Ethereal Group maintains a narrowly scoped product portfolio centered on the Ethereal application, which despite its limited product surface commands prominence in the vulnerability landscape, likely reflecting deep integration or widespread deployment in critical infrastructure or security tooling. The vulnerability exposure recurs through a mix of memory-safety and input-handling weakness classes, including buffer-boundary violations, improper input validation, and format-string flaws that are characteristic of legacy or performance-sensitive codebases. A moderate share of the vendor's disclosures have acquired public exploit code, consistent with the appeal of such flaws to researchers and tool developers. The concentration of high-prevalence CVEs within a single product underscores the importance of maintaining vigilant patch cycles for this widely trusted component. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ethereal Group over time
Signals from CVEs in this vendor scope (105 CVEs).
105 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0176MEDIUM Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) NetFlow, (2) IGAP, (3) EI | May 4, 2004 | 5.0 | 58 | NO | YES |
CVE-2005-3243HIGH Multiple buffer overflows in Ethereal 0.10.12 and earlier might allow remote attackers to execute arbitrary code via unknown vectors in the (1) SLIMP3 and (2) AgentX dissector. | Oct 27, 2005 | 7.5 | 33 | NO | YES |
CVE-2005-1461HIGH Multiple buffer overflows in the (1) SIP, (2) CMIP, (3) CMP, (4) CMS, (5) CRMF, (6) ESS, (7) OCSP, (8) X.509, (9) ISIS, (10) DISTCC, (11) FCELS, (12) Q.931, (13) NCP, (14) TCAP, (1 | May 5, 2005 | 7.5 | 31 | NO | YES |
CVE-2005-2367HIGH Format string vulnerability in the proto_item_set_text function in Ethereal 0.9.4 through 0.10.11, as used in multiple dissectors, allows remote attackers to write to arbitrary mem | Aug 10, 2005 | 7.5 | 30 | NO | YES |
CVE-2004-0633MEDIUM The iSNS dissector for Ethereal 0.10.3 through 0.10.4 allows remote attackers to cause a denial of service (process abort) via an integer overflow. | Dec 6, 2004 | 5.0 | 30 | NO | YES |
CVE-2003-0431HIGH The tvb_get_nstringz0 function in Ethereal 0.9.12 and earlier does not properly handle a zero-length buffer size, with unknown consequences. | Jul 24, 2003 | 10.0 | 30 | NO | NO |
CVE-2000-1174HIGH Multiple buffer overflows in AFS ACL parser for Ethereal 0.8.13 and earlier allows remote attackers to execute arbitrary commands via a packet with a long username. | Jan 9, 2001 | 7.5 | 30 | NO | YES |
CVE-2006-3628HIGH Multiple format string vulnerabilities in Wireshark (aka Ethereal) 0.10.x to 0.99.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the | Jul 21, 2006 | 10.0 | 27 | NO | NO |
CVE-2006-3632HIGH Buffer overflow in Wireshark (aka Ethereal) 0.8.16 to 0.99.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via the NFS dissector. | Jul 21, 2006 | 10.0 | 27 | NO | NO |
CVE-2005-3184HIGH Buffer overflow vulnerability in the unicode_to_bytes in the Service Location Protocol (srvloc) dissector (packet-srvloc.c) in Ethereal allows remote attackers to execute arbitrary | Oct 20, 2005 | 10.0 | 27 | NO | NO |
Signals from CVEs in this vendor scope (105 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ethereal Group.
Media articles that mention a CVE ID that affects a product developed by Ethereal Group — matched by CVE ID, not by vendor name.