| OSVDB ID | Disclosure Date | Title |
|
85971
Description:
WireShark is prone to an overflow condition. The remote interface fails to properly sanitize user-supplied input passed via the host input and port input fields, which will result in an overflow. This may allow a remote attacker to potentially execute arbitrary code.
|
2012-08-24
|
WireShark Remote Interface Addition Multiple Field Overflow
|
|
78257
Description:
Wireshark contains an overflow condition in the RLC dissector component. The issue is triggered as user-supplied input is not properly validated when handling RLC packet capture files. With a specially crafted capture file, a context-dependent attacker can cause a buffer overflow, resulting in a denial of service or potentially execution of arbitrary code.
|
2012-01-11
|
Wireshark RLC Packet Capture File Handling Remote Overflow
|
|
46650
Description:
(Description Provided by CVE) : Unspecified vulnerability in the RMI dissector in Wireshark (formerly Ethereal) 0.9.5 through 1.0.0 allows remote attackers to read system memory via unspecified vectors.
|
2008-06-30
|
Wireshark RMI Dissector Unspecified System Memory Disclosure
|
|
89664
Description:
Wireshark contains a flaw in the ROHC dissector that may allow a remote denial of service. The issue is triggered when parsing a specially crafted packet by the dissect_rohc_ir_packet function in epan/dissectors/packet-rohc.c . This may allow a remote attacker to cause the program to crash.
|
2012-08-29
|
Wireshark ROHC Dissector epan/dissectors/packet-rohc.c dissect_rohc_ir_packet Function Malformed Packet Parsing Remote DoS
|
|
43839
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Wireshark (formerly Ethereal) 0.99.5 through 0.99.8 allow remote attackers to cause a denial of service (application crash) via a malformed packet to the (1) X.509sat or (2) Roofnet dissectors. NOTE: Vector 2 might also lead to a hang.
|
2008-03-29
|
Wireshark Roofnet Dissector Unspecified DoS
|
|
40459
Description:
(Description Provided by CVE) : The RPL dissector in Wireshark (formerly Ethereal) 0.9.8 to 0.99.6 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.
|
2007-11-26
|
Wireshark RPL Dissector Unspecified Remote Infinite Loop DoS
|
|
87990
Description:
Wireshark contains a flaw that may allow a remote denial of service. The issue is triggered when an error occurs in the RTCP dissector during the processing of a malformed packet or when viewing a trace file containing malformed traffic. This will cause an infinite loop, which will result in a loss of availability.
|
2012-11-28
|
Wireshark RTCP Dissector Malformed Packet Processing Infinite Loop Remote DoS
|
|
46649
Description:
(Description Provided by CVE) : The RTMPT dissector in Wireshark (formerly Ethereal) 0.99.8 through 1.0.0 allows remote attackers to cause a denial of service (crash) via unknown vectors. NOTE: this might be due to a use-after-free error.
|
2008-06-30
|
Wireshark RTMPT Dissector Unspecified DoS
|
|
89677
Description:
Wireshark contains a flaw in the RTPS dissector that may allow for a denial of service. The issue is triggered when the rtps_util_add_bitmap function in epan/dissectors/packet-rtps.c parses a specially crafted packet. This may allow a remote attacker to cause an infinite loop and crash the system.
|
2013-01-12
|
Wireshark RTPS Dissector epan/dissectors/packet-rtps.c rtps_util_add_bitmap Function Crafted Packet Parsing Infinite Loop Remote DoS
|
|
90995
Description:
Wireshark contains a flaw in the RTPS Dissector that may allow a remote denial of service. The issue is triggered when handling a specific type of malformed packet, either via the network, or when replayed via a trace file. This may allow a remote attacker to crash the program.
|
2013-03-06
|
Wireshark RTPS Dissector Malformed Packet Handling Remote DoS
|
|
90991
Description:
Wireshark contains a flaw in the RTPS2 Dissector that may allow a remote denial of service. The issue is triggered when handling a specific type of malformed packet, either via the network, or when replayed via a trace file. This may allow a remote attacker to crash the program.
|
2013-03-06
|
Wireshark RTPS2 Dissector Malformed Packet Handling Remote DoS
|
|
84778
Description:
Wireshark is prone to an overflow condition. The RTPS2 dissector fails to properly sanitize user-supplied input resulting in a buffer overflow. With a specially crafted packet, a remote attacker can potentially execute arbitrary code or cause a denial of service.
|
2012-08-15
|
Wireshark RTPS2 Dissector Malformed Packet Parsing Overflow
|
|
43841
Description:
(Description Provided by CVE) : The "decode as" feature in packet-bssap.c in the SCCP dissector in Wireshark (formerly Ethereal) 0.99.6 through 0.99.8 allows remote attackers to cause a denial of service (application crash) via a malformed packet.
|
2008-03-29
|
Wireshark SCCP Dissector Decode As Feature Unspecified DoS
|
|
61648
Description:
Unknown / Incomplete
|
2009-05-21
|
Wireshark SCCP Dissector Unspecified Issue
|
|
28196
Description:
(Description Provided by CVE) : Unspecified vulnerability in the SCSI dissector in Wireshark (formerly Ethereal) 0.99.2 allows remote attackers to cause a denial of service (crash) via unspecified vectors.
|
2006-08-23
|
Wireshark SCSI Dissector Unspecified DoS
|
|
42575
Description:
Wireshark SCTP dissector contains a flaw that may allow a remote denial of service. The issue is triggered when malformed packets or trace files are loaded, and will result in loss of availability for the service.
