Vulnerabilities (CVE)

Filtered by vendor Wireshark Subscribe
Total 735 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-3628 2 Ethereal Group, Wireshark 2 Ethereal, Wireshark 2026-04-16 10.0 HIGH N/A
Multiple format string vulnerabilities in Wireshark (aka Ethereal) 0.10.x to 0.99.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) ANSI MAP, (2) Checkpoint FW-1, (3) MQ, (4) XML, and (5) NTP dissectors.
CVE-2006-4330 1 Wireshark 1 Wireshark 2026-04-16 4.3 MEDIUM N/A
Unspecified vulnerability in the SCSI dissector in Wireshark (formerly Ethereal) 0.99.2 allows remote attackers to cause a denial of service (crash) via unspecified vectors.
CVE-2006-4331 1 Wireshark 1 Wireshark 2026-04-16 5.0 MEDIUM N/A
Multiple off-by-one errors in the IPSec ESP preference parser in Wireshark (formerly Ethereal) 0.99.2 allow remote attackers to cause a denial of service (crash) via unspecified vectors.
CVE-2006-4333 1 Wireshark 1 Wireshark 2026-04-16 5.4 MEDIUM N/A
The SSCOP dissector in Wireshark (formerly Ethereal) before 0.99.3 allows remote attackers to cause a denial of service (resource consumption) via malformed packets that cause the Q.2391 dissector to use excessive memory.
CVE-2026-3201 1 Wireshark 1 Wireshark 2026-02-26 N/A 4.7 MEDIUM
USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
CVE-2026-3202 1 Wireshark 1 Wireshark 2026-02-26 N/A 4.7 MEDIUM
NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of service
CVE-2026-3203 1 Wireshark 1 Wireshark 2026-02-26 N/A 5.5 MEDIUM
RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
CVE-2026-0960 1 Wireshark 1 Wireshark 2026-01-21 N/A 4.7 MEDIUM
HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of service
CVE-2026-0959 1 Wireshark 1 Wireshark 2026-01-21 N/A 5.3 MEDIUM
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
CVE-2026-0961 1 Wireshark 1 Wireshark 2026-01-21 N/A 5.5 MEDIUM
BLF file parser crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
CVE-2026-0962 1 Wireshark 1 Wireshark 2026-01-21 N/A 5.3 MEDIUM
SOME/IP-SD protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
CVE-2025-13499 1 Wireshark 1 Wireshark 2025-12-31 N/A 7.8 HIGH
Kafka dissector crash in Wireshark 4.6.0 and 4.4.0 to 4.4.10 allows denial of service
CVE-2025-13946 1 Wireshark 1 Wireshark 2025-12-31 N/A 5.5 MEDIUM
MEGACO dissector infinite loop in Wireshark 4.6.0 to 4.6.1 and 4.4.0 to 4.4.11 allows denial of service
CVE-2025-9817 1 Wireshark 1 Wireshark 2025-12-05 N/A 7.8 HIGH
SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial of service
CVE-2025-13945 1 Wireshark 1 Wireshark 2025-12-05 N/A 5.5 MEDIUM
HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service
CVE-2025-13674 1 Wireshark 1 Wireshark 2025-12-03 N/A 5.5 MEDIUM
BPv7 dissector crash in Wireshark 4.6.0 allows denial of service
CVE-2025-11626 1 Wireshark 1 Wireshark 2025-12-03 N/A 5.5 MEDIUM
MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13 allows denial of service
CVE-2025-5601 1 Wireshark 1 Wireshark 2025-11-21 N/A 7.8 HIGH
Column handling crashes in Wireshark 4.4.0 to 4.4.6 and 4.2.0 to 4.2.12 allows denial of service via packet injection or crafted capture file
CVE-2024-24479 2 Fedoraproject, Wireshark 2 Fedora, Wireshark 2025-11-04 N/A 7.5 HIGH
A Buffer Overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the wsutil/to_str.c, and format_fractional_part_nsecs components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.
CVE-2024-24476 2 Fedoraproject, Wireshark 2 Fedora, Wireshark 2025-11-04 N/A 7.5 HIGH
A buffer overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the pan/addr_resolv.c, and ws_manuf_lookup_str(), size components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.