📦

tcpdump

Vendor: tcpdump

Actively Exploited 0 CISA KEV List
PoC / Exploits 18 Code Available
Total RCEs 2 Remote Access
Total CVEs 2448 Total Indexed
Avg. EPSS 4.60% Exploit Prob.
Latest CVE CVE-2023-1801 Apr 07

Security Vulnerability Index

Page 1 / 245
6.5 CVSS

The SMB protocol decoder in tcpdump version 4.99.3 can perform an out-of-bounds write when decoding a crafted network packet.

EPSS: 0.84%
9.1 CVSS

The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 3, a different vulnerability than CVE-2018-14463.

EPSS: 0.90%
7.5 CVSS

The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.

EPSS: 3.07%
7.5 CVSS
CVE-2020-8036
Exploit Found

The tok2strbuf() function in tcpdump 4.10.0-PRE-GIT was used by the SOME/IP dissector in an unsafe way.

EPSS: 1.45%
1.6 CVSS

lmp_print_data_link_subobjs() in print-lmp.c in tcpdump before 4.9.3 lacks certain bounds checks.

EPSS: 4.99%
7.5 CVSS

The SMB parser in tcpdump before 4.9.3 has stack exhaustion in smbutil.c:smb_fdata() via recursion.

EPSS: 4.12%
7.5 CVSS

The SMB parser in tcpdump before 4.9.3 has buffer over-reads in print-smb.c:print_trans() for \MAILSLOT\BROWSE and \PIPE\LANMAN.

EPSS: 4.13%
7.8 CVSS

The command-line argument parser in tcpdump before 4.99.0 has a buffer overflow in tcpdump.c:read_infile(). To trigger this vulnerability the attacker needs to create a 4GB file on the local filesystem and to specify the file name as the value of the -F command-line argument of tcpdump.

EPSS: 0.63%
7.5 CVSS

The BGP parser in tcpdump before 4.9.3 allows stack consumption in print-bgp.c:bgp_attr_print() because of unlimited recursion.

EPSS: 4.12%
7.5 CVSS

The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_attr_print() (MP_REACH_NLRI).

EPSS: 3.89%