CVE-2014-2299: Wireshark

High severity, CVSS 9.3. EPSS: 47.1% chance of exploitation in the next 30 days.

Buffer overflow in the mpeg_read function in wiretap/mpeg.c in the MPEG parser in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a large record in MPEG data.

Affected products

  • Wireshark Wireshark: version 1.8.0 only; version 1.8.1 only; version 1.8.2 only; version 1.8.3 only; version 1.8.4 only; version 1.8.5 only; …

Published 2014-03-11. Last modified 2026-06-17.