Skip to main content

CWE archive

CWE-835 CVEs

Programmatic archive

876 CVEs tagged with CWE-83510 Critical, 370 High, 474 Medium, 22 Low, 0 Unrated.

CVE-2017-16944

Published Nov 25, 2017

The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinite loop and stack exhaustion) via vector…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2017-16932

Published Nov 23, 2017

parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter entities.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-2909

Published Nov 7, 2017

An infinite loop programming error exists in the DNS server functionality of Cesanta Mongoose 6.8 library. A specially crafted DNS request can cause an infinite loop resulting in…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15871

Published Oct 24, 2017

The deserialize function in serialize-to-js through 1.1.1 allows attackers to cause a denial of service via vectors involving an Immediately Invoked Function Expression "function(…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15223

Published Oct 24, 2017

Denial-of-service vulnerability in ArGoSoft Mini Mail Server 1.0.0.2 and earlier allows remote attackers to waste CPU resources (memory consumption) via unspecified vectors, possi…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-15602

Published Oct 18, 2017

In GNU Libextractor 1.4, there is an integer signedness error for the chunk size in the EXTRACTOR_nsfe_extract_method function in plugins/nsfe_extractor.c, leading to an infinite…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15024

Published Oct 5, 2017

find_abstract_instance_name in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14934

Published Sep 30, 2017

process_debug_info in dwarf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14933

Published Sep 30, 2017

read_formatted_entries in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of serv…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14932

Published Sep 30, 2017

decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (i…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14929

Published Sep 30, 2017

In Poppler 0.59.0, memory corruption occurs in a call to Object::dictLookup() in Object.h after a repeating series of Gfx::display, Gfx::go, Gfx::execOp, Gfx::opFill, Gfx::doPatte…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14741

Published Sep 26, 2017

The ReadCAPTIONImage function in coders/caption.c in ImageMagick 7.0.7-3 allows remote attackers to cause a denial of service (infinite loop) via a crafted font file.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6267

Published Sep 22, 2017

NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer handler where an incorrect initialization of internal objects can cause an infinite loop which may lead…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14339

Published Sep 20, 2017

The DNS packet parser in YADIFA before 2.2.6 does not check for the presence of infinite pointer loops, and thus it is possible to force it to enter an infinite loop. This can cau…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14519

Published Sep 17, 2017

In Poppler 0.59.0, memory corruption occurs in a call to Object::streamGetChar in Object.h after a repeating series of Gfx::display, Gfx::go, Gfx::execOp, Gfx::opShowText, and Gfx…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12997

Published Sep 14, 2017

The LLDP parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-lldp.c:lldp_private_8021_print().

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-12995

Published Sep 14, 2017

The DNS parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-domain.c:ns_print().

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-12990

Published Sep 14, 2017

The ISAKMP parser in tcpdump before 4.9.2 could enter an infinite loop due to bugs in print-isakmp.c, several functions.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-12989

Published Sep 14, 2017

The RESP parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-resp.c:resp_get_length().

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14229

Published Sep 9, 2017

There is an infinite loop in the jpc_dec_tileinit function in jpc/jpc_dec.c of Jasper 2.0.13. It will lead to a remote denial of service attack.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14058

Published Aug 31, 2017

In FFmpeg 2.4 and 3.3.3, the read_data function in libavformat/hls.c does not restrict reload attempts for an insufficient list, which allows remote attackers to cause a denial of…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-13767

Published Aug 30, 2017

In Wireshark 2.4.0, 2.2.0 to 2.2.8, and 2.0.0 to 2.0.14, the MSDP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-msdp.c by adding length va…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 751-775 of 876 CVEsPage 31 of 36