Vulnerability index

Browse CVEs

870 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Infinite LoopCWE-835 × clear
HIGH 7.5 CVE-2021-38387 In Contiki 3.0, a Telnet server that silently quits (before disconnection with clients) leads to connected clients entering an infinite loop and wait… Contiki Mitigation only Fix from $1,9502021-08-10 HIGH 7.5 CVE-2021-38311 In Contiki 3.0, potential nonterminating acknowledgment loops exist in the Telnet service. When the negotiated options are already disabled, servers … Contiki Patch available Fix from $1,9502021-08-09 MEDIUM 5.5 CVE-2021-37621 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found… Fedora after 0.27.4 Fix from $1,6002021-08-09 MEDIUM 5.5 CVE-2021-37622 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found… Fedora after 0.27.4 Fix from $1,6002021-08-09 MEDIUM 5.5 CVE-2021-34334 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop is trigge… Fedora after 0.27.4 Fix from $1,6002021-08-09 MEDIUM 5.5 CVE-2021-37623 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found… Fedora after 0.27.4 Fix from $1,6002021-08-09 MEDIUM 5.5 CVE-2021-3679 A lack of CPU resource in the Linux kernel tracing module functionality in versions prior to 5.14-rc3 was found in the way user uses trace ring buffe… Linux Kernel 5.14+ Fix from $1,6002021-08-05 HIGH 7.5 CVE-2021-22235 Crash in DNP dissector in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 allows denial of service via packet injection or crafted capture file Wireshark 3.2.15 / 3.4.7+ Fix from $1,9502021-07-20 MEDIUM 5.5 CVE-2021-34332 A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The BMP_Loader.dll library in a… Jt2go 13.2.0+ Fix from $1,6002021-07-13 HIGH 7.5 CVE-2021-35515EPSS 12% When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This cou… Commons Compress after 18.3 Fix from $1,9502021-07-13 HIGH 7.5 CVE-2021-36125 An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. The Special:GlobalRenameRequest page is vulnerable to infinite loops … Mediawiki after 1.36 Fix from $1,9502021-07-02 HIGH 7.5 CVE-2021-21279 Contiki-NG is an open-source, cross-platform operating system for internet of things devices. In verions prior to 4.6, an attacker can perform a deni… Contiki Ng 4.6+ Fix from $1,9502021-06-18 HIGH 7.5 CVE-2021-30468EPSS 7% A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thr… Cxf 3.3.11 / 3.4.4+ Fix from $1,9502021-06-16 MEDIUM 5.5 CVE-2021-31812 In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 a… Pdfbox after 2.0.23 Fix from $1,6002021-06-12 HIGH 7.5 CVE-2021-22222 Infinite loop in DVB-S2-BB dissector in Wireshark 3.4.0 to 3.4.5 allows denial of service via packet injection or crafted capture file Wireshark after 3.4.5 Fix from $1,9502021-06-07 HIGH 7.5 CVE-2021-28676 An issue was discovered in Pillow before 8.2.0. For FLI data, FliDecode did not properly check that the block advance was non-zero, potentially leadi… Pillow 8.2.0+ Fix from $1,9502021-06-02 MEDIUM 5.5 CVE-2021-3468 A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is no… Debian Linux after 0.8 Fix from $1,6002021-06-02 HIGH 7.5 CVE-2021-33194EPSS 7% golang.org/x/net before v0.0.0-20210520170846-37e1c6afe023 allows attackers to cause a denial of service (infinite loop) via crafted ParseFragment in… Go after 1.16.4 Fix from $1,9502021-05-26 MEDIUM 5.5 CVE-2020-13602 Remote Denial of Service in LwM2M do_write_op_tlv. Zephyr versions >= 1.14.2, >= 2.2.0 contain Improper Input Validation (CWE-20), Loop with Unreacha… Zephyr after 2.2.0 Fix from $1,6002021-05-25 HIGH 7.8 CVE-2021-29591 TensorFlow is an end-to-end open source platform for machine learning. TFlite graphs must not have loops between nodes. However, this condition was n… Tensorflow 2.1.4 / 2.2.3+ Fix from $1,9502021-05-14 HIGH 7.5 CVE-2021-29510 Pydantic is a data validation and settings management using Python type hinting. In affected versions passing either `'infinity'`, `'inf'` or `float(… Fedora 1.6.2 / 1.7.4+ Fix from $1,9502021-05-13 HIGH 7.5 CVE-2021-27385 A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIM… Simatic Wincc Runtime Advanced 15.1 / 16+ Fix from $1,9502021-05-12 HIGH 7.5 CVE-2021-23009 On BIG-IP version 16.0.x before 16.0.1.1 and 15.1.x before 15.1.3, malformed HTTP/2 requests may cause an infinite loop which causes a Denial of Serv… Big Ip Access Policy Manager 15.1.3 / 16.0.1.1+ Fix from $1,9502021-05-10 HIGH 7.5 CVE-2021-29486 cumulative-distribution-function is an open source npm library used which calculates statistical cumulative distribution function from data array of … Cumulative Distribution Function 2.0.0+ Fix from $1,9502021-04-30 HIGH 7.5 CVE-2021-29482 xz is a compression and decompression library focusing on the xz format completely written in Go. The function readUvarint used to read the xz contai… Xz 0.5.8+ Fix from $1,9502021-04-28 MEDIUM 5.5 CVE-2021-3508 A flaw was found in PDFResurrect in version 0.22b. There is an infinite loop in get_xref_linear_skipped() in pdf.c via a crafted PDF file. Pdfresurrect Patch available Fix from $1,6002021-04-28 HIGH 7.5 CVE-2019-25040 Unbound before 1.9.5 allows an infinite loop via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Althoug… Debian Linux 1.9.5+ Fix from $1,9502021-04-27 HIGH 7.5 CVE-2021-25663 A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303),… Capital Vstar 4.1.0 / 2017.02.4+ Fix from $1,9502021-04-22 HIGH 7.5 CVE-2021-25664 A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303),… Capital Vstar 4.1.0 / 2017.02.4+ Fix from $1,9502021-04-22 MEDIUM 5.3 CVE-2021-0273 An always-incorrect control flow implementation in the implicit filter terms of Juniper Networks Junos OS and Junos OS Evolved on ACX5800, EX9200 Ser… Junos Mitigation only Fix from $1,6002021-04-22