CVE-2015-8726
MEDIUMWireshark - Memory Corruption
Title source: ruleDescription
wiretap/vwr.c in the VeriWave file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate certain signature and Modulation and Coding Scheme (MCS) data, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Google Security Research · textdosmultiple
https://www.exploit-db.com/exploits/39004
References (10)
Scores
CVSS v3
5.5
EPSS
0.0097
EPSS Percentile
76.4%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Classification
CWE
CWE-119
CWE-20
Status
draft
Affected Products (10)
wireshark/wireshark
wireshark/wireshark
wireshark/wireshark
wireshark/wireshark
wireshark/wireshark
wireshark/wireshark
wireshark/wireshark
wireshark/wireshark
wireshark/wireshark
wireshark/wireshark
Timeline
Published
Jan 04, 2016
Tracked Since
Feb 18, 2026