
CVE-2013-7114 – wireshark: NTLMSSP v2 dissector could crash (wnpa-sec-2013-68)
https://notcve.org/view.php?id=CVE-2013-7114
19 Dec 2013 — Multiple buffer overflows in the create_ntlmssp_v2_key function in epan/dissectors/packet-ntlmssp.c in the NTLMSSP v2 dissector in Wireshark 1.8.x before 1.8.12 and 1.10.x before 1.10.4 allow remote attackers to cause a denial of service (application crash) via a long domain name in a packet. Múltiples desbordamientos de buffer en la función create_ntlmssp_v2_key de epan/dissectors/packet-ntlmssp.c del dissector NTLMSSP v2 en Wireshark 1.8.x anteriores a 1.8.12 y 1.10.x anteriores a 1.10.4 permite a atacant... • http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-ntlmssp.c?r1=53626&r2=53625&pathrev=53626 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2013-6339 – wireshark: ActiveMQ OpenWire dissector large loop (wnpa-sec-2013-64)
https://notcve.org/view.php?id=CVE-2013-6339
04 Nov 2013 — The dissect_openwire_type function in epan/dissectors/packet-openwire.c in the OpenWire dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 allows remote attackers to cause a denial of service (loop) via a crafted packet. La función dissect_openwire_type en epan / dissectors / packet-openwire.c en diseccionador de OpenWire en Wireshark 1.8.11 y 1.8.x antes de 1.10.x antes de 1.10.3 permite a atacantes remotos provocar una denegación de servicio (bucle) a través de un paquete manipulado . The... • http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-openwire.c?r1=52458&r2=52457&pathrev=52458 • CWE-20: Improper Input Validation •

CVE-2013-6336 – wireshark: IEEE 802.15.4 dissector crash (wnpa-sec-2013-61)
https://notcve.org/view.php?id=CVE-2013-6336
04 Nov 2013 — The ieee802154_map_rec function in epan/dissectors/packet-ieee802154.c in the IEEE 802.15.4 dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 uses an incorrect pointer chain, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. La función ieee802154_map_rec en epan/dissectors/packet-ieee802154.c en el analizador de IEEE 802.15.4 en Wireshark 1.8.x antes de 1.8.11 y 1.10.x antes de 1.10.3 utiliza una cadena de puntero incorrecto, lo que permit... • http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-ieee802154.c?r1=52036&r2=52035&pathrev=52036 • CWE-20: Improper Input Validation •

CVE-2013-6337 – wireshark: NBAP dissector crash (wnpa-sec-2013-62)
https://notcve.org/view.php?id=CVE-2013-6337
04 Nov 2013 — Unspecified vulnerability in the NBAP dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 allows remote attackers to cause a denial of service (application crash) via a crafted packet. Vulnerabilidad no especificada en el analizador de NBAP en Wireshark 11.8.x antes de 1.8.11 y 1.10.x antes de 1.10.3 permite a atacantes remotos provocar una denegación de servicio (caída de aplicación) a través de un paquete manipulado. The ieee802154_map_rec function in epan/dissectors/packet-ieee802154.c in... • http://lists.opensuse.org/opensuse-updates/2013-11/msg00026.html •

CVE-2013-6338 – wireshark: SIP dissector crash (wnpa-sec-2013-63)
https://notcve.org/view.php?id=CVE-2013-6338
04 Nov 2013 — The dissect_sip_common function in epan/dissectors/packet-sip.c in the SIP dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 does not properly initialize a data structure, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. La función dissect_sip_common en epan / dissectors / packet sip.c en el disecionador de SIP de Wireshark 1.8.x antes de 1.8.11 y 1.10.3 anterior a 1.10.x no inicializa correctamente una estructura de datos, lo que permite... • http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-sip.c?r1=52354&r2=52353&pathrev=52354 • CWE-20: Improper Input Validation •

CVE-2013-6340 – wireshark: TCP dissector crash (wnpa-sec-2013-65)
https://notcve.org/view.php?id=CVE-2013-6340
04 Nov 2013 — epan/dissectors/packet-tcp.c in the TCP dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 does not properly determine the amount of remaining data, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. epan / dissectors / packet-tcp.c en el diseccionador de TCP de Wireshark 1.8.11 y 1.8.x antes 1.10.x antes de 1.10.3 no determina correctamente la cantidad de datos restantes, que permite a atacantes remotos provocar una denegación de servicio (... • http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-tcp.c?r1=52570&r2=52569&pathrev=52570 • CWE-20: Improper Input Validation •

CVE-2013-5718 – Debian Security Advisory 2756-1
https://notcve.org/view.php?id=CVE-2013-5718
13 Sep 2013 — The dissect_nbap_T_dCH_ID function in epan/dissectors/packet-nbap.c in the NBAP dissector in Wireshark 1.8.x before 1.8.10 and 1.10.x before 1.10.2 does not restrict the dch_id value, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. La función dissect_nbap_T_dCH_ID en epan/dissectors/packet-nbap.c del disector NBAP en Wireshark 1.8.x (anteriores a 1.8.10) y 1.10.x (anteriores a 1.10.2) no restringe el valor dch_id, lo que permite a atacantes remotos causar... • http://anonsvn.wireshark.org/viewvc?view=revision&revision=51195 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2013-5719 – Gentoo Linux Security Advisory 201312-13
https://notcve.org/view.php?id=CVE-2013-5719
13 Sep 2013 — epan/dissectors/packet-assa_r3.c in the ASSA R3 dissector in Wireshark 1.8.x before 1.8.10 and 1.10.x before 1.10.2 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet. epan/dissectors/packet-assa_r3.c en el disector ASSA R3 en Wireshark 1.8.x anterior a 1.8.10 y 1.10.x anterior a 1.10.2 permite a atacantes remotos provocar una denegación de servicio (bucle infinito) a través de un paquete manipulado. The dissect_nbap_T_dCH_ID function in epan/dissectors/packet-nbap.c i... • http://anonsvn.wireshark.org/viewvc?view=revision&revision=51196 • CWE-399: Resource Management Errors •

CVE-2013-5720 – Debian Security Advisory 2756-1
https://notcve.org/view.php?id=CVE-2013-5720
13 Sep 2013 — Buffer overflow in the RTPS dissector in Wireshark 1.8.x before 1.8.10 and 1.10.x before 1.10.2 allows remote attackers to cause a denial of service (application crash) via a crafted packet. Desbordamiento de buffer en el disector RTPS de Wireshark 1.8.x anteriores a 1.8.10 y 1.10.x anteriores a 1.10.2 permite a atacantes remotos causar denegación de servicio (caída de aplicación) a través de un paquete manipulado. The dissect_nbap_T_dCH_ID function in epan/dissectors/packet-nbap.c in the NBAP dissector in ... • http://lists.opensuse.org/opensuse-updates/2013-09/msg00050.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2013-5721 – wireshark: MQ dissector crash (wnpa-sec-2013-58, upstream bug 9079)
https://notcve.org/view.php?id=CVE-2013-5721
13 Sep 2013 — The dissect_mq_rr function in epan/dissectors/packet-mq.c in the MQ dissector in Wireshark 1.8.x before 1.8.10 and 1.10.x before 1.10.2 does not properly determine when to enter a certain loop, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. La función dissect_mq_rr en epan/dissectors/packet-mq.c de MQ dissector de Wireshark 1.8.x anterior a 1.8.10 y 1.10.x anterior a 1.10.2 no determina apropiadamente cuando entrar en un deteminado bucle , lo que permite... • http://anonsvn.wireshark.org/viewvc?view=revision&revision=51603 • CWE-20: Improper Input Validation •