Ethereal is a network protocol analysis tool with a narrowly scoped product footprint, where reported vulnerabilities center on memory-safety issues including NULL pointer dereferences and off-by-one errors common to packet-parsing code. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ethereal over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-0356CRITICAL Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP | Jun 9, 2003 | 9.8 | 34 | NO | NO |
CVE-2002-0401HIGH SMB dissector in Ethereal 0.9.3 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via malformed packets that cause Ethereal to dere | Jun 18, 2002 | 7.5 | 26 | NO | NO |
CVE-2004-0365HIGH The dissect_attribute_value_pairs function in packet-radius.c for Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a malformed RADIUS pack | May 4, 2004 | 7.5 | 21 | NO | NO |
CVE-2003-1013HIGH The Q.931 dissector in Ethereal before 0.10.0, and Tethereal, allows remote attackers to cause a denial of service (crash) via a malformed Q.931, which triggers a null dereference. | Jan 5, 2004 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ethereal.
Media articles that mention a CVE ID that affects a product developed by Ethereal — matched by CVE ID, not by vendor name.