← Back

Ethereal

ethereal

Vendor: Ethereal • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ethereal
1Ethereal
Apr 16, 2026
May 4, 2004
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The dissect_attribute_value_pairs function in packet-radius.c for Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a malformed RADIUS packet that triggers a null dereference.
1Ethereal
1Ethereal
Apr 16, 2026
Jan 5, 2004
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Q.931 dissector in Ethereal before 0.10.0, and Tethereal, allows remote attackers to cause a denial of service (crash) via a malformed Q.931, which triggers a null dereference.
1Ethereal
1Ethereal
Apr 16, 2026
Jun 9, 2003
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake,...Show more
Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake, (6) Quake2, (7) Quake3, (8) Rsync, (9) SMB, (10) SMPP, and (11) TSP dissectors, which do not properly use the tvb_get_nstringz and tvb_get_nstringz0 functions.Show less
2Debian
Ethereal
2Debian Linux
Ethereal
Apr 16, 2026
Jun 18, 2002
N/A· v4
7.5 HIGH· v3
7.5 HIGH· v2
SMB dissector in Ethereal 0.9.3 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via malformed packets that cause Ethereal to dereference a NULL pointer.