Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to libpcap 1.10.7.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 09 Sep 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 08 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 07 Sep 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tcpdump
Tcpdump libpcap |
|
| Vendors & Products |
Tcpdump
Tcpdump libpcap |
Sat, 05 Sep 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message and cause the client to treat up to 20 bytes of the client process memory beyond the end of the buffer as if it was a part of the captured packet. | |
| Title | OOBR in rpcap client in libpcap before 1.10.7 | |
| Weaknesses | CWE-126 CWE-1288 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Tcpdump
Published:
Updated: 2026-09-08T15:17:19.641Z
Reserved: 2026-07-29T13:32:44.322Z
Link: CVE-2026-18238
Updated: 2026-09-08T15:17:13.582Z
Status : Awaiting Analysis
Published: 2026-09-05T19:16:55.477
Modified: 2026-09-08T19:20:25.117
Link: CVE-2026-18238
OpenCVE Enrichment
Updated: 2026-09-10T04:45:16Z