| OSVDB ID | Disclosure Date | Title |
|
56021
Description:
Wireshark contains a flaw that may allow a remote denial of service. The issue is triggered when the MIOP dissector processes packets with malformed Unique ID lengths (>=256 bytes), and will result in loss of availability for the service.
|
2009-07-20
|
Wireshark MIOP Dissector Unspecified DoS
|
|
82100
Description:
Wireshark contains a flaw that may allow a remote denial of service. The issue is triggered by a misaligned memory error in SPARC and Itanium processors when parsing certain packets, and will result in loss of availability for the program.
|
2012-05-23
|
Wireshark Misaligned Memory Packet Parsing Remote DoS
|
|
84782
Description:
Wireshark contains a flaw that may allow a remote denial of service. The issue is triggered when an error occurs in the MongoDB dissector during the parsing of a malformed packet. This will result in an infinite loop and a loss of availability for the program.
|
2012-08-15
|
Wireshark MongoDB Dissector Infinite Loop Malformed Packet Parsing Remote DoS
|
|
90996
Description:
Wireshark contains a flaw in the Mount Dissector that may allow a remote denial of service. The issue is triggered when handling a specific type of malformed packet, either via the network, or when replayed via a trace file. This may allow a remote attacker to crash the program.
|
2013-03-06
|
Wireshark Mount Dissector Malformed Packet Handling Remote DoS
|
|
27365
Description:
The Wireshark MOUNT dissector contains a flaw that may allow a remote denial of service. The issue is triggered by a malformed packet or trace file, and will result in loss of availability for the application.
|
2006-07-17
|
Wireshark MOUNT Dissector Memory Exhaustion DoS
|
|
80714
Description:
Wireshark contains a flaw that may allow a remote denial of service. The issue is triggered when a specially crafted packet causes an error in the MP2T dissector when handling memory, and will result in a loss of availability.
|
2012-03-27
|
Wireshark MP2T Dissector Malformed Packet Handling Memory Exhaustion Remote DoS
|
|
40466
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Wireshark (formerly Ethereal) allow remote attackers to cause a denial of service (crash) via (1) a crafted MP3 file or (2) unspecified vectors to the NCP dissector.
|
2007-11-26
|
Wireshark MP3 File Handling Unspecified Remote DoS
|
|
93507
Description:
Wireshark contains a flaw in the MPEG DSM-CC dissector that may allow a remote denial of service. The issue is triggered when handling a malformed packet. This may allow a remote attacker to crash the program.
|
2013-03-15
|
Wireshark MPEG DSM-CC Dissector Malformed Packet Handling Remote DoS
|
|
89667
Description:
Wireshark contains a flaw in the MPLS dissector that may allow a remote denial of service. The issue is triggered when the dissect_pw_eth_heuristic function in epan/dissectors/packet-pw-eth.c parses a specially crafted packet. This may allow a remote attacker to cause an infinite loop and crash the system.
|
2012-12-02
|
Wireshark MPLS Dissector epan/dissectors/packet-pw-eth.c dissect_pw_eth_heuristic Function Crafted Packet Parsing Infinite Loop Remote DoS
|
|
90994
Description:
Wireshark contains a flaw in the MPLS Echo Dissector that may allow a remote denial of service. The issue is triggered when handling a specific type of malformed packet, either via the network, or when replayed via a trace file. This may allow a remote attacker to cause an infinite loop, which will crash the program.
|
2013-03-06
|
Wireshark MPLS Echo Dissector Malformed Packet Handling Infinite Loop Remote DoS
|
|
27363
Description:
A format string flaw exists in the Wireshark MQ dissector. With a specially crafted packet, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2006-07-17
|
Wireshark MQ Dissector Format String Flaw
|
|
89675
Description:
Wireshark contains a flaw in the MS-MMC dissector that may allow a remote denial of service. The issue is triggered when a function in epan/tvbuff.c parses a malformed packet. This may allow a remote attacker to cause the program to crash.
|
2012-12-20
|
Wireshark MS-MMC Dissector epan/tvbuff.c Malformed Packet Parsing Remote DoS
|
|
90993
Description:
Wireshark contains a flaw in the MS-MMS Dissector that may allow a remote denial of service. The issue is triggered when handling a specific type of malformed packet, either via the network, or when replayed via a trace file. This may allow a remote attacker to crash the program.
|
2013-03-06
|
Wireshark MS-MMS Dissector Malformed Packet Handling Remote DoS
|
|
71552
Description:
Wireshark contains a flaw that may allow a remote of service. The issue is triggered when an attacker directs an infinite recursive function call to the 'dissect_ms_compressed_string' and 'dissect_mscldap_string' functions via a a crafted SMB orConnection-less LDAP (CLDAP) packet, resulting in a loss of availability.
|
2011-02-22
|
Wireshark Multiple Function CLDAP Packet Handling DoS
|
|
71553
Description:
Wireshark contains a flaw that may allow a remote of service. The issue is triggered when an attacker directs an infinite recursive function call to the 'dissect_ms_compressed_string' and 'dissect_mscldap_string' functions via a a crafted SMB packet, resulting in a loss of availability.
