epan/dissectors/packet-spice.c in the SPICE dissector in Wireshark 2.x before 2.0.2 mishandles capability data, which allows remote attackers to cause a denial of service (large loop) via a crafted packet.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-4419.json"