CVE-2012-3826 describes multiple integer underflow vulnerabilities in Wireshark versions 1.4.x before 1.4.13 and 1.6.x before 1.6.8, specifically within the R3 dissector, which can lead to a denial of service (loop). This vulnerability has a CVSS score of 3.3, indicating a low severity, as it requires adjacent network access (AV:A) and results in partial availability impact (A:P) without requiring authentication. While there is no evidence of active exploitation or inclusion in the CISA KEV catalog, an exploit for a related denial of service vulnerability in Wireshark dissectors is available on ExploitDB, and there is minimal community discussion or media coverage surrounding this specific CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.4.0CPE matchmatch criteria | cpe:2.3:a:wireshark:wireshark:1.4.0:*:*:*:*:*:*:* | ||
1.4.1CPE matchmatch criteria | cpe:2.3:a:wireshark:wireshark:1.4.1:*:*:*:*:*:*:* | ||
1.4.2CPE matchmatch criteria | cpe:2.3:a:wireshark:wireshark:1.4.2:*:*:*:*:*:*:* | ||
1.4.3CPE matchmatch criteria | cpe:2.3:a:wireshark:wireshark:1.4.3:*:*:*:*:*:*:* | ||
1.4.4CPE matchmatch criteria | cpe:2.3:a:wireshark:wireshark:1.4.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:A/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.