Where
AND
-Infinity
0

Vendor Risk Score

See how wireshark compares to other vendors in security performance

View Risk Score →
Severity
3.3
AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

BLF file parser in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows possible information disclosure

First published (updated )
Severity
3.3
AV:A/AC:L/Au:N/C:N/I:N/A:P

The dissectmplsechotlvddmap function in epan/dissectors/packet-mpls-echo.c in the MPLS Echo dissector in Wireshark 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (infinite loop) via invalid Sub-tlv data.

First published (updated )
Severity
3.3
Buffer Overflow
AV:A/AC:L/Au:N/C:N/I:N/A:P

The CSN.1 dissector in Wireshark 1.8.x before 1.8.6 does not properly manage function pointers, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.

First published (updated )
Severity
3.3
AV:A/AC:L/Au:N/C:N/I:N/A:P

The RTPS and RTPS2 dissectors in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allow remote attackers to cause a denial of service (application crash) via a malformed packet.

First published (updated )
Severity
3.3
AV:A/AC:L/Au:N/C:N/I:N/A:P

The acnadddmpdata function in epan/dissectors/packet-acn.c in the ACN dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via an invalid count value in ACNDMPADTDRE DMP data.

First published (updated )
Severity
3.3
AV:A/AC:L/Au:N/C:N/I:N/A:P

The CIMD dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (application crash) via a malformed packet.

First published (updated )
Severity
3.3
AV:A/AC:L/Au:N/C:N/I:N/A:P

The TCP dissector in Wireshark 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (application crash) via a malformed packet.

First published (updated )
Severity
2.9
AV:A/AC:M/Au:N/C:N/I:N/A:P

Integer signedness error in the dissectmountdirpathcall function in epan/dissectors/packet-mount.c in the Mount dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6, when nfsfilenamesnooping is enabled, allows remote attackers to cause a denial of service (application crash) via a negative length value.

First published (updated )
Severity
3.3
Integer Overflow
AV:A/AC:L/Au:N/C:N/I:N/A:P

The dissectserverinfo function in epan/dissectors/packet-ms-mms.c in the MS-MMS dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 does not properly manage string lengths, which allows remote attackers to cause a denial of service (application crash) via a malformed packet that (1) triggers an integer overflow or (2) has embedded '\0' characters in a string.

First published (updated )
Severity
2.9
Input Validation
AV:A/AC:M/Au:N/C:N/I:N/A:P

The dissectpftfecdetailed function in epan/dissectors/packet-dcp-etsi.c in the DCP-ETSI dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly handle fragment gaps, which allows remote attackers to cause a denial of service (loop) via a malformed packet.

First published (updated )
Severity
2.9
AV:A/AC:M/Au:N/C:N/I:N/A:P

The dissectclnp function in epan/dissectors/packet-clnp.c in the CLNP dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly manage an offset variable, which allows remote attackers to cause a denial of service (infinite loop or application crash) via a malformed packet.

First published (updated )
Severity
2.9
Double Free
AV:A/AC:M/Au:N/C:N/I:N/A:P

Double free vulnerability in epan/proto.c in the dissection engine in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 allows remote attackers to cause a denial of service (application crash) via a malformed packet.

First published (updated )
Severity
2.9
AV:A/AC:M/Au:N/C:N/I:N/A:P

The dissectrohcirpacket function in epan/dissectors/packet-rohc.c in the ROHC dissector in Wireshark 1.8.x before 1.8.5 does not properly handle unknown profiles, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.

First published (updated )
Severity
2.9
Input Validation
AV:A/AC:M/Au:N/C:N/I:N/A:P

The dissectoampdueventnotification function in epan/dissectors/packet-slowprotocols.c in the IEEE 802.3 Slow Protocols dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly handle certain short lengths, which allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.

First published (updated )
Severity
2.9
AV:A/AC:M/Au:N/C:N/I:N/A:P

The dissectsdpmediaattribute function in epan/dissectors/packet-sdp.c in the SDP dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly process crypto-suite parameters, which allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.

