
CVE-2014-8710 – wireshark: SigComp dissector crash (wnpa-sec-2014-20)
https://notcve.org/view.php?id=CVE-2014-8710
21 Nov 2014 — The decompress_sigcomp_message function in epan/sigcomp-udvm.c in the SigComp UDVM dissector in Wireshark 1.10.x before 1.10.11 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet. La función decompress_sigcomp_message en epan/sigcomp-udvm.c en el diseccionador SigComp UDVM en Wireshark 1.10.x anterior a 1.10.11 permite a atacantes remotos causar una denegación de servicio (sobrelectura de buffer y caída de aplicación) a través de un paquete man... • http://lists.fedoraproject.org/pipermail/package-announce/2014-December/145658.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2014-8711 – wireshark: AMQP dissector crash (wnpa-sec-2014-21)
https://notcve.org/view.php?id=CVE-2014-8711
21 Nov 2014 — Multiple integer overflows in epan/dissectors/packet-amqp.c in the AMQP dissector in Wireshark 1.10.x before 1.10.11 and 1.12.x before 1.12.2 allow remote attackers to cause a denial of service (application crash) via a crafted amqp_0_10 PDU in a packet. Múltiples desbordamientos de enteros en epan/dissectors/packet-amqp.c en el diseccionador AMQP en Wireshark 1.10.x anterior a 1.10.11 y 1.12.x anterior a 1.12.2 permiten a atacantes remotos causar una denegación de servicio (caída de aplicación) a través de... • http://lists.fedoraproject.org/pipermail/package-announce/2014-December/145658.html • CWE-189: Numeric Errors •

CVE-2014-8713 – wireshark: NCP dissector crashes (wnpa-sec-2014-22)
https://notcve.org/view.php?id=CVE-2014-8713
21 Nov 2014 — Stack-based buffer overflow in the build_expert_data function in epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 1.10.x before 1.10.11 and 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (application crash) via a crafted packet. Desbordamiento de buffer basado en pila en la función build_expert_data en epan/dissectors/packet-ncp2222.inc en el diseccionador NCP en Wireshark 1.10.x anterior a 1.10.11 y 1.12.x anterior a 1.12.2 permite a atacantes remotos causar u... • http://lists.fedoraproject.org/pipermail/package-announce/2014-December/145658.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2014-6428 – wireshark: SES dissector crash (wnpa-sec-2014-18)
https://notcve.org/view.php?id=CVE-2014-6428
20 Sep 2014 — The dissect_spdu function in epan/dissectors/packet-ses.c in the SES dissector in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 does not initialize a certain ID value, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. La función dissect_spdu en epan/dissectors/packet-ses.c en el diseccionador SES en Wireshark 1.10.x anterior a 1.10.10 y 1.12.x anterior a 1.12.1 no inicializa adecuadamente ciertos valores ID, lo que permite a atacantes remotos cau... • http://linux.oracle.com/errata/ELSA-2014-1676 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-456: Missing Initialization of a Variable •

CVE-2014-6429 – wireshark: DOS Sniffer file parser flaw (wnpa-sec-2014-19)
https://notcve.org/view.php?id=CVE-2014-6429
20 Sep 2014 — The SnifferDecompress function in wiretap/ngsniffer.c in the DOS Sniffer file parser in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 does not properly handle empty input data, which allows remote attackers to cause a denial of service (application crash) via a crafted file. La función SnifferDecompress en wiretap/ngsniffer.c en el analizador de ficheros DOS Sniffer en Wireshark 1.10.x anterior a 1.10.10 y 1.12.x anterior a 1.12.1 no maneja adecuadamente entrada de datos vacía, lo que permite a a... • http://linux.oracle.com/errata/ELSA-2014-1676 • CWE-20: Improper Input Validation •

CVE-2014-6421 – wireshark: RTP dissector crash (wnpa-sec-2014-12)
https://notcve.org/view.php?id=CVE-2014-6421
20 Sep 2014 — Use-after-free vulnerability in the SDP dissector in Wireshark 1.10.x before 1.10.10 allows remote attackers to cause a denial of service (application crash) via a crafted packet that leverages split memory ownership between the SDP and RTP dissectors. Vulnerabilidad de uso después de liberación en el diseccionador SDP en Wireshark 1.10.x anterior a 1.10.10 permite a atacantes remotos causar una denegación de servicio (caída de la aplicación) a través de un paquete manipulado que aprovecha la titularidad de... • http://linux.oracle.com/errata/ELSA-2014-1676 • CWE-416: Use After Free •

CVE-2014-6424 – wireshark: Netflow dissector crash (wnpa-sec-2014-14)
https://notcve.org/view.php?id=CVE-2014-6424
20 Sep 2014 — The dissect_v9_v10_pdu_data function in epan/dissectors/packet-netflow.c in the Netflow dissector in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 refers to incorrect offset and start variables, which allows remote attackers to cause a denial of service (uninitialized memory read and application crash) via a crafted packet. La función dissect_v9_v10_pdu_data en epan/dissectors/packet-netflow.c en el diseccionador Netflow en Wireshark 1.10.x anterior a 1.10.10 y 1.12.x anterior a 1.12.1 hace refer... • http://linux.oracle.com/errata/ELSA-2014-1676 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2014-6430 – wireshark: DOS Sniffer file parser flaw (wnpa-sec-2014-19)
https://notcve.org/view.php?id=CVE-2014-6430
20 Sep 2014 — The SnifferDecompress function in wiretap/ngsniffer.c in the DOS Sniffer file parser in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 does not validate bitmask data, which allows remote attackers to cause a denial of service (application crash) via a crafted file. La función SnifferDecompress en wiretap/ngsniffer.c en el analizador de ficheros DOS Sniffer en Wireshark 1.10.x anterior a 1.10.10 y 1.12.x anterior a 1.12.1 no valida datos de máscara de bits, lo que permite a atacantes remotos causar... • http://linux.oracle.com/errata/ELSA-2014-1676 • CWE-20: Improper Input Validation •

CVE-2014-6422 – wireshark: RTP dissector crash (wnpa-sec-2014-12)
https://notcve.org/view.php?id=CVE-2014-6422
20 Sep 2014 — The SDP dissector in Wireshark 1.10.x before 1.10.10 creates duplicate hashtables for a media channel, which allows remote attackers to cause a denial of service (application crash) via a crafted packet to the RTP dissector. El diseccionador SDP en Wireshark 1.10.x anterior a 1.10.10 crea tablas hash duplicadas para un canal de medios, lo que permite a un atacante causar una denegación de servicio (caída de la aplicación) a través de un paquete manipulado hacia el diseccionador RTP. Wireshark is a network p... • http://linux.oracle.com/errata/ELSA-2014-1676 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-416: Use After Free •

CVE-2014-6431 – wireshark: DOS Sniffer file parser flaw (wnpa-sec-2014-19)
https://notcve.org/view.php?id=CVE-2014-6431
20 Sep 2014 — Buffer overflow in the SnifferDecompress function in wiretap/ngsniffer.c in the DOS Sniffer file parser in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 allows remote attackers to cause a denial of service (application crash) via a crafted file that triggers writes of uncompressed bytes beyond the end of the output buffer. Desbordamiento de buffer en la función SnifferDecompress en wiretap/ngsniffer.c en el analizador de ficheros DOS Sniffer en Wireshark 1.10.x anterior a 1.10.10 y 1.12.x anterio... • http://linux.oracle.com/errata/ELSA-2014-1676 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •