Vulnerability index

Browse CVEs

870 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Infinite LoopCWE-835 × clear
Tomcat HIGH 7.5
CVE-2016-6817EPSS 7%

The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header was received that was larger …

Mitigation only
Fix from $1,950 2017-08-10
Debian Linux MEDIUM 6.5
CVE-2015-7850

ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to cause a denial of service (infinite loop or crash) by …

Fix: 4.2.8 / 4.3.77+
Fix from $1,600 2017-08-07
Openexif MEDIUM 5.5
CVE-2017-11118

The ExifImageFile::readImage function in ExifImageFileRead.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (infinite loop …

Mitigation only
Fix from $1,600 2017-07-31
Soundtouch MEDIUM 5.5
CVE-2017-9258

The TDStretch::processSamples function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote attackers to cause a denial of service (i…

No fix yet
Fix from $1,600 2017-07-27
Qpdf MEDIUM 5.5
CVE-2017-11624

A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related…

No fix yet
Fix from $1,600 2017-07-25
Qpdf MEDIUM 5.5
CVE-2017-11625

A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related…

No fix yet
Fix from $1,600 2017-07-25
Qpdf MEDIUM 5.5
CVE-2017-11626

A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related…

No fix yet
Fix from $1,600 2017-07-25
Qpdf MEDIUM 5.5
CVE-2017-11627

A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related…

No fix yet
Fix from $1,600 2017-07-25
Python HIGH 7.5
CVE-2017-9233EPSS 9%

XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop usi…

Fix: 2.7.15 / 3.3.7+
Fix from $1,950 2017-07-25
Imagemagick MEDIUM 6.5
CVE-2017-11523

The ReadTXTImage function in coders/txt.c in ImageMagick through 6.9.9-0 and 7.x through 7.0.6-1 allows remote attackers to cause a denial of service…

Fix: after 6.9.9-0
Fix from $1,600 2017-07-22
Linux Kernel MEDIUM 5.5
CVE-2017-7542

The ip6_find_1stfragopt function in net/ipv6/output_core.c in the Linux kernel through 4.12.3 allows local users to cause a denial of service (intege…

Fix: after 4.12.3
Fix from $1,600 2017-07-21
Imagemagick MEDIUM 6.5
CVE-2017-11478

The ReadOneDJVUImage function in coders/djvu.c in ImageMagick through 6.9.9-0 and 7.x through 7.0.6-1 allows remote attackers to cause a denial of se…

Fix: after 6.9.9-0
Fix from $1,600 2017-07-20
Imagemagick MEDIUM 6.5
CVE-2017-11446

The ReadPESImage function in coders\pes.c in ImageMagick 7.0.6-1 has an infinite loop vulnerability that can cause CPU exhaustion via a crafted PES f…

Patch available
Fix from $1,600 2017-07-19
Wireshark HIGH 7.5
CVE-2017-11406

In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the DOCSIS dissector could go into an infinite loop. This was addressed in plugins/docsis/packet-doc…

Fix: after 2.2.7
Fix from $1,950 2017-07-18
Wireshark HIGH 7.5
CVE-2017-11410

In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the WBXML dissector could go into an infinite loop, triggered by packet injection or a malformed…

Patch available
Fix from $1,950 2017-07-18
Freeradius HIGH 7.5
CVE-2017-10985

An FR-GV-302 issue in FreeRADIUS 3.x before 3.0.15 allows "Infinite loop and memory exhaustion with 'concat' attributes" and a denial of service.

Patch available
Fix from $1,950 2017-07-17
Freeradius HIGH 7.5
CVE-2017-10986

An FR-GV-303 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Infinite read in dhcp_attr2vp()" and a denial of service.

Patch available
Fix from $1,950 2017-07-17
Exiv2 MEDIUM 6.5
CVE-2017-11338

There is an infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp in Exiv2 0.26. A crafted input will lead to a remote denial of…

Mitigation only
Fix from $1,600 2017-07-17
Gnome Session MEDIUM 5.5
CVE-2017-11171

Bad reference counting in the context of accept_ice_connection() in gsm-xsmp-server.c in old versions of gnome-session up until version 2.29.92 allow…

Fix: after 2.29.92
Fix from $1,600 2017-07-11
Android MEDIUM 5.5
CVE-2017-0685

A denial of service vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34203195.

No fix yet
Fix from $1,600 2017-07-06
Freeware Advanced Audio Decoder 2 MEDIUM 5.5
CVE-2017-9222

The mp4ff_parse_tag function in common/mp4ff/mp4meta.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of …

Mitigation only
Fix from $1,600 2017-06-27
Debian Linux MEDIUM 5.5
CVE-2017-9375

QEMU (aka Quick Emulator), when built with USB xHCI controller emulator support, allows local guest OS privileged users to cause a denial of service …

Fix: after 2.8.1.1
Fix from $1,600 2017-06-16
Libcroco MEDIUM 6.5
CVE-2017-8871EPSS 13%

The cr_parser_parse_selector_core function in cr-parser.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (infinite loop and …

No fix yet
Fix from $1,600 2017-06-12
Libquicktime MEDIUM 6.5
CVE-2017-9122EPSS 6%

The quicktime_read_moov function in moov.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (infinite loop and CPU consumpt…

No fix yet
Fix from $1,600 2017-06-12
Strongswan HIGH 7.5
CVE-2017-9023

The ASN.1 parser in strongSwan before 5.5.3 improperly handles CHOICE types when the x509 plugin is enabled, which allows remote attackers to cause a…

Fix: after 5.5.2
Fix from $1,950 2017-06-08
Debian Linux MEDIUM 5.6
CVE-2017-9310

QEMU (aka Quick Emulator), when built with the e1000e NIC emulation support, allows local guest OS privileged users to cause a denial of service (inf…

Fix: after 2.8.1.1
Fix from $1,600 2017-06-08
Debian Linux MEDIUM 5.6
CVE-2017-9330

QEMU (aka Quick Emulator) before 2.9.0, when built with the USB OHCI Emulation support, allows local guest OS users to cause a denial of service (inf…

Fix: after 2.8.1.1
Fix from $1,600 2017-06-08
Enterprise Linux Desktop MEDIUM 6.5
CVE-2017-9461

smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulnerability (fd_open_atomic infinite loop with high CPU usage and memory…

Fix: after 4.4.9
Fix from $1,600 2017-06-06
Wireshark HIGH 7.5
CVE-2017-9345

In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DNS dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-dns.c…

Fix: after 2.2.6
Fix from $1,950 2017-06-02
Wireshark HIGH 7.5
CVE-2017-9346

In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the SoulSeek dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-…

Fix: after 2.2.6
Fix from $1,950 2017-06-02