)The dissect_llrp_parameters function in epan/dissectors/packet-llrp.c in the LLRP dissector in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 does not limit the recursion depth, which allows remote attackers to cause a denial of service (memory consumption or application crash) via a crafted packet.NETWORK
CVE-2016-25312016-02-28 04:59:10MEDIUM (4)Off-by-one error in epan/dissectors/packet-rsl.c in the RSL dissector in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet that triggers a 0xff tag value, a different vulnerability than CVE-2016-2530.NETWORK
CVE-2016-25302016-02-28 04:59:09MEDIUM (4)The dissct_rsl_ipaccess_msg function in epan/dissectors/packet-rsl.c in the RSL dissector in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 mishandles the case of an unrecognized TLV type, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet, a different vulnerability than CVE-2016-2531.NETWORK
CVE-2016-25292016-02-28 04:59:08MEDIUM (4)The iseries_check_file_type function in wiretap/iseries.c in the iSeries file parser in Wireshark 2.0.x before 2.0.2 does not consider that a line may lack the "OBJECT PROTOCOL" substring, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file.NETWORK
CVE-2016-25282016-02-28 04:59:07MEDIUM (4)The dissect_nhdr_extopt function in epan/dissectors/packet-lbmc.c in the LBMC dissector in Wireshark 2.0.x before 2.0.2 does not validate length values, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted packet.NETWORK
CVE-2016-25272016-02-28 04:59:06MEDIUM (4)wiretap/nettrace_3gpp_32_423.c in the 3GPP TS 32.423 Trace file parser in Wireshark 2.0.x before 2.0.2 does not ensure that a '\0' character is present at the end of certain strings, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted file.NETWORK
CVE-2016-25262016-02-28 04:59:05MEDIUM (4)epan/dissectors/packet-hiqnet.c in the HiQnet dissector in Wireshark 2.0.x before 2.0.2 does not validate the data type, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet.NETWORK
CVE-2016-25252016-02-28 04:59:04MEDIUM (4)epan/dissectors/packet-http2.c in the HTTP/2 dissector in Wireshark 2.0.x before 2.0.2 does not limit the amount of header data, which allows remote attackers to cause a denial of service (memory consumption or application crash) via a crafted packet.NETWORK
CVE-2016-25242016-02-28 04:59:03MEDIUM (4)epan/dissectors/packet-x509af.c in the X.509AF dissector in Wireshark 2.0.x before 2.0.2 mishandles the algorithm ID, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2016-25232016-02-28 04:59:02HIGH (7)The dnp3_al_process_object function in epan/dissectors/packet-dnp.c in the DNP3 dissector in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.NETWORK
CVE-2016-25222016-02-28 04:59:01MEDIUM (4)The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 2.0.x before 2.0.2 does not verify that a certain length is nonzero, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet.NETWORK
CVE-2016-25212016-02-28 04:59:00HIGH (7)Untrusted search path vulnerability in the WiresharkApplication class in ui/qt/wireshark_application.cpp in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 on Windows allows local users to gain privileges via a Trojan horse riched20.dll.dll file in the current working directory, related to use of QLibrary.LOCAL
CVE-2015-87422016-01-04 05:59:33MEDIUM (4)The dissect_CPMSetBindings function in epan/dissectors/packet-mswsp.c in the MS-WSP dissector in Wireshark 2.0.x before 2.0.1 does not validate the column size, which allows remote attackers to cause a denial of service (memory consumption or application crash) via a crafted packet.NETWORK
CVE-2015-87412016-01-04 05:59:32MEDIUM (4)The dissect_ppi function in epan/dissectors/packet-ppi.c in the PPI dissector in Wireshark 2.0.x before 2.0.1 does not initialize a packet-header data structure, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2015-87402016-01-04 05:59:31MEDIUM (4)The dissect_tds7_colmetadata_token function in epan/dissectors/packet-tds.c in the TDS dissector in Wireshark 2.0.x before 2.0.1 does not validate the number of columns, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted packet.NETWORK
CVE-2015-87392016-01-04 05:59:30MEDIUM (4)The ipmi_fmt_udpport function in epan/dissectors/packet-ipmi.c in the IPMI dissector in Wireshark 2.0.x before 2.0.1 improperly attempts to access a packet scope, which allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted packet.NETWORK
CVE-2015-87382016-01-04 05:59:29MEDIUM (4)The s7comm_decode_ud_cpu_szl_subfunc function in epan/dissectors/packet-s7comm_szl_ids.c in the S7COMM dissector in Wireshark 2.0.x before 2.0.1 does not validate the list count in an SZL response, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted packet.NETWORK
