Filtered by vendor Ethereal
Subscribe
Total
4 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2003-0356 | 1 Ethereal | 1 Ethereal | 2024-02-28 | 10.0 HIGH | 9.8 CRITICAL |
Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake, (6) Quake2, (7) Quake3, (8) Rsync, (9) SMB, (10) SMPP, and (11) TSP dissectors, which do not properly use the tvb_get_nstringz and tvb_get_nstringz0 functions. | |||||
CVE-2004-0365 | 1 Ethereal | 1 Ethereal | 2024-02-28 | 5.0 MEDIUM | 7.5 HIGH |
The dissect_attribute_value_pairs function in packet-radius.c for Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a malformed RADIUS packet that triggers a null dereference. | |||||
CVE-2002-0401 | 2 Debian, Ethereal | 2 Debian Linux, Ethereal | 2024-02-28 | 7.5 HIGH | 7.5 HIGH |
SMB dissector in Ethereal 0.9.3 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via malformed packets that cause Ethereal to dereference a NULL pointer. | |||||
CVE-2003-1013 | 1 Ethereal | 1 Ethereal | 2024-02-28 | 5.0 MEDIUM | 7.5 HIGH |
The Q.931 dissector in Ethereal before 0.10.0, and Tethereal, allows remote attackers to cause a denial of service (crash) via a malformed Q.931, which triggers a null dereference. |