<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Wireshark (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/wireshark.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/wireshark-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Wireshark (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:41 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-7785 – A security flaw has been discovered in A-G-U-P-T-A wireshark-mcp edaf604416fbc94...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7785</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7785</guid>
    <pubDate>Tue, 05 May 2026 00:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7785</strong></p>
  <p>A security flaw has been discovered in A-G-U-P-T-A wireshark-mcp edaf604416fbc94a201b4043092d4a1b09a12275/400c3da70074f22f3cce7ccb65304cafc7089c89. This affects the function quick_capture of the file pyshark_mcp.py. The manipulation results in os command injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. This product operates o…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7785">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5656 – Profile import path traversal in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5656</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5656</guid>
    <pubDate>Fri, 01 May 2026 00:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5656</strong></p>
  <p>Profile import path traversal in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5656">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5405 – RDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5405</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5405</guid>
    <pubDate>Fri, 01 May 2026 00:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5405</strong></p>
  <p>RDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5405">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5403 – SBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5403</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5403</guid>
    <pubDate>Fri, 01 May 2026 00:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5403</strong></p>
  <p>SBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5403">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5402 – TLS protocol dissector heap overflow in Wireshark 4.6.0 to 4.6.4 allows denial o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5402</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5402</guid>
    <pubDate>Thu, 30 Apr 2026 07:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5402</strong></p>
  <p>TLS protocol dissector heap overflow in Wireshark 4.6.0 to 4.6.4 allows denial of service and possible code execution</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5402">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-24060 – Service information is not encrypted when transmitted as BACnet packets 
over th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24060</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24060</guid>
    <pubDate>Sat, 21 Mar 2026 00:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-24060</strong></p>
  <p>Service information is not encrypted when transmitted as BACnet packets  over the wire, and can be sniffed, intercepted, and modified by an  attacker. Valuable information such as the File Start Position and File  Data can be sniffed from network traffic using Wireshark's BACnet  dissector filter. The proprietary format used by WebCTRL to receive  updates from the PLC can also be sniffed and reve…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24060">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13499 – Kafka dissector crash in Wireshark 4.6.0 and 4.4.0 to 4.4.10 allows denial of se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13499</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13499</guid>
    <pubDate>Fri, 21 Nov 2025 06:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13499</strong></p>
  <p>Kafka dissector crash in Wireshark 4.6.0 and 4.4.0 to 4.4.10 allows denial of service</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-824</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13499">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-9817 – SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial of service</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9817</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9817</guid>
    <pubDate>Wed, 03 Sep 2025 08:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-9817</strong></p>
  <p>SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial of service</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9817">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-5601 – Column handling crashes in Wireshark 4.4.0 to 4.4.6 and 4.2.0 to 4.2.12 allows d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-5601</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-5601</guid>
    <pubDate>Wed, 04 Jun 2025 11:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-5601</strong></p>
  <p>Column handling crashes in Wireshark 4.4.0 to 4.4.6 and 4.2.0 to 4.2.12 allows denial of service via packet injection or crafted capture file</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5601">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-1492 – Bundle Protocol and CBOR dissector crashes in Wireshark 4.4.0 to 4.4.3 and 4.2.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-1492</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-1492</guid>
    <pubDate>Thu, 20 Feb 2025 02:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-1492</strong></p>
  <p>Bundle Protocol and CBOR dissector crashes in Wireshark 4.4.0 to 4.4.3 and 4.2.0 to 4.2.10 allows denial of service via packet injection or crafted capture file</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-674</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1492">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-11596 – ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denia...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11596</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11596</guid>
    <pubDate>Thu, 21 Nov 2024 11:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-11596</strong></p>
  <p>ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-126</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11596">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-11595 – FiveCo RAP dissector infinite loop in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11595</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11595</guid>
    <pubDate>Thu, 21 Nov 2024 11:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-11595</strong></p>
  <p>FiveCo RAP dissector infinite loop in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11595">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-9781 – AppleTalk and RELOAD Framing dissector crash in Wireshark 4.4.0 and 4.2.0 to 4.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-9781</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-9781</guid>
    <pubDate>Thu, 10 Oct 2024 07:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-9781</strong></p>
