Vulnerabilities > Tcpdump > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-11-13 CVE-2017-16808 Out-of-bounds Read vulnerability in Tcpdump 4.9.2
tcpdump before 4.9.3 has a heap-based buffer over-read related to aoe_print in print-aoe.c and lookup_emem in addrtoname.c.
local
low complexity
tcpdump CWE-125
5.5
2017-09-28 CVE-2015-3138 Improper Input Validation vulnerability in multiple products
print-wb.c in tcpdump before 4.7.4 allows remote attackers to cause a denial of service (segmentation fault and process crash).
network
low complexity
tcpdump opensuse opensuse-project CWE-20
5.0
2017-09-14 CVE-2017-12997 Infinite Loop vulnerability in Tcpdump
The LLDP parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-lldp.c:lldp_private_8021_print().
network
low complexity
tcpdump CWE-835
5.0
2017-09-14 CVE-2017-12995 Infinite Loop vulnerability in Tcpdump
The DNS parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-domain.c:ns_print().
network
low complexity
tcpdump CWE-835
5.0
2017-09-14 CVE-2017-12990 Infinite Loop vulnerability in Tcpdump
The ISAKMP parser in tcpdump before 4.9.2 could enter an infinite loop due to bugs in print-isakmp.c, several functions.
network
low complexity
tcpdump CWE-835
5.0
2017-09-14 CVE-2017-12989 Infinite Loop vulnerability in Tcpdump
The RESP parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-resp.c:resp_get_length().
network
low complexity
tcpdump CWE-835
5.0
2017-07-08 CVE-2017-11108 Out-of-bounds Read vulnerability in Tcpdump 4.9.0
tcpdump 4.9.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via crafted packet data.
network
low complexity
tcpdump CWE-125
5.0
2015-03-24 CVE-2015-2154 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Tcpdump
The osi_print_cksum function in print-isoclns.c in the ethernet printer in tcpdump before 4.7.2 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted (1) length, (2) offset, or (3) base pointer checksum value.
network
low complexity
tcpdump CWE-119
5.0
2015-03-24 CVE-2015-2153 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Tcpdump
The rpki_rtr_pdu_print function in print-rpki-rtr.c in the TCP printer in tcpdump before 4.7.2 allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) via a crafted header length in an RPKI-RTR Protocol Data Unit (PDU).
network
low complexity
tcpdump CWE-119
5.0
2007-03-02 CVE-2007-1218 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Tcpdump
Off-by-one buffer overflow in the parse_elements function in the 802.11 printer code (print-802_11.c) for tcpdump 3.9.5 and earlier allows remote attackers to cause a denial of service (crash) via a crafted 802.11 frame.
network
tcpdump CWE-119
6.8