Vulnerability index

Browse CVEs

870 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Infinite LoopCWE-835 × clear
Contiki HIGH 7.5
CVE-2021-38387

In Contiki 3.0, a Telnet server that silently quits (before disconnection with clients) leads to connected clients entering an infinite loop and wait…

Mitigation only
Fix from $1,950 2021-08-10
Contiki HIGH 7.5
CVE-2021-38311

In Contiki 3.0, potential nonterminating acknowledgment loops exist in the Telnet service. When the negotiated options are already disabled, servers …

Patch available
Fix from $1,950 2021-08-09
Fedora MEDIUM 5.5
CVE-2021-37621

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found…

Fix: after 0.27.4
Fix from $1,600 2021-08-09
Fedora MEDIUM 5.5
CVE-2021-37622

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found…

Fix: after 0.27.4
Fix from $1,600 2021-08-09
Fedora MEDIUM 5.5
CVE-2021-34334

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop is trigge…

Fix: after 0.27.4
Fix from $1,600 2021-08-09
Fedora MEDIUM 5.5
CVE-2021-37623

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found…

Fix: after 0.27.4
Fix from $1,600 2021-08-09
Linux Kernel MEDIUM 5.5
CVE-2021-3679

A lack of CPU resource in the Linux kernel tracing module functionality in versions prior to 5.14-rc3 was found in the way user uses trace ring buffe…

Fix: 5.14+
Fix from $1,600 2021-08-05
Wireshark HIGH 7.5
CVE-2021-22235

Crash in DNP dissector in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 allows denial of service via packet injection or crafted capture file

Fix: 3.2.15 / 3.4.7+
Fix from $1,950 2021-07-20
Jt2go MEDIUM 5.5
CVE-2021-34332

A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The BMP_Loader.dll library in a…

Fix: 13.2.0+
Fix from $1,600 2021-07-13
Commons Compress HIGH 7.5
CVE-2021-35515EPSS 12%

When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This cou…

Fix: after 18.3
Fix from $1,950 2021-07-13
Mediawiki HIGH 7.5
CVE-2021-36125

An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. The Special:GlobalRenameRequest page is vulnerable to infinite loops …

Fix: after 1.36
Fix from $1,950 2021-07-02
Contiki Ng HIGH 7.5
CVE-2021-21279

Contiki-NG is an open-source, cross-platform operating system for internet of things devices. In verions prior to 4.6, an attacker can perform a deni…

Fix: 4.6+
Fix from $1,950 2021-06-18
Cxf HIGH 7.5
CVE-2021-30468EPSS 7%

A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thr…

Fix: 3.3.11 / 3.4.4+
Fix from $1,950 2021-06-16
Pdfbox MEDIUM 5.5
CVE-2021-31812

In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 a…

Fix: after 2.0.23
Fix from $1,600 2021-06-12
Wireshark HIGH 7.5
CVE-2021-22222

Infinite loop in DVB-S2-BB dissector in Wireshark 3.4.0 to 3.4.5 allows denial of service via packet injection or crafted capture file

Fix: after 3.4.5
Fix from $1,950 2021-06-07
Pillow HIGH 7.5
CVE-2021-28676

An issue was discovered in Pillow before 8.2.0. For FLI data, FliDecode did not properly check that the block advance was non-zero, potentially leadi…

Fix: 8.2.0+
Fix from $1,950 2021-06-02
Debian Linux MEDIUM 5.5
CVE-2021-3468

A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is no…

Fix: after 0.8
Fix from $1,600 2021-06-02
Go HIGH 7.5
CVE-2021-33194EPSS 7%

golang.org/x/net before v0.0.0-20210520170846-37e1c6afe023 allows attackers to cause a denial of service (infinite loop) via crafted ParseFragment in…

Fix: after 1.16.4
Fix from $1,950 2021-05-26
Zephyr MEDIUM 5.5
CVE-2020-13602

Remote Denial of Service in LwM2M do_write_op_tlv. Zephyr versions >= 1.14.2, >= 2.2.0 contain Improper Input Validation (CWE-20), Loop with Unreacha…

Fix: after 2.2.0
Fix from $1,600 2021-05-25
Tensorflow HIGH 7.8
CVE-2021-29591

TensorFlow is an end-to-end open source platform for machine learning. TFlite graphs must not have loops between nodes. However, this condition was n…

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14
Fedora HIGH 7.5
CVE-2021-29510

Pydantic is a data validation and settings management using Python type hinting. In affected versions passing either `'infinity'`, `'inf'` or `float(…

Fix: 1.6.2 / 1.7.4+
Fix from $1,950 2021-05-13
Simatic Wincc Runtime Advanced HIGH 7.5
CVE-2021-27385

A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIM…

Fix: 15.1 / 16+
Fix from $1,950 2021-05-12
Big Ip Access Policy Manager HIGH 7.5
CVE-2021-23009

On BIG-IP version 16.0.x before 16.0.1.1 and 15.1.x before 15.1.3, malformed HTTP/2 requests may cause an infinite loop which causes a Denial of Serv…

Fix: 15.1.3 / 16.0.1.1+
Fix from $1,950 2021-05-10
Cumulative Distribution Function HIGH 7.5
CVE-2021-29486

cumulative-distribution-function is an open source npm library used which calculates statistical cumulative distribution function from data array of …

Fix: 2.0.0+
Fix from $1,950 2021-04-30
Xz HIGH 7.5
CVE-2021-29482

xz is a compression and decompression library focusing on the xz format completely written in Go. The function readUvarint used to read the xz contai…

Fix: 0.5.8+
Fix from $1,950 2021-04-28
Pdfresurrect MEDIUM 5.5
CVE-2021-3508

A flaw was found in PDFResurrect in version 0.22b. There is an infinite loop in get_xref_linear_skipped() in pdf.c via a crafted PDF file.

Patch available
Fix from $1,600 2021-04-28
Debian Linux HIGH 7.5
CVE-2019-25040

Unbound before 1.9.5 allows an infinite loop via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Althoug…

Fix: 1.9.5+
Fix from $1,950 2021-04-27
Capital Vstar HIGH 7.5
CVE-2021-25663

A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303),…

Fix: 4.1.0 / 2017.02.4+
Fix from $1,950 2021-04-22
Capital Vstar HIGH 7.5
CVE-2021-25664

A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303),…

Fix: 4.1.0 / 2017.02.4+
Fix from $1,950 2021-04-22
Junos MEDIUM 5.3
CVE-2021-0273

An always-incorrect control flow implementation in the implicit filter terms of Juniper Networks Junos OS and Junos OS Evolved on ACX5800, EX9200 Ser…

Mitigation only
Fix from $1,600 2021-04-22