Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2015-6244

The dissect_zbee_secure function in epan/dissectors/packet-zbee-security.c in the ZigBee dissector in Wireshark 1.12.x before 1.12.7 improperly relies on length fields contained in packet data, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

  • Published: Aug 25, 2015
  • Updated: Apr 13, 2023
  • CVE: CVE-2015-6244
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 4.3
  • AV:N/AC:M/Au:N/C:N/I:N/A:P

CWEs:

Software From Fixed in
wireshark / wireshark 1.12.4 1.12.4.x
wireshark / wireshark 1.12.5 1.12.5.x
wireshark / wireshark 1.12.0 1.12.0.x
wireshark / wireshark 1.12.2 1.12.2.x
wireshark / wireshark 1.12.1 1.12.1.x
wireshark / wireshark 1.12.6 1.12.6.x
wireshark / wireshark 1.12.3 1.12.3.x
oracle / solaris 11.3 11.3.x
oracle / linux 7 7.x