CVE-2015-87372016-01-04 05:59:28MEDIUM (4)The mp2t_open function in wiretap/mp2t.c in the MP2T file parser in Wireshark 2.0.x before 2.0.1 does not validate the bit rate, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted file.NETWORK
CVE-2015-87362016-01-04 05:59:27MEDIUM (4)The mp2t_find_next_pcr function in wiretap/mp2t.c in the MP2T file parser in Wireshark 2.0.x before 2.0.1 does not reserve memory for a trailer, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted file.NETWORK
CVE-2015-87352016-01-04 05:59:26MEDIUM (4)The get_value function in epan/dissectors/packet-btatt.c in the Bluetooth Attribute (aka BT ATT) dissector in Wireshark 2.0.x before 2.0.1 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (invalid write operation and application crash) via a crafted packet.NETWORK
CVE-2015-87342016-01-04 05:59:25MEDIUM (4)The dissect_nwp function in epan/dissectors/packet-nwp.c in the NWP dissector in Wireshark 2.0.x before 2.0.1 mishandles the packet type, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2015-87332016-01-04 05:59:24MEDIUM (4)The ngsniffer_process_record function in wiretap/ngsniffer.c in the Sniffer file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the relationships between record lengths and record header lengths, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file.NETWORK
CVE-2015-87322016-01-04 05:59:23MEDIUM (4)The dissect_zcl_pwr_prof_pwrprofstatersp function in epan/dissectors/packet-zbee-zcl-general.c in the ZigBee ZCL dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the Total Profile Number field, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet.NETWORK
CVE-2015-87312016-01-04 05:59:22MEDIUM (4)The dissct_rsl_ipaccess_msg function in epan/dissectors/packet-rsl.c in the RSL dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not reject unknown TLV types, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet.NETWORK
CVE-2015-87302016-01-04 05:59:21MEDIUM (4)epan/dissectors/packet-nbap.c in the NBAP dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the number of items, which allows remote attackers to cause a denial of service (invalid read operation and application crash) via a crafted packet.NETWORK
CVE-2015-87292016-01-04 05:59:20MEDIUM (4)The ascend_seek function in wiretap/ascendtext.c in the Ascend file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not ensure the presence of a '\0' character at the end of a date string, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file.NETWORK
CVE-2015-87282016-01-04 05:59:19MEDIUM (4)The Mobile Identity parser in (1) epan/dissectors/packet-ansi_a.c in the ANSI A dissector and (2) epan/dissectors/packet-gsm_a_common.c in the GSM A dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 improperly uses the tvb_bcd_dig_to_wmem_packet_str function, which allows remote attackers to cause a denial of service (buffer overflow and application crash) via a crafted packet.NETWORK
CVE-2015-87272016-01-04 05:59:18MEDIUM (4)The dissect_rsvp_common function in epan/dissectors/packet-rsvp.c in the RSVP dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not properly maintain request-key data, which allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted packet.NETWORK
CVE-2015-87262016-01-04 05:59:17MEDIUM (4)wiretap/vwr.c in the VeriWave file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate certain signature and Modulation and Coding Scheme (MCS) data, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file.NETWORK
CVE-2015-87252016-01-04 05:59:16MEDIUM (4)The dissect_diameter_base_framed_ipv6_prefix function in epan/dissectors/packet-diameter.c in the DIAMETER dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the IPv6 prefix length, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted packet.NETWORK
CVE-2015-87242016-01-04 05:59:15MEDIUM (4)The AirPDcapDecryptWPABroadcastKey function in epan/crypt/airpdcap.c in the 802.11 dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not verify the WPA broadcast key length, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet.NETWORK
CVE-2015-87232016-01-04 05:59:14MEDIUM (4)The AirPDcapPacketProcess function in epan/crypt/airpdcap.c in the 802.11 dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the relationship between the total length and the capture length, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted packet.NETWORK
CVE-2015-87222016-01-04 05:59:13MEDIUM (4)epan/dissectors/packet-sctp.c in the SCTP dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the frame pointer, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted packet.NETWORK
CVE-2015-87212016-01-04 05:59:12MEDIUM (4)Buffer overflow in the tvb_uncompress function in epan/tvbuff_zlib.c in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 allows remote attackers to cause a denial of service (application crash) via a crafted packet with zlib compression.NETWORK
