
CVE-2006-1934 – Debian Linux Security Advisory 1049-1
https://notcve.org/view.php?id=CVE-2006-1934
25 Apr 2006 — Multiple buffer overflows in Ethereal 0.10.x up to 0.10.14 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the (1) ALCAP dissector, (2) Network Instruments file code, or (3) NetXray/Windows Sniffer file code. Gerald Combs reported several vulnerabilities in ethereal, a popular network traffic analyser. • ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc •

CVE-2006-1935 – Debian Linux Security Advisory 1049-1
https://notcve.org/view.php?id=CVE-2006-1935
25 Apr 2006 — Buffer overflow in Ethereal 0.9.15 up to 0.10.14 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the COPS dissector. Gerald Combs reported several vulnerabilities in ethereal, a popular network traffic analyser. • ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc •

CVE-2006-1936 – Debian Linux Security Advisory 1049-1
https://notcve.org/view.php?id=CVE-2006-1936
25 Apr 2006 — Buffer overflow in Ethereal 0.8.5 up to 0.10.14 allows remote attackers to execute arbitrary code via the telnet dissector. Gerald Combs reported several vulnerabilities in ethereal, a popular network traffic analyser. • ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc •

CVE-2006-1937 – Debian Linux Security Advisory 1049-1
https://notcve.org/view.php?id=CVE-2006-1937
25 Apr 2006 — Multiple unspecified vulnerabilities in Ethereal 0.10.x up to 0.10.14 allow remote attackers to cause a denial of service (crash from null dereference) via (1) multiple vectors in H.248, and the (2) X.509if, (3) SRVLOC, (4) H.245, (5) AIM, and (6) general packet dissectors; and (7) the statistics counter. Gerald Combs reported several vulnerabilities in ethereal, a popular network traffic analyser. • ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc •

CVE-2006-1938 – Debian Linux Security Advisory 1049-1
https://notcve.org/view.php?id=CVE-2006-1938
25 Apr 2006 — Multiple unspecified vulnerabilities in Ethereal 0.8.x up to 0.10.14 allow remote attackers to cause a denial of service (crash from null dereference) via the (1) Sniffer capture or (2) SMB PIPE dissector. Gerald Combs reported several vulnerabilities in ethereal, a popular network traffic analyser. • ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc •

CVE-2006-1939 – Debian Linux Security Advisory 1049-1
https://notcve.org/view.php?id=CVE-2006-1939
25 Apr 2006 — Multiple unspecified vulnerabilities in Ethereal 0.9.x up to 0.10.14 allow remote attackers to cause a denial of service (crash from null dereference) via (1) an invalid display filter, or the (2) GSM SMS, (3) ASN.1-based, (4) DCERPC NT, (5) PER, (6) RPC, (7) DCERPC, and (8) ASN.1 dissectors. Gerald Combs reported several vulnerabilities in ethereal, a popular network traffic analyser. • ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc •

CVE-2006-1940 – Debian Linux Security Advisory 1049-1
https://notcve.org/view.php?id=CVE-2006-1940
25 Apr 2006 — Unspecified vulnerability in Ethereal 0.10.4 up to 0.10.14 allows remote attackers to cause a denial of service (abort) via the SNDCP dissector. Gerald Combs reported several vulnerabilities in ethereal, a popular network traffic analyser. • ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc •

CVE-2005-4585
https://notcve.org/view.php?id=CVE-2005-4585
29 Dec 2005 — Unspecified vulnerability in the GTP dissector for Ethereal 0.9.1 to 0.10.13 allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors. • ftp://patches.sgi.com/support/free/security/advisories/20060201-01-U •

CVE-2005-3651 – iDEFENSE Security Advisory 2005-12-09.t
https://notcve.org/view.php?id=CVE-2005-3651
10 Dec 2005 — Stack-based buffer overflow in the dissect_ospf_v3_address_prefix function in the OSPF protocol dissector in Ethereal 0.10.12, and possibly other versions, allows remote attackers to execute arbitrary code via crafted packets. Remote exploitation of an input validation vulnerability in the OSPF protocol dissectors within Ethereal, as included in various vendors operating system distributions, could allow attackers to crash the vulnerable process or potentially execute arbitrary code. iDefense has confirmed ... • ftp://patches.sgi.com/support/free/security/advisories/20060201-01-U •

CVE-2005-3313 – Gentoo Linux Security Advisory 200510-25
https://notcve.org/view.php?id=CVE-2005-3313
31 Oct 2005 — The IRC protocol dissector in Ethereal 0.10.13 allows remote attackers to cause a denial of service (infinite loop). Ethereal is vulnerable to numerous vulnerabilities, potentially resulting in the execution of arbitrary code or abnormal termination. Versions less than 0.10.13-r1 are affected. • ftp://patches.sgi.com/support/free/security/advisories/20060201-01-U •