  <p>AppleTalk and RELOAD Framing dissector crash in Wireshark 4.4.0 and 4.2.0 to 4.2.7 allows denial of service via packet injection or crafted capture file</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-230</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9781">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-9780 – ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-9780</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-9780</guid>
    <pubDate>Thu, 10 Oct 2024 07:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-9780</strong></p>
  <p>ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capture file</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-456</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9780">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-8250 – NTLMSSP dissector crash in Wireshark 4.2.0 to 4.0.6 and 4.0.0 to 4.0.16 allows d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8250</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8250</guid>
    <pubDate>Thu, 29 Aug 2024 00:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-8250</strong></p>
  <p>NTLMSSP dissector crash in Wireshark 4.2.0 to 4.0.6 and 4.0.0 to 4.0.16 allows denial of service via packet injection or crafted capture file</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-825</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8250">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-2955 – T.38 dissector crash in Wireshark 4.2.0 to 4.0.3 and 4.0.0 to 4.0.13 allows deni...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-2955</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-2955</guid>
    <pubDate>Tue, 26 Mar 2024 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-2955</strong></p>
  <p>T.38 dissector crash in Wireshark 4.2.0 to 4.0.3 and 4.0.0 to 4.0.13 allows denial of service via packet injection or crafted capture file</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-762</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2955">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-6175 – NetScreen file parser crash in Wireshark 4.0.0 to 4.0.10 and 3.6.0 to 3.6.18 all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6175</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6175</guid>
    <pubDate>Tue, 26 Mar 2024 08:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-6175</strong></p>
  <p>NetScreen file parser crash in Wireshark 4.0.0 to 4.0.10 and 3.6.0 to 3.6.18 allows denial of service via crafted capture file</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6175">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-24479 – A Buffer Overflow in Wireshark before 4.2.0 allows a remote attacker to cause a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-24479</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-24479</guid>
    <pubDate>Wed, 21 Feb 2024 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-24479</strong></p>
  <p>A Buffer Overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the wsutil/to_str.c, and format_fractional_part_nsecs components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24479">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-24476 – A buffer overflow in Wireshark before 4.2.0 allows a remote attacker to cause a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-24476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-24476</guid>
    <pubDate>Wed, 21 Feb 2024 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-24476</strong></p>
  <p>A buffer overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the pan/addr_resolv.c, and ws_manuf_lookup_str(), size components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-24478 – An issue in Wireshark before 4.2.0 allows a remote attacker to cause a denial of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-24478</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-24478</guid>
    <pubDate>Wed, 21 Feb 2024 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-24478</strong></p>
  <p>An issue in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the packet-bgp.c, dissect_bgp_open(tvbuff_t*tvb, proto_tree*tree, packet_info*pinfo), optlen components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-680</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24478">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-0211 – DOCSIS dissector crash in Wireshark 4.2.0 allows denial of service via packet in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0211</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0211</guid>
    <pubDate>Wed, 03 Jan 2024 08:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-0211</strong></p>
  <p>DOCSIS dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0211">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-0210 – Zigbee TLV dissector crash in Wireshark 4.2.0 allows denial of service via packe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0210</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0210</guid>
    <pubDate>Wed, 03 Jan 2024 08:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-0210</strong></p>
  <p>Zigbee TLV dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-674</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0210">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-0209 – IEEE 1609.2 dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0209</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0209</guid>
    <pubDate>Wed, 03 Jan 2024 08:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-0209</strong></p>
  <p>IEEE 1609.2 dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture file</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0209">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-0208 – GVCP dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0208</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0208</guid>
    <pubDate>Wed, 03 Jan 2024 08:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-0208</strong></p>
  <p>GVCP dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture file</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-230</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0208">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-0207 – HTTP3 dissector crash in Wireshark 4.2.0 allows denial of service via packet inj...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0207</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0207</guid>
    <pubDate>Wed, 03 Jan 2024 08:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-0207</strong></p>
  <p>HTTP3 dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0207">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-4190 – Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-4190</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-4190</guid>
    <pubDate>Thu, 30 Dec 2021 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-4190</strong></p>
  <p>Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service via packet injection or crafted capture file</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-834</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-4190">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-4185 – Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-4185</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-4185</guid>
    <pubDate>Thu, 30 Dec 2021 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-4185</strong></p>
