Vulnerabilities > Wireshark > Wireshark > 1.0

DATE CVE VULNERABILITY TITLE RISK
2008-10-22 CVE-2008-4683 Resource Management Errors vulnerability in Wireshark
The dissect_btacl function in packet-bthci_acl.c in the Bluetooth ACL dissector in Wireshark 0.99.2 through 1.0.3 allows remote attackers to cause a denial of service (application crash or abort) via a packet with an invalid length, related to an erroneous tvb_memcpy call.
network
low complexity
wireshark CWE-399
5.0
2008-10-22 CVE-2008-4682 Improper Input Validation vulnerability in Wireshark
wtap.c in Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a denial of service (application abort) via a malformed Tamos CommView capture file (aka .ncf file) with an "unknown/unexpected packet type" that triggers a failed assertion.
network
low complexity
wireshark CWE-20
5.0
2008-10-22 CVE-2008-4681 Improper Input Validation vulnerability in Wireshark
Unspecified vulnerability in the Bluetooth RFCOMM dissector in Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a denial of service (application crash or abort) via unknown packets.
network
wireshark CWE-20
4.3
2008-10-22 CVE-2008-4680 Resource Management Errors vulnerability in Wireshark
packet-usb.c in the USB dissector in Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a denial of service (application crash or abort) via a malformed USB Request Block (URB).
network
wireshark CWE-399
4.3
2008-09-02 CVE-2008-3146 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Wireshark
Multiple buffer overflows in packet_ncp2222.inc in Wireshark (formerly Ethereal) 0.9.7 through 1.0.2 allow attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted NCP packet that causes an invalid pointer to be used.
network
low complexity
wireshark CWE-119
critical
10.0
2008-07-16 CVE-2008-3145 Improper Input Validation vulnerability in Wireshark
The fragment_add_work function in epan/reassemble.c in Wireshark 0.8.19 through 1.0.1 allows remote attackers to cause a denial of service (crash) via a series of fragmented packets with non-sequential fragmentation offset values, which lead to a buffer over-read.
network
low complexity
wireshark CWE-20
5.0
2008-07-10 CVE-2008-3141 Information Exposure vulnerability in Wireshark
Unspecified vulnerability in the RMI dissector in Wireshark (formerly Ethereal) 0.9.5 through 1.0.0 allows remote attackers to read system memory via unspecified vectors.
local
low complexity
wireshark CWE-200
4.9
2008-07-10 CVE-2008-3139 Information Exposure vulnerability in multiple products
The RTMPT dissector in Wireshark (formerly Ethereal) 0.99.8 through 1.0.0 allows remote attackers to cause a denial of service (crash) via unknown vectors.
network
low complexity
rpath wireshark CWE-200
5.0
2008-07-10 CVE-2008-3138 Information Exposure vulnerability in multiple products
The (1) PANA and (2) KISMET dissectors in Wireshark (formerly Ethereal) 0.99.3 through 1.0.0 allow remote attackers to cause a denial of service (application stop) via unknown vectors.
network
low complexity
rpath wireshark CWE-200
5.0
2008-07-10 CVE-2008-3137 Improper Input Validation vulnerability in Wireshark
The GSM SMS dissector in Wireshark (formerly Ethereal) 0.99.2 through 1.0.0 allows remote attackers to cause a denial of service (application crash) via unknown vectors.
network
wireshark CWE-20
4.3