Tcpdump Group maintains a deceptively small but critically situated product portfolio centered on the tcpdump packet-capture utility and its foundational library libpcap, which are embedded across countless network monitoring, forensics, and security tools despite their narrow direct user base. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur through memory-safety weakness classes including out-of-bounds reads, buffer overflows, improper bounds checking, and infinite loops that are endemic to parsing untrusted packet data at the wire level. The exposure is concentrated in tcpdump, libpcap, and related tools such as tcpslice, where the challenge of safely handling arbitrary, malformed, or adversarial network traffic in memory-constrained capture contexts creates a durable attack surface. Defenders should treat tcpdump and libpcap updates as broadly applicable despite their compact footprint, since remediation often requires rebuilds across dependent tools and infrastructure; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tcpdump Group over time
Of all the CVEs published by Tcpdump Group as a CNA, 70.0% affect products that Tcpdump Group develops as a vendor.
Of all the CVEs published that affect products developed by Tcpdump Group, 3.9% are self-published by Tcpdump Group as a CNA.
Signals from CVEs in this vendor scope (181 CVEs).
181 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-3798CRITICAL Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an | Jul 16, 2007 | 9.8 | 78 | NO | YES |
CVE-2004-0184MEDIUM Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with an Identification payl | May 4, 2004 | 5.0 | 54 | NO | YES |
CVE-2016-8575CRITICAL The Q.933 parser in tcpdump before 4.9.0 has a buffer overflow in print-fr.c:q933_print(), a different vulnerability than CVE-2017-5482. | Jan 28, 2017 | 9.8 | 34 | NO | NO |
CVE-2017-5482CRITICAL The Q.933 parser in tcpdump before 4.9.0 has a buffer overflow in print-fr.c:q933_print(), a different vulnerability than CVE-2016-8575. | Jan 28, 2017 | 9.8 | 33 | NO | NO |
CVE-2017-5342CRITICAL In tcpdump before 4.9.0, a bug in multiple protocol parsers (Geneve, GRE, NSH, OTV, VXLAN and VXLAN GPE) could cause a buffer overflow in print-ether.c:ether_print(). | Jan 28, 2017 | 9.8 | 33 | NO | NO |
CVE-2017-13050CRITICAL The RPKI-Router parser in tcpdump before 4.9.2 has a buffer over-read in print-rpki-rtr.c:rpki_rtr_pdu_print(). | Sep 14, 2017 | 9.8 | 32 | NO | NO |
CVE-2017-13039CRITICAL The ISAKMP parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c, several functions. | Sep 14, 2017 | 9.8 | 32 | NO | NO |
CVE-2017-13022CRITICAL The IP parser in tcpdump before 4.9.2 has a buffer over-read in print-ip.c:ip_printroute(). | Sep 14, 2017 | 9.8 | 32 | NO | NO |
CVE-2017-13004CRITICAL The Juniper protocols parser in tcpdump before 4.9.2 has a buffer over-read in print-juniper.c:juniper_parse_header(). | Sep 14, 2017 | 9.8 | 32 | NO | NO |
CVE-2017-11541CRITICAL tcpdump 4.9.0 has a heap-based buffer over-read in the lldp_print function in print-lldp.c, related to util-print.c. | Jul 23, 2017 | 9.8 | 32 | NO | NO |
Signals from CVEs in this vendor scope (181 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tcpdump Group.
Media articles that mention a CVE ID that affects a product developed by Tcpdump Group — matched by CVE ID, not by vendor name.