Vulnerability index

Browse CVEs

870 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Infinite LoopCWE-835 × clear
Wireshark HIGH 7.5
CVE-2017-9349

In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DICOM dissector has an infinite loop. This was addressed in epan/dissectors/packet-dcm.c by vali…

Fix: after 2.2.6
Fix from $1,950 2017-06-02
Wireshark HIGH 7.5
CVE-2017-9352

In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the Bazaar dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-bz…

Fix: after 2.2.6
Fix from $1,950 2017-06-02
Asterisk HIGH 7.5
CVE-2017-9358

A memory exhaustion vulnerability exists in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1 and Certified Asterisk 13.13 before 13.13…

Mitigation only
Fix from $1,950 2017-06-02
Ubuntu Linux MEDIUM 5.5
CVE-2017-9208

libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, r…

Patch available
Fix from $1,600 2017-05-23
Ubuntu Linux MEDIUM 5.5
CVE-2017-9209

libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, r…

Patch available
Fix from $1,600 2017-05-23
Ubuntu Linux MEDIUM 5.5
CVE-2017-9210

libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, r…

Mitigation only
Fix from $1,600 2017-05-23
Imageworsener MEDIUM 6.5
CVE-2017-9093

The my_skip_input_data_fn function in imagew-jpeg.c in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service…

Fix: after 1.3.0
Fix from $1,600 2017-05-19
Imageworsener MEDIUM 6.5
CVE-2017-9094

The lzw_add_to_dict function in imagew-gif.c in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (infin…

Fix: after 1.3.0
Fix from $1,600 2017-05-19
Debian Linux MEDIUM 6.5
CVE-2017-8112

hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (infinite loop and CPU consumpt…

Fix: after 2.9.1
Fix from $1,600 2017-05-02
Podofo MEDIUM 5.5
CVE-2017-8054

The function PdfPagesTree::GetPageNodeFromArray in PdfPageTree.cpp:464 in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (infinite…

No fix yet
Fix from $1,600 2017-04-22
Podofo MEDIUM 5.5
CVE-2017-8053

PoDoFo 0.9.5 allows denial of service (infinite recursion and stack consumption) via a crafted PDF file in PoDoFo::PdfParser::ReadDocumentStructure (…

No fix yet
Fix from $1,600 2017-04-22
Jboss Data Grid HIGH 7.5
CVE-2016-4970EPSS 11%

handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (…

Fix: 4.0.37 / 4.1.1+
Fix from $1,950 2017-04-13
Wireshark MEDIUM 6.5
CVE-2017-7700

In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the NetScaler file parser could go into an infinite loop, triggered by a malformed capture file. Thi…

Fix: after 2.2.5
Fix from $1,600 2017-04-12
Wireshark HIGH 7.5
CVE-2017-7701

In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the BGP dissector could go into an infinite loop, triggered by packet injection or a malformed captu…

Patch available
Fix from $1,950 2017-04-12
Wireshark HIGH 7.5
CVE-2017-7702

In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the WBXML dissector could go into an infinite loop, triggered by packet injection or a malformed cap…

Patch available
Fix from $1,950 2017-04-12
Wireshark HIGH 7.5
CVE-2017-7704

In Wireshark 2.2.0 to 2.2.5, the DOF dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was ad…

Patch available
Fix from $1,950 2017-04-12
Wireshark HIGH 7.5
CVE-2017-7705

In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the RPC over RDMA dissector could go into an infinite loop, triggered by packet injection or a malfo…

Patch available
Fix from $1,950 2017-04-12
Wireshark HIGH 7.5
CVE-2017-7745

In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the SIGCOMP dissector could go into an infinite loop, triggered by packet injection or a malformed c…

Patch available
Fix from $1,950 2017-04-12
Wireshark HIGH 7.5
CVE-2017-7746

In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the SLSK dissector could go into an infinite loop, triggered by packet injection or a malformed capt…

Patch available
Fix from $1,950 2017-04-12
Wireshark HIGH 7.5
CVE-2017-7748

In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the WSP dissector could go into an infinite loop, triggered by packet injection or a malformed captu…

Patch available
Fix from $1,950 2017-04-12
Linux Kernel HIGH 7.5
CVE-2017-7618

crypto/ahash.c in the Linux kernel through 4.10.9 allows attackers to cause a denial of service (API operation calling its own callback, and infinite…

Fix: 3.16.44 / 3.18.50+
Fix from $1,950 2017-04-10
Imagemagick HIGH 7.5
CVE-2017-7619

In ImageMagick 7.0.4-9, an infinite loop can occur because of a floating-point rounding error in some of the color algorithms. This affects ModulateH…

Patch available
Fix from $1,950 2017-04-10
Collectd HIGH 7.5
CVE-2017-7401

Incorrect interaction of the parse_packet() and parse_part_sign_sha256() functions in network.c in collectd 5.7.1 and earlier allows remote attackers…

Fix: after 5.7.1
Fix from $1,950 2017-04-03
Iphone Os MEDIUM 5.5
CVE-2017-2417

An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watch…

Fix: after 10.12.3
Fix from $1,600 2017-04-02
Debian Linux MEDIUM 5.5
CVE-2017-5973

The xhci_kick_epctx function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (i…

Fix: after 2.8.1.1
Fix from $1,600 2017-03-27
Debian Linux MEDIUM 5.5
CVE-2017-5987

The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows local OS guest privileged users to cause a denial …

Fix: after 2.8.1.1
Fix from $1,600 2017-03-20
Qemu MEDIUM 6.5
CVE-2017-6505

The ohci_service_ed_list function in hw/usb/hcd-ohci.c in QEMU (aka Quick Emulator) before 2.9.0 allows local guest OS users to cause a denial of ser…

Fix: after 2.8.1.1
Fix from $1,600 2017-03-15
Fedora MEDIUM 5.5
CVE-2017-6314

The make_available_at_least function in io-tiff.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (infinite loop) via a…

Fix: 2.36.12+
Fix from $1,600 2017-03-10
Wireshark HIGH 7.5
CVE-2017-6467

In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a Netscaler file parser infinite loop, triggered by a malformed capture file. This was addr…

Fix: after 2.2.4
Fix from $1,950 2017-03-04
Wireshark HIGH 7.5
CVE-2017-6470

In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an IAX2 infinite loop, triggered by packet injection or a malformed capture file. This was …

Fix: after 2.2.4
Fix from $1,950 2017-03-04