9.8

CVE-2026-76886

Exploit

Heap-based Buffer Overflow in Wireshark

C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wireshark ≫ Wireshark Version >= 4.4.0 < 4.4.18
Wireshark ≫ Wireshark Version >= 4.6.0 < 4.6.8
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.27% 0.19
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cve@gitlab.com 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-122 Heap-based Buffer Overflow

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

https://gitlab.com/wireshark/wireshark/-/work_items/21446
Vendor Advisory
Exploit
Mitigation
https://www.wireshark.org/security/wnpa-sec-2026-75.html
Vendor Advisory
https://gitlab.com/wireshark/wireshark/-/work_items/21439
Vendor Advisory
Exploit
Mitigation