Vulnerabilities > Wireshark > Low
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2013-03-07 | CVE-2013-2475 | Denial of Service vulnerability in Wireshark TCP Dissector The TCP dissector in Wireshark 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (application crash) via a malformed packet. | 3.3 |
2013-03-07 | CVE-2013-2477 | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products The CSN.1 dissector in Wireshark 1.8.x before 1.8.6 does not properly manage function pointers, which allows remote attackers to cause a denial of service (application crash) via a malformed packet. | 3.3 |
2013-03-07 | CVE-2013-2478 | Numeric Errors vulnerability in multiple products The dissect_server_info function in epan/dissectors/packet-ms-mms.c in the MS-MMS dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 does not properly manage string lengths, which allows remote attackers to cause a denial of service (application crash) via a malformed packet that (1) triggers an integer overflow or (2) has embedded '\0' characters in a string. | 3.3 |
2013-03-07 | CVE-2013-2479 | Denial of Service vulnerability in Wireshark MPLS Echo Dissector The dissect_mpls_echo_tlv_dd_map function in epan/dissectors/packet-mpls-echo.c in the MPLS Echo dissector in Wireshark 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (infinite loop) via invalid Sub-tlv data. | 3.3 |
2013-03-07 | CVE-2013-2480 | Denial of Service vulnerability in Wireshark RTPS And RTPS2 Dissectors The RTPS and RTPS2 dissectors in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allow remote attackers to cause a denial of service (application crash) via a malformed packet. | 3.3 |
2013-03-07 | CVE-2013-2481 | Numeric Errors vulnerability in multiple products Integer signedness error in the dissect_mount_dirpath_call function in epan/dissectors/packet-mount.c in the Mount dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6, when nfs_file_name_snooping is enabled, allows remote attackers to cause a denial of service (application crash) via a negative length value. | 2.9 |
2013-03-07 | CVE-2013-2483 | Numeric Errors vulnerability in multiple products The acn_add_dmp_data function in epan/dissectors/packet-acn.c in the ACN dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via an invalid count value in ACN_DMP_ADT_D_RE DMP data. | 3.3 |
2013-03-07 | CVE-2013-2484 | Denial of Service vulnerability in Wireshark CIMD Dissector The CIMD dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (application crash) via a malformed packet. | 3.3 |
2013-02-03 | CVE-2013-1572 | Improper Input Validation vulnerability in Wireshark The dissect_oampdu_event_notification function in epan/dissectors/packet-slowprotocols.c in the IEEE 802.3 Slow Protocols dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly handle certain short lengths, which allows remote attackers to cause a denial of service (infinite loop) via a malformed packet. | 2.9 |
2013-02-03 | CVE-2013-1573 | Improper Input Validation vulnerability in Wireshark The csnStreamDissector function in epan/dissectors/packet-csn1.c in the CSN.1 dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly handle a large number of padding bits, which allows remote attackers to cause a denial of service (infinite loop) via a malformed packet. | 2.9 |