Libpcap
This hub aggregates every CVE we track for Libpcap, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
17
CVEs tracked
1
Critical
2
High
0
In CISA KEV
Severity distribution
MEDIUM12LOW2HIGH2CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2
0
0
0
0
0
0
0
0
7
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Libpcap.
- CVE-2026-18238OOBR in rpcap client in libpcap before 1.10.75.0
- CVE-2026-18313rpcapd memory leak in libpcap before 1.10.74.3
- CVE-2026-6554infinte loop in libpcap before 1.10.75.5
- CVE-2026-6244division by zero in libpcap before 1.10.75.5
- CVE-2026-31911abort() in libpcap before 1.10.7 on an invalid BPF opcode5.5
- CVE-2026-31912OOBR in libpcap before 1.10.75.5
- CVE-2026-0799OOBR and OOBW in libpcap before 1.10.78.7
- CVE-2025-11964OOBW in utf_16le_to_utf_8_truncated() in libpcap1.9
- CVE-2025-11961OOBR and OOBW in pcap_ether_aton() in libpcap1.9
- CVE-2024-8006NULL pointer dereference in libpcap before 1.10.5 with remote packet capture support4.4
- CVE-2023-7256Double-free in libpcap before 1.10.5 with remote packet capture support.4.4
- CVE-2019-15165sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.5.3
- CVE-2019-15164rpcapd/daemon.c in libpcap before 1.9.1 allows SSRF because a URL may be provided as a capture source.5.3
- CVE-2019-15163rpcapd/daemon.c in libpcap before 1.9.1 allows attackers to cause a denial of service (NULL pointer dereference and daemon crash) if a crypt() call fails.7.5
- CVE-2019-15162rpcapd/daemon.c in libpcap before 1.9.1 on non-Windows platforms provides details about why authentication failed, which might make it easier for attackers to enumerate valid usernames.5.3
Product normalization is registry-driven with AI assist and human review. How it works