Vulnerability index

Browse CVEs

870 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Infinite LoopCWE-835 × clear
Bass MEDIUM 6.5
CVE-2019-18796

The BASS Audio Library 2.4.14 under Windows is prone to a BASS_StreamCreateFile Denial of Service vulnerability (infinite loop) via a crafted .mp3 fi…

Fix: after 2.4.14.1
Fix from $1,600 2020-10-16
Wireshark HIGH 7.5
CVE-2020-26575

In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector could enter an infinite loop. This was addressed in epan/dissectors/pac…

Fix: after 3.2.7
Fix from $1,950 2020-10-06
Debian Linux HIGH 7.5
CVE-2020-15598

Trustwave ModSecurity 3.x through 3.0.4 allows denial of service via a special request. NOTE: The discoverer reports "Trustwave has signaled they are…

Fix: after 3.0.4
Fix from $1,950 2020-10-06
Linux Kernel MEDIUM 5.5
CVE-2020-25641

A flaw was found in the Linux kernel's implementation of biovecs in versions before 5.9-rc7. A zero-length biovec request issued by the block subsyst…

Fix: after 5.8.13
Fix from $1,600 2020-10-06
Debian Linux MEDIUM 5.3
CVE-2020-25625

hw/usb/hcd-ohci.c in QEMU 5.0.0 has an infinite loop when a TD list has a loop.

Patch available
Fix from $1,600 2020-09-25
Http HIGH 7.5
CVE-2020-25574

An issue was discovered in the http crate before 0.1.20 for Rust. An integer overflow in HeaderMap::reserve() could result in denial of service (e.g.…

Fix: 0.1.20+
Fix from $1,950 2020-09-14
Wolfssl HIGH 7.5
CVE-2020-12457

An issue was discovered in wolfSSL before 4.5.0. It mishandles the change_cipher_spec (CCS) message processing logic for TLS 1.3. If an attacker send…

Fix: 4.5.0+
Fix from $1,950 2020-08-21
Smart Connect Knx Vaillant HIGH 7.5
CVE-2019-19643

ise smart connect KNX Vaillant 1.2.839 contain a Denial of Service.

No fix yet
Fix from $1,950 2020-08-14
Android MEDIUM 5.5
CVE-2020-0247

In Threshold::getHistogram of ImageProcessHelper.java, there is a possible crash loop due to an uncaught exception. This could lead to local denial o…

Mitigation only
Fix from $1,600 2020-08-11
Firefox MEDIUM 6.5
CVE-2020-15654

When in an endless loop, a website specifying a custom cursor using CSS could make it look like the user is interacting with the user interface, when…

Fix: 78.1 / 79.0+
Fix from $1,600 2020-08-10
Go HIGH 7.5
CVE-2020-16845

Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary via invalid inputs.

Fix: 1.13.15 / 1.14.7+
Fix from $1,950 2020-08-06
Ht801 Firmware HIGH 7.5
CVE-2020-5761

Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to CPU exhaustion due to an infinite loop in the TR-069 service. Unauthent…

Fix: after 1.0.17.5
Fix from $1,950 2020-07-29
Libredwg MEDIUM 6.5
CVE-2019-20911

An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to denial of service in bit_calc_CRC in bits.c, related to a for loop.

Fix: after 0.9.3
Fix from $1,600 2020-07-16
Tomcat HIGH 7.5
CVE-2020-13935EPSS 87%

The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and …

Fix: after 9.0.36
Fix from $1,950 2020-07-14
Python HIGH 7.5
CVE-2019-20907EPSS 6%

In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, becaus…

Fix: 3.5.10 / 3.6.12+
Fix from $1,950 2020-07-13
Wireshark HIGH 7.5
CVE-2020-15466

In Wireshark 3.2.0 to 3.2.4, the GVCP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-gvcp.c by ensuring that …

Fix: after 3.2.4
Fix from $1,950 2020-07-05
Pa6 Firmware HIGH 7.5
CVE-2019-19506

Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a denial of service, caused by an error in the "homeplugd" process. By sending a special…

No fix yet
Fix from $1,950 2020-06-25
Mattermost Server HIGH 7.5
CVE-2020-14447

An issue was discovered in Mattermost Server before 5.23.0. Large webhook requests allow attackers to cause a denial of service (infinite loop), aka …

Fix: 5.23.0+
Fix from $1,950 2020-06-19
Mattermost Server HIGH 7.5
CVE-2020-14448

An issue was discovered in Mattermost Server before 5.23.0. Automatic direct message replies allow attackers to cause a denial of service (infinite l…

Fix: 5.23.0+
Fix from $1,950 2020-06-19
Mbed Os HIGH 7.5
CVE-2020-12885

An infinite loop was discovered in the CoAP library in Arm Mbed OS 5.15.3. The CoAP parser is responsible for parsing received CoAP packets. The func…

Patch available
Fix from $1,950 2020-06-18
Text HIGH 7.5
CVE-2020-14040

The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causi…

Fix: 0.3.3+
Fix from $1,950 2020-06-17
Ubuntu Linux HIGH 7.5
CVE-2020-14398

An issue was discovered in LibVNCServer before 0.9.13. An improperly closed TCP connection causes an infinite loop in libvncclient/sockets.c.

Fix: 3.2.1.0+
Fix from $1,950 2020-06-17
Android MEDIUM 6.5
CVE-2020-0184

In ihevcd_ref_list() of ihevcd_ref_list.c, there is a possible infinite loop due to a missing bounds check. This could lead to remote denial of servi…

Patch available
Fix from $1,600 2020-06-11
Android MEDIUM 6.5
CVE-2020-0189

In ihevcd_decode() of ihevcd_decode.c, there is possible resource exhaustion due to an infinite loop. This could lead to remote denial of service wit…

Patch available
Fix from $1,600 2020-06-11
Android MEDIUM 6.5
CVE-2020-0171

In Parse_lart of eas_mdls.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no…

Patch available
Fix from $1,600 2020-06-11
Android MEDIUM 6.5
CVE-2020-0172

In Parse_art of eas_mdls.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no …

Patch available
Fix from $1,600 2020-06-11
Android MEDIUM 6.5
CVE-2020-0174

In Parse_ptbl of eas_mdls.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no…

Patch available
Fix from $1,600 2020-06-11
Android MEDIUM 6.5
CVE-2020-0169

In RTTTL_Event of eas_rtttl.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with …

Patch available
Fix from $1,600 2020-06-11
Android MEDIUM 6.5
CVE-2020-0170

In IMY_Event of eas_imelody.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with …

Patch available
Fix from $1,600 2020-06-11
Phantompdf HIGH 7.5
CVE-2020-13807

An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has circular reference mishandling that causes a loop.

Fix: 9.7.2+
Fix from $1,950 2020-06-04