Wireshark is a ubiquitously deployed packet-analysis and network-protocol inspection tool that occupies a critical role in network diagnostics, security monitoring, and forensic investigation across enterprises and security operations worldwide. Despite its concentrated product portfolio, the volume and prominence of its vulnerabilities reflect its deep penetration into network infrastructure and its position as a trusted application in high-value defensive workflows. The vendor's disclosures recur around improper input validation, buffer-boundary violations, and infinite-loop conditions—characteristic of a parser-heavy application that must gracefully handle untrusted network traffic in an enormous variety of protocol formats and edge cases. While individual severity and exploitation tendencies vary, defenders should treat Wireshark updates as routine and broadly applicable maintenance, particularly for instances that process untrusted network capture files or live traffic; current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wireshark over time
Signals from CVEs in this vendor scope (748 CVEs).
748 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-0304HIGH Multiple buffer overflows in the LWRES dissector in Wireshark 0.9.15 through 1.0.10 and 1.2.0 through 1.2.5 allow remote attackers to cause a denial of service (crash) via a malfor | Feb 3, 2010 | 7.5 | 81 | NO | YES |
CVE-2014-2299HIGH Buffer overflow in the mpeg_read function in wiretap/mpeg.c in the MPEG parser in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 allows remote attackers to execute arbitrar | Mar 11, 2014 | 9.3 | 73 | NO | YES |
CVE-2011-1591HIGH Stack-based buffer overflow in the DECT dissector in epan/dissectors/packet-dect.c in Wireshark 1.4.x before 1.4.5 allows remote attackers to execute arbitrary code via a crafted . | Apr 29, 2011 | 9.3 | 72 | NO | YES |
CVE-2011-3360HIGH Untrusted search path vulnerability in Wireshark 1.4.x before 1.4.9 and 1.6.x before 1.6.2 allows local users to gain privileges via a Trojan horse Lua script in an unspecified dir | Sep 20, 2011 | 9.3 | 69 | NO | YES |
CVE-2013-4074MEDIUM The dissect_capwap_data function in epan/dissectors/packet-capwap.c in the CAPWAP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x before 1.8.8 incorrectly uses a -1 data value | Jun 9, 2013 | 5.0 | 63 | NO | YES |
CVE-2008-1562MEDIUM The LDAP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.8 allows remote attackers to cause a denial of service (application crash) via a malformed packet, a differe | Mar 31, 2008 | 5.0 | 60 | NO | YES |
CVE-2010-4538HIGH Buffer overflow in the sect_enttec_dmx_da function in epan/dissectors/packet-enttec.c in Wireshark 1.4.2 allows remote attackers to cause a denial of service (application crash) or | Jan 7, 2011 | 9.3 | 54 | NO | YES |
CVE-2017-17085HIGH In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the CIP Safety dissector could crash. This was addressed in epan/dissectors/packet-cipsafety.c by validating the packet length. | Dec 1, 2017 | 7.5 | 44 | NO | YES |
CVE-2018-19627HIGH In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the IxVeriWave file parser could crash. This was addressed in wiretap/vwr.c by adjusting a buffer boundary. | Nov 29, 2018 | 7.5 | 43 | NO | YES |
CVE-2017-9347HIGH In Wireshark 2.2.0 to 2.2.6, the ROS dissector could crash with a NULL pointer dereference. This was addressed in epan/dissectors/asn1/ros/packet-ros-template.c by validating an OI | Jun 2, 2017 | 7.5 | 42 | NO | YES |
Signals from CVEs in this vendor scope (748 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wireshark.
Media articles that mention a CVE ID that affects a product developed by Wireshark — matched by CVE ID, not by vendor name.