CVE-2015-87202016-01-04 05:59:11MEDIUM (4)The dissect_ber_GeneralizedTime function in epan/dissectors/packet-ber.c in the BER dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 improperly checks an sscanf return value, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2015-87192016-01-04 05:59:10MEDIUM (4)The dissect_dns_answer function in epan/dissectors/packet-dns.c in the DNS dissector in Wireshark 1.12.x before 1.12.9 mishandles the EDNS0 Client Subnet option, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2015-87182016-01-04 05:59:09MEDIUM (4)Double free vulnerability in epan/dissectors/packet-nlm.c in the NLM dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1, when the "Match MSG/RES packets for async NLM" option is enabled, allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2015-87172016-01-04 05:59:07MEDIUM (4)The dissect_sdp function in epan/dissectors/packet-sdp.c in the SDP dissector in Wireshark 1.12.x before 1.12.9 does not prevent use of a negative media count, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2015-87162016-01-04 05:59:06MEDIUM (4)The init_t38_info_conv function in epan/dissectors/packet-t38.c in the T.38 dissector in Wireshark 1.12.x before 1.12.9 does not ensure that a conversation exists, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2015-87152016-01-04 05:59:05MEDIUM (4)epan/dissectors/packet-alljoyn.c in the AllJoyn dissector in Wireshark 1.12.x before 1.12.9 does not check for empty arguments, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.NETWORK
CVE-2015-87142016-01-04 05:59:04MEDIUM (4)The dissect_dcom_OBJREF function in epan/dissectors/packet-dcom.c in the DCOM dissector in Wireshark 1.12.x before 1.12.9 does not initialize a certain IPv4 data structure, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2015-87132016-01-04 05:59:04MEDIUM (4)epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 1.12.x before 1.12.9 does not properly reserve memory for channel ID mappings, which allows remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted packet.NETWORK
CVE-2015-87122016-01-04 05:59:03MEDIUM (4)The dissect_hsdsch_channel_info function in epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 1.12.x before 1.12.9 does not validate the number of PDUs, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2015-87112016-01-04 05:59:01MEDIUM (4)epan/dissectors/packet-nbap.c in the NBAP dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate conversation data, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted packet.NETWORK
CVE-2015-78302015-11-15 03:59:02MEDIUM (4)The pcapng_read_if_descr_block function in wiretap/pcapng.c in the pcapng parser in Wireshark 1.12.x before 1.12.8 uses too many levels of pointer indirection, which allows remote attackers to cause a denial of service (incorrect free and application crash) via a crafted packet that triggers interface-filter copying.NETWORK
CVE-2015-62492015-08-24 23:59:10MEDIUM (4)The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.12.x before 1.12.7 does not prevent the conflicting use of a table for both IPv4 and IPv6 addresses, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2015-62482015-08-24 23:59:08MEDIUM (4)The ptvcursor_add function in the ptvcursor implementation in epan/proto.c in Wireshark 1.12.x before 1.12.7 does not check whether the expected amount of data is available, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2015-62472015-08-24 23:59:07MEDIUM (4)The dissect_openflow_tablemod_v5 function in epan/dissectors/packet-openflow_v5.c in the OpenFlow dissector in Wireshark 1.12.x before 1.12.7 does not validate a certain offset value, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.NETWORK
CVE-2015-62462015-08-24 23:59:06MEDIUM (4)The dissect_wa_payload function in epan/dissectors/packet-waveagent.c in the WaveAgent dissector in Wireshark 1.12.x before 1.12.7 mishandles large tag values, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2015-62452015-08-24 23:59:05MEDIUM (4)epan/dissectors/packet-gsm_rlcmac.c in the GSM RLC/MAC dissector in Wireshark 1.12.x before 1.12.7 uses incorrect integer data types, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.NETWORK
CVE-2015-62442015-08-24 23:59:04MEDIUM (4)The dissect_zbee_secure function in epan/dissectors/packet-zbee-security.c in the ZigBee dissector in Wireshark 1.12.x before 1.12.7 improperly relies on length fields contained in packet data, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2015-62432015-08-24 23:59:03MEDIUM (4)The dissector-table implementation in epan/packet.c in Wireshark 1.12.x before 1.12.7 mishandles table searches for empty strings, which allows remote attackers to cause a denial of service (application crash) via a crafted packet, related to the (1) dissector_get_string_handle and (2) dissector_get_default_string_handle functions.NETWORK
