Lucene search

K

Wireshark Security Vulnerabilities

cve
cve

CVE-2006-3627

Unspecified vulnerability in the GSM BSSMAP dissector in Wireshark (aka Ethereal) 0.10.11 to 0.99.0 allows remote attackers to cause a denial of service (crash) via unspecified vectors.

7.2AI Score

0.016EPSS

2006-07-21 02:03 PM
31
cve
cve

CVE-2006-3628

Multiple format string vulnerabilities in Wireshark (aka Ethereal) 0.10.x to 0.99.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) ANSI MAP, (2) Checkpoint FW-1, (3) MQ, (4) XML, and (5) NTP dissectors.

7.9AI Score

0.021EPSS

2006-07-21 02:03 PM
39
cve
cve

CVE-2006-3630

Multiple off-by-one errors in Wireshark (aka Ethereal) 0.9.7 to 0.99.0 have unknown impact and remote attack vectors via the (1) NCP NMAS and (2) NDPS dissectors.

7.3AI Score

0.013EPSS

2006-07-21 02:03 PM
36
cve
cve

CVE-2006-3631

Unspecified vulnerability in the SSH dissector in Wireshark (aka Ethereal) 0.9.10 to 0.99.0 allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.

7.1AI Score

0.018EPSS

2006-07-21 02:03 PM
26
cve
cve

CVE-2006-4330

Unspecified vulnerability in the SCSI dissector in Wireshark (formerly Ethereal) 0.99.2 allows remote attackers to cause a denial of service (crash) via unspecified vectors.

7.2AI Score

0.02EPSS

2006-08-24 08:04 PM
28
cve
cve

CVE-2006-4331

Multiple off-by-one errors in the IPSec ESP preference parser in Wireshark (formerly Ethereal) 0.99.2 allow remote attackers to cause a denial of service (crash) via unspecified vectors.

7.2AI Score

0.018EPSS

2006-08-24 08:04 PM
24
cve
cve

CVE-2006-4332

Unspecified vulnerability in the DHCP dissector in Wireshark (formerly Ethereal) 0.10.13 through 0.99.2, when run on Windows, allows remote attackers to cause a denial of service (crash) via unspecified vectors that trigger a bug in Glib.

7.2AI Score

0.018EPSS

2006-08-24 08:04 PM
19
cve
cve

CVE-2006-4333

The SSCOP dissector in Wireshark (formerly Ethereal) before 0.99.3 allows remote attackers to cause a denial of service (resource consumption) via malformed packets that cause the Q.2391 dissector to use excessive memory.

7.2AI Score

0.015EPSS

2006-08-24 08:04 PM
27
cve
cve

CVE-2006-4574

Off-by-one error in the MIME Multipart dissector in Wireshark (formerly Ethereal) 0.10.1 through 0.99.3 allows remote attackers to cause a denial of service (crash) via certain vectors that trigger an assertion error related to unexpected length values.

7.5CVSS

7.1AI Score

0.008EPSS

2006-10-28 12:07 AM
28
cve
cve

CVE-2006-4805

epan/dissectors/packet-xot.c in the XOT dissector (dissect_xot_pdu) in Wireshark (formerly Ethereal) 0.9.8 through 0.99.3 allows remote attackers to cause a denial of service (memory consumption and crash) via an encoded XOT packet that produces a zero length value when it is decoded.

7.2AI Score

0.022EPSS

2006-10-27 11:07 PM
27
cve
cve

CVE-2006-5468

Unspecified vulnerability in the HTTP dissector in Wireshark (formerly Ethereal) 0.99.3 allows remote attackers to cause a denial of service (crash) via unspecified vectors.

7.2AI Score

0.015EPSS

2006-10-27 11:07 PM
23
cve
cve

CVE-2006-5469

Unspecified vulnerability in the WBXML dissector in Wireshark (formerly Ethereal) 0.10.11 through 0.99.3 allows remote attackers to cause a denial of service (crash) via certain vectors that trigger a null dereference.

7.1AI Score

0.019EPSS

2006-10-28 12:07 AM
26
cve
cve

CVE-2006-5595

Unspecified vulnerability in the AirPcap support in Wireshark (formerly Ethereal) 0.99.3 has unspecified attack vectors related to WEP key parsing.

7.4AI Score

0.003EPSS

2006-10-28 12:07 AM
21
cve
cve

CVE-2006-5740

Unspecified vulnerability in the LDAP dissector in Wireshark (formerly Ethereal) 0.99.3 allows remote attackers to cause a denial of service (crash) via a crafted LDAP packet.

7.1AI Score

0.019EPSS

2006-10-27 11:07 PM
28
cve
cve

CVE-2007-0456

Unspecified vulnerability in the LLT dissector in Wireshark (formerly Ethereal) 0.99.3 and 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.

7.2AI Score

0.015EPSS

2007-02-02 08:28 PM
25
cve
cve

CVE-2007-0457

Unspecified vulnerability in the IEEE 802.11 dissector in Wireshark (formerly Ethereal) 0.10.14 through 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.

