Page 13 of 127 results (0.008 seconds)

CVSS: 5.9EPSS: 0%CPEs: 18EXPL: 0

Off-by-one error in epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted packet. Error por un paso en epan/dissectors/packet-rlc.c en el disector RLC en Wireshark 1.12.x en versiones anteriores a 1.12.13 y 2.x en versiones anteriores a 2.0.5 permite a atacantes remotos provocar una denegación de servicio (desbordamiento de búfer basado en pila y caída de aplicación) a través de un paquete manipulado. • http://openwall.com/lists/oss-security/2016/07/28/3 http://www.debian.org/security/2016/dsa-3648 http://www.securitytracker.com/id/1036480 http://www.wireshark.org/security/wnpa-sec-2016-46.html https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=12664 https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=47a5fa850b388fcf4ea762073806f01b459820fe • CWE-189: Numeric Errors •

CVSS: 5.9EPSS: 0%CPEs: 18EXPL: 0

epan/dissectors/packet-ldss.c in the LDSS dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 mishandles conversations, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. epan/dissectors/packet-ldss.c en el disector LDSS en Wireshark 1.12.x en versiones anteriores a 1.12.13 y 2.x en versiones anteriores a 2.0.5 no maneja adecuadamente conversaciones, lo que permite a atacantes remotos provocar una denegación de servicio (caída de aplicación) a través de un paquete manipulado. • http://openwall.com/lists/oss-security/2016/07/28/3 http://www.debian.org/security/2016/dsa-3648 http://www.securitytracker.com/id/1036480 http://www.wireshark.org/security/wnpa-sec-2016-45.html https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=12662 https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=5a469ddc893f7c1912d0e15cc73bd3011e6cc2fb • CWE-20: Improper Input Validation •

CVSS: 5.9EPSS: 1%CPEs: 5EXPL: 1

The CORBA IDL dissectors in Wireshark 2.x before 2.0.5 on 64-bit Windows platforms do not properly interact with Visual C++ compiler options, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. Los disectores CORBA IDL en Wireshark 2.x en versiones anteriores a 2.0.5 en plataformas Windows 64-bit no interactúa adecuadamente con opciones del compilador de Visual C++, lo que permite a atacantes remotos provocar una denegación de servicio (caída de aplicación) a través de un paquete manipulado. • https://www.exploit-db.com/exploits/40196 http://openwall.com/lists/oss-security/2016/07/28/3 http://www.securityfocus.com/bid/92162 http://www.securitytracker.com/id/1036480 http://www.wireshark.org/security/wnpa-sec-2016-39.html https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=12495 https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=581a17af40b84ef0c9e7f41ed0795af345b61ce1 • CWE-20: Improper Input Validation •

CVSS: 5.9EPSS: 1%CPEs: 5EXPL: 1

epan/dissectors/packet-wap.c in Wireshark 2.x before 2.0.5 omits an overflow check in the tvb_get_guintvar function, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet, related to the MMSE, WAP, WBXML, and WSP dissectors. epan/dissectors/packet-wap.c in Wireshark 2.x en versiones anteriores a 2.0.5 omite una comprobación de desbordamiento en la función tvb_get_guintvar, lo que permite a atacantes remotos provocar una denegación de servicio (bucle infinito) a través de un paquete manipulado, relacionado con los disertores MMSE, WAP, WBXML y WSP. • https://www.exploit-db.com/exploits/40195 http://openwall.com/lists/oss-security/2016/07/28/3 http://www.securityfocus.com/bid/92174 http://www.securitytracker.com/id/1036480 http://www.wireshark.org/security/wnpa-sec-2016-48.html https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=12661 https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=2193bea3212d74e2a907152055e27d409b59485e • CWE-20: Improper Input Validation •

CVSS: 5.9EPSS: 0%CPEs: 18EXPL: 0

epan/proto.c in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause a denial of service (OpenFlow dissector large loop) via a crafted packet. epan/proto.c en Wireshark 1.12.x en versiones anteriores a 1.12.13 y 2.x en versiones anteriores a 2.0.5 permite a atacantes remotos provocar una denegación de servicio (bucle grande de disector OpenFlow) a través de un paquete manipulado. • http://openwall.com/lists/oss-security/2016/07/28/3 http://www.debian.org/security/2016/dsa-3648 http://www.securitytracker.com/id/1036480 http://www.wireshark.org/security/wnpa-sec-2016-47.html https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=12659 https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=56706427f53cc64793870bf072c2c06248ae88f3 • CWE-399: Resource Management Errors •