Vulnerabilidades em Wireshark Foundation

169 resultados
Análise Vexday

Com 129 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, o Wireshark Foundation apresenta taxa de exploração abaixo da média geral do catálogo, o que sugere menor pressão imediata de ameaças oportunistas. Ainda assim, 44 vulnerabilidades surgiram nos últimos 90 dias — volume que merece acompanhamento contínuo — e 15 possuem PoC pública disponível, ampliando a superfície de risco potencial. O tipo de falha mais recorrente é CWE-835 (loop infinito), padrão que tipicamente viabiliza negação de serviço em ferramentas de análise de tráfego como o Wireshark. A CVE mais perigosa atualmente rastreada é CVE-2021-39925, com escore EPSS de 0,0789, indicando probabilidade ainda baixa, porém não desprezível, de exploração em curto prazo.

CVE-2023-0413MEDIUMDissection engine bug in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture fEPSS 0.9%CVE-2023-0417MEDIUMMemory leak in the NFS dissector in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafteEPSS 0.9%CVE-2023-0415MEDIUMiSCSI dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture fEPSS 0.9%CVE-2023-0416MEDIUMGNW dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture filEPSS 0.9%CVE-2022-3725MEDIUMCrash in the OPUS protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or crafted capture fileEPSS 0.9%CVE-2023-0412MEDIUMTIPC dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture fiEPSS 0.8%CVE-2024-4854MEDIUMLoop with Unreachable Exit Condition ('Infinite Loop') in WiresharkEPSS 0.8%CVE-2023-0414MEDIUMCrash in the EAP dissector in Wireshark 4.0.0 to 4.0.2 allows denial of service via packet injection or crafted capture fileEPSS 0.8%CVE-2023-6174MEDIUMOut-of-bounds Read in WiresharkEPSS 0.7%CVE-2022-4345MEDIUMInfinite loops in the BPv6, OpenFlow, and Kafka protocol dissectors in Wireshark 4.0.0 to 4.0.1 and 3.6.0 to 3.6.9 allows denial of service EPSS 0.7%CVE-2023-1161MEDIUMISO 15765 and ISO 10681 dissector crash in Wireshark 4.0.0 to 4.0.3 and 3.6.0 to 3.6.11 allows denial of service via packet injection or craEPSS 0.6%CVE-2024-0209HIGHNULL Pointer Dereference in WiresharkEPSS 0.6%CVE-2022-4344MEDIUMMemory exhaustion in the Kafka protocol dissector in Wireshark 4.0.0 to 4.0.1 and 3.6.0 to 3.6.9 allows denial of service via packet injectiEPSS 0.6%CVE-2024-0211HIGHLoop with Unreachable Exit Condition ('Infinite Loop') in WiresharkEPSS 0.5%CVE-2023-4513MEDIUMMissing Release of Memory after Effective Lifetime in WiresharkEPSS 0.5%CVE-2023-4512MEDIUMUncontrolled Recursion in WiresharkEPSS 0.5%CVE-2023-5371MEDIUMMemory Allocation with Excessive Size Value in WiresharkEPSS 0.5%CVE-2024-0210HIGHUncontrolled Recursion in WiresharkEPSS 0.5%CVE-2024-0207HIGHOut-of-bounds Read in WiresharkEPSS 0.5%CVE-2023-4511MEDIUMLoop with Unreachable Exit Condition ('Infinite Loop') in WiresharkEPSS 0.5%