Vulnerability index

Browse CVEs

870 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Infinite LoopCWE-835 × clear
Enterprise Linux Openstack Platform MEDIUM 6.5
CVE-2015-5694

Designate does not enforce the DNS protocol limit concerning record set sizes

Mitigation only
Fix from $1,600 2019-11-22
Apq8009 Firmware HIGH 7.5
CVE-2019-2335

While processing Attach Reject message, Valid exit condition is not met resulting into an infinite loop in Snapdragon Auto, Snapdragon Compute, Snapd…

No fix yet
Fix from $1,950 2019-11-21
Istio HIGH 7.5
CVE-2019-18817

Istio 1.3.x before 1.3.5 allows Denial of Service because continue_on_listener_filters_timeout is set to True, a related issue to CVE-2019-18836.

Fix: 1.3.5+
Fix from $1,950 2019-11-12
Envoy HIGH 7.5
CVE-2019-18836

Envoy 1.12.0 allows a remote denial of service because of resource loops, as demonstrated by a single idle TCP connection being able to keep a worker…

Fix: after 1.3.3
Fix from $1,950 2019-11-11
Xpdf MEDIUM 5.5
CVE-2010-0207

In xpdf, the xref table contains an infinite loop which allows remote attackers to cause a denial of service (application crash) in xpdf-based PDF vi…

Mitigation only
Fix from $1,600 2019-10-30
Thrift HIGH 7.5
CVE-2019-0205EPSS 9%

In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because…

Fix: after 0.12.0
Fix from $1,950 2019-10-29
Proftpd HIGH 7.5
CVE-2019-18217EPSS 20%

ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handling of overly long commands b…

Fix: after 1.3.5
Fix from $1,950 2019-10-21
Debian Linux MEDIUM 5.5
CVE-2019-17349

An issue was discovered in Xen through 4.12.x allowing Arm domU attackers to cause a denial of service (infinite loop) involving a LoadExcl or StoreE…

Fix: after 4.12.1
Fix from $1,600 2019-10-08
Debian Linux MEDIUM 5.5
CVE-2019-17350

An issue was discovered in Xen through 4.12.x allowing Arm domU attackers to cause a denial of service (infinite loop) involving a compare-and-exchan…

Fix: after 4.12.1
Fix from $1,600 2019-10-08
Linux Kernel HIGH 7.5
CVE-2019-16413

An issue was discovered in the Linux kernel before 5.0.4. The 9p filesystem did not protect i_size_write() properly, which causes an i_size_read() in…

Fix: 5.0.4+
Fix from $1,950 2019-09-19
Wireshark HIGH 7.5
CVE-2019-16319

In Wireshark 3.0.0 to 3.0.3 and 2.6.0 to 2.6.10, the Gryphon dissector could go into an infinite loop. This was addressed in plugins/epan/gryphon/pac…

Fix: after 3.0.3
Fix from $1,950 2019-09-15
Commons Compress HIGH 7.5
CVE-2019-12402EPSS 16%

The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially craf…

Fix: after 14.4.0
Fix from $1,950 2019-08-30
Riot HIGH 7.5
CVE-2019-15702

In the TCP implementation (gnrc_tcp) in RIOT through 2019.07, the parser for TCP options does not terminate on all inputs, allowing a denial-of-servi…

Fix: after 2019.07
Fix from $1,950 2019-08-27
Debian Linux MEDIUM 5.5
CVE-2019-15143

In DjVuLibre 3.5.27, the bitmap reader component allows attackers to cause a denial-of-service error (resource exhaustion caused by a GBitmap::read_r…

No fix yet
Fix from $1,600 2019-08-18
Debian Linux MEDIUM 6.5
CVE-2019-14442

In mpc8_read_header in libavformat/mpc8.c in Libav 12.3, an input file can result in an avio_seek infinite loop and hang, with 100% CPU consumption. …

No fix yet
Fix from $1,600 2019-07-30
Libav MEDIUM 6.5
CVE-2019-14371

An issue was discovered in Libav 12.3. There is an infinite loop in the function mov_probe in the file libavformat/mov.c, related to offset and tag.

