Show filters
97 Total Results
Displaying 71-80 of 97
Sort by:
Attacker Value
Unknown
CVE-2016-2532
Disclosure Date: February 28, 2016 (last updated November 08, 2023)
The dissect_llrp_parameters function in epan/dissectors/packet-llrp.c in the LLRP dissector in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 does not limit the recursion depth, which allows remote attackers to cause a denial of service (memory consumption or application crash) via a crafted packet.
0
Attacker Value
Unknown
CVE-2016-2527
Disclosure Date: February 28, 2016 (last updated November 08, 2023)
wiretap/nettrace_3gpp_32_423.c in the 3GPP TS 32.423 Trace file parser in Wireshark 2.0.x before 2.0.2 does not ensure that a '\0' character is present at the end of certain strings, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted file.
0
Attacker Value
Unknown
CVE-2016-2521
Disclosure Date: February 28, 2016 (last updated November 08, 2023)
Untrusted search path vulnerability in the WiresharkApplication class in ui/qt/wireshark_application.cpp in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 on Windows allows local users to gain privileges via a Trojan horse riched20.dll.dll file in the current working directory, related to use of QLibrary.
0
Attacker Value
Unknown
CVE-2016-2525
Disclosure Date: February 28, 2016 (last updated November 08, 2023)
epan/dissectors/packet-http2.c in the HTTP/2 dissector in Wireshark 2.0.x before 2.0.2 does not limit the amount of header data, which allows remote attackers to cause a denial of service (memory consumption or application crash) via a crafted packet.
0
Attacker Value
Unknown
CVE-2015-8731
Disclosure Date: January 04, 2016 (last updated November 08, 2023)
The dissct_rsl_ipaccess_msg function in epan/dissectors/packet-rsl.c in the RSL dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not reject unknown TLV types, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet.
0
Attacker Value
Unknown
CVE-2015-8738
Disclosure Date: January 04, 2016 (last updated November 08, 2023)
The s7comm_decode_ud_cpu_szl_subfunc function in epan/dissectors/packet-s7comm_szl_ids.c in the S7COMM dissector in Wireshark 2.0.x before 2.0.1 does not validate the list count in an SZL response, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted packet.
0
Attacker Value
Unknown
CVE-2015-8725
Disclosure Date: January 04, 2016 (last updated November 08, 2023)
The dissect_diameter_base_framed_ipv6_prefix function in epan/dissectors/packet-diameter.c in the DIAMETER dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the IPv6 prefix length, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted packet.
0
Attacker Value
Unknown
CVE-2015-8739
Disclosure Date: January 04, 2016 (last updated November 08, 2023)
The ipmi_fmt_udpport function in epan/dissectors/packet-ipmi.c in the IPMI dissector in Wireshark 2.0.x before 2.0.1 improperly attempts to access a packet scope, which allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted packet.
0
Attacker Value
Unknown
CVE-2015-8734
Disclosure Date: January 04, 2016 (last updated November 08, 2023)
The dissect_nwp function in epan/dissectors/packet-nwp.c in the NWP dissector in Wireshark 2.0.x before 2.0.1 mishandles the packet type, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
0
Attacker Value
Unknown
CVE-2015-8732
Disclosure Date: January 04, 2016 (last updated November 08, 2023)
The dissect_zcl_pwr_prof_pwrprofstatersp function in epan/dissectors/packet-zbee-zcl-general.c in the ZigBee ZCL dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the Total Profile Number field, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet.
0