Vulnerability index

Browse CVEs

870 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Infinite LoopCWE-835 × clear
Wireshark HIGH 7.5
CVE-2017-6472

In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an RTMPT dissector infinite loop, triggered by packet injection or a malformed capture file…

Fix: after 2.2.4
Fix from $1,950 2017-03-04
Wireshark HIGH 7.5
CVE-2017-6474

In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a NetScaler file parser infinite loop, triggered by a malformed capture file. This was addr…

Fix: after 2.2.4
Fix from $1,950 2017-03-04
Podofo MEDIUM 5.5
CVE-2017-5852

The PoDoFo::PdfPage::GetInheritedKeyFromObject function in base/PdfVariant.cpp in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (…

Mitigation only
Fix from $1,600 2017-03-01
Imagemagick MEDIUM 5.5
CVE-2015-8900

The ReadHDRImage function in coders/hdr.c in ImageMagick 6.x and 7.x allows remote attackers to cause a denial of service (infinite loop) via a craft…

Fix: after 7.0.5-0
Fix from $1,600 2017-02-27
Imagemagick MEDIUM 6.5
CVE-2015-8901

ImageMagick 6.x before 6.9.0-5 Beta allows remote attackers to cause a denial of service (infinite loop) via a crafted MIFF file.

Fix: 6.9.0-5+
Fix from $1,600 2017-02-27
Imagemagick MEDIUM 6.5
CVE-2015-8902

The ReadBlobByte function in coders/pdb.c in ImageMagick 6.x before 6.9.0-5 Beta allows remote attackers to cause a denial of service (infinite loop)…

Fix: 6.9.0-5+
Fix from $1,600 2017-02-27
Imagemagick MEDIUM 6.5
CVE-2015-8903

The ReadVICARImage function in coders/vicar.c in ImageMagick 6.x before 6.9.0-5 Beta allows remote attackers to cause a denial of service (infinite l…

Fix: 6.9.0-5+
Fix from $1,600 2017-02-27
Debian Linux MEDIUM 5.5
CVE-2017-6299

An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "2 of 9. Infinite Loop / DoS in the TNEFFillMapi function in l…

Fix: after 1.9
Fix from $1,600 2017-02-24
Linux Kernel HIGH 7.5
CVE-2017-6214

The tcp_splice_read function in net/ipv4/tcp.c in the Linux kernel before 4.9.11 allows remote attackers to cause a denial of service (infinite loop …

Fix: after 4.9.10
Fix from $1,950 2017-02-23
Libdwarf HIGH 7.5
CVE-2016-5042

The dwarf_get_aranges_list function in libdwarf before 20160923 allows remote attackers to cause a denial of service (infinite loop and crash) via a …

Fix: 2016-09-23+
Fix from $1,950 2017-02-17
Wireshark HIGH 7.5
CVE-2017-6014

In Wireshark 2.2.4 and earlier, a crafted or malformed STANAG 4607 capture file will cause an infinite loop and memory exhaustion. If the packet size…

Fix: after 2.2.4
Fix from $1,950 2017-02-17
Wireshark HIGH 7.5
CVE-2017-5596

In Wireshark 2.2.0 to 2.2.3 and 2.0.0 to 2.0.9, the ASTERIX dissector could go into an infinite loop, triggered by packet injection or a malformed ca…

Patch available
Fix from $1,950 2017-01-25
Debian Linux MEDIUM 5.5
CVE-2016-1981

QEMU (aka Quick Emulator) built with the e1000 NIC emulation support is vulnerable to an infinite loop issue. It could occur while processing data vi…

Fix: after 2.5.1.1
Fix from $1,600 2016-12-29
Debian Linux MEDIUM 5.5
CVE-2016-9776

QEMU (aka Quick Emulator) built with the ColdFire Fast Ethernet Controller emulator support is vulnerable to an infinite loop issue. It could occur w…

Fix: after 2.7.1
Fix from $1,600 2016-12-29
Busybox HIGH 7.5
CVE-2016-6301EPSS 9%

