Skip to main content

Vendor archive

wireshark CVEs

Beta · best-effort

748 CVEs tagged to vendor wireshark20 Critical, 222 High, 441 Medium, 65 Low, 0 Unrated.

CVE-2018-18227

Published Oct 12, 2018

In Wireshark 2.6.0 to 2.6.3 and 2.4.0 to 2.4.9, the MS-WSP protocol dissector could crash. This was addressed in epan/dissectors/packet-mswsp.c by properly handling NULL return va…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-18226

Published Oct 12, 2018

In Wireshark 2.6.0 to 2.6.3, the Steam IHS Discovery dissector could consume system memory. This was addressed in epan/dissectors/packet-steam-ihs-discovery.c by changing the memo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-16058

Published Aug 30, 2018

In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Bluetooth AVDTP dissector could crash. This was addressed in epan/dissectors/packet-btavdtp.c by properly ini…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2018-16057

Published Aug 30, 2018

In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Radiotap dissector could crash. This was addressed in epan/dissectors/packet-ieee80211-radiotap-iter.c by val…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2018-16056

Published Aug 30, 2018

In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Bluetooth Attribute Protocol dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by v…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2018-14438

Published Jul 20, 2018

In Wireshark through 2.6.2, the create_app_running_mutex function in wsutil/file_util.c calls SetSecurityDescriptorDacl to set a NULL DACL, which allows attackers to modify the ac…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-14370

Published Jul 19, 2018

In Wireshark 2.6.0 to 2.6.1 and 2.4.0 to 2.4.7, the IEEE 802.11 protocol dissector could crash. This was addressed in epan/crypt/airpdcap.c via bounds checking that prevents a buf…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-14369

Published Jul 19, 2018

In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the HTTP2 dissector could crash. This was addressed in epan/dissectors/packet-http2.c by verifying that header da…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-14368

Published Jul 19, 2018

In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the Bazaar protocol dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-bzr.c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-14367

Published Jul 19, 2018

In Wireshark 2.6.0 to 2.6.1 and 2.4.0 to 2.4.7, the CoAP protocol dissector could crash. This was addressed in epan/dissectors/packet-coap.c by properly checking for a NULL condit…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-14344

Published Jul 19, 2018

In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the ISMP dissector could crash. This was addressed in epan/dissectors/packet-ismp.c by validating the IPX address…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-14343

Published Jul 19, 2018

In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the ASN.1 BER dissector could crash. This was addressed in epan/dissectors/packet-ber.c by ensuring that length v…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-14342

Published Jul 19, 2018

In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the BGP protocol dissector could go into a large loop. This was addressed in epan/dissectors/packet-bgp.c by vali…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-14340

Published Jul 19, 2018

In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, dissectors that support zlib decompression could crash. This was addressed in epan/tvbuff_zlib.c by rejecting neg…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11362

Published May 22, 2018

In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LDSS dissector could crash. This was addressed in epan/dissectors/packet-ldss.c by avoiding a buffer over-read upon en…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11361

Published May 22, 2018

In Wireshark 2.6.0, the IEEE 802.11 protocol dissector could crash. This was addressed in epan/crypt/dot11decrypt.c by avoiding a buffer overflow during FTE processing in Dot11Dec…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11360

Published May 22, 2018

In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the GSM A DTAP dissector could crash. This was addressed in epan/dissectors/packet-gsm_a_dtap.c by fixing an off-by-one er…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11359

Published May 22, 2018

In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the RRC dissector and other dissectors could crash. This was addressed in epan/proto.c by avoiding a NULL pointer derefere…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11358

Published May 22, 2018

In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the Q.931 dissector could crash. This was addressed in epan/dissectors/packet-q931.c by avoiding a use-after-free after a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11357

Published May 22, 2018

In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LTP dissector and other dissectors could consume excessive memory. This was addressed in epan/tvbuff.c by rejecting ne…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11356

Published May 22, 2018

In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the DNS dissector could crash. This was addressed in epan/dissectors/packet-dns.c by avoiding a NULL pointer dereference f…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11355

Published May 22, 2018

In Wireshark 2.6.0, the RTCP dissector could crash. This was addressed in epan/dissectors/packet-rtcp.c by avoiding a buffer overflow for packet status chunks.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 201-225 of 748 CVEsPage 9 of 30