CVE-2010-0304
Wireshark - Memory Corruption
Title source: ruleDescription
Multiple buffer overflows in the LWRES dissector in Wireshark 0.9.15 through 1.0.10 and 1.2.0 through 1.2.5 allow remote attackers to cause a denial of service (crash) via a malformed packet, as demonstrated using a stack-based buffer overflow to the dissect_getaddrsbyname_request function.
Exploits (5)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/16292
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotelinux
https://www.exploit-db.com/exploits/16289
exploitdb
WORKING POC
VERIFIED
by babi · pythondosmultiple
https://www.exploit-db.com/exploits/11288
metasploit
WORKING POC
GREAT
by babi, jduck, redsand · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/misc/wireshark_lwres_getaddrbyname.rb
metasploit
WORKING POC
GREAT
by babi, jduck, redsand · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/misc/wireshark_lwres_getaddrbyname_loop.rb
Scores
EPSS
0.7471
EPSS Percentile
98.9%
Details
CWE
CWE-119
Status
published
Products (20)
wireshark/wireshark
0.9.15
wireshark/wireshark
1.0
wireshark/wireshark
1.0.0
wireshark/wireshark
1.0.1
wireshark/wireshark
1.0.2
wireshark/wireshark
1.0.3
wireshark/wireshark
1.0.4
wireshark/wireshark
1.0.5
wireshark/wireshark
1.0.6
wireshark/wireshark
1.0.7
... and 10 more
Published
Feb 03, 2010
Tracked Since
Feb 18, 2026