First published (updated )
Severity
2.9
Input Validation
AV:A/AC:M/Au:N/C:N/I:N/A:P

The dissectversion5and6primaryheader function in epan/dissectors/packet-dtn.c in the DTN dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 accesses an inappropriate pointer, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.

First published (updated )
Severity
2.9
AV:A/AC:M/Au:N/C:N/I:N/A:P

The rtpsutiladdbitmap function in epan/dissectors/packet-rtps.c in the RTPS dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly implement certain nested loops for processing bitmap data, which allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.

First published (updated )
Severity
2.9
AV:A/AC:M/Au:N/C:N/I:N/A:P

The fragmentsettotlen function in epan/reassemble.c in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly determine the length of a reassembled packet for the DTLS dissector, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.

First published (updated )
Severity
2.9
Input Validation
AV:A/AC:M/Au:N/C:N/I:N/A:P

The dissectr3cmdalarmconfigure function in epan/dissectors/packet-assar3.c in the R3 dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly handle a certain alarm length, which allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.

First published (updated )
Severity
2.9
Buffer Overflow
AV:A/AC:M/Au:N/C:N/I:N/A:P

Buffer overflow in the NTLMSSP dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 allows remote attackers to cause a denial of service (application crash) via a malformed packet.

First published (updated )
Severity
2.9
Input Validation
AV:A/AC:M/Au:N/C:N/I:N/A:P

The dissectsippchargingfuncaddresses function in epan/dissectors/packet-sip.c in the SIP dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly handle offset data associated with a quoted string, which allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.

First published (updated )
Severity
2.9
Buffer Overflow
AV:A/AC:M/Au:N/C:N/I:N/A:P

Multiple buffer overflows in the dissectpftfecdetailed function in the DCP-ETSI dissector in epan/dissectors/packet-dcp-etsi.c in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 allow remote attackers to cause a denial of service (application crash) via a malformed packet.

First published (updated )
Severity
2.9
Input Validation
AV:A/AC:M/Au:N/C:N/I:N/A:P

The dissectbthcieiraddata function in epan/dissectors/packet-bthcicmd.c in the Bluetooth HCI dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 uses an incorrect data type for a counter variable, which allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.

First published (updated )
Severity
2.9
Input Validation
AV:A/AC:M/Au:N/C:N/I:N/A:P

The dissectversion4primaryheader function in epan/dissectors/packet-dtn.c in the DTN dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 accesses an inappropriate pointer, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.

First published (updated )
Severity
2.9
Input Validation
AV:A/AC:M/Au:N/C:N/I:N/A:P

The dissectcmstatustlv function in plugins/docsis/packet-cmstatus.c in the DOCSIS CM-STATUS dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 uses an incorrect data type for a position variable, which allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.

First published (updated )
Severity
2.9
Input Validation
AV:A/AC:M/Au:N/C:N/I:N/A:P

epan/tvbuff.c in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly validate certain length values for the MS-MMC dissector, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.

First published (updated )
Severity
2.9
Input Validation
AV:A/AC:M/Au:N/C:N/I:N/A:P

The csnStreamDissector function in epan/dissectors/packet-csn1.c in the CSN.1 dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly handle a large number of padding bits, which allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.

First published (updated )
Severity
2.9
Input Validation
AV:A/AC:M/Au:N/C:N/I:N/A:P

The dissectpwethheuristic function in epan/dissectors/packet-pw-eth.c in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly handle apparent Ethernet address values at the beginning of MPLS data, which allows remote attackers to cause a denial of service (loop) via a malformed packet.

First published (updated )
Severity
3.3
AV:A/AC:L/Au:N/C:N/I:N/A:P

The dissecthsrp function in epan/dissectors/packet-hsrp.c in the HSRP dissector in Wireshark 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.

First published (updated )
Severity
3.3
AV:A/AC:L/Au:N/C:N/I:N/A:P

epan/dissectors/packet-ppp.c in the PPP dissector in Wireshark 1.8.x before 1.8.3 uses incorrect OUI data structures during the decoding of (1) PPP and (2) LCP data, which allows remote attackers to cause a denial of service (assertion failure and application exit) via a malformed packet.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203