  <p>Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-4185">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-4184 – Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-4184</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-4184</guid>
    <pubDate>Thu, 30 Dec 2021 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-4184</strong></p>
  <p>Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-4184">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-4182 – Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows de...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-4182</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-4182</guid>
    <pubDate>Thu, 30 Dec 2021 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-4182</strong></p>
  <p>Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-4182">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-4181 – Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-4181</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-4181</guid>
    <pubDate>Thu, 30 Dec 2021 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-4181</strong></p>
  <p>Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-4181">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-39929 – Uncontrolled Recursion in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-39929</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-39929</guid>
    <pubDate>Fri, 19 Nov 2021 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-39929</strong></p>
  <p>Uncontrolled Recursion in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-674</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39929">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-39926 – Buffer overflow in the Bluetooth HCI_ISO dissector in Wireshark 3.4.0 to 3.4.9 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-39926</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-39926</guid>
    <pubDate>Fri, 19 Nov 2021 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-39926</strong></p>
  <p>Buffer overflow in the Bluetooth HCI_ISO dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39926">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-39925 – Buffer overflow in the Bluetooth SDP dissector in Wireshark 3.4.0 to 3.4.9 and 3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-39925</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-39925</guid>
    <pubDate>Fri, 19 Nov 2021 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-39925</strong></p>
  <p>Buffer overflow in the Bluetooth SDP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39925">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-39924 – Large loop in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-39924</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-39924</guid>
    <pubDate>Fri, 19 Nov 2021 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-39924</strong></p>
  <p>Large loop in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-834</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39924">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-39923 – Large loop in the PNRP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-39923</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-39923</guid>
    <pubDate>Fri, 19 Nov 2021 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-39923</strong></p>
  <p>Large loop in the PNRP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-834</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39923">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-39922 – Buffer overflow in the C12.22 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-39922</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-39922</guid>
    <pubDate>Fri, 19 Nov 2021 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-39922</strong></p>
  <p>Buffer overflow in the C12.22 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39922">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-39921 – NULL pointer exception in the Modbus dissector in Wireshark 3.4.0 to 3.4.9 and 3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-39921</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-39921</guid>
    <pubDate>Fri, 19 Nov 2021 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-39921</strong></p>
  <p>NULL pointer exception in the Modbus dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39921">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-39928 – NULL pointer exception in the IEEE 802.11 dissector in Wireshark 3.4.0 to 3.4.9 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-39928</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-39928</guid>
    <pubDate>Thu, 18 Nov 2021 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-39928</strong></p>
  <p>NULL pointer exception in the IEEE 802.11 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39928">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-39920 – NULL pointer exception in the IPPUSB dissector in Wireshark 3.4.0 to 3.4.9 allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-39920</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-39920</guid>
    <pubDate>Thu, 18 Nov 2021 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-39920</strong></p>
  <p>NULL pointer exception in the IPPUSB dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39920">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22235 – Crash in DNP dissector in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 allows de...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22235</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22235</guid>
    <pubDate>Tue, 20 Jul 2021 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22235</strong></p>
  <p>Crash in DNP dissector in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 allows denial of service via packet injection or crafted capture file</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22235">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22222 – Infinite loop in DVB-S2-BB dissector in Wireshark 3.4.0 to 3.4.5 allows denial o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22222</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22222</guid>
    <pubDate>Mon, 07 Jun 2021 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22222</strong></p>
  <p>Infinite loop in DVB-S2-BB dissector in Wireshark 3.4.0 to 3.4.5 allows denial of service via packet injection or crafted capture file</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22222">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-28030 – In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-28030</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-28030</guid>
    <pubDate>Mon, 02 Nov 2020 21:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-28030</strong></p>
  <p>In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed in epan/dissectors/packet-gquic.c by correcting the implementation of offset advancement.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-682</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-28030">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-26575 – In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-26575</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-26575</guid>
    <pubDate>Tue, 06 Oct 2020 15:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-26575</strong></p>
