Skip to main content

CWE archive

CWE-835 CVEs

Programmatic archive

876 CVEs tagged with CWE-83510 Critical, 370 High, 474 Medium, 22 Low, 0 Unrated.

CVE-2024-8088

Published Aug 22, 2024

There is a HIGH severity vulnerability affecting the CPython "zipfile" module affecting "zipfile.Path". Note that the more common API "zipfile.ZipFile" class is unaffected. W…

CVSS 8.7 · High

CVE-2024-43828

Published Aug 17, 2024

In the Linux kernel, the following vulnerability has been resolved: ext4: fix infinite loop when replaying fast_commit When doing fast_commit replay an infinite loop may occur d…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-43366

Published Aug 15, 2024

zkvyper is a Vyper compiler. Starting in version 1.3.12 and prior to version 1.5.3, since LLL IR has no Turing-incompletness restrictions, it is compiled to a loop with a much mor…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42246

Published Aug 7, 2024

In the Linux kernel, the following vulnerability has been resolved: net, sunrpc: Remap EPERM in case of connection failure in xs_tcp_setup_socket When using a BPF program on ker…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42240

Published Aug 7, 2024

In the Linux kernel, the following vulnerability has been resolved: x86/bhi: Avoid warning in #DB handler due to BHI mitigation When BHI mitigation is enabled, if SYSENTER is in…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42358

Published Aug 6, 2024

PDFio is a simple C library for reading and writing PDF files. There is a denial of service (DOS) vulnerability in the TTF parser. Maliciously crafted TTF files can cause the prog…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-41088

Published Jul 29, 2024

In the Linux kernel, the following vulnerability has been resolved: can: mcp251xfd: fix infinite loop when xmit fails When the mcp251xfd_start_xmit() function fails, the driver…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-40060

Published Jul 23, 2024

go-chart v2.1.1 was discovered to contain an infinite loop via the drawCanvas() function.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-48862

Published Jul 16, 2024

In the Linux kernel, the following vulnerability has been resolved: vhost: fix hung thread due to erroneous iotlb entries In vhost_iotlb_add_range_ctx(), range size can overflow…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-48840

Published Jul 16, 2024

In the Linux kernel, the following vulnerability has been resolved: iavf: Fix hang during reboot/shutdown Recent commit 974578017fc1 ("iavf: Add waiting so the port is initializ…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-48780

Published Jul 16, 2024

In the Linux kernel, the following vulnerability has been resolved: net/smc: Avoid overwriting the copies of clcsock callback functions The callback functions of clcsock will be…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-40995

Published Jul 12, 2024

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_api: fix possible infinite loop in tcf_idr_check_alloc() syzbot found hanging tasks waiting on…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6614

Published Jul 9, 2024

The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128 and Thunderbird < 12…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5569

Published Jul 9, 2024

A Denial of Service (DoS) vulnerability exists in the jaraco/zipp library, affecting all versions prior to 3.19.1. The vulnerability is triggered when processing a specially craft…

CVSS 6.2 · Medium

CVE-2024-6227

Published Jul 8, 2024

A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to cause an infinite loop by configuring the remote tracking server to point at itself. This results in the serve…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-36990

Published Jul 1, 2024

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.2.2403.100, an authenticated, low-privileged user that does not hold the ad…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-36288

Published Jun 21, 2024

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix loop termination condition in gss_free_in_token_pages() The in_token->pages[] array is not NULL t…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-47617

Published Jun 20, 2024

In the Linux kernel, the following vulnerability has been resolved: PCI: pciehp: Fix infinite loop in IRQ handler upon power fault The Power Fault Detected bit in the Slot Statu…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6061

Published Jun 17, 2024

A vulnerability has been found in GPAC 2.5-DEV-rev228-g11067ea92-master and classified as problematic. Affected by this vulnerability is the function isoffin_process of the file s…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50763

Published Jun 11, 2024

A vulnerability has been identified in SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0) (All versions < V2.3), SIMATIC CP 1542SP-1 IRC (6GK7542-6VX00-0XE0) (All versions < V2.3), SIMATIC…

CVSS 6.9 · Medium

CVE-2024-36732

Published Jun 6, 2024

An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when an empty array is processed with oneflow.tensordot.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-32976

Published Jun 4, 2024

Envoy is a cloud-native, open source edge and service proxy. Envoyproxy with a Brotli filter can get into an endless loop during decompression of Brotli data with extra input.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-47448

Published May 22, 2024

In the Linux kernel, the following vulnerability has been resolved: mptcp: fix possible stall on recvmsg() recvmsg() can enter an infinite loop if the caller provides the MSG_WA…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 251-275 of 876 CVEsPage 11 of 36