CVE-2015-62422015-08-24 23:59:02MEDIUM (4)The wmem_block_split_free_chunk function in epan/wmem/wmem_allocator_block.c in the wmem block allocator in the memory manager in Wireshark 1.12.x before 1.12.7 does not properly consider a certain case of multiple realloc operations that restore a memory chunk to its original size, which allows remote attackers to cause a denial of service (incorrect free operation and application crash) via a crafted packet.NETWORK
CVE-2015-62412015-08-24 23:59:00MEDIUM (4)The proto_tree_add_bytes_item function in epan/proto.c in the protocol-tree implementation in Wireshark 1.12.x before 1.12.7 does not properly terminate a data structure after a failure to locate a number within a string, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2015-46522015-07-22 01:59:05MEDIUM (4)epan/dissectors/packet-gsm_a_dtap.c in the GSM DTAP dissector in Wireshark 1.12.x before 1.12.6 does not properly validate digit characters, which allows remote attackers to cause a denial of service (application crash) via a crafted packet, related to the de_emerg_num_list and de_bcd_num functions.NETWORK
CVE-2015-46512015-07-22 01:59:03MEDIUM (5)The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.12.x before 1.12.6 does not properly determine whether enough memory is available for storing IP address strings, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2015-39062015-05-26 15:59:12MEDIUM (5)The logcat_dump_text function in wiretap/logcat.c in the Android Logcat file parser in Wireshark 1.12.x before 1.12.5 does not properly handle a lack of \0 termination, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted message in a packet, a different vulnerability than CVE-2015-3815.NETWORK
CVE-2015-38152015-05-26 15:59:09MEDIUM (5)The detect_version function in wiretap/logcat.c in the Android Logcat file parser in Wireshark 1.12.x before 1.12.5 does not check the length of the payload, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a packet with a crafted payload, as demonstrated by a length of zero, a different vulnerability than CVE-2015-3906.NETWORK
CVE-2015-38142015-05-26 15:59:08MEDIUM (5)The (1) dissect_tfs_request and (2) dissect_tfs_response functions in epan/dissectors/packet-ieee80211.c in the IEEE 802.11 dissector in Wireshark 1.10.x before 1.10.14 and 1.12.x before 1.12.5 interpret a zero value as a length rather than an error condition, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.NETWORK
CVE-2015-38132015-05-26 15:59:07MEDIUM (5)The fragment_add_work function in epan/reassemble.c in the packet-reassembly feature in Wireshark 1.12.x before 1.12.5 does not properly determine the defragmentation state in a case of an insufficient snapshot length, which allows remote attackers to cause a denial of service (memory consumption) via a crafted packet.NETWORK
CVE-2015-38122015-05-26 15:59:06HIGH (8)Multiple memory leaks in the x11_init_protocol function in epan/dissectors/packet-x11.c in the X11 dissector in Wireshark 1.10.x before 1.10.14 and 1.12.x before 1.12.5 allow remote attackers to cause a denial of service (memory consumption) via a crafted packet.NETWORK
CVE-2015-38112015-05-26 15:59:05MEDIUM (5)epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.14 and 1.12.x before 1.12.5 improperly refers to previously processed bytes, which allows remote attackers to cause a denial of service (application crash) via a crafted packet, a different vulnerability than CVE-2015-2188.NETWORK
CVE-2015-38102015-05-26 15:59:04HIGH (8)epan/dissectors/packet-websocket.c in the WebSocket dissector in Wireshark 1.12.x before 1.12.5 uses a recursive algorithm, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted packet.NETWORK
CVE-2015-38092015-05-26 15:59:03HIGH (8)The dissect_lbmr_pser function in epan/dissectors/packet-lbmr.c in the LBMR dissector in Wireshark 1.12.x before 1.12.5 does not properly track the current offset, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.NETWORK
CVE-2015-38082015-05-26 15:59:02HIGH (8)The dissect_lbmr_pser function in epan/dissectors/packet-lbmr.c in the LBMR dissector in Wireshark 1.12.x before 1.12.5 does not reject a zero length, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.NETWORK
CVE-2015-31822016-01-04 05:59:00MEDIUM (4)epan/dissectors/packet-dec-dnart.c in the DECnet NSP/RT dissector in Wireshark 1.10.12 through 1.10.14 mishandles a certain strdup return value, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2015-21922015-03-08 02:59:07MEDIUM (5)Integer overflow in the dissect_osd2_cdb_continuation function in epan/dissectors/packet-scsi-osd.c in the SCSI OSD dissector in Wireshark 1.12.x before 1.12.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted length field in a packet.NETWORK
