Vulnerability index

Browse CVEs

140 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tcpdump MEDIUM 6.5
CVE-2023-1801

The SMB protocol decoder in tcpdump version 4.99.3 can perform an out-of-bounds write when decoding a crafted network packet.

Patch available
Fix from $1,600 2023-04-07
Tcpdump CRITICAL 9.1
CVE-2019-15167

The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 3, a different vulnerability than CVE-20…

Fix: 4.9.3+
Fix from $2,300 2022-08-27
Tcpslice MEDIUM 5.5
CVE-2021-41043

Use after free in tcpslice triggers AddressSanitizer, no other confirmed impact.

Fix: 1.5+
Fix from $1,600 2022-01-05
Tcpdump HIGH 7.5
CVE-2020-8036

The tok2strbuf() function in tcpdump 4.10.0-PRE-GIT was used by the SOME/IP dissector in an unsafe way.

Patch available
Fix from $1,950 2020-11-04
Libpcap HIGH 7.5
CVE-2019-15163

rpcapd/daemon.c in libpcap before 1.9.1 allows attackers to cause a denial of service (NULL pointer dereference and daemon crash) if a crypt() call f…

Fix: 1.9.1+
Fix from $1,950 2019-10-03
Libpcap MEDIUM 5.3
CVE-2019-15161

rpcapd/daemon.c in libpcap before 1.9.1 mishandles certain length values because of reuse of a variable. This may open up an attack vector involving …

Fix: 1.9.1+
Fix from $1,600 2019-10-03
Libpcap MEDIUM 5.3
CVE-2019-15162

rpcapd/daemon.c in libpcap before 1.9.1 on non-Windows platforms provides details about why authentication failed, which might make it easier for att…

Fix: 1.9.1+
Fix from $1,600 2019-10-03
Libpcap MEDIUM 5.3
CVE-2019-15164

rpcapd/daemon.c in libpcap before 1.9.1 allows SSRF because a URL may be provided as a capture source.

Fix: 1.9.1+
Fix from $1,600 2019-10-03
Tcpdump HIGH 7.8
CVE-2018-16301

The command-line argument parser in tcpdump before 4.99.0 has a buffer overflow in tcpdump.c:read_infile(). To trigger this vulnerability the attacke…

Fix: 4.99.0+
Fix from $1,950 2019-10-03
Tcpdump HIGH 7.5
CVE-2018-16300

The BGP parser in tcpdump before 4.9.3 allows stack consumption in print-bgp.c:bgp_attr_print() because of unlimited recursion.

Fix: 4.9.3+
Fix from $1,950 2019-10-03
Tcpdump HIGH 7.5
CVE-2018-16452

The SMB parser in tcpdump before 4.9.3 has stack exhaustion in smbutil.c:smb_fdata() via recursion.

Fix: 4.9.3+
Fix from $1,950 2019-10-03
Tcpdump CRITICAL 9.8
CVE-2018-10103

tcpdump before 4.9.3 mishandles the printing of SMB data (issue 1 of 2).

Fix: 4.9.3+
Fix from $2,300 2019-10-03
Tcpdump CRITICAL 9.8
CVE-2018-10105

tcpdump before 4.9.3 mishandles the printing of SMB data (issue 2 of 2).

Fix: 4.9.3+
Fix from $2,300 2019-10-03
Tcpdump MEDIUM 5.5
CVE-2018-19519

In tcpdump 4.9.2, a stack-based buffer over-read exists in the print_prefix function of print-hncp.c via crafted packet data because of missing initi…

No fix yet
Fix from $1,600 2018-11-25
Tcpdump MEDIUM 5.5
CVE-2017-16808

tcpdump before 4.9.3 has a heap-based buffer over-read related to aoe_print in print-aoe.c and lookup_emem in addrtoname.c.

No fix yet
Fix from $1,600 2017-11-13
Libpcap CRITICAL 9.8
CVE-2011-1935

pcap-linux.c in libpcap 1.1.1 before commit ea9432fabdf4b33cbc76d9437200e028f1c47c93 when snaplen is set may truncate packets, which might allow remo…

Fix: 1.2.1+
Fix from $2,300 2017-10-20
Tcpdump HIGH 7.5
CVE-2015-3138

print-wb.c in tcpdump before 4.7.4 allows remote attackers to cause a denial of service (segmentation fault and process crash).

Fix: after 4.7.3
Fix from $1,950 2017-09-28
Tcpdump CRITICAL 9.8
CVE-2017-13049

The Rx protocol parser in tcpdump before 4.9.2 has a buffer over-read in print-rx.c:ubik_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Tcpdump CRITICAL 9.8
CVE-2017-13050

The RPKI-Router parser in tcpdump before 4.9.2 has a buffer over-read in print-rpki-rtr.c:rpki_rtr_pdu_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Tcpdump CRITICAL 9.8
CVE-2017-13051

The RSVP parser in tcpdump before 4.9.2 has a buffer over-read in print-rsvp.c:rsvp_obj_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Tcpdump CRITICAL 9.8
CVE-2017-13052

The CFM parser in tcpdump before 4.9.2 has a buffer over-read in print-cfm.c:cfm_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Tcpdump CRITICAL 9.8
CVE-2017-13053

The BGP parser in tcpdump before 4.9.2 has a buffer over-read in print-bgp.c:decode_rt_routing_info().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Tcpdump CRITICAL 9.8
CVE-2017-13054

The LLDP parser in tcpdump before 4.9.2 has a buffer over-read in print-lldp.c:lldp_private_8023_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Tcpdump CRITICAL 9.8
CVE-2017-13055

The ISO IS-IS parser in tcpdump before 4.9.2 has a buffer over-read in print-isoclns.c:isis_print_is_reach_subtlv().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Tcpdump CRITICAL 9.8
CVE-2017-13688

The OLSR parser in tcpdump before 4.9.2 has a buffer over-read in print-olsr.c:olsr_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Tcpdump CRITICAL 9.8
CVE-2017-13689

The IKEv1 parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c:ikev1_id_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Tcpdump CRITICAL 9.8
CVE-2017-13690

The IKEv2 parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c, several functions.

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Tcpdump CRITICAL 9.8
CVE-2017-13022

The IP parser in tcpdump before 4.9.2 has a buffer over-read in print-ip.c:ip_printroute().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Tcpdump CRITICAL 9.8
CVE-2017-13023

The IPv6 mobility parser in tcpdump before 4.9.2 has a buffer over-read in print-mobility.c:mobility_opt_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Tcpdump CRITICAL 9.8
CVE-2017-13025

The IPv6 mobility parser in tcpdump before 4.9.2 has a buffer over-read in print-mobility.c:mobility_opt_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14