  <p>In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector could enter an infinite loop. This was addressed in epan/dissectors/packet-fbzero.c by correcting the implementation of offset advancement.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-26575">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-25866 – In Wireshark 3.2.0 to 3.2.6 and 3.0.0 to 3.0.13, the BLIP protocol dissector has...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-25866</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-25866</guid>
    <pubDate>Tue, 06 Oct 2020 15:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-25866</strong></p>
  <p>In Wireshark 3.2.0 to 3.2.6 and 3.0.0 to 3.0.13, the BLIP protocol dissector has a NULL pointer dereference because a buffer was sized for compressed (not uncompressed) messages. This was addressed in epan/dissectors/packet-blip.c by allowing reasonable compression ratios and rejecting ZIP bombs.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25866">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-25863 – In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the MIME Mult...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-25863</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-25863</guid>
    <pubDate>Tue, 06 Oct 2020 15:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-25863</strong></p>
  <p>In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the MIME Multipart dissector could crash. This was addressed in epan/dissectors/packet-multipart.c by correcting the deallocation of invalid MIME parts.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25863">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-25862 – In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the TCP disse...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-25862</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-25862</guid>
    <pubDate>Tue, 06 Oct 2020 15:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-25862</strong></p>
  <p>In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by changing the handling of the invalid 0xFFFF checksum.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-354</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25862">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15466 – In Wireshark 3.2.0 to 3.2.4, the GVCP dissector could go into an infinite loop. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15466</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15466</guid>
    <pubDate>Sun, 05 Jul 2020 11:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15466</strong></p>
  <p>In Wireshark 3.2.0 to 3.2.4, the GVCP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-gvcp.c by ensuring that an offset increases in all situations.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15466">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-13164 – In Wireshark 3.2.0 to 3.2.3, 3.0.0 to 3.0.10, and 2.6.0 to 2.6.16, the NFS disse...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13164</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13164</guid>
    <pubDate>Tue, 19 May 2020 22:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-13164</strong></p>
  <p>In Wireshark 3.2.0 to 3.2.3, 3.0.0 to 3.0.10, and 2.6.0 to 2.6.16, the NFS dissector could crash. This was addressed in epan/dissectors/packet-nfs.c by preventing excessive recursion, such as for a cycle in the directory graph on a filesystem.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-674</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13164">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-11647 – In Wireshark 3.2.0 to 3.2.2, 3.0.0 to 3.0.9, and 2.6.0 to 2.6.15, the BACapp dis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11647</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11647</guid>
    <pubDate>Fri, 10 Apr 2020 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-11647</strong></p>
  <p>In Wireshark 3.2.0 to 3.2.2, 3.0.0 to 3.0.9, and 2.6.0 to 2.6.15, the BACapp dissector could crash. This was addressed in epan/dissectors/packet-bacapp.c by limiting the amount of recursion.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-674</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11647">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-9431 – In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the LTE RRC di...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9431</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9431</guid>
    <pubDate>Thu, 27 Feb 2020 23:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-9431</strong></p>
  <p>In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the LTE RRC dissector could leak memory. This was addressed in epan/dissectors/packet-lte-rrc.c by adjusting certain append operations.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9431">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-9430 – In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the WiMax DLMA...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9430</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9430</guid>
    <pubDate>Thu, 27 Feb 2020 23:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-9430</strong></p>
  <p>In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the WiMax DLMAP dissector could crash. This was addressed in plugins/epan/wimax/msg_dlmap.c by validating a length field.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9430">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-9429 – In Wireshark 3.2.0 to 3.2.1, the WireGuard dissector could crash. This was addre...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9429</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9429</guid>
    <pubDate>Thu, 27 Feb 2020 23:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-9429</strong></p>
  <p>In Wireshark 3.2.0 to 3.2.1, the WireGuard dissector could crash. This was addressed in epan/dissectors/packet-wireguard.c by handling the situation where a certain data structure intentionally has a NULL value.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9429">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-9428 – In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the EAP dissec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9428</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9428</guid>
    <pubDate>Thu, 27 Feb 2020 23:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-9428</strong></p>
  <p>In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the EAP dissector could crash. This was addressed in epan/dissectors/packet-eap.c by using more careful sscanf parsing.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9428">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7044 – In Wireshark 3.2.x before 3.2.1, the WASSP dissector could crash. This was addre...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7044</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7044</guid>
    <pubDate>Thu, 16 Jan 2020 04:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7044</strong></p>
  <p>In Wireshark 3.2.x before 3.2.1, the WASSP dissector could crash. This was addressed in epan/dissectors/packet-wassp.c by using >= and <= to resolve off-by-one errors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7044">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19553 – In Wireshark 3.0.0 to 3.0.6 and 2.6.0 to 2.6.12, the CMS dissector could crash. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19553</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19553</guid>
