Vulnerability index

Browse CVEs

870 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Infinite LoopCWE-835 × clear
Bento4 HIGH 7.8
CVE-2018-5253

The AP4_FtypAtom class in Core/Ap4FtypAtom.cpp in Bento4 1.5.1.0 has an Infinite loop via a crafted MP4 file that triggers size mishandling.

No fix yet
Fix from $1,950 2018-01-05
Ubuntu Linux MEDIUM 6.5
CVE-2017-17681

In ImageMagick 7.0.7-12 Q16, an infinite loop vulnerability was found in the function ReadPSDChannelZip in coders/psd.c, which allows attackers to ca…

No fix yet
Fix from $1,600 2017-12-14
Xen MEDIUM 6.5
CVE-2017-17044

An issue was discovered in Xen through 4.9.x allowing HVM guest OS users to cause a denial of service (infinite loop and host OS hang) by leveraging …

Fix: after 4.9.1
Fix from $1,600 2017-11-28
Debian Linux HIGH 7.5
CVE-2017-16944EPSS 63%

The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinite loop an…

No fix yet
Fix from $1,950 2017-11-25
Libxml2 HIGH 7.5
CVE-2017-16932EPSS 6%

parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter entities.

Fix: after 2.9.4
Fix from $1,950 2017-11-23
Mongoose HIGH 7.5
CVE-2017-2909

An infinite loop programming error exists in the DNS server functionality of Cesanta Mongoose 6.8 library. A specially crafted DNS request can cause …

Mitigation only
Fix from $1,950 2017-11-07
Ubuntu Linux HIGH 7.5
CVE-2017-15908EPSS 24%

In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in the dns_pac…

Patch available
Fix from $1,950 2017-10-26
Serialize To Js HIGH 7.5
CVE-2017-15871

The deserialize function in serialize-to-js through 1.1.1 allows attackers to cause a denial of service via vectors involving an Immediately Invoked …

Fix: after 1.1.1
Fix from $1,950 2017-10-24
Mini Mail Server MEDIUM 5.3
CVE-2017-15223

Denial-of-service vulnerability in ArGoSoft Mini Mail Server 1.0.0.2 and earlier allows remote attackers to waste CPU resources (memory consumption) …

Fix: after 1.0.0.2
Fix from $1,600 2017-10-24
Libextractor HIGH 7.5
CVE-2017-15602

In GNU Libextractor 1.4, there is an integer signedness error for the chunk size in the EXTRACTOR_nsfe_extract_method function in plugins/nsfe_extrac…

No fix yet
Fix from $1,950 2017-10-18
Binutils MEDIUM 5.5
CVE-2017-15024

find_abstract_instance_name in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote …

Patch available
Fix from $1,600 2017-10-05
Poppler HIGH 7.5
CVE-2017-14929

In Poppler 0.59.0, memory corruption occurs in a call to Object::dictLookup() in Object.h after a repeating series of Gfx::display, Gfx::go, Gfx::exe…

Mitigation only
Fix from $1,950 2017-09-30
Binutils MEDIUM 5.5
CVE-2017-14932

decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers t…

Patch available
Fix from $1,600 2017-09-30
Binutils MEDIUM 5.5
CVE-2017-14933

read_formatted_entries in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attac…

Patch available
Fix from $1,600 2017-09-30
Binutils MEDIUM 5.5
CVE-2017-14934

process_debug_info in dwarf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers …

Patch available
Fix from $1,600 2017-09-30
Imagemagick MEDIUM 6.5
CVE-2017-14741

The ReadCAPTIONImage function in coders/caption.c in ImageMagick 7.0.7-3 allows remote attackers to cause a denial of service (infinite loop) via a c…

Patch available
Fix from $1,600 2017-09-26
Gpu Driver MEDIUM 5.5
CVE-2017-6267

NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer handler where an incorrect initialization of internal objects can cause a…

Mitigation only
Fix from $1,600 2017-09-22
Yadifa HIGH 7.5
CVE-2017-14339

The DNS packet parser in YADIFA before 2.2.6 does not check for the presence of infinite pointer loops, and thus it is possible to force it to enter …

Fix: after 2.2.5
Fix from $1,950 2017-09-20
Poppler HIGH 7.5
CVE-2017-14519

In Poppler 0.59.0, memory corruption occurs in a call to Object::streamGetChar in Object.h after a repeating series of Gfx::display, Gfx::go, Gfx::ex…

No fix yet
Fix from $1,950 2017-09-17
Tcpdump HIGH 7.5
CVE-2017-12989

The RESP parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-resp.c:resp_get_length().

Fix: after 4.9.1
Fix from $1,950 2017-09-14
Tcpdump CRITICAL 9.8
CVE-2017-12990

The ISAKMP parser in tcpdump before 4.9.2 could enter an infinite loop due to bugs in print-isakmp.c, several functions.

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Tcpdump CRITICAL 9.8
CVE-2017-12995

The DNS parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-domain.c:ns_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Tcpdump CRITICAL 9.8
CVE-2017-12997

The LLDP parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-lldp.c:lldp_private_8021_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Jasper HIGH 7.5
CVE-2017-14229

There is an infinite loop in the jpc_dec_tileinit function in jpc/jpc_dec.c of Jasper 2.0.13. It will lead to a remote denial of service attack.

Mitigation only
Fix from $1,950 2017-09-09
Ubuntu Linux MEDIUM 6.5
CVE-2017-14173

In the function ReadTXTImage() in coders/txt.c in ImageMagick 7.0.6-10, an integer overflow might occur for the addition operation "GetQuantumRange(d…

Patch available
Fix from $1,600 2017-09-07
Ffmpeg MEDIUM 6.5
CVE-2017-14058

In FFmpeg 2.4 and 3.3.3, the read_data function in libavformat/hls.c does not restrict reload attempts for an insufficient list, which allows remote …

Patch available
Fix from $1,600 2017-08-31
Wireshark HIGH 7.5
CVE-2017-13767

In Wireshark 2.4.0, 2.2.0 to 2.2.8, and 2.0.0 to 2.0.14, the MSDP dissector could go into an infinite loop. This was addressed in epan/dissectors/pac…

Patch available
Fix from $1,950 2017-08-30
Debian Linux MEDIUM 5.5
CVE-2017-13756

In The Sleuth Kit (TSK) 4.4.2, opening a crafted disk image triggers infinite recursion in dos_load_ext_table() in tsk/vs/dos.c in libtskvs.a, as dem…

Mitigation only
Fix from $1,600 2017-08-29
Ncurses HIGH 7.5
CVE-2017-13728

There is an infinite loop in the next_char function in comp_scan.c in ncurses 6.0, related to libtic. A crafted input will lead to a remote denial of…

No fix yet
Fix from $1,950 2017-08-29
Numpy HIGH 7.5
CVE-2017-12852

The numpy.pad function in Numpy 1.13.1 and older versions is missing input validation. An empty list or ndarray will stick into an infinite loop, whi…

Fix: after 1.13.1
Fix from $1,950 2017-08-15