Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2019-18796
The BASS Audio Library 2.4.14 under Windows is prone to a BASS_StreamCreateFile Denial of Service vulnerability (infinite loop) via a crafted .mp3 fi…
Bass
after 2.4.14.1
HIGH 7.5
CVE-2020-26575
In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector could enter an infinite loop. This was addressed in epan/dissectors/pac…
Wireshark
after 3.2.7
HIGH 7.5
CVE-2020-15598
Trustwave ModSecurity 3.x through 3.0.4 allows denial of service via a special request. NOTE: The discoverer reports "Trustwave has signaled they are…
Debian Linux
after 3.0.4
MEDIUM 5.5
CVE-2020-25641
A flaw was found in the Linux kernel's implementation of biovecs in versions before 5.9-rc7. A zero-length biovec request issued by the block subsyst…
Linux Kernel
after 5.8.13
MEDIUM 5.3
CVE-2020-25625
hw/usb/hcd-ohci.c in QEMU 5.0.0 has an infinite loop when a TD list has a loop.
Debian Linux
Patch available
HIGH 7.5
CVE-2020-25574
An issue was discovered in the http crate before 0.1.20 for Rust. An integer overflow in HeaderMap::reserve() could result in denial of service (e.g.…
Http
0.1.20+
HIGH 7.5
CVE-2020-12457
An issue was discovered in wolfSSL before 4.5.0. It mishandles the change_cipher_spec (CCS) message processing logic for TLS 1.3. If an attacker send…
Wolfssl
4.5.0+
HIGH 7.5
CVE-2019-19643
ise smart connect KNX Vaillant 1.2.839 contain a Denial of Service.
Smart Connect Knx Vaillant
No fix yet
MEDIUM 5.5
CVE-2020-0247
In Threshold::getHistogram of ImageProcessHelper.java, there is a possible crash loop due to an uncaught exception. This could lead to local denial o…
Android
Mitigation only
MEDIUM 6.5
CVE-2020-15654
When in an endless loop, a website specifying a custom cursor using CSS could make it look like the user is interacting with the user interface, when…
Firefox
78.1 / 79.0+
HIGH 7.5
CVE-2020-16845
Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary via invalid inputs.
Go
1.13.15 / 1.14.7+
HIGH 7.5
CVE-2020-5761
Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to CPU exhaustion due to an infinite loop in the TR-069 service. Unauthent…
Ht801 Firmware
after 1.0.17.5
MEDIUM 6.5
CVE-2019-20911
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to denial of service in bit_calc_CRC in bits.c, related to a for loop.
Libredwg
after 0.9.3
HIGH 7.5
CVE-2020-13935EPSS 87%
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and …
Tomcat
after 9.0.36
HIGH 7.5
CVE-2019-20907EPSS 6%
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, becaus…
Python
3.5.10 / 3.6.12+
HIGH 7.5
CVE-2020-15466
In Wireshark 3.2.0 to 3.2.4, the GVCP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-gvcp.c by ensuring that …
Wireshark
after 3.2.4
HIGH 7.5
CVE-2019-19506
Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a denial of service, caused by an error in the "homeplugd" process. By sending a special…
Pa6 Firmware
No fix yet
HIGH 7.5
CVE-2020-14447
An issue was discovered in Mattermost Server before 5.23.0. Large webhook requests allow attackers to cause a denial of service (infinite loop), aka …
Mattermost Server
5.23.0+
HIGH 7.5
CVE-2020-14448
An issue was discovered in Mattermost Server before 5.23.0. Automatic direct message replies allow attackers to cause a denial of service (infinite l…
Mattermost Server
5.23.0+
HIGH 7.5
CVE-2020-12885
An infinite loop was discovered in the CoAP library in Arm Mbed OS 5.15.3. The CoAP parser is responsible for parsing received CoAP packets. The func…
Mbed Os
Patch available
HIGH 7.5
CVE-2020-14040
The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causi…
Text
0.3.3+
HIGH 7.5
CVE-2020-14398
An issue was discovered in LibVNCServer before 0.9.13. An improperly closed TCP connection causes an infinite loop in libvncclient/sockets.c.
Ubuntu Linux
3.2.1.0+
MEDIUM 6.5
CVE-2020-0184
In ihevcd_ref_list() of ihevcd_ref_list.c, there is a possible infinite loop due to a missing bounds check. This could lead to remote denial of servi…
Android
Patch available
MEDIUM 6.5
CVE-2020-0189
In ihevcd_decode() of ihevcd_decode.c, there is possible resource exhaustion due to an infinite loop. This could lead to remote denial of service wit…
Android
Patch available
MEDIUM 6.5
CVE-2020-0171
In Parse_lart of eas_mdls.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no…
Android
Patch available
MEDIUM 6.5
CVE-2020-0172
In Parse_art of eas_mdls.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no …
Android
Patch available
MEDIUM 6.5
CVE-2020-0174
In Parse_ptbl of eas_mdls.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no…
Android
Patch available
MEDIUM 6.5
CVE-2020-0169
In RTTTL_Event of eas_rtttl.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with …
Android
Patch available
MEDIUM 6.5
CVE-2020-0170
In IMY_Event of eas_imelody.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with …
Android
Patch available
HIGH 7.5
CVE-2020-13807
An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has circular reference mishandling that causes a loop.
Phantompdf
9.7.2+