|
2008-02-27
|
Wireshark SCTP Dissector Malformed Packet Handling Remote DoS
|
|
87995
Description:
Wireshark contains a flaw that may allow a remote denial of service. The issue is triggered when an error occurs in the SCTP dissector during the processing of a malformed packet or when viewing a trace file containing malformed traffic. This will cause an infinite loop, which will result in a loss of availability.
|
2012-11-28
|
Wireshark SCTP Dissector Malformed Packet Processing Infinite Loop Remote DoS
|
|
89669
Description:
Wireshark contains a flaw in the SDP dissector that may allow a remote denial of service. The issue is triggered when the dissect_sdp_media_attribute function in epan/dissectors/packet-sdp.c parses a specially crafted packet. This may allow a remote attacker to cause an infinite loop and crash the system.
|
2012-12-02
|
Wireshark SDP Dissector epan/dissectors/packet-sdp.c dissect_sdp_media_attribute Function Crafted Packet Parsing Infinite Loop Remote DoS
|
|
87996
Description:
Wireshark contains a flaw that may allow a remote denial of service. The issue is triggered when an error occurs in the sFlow dissector during the processing of a malformed packet or when viewing a trace file containing malformed traffic. This will cause an infinite loop, which will result in a loss of availability.
|
2012-11-28
|
Wireshark sFlow Dissector Malformed Packet Processing Infinite Loop Remote DoS
|
|
56022
Description:
Wireshark contains a flaw that may allow a remote denial of service. The issue is triggered when the sFlow dissector processes packets with more than 1,000,000 items in the tree, and will result in loss of availability for the service.
|
2009-07-20
|
Wireshark sFlow Dissector Unspecified Memory/CPU Consumption DoS
|
|
65374
Description:
(Description Provided by CVE) : The SigComp Universal Decompressor Virtual Machine dissector in Wireshark 0.10.7 through 1.0.13 and 1.2.0 through 1.2.8 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.
|
2010-06-10
|
Wireshark SigComp Universal Decompressor Virtual Machine Infinite Loop DoS
|
|
65375
Description:
(Description Provided by CVE) : Buffer overflow in the SigComp Universal Decompressor Virtual Machine dissector in Wireshark 0.10.8 through 1.0.13 and 1.2.0 through 1.2.8 has unknown impact and remote attack vectors.
|
2010-06-10
|
Wireshark SigComp Universal Decompressor Virtual Machine Overflow
|
|
67191
Description:
(Description Provided by CVE) : The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0.10.8 through 1.0.14 and 1.2.0 through 1.2.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to sigcomp-udvm.c and an off-by-one error, which triggers a buffer overflow, different vulnerabilities than CVE-2010-2287.
|
2010-06-11
|
Wireshark SigComp Universal Decompressor Virtual Machine sigcomp-udvm.c Off-by-one Overflow
|
|
89668
Description:
Wireshark contains a flaw in the SIP dissector that may allow a remote denial of service. The issue is triggered when the dissect_sip_p_charging_func_addresses function in epan/dissectors/packet-sip.c parses a specially crafted packet. This may allow a remote attacker to cause an infinite loop and crash the system.
|
2012-12-02
|
Wireshark SIP Dissector epan/dissectors/packet-sip.c dissect_sip_p_charging_func_addresses Function Crafted Packet Parsing Infinite Loop Remote DoS
|
|
61178
Description:
(Description Provided by CVE) : The (1) SMB and (2) SMB2 dissectors in Wireshark 0.9.0 through 1.2.4 allow remote attackers to cause a denial of service (crash) via a crafted packet that triggers a NULL pointer dereference, as demonstrated by fuzz-2009-12-07-11141.pcap.
|
2009-12-17
|
Wireshark SMB / SMB2 Dissector Remote DoS
|
|
65371
Description:
(Description Provided by CVE) : The SMB dissector in Wireshark 0.99.6 through 1.0.13, and 1.2.0 through 1.2.8 allows remote attackers to cause a denial of service (NULL pointer dereference) via unknown vectors.
|
2010-06-10
|
Wireshark SMB Dissector NULL Dereference DoS
|
|
59458
Description:
Wireshark contains a flaw that may allow a remote denial of service. The issue is triggered when off-by-one error within the dissect_negprot_response() function in epan/dissectors/packet-smb.c of the SMB dissector occurs, and will result in loss of availability for the service.
|
2009-10-26
|
Wireshark SMB Dissector Unspecified DoS
|
|
40463
Description:
(Description Provided by CVE) : Unspecified vulnerability in the SMB dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service via unknown vectors. NOTE: this identifier originally included MP3 and NCP, but those issues are already covered by CVE-2007-6111.
|
2007-11-26
|
Wireshark SMB Dissector Unspecified Remote DoS
|
|
65373
Description:
(Description Provided by CVE) : The SMB PIPE dissector in Wireshark 0.8.20 through 1.0.13 and 1.2.0 through 1.2.8 allows remote attackers to cause a denial of service (NULL pointer dereference) via unknown vectors.
|
2010-06-10
|
Wireshark SMB PIPE Dissector NULL Dereference DoS
|
|
50069
Description:
(Description Provided by CVE) : Wireshark 1.0.4 and earlier allows remote attackers to cause a denial of service via a long SMTP request, which triggers an infinite loop.
|
2008-11-22
|
Wireshark SMTP Dissector Packet Handling Infinite Loop DoS
|