CVE-2015-21912015-03-08 02:59:06MEDIUM (5)Integer overflow in the dissect_tnef function in epan/dissectors/packet-tnef.c in the TNEF dissector in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted length field in a packet.NETWORK
CVE-2015-21902015-03-08 02:59:05MEDIUM (5)epan/proto.c in Wireshark 1.12.x before 1.12.4 does not properly handle integer data types greater than 32 bits in size, which allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted packet that is improperly handled by the LLDP dissector.NETWORK
CVE-2015-21892015-03-08 02:59:04MEDIUM (5)Off-by-one error in the pcapng_read function in wiretap/pcapng.c in the pcapng file parser in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via an invalid Interface Statistics Block (ISB) interface ID in a crafted packet.NETWORK
CVE-2015-21882015-03-08 02:59:03MEDIUM (5)epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 does not properly initialize a data structure, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet that is improperly handled during decompression.NETWORK
CVE-2015-21872015-03-08 02:59:02MEDIUM (5)The dissect_atn_cpdlc_heur function in asn1/atn-cpdlc/packet-atn-cpdlc-template.c in the ATN-CPDLC dissector in Wireshark 1.12.x before 1.12.4 does not properly follow the TRY/ENDTRY code requirements, which allows remote attackers to cause a denial of service (stack memory corruption and application crash) via a crafted packet.NETWORK
CVE-2015-05642015-01-10 02:59:42MEDIUM (5)Buffer underflow in the ssl_decrypt_record function in epan/dissectors/packet-ssl-utils.c in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 allows remote attackers to cause a denial of service (application crash) via a crafted packet that is improperly handled during decryption of an SSL session.NETWORK
CVE-2015-05632015-01-10 02:59:42MEDIUM (5)epan/dissectors/packet-smtp.c in the SMTP dissector in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 uses an incorrect length value for certain string-append operations, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2015-05622015-01-10 02:59:41MEDIUM (5)Multiple use-after-free vulnerabilities in epan/dissectors/packet-dec-dnart.c in the DEC DNA Routing Protocol dissector in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 allow remote attackers to cause a denial of service (application crash) via a crafted packet, related to the use of packet-scope memory instead of pinfo-scope memory.NETWORK
CVE-2015-05612015-01-10 02:59:40MEDIUM (5)asn1/lpp/lpp.cnf in the LPP dissector in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 does not validate a certain index value, which allows remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted packet.NETWORK
CVE-2015-05602015-01-10 02:59:39MEDIUM (5)The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 does not initialize certain data structures, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2015-05592015-01-10 02:59:38MEDIUM (5)Multiple use-after-free vulnerabilities in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 allow remote attackers to cause a denial of service (application crash) via a crafted packet, related to the use of packet-scope memory instead of pinfo-scope memory.NETWORK
CVE-2014-87142014-11-23 02:59:06MEDIUM (5)The dissect_write_structured_field function in epan/dissectors/packet-tn5250.c in the TN5250 dissector in Wireshark 1.10.x before 1.10.11 and 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.NETWORK
CVE-2014-87132014-11-23 02:59:05MEDIUM (5)Stack-based buffer overflow in the build_expert_data function in epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 1.10.x before 1.10.11 and 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2014-87122014-11-23 02:59:04MEDIUM (5)The build_expert_data function in epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 1.10.x before 1.10.11 and 1.12.x before 1.12.2 does not properly initialize a data structure, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2014-87112014-11-23 02:59:03MEDIUM (5)Multiple integer overflows in epan/dissectors/packet-amqp.c in the AMQP dissector in Wireshark 1.10.x before 1.10.11 and 1.12.x before 1.12.2 allow remote attackers to cause a denial of service (application crash) via a crafted amqp_0_10 PDU in a packet.NETWORK
CVE-2014-87102014-11-23 02:59:01MEDIUM (5)The decompress_sigcomp_message function in epan/sigcomp-udvm.c in the SigComp UDVM dissector in Wireshark 1.10.x before 1.10.11 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet.NETWORK
