Vulnerability index

Browse CVEs

870 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Infinite LoopCWE-835 × clear
Xpdf MEDIUM 5.5
CVE-2018-7453

Infinite recursion in AcroForm::scanField in AcroForm.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file due to lac…

Mitigation only
Fix from $1,600 2018-02-24
Wireshark HIGH 7.5
CVE-2018-7330

In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-thread.c had an infinite loop that was addressed by using a correct integer d…

Fix: after 2.4.4
Fix from $1,950 2018-02-23
Wireshark HIGH 7.5
CVE-2018-7331

In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-ber.c had an infinite loop that was addressed by validating a length.

Fix: after 2.4.4
Fix from $1,950 2018-02-23
Wireshark HIGH 7.5
CVE-2018-7332

In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-reload.c had an infinite loop that was addressed by validating a length.

Fix: after 2.4.4
Fix from $1,950 2018-02-23
Wireshark HIGH 7.5
CVE-2018-7333

In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-rpcrdma.c had an infinite loop that was addressed by validating a chunk size.

Fix: after 2.4.4
Fix from $1,950 2018-02-23
Wireshark HIGH 7.5
CVE-2018-7421

In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the DMP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-dmp.c…

Fix: after 2.4.4
Fix from $1,950 2018-02-23
Wireshark HIGH 7.5
CVE-2018-7322

In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-dcm.c had an infinite loop that was addressed by checking for integer wraparo…

Fix: after 2.4.4
Fix from $1,950 2018-02-23
Wireshark HIGH 7.5
CVE-2018-7324

In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-sccp.c had an infinite loop that was addressed by using a correct integer dat…

Fix: after 2.4.4
Fix from $1,950 2018-02-23
Wireshark HIGH 7.5
CVE-2018-7325

In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-rpki-rtr.c had an infinite loop that was addressed by validating a length fie…

Fix: after 2.4.4
Fix from $1,950 2018-02-23
Wireshark HIGH 7.5
CVE-2018-7326

In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-lltd.c had an infinite loop that was addressed by using a correct integer dat…

Fix: after 2.4.4
Fix from $1,950 2018-02-23
Wireshark HIGH 7.5
CVE-2018-7327

In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-openflow_v6.c had an infinite loop that was addressed by validating property …

Fix: after 2.4.4
Fix from $1,950 2018-02-23
Wireshark HIGH 7.5
CVE-2018-7328

In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-usb.c had an infinite loop that was addressed by rejecting short frame header…

Fix: after 2.4.4
Fix from $1,950 2018-02-23
Wireshark HIGH 7.5
CVE-2018-7329

In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-s7comm.c had an infinite loop that was addressed by correcting off-by-one err…

Fix: after 2.4.4
Fix from $1,950 2018-02-23
Ubuntu Linux HIGH 7.5
CVE-2018-5381EPSS 30%

The Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bug in its parsing of "Capabilities" in BGP OPEN messages, in the bgp_packet.c:bgp_capabili…

Fix: 2.13.0+
Fix from $1,950 2018-02-19
Xpdf MEDIUM 5.5
CVE-2018-7174

An issue was discovered in xpdf 4.00. An infinite loop in XRef::Xref allows an attacker to cause denial of service because loop detection exists only…

Mitigation only
Fix from $1,600 2018-02-15
Jboss Enterprise Application Platform HIGH 7.5
CVE-2018-1041EPSS 16%

A vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting versions 3.3.10, reads from an empty buffer. An attacker coul…

No fix yet
Fix from $1,950 2018-02-15
Qpdf MEDIUM 5.5
CVE-2017-18183

An issue was discovered in QPDF before 7.0.0. There is an infinite loop in the QPDFWriter::enqueueObject() function in libqpdf/QPDFWriter.cc.

Fix: 7.0.0+
Fix from $1,600 2018-02-13
Qpdf MEDIUM 5.5
CVE-2017-18186

An issue was discovered in QPDF before 7.0.0. There is an infinite loop due to looping xref tables in QPDF.cc.

Fix: 7.0.0+
Fix from $1,600 2018-02-13
Ccn Lite HIGH 7.8
CVE-2017-12412

ccn-lite-ccnb2xml in CCN-lite before 2.0.0 allows context-dependent attackers to have unspecified impact via a crafted file, which triggers infinite …

Fix: 2.0.0+
Fix from $1,950 2018-02-07
Poi HIGH 7.5
CVE-2017-12626EPSS 10%

Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks: 1) Infinite Loops while parsing crafted WMF, EMF, MSG and m…

Fix: 3.17+
Fix from $1,950 2018-01-29
Ubuntu Linux HIGH 7.5
CVE-2018-6196

w3m through 0.5.3 is prone to an infinite recursion flaw in HTMLlineproc0 because the feed_table_block_tag function in table.c does not prevent a neg…

Fix: after 0.5.3
Fix from $1,950 2018-01-25
Debian Linux MEDIUM 5.5
CVE-2018-5786

In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the get_fileinfo function (lrzip.c). Remote attackers could le…

Patch available
Fix from $1,600 2018-01-19
PHP MEDIUM 5.5
CVE-2018-5711EPSS 13%

gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1, h…

Fix: after 7.1.12
Fix from $1,600 2018-01-16
Debian Linux MEDIUM 6.5
CVE-2018-5685

In GraphicsMagick 1.3.27, there is an infinite loop and application hang in the ReadBMPImage function (coders/bmp.c). Remote attackers could leverage…

Patch available
Fix from $1,600 2018-01-14
Debian Linux MEDIUM 5.5
CVE-2018-5686

In MuPDF 1.12.0, there is an infinite loop vulnerability and application hang in the pdf_parse_array function (pdf/pdf-parse.c) because EOF is not co…

No fix yet
Fix from $1,600 2018-01-14
Android HIGH 7.5
CVE-2017-13195

In the ihevcd_parse_sps function of ihevcd_parse_headers.c, several parameter values could be negative which could lead to negative indexes which cou…

Patch available
Fix from $1,950 2018-01-12
Android HIGH 7.5
CVE-2017-13191

In the ihevcd_decode function of ihevcd_decode.c, there is an infinite loop due to an incomplete frame error. This could lead to a remote denial of s…

Patch available
Fix from $1,950 2018-01-12
Android HIGH 7.5
CVE-2017-13192

In the ihevcd_parse_slice_header function of ihevcd_parse_slice_header.c a slice address of zero after the first slice could result in an infinite lo…

Patch available
Fix from $1,950 2018-01-12
Android HIGH 7.5
CVE-2017-13193

In ihevcd_decode.c there is a possible infinite loop due to bytes for an sps of unsupported resolution resulting in the same sps being fed in over an…

Patch available
Fix from $1,950 2018-01-12
Long Range Zip MEDIUM 5.5
CVE-2018-5650

In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the unzip_match function in runzip.c. Remote attackers could l…

No fix yet
Fix from $1,600 2018-01-12