Where
AND
-Infinity
0
Severity
6.6
AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H

Ixia IxVeriWave and Vector Informatik BLF file parser crashes in 4.6.0 to 4.6.7 allows denial of service on Windows

First published (updated )
Severity
6.5
EPSS
0.03%
AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H

IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service

Remedy

Upgrade to version 4.6.3 or above
First published (updated )
Severity
6.5
EPSS
0.02%
AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

BLF file parser crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service

Remedy

Upgrade to version 4.6.3 or above
First published (updated )
Severity
6.5
EPSS
0.03%
AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H

SOME/IP-SD protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service

Remedy

Upgrade to version 4.6.3 or above
First published (updated )
Severity
6.5
EPSS
0.04%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

RTPS dissector memory leak in Wireshark 4.0.0 to 4.0.8 and 3.6.0 to 3.6.16 allows denial of service via packet injection or crafted capture file

Remedy

Upgrade to version 4.0.9, 3.6.17 or above.
First published (updated )
Severity
6.5
Buffer Overflow
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the WCP dissector could crash. This was addressed in epan/dissectors/packet-wcp.c by validating the available buffer length.

First published (updated )
Severity
6.5
Buffer Overflow
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the IxVeriWave file parser could crash. This was addressed in wiretap/vwr.c by correcting the signature timestamp bounds checks.

First published (updated )
Severity
6.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the NetScaler file parser could go into an infinite loop, triggered by a malformed capture file. This was addressed in wiretap/netscaler.c by ensuring a nonzero record size.

First published (updated )
Severity
6.5
Null Pointer Dereference
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In Wireshark 3.0.x before 3.0.8, the BT ATT dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by validating opcodes.

First published (updated )
Severity
6.5
EPSS
0.05%
AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

SSH dissector crash in Wireshark 4.0.0 to 4.0.10 allows denial of service via packet injection or crafted capture file

1 / 3

Remedy

Upgrade to version 4.0.11 or above.
First published (updated )
Severity
6.1
AV:A/AC:L/Au:N/C:N/I:N/A:C

The AMPQ dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.

First published (updated )
Severity
6.1
AV:A/AC:L/Au:N/C:N/I:N/A:C

The dissectdiagnosticrequest function in epan/dissectors/packet-reload.c in the REsource LOcation And Discovery (aka RELOAD) dissector in Wireshark 1.8.x before 1.8.6 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (infinite loop) via crafted integer values in a packet.

First published (updated )
Severity
6.1
AV:A/AC:L/Au:N/C:N/I:N/A:C

The dissecthartip function in epan/dissectors/packet-hartip.c in the HART/IP dissector in Wireshark 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (infinite loop) via a packet with a header that is too short.

First published (updated )
Severity
6.1
AV:A/AC:L/Au:N/C:N/I:N/A:C

The FCSP dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.

First published (updated )
Severity
6.1
AV:A/AC:L/Au:N/C:N/I:N/A:C

Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (infinite or large loop) via the (1) IPv6 or (2) USB dissector, which can trigger resource consumption or a crash. NOTE: this identifier originally included Firebird/Interbase, but it is already covered by CVE-2007-6116. The DCP ETSI issue is already covered by CVE-2007-6119.

1 / 2
First published (updated )
Severity
5.9
Buffer Overflow
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

epan/dissectors/packet-ieee80211.c in the IEEE 802.11 dissector in Wireshark 2.x before 2.0.2 mishandles the Grouping subfield, which allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet.

First published (updated )
Severity
5.8
Buffer Overflow
AV:A/AC:L/Au:N/C:P/I:P/A:P

Buffer overflow in the reassemblemessage function in epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a series of fragmented RLC packets.

First published (updated )
Severity
5.8
Buffer Overflow
AV:A/AC:L/Au:N/C:P/I:P/A:P

Buffer overflow in the channelisedfillsdhg707format function in epan/dissectors/packet-erf.c in the ERF dissector in Wireshark 1.8.x before 1.8.2 allows remote attackers to execute arbitrary code via a large speed (aka rate) value.

First published (updated )
Severity
5.5
EPSS
0.04%
AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L

Memory handling issue in editcap could cause denial of service via crafted capture file

First published (updated )
Severity
5.5
EPSS
0.04%
Use After Free
AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L

Use after free issue in editcap could cause denial of service via crafted capture file

First published (updated )
Severity
5.5
EPSS
0.04%
AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

SPRT dissector crash in Wireshark 4.2.0 to 4.0.5 and 4.0.0 to 4.0.15 allows denial of service via packet injection or crafted capture file

Remedy

Upgrade to versions 4.2.6, 4.0.16 or above.
First published (updated )
Severity
5.5
AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13 allows denial of service

Remedy

Upgrade to version 4.4.10, 4.2.14, or above
First published (updated )
Severity
5.5
AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

BPv7 dissector crash in Wireshark 4.6.0 allows denial of service

Remedy

Upgrade to version 4.6.1 or above
First published (updated )
Severity
5.5
AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service

Remedy

Upgrade to version 4.6.2 or above
First published (updated )
Severity
5.5
AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

MEGACO dissector infinite loop in Wireshark 4.6.0 to 4.6.1 and 4.4.0 to 4.4.11 allows denial of service

Remedy

Upgrade to version 4.6.2, 4.4.12, or above
First published (updated )
Severity
5.5
EPSS
0.01%
AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H

HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of service

Remedy

Upgrade to version 4.6.3 or above
First published (updated )
Severity
5.5
EPSS
0.01%
AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

SMB2 protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

First published (updated )
Severity
5.5
EPSS
0.01%
AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

GSM RP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

First published (updated )
Severity
5.5
EPSS
0.01%
AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

OpenFlow v5 protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

First published (updated )
Severity
5.5
EPSS
0.01%
AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

BEEP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203