    <pubDate>Thu, 05 Dec 2019 01:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19553</strong></p>
  <p>In Wireshark 3.0.0 to 3.0.6 and 2.6.0 to 2.6.12, the CMS dissector could crash. This was addressed in epan/dissectors/asn1/cms/packet-cms-template.c by ensuring that an object identifier is set to NULL after a ContentInfo dissection.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-909</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19553">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-16319 – In Wireshark 3.0.0 to 3.0.3 and 2.6.0 to 2.6.10, the Gryphon dissector could go ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-16319</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-16319</guid>
    <pubDate>Sun, 15 Sep 2019 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-16319</strong></p>
  <p>In Wireshark 3.0.0 to 3.0.3 and 2.6.0 to 2.6.10, the Gryphon dissector could go into an infinite loop. This was addressed in plugins/epan/gryphon/packet-gryphon.c by checking for a message length of zero.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16319">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-13619 – In Wireshark 3.0.0 to 3.0.2, 2.6.0 to 2.6.9, and 2.4.0 to 2.4.15, the ASN.1 BER ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-13619</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-13619</guid>
    <pubDate>Wed, 17 Jul 2019 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-13619</strong></p>
  <p>In Wireshark 3.0.0 to 3.0.2, 2.6.0 to 2.6.9, and 2.4.0 to 2.4.15, the ASN.1 BER dissector and related dissectors could crash. This was addressed in epan/asn1.c by properly restricting buffer increments.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-13619">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-12295 – In Wireshark 3.0.0 to 3.0.1, 2.6.0 to 2.6.8, and 2.4.0 to 2.4.14, the dissection...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12295</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12295</guid>
    <pubDate>Thu, 23 May 2019 12:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-12295</strong></p>
  <p>In Wireshark 3.0.0 to 3.0.1, 2.6.0 to 2.6.8, and 2.4.0 to 2.4.14, the dissection engine could crash. This was addressed in epan/packet.c by restricting the number of layers and consequently limiting recursion.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-674</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12295">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-10903 – In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DCERPC SPOOLSS diss...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10903</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10903</guid>
    <pubDate>Tue, 09 Apr 2019 04:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-10903</strong></p>
  <p>In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DCERPC SPOOLSS dissector could crash. This was addressed in epan/dissectors/packet-dcerpc-spoolss.c by adding a boundary check.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10903">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-10902 – In Wireshark 3.0.0, the TSDNS dissector could crash. This was addressed in epan/...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10902</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10902</guid>
    <pubDate>Tue, 09 Apr 2019 04:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-10902</strong></p>
  <p>In Wireshark 3.0.0, the TSDNS dissector could crash. This was addressed in epan/dissectors/packet-tsdns.c by splitting strings safely.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-252</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10902">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-10901 – In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the LDSS dissector coul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10901</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10901</guid>
    <pubDate>Tue, 09 Apr 2019 04:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-10901</strong></p>
  <p>In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the LDSS dissector could crash. This was addressed in epan/dissectors/packet-ldss.c by handling file digests properly.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10901">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-10900 – In Wireshark 3.0.0, the Rbm dissector could go into an infinite loop. This was a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10900</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10900</guid>
    <pubDate>Tue, 09 Apr 2019 04:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-10900</strong></p>
  <p>In Wireshark 3.0.0, the Rbm dissector could go into an infinite loop. This was addressed in epan/dissectors/file-rbm.c by handling unknown object types safely.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10900">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-10899 – In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the SRVLOC dissector co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10899</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10899</guid>
    <pubDate>Tue, 09 Apr 2019 04:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-10899</strong></p>
  <p>In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the SRVLOC dissector could crash. This was addressed in epan/dissectors/packet-srvloc.c by preventing a heap-based buffer under-read.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10899">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-10898 – In Wireshark 3.0.0, the GSUP dissector could go into an infinite loop. This was ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10898</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10898</guid>
    <pubDate>Tue, 09 Apr 2019 04:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-10898</strong></p>
  <p>In Wireshark 3.0.0, the GSUP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-gsm_gsup.c by rejecting an invalid Information Element length.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10898">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-10897 – In Wireshark 3.0.0, the IEEE 802.11 dissector could go into an infinite loop. Th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10897</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10897</guid>
    <pubDate>Tue, 09 Apr 2019 04:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-10897</strong></p>
  <p>In Wireshark 3.0.0, the IEEE 802.11 dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-ieee80211.c by detecting cases in which the bit offset does not advance.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10897">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-10896 – In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DOF dissector could...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10896</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10896</guid>
    <pubDate>Tue, 09 Apr 2019 04:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-10896</strong></p>
