Skip to main content

CWE archive

CWE-835 CVEs

Programmatic archive

878 CVEs tagged with CWE-83510 Critical, 372 High, 474 Medium, 22 Low, 0 Unrated.

CVE-2018-16789

Published Mar 21, 2019

libhttp/url.c in shellinabox through 2.20 has an implementation flaw in the HTTP request parsing logic. By sending a crafted multipart/form-data HTTP request, an attacker could ex…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-9747

Published Mar 13, 2019

In tinysvcmdns through 2018-01-16, a maliciously crafted mDNS (Multicast DNS) packet triggers an infinite loop while parsing an mDNS query. When mDNS compressed labels point to ea…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6687

Published Feb 21, 2019

Loop with Unreachable Exit Condition ('Infinite Loop') in McAfee GetSusp (GetSusp) 3.0.0.461 and earlier allows attackers to DoS a manual GetSusp scan via while scanning a specifi…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-5818

Published Feb 20, 2019

An error within the "parse_rollei()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can be exploited to trigger an infinite loop.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-18361

Published Feb 1, 2019

In Pylons Colander through 1.6, the URL validator allows an attacker to potentially cause an infinite loop thereby causing a denial of service via an unclosed parenthesis.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-6462

Published Jan 16, 2019

An issue was discovered in cairo 1.16.0. There is an infinite loop in the function _arc_error_normalized in the file cairo-arc.c, related to _arc_max_angle_for_tolerance_normalize…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3573

Published Jan 2, 2019

In libsixel v1.8.2, there is an infinite loop in the function sixel_decode_raw_impl() in the file fromsixel.c, as demonstrated by sixel2png.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20578

Published Dec 28, 2018

An issue was discovered in NuttX before 7.27. The function netlib_parsehttpurl() in apps/netutils/netlib/netlib_parsehttpurl.c mishandles URLs longer than hostlen bytes (in the we…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-17197

Published Dec 24, 2018

A carefully crafted or corrupt sqlite file can cause an infinite loop in Apache Tika's SQLite3Parser in versions 1.8-1.19.1 of Apache Tika.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20348

Published Dec 22, 2018

libpff_item_tree_create_node in libpff_item_tree.c in libpff before experimental-20180714 allows attackers to cause a denial of service (infinite recursion) via a crafted file, re…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20099

Published Dec 12, 2018

There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-5813

Published Dec 7, 2018

An error within the "parse_minolta()" function (dcraw/dcraw.c) in LibRaw versions prior to 0.18.11 can be exploited to trigger an infinite loop via a specially crafted file.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-15835

Published Dec 7, 2018

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, While processing the RIC Data Descriptor IE in an artificially crafted 8…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 626-650 of 878 CVEsPage 26 of 36