7.2AI Score

0.015EPSS

2007-02-02 08:28 PM
25
cve
cve

CVE-2007-0458

Unspecified vulnerability in the HTTP dissector in Wireshark (formerly Ethereal) 0.99.3 and 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors, a different issue than CVE-2006-5468.

6.3AI Score

0.015EPSS

2007-02-02 08:28 PM
24
cve
cve

CVE-2007-0459

packet-tcp.c in the TCP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.4 allows remote attackers to cause a denial of service (application crash or hang) via fragmented HTTP packets.

7.3AI Score

0.03EPSS

2007-02-02 08:28 PM
22
cve
cve

CVE-2007-3389

Wireshark before 0.99.6 allows remote attackers to cause a denial of service (crash) via a crafted chunked encoding in an HTTP response, possibly related to a zero-length payload.

6.1AI Score

0.022EPSS

2007-06-26 12:30 AM
24
cve
cve

CVE-2007-3390

Wireshark 0.99.5 and 0.10.x up to 0.10.14, when running on certain systems, allows remote attackers to cause a denial of service (crash) via crafted iSeries capture files that trigger a SIGTRAP.

6.2AI Score

0.019EPSS

2007-06-26 12:30 AM
26
cve
cve

CVE-2007-3391

Wireshark 0.99.5 allows remote attackers to cause a denial of service (memory consumption) via a malformed DCP ETSI packet that triggers an infinite loop.

6.1AI Score

0.017EPSS

2007-06-26 12:30 AM
30
cve
cve

CVE-2007-3392

Wireshark before 0.99.6 allows remote attackers to cause a denial of service via malformed (1) SSL or (2) MMS packets that trigger an infinite loop.

6.2AI Score

0.028EPSS

2007-06-26 12:30 AM
27
4
cve
cve

CVE-2007-3393

Off-by-one error in the DHCP/BOOTP dissector in Wireshark before 0.99.6 allows remote attackers to cause a denial of service (crash) via crafted DHCP-over-DOCSIS packets.

6AI Score

0.028EPSS

2007-06-26 12:30 AM
31
cve
cve

CVE-2007-6111

Multiple unspecified vulnerabilities in Wireshark (formerly Ethereal) allow remote attackers to cause a denial of service (crash) via (1) a crafted MP3 file or (2) unspecified vectors to the NCP dissector.

6.5AI Score

0.004EPSS

2007-11-23 08:46 PM
31
cve
cve

CVE-2007-6112

Buffer overflow in the PPP dissector Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.

7.5AI Score

0.034EPSS

2007-11-23 08:46 PM
24
cve
cve

CVE-2007-6113

Integer signedness error in the DNP3 dissector in Wireshark (formerly Ethereal) 0.10.12 to 0.99.6 allows remote attackers to cause a denial of service (long loop) via a malformed DNP3 packet.

6AI Score

0.02EPSS

2007-11-23 08:46 PM
22
cve
cve

CVE-2007-6114

Multiple buffer overflows in Wireshark (formerly Ethereal) 0.99.0 through 0.99.6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) the SSL dissector or (2) the iSeries (OS/400) Communication trace file parser.

7.5AI Score

0.039EPSS

2007-11-23 08:46 PM
35
cve
cve

CVE-2007-6115

Buffer overflow in the ANSI MAP dissector for Wireshark (formerly Ethereal) 0.99.5 to 0.99.6, when running on unspecified platforms, allows remote attackers to cause a denial of service and possibly execute arbitrary code via unknown vectors.

7.6AI Score

0.072EPSS

2007-11-23 08:46 PM
26
cve
cve

CVE-2007-6116

The Firebird/Interbase dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (infinite loop or crash) via unknown vectors.

6.2AI Score

0.005EPSS

2007-11-23 08:46 PM
21
cve
cve

CVE-2007-6117

Unspecified vulnerability in the HTTP dissector for Wireshark (formerly Ethereal) 0.10.14 to 0.99.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted chunked messages.

7.3AI Score

0.054EPSS

2007-11-23 08:46 PM
34
cve
cve

CVE-2007-6118

The MEGACO dissector in Wireshark (formerly Ethereal) 0.9.14 to 0.99.6 allows remote attackers to cause a denial of service (long loop and resource consumption) via unknown vectors.

6.1AI Score

0.004EPSS

2007-11-23 08:46 PM
28
cve
cve

CVE-2007-6119

The DCP ETSI dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (long loop and resource consumption) via unknown vectors.

6.1AI Score

0.005EPSS

2007-11-23 08:46 PM
37
cve
cve

CVE-2007-6120

The Bluetooth SDP dissector Wireshark (formerly Ethereal) 0.99.2 to 0.99.6 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.

6.1AI Score

0.004EPSS

2007-11-23 08:46 PM
41
cve
cve

CVE-2007-6121

Wireshark (formerly Ethereal) 0.8.16 to 0.99.6 allows remote attackers to cause a denial of service (crash) via a malformed RPC Portmap packet.

