CVE-2015-8740
The dissect_tds7_colmetadata_token function in epan/dissectors/packet-tds.c in the TDS dissector in Wireshark 2.0.x before 2.0.1 does not validate the...
- Published
- Jan 4, 2016
- Updated
- Aug 6, 2024
- Assigning CNA
- mitre
- Evidence observed
- Dec 16, 2015
Primary CVSS
nvd · CVSS 3.0
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HLow · next 30 days
- Percentile
- 93.6%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
The dissect_tds7_colmetadata_token function in epan/dissectors/packet-tds.c in the TDS dissector in Wireshark 2.0.x before 2.0.1 does not validate the number of columns, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted packet.
Sources
1Google Security Research · multiple · Dec 16, 2015
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.