Vulnerabilities > Wireshark > High

DATE CVE VULNERABILITY TITLE RISK
2010-02-03 CVE-2010-0304 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Wireshark
Multiple buffer overflows in the LWRES dissector in Wireshark 0.9.15 through 1.0.10 and 1.2.0 through 1.2.5 allow remote attackers to cause a denial of service (crash) via a malformed packet, as demonstrated using a stack-based buffer overflow to the dissect_getaddrsbyname_request function.
network
low complexity
wireshark CWE-119
7.5
2009-09-18 CVE-2009-3241 Multiple vulnerability in Wireshark 1.2.1
Unspecified vulnerability in the OpcUa (OPC UA) dissector in Wireshark 0.99.6 through 1.0.8 and 1.2.0 through 1.2.1 allows remote attackers to cause a denial of service (memory and CPU consumption) via malformed OPCUA Service CallRequest packets.
network
low complexity
wireshark
7.8
2009-07-21 CVE-2009-2563 Multiple vulnerability in Wireshark 1.2.0
Unspecified vulnerability in the Infiniband dissector in Wireshark 1.0.6 through 1.2.0, when running on unspecified platforms, allows remote attackers to cause a denial of service (crash) via unknown vectors.
network
wireshark
7.1
2007-11-23 CVE-2007-6119 Remote vulnerability in Wireshark 0.99.6
The DCP ETSI dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (long loop and resource consumption) via unknown vectors.
network
low complexity
wireshark
7.8
2007-11-23 CVE-2007-6118 Remote vulnerability in Wireshark 0.99.6
The MEGACO dissector in Wireshark (formerly Ethereal) 0.9.14 to 0.99.6 allows remote attackers to cause a denial of service (long loop and resource consumption) via unknown vectors.
network
low complexity
ethereal-group wireshark
7.8
2007-11-23 CVE-2007-6111 Remote vulnerability in Wireshark 0.99.6
Multiple unspecified vulnerabilities in Wireshark (formerly Ethereal) allow remote attackers to cause a denial of service (crash) via (1) a crafted MP3 file or (2) unspecified vectors to the NCP dissector.
7.1
2007-06-26 CVE-2007-3391 Improper Input Validation vulnerability in Wireshark 0.99.5
Wireshark 0.99.5 allows remote attackers to cause a denial of service (memory consumption) via a malformed DCP ETSI packet that triggers an infinite loop.
network
low complexity
wireshark CWE-20
7.8
2006-10-28 CVE-2006-4574 Reachable Assertion vulnerability in Wireshark 0.10.1/0.99.2/0.99.3
Off-by-one error in the MIME Multipart dissector in Wireshark (formerly Ethereal) 0.10.1 through 0.99.3 allows remote attackers to cause a denial of service (crash) via certain vectors that trigger an assertion error related to unexpected length values.
network
low complexity
wireshark CWE-617
7.5
2006-07-21 CVE-2006-3630 Numeric Errors vulnerability in Wireshark 0.9.7/0.9.8/0.99.0
Multiple off-by-one errors in Wireshark (aka Ethereal) 0.9.7 to 0.99.0 have unknown impact and remote attack vectors via the (1) NCP NMAS and (2) NDPS dissectors.
network
low complexity
wireshark CWE-189
7.5