605
VMScore

CVE-2021-22191

Published: 15/03/2021 Updated: 27/05/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Improper URL handling in Wireshark 3.4.0 to 3.4.3 and 3.2.0 to 3.2.11 could allow remote code execution via via packet injection or crafted capture file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wireshark wireshark

oracle zfs storage appliance 8.8

debian debian linux 9.0

Vendor Advisories

Improper URL handling in Wireshark 340 to 343 and 320 to 3211 could allow remote code execution via via packet injection or crafted capture file ...
A security issue has been found in Wireshark before version 344 Some fields in the Wireshark proto_tree are double-clickable and pass URLs with arbitrary schemes to the QDesktopServices::openUrl function http and https URLs passed to this function are opened by the browser which is generally safe For some other schemes like dav and file howeve ...