Vulnerability index

Browse CVEs

59 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Infinite LoopCWE-835 × clear
Debian Linux MEDIUM 6.5
CVE-2017-18273

In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-22, an infinite loop vulnerability was found in the function ReadTXTImage in coders/txt.c, which allows at…

No fix yet
Fix from $1,600 2018-05-18
Debian Linux MEDIUM 6.5
CVE-2018-10981

An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to cause a denial of service (host OS infinite loop) in situations wher…

Fix: after 4.10.1
Fix from $1,600 2018-05-10
Debian Linux MEDIUM 5.5
CVE-2018-10289

In MuPDF 1.13.0, there is an infinite loop in the fz_skip_space function of the pdf/pdf-xref.c file. A remote adversary could leverage this vulnerabi…

No fix yet
Fix from $1,600 2018-04-22
Debian Linux MEDIUM 5.3
CVE-2018-9251

The xz_decomp function in xzlib.c in libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via …

No fix yet
Fix from $1,600 2018-04-04
Debian Linux MEDIUM 5.5
CVE-2017-18233

An issue was discovered in Exempi before 2.4.4. Integer overflow in the Chunk class in XMPFiles/source/FormatSupport/RIFF.cpp allows remote attackers…

Fix: 2.4.4+
Fix from $1,600 2018-03-15
Debian Linux MEDIUM 5.5
CVE-2017-18236

An issue was discovered in Exempi before 2.4.4. The ASF_Support::ReadHeaderObject function in XMPFiles/source/FormatSupport/ASF_Support.cpp allows re…

Fix: 2.4.4+
Fix from $1,600 2018-03-15
Debian Linux MEDIUM 5.5
CVE-2017-18238

An issue was discovered in Exempi before 2.4.4. The TradQT_Manager::ParseCachedBoxes function in XMPFiles/source/FormatSupport/QuickTime_Support.cpp …

Fix: 2.4.4+
Fix from $1,600 2018-03-15
Debian Linux HIGH 7.5
CVE-2018-1000075

RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 a…

Fix: after 2.5.0
Fix from $1,950 2018-03-13
Debian Linux MEDIUM 5.5
CVE-2018-5786

In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the get_fileinfo function (lrzip.c). Remote attackers could le…

Patch available
Fix from $1,600 2018-01-19
Debian Linux MEDIUM 6.5
CVE-2018-5685

In GraphicsMagick 1.3.27, there is an infinite loop and application hang in the ReadBMPImage function (coders/bmp.c). Remote attackers could leverage…

Patch available
Fix from $1,600 2018-01-14
Debian Linux MEDIUM 5.5
CVE-2018-5686

In MuPDF 1.12.0, there is an infinite loop vulnerability and application hang in the pdf_parse_array function (pdf/pdf-parse.c) because EOF is not co…

No fix yet
Fix from $1,600 2018-01-14
Debian Linux HIGH 7.5
CVE-2017-16944EPSS 63%

The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinite loop an…

No fix yet
Fix from $1,950 2017-11-25
Debian Linux MEDIUM 5.5
CVE-2017-13756

In The Sleuth Kit (TSK) 4.4.2, opening a crafted disk image triggers infinite recursion in dos_load_ext_table() in tsk/vs/dos.c in libtskvs.a, as dem…

Mitigation only
Fix from $1,600 2017-08-29
Debian Linux MEDIUM 6.5
CVE-2015-7850

ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to cause a denial of service (infinite loop or crash) by …

Fix: 4.2.8 / 4.3.77+
Fix from $1,600 2017-08-07
Debian Linux MEDIUM 5.5
CVE-2017-9375

QEMU (aka Quick Emulator), when built with USB xHCI controller emulator support, allows local guest OS privileged users to cause a denial of service …

Fix: after 2.8.1.1
Fix from $1,600 2017-06-16
Debian Linux MEDIUM 5.6
CVE-2017-9310

QEMU (aka Quick Emulator), when built with the e1000e NIC emulation support, allows local guest OS privileged users to cause a denial of service (inf…

Fix: after 2.8.1.1
Fix from $1,600 2017-06-08
Debian Linux MEDIUM 5.6
CVE-2017-9330

QEMU (aka Quick Emulator) before 2.9.0, when built with the USB OHCI Emulation support, allows local guest OS users to cause a denial of service (inf…

Fix: after 2.8.1.1
Fix from $1,600 2017-06-08
Debian Linux MEDIUM 6.5
CVE-2017-8112

hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (infinite loop and CPU consumpt…

Fix: after 2.9.1
Fix from $1,600 2017-05-02
Debian Linux MEDIUM 5.5
CVE-2017-5973

The xhci_kick_epctx function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (i…

Fix: after 2.8.1.1
Fix from $1,600 2017-03-27
Debian Linux MEDIUM 5.5
CVE-2017-5987

The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows local OS guest privileged users to cause a denial …

Fix: after 2.8.1.1
Fix from $1,600 2017-03-20
Debian Linux MEDIUM 5.5
CVE-2017-6299

An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "2 of 9. Infinite Loop / DoS in the TNEFFillMapi function in l…

Fix: after 1.9
Fix from $1,600 2017-02-24
Debian Linux MEDIUM 5.5
CVE-2016-1981

QEMU (aka Quick Emulator) built with the e1000 NIC emulation support is vulnerable to an infinite loop issue. It could occur while processing data vi…

Fix: after 2.5.1.1
Fix from $1,600 2016-12-29
Debian Linux MEDIUM 5.5
CVE-2016-9776

QEMU (aka Quick Emulator) built with the ColdFire Fast Ethernet Controller emulator support is vulnerable to an infinite loop issue. It could occur w…

Fix: after 2.7.1
Fix from $1,600 2016-12-29
Debian Linux MEDIUM 6.0
CVE-2016-8910

The rtl8139_cplus_transmit function in hw/net/rtl8139.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of servic…

Fix: after 2.7.1
Fix from $1,600 2016-11-04
Debian Linux MEDIUM 6.0
CVE-2016-8909

The intel_hda_xfer function in hw/audio/intel-hda.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (i…

Fix: after 2.7.1
Fix from $1,600 2016-11-04
Debian Linux MEDIUM 5.5
CVE-2015-8558

The ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and CPU c…

Fix: after 2.5.1.1
Fix from $1,600 2016-05-23
Debian Linux MEDIUM 5.5
CVE-2012-1186

Integer overflow in the SyncImageProfiles function in profile.c in ImageMagick 6.7.5-8 and earlier allows remote attackers to cause a denial of servi…

Fix: after 6.7.5-8
Fix from $1,600 2012-06-05
Debian Linux MEDIUM 5.5
CVE-2012-0248

ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted image whose IFD contains …

Patch available
Fix from $1,600 2012-06-05
Debian Linux HIGH 7.8
CVE-2009-1270EPSS 5%

libclamav/untar.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (infinite loop) via a crafted TAR file that causes (1) c…

Fix: 0.95+
Fix from $1,950 2009-04-08