No fix yet
Fix from $1,600 2019-07-28
Libav MEDIUM 6.5
CVE-2019-14372

In Libav 12.3, there is an infinite loop in the function wv_read_block_header() in the file wvdec.c.

No fix yet
Fix from $1,600 2019-07-28
Mgetty MEDIUM 5.5
CVE-2019-1010189

mgetty prior to version 1.2.1 is affected by: Infinite Loop. The impact is: DoS, the program does never terminates. The component is: g3/g32pbm.c. Th…

Fix: 1.2.1+
Fix from $1,600 2019-07-24
Haproxy HIGH 7.5
CVE-2019-14241EPSS 70%

HAProxy through 2.0.2 allows attackers to cause a denial of service (ha_panic) via vectors related to htx_manage_client_side_cookies in proto_htx.c.

Fix: after 2.0.2
Fix from $1,950 2019-07-23
Phantompdf HIGH 7.5
CVE-2019-14207

An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash when calling the clone function due to an endless loop resulti…

Fix: 8.3.11+
Fix from $1,950 2019-07-21
Fedora HIGH 7.5
CVE-2019-1010142

scapy 2.4.0 is affected by: Denial of Service. The impact is: infinite loop, resource consumption and program unresponsive. The component is: _RADIUS…

Patch available
Fix from $1,950 2019-07-19
Zipios MEDIUM 6.5
CVE-2019-13453

Zipios before 0.1.7 does not properly handle certain malformed zip archives and can go into an infinite loop, causing a denial of service. This is re…

Fix: 0.1.7+
Fix from $1,600 2019-07-17
Big Ip Local Traffic Manager MEDIUM 6.5
CVE-2019-6638

On BIG-IP 14.1.0-14.1.0.5 and 14.0.0-14.0.0.4, Malformed http requests made to an undisclosed iControl REST endpoint can lead to infinite loop of the…

Fix: 14.0.0.5 / 14.1.0.6+
Fix from $1,600 2019-07-03
Commons Imaging HIGH 7.5
CVE-2018-17202

Certain input files could make the code to enter into an infinite loop when Apache Sanselan 0.97-incubator was used to parse them, which could be use…

Mitigation only
Fix from $1,950 2019-05-06
Fizz HIGH 7.5
CVE-2019-3560

An improperly performed length calculation on a buffer in PlaintextRecordLayer could lead to an infinite loop and denial-of-service based on user inp…

Fix: 2019.03.04.00+
Fix from $1,950 2019-04-29
Linux Kernel HIGH 7.7
CVE-2019-3900

An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in hand…

Fix: 3.16.72 / 4.4.191+
Fix from $1,950 2019-04-25
Wireshark HIGH 7.5
CVE-2019-10897

In Wireshark 3.0.0, the IEEE 802.11 dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-ieee80211.c by detecting c…

Patch available
Fix from $1,950 2019-04-09
Wireshark HIGH 7.5
CVE-2019-10898

In Wireshark 3.0.0, the GSUP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-gsm_gsup.c by rejecting an invali…

Patch available
Fix from $1,950 2019-04-09
Wireshark HIGH 7.5
CVE-2019-10900

In Wireshark 3.0.0, the Rbm dissector could go into an infinite loop. This was addressed in epan/dissectors/file-rbm.c by handling unknown object typ…

Patch available
Fix from $1,950 2019-04-09
Shellinabox HIGH 7.5
CVE-2018-16789EPSS 6%

libhttp/url.c in shellinabox through 2.20 has an implementation flaw in the HTTP request parsing logic. By sending a crafted multipart/form-data HTTP…

Fix: after 2.20
Fix from $1,950 2019-03-21