Tcpdump Group

First CVE: Oct 3, 2019Active for: 7 years
10
CVEs Published
More CVEs Published than 27% of tracked CNAs
1.7
Avg CVEs / Year
More Avg CVEs / Year than 10% of tracked CNAs
5.4
Avg CVSS Score
Higher Avg CVSS Score than 4% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Tcpdump Group as a CNA, 70.0% affect products that Tcpdump Group develops as a vendor.

70.0%
30.0%
Self-reported: 7Third-party: 3

Of all the CVEs published that affect products developed by Tcpdump Group, 3.9% are self-published by Tcpdump Group as a CNA.

96.1%
Self-published: 7Published by other CNAs: 174

Trends Over Time

The number and severity of CVEs published by Tcpdump Group over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 3, 2019
6 years ago
Most Recent CVE
Dec 31, 2025
205 days ago

Top CVEs

All CVEs published by Tcpdump Group as a CNA, regardless of affected vendor or product.

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.
Nov 4, 20207.526NONO
The command-line argument parser in tcpdump before 4.99.0 has a buffer overflow in tcpdump.c:read_infile(). To trigger this vulnerability the attacker needs to create a 4GB file on
Oct 3, 20197.826NONO
The tok2strbuf() function in tcpdump 4.10.0-PRE-GIT was used by the SOME/IP dissector in an unsafe way.
Nov 4, 20207.525NONO
The SMB protocol decoder in tcpdump version 4.99.3 can perform an out-of-bounds write when decoding a crafted network packet.
Apr 7, 20236.522NONO
Use after free in tcpslice triggers AddressSanitizer, no other confirmed impact.
Jan 5, 20225.520NONO
Due to a bug in packet data buffers management, the PPP printer in tcpdump can enter an infinite loop when reading a crafted DLT_PPP_SERIAL .pcap savefile. This problem does not a
Apr 12, 20246.218NONO
Remote packet capture support is disabled by default in libpcap. When a user builds libpcap with remote packet capture support enabled, one of the functions that become available
Aug 31, 20244.416NONO
pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buffer. The string argument must be a well-formed MAC-48 addre
Dec 31, 20251.915NONO
On Windows only, if libpcap needs to convert a Windows error message to UTF-8 and the message includes characters that UTF-8 represents using 4 bytes, utf_16le_to_utf_8_truncated()
Dec 31, 20251.914NONO
In affected libpcap versions during the setup of a remote packet capture the internal function sock_initaddress() calls getaddrinfo() and possibly freeaddrinfo(), but does not clea
Aug 31, 20244.414NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA10 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHigh
Attack Vector
Local7 (70.0%)
Network3 (30.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (80.0%)
High2 (20.0%)
Unknown0 (0.0%)
User Interaction
None7 (70.0%)
Unknown0 (0.0%)
Required3 (30.0%)
Privileges Required
Low0 (0.0%)
High4 (40.0%)
None6 (60.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Tcpdump Group as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Tcpdump Group as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs