
CVE-2016-5353 – Debian Security Advisory 3615-1
https://notcve.org/view.php?id=CVE-2016-5353
02 Jul 2016 — epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles the reserved C/T value, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. epan/dissectors/packet-umts_fp.c en el disector UMTS FP en Wireshark 1.12.x en versiones anteriores a 1.12.12 y 2.x en versiones anteriores a 2.0.4 no maneja correctamente el valor reservado C/T, lo que permite a atacantes remotos provocar una denegación de serv... • http://www.debian.org/security/2016/dsa-3615 • CWE-20: Improper Input Validation •

CVE-2016-5354 – Debian Security Advisory 3615-1
https://notcve.org/view.php?id=CVE-2016-5354
02 Jul 2016 — The USB subsystem in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles class types, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. El subsistema de USB en Wireshark 1.12.x en versiones anteriores a 1.12.12 y 2.x en versiones anteriores a 2.0.4 no maneja correctamente tipos de clase, lo que permite a atacantes remotos provocar una denegación de servicio (caída de aplicación) a través de un paquete manipulado. Multiple vulnerabilities were di... • http://www.debian.org/security/2016/dsa-3615 • CWE-476: NULL Pointer Dereference •

CVE-2016-5355 – Debian Security Advisory 3615-1
https://notcve.org/view.php?id=CVE-2016-5355
02 Jul 2016 — wiretap/toshiba.c in the Toshiba file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, which allows remote attackers to cause a denial of service (application crash) via a crafted file. wiretap/toshiba.c en el analizador de archivo Toshiba en Wireshark 1.12.x en versiones anteriores a 1.12.12 y 2.x en versiones anteriores a 2.0.4 no maneja correctamente procesamiento sin signo de entero sscanf, lo que permite a atacantes remotos provocar una deneg... • http://www.debian.org/security/2016/dsa-3615 • CWE-20: Improper Input Validation •

CVE-2016-5357 – Debian Security Advisory 3615-1
https://notcve.org/view.php?id=CVE-2016-5357
02 Jul 2016 — wiretap/netscreen.c in the NetScreen file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, which allows remote attackers to cause a denial of service (application crash) via a crafted file. wiretap/netscreen.c en el analizador de archivo NetScreen en Wireshark 1.12.x en versiones anteriores a 1.12.12 y 2.x en versiones anteriores a 2.0.4 no maneja correctamente procesamiento sin signo de entero sscanf, lo que permite a atacantes remotos provocar u... • http://www.debian.org/security/2016/dsa-3615 • CWE-20: Improper Input Validation •

CVE-2016-4416
https://notcve.org/view.php?id=CVE-2016-4416
01 May 2016 — epan/dissectors/packet-ieee80211.c in the IEEE 802.11 dissector in Wireshark 2.x before 2.0.2 mishandles the Grouping subfield, which allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet. epan/dissectors/packet-ieee80211.c en el disector IEEE 802.11 en Wireshark 2.x en versiones anteriores a 2.0.2 maneja incorrectamente el subcampo Grouping, lo que permite a atacantes remotos provocar una denegación de servicio (sobrelectura de buffer y caída de ... • https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11818 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2016-4418
https://notcve.org/view.php?id=CVE-2016-4418
01 May 2016 — epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.12.x before 1.12.10 and 2.x before 2.0.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet that triggers an empty set. epan/dissectors/packet-ber.c en el disector ASN.1 BER en Wireshark 1.12.x en versiones anteriores a 1.12.10 y 2.x en versiones anteriores a 2.0.2 permite a atacantes remotos provocar una denegación de servicio (sobrelectura de buffer y caída de aplicación) ... • http://lists.opensuse.org/opensuse-updates/2016-03/msg00015.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2016-4419
https://notcve.org/view.php?id=CVE-2016-4419
01 May 2016 — epan/dissectors/packet-spice.c in the SPICE dissector in Wireshark 2.x before 2.0.2 mishandles capability data, which allows remote attackers to cause a denial of service (large loop) via a crafted packet. epan/dissectors/packet-spice.c en el disector SPICE en Wireshark 2.x en versiones anteriores a 2.0.2 maneja incorrectamente datos capability, lo que permite a atacantes remotos provocar una denegación de servicio (bucle grande) a través de un paquete manipulado. • https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=12151 • CWE-399: Resource Management Errors •

CVE-2016-4417
https://notcve.org/view.php?id=CVE-2016-4417
01 May 2016 — Off-by-one error in epan/dissectors/packet-gsm_abis_oml.c in the GSM A-bis OML dissector in Wireshark 1.12.x before 1.12.10 and 2.x before 2.0.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet that triggers a 0xff tag value. Error por un paso en epan/dissectors/packet-gsm_abis_oml.c en el disector GSM A-bis OML en Wireshark 1.12.x en versiones anteriores a 1.12.10 y 2.x en versiones anteriores a 2.0.2 permite a atacantes remotos provocar una... • http://lists.opensuse.org/opensuse-updates/2016-03/msg00015.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2016-4420
https://notcve.org/view.php?id=CVE-2016-4420
01 May 2016 — The NFS dissector in Wireshark 2.x before 2.0.2 allows remote attackers to cause a denial of service (application crash) via a crafted packet. El disector NFS en Wireshark 2.x en versiones anteriores a 2.0.2 permite a atacantes remotos provocar una denegación de servicio (caída de aplicación) a través de un paquete manipulado. • https://www.wireshark.org/security/wnpa-sec-2016-17.html • CWE-20: Improper Input Validation •

CVE-2016-4415
https://notcve.org/view.php?id=CVE-2016-4415
01 May 2016 — wiretap/vwr.c in the Ixia IxVeriWave file parser in Wireshark 2.x before 2.0.2 incorrectly increases a certain octet count, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a crafted file. wiretap/vwr.c en el intérprete de archivo Ixia IxVeriWave en Wireshark 2.x en versiones anteriores a 2.0.2 incrementa incorrectamente una determinada cuenta de octeto, lo que permite a atacantes remotos provocar una denegación de servicio (desbordamiento de ... • https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11795 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •