Lucene search

K
nvd[email protected]NVD:CVE-2008-3146
HistorySep 02, 2008 - 2:24 p.m.

CVE-2008-3146

2008-09-0214:24:00
CWE-119
web.nvd.nist.gov
4

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

Low

EPSS

0.01

Percentile

83.3%

Multiple buffer overflows in packet_ncp2222.inc in Wireshark (formerly Ethereal) 0.9.7 through 1.0.2 allow attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted NCP packet that causes an invalid pointer to be used.

Affected configurations

Nvd
Node
wiresharkwiresharkMatch0.9.7
OR
wiresharkwiresharkMatch0.9.8
OR
wiresharkwiresharkMatch0.99
OR
wiresharkwiresharkMatch0.99.0
OR
wiresharkwiresharkMatch0.99.1
OR
wiresharkwiresharkMatch0.99.2
OR
wiresharkwiresharkMatch0.99.3
OR
wiresharkwiresharkMatch0.99.4
OR
wiresharkwiresharkMatch0.99.5
OR
wiresharkwiresharkMatch0.99.6
OR
wiresharkwiresharkMatch0.99.6a
OR
wiresharkwiresharkMatch0.99.7
OR
wiresharkwiresharkMatch0.99.8
OR
wiresharkwiresharkMatch1.0
OR
wiresharkwiresharkMatch1.0.0
OR
wiresharkwiresharkMatch1.0.1
OR
wiresharkwiresharkMatch1.0.2

References

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

Low

EPSS

0.01

Percentile

83.3%