Vulnerability index

Browse CVEs

870 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Infinite LoopCWE-835 × clear
HIGH 7.5 CVE-2019-3833EPSS 15% Openwsman, versions up to and including 2.6.9, are vulnerable to infinite loop in process_connection() when parsing specially crafted HTTP requests. … Fedora after 2.6.9 Fix from $1,9502019-03-14 HIGH 7.5 CVE-2019-9747 In tinysvcmdns through 2018-01-16, a maliciously crafted mDNS (Multicast DNS) packet triggers an infinite loop while parsing an mDNS query. When mDNS… Tinysvcmdns after 2018-01-16 Fix from $1,9502019-03-13 MEDIUM 5.9 CVE-2019-6594 On BIG-IP 11.5.1-11.6.3.2, 12.1.3.4-12.1.3.7, 13.0.0 HF1-13.1.1.1, and 14.0.0-14.0.0.2, Multi-Path TCP (MPTCP) does not protect against multiple zero… Big Ip Access Policy Manager after 14.0.0.2 Fix from $1,6002019-02-26 CRITICAL 9.8 CVE-2018-20784 In the Linux kernel before 4.20.2, kernel/sched/fair.c mishandles leaf cfs_rq's, which allows attackers to cause a denial of service (infinite loop i… Linux Kernel 4.14.93 / 4.19.15+ Fix from $2,3002019-02-22 MEDIUM 5.5 CVE-2018-6687 Loop with Unreachable Exit Condition ('Infinite Loop') in McAfee GetSusp (GetSusp) 3.0.0.461 and earlier allows attackers to DoS a manual GetSusp sca… Getsusp after 3.0.0.461 Fix from $1,6002019-02-21 HIGH 7.5 CVE-2018-5818 An error within the "parse_rollei()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can be exploited to trigger an infin… Debian Linux 0.19.1+ Fix from $1,9502019-02-20 MEDIUM 6.5 CVE-2019-1000020 libarchive version commit 5a98dcf8a86364b3c2c469c85b93647dfb139961 onwards (version v2.8.0 onwards) contains a CWE-835: Loop with Unreachable Exit Co… Ubuntu Linux 3.4.0+ Fix from $1,6002019-02-04 HIGH 7.5 CVE-2017-18361 In Pylons Colander through 1.6, the URL validator allows an attacker to potentially cause an infinite loop thereby causing a denial of service via an… Colander after 1.6 Fix from $1,9502019-02-01 MEDIUM 6.5 CVE-2019-6462 An issue was discovered in cairo 1.16.0. There is an infinite loop in the function _arc_error_normalized in the file cairo-arc.c, related to _arc_max… Cairo Mitigation only Fix from $1,6002019-01-16 MEDIUM 5.5 CVE-2019-3573 In libsixel v1.8.2, there is an infinite loop in the function sixel_decode_raw_impl() in the file fromsixel.c, as demonstrated by sixel2png. Libsixel No fix yet Fix from $1,6002019-01-02 HIGH 7.5 CVE-2018-20578 An issue was discovered in NuttX before 7.27. The function netlib_parsehttpurl() in apps/netutils/netlib/netlib_parsehttpurl.c mishandles URLs longer… Nuttx 7.27+ Fix from $1,9502018-12-28 MEDIUM 6.5 CVE-2018-20467 In coders/bmp.c in ImageMagick before 7.0.8-16, an input file can result in an infinite loop and hang, with high CPU and memory consumption. Remote a… Debian Linux 6.9.10-16 / 7.0.8-16+ Fix from $1,6002018-12-26 MEDIUM 6.5 CVE-2018-17197EPSS 6% A carefully crafted or corrupt sqlite file can cause an infinite loop in Apache Tika's SQLite3Parser in versions 1.8-1.19.1 of Apache Tika. Tika after 1.19.1 Fix from $1,6002018-12-24 MEDIUM 5.5 CVE-2018-20348 libpff_item_tree_create_node in libpff_item_tree.c in libpff before experimental-20180714 allows attackers to cause a denial of service (infinite rec… Libpff 20180714+ Fix from $1,6002018-12-22 HIGH 7.5 