CVE-2016-2525 describes a denial-of-service vulnerability in the HTTP/2 dissector within Wireshark versions 2.0.x prior to 2.0.2. This flaw allows remote attackers to consume excessive memory or crash the application by sending a specially crafted packet that exploits the dissector's failure to limit header data. Rated Medium severity (CVSS 5.9), it requires high attack complexity but can lead to high availability impact without user interaction. While not actively exploited (no KEV entry or public exploit code), it garnered some community and media attention upon disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.0CPE matchmatch criteria | cpe:2.3:a:wireshark:wireshark:2.0.0:*:*:*:*:*:*:* | ||
2.0.1CPE matchmatch criteria | cpe:2.3:a:wireshark:wireshark:2.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.