Vulnerability index

Browse CVEs

869 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Infinite LoopCWE-835 × clear
Hutool HIGH 7.5
CVE-2023-51075

hutool-core v5.8.23 was discovered to contain an infinite loop in the StrSplitter.splitByRegex function. This vulnerability allows attackers to cause…

Fix: 5.8.24+
Fix from $1,950 2023-12-27
Crypto\+\+ HIGH 7.5
CVE-2023-50981

ModularSquareRoot in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (infinite loop) via crafted DER public-key d…

Fix: after 8.9.0
Fix from $1,950 2023-12-18
Candid HIGH 7.5
CVE-2023-6245

The Candid library causes a Denial of Service while parsing a specially crafted payload with 'empty' data type. For example, if the payload is `rec…

Fix: 0.9.10+
Fix from $1,950 2023-12-08
Aleos HIGH 7.5
CVE-2023-40458

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Sierra Wireless, Inc ALEOS could potentially allow a remote attacker to trigg…

Fix: after 4.16.2
Fix from $1,950 2023-11-29
Kyverno MEDIUM 5.3
CVE-2023-42814

Kyverno is a policy engine designed for Kubernetes. A security vulnerability was found in Kyverno where an attacker could cause denial of service of …

Patch available
Fix from $1,600 2023-11-13
Kyverno MEDIUM 5.3
CVE-2023-42815

Kyverno is a policy engine designed for Kubernetes. A security vulnerability was found in Kyverno where an attacker could cause denial of service of …

Patch available
Fix from $1,600 2023-11-13
Cosign MEDIUM 5.3
CVE-2023-46737

Cosign is a sigstore signing tool for OCI containers. Cosign is susceptible to a denial of service by an attacker controlled registry. An attacker wh…

Fix: 2.2.1+
Fix from $1,600 2023-11-07
GitLab MEDIUM 6.5
CVE-2023-5825

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.2 before 16.3.6, all versions starting from 16.4 before 16.4.2, …

Fix: 16.3.6 / 16.4.2+
Fix from $1,600 2023-11-06
Secure Firewall Threat Defense HIGH 8.6
CVE-2023-20083

A vulnerability in ICMPv6 inspection when configured with the Snort 2 detection engine for Cisco Firepower Threat Defense (FTD) Software could allow …

Fix: after 7.3.1.1
Fix from $1,950 2023-11-01
Bitrix24 HIGH 7.5
CVE-2023-1718EPSS 24%

Improper file stream access in /desktop_app/file.ajax.php?action=uploadfile in Bitrix24 22.0.300 allows unauthenticated remote attackers to cause den…

No fix yet
Fix from $1,950 2023-11-01
Pypdf MEDIUM 5.5
CVE-2023-46250

pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions 3.7.0 through 3.16.4 can craft a PD…

Fix: 3.17.0+
Fix from $1,600 2023-10-31
Junos HIGH 7.5
CVE-2023-44181

An Improperly Implemented Security Check for Standard vulnerability in storm control of Juniper Networks Junos OS QFX5k devices allows packets to be …

Fix: 20.2+
Fix from $1,950 2023-10-13
Vpn MEDIUM 5.9
CVE-2023-22325

A denial of service vulnerability exists in the DCRegister DDNS_RPC_MAX_RECV_SIZE functionality of SoftEther VPN 4.41-9782-beta, 5.01.9674 and 5.02. …

Patch available
Fix from $1,600 2023-10-12
Enterprise Linux MEDIUM 5.5
CVE-2023-43786

A vulnerability was found in libX11 due to an infinite loop within the PutSubImage() function. This flaw allows a local user to consume all available…

Fix: 1.8.7+
Fix from $1,600 2023-10-10
Debian Linux HIGH 7.5
CVE-2023-45363EPSS 23%

An issue was discovered in ApiPageSet.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. It allows attac…

Fix: 1.35.12 / 1.39.5+
Fix from $1,950 2023-10-09
Opcua Asyncio HIGH 7.5
CVE-2023-26151

Versions of the package asyncua before 0.9.96 are vulnerable to Denial of Service (DoS) such that an attacker can send a malformed packet and as a re…

Fix: 0.9.96+
Fix from $1,950 2023-10-03
Openfga MEDIUM 5.9
CVE-2023-43645

OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA is vulnerable to a denial of service atta…

Fix: 1.3.2+
Fix from $1,600 2023-09-27
Linux Protection HIGH 7.5
CVE-2023-43761

Certain WithSecure products allow Denial of Service (infinite loop). This affects WithSecure Client Security 15, WithSecure Server Security 15, WithS…

Mitigation only
Fix from $1,950 2023-09-22
Client Security HIGH 7.5
CVE-2023-42524

Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types. This affects WithSecure Client Security 15, WithS…

Mitigation only
Fix from $1,950 2023-09-18
Client Security HIGH 7.5
CVE-2023-42525

Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types. This affects WithSecure Client Security 15, WithS…

Mitigation only
Fix from $1,950 2023-09-18
Build Of Quarkus HIGH 7.5
CVE-2023-1108

A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, wh…

Mitigation only
Fix from $1,950 2023-09-14
Enterprise Linux MEDIUM 6.5
CVE-2023-3255

A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. A wrong exit condition may lead to an infinite loop when in…

Fix: after 8.0.3
Fix from $1,600 2023-09-13
Wireshark HIGH 7.5
CVE-2023-4511

BT SDP dissector infinite loop in Wireshark 4.0.0 to 4.0.7 and 3.6.0 to 3.6.15 allows denial of service via packet injection or crafted capture file

Fix: after 4.0.7
Fix from $1,950 2023-08-24
Firepower 9300 Firmware MEDIUM 6.3
CVE-2023-20200

A vulnerability in the Simple Network Management Protocol (SNMP) service of Cisco FXOS Software for Firepower 4100 Series and Firepower 9300 Security…

Fix: 4.1 / 4.2+
Fix from $1,600 2023-08-23
Libtiff MEDIUM 6.5
CVE-2022-40090

An issue was discovered in function TIFFReadDirectory libtiff before 4.4.0 allows attackers to cause a denial of service via crafted TIFF file.

Fix: 4.4.0+
Fix from $1,600 2023-08-22
Secure Endpoint HIGH 7.5
CVE-2023-20197

A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to …

Fix: 1.22.0 / 3.8.0+
Fix from $1,950 2023-08-16
Document Server HIGH 7.5
CVE-2023-30188

Memory Exhaustion vulnerability in ONLYOFFICE Document Server 4.0.3 through 7.3.2 allows remote attackers to cause a denial of service via crafted Ja…

Fix: after 7.3.2
Fix from $1,950 2023-08-14
Ryu HIGH 7.5
CVE-2020-35139

An issue was discovered in OFPBundleCtrlMsg in parser.py in Faucet SDN Ryu version 4.34, allows remote attackers to cause a denial of service (DoS) (…

No fix yet
Fix from $1,950 2023-08-11
Ryu HIGH 7.5
CVE-2020-35141

An issue was discovered in OFPQueueGetConfigReply in parser.py in Faucet SDN Ryu version 4.34, allows remote attackers to cause a denial of service (…

No fix yet
Fix from $1,950 2023-08-11
Poppler MEDIUM 6.5
CVE-2020-36023

An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to F…

Patch available
Fix from $1,600 2023-08-11