← Vulnerability feed

Vulnerability record · CVE-2014-9376 · published 19 December 2014

CVE-2014-9376: Ettercap-project ettercap vulnerability

Ettercap Project · Ettercap

Integer underflow in Ettercap 0.8.1 allows remote attackers to cause a denial of service (out-of-bounds write) and possibly execute arbitrary code via a small (1) size variable value in the dissector_dhcp function in dissectors/ec_dhcp.c, (2) length value to the dissector_gg function in dissectors/ec_gg.c, or (3) string length to the get_decode_len function in ec_utils.c or a request without a (4) username or (5) password to the dissector_TN3270 function in dissectors/ec_TN3270.c.

7.5 CVSS 2.0 High EPSS 4.1% · top 9.5%
7.5CVSS 2.0 base score
4.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References
17 Jun 2026Last modified by NVD

Description

Integer underflow in Ettercap 0.8.1 allows remote attackers to cause a denial of service (out-of-bounds write) and possibly execute arbitrary code via a small (1) size variable value in the dissector_dhcp function in dissectors/ec_dhcp.c, (2) length value to the dissector_gg function in dissectors/ec_gg.c, or (3) string length to the get_decode_len function in ec_utils.c or a request without a (4) username or (5) password to the dissector_TN3270 function in dissectors/ec_TN3270.c.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-9376 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2010-3844Ettercap-project ettercap classic buffer overflow vulnerabilityAn unchecked sscanf() call in ettercap before 0.7.5 allows an insecure temporary settings file to overflow a static-sized buffer on the stack.EPSS 1.4%7.8CVE-2010-3843Ettercap-project ettercap out-of-bounds write vulnerabilityThe GTK version of ettercap uses a global settings file at /tmp/.ettercap_gtk and does not verify ownership of this file. When parsing this file for …EPSS 0.31%7.5CVE-2014-9379Ettercap-project ettercap memory buffer overflow vulnerabilityThe radius_get_attribute function in dissectors/ec_radius.c in Ettercap 0.8.1 performs an incorrect cast, which allows remote attackers to cause a de…EPSS 4.0%7.5CVE-2014-9378Ettercap-project ettercap improper input validation vulnerabilityEttercap 0.8.1 does not validate certain return values, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitr…EPSS 3.9%7.5CVE-2014-9377Ettercap-project ettercap memory buffer overflow vulnerabilityHeap-based buffer overflow in the nbns_spoof function in plug-ins/nbns_spoof/nbns_spoof.c in Ettercap 0.8.1 allows remote attackers to cause a denial…EPSS 4.0%7.5CVE-2014-6396Ettercap-project ettercap memory buffer overflow vulnerabilityThe dissector_postgresql function in dissectors/ec_postgresql.c in Ettercap before 0.8.1 allows remote attackers to cause a denial of service and pos…EPSS 3.6%7.5CVE-2014-6395Ettercap-project ettercap memory buffer overflow vulnerabilityHeap-based buffer overflow in the dissector_postgresql function in dissectors/ec_postgresql.c in Ettercap before 0.8.1 allows remote attackers to cau…EPSS 13%5.5CVE-2017-6430Ettercap-project ettercap out-of-bounds read vulnerabilityThe compile_tree function in ef_compiler.c in the Etterfilter utility in Ettercap 0.8.2 and earlier allows remote attackers to cause a denial of serv…EPSS 2.0%

Source: NIST National Vulnerability Database (record CVE-2014-9376), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.