Vulnerabilities > Wireshark > Low

DATE CVE VULNERABILITY TITLE RISK
2013-03-07 CVE-2013-2475 Denial of Service vulnerability in Wireshark TCP Dissector
The TCP dissector in Wireshark 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (application crash) via a malformed packet.
low complexity
wireshark opensuse
3.3
2013-03-07 CVE-2013-2477 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
The CSN.1 dissector in Wireshark 1.8.x before 1.8.6 does not properly manage function pointers, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.
low complexity
wireshark opensuse CWE-119
3.3
2013-03-07 CVE-2013-2478 Numeric Errors vulnerability in multiple products
The dissect_server_info function in epan/dissectors/packet-ms-mms.c in the MS-MMS dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 does not properly manage string lengths, which allows remote attackers to cause a denial of service (application crash) via a malformed packet that (1) triggers an integer overflow or (2) has embedded '\0' characters in a string.
low complexity
debian opensuse wireshark CWE-189
3.3
2013-03-07 CVE-2013-2479 Denial of Service vulnerability in Wireshark MPLS Echo Dissector
The dissect_mpls_echo_tlv_dd_map function in epan/dissectors/packet-mpls-echo.c in the MPLS Echo dissector in Wireshark 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (infinite loop) via invalid Sub-tlv data.
low complexity
wireshark opensuse
3.3
2013-03-07 CVE-2013-2480 Denial of Service vulnerability in Wireshark RTPS And RTPS2 Dissectors
The RTPS and RTPS2 dissectors in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allow remote attackers to cause a denial of service (application crash) via a malformed packet.
low complexity
debian opensuse wireshark
3.3
2013-03-07 CVE-2013-2481 Numeric Errors vulnerability in multiple products
Integer signedness error in the dissect_mount_dirpath_call function in epan/dissectors/packet-mount.c in the Mount dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6, when nfs_file_name_snooping is enabled, allows remote attackers to cause a denial of service (application crash) via a negative length value.
2.9
2013-03-07 CVE-2013-2483 Numeric Errors vulnerability in multiple products
The acn_add_dmp_data function in epan/dissectors/packet-acn.c in the ACN dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via an invalid count value in ACN_DMP_ADT_D_RE DMP data.
low complexity
wireshark debian opensuse CWE-189
3.3
2013-03-07 CVE-2013-2484 Denial of Service vulnerability in Wireshark CIMD Dissector
The CIMD dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (application crash) via a malformed packet.
low complexity
debian opensuse wireshark
3.3
2013-02-03 CVE-2013-1572 Improper Input Validation vulnerability in Wireshark
The dissect_oampdu_event_notification function in epan/dissectors/packet-slowprotocols.c in the IEEE 802.3 Slow Protocols dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly handle certain short lengths, which allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.
2.9
2013-02-03 CVE-2013-1573 Improper Input Validation vulnerability in Wireshark
The csnStreamDissector function in epan/dissectors/packet-csn1.c in the CSN.1 dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly handle a large number of padding bits, which allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.
2.9