- EPSS 0.33%
- Veröffentlicht 01.08.2014 11:13:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
The read_new_line function in wiretap/catapult_dct2000.c in the Catapult DCT2000 dissector in Wireshark 1.10.x before 1.10.9 does not properly strip '\n' and '\r' characters, which allows remote attackers to cause a denial of service (off-by-one buff...
- EPSS 0.74%
- Veröffentlicht 01.08.2014 11:13:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
The APN decode functionality in (1) epan/dissectors/packet-gtp.c and (2) epan/dissectors/packet-gsm_a_gm.c in the GTP and GSM Management dissectors in Wireshark 1.10.x before 1.10.9 does not completely initialize a certain buffer, which allows remote...
- EPSS 0.35%
- Veröffentlicht 01.08.2014 11:13:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
The rlc_decode_li function in epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.10.x before 1.10.9 initializes a certain structure member only after this member is used, which allows remote attackers to cause a denial of service (appli...
- EPSS 0.35%
- Veröffentlicht 01.08.2014 11:13:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.10.x before 1.10.9 does not properly validate padding values, which allows remote attackers to cause a denial of service (buffer ...
CVE-2014-4020
- EPSS 0.17%
- Veröffentlicht 18.06.2014 16:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The dissect_frame function in epan/dissectors/packet-frame.c in the frame metadissector in Wireshark 1.10.x before 1.10.8 interprets a negative integer as a length value even though it was intended to represent an error condition, which allows remote...
CVE-2014-4174
- EPSS 1.5%
- Veröffentlicht 18.06.2014 16:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
wiretap/libpcap.c in the libpcap file parser in Wireshark 1.10.x before 1.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted packet-trace file that includes a la...
CVE-2014-2907
- EPSS 0.21%
- Veröffentlicht 24.04.2014 10:55:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The srtp_add_address function in epan/dissectors/packet-rtp.c in the RTP dissector in Wireshark 1.10.x before 1.10.7 does not properly update SRTP conversation data, which allows remote attackers to cause a denial of service (application crash) via a...
CVE-2014-2281
- EPSS 3.12%
- Veröffentlicht 11.03.2014 13:01:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
The nfs_name_snoop_add_name function in epan/dissectors/packet-nfs.c in the NFS dissector in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 does not validate a certain length value, which allows remote attackers to cause a denial of service (...
CVE-2014-2282
- EPSS 0.61%
- Veröffentlicht 11.03.2014 13:01:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
The dissect_protocol_data_parameter function in epan/dissectors/packet-m3ua.c in the M3UA dissector in Wireshark 1.10.x before 1.10.6 does not properly allocate memory, which allows remote attackers to cause a denial of service (application crash) vi...
CVE-2014-2283
- EPSS 3.31%
- Veröffentlicht 11.03.2014 13:01:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
epan/dissectors/packet-rlc in the RLC dissector in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 uses inconsistent memory-management approaches, which allows remote attackers to cause a denial of service (use-after-free error and application...