Vulnerability index

Browse CVEs

869 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Infinite LoopCWE-835 × clear
Opc Ua Module For M580 Firmware HIGH 7.5
CVE-2022-34760

A CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability exists that could cause a denial of service of the webserver due to i…

Fix: after 1.10
Fix from $1,950 2022-07-13
Tl Wr741n Firmware HIGH 7.5
CVE-2022-32058

An infinite loop in the function httpRpmPass of TP-Link TL-WR741N/TL-WR742N V1/V2/V3_130415 allows attackers to cause a Denial of Service (DoS) via a…

No fix yet
Fix from $1,950 2022-07-07
Ua .net Standard Stack HIGH 7.5
CVE-2022-29862

An infinite loop in OPC UA .NET Standard Stack 1.04.368 allows a remote attackers to cause the application to hang via a crafted message.

Fix: 1.4.368.58+
Fix from $1,950 2022-06-16
Jpeg Js HIGH 7.5
CVE-2022-25851

The package jpeg-js before 0.4.4 are vulnerable to Denial of Service (DoS) where a particular piece of input will cause to enter an infinite loop and…

Fix: 0.4.4+
Fix from $1,950 2022-06-10
Gpac MEDIUM 5.5
CVE-2021-40592

GPAC version before commit 71460d72ec07df766dab0a4d52687529f3efcf0a (version v1.0.1 onwards) contains loop with unreachable exit condition ('infinite…

Fix: 1.0.1+
Fix from $1,600 2022-06-08
Curl HIGH 7.5
CVE-2022-27781

libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.Due to an er…

Fix: 7.83.1+
Fix from $1,950 2022-06-02
Dtls HIGH 7.5
CVE-2022-29190

Pion DTLS is a Go implementation of Datagram Transport Layer Security. Prior to version 2.1.4, an attacker can send packets that sends Pion DTLS into…

Fix: 2.1.4+
Fix from $1,950 2022-05-21
Jt2go MEDIUM 5.5
CVE-2022-29028

A vulnerability has been identified in JT2Go (All versions < V13.3.0.3), Teamcenter Visualization V13.3 (All versions < V13.3.0.3), Teamcenter Visual…

Fix: 13.3.0.3 / 14.0.0.1+
Fix from $1,600 2022-05-20
Debian Linux HIGH 7.5
CVE-2022-24792

PJSIP is a free and open source multimedia communication library written in C. A denial-of-service vulnerability affects applications on a 32-bit sys…

Fix: after 2.12
Fix from $1,950 2022-04-25
Debian Linux MEDIUM 5.5
CVE-2022-24859

PyPDF2 is an open source python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF files. In versions prior to 1.…

Fix: 1.27.5+
Fix from $1,600 2022-04-18
Libiec61850 HIGH 7.5
CVE-2022-21159

A denial of service vulnerability exists in the parseNormalModeParameters functionality of MZ Automation GmbH libiec61850 1.5.0. A specially-crafted …

Patch available
Fix from $1,950 2022-04-15
Fedora MEDIUM 5.5
CVE-2022-24191

In HTMLDOC 1.9.14, an infinite loop in the gif_read_lzw function can lead to a pointer arbitrarily pointing to heap memory and resulting in a buffer …

Fix: 1.9.15+
Fix from $1,600 2022-04-04
Gpac MEDIUM 5.5
CVE-2022-1222

Inf loop in GitHub repository gpac/gpac prior to 2.1.0-DEV.

Fix: after 2.0
Fix from $1,600 2022-04-04
Debian Linux HIGH 7.5
CVE-2022-24763

PJSIP is a free and open source multimedia communication library written in the C language. Versions 2.12 and prior contain a denial-of-service vulne…

Fix: 2.13+
Fix from $1,950 2022-03-30
Bigant Server HIGH 7.5
CVE-2022-23352

An issue in BigAnt Software BigAnt Server v5.6.06 can lead to a Denial of Service (DoS).

No fix yet
Fix from $1,950 2022-03-21
Fedora MEDIUM 6.5
CVE-2021-20257

An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descriptors in process_tx_de…

Fix: 6.2.0+
Fix from $1,600 2022-03-16
OpenSSL HIGH 7.5
CVE-2022-0778EPSS 73%

The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally t…

Fix: 1.0.2zd / 1.1.1n+
Fix from $1,950 2022-03-15
Python HIGH 7.5
CVE-2021-3737EPSS 12%

A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP …

Fix: 3.6.14 / 3.7.11+
Fix from $1,950 2022-03-04
Openshift Container Platform HIGH 7.5
CVE-2022-0711EPSS 17%

A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted H…

Fix: 2.2.21 / 2.3.18+
Fix from $1,950 2022-03-02
Discourse MEDIUM 6.5
CVE-2022-23641

Discourse is an open source discussion platform. In versions prior to 2.8.1 in the `stable` branch, 2.9.0.beta2 in the `beta` branch, and 2.9.0.beta2…

Fix: 2.8.1+
Fix from $1,600 2022-02-15
Wireshark HIGH 7.5
CVE-2022-0586

Infinite loop in RTMPT protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted ca…

Fix: 3.4.12 / 3.6.2+
Fix from $1,950 2022-02-14
Django HIGH 7.5
CVE-2022-23833EPSS 49%

An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart …

Fix: 2.2.27 / 3.2.12+
Fix from $1,950 2022-02-03
Junrar HIGH 7.5
CVE-2022-23596

Junrar is an open source java RAR archive library. In affected versions A carefully crafted RAR archive can trigger an infinite loop while extracting…

Fix: 7.4.1+
Fix from $1,950 2022-02-01
Debian Linux HIGH 7.5
CVE-2022-23098

An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation has an infinite loop if no data is received.

Fix: after 1.40
Fix from $1,950 2022-01-28
Versalink Firmware HIGH 7.5
CVE-2022-23968

Xerox VersaLink devices on specific versions of firmware before 2022-01-26 allow remote attackers to brick the device via a crafted TIFF file in an u…

Fix: after 50.61
Fix from $1,950 2022-01-26
Xerces J MEDIUM 6.5
CVE-2022-23437

There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the Xe…

Fix: 9.0+
Fix from $1,600 2022-01-24
Colors.js HIGH 7.5
CVE-2021-23567

The package colors after 1.4.0 are vulnerable to Denial of Service (DoS) that was introduced through an infinite loop in the americanFlag module. Unf…

Patch available
Fix from $1,950 2022-01-14
Clearpath Mcp Tcp\/ip Networking Services HIGH 7.5
CVE-2021-45445

Unisys ClearPath MCP TCP/IP Networking Services 59.1, 60.0, and 62.0 has an Infinite Loop.

No fix yet
Fix from $1,950 2022-01-12
James MEDIUM 6.5
CVE-2021-40111

In Apache James, while fuzzing with Jazzer the IMAP parsing stack, we discover that crafted APPEND and STATUS IMAP command could be used to trigger i…

Fix: 3.6.1+
Fix from $1,600 2022-01-04
Wireshark HIGH 7.5
CVE-2021-4182

Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

Fix: 3.4.11+
Fix from $1,950 2021-12-30