The recv_and_process_client_pkt function in networking/ntpd.c in busybox allows remote attackers to cause a denial of service (CPU and bandwidth cons…

Fix: 1.25.1+
Fix from $1,950 2016-12-09
Debian Linux MEDIUM 6.0
CVE-2016-8910

The rtl8139_cplus_transmit function in hw/net/rtl8139.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of servic…

Fix: after 2.7.1
Fix from $1,600 2016-11-04
Debian Linux MEDIUM 6.0
CVE-2016-8909

The intel_hda_xfer function in hw/audio/intel-hda.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (i…

Fix: after 2.7.1
Fix from $1,600 2016-11-04
Debian Linux MEDIUM 5.5
CVE-2015-8558

The ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and CPU c…

Fix: after 2.5.1.1
Fix from $1,600 2016-05-23
Linux Kernel MEDIUM 6.2
CVE-2015-8785

The fuse_fill_write_pages function in fs/fuse/file.c in the Linux kernel before 4.4 allows local users to cause a denial of service (infinite loop) v…

Fix: 4.4+
Fix from $1,600 2016-02-08
Kepserverex HIGH 7.8
CVE-2013-2789

The Kepware DNP Master Driver for the KEPServerEX Communications Platform before 5.12.140.0 allows remote attackers to cause a denial of service (mas…

Fix: 5.12.140.0+
Fix from $1,950 2013-08-22
Debian Linux MEDIUM 5.5
CVE-2012-1186

Integer overflow in the SyncImageProfiles function in profile.c in ImageMagick 6.7.5-8 and earlier allows remote attackers to cause a denial of servi…

Fix: after 6.7.5-8
Fix from $1,600 2012-06-05
Debian Linux MEDIUM 5.5
CVE-2012-0248

ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted image whose IFD contains …

Patch available
Fix from $1,600 2012-06-05
Linux Kernel MEDIUM 5.5
CVE-2011-4621

The Linux kernel before 2.6.37 does not properly implement a certain clock-update optimization, which allows local users to cause a denial of service…

Fix: 2.6.37+
Fix from $1,600 2012-05-17
Wireshark HIGH 7.5
CVE-2011-1142

Stack consumption vulnerability in the dissect_ber_choice function in the BER dissector in Wireshark 1.2.x through 1.2.15 and 1.4.x through 1.4.4 mig…

Mitigation only
Fix from $1,950 2011-03-03
Fedora MEDIUM 5.0
CVE-2011-1002EPSS 29%

avahi-core/socket.c in avahi-daemon in Avahi before 0.6.29 allows remote attackers to cause a denial of service (infinite loop) via an empty mDNS (1)…

Fix: after 0.6.28
Fix from $1,600 2011-02-22
Debian Linux HIGH 7.8
CVE-2009-1270EPSS 5%

libclamav/untar.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (infinite loop) via a crafted TAR file that causes (1) c…

Fix: 0.95+
Fix from $1,950 2009-04-08
Asp.net MEDIUM 5.0
CVE-2005-2224EPSS 18%

aspnet_wp.exe in Microsoft ASP.NET web services allows remote attackers to cause a denial of service (CPU consumption from infinite loop) via a craft…

No fix yet
Fix from $1,600 2005-07-12
Filezilla Server MEDIUM 5.0
CVE-2005-0851

FileZilla FTP server before 0.9.6, when using MODE Z (zlib compression), allows remote attackers to cause a denial of service (infinite loop) via cer…

Fix: 0.9.6+
Fix from $1,600 2005-05-02
HTTP Server MEDIUM 5.0
CVE-2004-0748EPSS 25%

mod_ssl in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (CPU consumption) by aborting an SSL connection in a way th…

Fix: 2.0.51+
Fix from $1,600 2004-10-20
Gdkpixbuf MEDIUM 5.0
CVE-2004-0753EPSS 6%

The BMP image processor for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attackers to cause a denial of service (infinite loop)…

Fix: 2.2.4+
Fix from $1,600 2004-10-20