Vulnerability index

Browse CVEs

870 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Infinite LoopCWE-835 × clear
Phantompdf HIGH 7.5
CVE-2020-13808

An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows resource consumption via crafted cross-reference stream data.

Fix: 9.7.2+
Fix from $1,950 2020-06-04
Debian Linux HIGH 7.5
CVE-2020-12663

Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers.

Fix: 1.10.1+
Fix from $1,950 2020-05-19
Linux Kernel MEDIUM 5.5
CVE-2020-12655

An issue was discovered in xfs_agf_verify in fs/xfs/libxfs/xfs_alloc.c in the Linux kernel through 5.6.10. Attackers may trigger a sync of excessive …

Fix: after 5.6.10
Fix from $1,600 2020-05-05
Tika MEDIUM 5.5
CVE-2020-9489

A carefully crafted or corrupt file may trigger a System.exit in Tika's OneNote Parser. Crafted or corrupted files can also cause out of memory error…

Fix: after 17.12
Fix from $1,600 2020-04-27
Fedora HIGH 7.5
CVE-2013-7488

perl-Convert-ASN1 (aka the Convert::ASN1 module for Perl) through 0.27 allows remote attackers to cause an infinite loop via unexpected input.

Fix: after 0.27
Fix from $1,950 2020-04-07
Tika MEDIUM 5.5
CVE-2020-1951

A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.

Fix: after 1.23
Fix from $1,600 2020-03-23
Fedora HIGH 7.5
CVE-2020-10675

The Library API in buger jsonparser through 2019-12-04 allows attackers to cause a denial of service (infinite loop) via a Delete call.

Fix: 1.0.0+
Fix from $1,950 2020-03-19
Icloud HIGH 7.5
CVE-2019-8741

A denial of service issue was addressed with improved input validation.

Fix: 6.0 / 7.14+
Fix from $1,950 2020-02-28
Opensips HIGH 7.5
CVE-2013-3722

A Denial of Service (infinite loop) exists in OpenSIPS before 1.10 in lookup.c.

Fix: 1.10+
Fix from $1,950 2020-02-17
Fedora HIGH 7.5
CVE-2020-7046EPSS 51%

lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the u…

Fix: 2.3.9.3+
Fix from $1,950 2020-02-12
Jobscheduler MEDIUM 6.5
CVE-2020-6855

A large or infinite loop vulnerability in the JOC Cockpit component of SOS JobScheduler 1.11 and 1.13.2 allows attackers to parameterize housekeeping…

Mitigation only
Fix from $1,600 2020-02-06
Monitoring And Management HIGH 7.5
CVE-2020-7920

pmm-server in Percona Monitoring and Management (PMM) 2.2.x before 2.2.1 allows unauthenticated denial of service.

Fix: 2.2.1+
Fix from $1,950 2020-02-06
Ubuntu Linux HIGH 7.5
CVE-2019-20421

In Jp2Image::readMetadata() in jp2image.cpp in Exiv2 0.27.2, an input file can result in an infinite loop and hang, with high CPU consumption. Remote…

Patch available
Fix from $1,950 2020-01-27
Fedora MEDIUM 6.5
CVE-2015-5239

Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT m…

Fix: 2.1.0+
Fix from $1,600 2020-01-23
Fedora MEDIUM 6.5
CVE-2015-5278

The ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows attackers to cause a denial of service (infinite loop and instance crash…

Fix: 2.4.0.1+
Fix from $1,600 2020-01-23
Fedora HIGH 7.5
CVE-2020-7595EPSS 8%

xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.

Fix: 3.0+
Fix from $1,950 2020-01-21
Junos MEDIUM 6.5
CVE-2020-1600

In a Point-to-Multipoint (P2MP) Label Switched Path (LSP) scenario, an uncontrolled resource consumption vulnerability in the Routing Protocol Daemon…

Mitigation only
Fix from $1,600 2020-01-15
Ezxml MEDIUM 6.5
CVE-2019-20201

An issue was discovered in ezXML 0.8.3 through 0.8.6. The ezxml_parse_* functions mishandle XML entities, leading to an infinite loop in which memory…

Fix: after 0.8.6
Fix from $1,600 2019-12-31
Usg9500 Firmware HIGH 7.5
CVE-2019-5274

USG9500 with versions of V500R001C30;V500R001C60 have a denial of service vulnerability. Due to a flaw in the X.509 implementation in the affected pr…

Mitigation only
Fix from $1,950 2019-12-26
Linux Kernel MEDIUM 5.5
CVE-2011-1474

A locally locally exploitable DOS vulnerability was found in pax-linux versions 2.6.32.33-test79.patch, 2.6.38-test3.patch, and 2.6.37.4-test14.patch…

Mitigation only
Fix from $1,600 2019-12-26
Debian Linux MEDIUM 6.5
CVE-2014-8561

imagemagick 6.8.9.6 has remote DOS via infinite loop

Patch available
Fix from $1,600 2019-12-15
Apq8009 Firmware HIGH 7.5
CVE-2019-10485

Infinite loop while decoding compressed data can lead to overrun condition in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdrago…

Mitigation only
Fix from $1,950 2019-12-12
Leadtools HIGH 7.5
CVE-2019-5091

An exploitable denial-of-service vulnerability exists in the Dicom-packet parsing functionality of LEADTOOLS libltdic.so version 20.0.2019.3.15. A sp…

Mitigation only
Fix from $1,950 2019-12-12
Fedora MEDIUM 6.5
CVE-2019-19582

An issue was discovered in Xen through 4.12.x allowing x86 guest OS users to cause a denial of service (infinite loop) because certain bit iteration …

Fix: after 4.12.1
Fix from $1,600 2019-12-11
Otrs HIGH 7.5
CVE-2019-18180

Improper Check for filenames with overly long extensions in PostMaster (sending in email) or uploading files (e.g. attaching files to mails) of ((OTR…

Fix: 5.0.39 / 6.0.24+
Fix from $1,950 2019-12-05
Validators HIGH 7.5
CVE-2019-19588

The validators package 0.12.2 through 0.12.5 for Python enters an infinite loop when validators.domain is called with a crafted domain string. This i…

Fix: after 0.12.5
Fix from $1,950 2019-12-05
Goahead HIGH 7.5
CVE-2019-5097EPSS 45%

A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web server application in versions v5…

No fix yet
Fix from $1,950 2019-12-03
Fedora MEDIUM 5.5
CVE-2019-19451

When GNOME Dia before 2019-11-27 is launched with a filename argument that is not a valid codepoint in the current encoding, it enters an endless loo…

Fix: 2019-11-27+
Fix from $1,600 2019-11-29
GitLab HIGH 7.5
CVE-2019-18455

An issue was discovered in GitLab Community and Enterprise Edition 11 through 12.4 when building Nested GraphQL queries. It has a large or infinite l…

Fix: after 12.4.0
Fix from $1,950 2019-11-26
Mongoose CRITICAL 9.8
CVE-2019-19307EPSS 42%

An integer overflow in parse_mqtt in mongoose.c in Cesanta Mongoose 6.16 allows an attacker to achieve remote DoS (infinite loop), or possibly cause …

No fix yet
Fix from $2,300 2019-11-26