CVE-2016-2521

Source
https://cve.org/CVERecord?id=CVE-2016-2521
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-2521.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2016-2521
Downstream
Published
2016-02-28T04:59:00.120Z
Modified
2026-07-08T12:43:42.188800Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Untrusted search path vulnerability in the WiresharkApplication class in ui/qt/wireshark_application.cpp in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 on Windows allows local users to gain privileges via a Trojan horse riched20.dll.dll file in the current working directory, related to use of QLibrary.

References

Affected packages

Git / github.com/wireshark/wireshark

Affected ranges

Type
GIT
Repo
https://github.com/wireshark/wireshark
Events
Database specific
Show details
{
    "cpe": [
        "cpe:2.3:a:wireshark:wireshark:1.12.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:wireshark:wireshark:1.12.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:wireshark:wireshark:1.12.2:*:*:*:*:*:*:*",
        "cpe:2.3:a:wireshark:wireshark:1.12.3:*:*:*:*:*:*:*",
        "cpe:2.3:a:wireshark:wireshark:1.12.4:*:*:*:*:*:*:*",
        "cpe:2.3:a:wireshark:wireshark:1.12.5:*:*:*:*:*:*:*",
        "cpe:2.3:a:wireshark:wireshark:1.12.6:*:*:*:*:*:*:*",
        "cpe:2.3:a:wireshark:wireshark:1.12.7:*:*:*:*:*:*:*",
        "cpe:2.3:a:wireshark:wireshark:1.12.8:*:*:*:*:*:*:*",
        "cpe:2.3:a:wireshark:wireshark:1.12.9:*:*:*:*:*:*:*",
        "cpe:2.3:a:wireshark:wireshark:2.0.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:wireshark:wireshark:2.0.1:*:*:*:*:*:*:*"
    ],
    "source": "CPE_STRING",
    "extracted_events": [
        {
            "introduced": "1.12.0"
        },
        {
            "last_affected": "1.12.0"
        },
        {
            "introduced": "1.12.1"
        },
        {
            "last_affected": "1.12.1"
        },
        {
            "introduced": "1.12.2"
        },
        {
            "last_affected": "1.12.2"
        },
        {
            "introduced": "1.12.3"
        },
        {
            "last_affected": "1.12.3"
        },
        {
            "introduced": "1.12.4"
        },
        {
            "last_affected": "1.12.4"
        },
        {
            "introduced": "1.12.5"
        },
        {
            "last_affected": "1.12.5"
        },
        {
            "introduced": "1.12.6"
        },
        {
            "last_affected": "1.12.6"
        },
        {
            "introduced": "1.12.7"
        },
        {
            "last_affected": "1.12.7"
        },
        {
            "introduced": "1.12.8"
        },
        {
            "last_affected": "1.12.8"
        },
        {
            "introduced": "1.12.9"
        },
        {
            "last_affected": "1.12.9"
        },
        {
            "introduced": "2.0.0"
        },
        {
            "last_affected": "2.0.0"
        },
        {
            "introduced": "2.0.1"
        },
        {
            "last_affected": "2.0.1"
        }
    ]
}

Affected versions

1.*
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.12.9
2.*
2.0.0
2.0.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-2521.json"

Git / gitlab.com/wireshark/wireshark

Affected ranges

Type
GIT
Repo
https://gitlab.com/wireshark/wireshark
Events
Database specific
Show details
{
    "cpe": [
        "cpe:2.3:a:wireshark:wireshark:1.12.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:wireshark:wireshark:1.12.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:wireshark:wireshark:1.12.2:*:*:*:*:*:*:*",
        "cpe:2.3:a:wireshark:wireshark:1.12.3:*:*:*:*:*:*:*",
        "cpe:2.3:a:wireshark:wireshark:1.12.4:*:*:*:*:*:*:*",
        "cpe:2.3:a:wireshark:wireshark:1.12.5:*:*:*:*:*:*:*",
        "cpe:2.3:a:wireshark:wireshark:1.12.6:*:*:*:*:*:*:*",
        "cpe:2.3:a:wireshark:wireshark:1.12.7:*:*:*:*:*:*:*",
        "cpe:2.3:a:wireshark:wireshark:1.12.8:*:*:*:*:*:*:*",
        "cpe:2.3:a:wireshark:wireshark:1.12.9:*:*:*:*:*:*:*",
        "cpe:2.3:a:wireshark:wireshark:2.0.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:wireshark:wireshark:2.0.1:*:*:*:*:*:*:*"
    ],
    "source": "CPE_STRING",
    "extracted_events": [
        {
            "introduced": "1.12.0"
        },
        {
            "last_affected": "1.12.0"
        },
        {
            "introduced": "1.12.1"
        },
        {
            "last_affected": "1.12.1"
        },
        {
            "introduced": "1.12.2"
        },
        {
            "last_affected": "1.12.2"
        },
        {
            "introduced": "1.12.3"
        },
        {
            "last_affected": "1.12.3"
        },
        {
            "introduced": "1.12.4"
        },
        {
            "last_affected": "1.12.4"
        },
        {
            "introduced": "1.12.5"
        },
        {
            "last_affected": "1.12.5"
        },
        {
            "introduced": "1.12.6"
        },
        {
            "last_affected": "1.12.6"
        },
        {
            "introduced": "1.12.7"
        },
        {
            "last_affected": "1.12.7"
        },
        {
            "introduced": "1.12.8"
        },
        {
            "last_affected": "1.12.8"
        },
        {
            "introduced": "1.12.9"
        },
        {
            "last_affected": "1.12.9"
        },
        {
            "introduced": "2.0.0"
        },
        {
            "last_affected": "2.0.0"
        },
        {
            "introduced": "2.0.1"
        },
        {
            "last_affected": "2.0.1"
        }
    ]
}

Affected versions

1.*
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.12.9
2.*
2.0.0
2.0.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-2521.json"