CVE-2018-9258
- EPSS 0.69%
- Veröffentlicht 04.04.2018 07:29:00
- Zuletzt bearbeitet 21.11.2024 04:15:13
In Wireshark 2.4.0 to 2.4.5, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by preserving valid data sources.
CVE-2018-9259
- EPSS 0.51%
- Veröffentlicht 04.04.2018 07:29:00
- Zuletzt bearbeitet 21.11.2024 04:15:14
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the MP4 dissector could crash. This was addressed in epan/dissectors/file-mp4.c by restricting the box recursion depth.
CVE-2018-9260
- EPSS 0.44%
- Veröffentlicht 04.04.2018 07:29:00
- Zuletzt bearbeitet 21.11.2024 04:15:14
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the IEEE 802.15.4 dissector could crash. This was addressed in epan/dissectors/packet-ieee802154.c by ensuring that an allocation step occurs.
CVE-2018-9261
- EPSS 0.48%
- Veröffentlicht 04.04.2018 07:29:00
- Zuletzt bearbeitet 21.11.2024 04:15:14
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the NBAP dissector could crash with a large loop that ends with a heap-based buffer overflow. This was addressed in epan/dissectors/packet-nbap.c by prohibiting the self-linking of DCH-IDs.
CVE-2018-9262
- EPSS 0.56%
- Veröffentlicht 04.04.2018 07:29:00
- Zuletzt bearbeitet 21.11.2024 04:15:14
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the VLAN dissector could crash. This was addressed in epan/dissectors/packet-vlan.c by limiting VLAN tag nesting to restrict the recursion depth.
CVE-2018-9263
- EPSS 0.44%
- Veröffentlicht 04.04.2018 07:29:00
- Zuletzt bearbeitet 21.11.2024 04:15:14
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the Kerberos dissector could crash. This was addressed in epan/dissectors/packet-kerberos.c by ensuring a nonzero key length.
CVE-2018-9264
- EPSS 0.55%
- Veröffentlicht 04.04.2018 07:29:00
- Zuletzt bearbeitet 21.11.2024 04:15:14
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the ADB dissector could crash with a heap-based buffer overflow. This was addressed in epan/dissectors/packet-adb.c by checking for a length inconsistency.
CVE-2018-7330
- EPSS 0.36%
- Veröffentlicht 23.02.2018 22:29:01
- Zuletzt bearbeitet 21.11.2024 04:12:01
In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-thread.c had an infinite loop that was addressed by using a correct integer data type.
CVE-2018-7331
- EPSS 1.3%
- Veröffentlicht 23.02.2018 22:29:01
- Zuletzt bearbeitet 21.11.2024 04:12:02
In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-ber.c had an infinite loop that was addressed by validating a length.
CVE-2018-7332
- EPSS 0.37%
- Veröffentlicht 23.02.2018 22:29:01
- Zuletzt bearbeitet 21.11.2024 04:12:02
In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-reload.c had an infinite loop that was addressed by validating a length.