Vulnerability index

Browse CVEs

870 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Infinite LoopCWE-835 × clear
Fedora HIGH 7.5
CVE-2021-28484

An issue was discovered in the /api/connector endpoint handler in Yubico yubihsm-connector before 3.0.1 (in YubiHSM SDK before 2021.04). The handler …

Fix: 3.0.1+
Fix from $1,950 2021-04-14
Clamav HIGH 7.5
CVE-2021-1252

A vulnerability in the Excel XLM macro parsing module in Clam AntiVirus (ClamAV) Software versions 0.103.0 and 0.103.1 could allow an unauthenticated…

Mitigation only
Fix from $1,950 2021-04-08
Linux Kernel MEDIUM 5.5
CVE-2020-36310

An issue was discovered in the Linux kernel before 5.8. arch/x86/kvm/svm/svm.c allows a set_memory_region_test infinite loop for certain nested page …

Fix: 5.8+
Fix from $1,600 2021-04-07
Tika MEDIUM 5.5
CVE-2021-28657

A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade …

Fix: after 17.12
Fix from $1,600 2021-03-31
Openshift Container Platform HIGH 7.5
CVE-2021-20270

An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SM…

Fix: after 2.7.3
Fix from $1,950 2021-03-23
Fedora MEDIUM 6.0
CVE-2021-3416

A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in versions up to and including 5.2.0. The issue occurs…

Fix: after 5.2.0
Fix from $1,600 2021-03-18
Stackstorm HIGH 7.5
CVE-2021-28667

StackStorm before 3.4.1, in some situations, has an infinite loop that consumes all available memory and disk space. This can occur if Python 3.x is …

Fix: 3.4.1+
Fix from $1,950 2021-03-18
Csrb31024 Firmware MEDIUM 5.5
CVE-2020-11186

Modem will enter into busy mode in an infinite loop while parsing histogram dimension due to improper validation of input received in Snapdragon Auto…

Mitigation only
Fix from $1,600 2021-03-17
Simatic S7 Plcsim MEDIUM 5.5
CVE-2021-25673

A vulnerability has been identified in SIMATIC S7-PLCSIM V5.4 (All versions). An attacker with local access to the system could cause a Denial-of-Ser…

Mitigation only
Fix from $1,600 2021-03-15
Go HIGH 7.5
CVE-2021-27918

encoding/xml in Go before 1.15.9 and 1.16.x before 1.16.1 has an infinite loop if a custom TokenReader (for xml.NewTokenDecoder) returns EOF in the m…

Fix: 1.15.9 / 1.16.1+
Fix from $1,950 2021-03-11
Debian Linux MEDIUM 5.5
CVE-2021-20255

A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU. This issue occurs while processing…

Patch available
Fix from $1,600 2021-03-09
Debian Linux MEDIUM 5.5
CVE-2020-27618

The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input sequences in IBM1364, IBM1371…

Fix: after 2.32
Fix from $1,600 2021-02-26
Hirschmann Hios MEDIUM 6.5
CVE-2020-9307

Hirschmann OS2, RSP, and RSPE devices before HiOS 08.3.00 allow a denial of service. An unauthenticated, adjacent attacker can cause an infinite loop…

Fix: 07.1.00 / 08.3.00+
Fix from $1,600 2021-02-11
Picoquic HIGH 7.5
CVE-2020-24944

picoquic (before 3rd of July 2020) allows attackers to cause a denial of service (infinite loop) via a crafted QUIC frame, related to the picoquic_de…

Fix: 2020-07-03+
Fix from $1,950 2021-02-08
Openwrt MEDIUM 6.5
CVE-2021-22161

In OpenWrt 19.07.x before 19.07.7, when IPv6 is used, a routing loop can occur that generates excessive network traffic between an affected device an…

Fix: after 19.07.6
Fix from $1,600 2021-02-07
Debian Linux HIGH 7.5
CVE-2020-36227EPSS 78%

A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in denial of s…

Fix: 2.4.57 / 11.4+
Fix from $1,950 2021-01-26
Junos MEDIUM 6.5
CVE-2021-0221

In an EVPN/VXLAN scenario, if an IRB interface with a virtual gateway address (VGA) is configured on a PE, a traffic loop may occur upon receipt of s…

Mitigation only
Fix from $1,600 2021-01-15
Kamadak Exif MEDIUM 6.5
CVE-2021-21235

kamadak-exif is an exif parsing library written in pure Rust. In kamadak-exif version 0.5.2, there is an infinite loop in parsing crafted PNG files. …

Patch available
Fix from $1,600 2021-01-06
Ac6 Firmware HIGH 7.5
CVE-2020-28095

On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, a large HTTP POST request sent to the change password API will trigger the router to crash and…

No fix yet
Fix from $1,950 2020-12-30
Ubuntu Linux MEDIUM 5.5
CVE-2020-29385

GNOME gdk-pixbuf (aka GdkPixbuf) before 2.42.2 allows a denial of service (infinite loop) in lzw.c in the function write_indexes. if c->self_code equ…

Fix: 2.42.2+
Fix from $1,600 2020-12-26
Azure Sphere MEDIUM 5.5
CVE-2020-35609

A denial-of-service vulnerability exists in the asynchronous ioctl functionality of Microsoft Azure Sphere 20.05. A sequence of specially crafted ioc…

No fix yet
Fix from $1,600 2020-12-22
Picotcp HIGH 7.5
CVE-2020-17444

An issue was discovered in picoTCP 1.7.0. The routine for processing the next header field (and deducing whether the IPv6 extension headers are valid…

Fix: after 1.7.0
Fix from $1,950 2020-12-11
Picotcp HIGH 7.5
CVE-2020-24337

An issue was discovered in picoTCP and picoTCP-NG through 1.7.0. When an unsupported TCP option with zero length is provided in an incoming TCP packe…

Fix: after 1.7.0
Fix from $1,950 2020-12-11
Contiki HIGH 7.5
CVE-2020-13984

An issue was discovered in Contiki through 3.0. An infinite loop exists in the uIP TCP/IP stack component when processing IPv6 extension headers in e…

Fix: after 3.0
Fix from $1,950 2020-12-11
Contiki HIGH 7.5
CVE-2020-13986

An issue was discovered in Contiki through 3.0. An infinite loop exists in the uIP TCP/IP stack component when handling RPL extension headers of IPv6…

Fix: after 3.0
Fix from $1,950 2020-12-11
Debian Linux MEDIUM 5.5
CVE-2020-28916

hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address.

Patch available
Fix from $1,600 2020-12-04
MongoDB MEDIUM 6.5
CVE-2018-20803

A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which loop indefinitely in mathemat…

Fix: 3.4.19 / 3.6.10+
Fix from $1,600 2020-11-23
Accountsservice MEDIUM 5.5
CVE-2020-16127

An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, would perform unbounded read …

Fix: 0.6.55+
Fix from $1,600 2020-11-11
Linux Kernel MEDIUM 5.5
CVE-2020-27152

An issue was discovered in ioapic_lazy_update_eoi in arch/x86/kvm/ioapic.c in the Linux kernel before 5.9.2. It has an infinite loop related to impro…

Fix: 5.9.2+
Fix from $1,600 2020-11-06
Wireshark HIGH 7.5
CVE-2020-28030

In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed in epan/dissectors/packet-gquic.c by correcting the implementation o…

Fix: after 3.2.7
Fix from $1,950 2020-11-02