Skip to main content

CWE archive

CWE-835 CVEs

Programmatic archive

876 CVEs tagged with CWE-83510 Critical, 370 High, 474 Medium, 22 Low, 0 Unrated.

CVE-2017-13728

Published Aug 29, 2017

There is an infinite loop in the next_char function in comp_scan.c in ncurses 6.0, related to libtic. A crafted input will lead to a remote denial of service attack.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12852

Published Aug 15, 2017

The numpy.pad function in Numpy 1.13.1 and older versions is missing input validation. An empty list or ndarray will stick into an infinite loop, which can allow attackers to caus…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6817

Published Aug 10, 2017

The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header was received that was larger than the available buffer. Thi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-11118

Published Jul 31, 2017

The ExifImageFile::readImage function in ExifImageFileRead.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a cra…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9258

Published Jul 27, 2017

The TDStretch::processSamples function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumpti…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-11627

Published Jul 25, 2017

A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related to the PointerHolder function…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-11626

Published Jul 25, 2017

A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related to the QPDFTokenizer::resolve…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-11625

Published Jul 25, 2017

A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related to the QPDF::resolveObjectsIn…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-11624

Published Jul 25, 2017

A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related to the QPDFTokenizer::resolve…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-11523

Published Jul 22, 2017

The ReadTXTImage function in coders/txt.c in ImageMagick through 6.9.9-0 and 7.x through 7.0.6-1 allows remote attackers to cause a denial of service (infinite loop) via a crafted…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7542

Published Jul 21, 2017

The ip6_find_1stfragopt function in net/ipv6/output_core.c in the Linux kernel through 4.12.3 allows local users to cause a denial of service (integer overflow and infinite loop)…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-11478

Published Jul 20, 2017

The ReadOneDJVUImage function in coders/djvu.c in ImageMagick through 6.9.9-0 and 7.x through 7.0.6-1 allows remote attackers to cause a denial of service (infinite loop and CPU c…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-11446

Published Jul 19, 2017

The ReadPESImage function in coders\pes.c in ImageMagick 7.0.6-1 has an infinite loop vulnerability that can cause CPU exhaustion via a crafted PES file.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-11410

Published Jul 18, 2017

In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the WBXML dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addres…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-11406

Published Jul 18, 2017

In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the DOCSIS dissector could go into an infinite loop. This was addressed in plugins/docsis/packet-docsis.c by rejecting invalid Fra…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-10986

Published Jul 17, 2017

An FR-GV-303 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Infinite read in dhcp_attr2vp()" and a denial of service.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-10985

Published Jul 17, 2017

An FR-GV-302 issue in FreeRADIUS 3.x before 3.0.15 allows "Infinite loop and memory exhaustion with 'concat' attributes" and a denial of service.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-11338

Published Jul 17, 2017

There is an infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp in Exiv2 0.26. A crafted input will lead to a remote denial of service attack.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-11171

Published Jul 11, 2017

Bad reference counting in the context of accept_ice_connection() in gsm-xsmp-server.c in old versions of gnome-session up until version 2.29.92 allows a local attacker to establis…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-0685

Published Jul 6, 2017

A denial of service vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34203195.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9375

Published Jun 16, 2017

QEMU (aka Quick Emulator), when built with USB xHCI controller emulator support, allows local guest OS privileged users to cause a denial of service (infinite recursive call) via…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9122

Published Jun 12, 2017

The quicktime_read_moov function in moov.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted mp4 file.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 776-800 of 876 CVEsPage 32 of 36