CVE-2018-20216 QEMU can have an infinite loop in hw/rdma/vmw/pvrdma_dev_ring.c because return values are not checked (and -1 is mishandled). Ubuntu Linux after 3.1.0 Fix from $1,9502018-12-20 HIGH 7.5 CVE-2018-20021 LibVNC before commit c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c contains a CWE-835: Infinite loop vulnerability in VNC client code. Vulnerability allow… Ubuntu Linux 0.9.12+ Fix from $1,9502018-12-19 HIGH 7.5 CVE-2018-20103EPSS 7% An issue was discovered in dns.c in HAProxy through 1.8.14. In the case of a compressed pointer, a crafted packet can trigger infinite recursion by m… Ubuntu Linux after 1.8.14 Fix from $1,9502018-12-12 MEDIUM 6.5 CVE-2018-20099 There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of serv… Exiv2 Patch available Fix from $1,6002018-12-12 MEDIUM 6.5 CVE-2018-1000864 A denial of service vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in CronTab.java that allows attackers with Overall/Rea… Jenkins after 2.153 Fix from $1,6002018-12-10 MEDIUM 6.5 CVE-2018-5813 An error within the "parse_minolta()" function (dcraw/dcraw.c) in LibRaw versions prior to 0.18.11 can be exploited to trigger an infinite loop via a… Ubuntu Linux 0.18.11+ Fix from $1,6002018-12-07 MEDIUM 6.5 CVE-2017-15835 In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, While processing the RIC Data Descriptor I… Android Patch available Fix from $1,6002018-12-07 MEDIUM 5.5 CVE-2018-19840 The function WavpackPackInit in pack_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (resource exhaust… Ubuntu Linux after 5.1.0 Fix from $1,6002018-12-04 MEDIUM 6.5 CVE-2018-19826 In inspect.cpp in LibSass 3.5.5, a high memory footprint caused by an endless loop (containing a Sass::Inspect::operator()(Sass::String_Quoted*) stac… Libsass Mitigation only Fix from $1,6002018-12-03 MEDIUM 5.5 CVE-2018-19777 In Artifex MuPDF 1.14.0, there is an infinite loop in the function svg_dev_end_tile in fitz/svg-device.c, as demonstrated by mutool. Debian Linux No fix yet Fix from $1,6002018-11-30 HIGH 7.5 CVE-2018-19622 In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the MMSE dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-mmse… Wireshark after 2.6.4 Fix from $1,9502018-11-29 MEDIUM 6.5 CVE-2018-14629EPSS 5% A denial of service vulnerability was discovered in Samba's LDAP server before versions 4.7.12, 4.8.7, and 4.9.3. A CNAME loop could lead to infinite… Ubuntu Linux 4.7.12 / 4.8.7+ Fix from $1,6002018-11-28 MEDIUM 6.5 CVE-2018-19108 In Exiv2 0.26, Exiv2::PsdImage::readMetadata in psdimage.cpp in the PSD image reader may suffer from a denial of service (infinite loop) caused by an… Debian Linux Patch available Fix from $1,6002018-11-08 MEDIUM 6.1 CVE-2018-16845EPSS 10% nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker… Nginx 13.0+ Fix from $1,6002018-11-07 MEDIUM 5.5 CVE-2018-9444 In ih264d_video_decode of ih264d_api.c there is a possible resource exhaustion due to an infinite loop. This could lead to remote temporary device de… Android Mitigation only Fix from $1,6002018-11-06 MEDIUM 6.5 CVE-2018-18915 There is an infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp in Exiv2 0.27-RC1. A crafted input will lead to a remote denia… Exiv2 Patch available Fix from $1,6002018-11-03