  <p>In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DOF dissector could crash. This was addressed in epan/dissectors/packet-dof.c by properly handling generated IID and OID bytes.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10896">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-10895 – In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the NetScaler file pars...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10895</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10895</guid>
    <pubDate>Tue, 09 Apr 2019 04:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-10895</strong></p>
  <p>In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the NetScaler file parser could crash. This was addressed in wiretap/netscaler.c by improving data validation.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10895">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-10894 – In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the GSS-API dissector c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10894</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10894</guid>
    <pubDate>Tue, 09 Apr 2019 04:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-10894</strong></p>
  <p>In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the GSS-API dissector could crash. This was addressed in epan/dissectors/packet-gssapi.c by ensuring that a valid dissector is called.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-617</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10894">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-9214 – In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the RPCAP dissector could crash...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-9214</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-9214</guid>
    <pubDate>Thu, 28 Feb 2019 04:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-9214</strong></p>
  <p>In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the RPCAP dissector could crash. This was addressed in epan/dissectors/packet-rpcap.c by avoiding an attempted dereference of a NULL conversation.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9214">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-9208 – In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the TCAP dissector could crash...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-9208</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-9208</guid>
    <pubDate>Thu, 28 Feb 2019 04:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-9208</strong></p>
  <p>In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the TCAP dissector could crash. This was addressed in epan/dissectors/asn1/tcap/tcap.cnf by avoiding NULL pointer dereferences.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9208">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-19628 – In Wireshark 2.6.0 to 2.6.4, the ZigBee ZCL dissector could crash. This was addr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-19628</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-19628</guid>
    <pubDate>Thu, 29 Nov 2018 04:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-19628</strong></p>
  <p>In Wireshark 2.6.0 to 2.6.4, the ZigBee ZCL dissector could crash. This was addressed in epan/dissectors/packet-zbee-zcl-lighting.c by preventing a divide-by-zero error.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-369</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-19628">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-19627 – In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the IxVeriWave file parser coul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-19627</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-19627</guid>
    <pubDate>Thu, 29 Nov 2018 04:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-19627</strong></p>
  <p>In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the IxVeriWave file parser could crash. This was addressed in wiretap/vwr.c by adjusting a buffer boundary.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-19627">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-19623 – In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the LBMPDM dissector could cras...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-19623</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-19623</guid>
    <pubDate>Thu, 29 Nov 2018 04:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-19623</strong></p>
  <p>In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the LBMPDM dissector could crash. In addition, a remote attacker could write arbitrary data to any memory locations before the packet-scoped memory. This was addressed in epan/dissectors/packet-lbmpdm.c by disallowing certain negative values.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-19623">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-19622 – In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the MMSE dissector could go int...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-19622</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-19622</guid>
    <pubDate>Thu, 29 Nov 2018 04:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-19622</strong></p>
  <p>In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the MMSE dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-mmse.c by preventing length overflows.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-19622">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-18227 – In Wireshark 2.6.0 to 2.6.3 and 2.4.0 to 2.4.9, the MS-WSP protocol dissector co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-18227</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-18227</guid>
    <pubDate>Fri, 12 Oct 2018 06:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-18227</strong></p>
  <p>In Wireshark 2.6.0 to 2.6.3 and 2.4.0 to 2.4.9, the MS-WSP protocol dissector could crash. This was addressed in epan/dissectors/packet-mswsp.c by properly handling NULL return values.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-18227">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-18226 – In Wireshark 2.6.0 to 2.6.3, the Steam IHS Discovery dissector could consume sys...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-18226</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-18226</guid>
    <pubDate>Fri, 12 Oct 2018 06:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-18226</strong></p>
  <p>In Wireshark 2.6.0 to 2.6.3, the Steam IHS Discovery dissector could consume system memory. This was addressed in epan/dissectors/packet-steam-ihs-discovery.c by changing the memory-management approach.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-772</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-18226">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-18225 – In Wireshark 2.6.0 to 2.6.3, the CoAP dissector could crash. This was addressed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-18225</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-18225</guid>
    <pubDate>Fri, 12 Oct 2018 06:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-18225</strong></p>
  <p>In Wireshark 2.6.0 to 2.6.3, the CoAP dissector could crash. This was addressed in epan/dissectors/packet-coap.c by ensuring that the piv length is correctly computed.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-682</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-18225">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-16058 – In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Bluetooth ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-16058</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-16058</guid>
