CVE-2026-6524
MySQL protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.5
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS probability
- 0.12%
- CWE
- CWE-824
- Published
- 2026-04-30
- Last modified
- 2026-04-30
Affected products
- Wireshark Foundation Wireshark
- Wireshark Foundation Wireshark
Weakness type
Related vulnerabilities
- CVE-2026-88054 — Tesseract: Denial of service via empty-stack dereference in Plumbing/Series at model load
- CVE-2026-67281 — Unauthenticated file read in Mikrotik RouterOS
- CVE-2026-54920 — OpenEXR: Integer overflow and uninitialized pointer cause invalid delete in OpenEXRUtil image resize
- CVE-2026-47908 — Dreamweaver Desktop | Access of Uninitialized Pointer (CWE-824)
- CVE-2026-47320 — Access of uninitialized pointer, Uncontrolled Recursion vulnerability in Samsung Open Source...
- CVE-2026-42959 — Crash during DNSSEC validation of malicious content
- CVE-2026-39458 — BIG-IP DNS Cache vulnerability
- CVE-2026-44411 — A vulnerability has been identified in Solid Edge SE2026 (All versions < V226.0 Update 5). The...