Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-15165

21
FAUCET Score

CVE-2019-15165 is a vulnerability in libpcap, affecting products from vendors including Apple, Canonical, and Oracle, where improper validation of the PHB header length in sf-pcapng.c can lead to memory allocation issues. Rated as Medium severity (CVSS 5.3), it is a network-exploitable vulnerability with low attack complexity, potentially resulting in a denial of service or other availability impacts without requiring user interaction. There is currently no evidence of active exploitation, no publicly available exploit code in Metasploit or ExploitDB, and minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.9.1CPE matchmatch criteria
cpe:2.3:a:tcpdump:libpcap:*:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
9.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
15.0CPE matchmatch criteria
cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*
15.1CPE matchmatch criteria
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.83%
Probability of exploitation in next 30 days
EPSS Percentile
85.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0283 is in the 79th percentile among its peer group of 23,701 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

github_advisorypatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: libpcap-14:1.9.1-4.el8
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: libpcap

Vendor Advisories (1)

redhatCVE-2019-15165Low

libpcap: Resource exhaustion during PHB header length validation

Sep 20, 2019

References

lists.opensuse.org / opensuse-security-announce/2019-10/msg00051.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2019-10/msg00052.html
Mailing ListThird Party Advisory
seclists.org / fulldisclosure/2019/Dec/26
Issue TrackingMailing ListThird Party Advisory
github.com / the-tcpdump-group/libpcap/blob/libpcap-1.9/CHANGES
ProductRelease Notes
github.com / the-tcpdump-group/libpcap/commit/87d6bef033062f969e70fa40c43dfd945d5a20ab
PatchThird Party Advisory
github.com / the-tcpdump-group/libpcap/commit/a5a36d9e82dde7265e38fe1f87b7f11c461c29f6
PatchThird Party Advisory
lists.debian.org / debian-lts-announce/2019/10/msg00031.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2021/12/msg00014.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/5P5K3DQ4TFSZBDB3XN4CZNJNQ3UIF3D3
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/GBIEKWLNIR62KZ5GA7EDXZS52HU6OE5F
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/UZTIPUWABYUE5KQOLCKAW65AUUSB7QO6
seclists.org / bugtraq/2019/Dec/23
Mailing ListThird Party Advisory
support.apple.com / kb/HT210785
Third Party Advisory
support.apple.com / kb/HT210788
Third Party Advisory
support.apple.com / kb/HT210789
Third Party Advisory
support.apple.com / kb/HT210790
Third Party Advisory
usn.ubuntu.com / 4221-1
Third Party Advisory
usn.ubuntu.com / 4221-2
Third Party Advisory
oracle.com / security-alerts/cpuapr2020.html
Third Party Advisory
tcpdump.org / public-cve-list.txt
Vendor Advisory