Show filters
32 Total Results
Displaying 1-10 of 32
Sort by:
Attacker Value
Unknown

CVE-2013-4074

Disclosure Date: June 09, 2013 (last updated October 05, 2023)
The dissect_capwap_data function in epan/dissectors/packet-capwap.c in the CAPWAP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x before 1.8.8 incorrectly uses a -1 data value to represent an error condition, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
0
Attacker Value
Unknown

CVE-2013-4083

Disclosure Date: June 09, 2013 (last updated October 05, 2023)
The dissect_pft function in epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark 1.6.x before 1.6.16, 1.8.x before 1.8.8, and 1.10.0 does not validate a certain fragment length value, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
0
Attacker Value
Unknown

CVE-2013-4081

Disclosure Date: June 09, 2013 (last updated October 05, 2023)
The http_payload_subdissector function in epan/dissectors/packet-http.c in the HTTP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x before 1.8.8 does not properly determine when to use a recursive approach, which allows remote attackers to cause a denial of service (stack consumption) via a crafted packet.
0
Attacker Value
Unknown

CVE-2013-3556

Disclosure Date: May 25, 2013 (last updated October 05, 2023)
The fragment_add_seq_common function in epan/reassemble.c in the ASN.1 BER dissector in Wireshark before r48943 has an incorrect pointer dereference during a comparison, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.
0
Attacker Value
Unknown

CVE-2013-3557

Disclosure Date: May 25, 2013 (last updated October 05, 2023)
The dissect_ber_choice function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.6.x before 1.6.15 and 1.8.x before 1.8.7 does not properly initialize a certain variable, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.
0
Attacker Value
Unknown

CVE-2013-2478

Disclosure Date: March 07, 2013 (last updated October 05, 2023)
The dissect_server_info function in epan/dissectors/packet-ms-mms.c in the MS-MMS dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 does not properly manage string lengths, which allows remote attackers to cause a denial of service (application crash) via a malformed packet that (1) triggers an integer overflow or (2) has embedded '\0' characters in a string.
0
Attacker Value
Unknown

CVE-2013-2480

Disclosure Date: March 07, 2013 (last updated October 05, 2023)
The RTPS and RTPS2 dissectors in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allow remote attackers to cause a denial of service (application crash) via a malformed packet.
0
Attacker Value
Unknown

CVE-2013-2488

Disclosure Date: March 07, 2013 (last updated October 05, 2023)
The DTLS dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 does not validate the fragment offset before invoking the reassembly state machine, which allows remote attackers to cause a denial of service (application crash) via a large offset value that triggers write access to an invalid memory location.
0
Attacker Value
Unknown

CVE-2013-2484

Disclosure Date: March 07, 2013 (last updated October 05, 2023)
The CIMD dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (application crash) via a malformed packet.
0
Attacker Value
Unknown

CVE-2013-2485

Disclosure Date: March 07, 2013 (last updated October 05, 2023)
The FCSP dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.
0