6.1AI Score

0.004EPSS

2007-11-23 08:46 PM
41
cve
cve

CVE-2007-6438

Unspecified vulnerability in the SMB dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service via unknown vectors. NOTE: this identifier originally included MP3 and NCP, but those issues are already covered by CVE-2007-6111.

6.2AI Score

0.005EPSS

2007-12-19 10:46 PM
23
cve
cve

CVE-2007-6439

Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (infinite or large loop) via the (1) IPv6 or (2) USB dissector, which can trigger resource consumption or a crash. NOTE: this identifier originally included Firebird/Interbase, but it is already covered by CVE...

6.1AI Score

0.005EPSS

2007-12-19 10:46 PM
28
cve
cve

CVE-2007-6441

The WiMAX dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (crash) via unknown vectors related to "unaligned access on some platforms."

6.1AI Score

0.003EPSS

2007-12-19 10:46 PM
24
cve
cve

CVE-2007-6450

The RPL dissector in Wireshark (formerly Ethereal) 0.9.8 to 0.99.6 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.

6.1AI Score

0.005EPSS

2007-12-19 10:46 PM
43
4
cve
cve

CVE-2007-6451

Unspecified vulnerability in the CIP dissector in Wireshark (formerly Ethereal) 0.9.14 to 0.99.6 allows remote attackers to cause a denial of service (crash) via unknown vectors that trigger allocation of large amounts of memory.

6AI Score

0.005EPSS

2007-12-19 10:46 PM
33
cve
cve

CVE-2008-1070

The SCTP dissector in Wireshark (formerly Ethereal) 0.99.5 through 0.99.7 allows remote attackers to cause a denial of service (crash) via a malformed packet.

6.1AI Score

0.004EPSS

2008-02-28 10:44 PM
27
cve
cve

CVE-2008-1071

The SNMP dissector in Wireshark (formerly Ethereal) 0.99.6 through 0.99.7 allows remote attackers to cause a denial of service (crash) via a malformed packet.

6.1AI Score

0.004EPSS

2008-02-28 10:44 PM
25
cve
cve

CVE-2008-1072

The TFTP dissector in Wireshark (formerly Ethereal) 0.6.0 through 0.99.7, when running on Ubuntu 7.10, allows remote attackers to cause a denial of service (crash or memory consumption) via a malformed packet, possibly related to a Cairo library bug.

6.3AI Score

0.002EPSS

2008-02-28 10:44 PM
17
cve
cve

CVE-2008-1561

Multiple unspecified vulnerabilities in Wireshark (formerly Ethereal) 0.99.5 through 0.99.8 allow remote attackers to cause a denial of service (application crash) via a malformed packet to the (1) X.509sat or (2) Roofnet dissectors. NOTE: Vector 2 might also lead to a hang.

6.5AI Score

0.024EPSS

2008-03-31 10:44 PM
23
cve
cve

CVE-2008-1562

The LDAP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.8 allows remote attackers to cause a denial of service (application crash) via a malformed packet, a different vulnerability than CVE-2006-5740.

6.1AI Score

0.019EPSS

2008-03-31 10:44 PM
26
cve
cve

CVE-2008-1563

The "decode as" feature in packet-bssap.c in the SCCP dissector in Wireshark (formerly Ethereal) 0.99.6 through 0.99.8 allows remote attackers to cause a denial of service (application crash) via a malformed packet.

6.1AI Score

0.019EPSS

2008-03-31 10:44 PM
23
cve
cve

CVE-2008-3137

The GSM SMS dissector in Wireshark (formerly Ethereal) 0.99.2 through 1.0.0 allows remote attackers to cause a denial of service (application crash) via unknown vectors.

6.1AI Score

0.005EPSS

2008-07-10 11:41 PM
36
cve
cve

CVE-2008-3138

The (1) PANA and (2) KISMET dissectors in Wireshark (formerly Ethereal) 0.99.3 through 1.0.0 allow remote attackers to cause a denial of service (application stop) via unknown vectors.

6.1AI Score

0.004EPSS

2008-07-10 11:41 PM
28
cve
cve

CVE-2008-3139

The RTMPT dissector in Wireshark (formerly Ethereal) 0.99.8 through 1.0.0 allows remote attackers to cause a denial of service (crash) via unknown vectors. NOTE: this might be due to a use-after-free error.

6.2AI Score

0.004EPSS

2008-07-10 11:41 PM
27
cve
cve

CVE-2008-3140

The syslog dissector in Wireshark (formerly Ethereal) 1.0.0 allows remote attackers to cause a denial of service (application crash) via unknown vectors, possibly related to an "incomplete SS7 MSU syslog encapsulated packet."

6.3AI Score

0.012EPSS

2008-07-10 11:41 PM
29
cve
cve

CVE-2008-3141

Unspecified vulnerability in the RMI dissector in Wireshark (formerly Ethereal) 0.9.5 through 1.0.0 allows remote attackers to read system memory via unspecified vectors.

6.1AI Score

0.002EPSS

2008-07-10 11:41 PM
30
Total number of security vulnerabilities663