Vulnerability index

Browse CVEs

869 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Infinite LoopCWE-835 × clear
HIGH 7.5 CVE-2022-34760 A CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability exists that could cause a denial of service of the webserver due to i… Opc Ua Module For M580 Firmware after 1.10 Fix from $1,9502022-07-13 HIGH 7.5 CVE-2022-32058 An infinite loop in the function httpRpmPass of TP-Link TL-WR741N/TL-WR742N V1/V2/V3_130415 allows attackers to cause a Denial of Service (DoS) via a… Tl Wr741n Firmware No fix yet Fix from $1,9502022-07-07 HIGH 7.5 CVE-2022-29862 An infinite loop in OPC UA .NET Standard Stack 1.04.368 allows a remote attackers to cause the application to hang via a crafted message. Ua .net Standard Stack 1.4.368.58+ Fix from $1,9502022-06-16 HIGH 7.5 CVE-2022-25851 The package jpeg-js before 0.4.4 are vulnerable to Denial of Service (DoS) where a particular piece of input will cause to enter an infinite loop and… Jpeg Js 0.4.4+ Fix from $1,9502022-06-10 MEDIUM 5.5 CVE-2021-40592 GPAC version before commit 71460d72ec07df766dab0a4d52687529f3efcf0a (version v1.0.1 onwards) contains loop with unreachable exit condition ('infinite… Gpac 1.0.1+ Fix from $1,6002022-06-08 HIGH 7.5 CVE-2022-27781 libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.Due to an er… Curl 7.83.1+ Fix from $1,9502022-06-02 HIGH 7.5 CVE-2022-29190 Pion DTLS is a Go implementation of Datagram Transport Layer Security. Prior to version 2.1.4, an attacker can send packets that sends Pion DTLS into… Dtls 2.1.4+ Fix from $1,9502022-05-21 MEDIUM 5.5 CVE-2022-29028 A vulnerability has been identified in JT2Go (All versions < V13.3.0.3), Teamcenter Visualization V13.3 (All versions < V13.3.0.3), Teamcenter Visual… Jt2go 13.3.0.3 / 14.0.0.1+ Fix from $1,6002022-05-20 HIGH 7.5 CVE-2022-24792 PJSIP is a free and open source multimedia communication library written in C. A denial-of-service vulnerability affects applications on a 32-bit sys… Debian Linux after 2.12 Fix from $1,9502022-04-25 MEDIUM 5.5 CVE-2022-24859 PyPDF2 is an open source python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF files. In versions prior to 1.… Debian Linux 1.27.5+ Fix from $1,6002022-04-18 HIGH 7.5 CVE-2022-21159 A denial of service vulnerability exists in the parseNormalModeParameters functionality of MZ Automation GmbH libiec61850 1.5.0. A specially-crafted … Libiec61850 Patch available Fix from $1,9502022-04-15 MEDIUM 5.5 CVE-2022-24191 In HTMLDOC 1.9.14, an infinite loop in the gif_read_lzw function can lead to a pointer arbitrarily pointing to heap memory and resulting in a buffer … Fedora 1.9.15+ Fix from $1,6002022-04-04 MEDIUM 5.5 CVE-2022-1222 Inf loop in GitHub repository gpac/gpac prior to 2.1.0-DEV. Gpac after 2.0 Fix from $1,6002022-04-04 HIGH 7.5 CVE-2022-24763 PJSIP is a free and open source multimedia communication library written in the C language. Versions 2.12 and prior contain a denial-of-service vulne… Debian Linux 2.13+ Fix from $1,9502022-03-30 HIGH 7.5 CVE-2022-23352 An issue in BigAnt Software BigAnt Server v5.6.06 can lead to a Denial of Service (DoS). Bigant Server No fix yet Fix from $1,9502022-03-21 MEDIUM 6.5 CVE-2021-20257 An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descriptors in process_tx_de… Fedora 6.2.0+ Fix from $1,6002022-03-16 HIGH 7.5 CVE-2022-0778EPSS 73% The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally t… OpenSSL 1.0.2zd / 1.1.1n+ Fix from $1,9502022-03-15 HIGH 7.5 CVE-2021-3737EPSS 12% A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP … Python 3.6.14 / 3.7.11+ Fix from $1,9502022-03-04 HIGH 7.5 CVE-2022-0711EPSS 17% A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted H… Openshift Container Platform 2.2.21 / 2.3.18+ Fix from $1,9502022-03-02 MEDIUM 6.5 CVE-2022-23641 Discourse is an open source discussion platform. In versions prior to 2.8.1 in the `stable` branch, 2.9.0.beta2 in the `beta` branch, and 2.9.0.beta2… Discourse 2.8.1+ Fix from $1,6002022-02-15 HIGH 7.5 CVE-2022-0586 Infinite loop in RTMPT protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted ca… Wireshark 3.4.12 / 3.6.2+ Fix from $1,9502022-02-14 HIGH 7.5 CVE-2022-23833EPSS 49% An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart … Django 2.2.27 / 3.2.12+ Fix from $1,9502022-02-03 HIGH 7.5 CVE-2022-23596 Junrar is an open source java RAR archive library. In affected versions A carefully crafted RAR archive can trigger an infinite loop while extracting… Junrar 7.4.1+ Fix from $1,9502022-02-01 HIGH 7.5 CVE-2022-23098 An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation has an infinite loop if no data is received. Debian Linux after 1.40 Fix from $1,9502022-01-28 HIGH 7.5 CVE-2022-23968 Xerox VersaLink devices on specific versions of firmware before 2022-01-26 allow remote attackers to brick the device via a crafted TIFF file in an u… Versalink Firmware after 50.61 Fix from $1,9502022-01-26 MEDIUM 6.5 CVE-2022-23437 There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the Xe… Xerces J 9.0+ Fix from $1,6002022-01-24 HIGH 7.5 CVE-2021-23567 The package colors after 1.4.0 are vulnerable to Denial of Service (DoS) that was introduced through an infinite loop in the americanFlag module. Unf… Colors.js Patch available Fix from $1,9502022-01-14 HIGH 7.5 CVE-2021-45445 Unisys ClearPath MCP TCP/IP Networking Services 59.1, 60.0, and 62.0 has an Infinite Loop. Clearpath Mcp Tcp\/ip Networking Services No fix yet Fix from $1,9502022-01-12 MEDIUM 6.5 CVE-2021-40111 In Apache James, while fuzzing with Jazzer the IMAP parsing stack, we discover that crafted APPEND and STATUS IMAP command could be used to trigger i… James 3.6.1+ Fix from $1,6002022-01-04 HIGH 7.5 CVE-2021-4182 Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file Wireshark 3.4.11+ Fix from $1,9502021-12-30