CVE-2014-64322014-09-20 10:55:07MEDIUM (5)The SnifferDecompress function in wiretap/ngsniffer.c in the DOS Sniffer file parser in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 does not prevent data overwrites during copy operations, which allows remote attackers to cause a denial of service (application crash) via a crafted file.NETWORK
CVE-2014-64312014-09-20 10:55:07MEDIUM (5)Buffer overflow in the SnifferDecompress function in wiretap/ngsniffer.c in the DOS Sniffer file parser in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 allows remote attackers to cause a denial of service (application crash) via a crafted file that triggers writes of uncompressed bytes beyond the end of the output buffer.NETWORK
CVE-2014-64302014-09-20 10:55:07MEDIUM (5)The SnifferDecompress function in wiretap/ngsniffer.c in the DOS Sniffer file parser in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 does not validate bitmask data, which allows remote attackers to cause a denial of service (application crash) via a crafted file.NETWORK
CVE-2014-64292014-09-20 10:55:07MEDIUM (5)The SnifferDecompress function in wiretap/ngsniffer.c in the DOS Sniffer file parser in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 does not properly handle empty input data, which allows remote attackers to cause a denial of service (application crash) via a crafted file.NETWORK
CVE-2014-64282014-09-20 10:55:06MEDIUM (5)The dissect_spdu function in epan/dissectors/packet-ses.c in the SES dissector in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 does not initialize a certain ID value, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2014-64272014-09-20 10:55:06MEDIUM (5)Off-by-one error in the is_rtsp_request_or_reply function in epan/dissectors/packet-rtsp.c in the RTSP dissector in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 allows remote attackers to cause a denial of service (application crash) via a crafted packet that triggers parsing of a token located one position beyond the current position.NETWORK
CVE-2014-64262014-09-20 10:55:06MEDIUM (5)The dissect_hip_tlv function in epan/dissectors/packet-hip.c in the HIP dissector in Wireshark 1.12.x before 1.12.1 does not properly handle a NULL tree, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.NETWORK
CVE-2014-64252014-09-20 10:55:06MEDIUM (5)The (1) get_quoted_string and (2) get_unquoted_string functions in epan/dissectors/packet-cups.c in the CUPS dissector in Wireshark 1.12.x before 1.12.1 allow remote attackers to cause a denial of service (buffer over-read and application crash) via a CUPS packet that lacks a trailing '\0' character.NETWORK
CVE-2014-64242014-09-20 10:55:06MEDIUM (5)The dissect_v9_v10_pdu_data function in epan/dissectors/packet-netflow.c in the Netflow dissector in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 refers to incorrect offset and start variables, which allows remote attackers to cause a denial of service (uninitialized memory read and application crash) via a crafted packet.NETWORK
CVE-2014-64232014-09-20 10:55:06MEDIUM (5)The tvb_raw_text_add function in epan/dissectors/packet-megaco.c in the MEGACO dissector in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 allows remote attackers to cause a denial of service (infinite loop) via an empty line.NETWORK
CVE-2014-64222014-09-20 10:55:06MEDIUM (5)The SDP dissector in Wireshark 1.10.x before 1.10.10 creates duplicate hashtables for a media channel, which allows remote attackers to cause a denial of service (application crash) via a crafted packet to the RTP dissector.NETWORK
CVE-2014-64212014-09-20 10:55:06MEDIUM (5)Use-after-free vulnerability in the SDP dissector in Wireshark 1.10.x before 1.10.10 allows remote attackers to cause a denial of service (application crash) via a crafted packet that leverages split memory ownership between the SDP and RTP dissectors.NETWORK
CVE-2014-51652014-08-01 11:13:10MEDIUM (5)The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.10.x before 1.10.9 does not properly validate padding values, which allows remote attackers to cause a denial of service (buffer underflow and application crash) via a crafted packet.NETWORK
CVE-2014-51642014-08-01 11:13:10MEDIUM (5)The rlc_decode_li function in epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.10.x before 1.10.9 initializes a certain structure member only after this member is used, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2014-51632014-08-01 11:13:10MEDIUM (5)The APN decode functionality in (1) epan/dissectors/packet-gtp.c and (2) epan/dissectors/packet-gsm_a_gm.c in the GTP and GSM Management dissectors in Wireshark 1.10.x before 1.10.9 does not completely initialize a certain buffer, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2014-51622014-08-01 11:13:10MEDIUM (5)The read_new_line function in wiretap/catapult_dct2000.c in the Catapult DCT2000 dissector in Wireshark 1.10.x before 1.10.9 does not properly strip '\n' and '\r' characters, which allows remote attackers to cause a denial of service (off-by-one buffer underflow and application crash) via a crafted packet.NETWORK
