← Vulnerability feed

Vulnerability record · CVE-2014-6395 · published 19 December 2014

CVE-2014-6395: Ettercap-project ettercap memory buffer overflow vulnerability

Ettercap Project · Ettercap

Heap-based buffer overflow in the dissector_postgresql function in dissectors/ec_postgresql.c in Ettercap before 0.8.1 allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted password length value that is inconsistent with the actual length of the password.

7.5 CVSS 2.0 High EPSS 13% · top 3.9% CWE-119 · Memory buffer overflow
7.5CVSS 2.0 base score
13%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
17 Jun 2026Last modified by NVD

Description

Heap-based buffer overflow in the dissector_postgresql function in dissectors/ec_postgresql.c in Ettercap before 0.8.1 allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted password length value that is inconsistent with the actual length of the password.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-6395 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2010-3844Ettercap-project ettercap classic buffer overflow vulnerabilityAn unchecked sscanf() call in ettercap before 0.7.5 allows an insecure temporary settings file to overflow a static-sized buffer on the stack.EPSS 1.4%7.8CVE-2010-3843Ettercap-project ettercap out-of-bounds write vulnerabilityThe GTK version of ettercap uses a global settings file at /tmp/.ettercap_gtk and does not verify ownership of this file. When parsing this file for …EPSS 0.31%7.5CVE-2014-9379Ettercap-project ettercap memory buffer overflow vulnerabilityThe radius_get_attribute function in dissectors/ec_radius.c in Ettercap 0.8.1 performs an incorrect cast, which allows remote attackers to cause a de…EPSS 4.0%7.5CVE-2014-9378Ettercap-project ettercap improper input validation vulnerabilityEttercap 0.8.1 does not validate certain return values, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitr…EPSS 3.9%7.5CVE-2014-9376Ettercap-project ettercap vulnerabilityInteger underflow in Ettercap 0.8.1 allows remote attackers to cause a denial of service (out-of-bounds write) and possibly execute arbitrary code vi…EPSS 4.1%7.5CVE-2014-9377Ettercap-project ettercap memory buffer overflow vulnerabilityHeap-based buffer overflow in the nbns_spoof function in plug-ins/nbns_spoof/nbns_spoof.c in Ettercap 0.8.1 allows remote attackers to cause a denial…EPSS 4.0%7.5CVE-2014-6396Ettercap-project ettercap memory buffer overflow vulnerabilityThe dissector_postgresql function in dissectors/ec_postgresql.c in Ettercap before 0.8.1 allows remote attackers to cause a denial of service and pos…EPSS 3.6%5.5CVE-2017-6430Ettercap-project ettercap out-of-bounds read vulnerabilityThe compile_tree function in ef_compiler.c in the Etterfilter utility in Ettercap 0.8.2 and earlier allows remote attackers to cause a denial of serv…EPSS 2.0%

Source: NIST National Vulnerability Database (record CVE-2014-6395), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.