    <pubDate>Thu, 30 Aug 2018 01:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-16058</strong></p>
  <p>In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Bluetooth AVDTP dissector could crash. This was addressed in epan/dissectors/packet-btavdtp.c by properly initializing a data structure.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-665</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-16058">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-16057 – In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Radiotap d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-16057</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-16057</guid>
    <pubDate>Thu, 30 Aug 2018 01:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-16057</strong></p>
  <p>In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Radiotap dissector could crash. This was addressed in epan/dissectors/packet-ieee80211-radiotap-iter.c by validating iterator operations.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-16057">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-16056 – In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Bluetooth ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-16056</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-16056</guid>
    <pubDate>Thu, 30 Aug 2018 01:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-16056</strong></p>
  <p>In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Bluetooth Attribute Protocol dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by verifying that a dissector for a specific UUID exists.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-16056">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-14438 – In Wireshark through 2.6.2, the create_app_running_mutex function in wsutil/file...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-14438</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-14438</guid>
    <pubDate>Fri, 20 Jul 2018 00:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-14438</strong></p>
  <p>In Wireshark through 2.6.2, the create_app_running_mutex function in wsutil/file_util.c calls SetSecurityDescriptorDacl to set a NULL DACL, which allows attackers to modify the access control arbitrarily.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-14438">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-14370 – In Wireshark 2.6.0 to 2.6.1 and 2.4.0 to 2.4.7, the IEEE 802.11 protocol dissect...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-14370</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-14370</guid>
    <pubDate>Thu, 19 Jul 2018 02:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-14370</strong></p>
  <p>In Wireshark 2.6.0 to 2.6.1 and 2.4.0 to 2.4.7, the IEEE 802.11 protocol dissector could crash. This was addressed in epan/crypt/airpdcap.c via bounds checking that prevents a buffer over-read.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-14370">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-14369 – In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the HTTP2 diss...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-14369</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-14369</guid>
    <pubDate>Thu, 19 Jul 2018 02:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-14369</strong></p>
  <p>In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the HTTP2 dissector could crash. This was addressed in epan/dissectors/packet-http2.c by verifying that header data was found before proceeding to header decompression.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-14369">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-14368 – In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the Bazaar pro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-14368</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-14368</guid>
    <pubDate>Thu, 19 Jul 2018 02:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-14368</strong></p>
  <p>In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the Bazaar protocol dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-bzr.c by properly handling items that are too long.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-14368">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-14367 – In Wireshark 2.6.0 to 2.6.1 and 2.4.0 to 2.4.7, the CoAP protocol dissector coul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-14367</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-14367</guid>
    <pubDate>Thu, 19 Jul 2018 02:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-14367</strong></p>
  <p>In Wireshark 2.6.0 to 2.6.1 and 2.4.0 to 2.4.7, the CoAP protocol dissector could crash. This was addressed in epan/dissectors/packet-coap.c by properly checking for a NULL condition.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-252</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-14367">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-14344 – In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the ISMP disse...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-14344</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-14344</guid>
    <pubDate>Thu, 19 Jul 2018 02:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-14344</strong></p>
  <p>In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the ISMP dissector could crash. This was addressed in epan/dissectors/packet-ismp.c by validating the IPX address length to avoid a buffer over-read.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-14344">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-14343 – In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the ASN.1 BER ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-14343</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-14343</guid>
    <pubDate>Thu, 19 Jul 2018 02:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-14343</strong></p>
  <p>In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the ASN.1 BER dissector could crash. This was addressed in epan/dissectors/packet-ber.c by ensuring that length values do not exceed the maximum signed integer.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-14343">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-14342 – In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the BGP protoc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-14342</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-14342</guid>
    <pubDate>Thu, 19 Jul 2018 02:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-14342</strong></p>
  <p>In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the BGP protocol dissector could go into a large loop. This was addressed in epan/dissectors/packet-bgp.c by validating Path Attribute lengths.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-834</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-14342">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-14341 – In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the DICOM diss...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-14341</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-14341</guid>