|
2011-02-22
|
Wireshark Multiple Function SMB Packet Handling DoS
|
|
49344
Description:
(Description Provided by CVE) : packet-frame in Wireshark 0.99.2 through 1.0.3 does not properly handle exceptions thrown by post dissectors, which allows remote attackers to cause a denial of service (application crash) via a certain series of packets, as demonstrated by enabling the (1) PRP or (2) MATE post dissector.
|
2008-10-20
|
Wireshark Multiple Post Dissector packet-frame Remote DoS
|
|
93505
Description:
Wireshark contains a flaw in the MySQL dissector (packet-mysql.c) that may allow a remote denial of service. The issue is triggered when handling a malformed packet, which will result in an infinite loop. This will allow a remote attacker to crash the program.
|
2013-03-10
|
Wireshark MySQL Dissector (packet-mysql.c) Malformed Packet Handling Infinite Loop Remote DoS
|
|
47931
Description:
(Description Provided by CVE) : Multiple buffer overflows in packet_ncp2222.inc in Wireshark (formerly Ethereal) 0.9.7 through 1.0.2 allow attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted NCP packet that causes an invalid pointer to be used.
|
2008-09-03
|
Wireshark NCP Dissector Multiple Unspecified Overflows
|
|
47932
Description:
(Description Provided by CVE) : Wireshark (formerly Ethereal) 0.9.7 through 1.0.2 allows attackers to cause a denial of service (hang) via a crafted NCP packet that triggers an infinite loop.
|
2008-09-03
|
Wireshark NCP Dissector Unspecified Infinite Loop DoS
|
|
27366
Description:
A remote overflow exists in the Wireshark NCP dissector. The application fails to properly iterate over a buffer resulting in a off-by-one overflow. With a specially crafted packet, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2006-07-17
|
Wireshark NCP Dissector Unspecified Off-by-one
|
|
40465
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Wireshark (formerly Ethereal) allow remote attackers to cause a denial of service (crash) via (1) a crafted MP3 file or (2) unspecified vectors to the NCP dissector.
|
2007-11-26
|
Wireshark NCP Dissector Unspecified Remote DoS
|
|
27368
Description:
A remote overflow exists in the Wireshark NDPS dissector. The application fails to properly iterate over a buffer resulting in a off-by-one overflow. With a specially crafted packet, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2006-07-17
|
Wireshark NDPS Dissector Unspecified Off-by-one
|
|
84261
Description:
Wireshark contains a flaw that may allow a remote denial of service. The issue is triggered when an error occurs in the NFS dissecotr when parsing a malformed packet, and will result in a consumption of resources and a loss of availability for the program.
|
2012-05-02
|
Wireshark NFS Dissector Malformed Packet Parsing Resource Consumption Remote DoS
|
|
27371
Description:
A remote overflow exists in the Wireshark NFS dissector. The dissector fails to perform proper bounds checking resulting in a buffer overflow. With a specially crafted packet, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2006-07-17
|
Wireshark NFS Dissector Unspecified Remote Overflow
|
|
27367
Description:
A remote overflow exists in the Wireshark NMAS dissector. The application fails to properly iterate over a buffer resulting in a off-by-one overflow. With a specially crafted packet, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2006-07-17
|
Wireshark NMAS Dissector Unspecified Off-by-one
|
|
71554
Description:
Wireshark is prone to an overflow condition. The wiretap/dct3trace.c process fails to properly sanitize user-supplied input resulting in a heap-based buffer overflow. With a specially crafted long record in a Nokia DCT3 trace file, a context-dependent attacker can potentially execute arbitrary code.
|
2011-03-01
|
Wireshark Nokia DCT3 Trace File Handling Overflow
|
|
89681
Description:
Wireshark contains a buffer overflow condition in the NTLMSSP dissector. The issue is triggered as user-supplied input is not properly validated when parsing a specially crafted packet. This may allow a remote attacker to cause a buffer overflow, resulting in a denial of service or potentially execution of arbitrary code.
|
2013-01-29
|
Wireshark NTLMSSP Dissector Crafted Packet Parsing Remote Buffer Overflow
|
|
71548
Description:
Wireshark contains a flaw that may allow a denial of service. The issue is triggered when the 'dissect_ntlmssp_string()' function in 'epan/dissectors/packet-ntlmssp.c' suffers a NULL pointer dereference error, allowing a context-dependent attacker to use a crafted pcap file to cause a denial of service.
|
2011-03-01
|
Wireshark NTLMSSP Dissector PCAP File Handling DoS
|
|
27369
Description:
A format string flaw exists in the Wireshark NTP dissector. With a specially crafted packet, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2006-07-17
|
Wireshark NTP Dissector Format String Flaw
|
|
76769
Description:
(Description Provided by CVE) : The dissect_infiniband_common function in epan/dissectors/packet-infiniband.c in the Infiniband dissector in Wireshark 1.4.0 through 1.4.9 and 1.6.x before 1.6.3 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed packet.
|
2011-11-01
|
Wireshark NULL Dereference Infiniband Dissector Remote DoS
|