CVE-2014-51612014-08-01 11:13:10MEDIUM (5)The dissect_log function in plugins/irda/packet-irda.c in the IrDA dissector in Wireshark 1.10.x before 1.10.9 does not properly strip '\n' characters, which allows remote attackers to cause a denial of service (buffer underflow and application crash) via a crafted packet.NETWORK
CVE-2014-41742014-06-18 16:55:08HIGH (9)wiretap/libpcap.c in the libpcap file parser in Wireshark 1.10.x before 1.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted packet-trace file that includes a large packet.NETWORK
CVE-2014-40202014-06-18 16:55:08MEDIUM (4)The dissect_frame function in epan/dissectors/packet-frame.c in the frame metadissector in Wireshark 1.10.x before 1.10.8 interprets a negative integer as a length value even though it was intended to represent an error condition, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2014-29072014-04-24 10:55:02MEDIUM (4)The srtp_add_address function in epan/dissectors/packet-rtp.c in the RTP dissector in Wireshark 1.10.x before 1.10.7 does not properly update SRTP conversation data, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2014-22992014-03-11 13:01:10HIGH (9)Buffer overflow in the mpeg_read function in wiretap/mpeg.c in the MPEG parser in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a large record in MPEG data.NETWORK
CVE-2014-22832014-03-11 13:01:10MEDIUM (4)epan/dissectors/packet-rlc in the RLC dissector in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 uses inconsistent memory-management approaches, which allows remote attackers to cause a denial of service (use-after-free error and application crash) via a crafted UMTS Radio Link Control packet.NETWORK
CVE-2014-22822014-03-11 13:01:10MEDIUM (4)The dissect_protocol_data_parameter function in epan/dissectors/packet-m3ua.c in the M3UA dissector in Wireshark 1.10.x before 1.10.6 does not properly allocate memory, which allows remote attackers to cause a denial of service (application crash) via a crafted SS7 MTP3 packet.NETWORK
CVE-2014-22812014-03-11 13:01:10MEDIUM (4)The nfs_name_snoop_add_name function in epan/dissectors/packet-nfs.c in the NFS dissector in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 does not validate a certain length value, which allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted NFS packet.NETWORK
CVE-2013-71142013-12-19 22:55:05MEDIUM (5)Multiple buffer overflows in the create_ntlmssp_v2_key function in epan/dissectors/packet-ntlmssp.c in the NTLMSSP v2 dissector in Wireshark 1.8.x before 1.8.12 and 1.10.x before 1.10.4 allow remote attackers to cause a denial of service (application crash) via a long domain name in a packet.NETWORK
CVE-2013-71132013-12-19 22:55:05MEDIUM (5)epan/dissectors/packet-bssgp.c in the BSSGP dissector in Wireshark 1.10.x before 1.10.4 incorrectly relies on a global variable, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2013-71122013-12-19 22:55:05MEDIUM (5)The dissect_sip_common function in epan/dissectors/packet-sip.c in the SIP dissector in Wireshark 1.8.x before 1.8.12 and 1.10.x before 1.10.4 does not check for empty lines, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.NETWORK
CVE-2013-63402013-11-04 16:55:05MEDIUM (4)epan/dissectors/packet-tcp.c in the TCP dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 does not properly determine the amount of remaining data, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2013-63392013-11-04 16:55:05MEDIUM (4)The dissect_openwire_type function in epan/dissectors/packet-openwire.c in the OpenWire dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 allows remote attackers to cause a denial of service (loop) via a crafted packet.NETWORK
CVE-2013-63382013-11-04 16:55:05MEDIUM (4)The dissect_sip_common function in epan/dissectors/packet-sip.c in the SIP dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 does not properly initialize a data structure, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2013-63372013-11-04 16:55:05MEDIUM (4)Unspecified vulnerability in the NBAP dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2013-63362013-11-04 16:55:05MEDIUM (4)The ieee802154_map_rec function in epan/dissectors/packet-ieee802154.c in the IEEE 802.15.4 dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 uses an incorrect pointer chain, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2013-57222013-09-16 13:01:47MEDIUM (4)Unspecified vulnerability in the LDAP dissector in Wireshark 1.8.x before 1.8.10 and 1.10.x before 1.10.2 allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2013-57212013-09-16 13:01:47MEDIUM (4)The dissect_mq_rr function in epan/dissectors/packet-mq.c in the MQ dissector in Wireshark 1.8.x before 1.8.10 and 1.10.x before 1.10.2 does not properly determine when to enter a certain loop, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2013-57202013-09-16 13:01:47MEDIUM (5)Buffer overflow in the RTPS dissector in Wireshark 1.8.x before 1.8.10 and 1.10.x before 1.10.2 allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2013-57192013-09-16 13:01:47MEDIUM (4)epan/dissectors/packet-assa_r3.c in the ASSA R3 dissector in Wireshark 1.8.x before 1.8.10 and 1.10.x before 1.10.2 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.NETWORK
