🚨 CVE-2026-76887
Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
Wireshark reassembly memory-safety report (#21423) · Issues · Wireshark Foundation / Wireshark · GitLab
Daniel Birtwhistle reported the following: Case: WS-REASM-WRAP-01 Audience: Wireshark security team Hello Wireshark Security Team, My name is Daniel Birtwhistle....
🚨 CVE-2026-76888
RDP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
RDP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
RDP8/ZGFX decompressor: off-by-one heap overflow in zgfx_write_literal() (outputSegment[65536]) (ANT-2026-05VXN1Y6) (#21396) ·…
I am writing to report a stack-buffer-overflow (write) that is triggerable by way of the Wireshark fuzzing harness fuzzshark) This is a security issue that...
🚨 CVE-2026-76889
UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
UMTS FP MAC-is descriptor count causes fixed-array out-of-bounds writes (#21413) · Issues · Wireshark Foundation / Wireshark ·…
Summary The UMTS FP dissector does not limit the number of MAC-is SDU descriptors before using the count...
🚨 CVE-2026-76890
Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
sharkd: use-after-return via dangling stack-array iograph tap listeners on error path (ANT-2026-GACTPNVK) (#21399) · Issues · Wireshark…
I am writing to report stack-use-after-return in tshark sharkd This is a security issue that was found by Anthropic using Claude to find...
🚨 CVE-2026-76891
Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
sharkd: use-after-return via dangling stack-object rtp-streams tap listener on error path (ANT-2026-27KVBTTP) (#21395) · Issues…
I am writing to report stack-use-after-return in tshark sharkd This is a security issue that was found by Anthropic using Claude to find...
🚨 CVE-2026-76917
Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
AVRCP Vendor-Dependent Fragment Reassembly — uint32_t Integer Overflow → Heap Buffer Overflow (#21488) · Issues · Wireshark Foundation…
AVRCP Vendor-Dependent Fragment Reassembly — uint32_t Integer Overflow → Heap Buffer Overflow 1. Executive Summary
🚨 CVE-2026-76918
SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
SSH dissector: heap buffer overflow in curve25519 key exchange (#21465) · Issues · Wireshark Foundation / Wireshark · GitLab
Affected: master, release-4.6, release-4.4. Introduced in 3.4.0 (2020-10-29) with SSH decryption support; unfixed on every branch as of 2026-08-02. Impact: heap out-of-bounds write of...
🚨 CVE-2026-76919
ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
Malformed ESS BIT STRING can use uninitialized TVB pointer in attribute-flag dissection (#21467) · Issues · Wireshark Foundation…
From AISLE Security: Summary A malformed BER BIT STRING in an ESS security-category attribute can make...
🚨 CVE-2026-76920
3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
3GPP log decoder can write one byte past packet buffer (#21454) · Issues · Wireshark Foundation / Wireshark · GitLab
From Aisle Security: [Security] 3GPP log decoder writes one byte past packet buffer
🚨 CVE-2026-76921
CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
CMS RC2 parameter decoding reuses freed capability-tree pointer (#21457) · Issues · Wireshark Foundation / Wireshark · GitLab
From AISLE Security: [Security] CMS RC2 parameter decoding reuses freed capability-tree pointer
🚨 CVE-2026-76922
Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
BR/EDR fragmented L2CAP uses an unregistered reassembly table (#21452) · Issues · Wireshark Foundation / Wireshark · GitLab
Aisle Security reported: [Security] BR/EDR fragmented L2CAP uses an unregistered reassembly table
🚨 CVE-2026-76923
Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
Short +XAPL accessory parameter causes heap out-of-bounds read (#21451) · Issues · Wireshark Foundation / Wireshark · GitLab
From AISLE Security: [Security] Short +XAPL accessory parameter causes heap out-of-bounds read
🚨 CVE-2026-76924
Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
Kerberos learned-key formatting reads past short EncryptionKey (#21449) · Issues · Wireshark Foundation / Wireshark · GitLab
From AISLE Security: [Security] Kerberos learned-key formatting reads past short EncryptionKey
🚨 CVE-2026-76927
H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
H.245 returnedFunction nested GenericMessage dereferences NULL packet state (#21447) · Issues · Wireshark Foundation / Wireshark…
From AISLE Security: [Security] H.245 returnedFunction nested GenericMessage dereferences NULL packet state
🚨 CVE-2026-76928
X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
Nested DistinguishedName corrupts X.509IF DN/RDN formatting state (#21469) · Issues · Wireshark Foundation / Wireshark · GitLab
From AISLE Security: [Security] Nested DistinguishedName corrupts X.509IF DN/RDN formatting state
🚨 CVE-2026-76929
Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
Out-of-bounds read in Netflix pcapng TCPINFO option parsing (#21460) · Issues · Wireshark Foundation / Wireshark · GitLab
[Security] Out-of-bounds read in Netflix pcapng TCPINFO option parsing
🚨 CVE-2025-62307
HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weakens accountability, obscures attack detection, and enables privilege probing.