    <pubDate>Thu, 19 Jul 2018 02:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-14341</strong></p>
  <p>In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the DICOM dissector could go into a large or infinite loop. This was addressed in epan/dissectors/packet-dcm.c by preventing an offset overflow.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-14341">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-14340 – In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, dissectors tha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-14340</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-14340</guid>
    <pubDate>Thu, 19 Jul 2018 02:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-14340</strong></p>
  <p>In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, dissectors that support zlib decompression could crash. This was addressed in epan/tvbuff_zlib.c by rejecting negative lengths to avoid a buffer over-read.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-14340">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-14339 – In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the MMSE disse...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-14339</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-14339</guid>
    <pubDate>Thu, 19 Jul 2018 02:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-14339</strong></p>
  <p>In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the MMSE dissector could go into an infinite loop. This was addressed in epan/proto.c by adding offset and length validation.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-14339">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-11362 – In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LDSS dissector coul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-11362</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-11362</guid>
    <pubDate>Tue, 22 May 2018 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-11362</strong></p>
  <p>In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LDSS dissector could crash. This was addressed in epan/dissectors/packet-ldss.c by avoiding a buffer over-read upon encountering a missing '\0' character.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-11362">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-11361 – In Wireshark 2.6.0, the IEEE 802.11 protocol dissector could crash. This was add...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-11361</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-11361</guid>
    <pubDate>Tue, 22 May 2018 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-11361</strong></p>
  <p>In Wireshark 2.6.0, the IEEE 802.11 protocol dissector could crash. This was addressed in epan/crypt/dot11decrypt.c by avoiding a buffer overflow during FTE processing in Dot11DecryptTDLSDeriveKey.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-11361">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-11360 – In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the GSM A DTAP dissecto...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-11360</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-11360</guid>
    <pubDate>Tue, 22 May 2018 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-11360</strong></p>
  <p>In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the GSM A DTAP dissector could crash. This was addressed in epan/dissectors/packet-gsm_a_dtap.c by fixing an off-by-one error that caused a buffer overflow.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-11360">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-11359 – In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the RRC dissector and o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-11359</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-11359</guid>
    <pubDate>Tue, 22 May 2018 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-11359</strong></p>
  <p>In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the RRC dissector and other dissectors could crash. This was addressed in epan/proto.c by avoiding a NULL pointer dereference.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-11359">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-11358 – In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the Q.931 dissector cou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-11358</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-11358</guid>
    <pubDate>Tue, 22 May 2018 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-11358</strong></p>
  <p>In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the Q.931 dissector could crash. This was addressed in epan/dissectors/packet-q931.c by avoiding a use-after-free after a malformed packet prevented certain cleanup.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-11358">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-11357 – In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LTP dissector and o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-11357</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-11357</guid>
    <pubDate>Tue, 22 May 2018 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-11357</strong></p>
  <p>In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LTP dissector and other dissectors could consume excessive memory. This was addressed in epan/tvbuff.c by rejecting negative lengths.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-11357">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-11356 – In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the DNS dissector could...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-11356</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-11356</guid>
    <pubDate>Tue, 22 May 2018 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-11356</strong></p>
  <p>In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the DNS dissector could crash. This was addressed in epan/dissectors/packet-dns.c by avoiding a NULL pointer dereference for an empty name in an SRV record.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-11356">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-11355 – In Wireshark 2.6.0, the RTCP dissector could crash. This was addressed in epan/d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-11355</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-11355</guid>
    <pubDate>Tue, 22 May 2018 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-11355</strong></p>
  <p>In Wireshark 2.6.0, the RTCP dissector could crash. This was addressed in epan/dissectors/packet-rtcp.c by avoiding a buffer overflow for packet status chunks.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-11355">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-11354 – In Wireshark 2.6.0, the IEEE 1905.1a dissector could crash. This was addressed i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-11354</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-11354</guid>
    <pubDate>Tue, 22 May 2018 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-11354</strong></p>
  <p>In Wireshark 2.6.0, the IEEE 1905.1a dissector could crash. This was addressed in epan/dissectors/packet-ieee1905.c by making a certain correction to string handling.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-11354">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
