CVE-2015-8733 is an out-of-bounds read vulnerability in the Sniffer file parser of Wireshark versions 1.12.x before 1.12.9 and 2.0.x before 2.0.1. This flaw allows a remote attacker to cause a denial of service (application crash) by providing a specially crafted file that exploits improper validation of record and header lengths. Rated Medium severity (CVSS 5.5), it requires user interaction (UI:R) to open the malicious file, with a local attack vector (AV:L). While not listed in CISA's KEV catalog or Hot List, an ExploitDB entry (EDB-39076) exists for a heap out-of-bounds read, indicating public exploit code availability. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.12.0CPE matchmatch criteria | cpe:2.3:a:wireshark:wireshark:1.12.0:*:*:*:*:*:*:* | ||
1.12.1CPE matchmatch criteria | cpe:2.3:a:wireshark:wireshark:1.12.1:*:*:*:*:*:*:* | ||
1.12.2CPE matchmatch criteria | cpe:2.3:a:wireshark:wireshark:1.12.2:*:*:*:*:*:*:* | ||
1.12.3CPE matchmatch criteria | cpe:2.3:a:wireshark:wireshark:1.12.3:*:*:*:*:*:*:* | ||
1.12.4CPE matchmatch criteria | cpe:2.3:a:wireshark:wireshark:1.12.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.