🎖@cveNotify
HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weakens accountability, obscures attack detection, and enables privilege probing.
🎖@cveNotify
Hcl-Software
Security Bulletin: Multiple security vulnerabilities affect HCL IntelliOps Event Management (IEM) - Customer Support
HCL IntelliOps Event Management is affected by multiple security vulnerabilities.
🚨 CVE-2025-62299
HCL IntelliOps Event Management (IEM) is affected by a least privileges violation which could allow an attacker to access the resource with the elevated privilege that could not be accessed with the attacker's original privileges.
🎖@cveNotify
HCL IntelliOps Event Management (IEM) is affected by a least privileges violation which could allow an attacker to access the resource with the elevated privilege that could not be accessed with the attacker's original privileges.
🎖@cveNotify
Hcl-Software
Security Bulletin: Multiple security vulnerabilities affect HCL IntelliOps Event Management (IEM) - Customer Support
HCL IntelliOps Event Management is affected by multiple security vulnerabilities.
🚨 CVE-2025-62300
HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur where an attacker can modify the resource causing unpredictable behavior.
🎖@cveNotify
HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur where an attacker can modify the resource causing unpredictable behavior.
🎖@cveNotify
Hcl-Software
Security Bulletin: Multiple security vulnerabilities affect HCL IntelliOps Event Management (IEM) - Customer Support
HCL IntelliOps Event Management is affected by multiple security vulnerabilities.
🚨 CVE-2025-62306
HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information breaks auditability and observability of a workflow. if an attacker were to gain access to the application, the insufficient logging could hinder incident response.
🎖@cveNotify
HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information breaks auditability and observability of a workflow. if an attacker were to gain access to the application, the insufficient logging could hinder incident response.
🎖@cveNotify
Hcl-Software
Security Bulletin: Multiple security vulnerabilities affect HCL IntelliOps Event Management (IEM) - Customer Support
HCL IntelliOps Event Management is affected by multiple security vulnerabilities.
🚨 CVE-2026-64960
ATutor Gameme module allows users to upload files of any type and extension without restriction. Due to improper handling of file uploads, files are stored in a web-accessible location before their content is validated. An authenticated attacker who knows a valid course_id can upload a server-executable malicious script. The uploaded file can then be requested over HTTP, resulting in remote code execution as the web server process user. In most cases, course_id=0 can be used, as it commonly represents the global context.
Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.
🎖@cveNotify
ATutor Gameme module allows users to upload files of any type and extension without restriction. Due to improper handling of file uploads, files are stored in a web-accessible location before their content is validated. An authenticated attacker who knows a valid course_id can upload a server-executable malicious script. The uploaded file can then be requested over HTTP, resulting in remote code execution as the web server process user. In most cases, course_id=0 can be used, as it commonly represents the global context.
Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.
🎖@cveNotify