CVE Tools

Libpcap

17 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Libpcap, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Libpcap CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Libpcap CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-122
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-097

Severity

How the 17 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical16%
  • High212%
  • Medium1271%
  • Low212%

Latest CVEs

The 15 most recently published vulnerabilities affecting Libpcap.

  1. CVE-2026-18238OOBR in rpcap client in libpcap before 1.10.75.0
  2. CVE-2026-18313rpcapd memory leak in libpcap before 1.10.74.3
  3. CVE-2026-6554infinte loop in libpcap before 1.10.75.5
  4. CVE-2026-6244division by zero in libpcap before 1.10.75.5
  5. CVE-2026-31911abort() in libpcap before 1.10.7 on an invalid BPF opcode5.5
  6. CVE-2026-31912OOBR in libpcap before 1.10.75.5
  7. CVE-2026-0799OOBR and OOBW in libpcap before 1.10.78.7
  8. CVE-2025-11964OOBW in utf_16le_to_utf_8_truncated() in libpcap1.9
  9. CVE-2025-11961OOBR and OOBW in pcap_ether_aton() in libpcap1.9
  10. CVE-2024-8006NULL pointer dereference in libpcap before 1.10.5 with remote packet capture support4.4
  11. CVE-2023-7256Double-free in libpcap before 1.10.5 with remote packet capture support.4.4
  12. CVE-2019-15165sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.5.3
  13. CVE-2019-15164rpcapd/daemon.c in libpcap before 1.9.1 allows SSRF because a URL may be provided as a capture source.5.3
  14. CVE-2019-15163rpcapd/daemon.c in libpcap before 1.9.1 allows attackers to cause a denial of service (NULL pointer dereference and daemon crash) if a crypt() call fails.7.5
  15. CVE-2019-15162rpcapd/daemon.c in libpcap before 1.9.1 on non-Windows platforms provides details about why authentication failed, which might make it easier for attackers to enumerate valid usernames.5.3

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store