Vulnerability index

Browse CVEs

870 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Infinite LoopCWE-835 × clear
Miniz HIGH 7.5
CVE-2018-12913

In Miniz 2.0.7, tinfl_decompress in miniz_tinfl.c has an infinite loop because sym2 and counter can both remain equal to zero.

No fix yet
Fix from $1,950 2018-06-27
Junrar MEDIUM 5.5
CVE-2018-12418

Archive.java in Junrar before 1.0.1, as used in Apache Tika and other products, is affected by a denial of service vulnerability due to an infinite l…

Fix: 1.0.1+
Fix from $1,600 2018-06-14
Asterisk MEDIUM 6.5
CVE-2018-12228EPSS 7%

An issue was discovered in Asterisk Open Source 15.x before 15.4.1. When connected to Asterisk via TCP/TLS, if the client abruptly disconnects, or se…

Fix: 15.4.1+
Fix from $1,600 2018-06-12
Ngiflib HIGH 7.5
CVE-2018-11657

ngiflib.c in MiniUPnP ngiflib 0.4 has an infinite loop in DecodeGifImg and LoadGif.

Mitigation only
Fix from $1,950 2018-06-01
Readstat HIGH 7.5
CVE-2018-11365

sas/readstat_sas7bcat_read.c in libreadstat.a in ReadStat 0.1.1 has an infinite loop.

No fix yet
Fix from $1,950 2018-05-22
Ubuntu Linux MEDIUM 6.5
CVE-2017-18271

In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-22, an infinite loop vulnerability was found in the function ReadMIFFImage in coders/miff.c, which allows …

Mitigation only
Fix from $1,600 2018-05-18
Debian Linux MEDIUM 6.5
CVE-2017-18273

In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-22, an infinite loop vulnerability was found in the function ReadTXTImage in coders/txt.c, which allows at…

No fix yet
Fix from $1,600 2018-05-18
Debian Linux MEDIUM 6.5
CVE-2018-10981

An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to cause a denial of service (host OS infinite loop) in situations wher…

Fix: after 4.10.1
Fix from $1,600 2018-05-10
Ubuntu Linux MEDIUM 5.5
CVE-2017-18267

The FoFiType1C::cvtGlyph function in fofi/FoFiType1C.cc in Poppler through 0.64.0 allows remote attackers to cause a denial of service (infinite recu…

Fix: after 0.64.0
Fix from $1,600 2018-05-10
PHP HIGH 7.5
CVE-2018-10546EPSS 10%

An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. An infinite loop exists in ext/iconv/…

Fix: 5.6.36 / 7.0.30+
Fix from $1,950 2018-04-29
Tika MEDIUM 5.5
CVE-2018-1338

A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's BPGParser in versions of Apache Tika before 1.18.

Fix: 1.18+
Fix from $1,600 2018-04-25
Tika MEDIUM 5.5
CVE-2018-1339

A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's ChmParser in versions of Apache Tika before 1.18.

Fix: 1.18+
Fix from $1,600 2018-04-25
Ffmpeg MEDIUM 6.5
CVE-2018-7751

The svg_probe function in libavformat/img2dec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (Infinite Loop) via a cr…

Fix: after 3.4.2
Fix from $1,600 2018-04-24
Debian Linux MEDIUM 5.5
CVE-2018-10289

In MuPDF 1.13.0, there is an infinite loop in the fz_skip_space function of the pdf/pdf-xref.c file. A remote adversary could leverage this vulnerabi…

No fix yet
Fix from $1,600 2018-04-22
Linux Kernel MEDIUM 5.5
CVE-2017-18261

The arch_timer_reg_read_stable macro in arch/arm64/include/asm/arch_timer.h in the Linux kernel before 4.13 allows local users to cause a denial of s…

Fix: 4.13+
Fix from $1,600 2018-04-19
Ubuntu Linux MEDIUM 6.5
CVE-2018-10177

In ImageMagick 7.0.7-28, there is an infinite loop in the ReadOneMNGImage function of the coders/png.c file. Remote attackers could leverage this vul…

No fix yet
Fix from $1,600 2018-04-16
FreeBSD HIGH 7.5
CVE-2018-6918

In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p9, 10.4-STABLE, 10.4-RELEASE-p8 and 10.3-RELEASE-p28, the length field of the ipsec option header does n…

Fix: 10.4 / 11.1+
Fix from $1,950 2018-04-04
Wireshark HIGH 7.5
CVE-2018-9257

In Wireshark 2.4.0 to 2.4.5, the CQL dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-cql.c by checking for a n…

Fix: after 2.4.5
Fix from $1,950 2018-04-04
Debian Linux MEDIUM 5.3
CVE-2018-9251

The xz_decomp function in xzlib.c in libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via …

No fix yet
Fix from $1,600 2018-04-04
Gpu Driver MEDIUM 5.5
CVE-2018-6253

NVIDIA GPU Display Driver contains a vulnerability in the DirectX and OpenGL Usermode drivers where a specially crafted pixel shader can cause infini…

Mitigation only
Fix from $1,600 2018-04-02
Long Range Zip MEDIUM 5.5
CVE-2018-9058

In Long Range Zip (aka lrzip) 0.631, there is an infinite loop in the runzip_fd function of runzip.c. Remote attackers could leverage this vulnerabil…

No fix yet
Fix from $1,600 2018-03-27
Commons Compress MEDIUM 5.5
CVE-2018-1324

A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and Z…

Fix: after 8.0.27
Fix from $1,600 2018-03-16
Debian Linux MEDIUM 5.5
CVE-2017-18233

An issue was discovered in Exempi before 2.4.4. Integer overflow in the Chunk class in XMPFiles/source/FormatSupport/RIFF.cpp allows remote attackers…

Fix: 2.4.4+
Fix from $1,600 2018-03-15
Debian Linux MEDIUM 5.5
CVE-2017-18236

An issue was discovered in Exempi before 2.4.4. The ASF_Support::ReadHeaderObject function in XMPFiles/source/FormatSupport/ASF_Support.cpp allows re…

Fix: 2.4.4+
Fix from $1,600 2018-03-15
Debian Linux MEDIUM 5.5
CVE-2017-18238

An issue was discovered in Exempi before 2.4.4. The TradQT_Manager::ParseCachedBoxes function in XMPFiles/source/FormatSupport/QuickTime_Support.cpp …

Fix: 2.4.4+
Fix from $1,600 2018-03-15
Debian Linux HIGH 7.5
CVE-2018-1000075

RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 a…

Fix: after 2.5.0
Fix from $1,950 2018-03-13
Podofo HIGH 8.8
CVE-2018-8002EPSS 8%

In PoDoFo 0.9.5, there exists an infinite loop vulnerability in PdfParserObject::ParseFileComplete() in PdfParserObject.cpp which may result in stack…

No fix yet
Fix from $1,950 2018-03-09
Dp300 Firmware MEDIUM 5.5
CVE-2017-17150

Timergrp module in Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C0…

Mitigation only
Fix from $1,600 2018-03-09
Dp300 Firmware MEDIUM 5.7
CVE-2017-17131

Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V600R006C00; TE50 V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00…

Mitigation only
Fix from $1,600 2018-03-05
Linux Kernel MEDIUM 5.5
CVE-2017-18208

The madvise_willneed function in mm/madvise.c in the Linux kernel before 4.14.4 allows local users to cause a denial of service (infinite loop) by tr…

Fix: 4.14.4+
Fix from $1,600 2018-03-01