Libpcap
17 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Libpcap, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Libpcap CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 2 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 7 |
Severity
How the 17 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- High2
- Medium12
- Low2
Latest CVEs
The 15 most recently published vulnerabilities affecting Libpcap.
- CVE-2026-18238OOBR in rpcap client in libpcap before 1.10.75.0
- CVE-2026-18313rpcapd memory leak in libpcap before 1.10.74.3
- CVE-2026-6554infinte loop in libpcap before 1.10.75.5
- CVE-2026-6244division by zero in libpcap before 1.10.75.5
- CVE-2026-31911abort() in libpcap before 1.10.7 on an invalid BPF opcode5.5
- CVE-2026-31912OOBR in libpcap before 1.10.75.5
- CVE-2026-0799OOBR and OOBW in libpcap before 1.10.78.7
- CVE-2025-11964OOBW in utf_16le_to_utf_8_truncated() in libpcap1.9
- CVE-2025-11961OOBR and OOBW in pcap_ether_aton() in libpcap1.9
- CVE-2024-8006NULL pointer dereference in libpcap before 1.10.5 with remote packet capture support4.4
- CVE-2023-7256Double-free in libpcap before 1.10.5 with remote packet capture support.4.4
- CVE-2019-15165sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.5.3
- CVE-2019-15164rpcapd/daemon.c in libpcap before 1.9.1 allows SSRF because a URL may be provided as a capture source.5.3
- CVE-2019-15163rpcapd/daemon.c in libpcap before 1.9.1 allows attackers to cause a denial of service (NULL pointer dereference and daemon crash) if a crypt() call fails.7.5
- CVE-2019-15162rpcapd/daemon.c in libpcap before 1.9.1 on non-Windows platforms provides details about why authentication failed, which might make it easier for attackers to enumerate valid usernames.5.3
Product grouping is registry-driven, with AI assist and human review. How it works