Vulnerability index

Browse CVEs

59 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Infinite LoopCWE-835 × clear
Dpkg HIGH 7.5
CVE-2026-2219

It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream whe…

Fix: 1.21.23 / 1.22.22+
Fix from $1,950 2026-03-07
Debian Linux HIGH 7.5
CVE-2023-45363EPSS 23%

An issue was discovered in ApiPageSet.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. It allows attac…

Fix: 1.35.12 / 1.39.5+
Fix from $1,950 2023-10-09
Debian Linux HIGH 7.5
CVE-2021-46828

In libtirpc before 1.3.3rc1, remote attackers could exhaust the file descriptors of a process that uses libtirpc because idle TCP connections are mis…

Fix: 1.3.3+
Fix from $1,950 2022-07-20
Debian Linux HIGH 7.5
CVE-2022-24792

PJSIP is a free and open source multimedia communication library written in C. A denial-of-service vulnerability affects applications on a 32-bit sys…

Fix: after 2.12
Fix from $1,950 2022-04-25
Debian Linux MEDIUM 5.5
CVE-2022-24859

PyPDF2 is an open source python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF files. In versions prior to 1.…

Fix: 1.27.5+
Fix from $1,600 2022-04-18
Debian Linux HIGH 7.5
CVE-2022-24763

PJSIP is a free and open source multimedia communication library written in the C language. Versions 2.12 and prior contain a denial-of-service vulne…

Fix: 2.13+
Fix from $1,950 2022-03-30
Debian Linux HIGH 7.5
CVE-2022-23098

An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation has an infinite loop if no data is received.

Fix: after 1.40
Fix from $1,950 2022-01-28
Debian Linux HIGH 7.5
CVE-2021-3908

OctoRPKI does not limit the depth of a certificate chain, allowing for a CA to create children in an ad-hoc fashion, thereby making tree traversal ne…

Fix: 1.3.0+
Fix from $1,950 2021-11-11
Debian Linux HIGH 7.5
CVE-2021-42260

TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxmlparser.cpp via the TIXML_UTF_LEAD_0 case. It can be triggered by a cr…

Fix: after 2.6.2
Fix from $1,950 2021-10-11
Debian Linux MEDIUM 6.3
CVE-2021-39140EPSS 6%

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to alloca…

Fix: 1.4.18+
Fix from $1,600 2021-08-23
Debian Linux MEDIUM 5.5
CVE-2021-3468

A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is no…

Fix: after 0.8
Fix from $1,600 2021-06-02
Debian Linux HIGH 7.5
CVE-2019-25040

Unbound before 1.9.5 allows an infinite loop via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Althoug…

Fix: 1.9.5+
Fix from $1,950 2021-04-27
Debian Linux MEDIUM 5.5
CVE-2021-20255

A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU. This issue occurs while processing…

Patch available
Fix from $1,600 2021-03-09
Debian Linux MEDIUM 5.5
CVE-2020-27618

The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input sequences in IBM1364, IBM1371…

Fix: after 2.32
Fix from $1,600 2021-02-26
Debian Linux HIGH 7.5
CVE-2020-36227EPSS 78%

A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in denial of s…

Fix: 2.4.57 / 11.4+
Fix from $1,950 2021-01-26
Debian Linux MEDIUM 5.5
CVE-2020-28916

hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address.

Patch available
Fix from $1,600 2020-12-04
Debian Linux HIGH 7.5
CVE-2020-15598

Trustwave ModSecurity 3.x through 3.0.4 allows denial of service via a special request. NOTE: The discoverer reports "Trustwave has signaled they are…

Fix: after 3.0.4
Fix from $1,950 2020-10-06
Debian Linux MEDIUM 5.3
CVE-2020-25625

hw/usb/hcd-ohci.c in QEMU 5.0.0 has an infinite loop when a TD list has a loop.

Patch available
Fix from $1,600 2020-09-25
Debian Linux HIGH 7.5
CVE-2020-12663

Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers.

Fix: 1.10.1+
Fix from $1,950 2020-05-19
Debian Linux MEDIUM 6.5
CVE-2014-8561

imagemagick 6.8.9.6 has remote DOS via infinite loop

Patch available
Fix from $1,600 2019-12-15
Debian Linux MEDIUM 5.5
CVE-2019-17349

An issue was discovered in Xen through 4.12.x allowing Arm domU attackers to cause a denial of service (infinite loop) involving a LoadExcl or StoreE…

Fix: after 4.12.1
Fix from $1,600 2019-10-08
Debian Linux MEDIUM 5.5
CVE-2019-17350

An issue was discovered in Xen through 4.12.x allowing Arm domU attackers to cause a denial of service (infinite loop) involving a compare-and-exchan…

Fix: after 4.12.1
Fix from $1,600 2019-10-08
Debian Linux MEDIUM 5.5
CVE-2019-15143

In DjVuLibre 3.5.27, the bitmap reader component allows attackers to cause a denial-of-service error (resource exhaustion caused by a GBitmap::read_r…

No fix yet
Fix from $1,600 2019-08-18
Debian Linux MEDIUM 6.5
CVE-2019-14442

In mpc8_read_header in libavformat/mpc8.c in Libav 12.3, an input file can result in an avio_seek infinite loop and hang, with 100% CPU consumption. …

No fix yet
Fix from $1,600 2019-07-30
Debian Linux HIGH 7.5
CVE-2018-5818

An error within the "parse_rollei()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can be exploited to trigger an infin…

Fix: 0.19.1+
Fix from $1,950 2019-02-20
Debian Linux MEDIUM 6.5
CVE-2018-20467

In coders/bmp.c in ImageMagick before 7.0.8-16, an input file can result in an infinite loop and hang, with high CPU and memory consumption. Remote a…

Fix: 6.9.10-16 / 7.0.8-16+
Fix from $1,600 2018-12-26
Debian Linux MEDIUM 5.5
CVE-2018-19777

In Artifex MuPDF 1.14.0, there is an infinite loop in the function svg_dev_end_tile in fitz/svg-device.c, as demonstrated by mutool.

No fix yet
Fix from $1,600 2018-11-30
Debian Linux MEDIUM 6.5
CVE-2018-19108

In Exiv2 0.26, Exiv2::PsdImage::readMetadata in psdimage.cpp in the PSD image reader may suffer from a denial of service (infinite loop) caused by an…

Patch available
Fix from $1,600 2018-11-08
Debian Linux MEDIUM 6.5
CVE-2018-16646

In Poppler 0.68.0, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote attacker can leverage this fo…

Patch available
Fix from $1,600 2018-09-06
Debian Linux MEDIUM 6.5
CVE-2018-14347

GNU Libextractor before 1.7 contains an infinite loop vulnerability in EXTRACTOR_mpeg_extract_method (mpeg_extractor.c).

Fix: 1.7+
Fix from $1,600 2018-07-17