Vulnerabilities > Tcpdump > High

DATE CVE VULNERABILITY TITLE RISK
2020-11-04 CVE-2020-8037 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.
network
low complexity
tcpdump debian fedoraproject apple CWE-770
7.5
2019-10-03 CVE-2019-15163 NULL Pointer Dereference vulnerability in Tcpdump Libpcap
rpcapd/daemon.c in libpcap before 1.9.1 allows attackers to cause a denial of service (NULL pointer dereference and daemon crash) if a crypt() call fails.
network
low complexity
tcpdump CWE-476
7.5
2019-10-03 CVE-2019-15166 Classic Buffer Overflow vulnerability in multiple products
lmp_print_data_link_subobjs() in print-lmp.c in tcpdump before 4.9.3 lacks certain bounds checks.
7.5
2019-10-03 CVE-2018-16301 Classic Buffer Overflow vulnerability in Tcpdump
The command-line argument parser in tcpdump before 4.99.0 has a buffer overflow in tcpdump.c:read_infile().
local
low complexity
tcpdump CWE-120
7.8
2019-10-03 CVE-2018-16452 Uncontrolled Recursion vulnerability in Tcpdump
The SMB parser in tcpdump before 4.9.3 has stack exhaustion in smbutil.c:smb_fdata() via recursion.
network
low complexity
tcpdump CWE-674
7.5
2019-10-03 CVE-2018-16451 Out-of-bounds Read vulnerability in multiple products
The SMB parser in tcpdump before 4.9.3 has buffer over-reads in print-smb.c:print_trans() for \MAILSLOT\BROWSE and \PIPE\LANMAN.
7.5
2019-10-03 CVE-2018-16300 Uncontrolled Recursion vulnerability in Tcpdump
The BGP parser in tcpdump before 4.9.3 allows stack consumption in print-bgp.c:bgp_attr_print() because of unlimited recursion.
network
low complexity
tcpdump CWE-674
7.5
2019-10-03 CVE-2018-16230 Out-of-bounds Read vulnerability in multiple products
The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_attr_print() (MP_REACH_NLRI).
7.5
2019-10-03 CVE-2018-16229 Out-of-bounds Read vulnerability in multiple products
The DCCP parser in tcpdump before 4.9.3 has a buffer over-read in print-dccp.c:dccp_print_option().
7.5
2019-10-03 CVE-2018-16228 Out-of-bounds Read vulnerability in multiple products
The HNCP parser in tcpdump before 4.9.3 has a buffer over-read in print-hncp.c:print_prefix().
7.5