CVE Tools

Tcpdump

196 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Tcpdump, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

Tcpdump CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Tcpdump CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 196 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical13468%
  • High3417%
  • Medium2613%
  • Low21%

Latest CVEs

The 15 most recently published vulnerabilities affecting Tcpdump.

  1. CVE-2024-2397infinite loop in the PPP printer of tcpdump6.2
  2. CVE-2023-1801The SMB protocol decoder in tcpdump version 4.99.3 can perform an out-of-bounds write when decoding a crafted network packet.6.5
  3. CVE-2019-15167The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 3, a different vulnerability than CVE-2018-14463.9.1
  4. CVE-2021-41043Use after free in tcpslice triggers AddressSanitizer, no other confirmed impact.5.5
  5. CVE-2020-8036str2tokbuf used incorrectly by print-someip.c7.5
  6. CVE-2020-8037ppp decapsulator can be convinced to allocate a large amount of memory7.5
  7. CVE-2019-15166lmp_print in tcpdump lacks certain boundary checks1.6
  8. CVE-2018-16452The SMB parser in tcpdump before 4.9.3 has stack exhaustion in smbutil.c:smb_fdata() via recursion.7.5
  9. CVE-2018-16451The SMB parser in tcpdump before 4.9.3 has buffer over-reads in print-smb.c:print_trans() for \MAILSLOT\BROWSE and \PIPE\LANMAN.7.5
  10. CVE-2018-16301The command-line argument parser in tcpdump before 4.99.0 has a buffer overflow in tcpdump.c:read_infile(). To trigger this vulnerability the attacker needs to create a 4GB file on the local filesy...7.8
  11. CVE-2018-16300The BGP parser in tcpdump before 4.9.3 allows stack consumption in print-bgp.c:bgp_attr_print() because of unlimited recursion.7.5
  12. CVE-2018-16230The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_attr_print() (MP_REACH_NLRI).7.5
  13. CVE-2018-16229The DCCP parser in tcpdump before 4.9.3 has a buffer over-read in print-dccp.c:dccp_print_option().7.5
  14. CVE-2018-16228The HNCP parser in tcpdump before 4.9.3 has a buffer over-read in print-hncp.c:print_prefix().7.5
  15. CVE-2018-16227The IEEE 802.11 parser in tcpdump before 4.9.3 has a buffer over-read in print-802_11.c for the Mesh Flags subfield.7.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store