Show filters
59 Total Results
Displaying 1-10 of 59
Sort by:
Attacker Value
Unknown
CVE-2013-4074
Disclosure Date: June 09, 2013 (last updated October 05, 2023)
The dissect_capwap_data function in epan/dissectors/packet-capwap.c in the CAPWAP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x before 1.8.8 incorrectly uses a -1 data value to represent an error condition, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
0
Attacker Value
Unknown
CVE-2013-4083
Disclosure Date: June 09, 2013 (last updated October 05, 2023)
The dissect_pft function in epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark 1.6.x before 1.6.16, 1.8.x before 1.8.8, and 1.10.0 does not validate a certain fragment length value, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
0
Attacker Value
Unknown
CVE-2013-4081
Disclosure Date: June 09, 2013 (last updated October 05, 2023)
The http_payload_subdissector function in epan/dissectors/packet-http.c in the HTTP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x before 1.8.8 does not properly determine when to use a recursive approach, which allows remote attackers to cause a denial of service (stack consumption) via a crafted packet.
0
Attacker Value
Unknown
CVE-2013-3556
Disclosure Date: May 25, 2013 (last updated October 05, 2023)
The fragment_add_seq_common function in epan/reassemble.c in the ASN.1 BER dissector in Wireshark before r48943 has an incorrect pointer dereference during a comparison, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.
0
Attacker Value
Unknown
CVE-2013-3557
Disclosure Date: May 25, 2013 (last updated October 05, 2023)
The dissect_ber_choice function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.6.x before 1.6.15 and 1.8.x before 1.8.7 does not properly initialize a certain variable, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.
0
Attacker Value
Unknown
CVE-2013-2478
Disclosure Date: March 07, 2013 (last updated October 05, 2023)
The dissect_server_info function in epan/dissectors/packet-ms-mms.c in the MS-MMS dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 does not properly manage string lengths, which allows remote attackers to cause a denial of service (application crash) via a malformed packet that (1) triggers an integer overflow or (2) has embedded '\0' characters in a string.
0
Attacker Value
Unknown
CVE-2013-2480
Disclosure Date: March 07, 2013 (last updated October 05, 2023)
The RTPS and RTPS2 dissectors in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allow remote attackers to cause a denial of service (application crash) via a malformed packet.
0
Attacker Value
Unknown
CVE-2013-2488
Disclosure Date: March 07, 2013 (last updated October 05, 2023)
The DTLS dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 does not validate the fragment offset before invoking the reassembly state machine, which allows remote attackers to cause a denial of service (application crash) via a large offset value that triggers write access to an invalid memory location.
0
Attacker Value
Unknown
CVE-2013-2484
Disclosure Date: March 07, 2013 (last updated October 05, 2023)
The CIMD dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (application crash) via a malformed packet.
0
Attacker Value
Unknown
CVE-2013-2485
Disclosure Date: March 07, 2013 (last updated October 05, 2023)
The FCSP dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.
0