Vulnerability index

Browse CVEs

870 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Infinite LoopCWE-835 × clear
Wireshark HIGH 7.5
CVE-2021-4182

Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

Fix: 3.4.11+
Fix from $1,950 2021-12-30
Wireshark HIGH 7.5
CVE-2021-4184

Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture…

Fix: after 3.4.10
Fix from $1,950 2021-12-30
Wireshark HIGH 7.5
CVE-2021-4185

Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

Fix: 3.4.11+
Fix from $1,950 2021-12-30
Netwide Assembler MEDIUM 5.5
CVE-2021-45257

An infinite loop vulnerability exists in nasm 2.16rc0 via the gpaste_tokens function.

Mitigation only
Fix from $1,600 2021-12-22
Gpac MEDIUM 5.5
CVE-2021-44924

An infinite loop vulnerability exists in gpac 1.1.0 in the gf_log function, which causes a Denial of Service.

No fix yet
Fix from $1,600 2021-12-21
Gpac MEDIUM 5.5
CVE-2021-45297

An infinite loop vulnerability exists in Gpac 1.0.1 in gf_get_bit_size.

No fix yet
Fix from $1,600 2021-12-21
OpenSSL HIGH 7.5
CVE-2021-4044EPSS 50%

Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server. That function may return a neg…

Fix: 1.0.2 / 17.3.0+
Fix from $1,950 2021-12-14
Sma 200 Firmware HIGH 7.5
CVE-2021-20041EPSS 7%

An unauthenticated and remote adversary can consume all of the device's CPU due to crafted HTTP requests sent to SMA100 /fileshare/sonicfiles/sonicfi…

Mitigation only
Fix from $1,950 2021-12-08
Debian Linux HIGH 7.5
CVE-2021-3908

OctoRPKI does not limit the depth of a certificate chain, allowing for a CA to create children in an ad-hoc fashion, thereby making tree traversal ne…

Fix: 1.3.0+
Fix from $1,950 2021-11-11
Routinator HIGH 7.5
CVE-2021-43172

NLnet Labs Routinator prior to 0.10.2 happily processes a chain of RRDP repositories of infinite length causing it to never finish a validation run. …

Fix: 0.10.2+
Fix from $1,950 2021-11-09
Irfanview MEDIUM 5.5
CVE-2020-23566

Irfanview v4.53 was discovered to contain an infinity loop via JPEG2000!ShowPlugInSaveOptions_W+0x1ecd8.

No fix yet
Fix from $1,600 2021-11-05
Mina MEDIUM 6.5
CVE-2021-41973

In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the H…

Fix: 2.0.22 / 2.1.5+
Fix from $1,600 2021-11-01
Fedora MEDIUM 5.5
CVE-2021-42715

An issue was discovered in stb stb_image.h 1.33 through 2.27. The HDR loader parsed truncated end-of-file RLE scanlines as an infinite sequence of ze…

Fix: after 2.27
Fix from $1,600 2021-10-21
Junos MEDIUM 6.5
CVE-2021-31363

In an MPLS P2MP environment a Loop with Unreachable Exit Condition vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS an…

Patch available
Fix from $1,600 2021-10-19
Debian Linux HIGH 7.5
CVE-2021-42260

TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxmlparser.cpp via the TIXML_UTF_LEAD_0 case. It can be triggered by a cr…

Fix: after 2.6.2
Fix from $1,950 2021-10-11
Zammad MEDIUM 6.5
CVE-2021-42084

An issue was discovered in Zammad before 4.1.1. An attacker with valid agent credentials may send a series of crafted requests that cause an endless …

Fix: 4.1.1+
Fix from $1,600 2021-10-07
Mediawiki HIGH 7.5
CVE-2021-42040

An issue was discovered in MediaWiki through 1.36.2. A parser function related to loop control allowed for an infinite loop (and php-fpm hang) within…

Fix: after 1.36.2
Fix from $1,950 2021-10-06
Irfanview MEDIUM 5.5
CVE-2021-29365

Irfanview 4.57 is affected by an infinite loop when processing a crafted BMP file in the EFFECTS!AutoCrop_W component. This can cause a denial of ser…

Mitigation only
Fix from $1,600 2021-09-28
Ros Comm HIGH 7.5
CVE-2021-37146

An infinite loop in Open Robotics ros_comm XMLRPC server in ROS Melodic through 1.4.11 and ROS Noetic through1.15.11 allows remote attackers to cause…

Fix: after 1.15.11
Fix from $1,950 2021-09-28
Tomcat HIGH 7.5
CVE-2021-41079EPSS 7%

Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured …

Fix: 8.5.64 / 9.0.44+
Fix from $1,950 2021-09-16
Rencode HIGH 7.5
CVE-2021-40839EPSS 6%

The rencode package through 1.0.6 for Python allows an infinite loop in typecode decoding (such as via ;\x2f\x7f), enabling a remote attack that cons…

Fix: after 1.0.6
Fix from $1,950 2021-09-10
Apq8009 Firmware HIGH 7.5
CVE-2021-1914

Loop with unreachable exit condition may occur due to improper handling of unsupported input in Snapdragon Auto, Snapdragon Compute, Snapdragon Conne…

Mitigation only
Fix from $1,950 2021-09-08
Kaml MEDIUM 6.5
CVE-2021-39194

kaml is an open source implementation of the YAML format with support for kotlinx.serialization. In affected versions attackers that could provide ar…

Fix: 0.35.3+
Fix from $1,600 2021-09-07
Atlant MEDIUM 5.5
CVE-2021-33599

A vulnerability affecting F-Secure Antivirus engine was discovered whereby scanning WIM archive file can lead to denial-of-service (infinite loop and…

Mitigation only
Fix from $1,600 2021-09-07
Fedora MEDIUM 5.5
CVE-2021-28698

long running loops in grant table handling In order to properly monitor resource use, Xen maintains information on the grant mappings a domain may cr…

Mitigation only
Fix from $1,600 2021-08-27
Debian Linux MEDIUM 6.3
CVE-2021-39140EPSS 6%

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to alloca…

Fix: 1.4.18+
Fix from $1,600 2021-08-23
Nichestack HIGH 7.5
CVE-2021-27565

The web server in InterNiche NicheStack through 4.0.1 allows remote attackers to cause a denial of service (infinite loop and networking outage) via …

Fix: after 4.0.1
Fix from $1,950 2021-08-19
Nichestack HIGH 7.5
CVE-2021-31400

An issue was discovered in tcp_pulloutofband() in tcp_in.c in HCC embedded InterNiche 4.0.1. The TCP out-of-band urgent-data processing function invo…

Fix: 4.3+
Fix from $1,950 2021-08-19
Jsoup HIGH 7.5
CVE-2021-37714EPSS 7%

jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS att…

Fix: 1.14.2+
Fix from $1,950 2021-08-18
Tensorflow MEDIUM 5.5
CVE-2021-37686

TensorFlow is an end-to-end open source platform for machine learning. In affected versions the strided slice implementation in TFLite has a logic bu…

Fix: 2.3.4 / 2.4.3+
Fix from $1,600 2021-08-12