Search CVE reports


Toggle filters

541 – 550 of 915 results


CVE-2015-8711

Medium priority

Some fixes available 1 of 6

epan/dissectors/packet-nbap.c in the NBAP dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate conversation data, which allows remote attackers to cause a denial of service (NULL pointer dereference...

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Not affected
Show less packages

CVE-2015-3182

Medium priority

Some fixes available 3 of 4

epan/dissectors/packet-dec-dnart.c in the DECnet NSP/RT dissector in Wireshark 1.10.12 through 1.10.14 mishandles a certain strdup return value, which allows remote attackers to cause a denial of service (application crash) via a...

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Fixed
Show less packages

CVE-2015-8367

Low priority

Some fixes available 1 of 95

The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors and possibly execute arbitrary code, related to memory object initialization.

8 affected packages

exactimage, rawtherapee, kodi, darktable, dcraw...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exactimage Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
rawtherapee Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
kodi Needs evaluation Needs evaluation Vulnerable Vulnerable Vulnerable
darktable Not affected Not affected Not affected Not affected Not affected
dcraw Not affected Not affected Not affected Not affected Not affected
libraw Not affected Not affected Not affected Not affected Not affected
ufraw Not in release Not in release Not in release Not in release Not affected
xbmc Not in release Not in release Not in release Not in release Not in release
Show all 8 packages Show less packages

CVE-2015-8366

Low priority

Some fixes available 1 of 117

Array index error in smal_decode_segment function in LibRaw before 0.17.1 allows context-dependent attackers to cause memory errors and possibly execute arbitrary code via vectors related to indexes.

8 affected packages

ufraw, darktable, exactimage, dcraw, rawtherapee...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ufraw Not in release Not in release Not in release Not in release Not affected
darktable Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
exactimage Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
dcraw Not affected Not affected Not affected Not affected Vulnerable
rawtherapee Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
kodi Needs evaluation Needs evaluation Vulnerable Vulnerable Vulnerable
libraw Not affected Not affected Not affected Not affected Not affected
xbmc Not in release Not in release Not in release Not in release Not in release
Show all 8 packages Show less packages

CVE-2015-7830

Low priority
Ignored

The pcapng_read_if_descr_block function in wiretap/pcapng.c in the pcapng parser in Wireshark 1.12.x before 1.12.8 uses too many levels of pointer indirection, which allows remote attackers to cause a denial of service (incorrect...

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark
Show less packages

CVE-2015-6249

Medium priority

Some fixes available 4 of 5

The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.12.x before 1.12.7 does not prevent the conflicting use of a table for both IPv4 and IPv6 addresses, which...

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Fixed
Show less packages

CVE-2015-6248

Medium priority

Some fixes available 4 of 5

The ptvcursor_add function in the ptvcursor implementation in epan/proto.c in Wireshark 1.12.x before 1.12.7 does not check whether the expected amount of data is available, which allows remote attackers to cause a denial of...

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Fixed
Show less packages

CVE-2015-6247

Medium priority

Some fixes available 4 of 5

The dissect_openflow_tablemod_v5 function in epan/dissectors/packet-openflow_v5.c in the OpenFlow dissector in Wireshark 1.12.x before 1.12.7 does not validate a certain offset value, which allows remote attackers to cause a...

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Fixed
Show less packages

CVE-2015-6246

Medium priority

Some fixes available 4 of 5

The dissect_wa_payload function in epan/dissectors/packet-waveagent.c in the WaveAgent dissector in Wireshark 1.12.x before 1.12.7 mishandles large tag values, which allows remote attackers to cause a denial of...

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Fixed
Show less packages

CVE-2015-6245

Medium priority

Some fixes available 4 of 5

epan/dissectors/packet-gsm_rlcmac.c in the GSM RLC/MAC dissector in Wireshark 1.12.x before 1.12.7 uses incorrect integer data types, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Fixed
Show less packages