Vulnerabilidades em Wireshark Foundation

141 resultados
Análise Vexday

Com 129 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, o Wireshark Foundation apresenta taxa de exploração abaixo da média geral do catálogo, o que sugere menor pressão imediata de ameaças oportunistas. Ainda assim, 44 vulnerabilidades surgiram nos últimos 90 dias — volume que merece acompanhamento contínuo — e 15 possuem PoC pública disponível, ampliando a superfície de risco potencial. O tipo de falha mais recorrente é CWE-835 (loop infinito), padrão que tipicamente viabiliza negação de serviço em ferramentas de análise de tráfego como o Wireshark. A CVE mais perigosa atualmente rastreada é CVE-2021-39925, com escore EPSS de 0,0789, indicando probabilidade ainda baixa, porém não desprezível, de exploração em curto prazo.

CVE-2023-0668MEDIUMWireshark IEEE-C37.118 parsing buffer overflowEPSS 2.3%CVE-2021-4186MEDIUMCrash in the Gryphon dissector in Wireshark 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture fileEPSS 2.1%CVE-2022-0586MEDIUMInfinite loop in RTMPT protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or cEPSS 2.0%CVE-2023-0667MEDIUMWireshark MSMMS parsing buffer overflowEPSS 2.0%CVE-2022-0582MEDIUMUnaligned access in the CSN.1 protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injectiEPSS 2.0%CVE-2022-0583MEDIUMCrash in the PVFS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafteEPSS 1.8%CVE-2022-0581MEDIUMCrash in the CMS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or craftedEPSS 1.8%CVE-2024-0208HIGHImproper Handling of Missing Values in WiresharkEPSS 1.8%CVE-2023-2856MEDIUMVMS TCPIPtrace file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture fileEPSS 1.8%CVE-2023-2858MEDIUMNetScaler file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture fileEPSS 1.8%CVE-2023-2855MEDIUMCandump log parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture fileEPSS 1.6%CVE-2023-2879MEDIUMGDSDB infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or crafted capture fileEPSS 1.6%CVE-2021-39923HIGHLarge loop in the PNRP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted caEPSS 1.5%CVE-2021-4183MEDIUMCrash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture fileEPSS 1.4%CVE-2024-2955HIGHMismatched Memory Management Routines in WiresharkEPSS 1.4%CVE-2023-2952MEDIUMXRA dissector infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or crafted captureEPSS 1.1%CVE-2023-1994MEDIUMGQUIC dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture fileEPSS 1.0%CVE-2023-0411MEDIUMExcessive loops in multiple dissectors in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or EPSS 0.9%CVE-2023-2854MEDIUMBLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture fileEPSS 0.9%CVE-2023-2857MEDIUMBLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture fileEPSS 0.9%