Skip to main content

CWE archive

CWE-674 CVEs

Programmatic archive

503 CVEs tagged with CWE-6747 Critical, 227 High, 239 Medium, 30 Low, 0 Unrated.

CVE-2016-10707

Published Jan 18, 2018

jQuery 3.0.0-rc.1 is vulnerable to Denial of Service (DoS) due to removing a logic that lowercased attribute names. Any attribute getter using a mixed-cased name for boolean attri…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5772

Published Jan 18, 2018

In Exiv2 0.26, there is a segmentation fault caused by uncontrolled recursion in the Exiv2::Image::printIFDStructure function in the image.cpp file. Remote attackers could leverag…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-10910

Published Dec 28, 2017

MQTT.js 2.x.x prior to 2.15.0 issue in handling PUBLISH tickets may lead to an attacker causing a denial-of-service condition.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14861

Published Sep 29, 2017

There is a stack consumption vulnerability in the Exiv2::Internal::stringFormat function of image.cpp in Exiv2 0.26. A Crafted input will lead to a remote denial of service attack.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-12964

Published Aug 18, 2017

There is a stack consumption issue in LibSass 3.4.5 that is triggered in the function Sass::Eval::operator() in eval.cpp. It will lead to a remote denial of service attack.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-11556

Published Jul 23, 2017

There is a stack consumption vulnerability in the Parser::advanceToNextToken function in parser.cpp in LibSass 3.4.5. A crafted input may lead to remote denial of service.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-11554

Published Jul 23, 2017

There is a stack consumption vulnerability in the lex function in parser.hpp (as used in sassc) in LibSass 3.4.5. A crafted input will lead to a remote denial of service.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-11164

Published Jul 11, 2017

In PCRE 8.41, the OP_KETRMAX feature in the match function in pcre_exec.c allows stack exhaustion (uncontrolled recursion) when processing a crafted regular expression.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-0692

Published Jul 6, 2017

A denial of service vulnerability in the Android media framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36725407.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9766

Published Jun 21, 2017

In Wireshark 2.2.7, PROFINET IO data with a high recursion depth allows remote attackers to cause a denial of service (stack exhaustion) in the dissect_IODWriteReq function in plu…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-9729

Published Jun 16, 2017

In uClibc 0.9.33.2, there is stack exhaustion (uncontrolled recursion) in the check_dst_limits_calc_pos_1 function in misc/regex/regexec.c when processing a crafted regular expres…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-9617

Published Jun 14, 2017

In Wireshark 2.2.7, deeply nested DAAP data may cause stack exhaustion (uncontrolled recursion) in the dissect_daap_one_tag function in epan/dissectors/packet-daap.c in the DAAP d…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9616

Published Jun 14, 2017

In Wireshark 2.2.7, overly deep mp4 chunks may cause stack exhaustion (uncontrolled recursion) in the dissect_mp4_box function in epan/dissectors/file-mp4.c.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7515

Published Jun 6, 2017

poppler through version 0.55.0 is vulnerable to an uncontrolled recursion in pdfunite resulting into potential denial-of-service.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9438

Published Jun 5, 2017

libyara/re.c in the regexp module in YARA 3.5.0 allows remote attackers to cause a denial of service (stack consumption) via a crafted rule (involving hex strings) that is mishand…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-9304

Published May 31, 2017

libyara/re.c in the regexp module in YARA 3.5.0 allows remote attackers to cause a denial of service (stack consumption) via a crafted rule that is mishandled in the _yr_re_emit f…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8542

Published May 26, 2017

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2017-8539

Published May 26, 2017

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2017-0886

Published Apr 5, 2017

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Denial of Service attack. Due to an error in the application logic an authenticated adversary may trigger an endless recur…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5839

Published Feb 9, 2017

The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in GStreamer before 1.10.3 does not properly limit recursion, which allows remote att…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4425

Published May 17, 2016

Jansson 2.7 and earlier allows context-dependent attackers to cause a denial of service (deep recursion, stack consumption, and crash) via crafted JSON data.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 476-500 of 503 CVEsPage 20 of 21