The bgpupdateprint function in tcpdump 3.x does not properly handle a -1 return value from the decodeprefix4 function, which allows remote attackers to cause a denial of service (infinite loop) via a crafted BGP packet.
Multiple buffer overflows in LBNL tcpdump allow remote attackers to execute arbitrary commands.