CVE-2013-57182013-09-16 13:01:47MEDIUM (4)The dissect_nbap_T_dCH_ID function in epan/dissectors/packet-nbap.c in the NBAP dissector in Wireshark 1.8.x before 1.8.10 and 1.10.x before 1.10.2 does not restrict the dch_id value, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2013-57172013-09-16 13:01:47MEDIUM (4)The Bluetooth HCI ACL dissector in Wireshark 1.10.x before 1.10.2 does not properly maintain a certain free list, which allows remote attackers to cause a denial of service (application crash) via a crafted packet that is not properly handled by the wmem_block_alloc function in epan/wmem/wmem_allocator_block.c.NETWORK
CVE-2013-49362013-07-30 00:56:16MEDIUM (5)The IsDFP_Frame function in plugins/profinet/packet-pn-rt.c in the PROFINET Real-Time dissector in Wireshark 1.10.x before 1.10.1 does not validate MAC addresses, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted packet.NETWORK
CVE-2013-49352013-07-30 00:56:16MEDIUM (4)The dissect_per_length_determinant function in epan/dissectors/packet-per.c in the ASN.1 PER dissector in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 does not initialize a length field in certain abnormal situations, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2013-49342013-07-30 00:56:16MEDIUM (4)The netmon_open function in wiretap/netmon.c in the Netmon file parser in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 does not initialize certain structure members, which allows remote attackers to cause a denial of service (application crash) via a crafted packet-trace file.NETWORK
CVE-2013-49332013-07-30 00:56:16MEDIUM (5)The netmon_open function in wiretap/netmon.c in the Netmon file parser in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 does not properly allocate memory, which allows remote attackers to cause a denial of service (application crash) via a crafted packet-trace file.NETWORK
CVE-2013-49322013-07-30 00:56:16MEDIUM (5)Multiple array index errors in epan/dissectors/packet-gsm_a_common.c in the GSM A Common dissector in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 allow remote attackers to cause a denial of service (application crash) via a crafted packet.NETWORK
CVE-2013-49312013-07-30 00:56:16MEDIUM (5)epan/proto.c in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 allows remote attackers to cause a denial of service (loop) via a crafted packet that is not properly handled by the GSM RR dissector.NETWORK

Showing the 500 most recent of 654 tracked CVEs.

Why keeping Wireshark patched matters

Unpatched third-party applications are one of the most common ways attackers get in: 57% of breached MSP clients and 32% of ransomware cases trace back to a missing patch. Every Wireshark release that fixes a security bug is public, so attackers see it too, and an out-of-date install becomes a documented way in. Tracking the installed version on every machine and closing the gap quickly is what turns a disclosed CVE into a non-event.

How Lavawall® patches Wireshark

Lavawall® watches Wireshark releases and CVEs continuously, ranks each update by risk, and deploys it across your whole fleet, Windows, macOS, and Linux, from a single agent, independently of your RMM. You get one place to see which machines are behind on Wireshark, one policy to bring them current, and timestamped evidence for audits.

Frequently asked questions

What is the latest version of Wireshark?
Lavawall tracks Wireshark at version 4.6.7 (last checked 2026-08-10). New releases are monitored continuously and can be deployed automatically across your fleet.
Does Wireshark have known security vulnerabilities (CVEs)?
Lavawall continuously monitors Wireshark for newly disclosed CVEs and remediates them automatically as they appear.
How do I patch Wireshark automatically?
Deploy the Lavawall® agent and Wireshark updates are applied automatically across Windows, macOS, and Linux, risk-ranked and reported, independently of your RMM.

Lavawall® monitors releases and CVEs for Wireshark through public information and proprietary statistical analysis, and can patch it automatically across your fleet.