Show filters
439 Total Results
Displaying 371-380 of 439
Sort by:
Attacker Value
Unknown

CVE-2020-17444

Disclosure Date: December 11, 2020 (last updated February 22, 2025)
An issue was discovered in picoTCP 1.7.0. The routine for processing the next header field (and deducing whether the IPv6 extension headers are valid) doesn't check whether the header extension length field would overflow. Therefore, if it wraps around to zero, iterating through the extension headers will not increment the current data pointer. This leads to an infinite loop and Denial-of-Service in pico_ipv6_check_headers_sequence() in pico_ipv6.c.
Attacker Value
Unknown

CVE-2020-13984

Disclosure Date: December 11, 2020 (last updated February 22, 2025)
An issue was discovered in Contiki through 3.0. An infinite loop exists in the uIP TCP/IP stack component when processing IPv6 extension headers in ext_hdr_options_process in net/ipv6/uip6.c.
Attacker Value
Unknown

CVE-2020-13986

Disclosure Date: December 11, 2020 (last updated February 22, 2025)
An issue was discovered in Contiki through 3.0. An infinite loop exists in the uIP TCP/IP stack component when handling RPL extension headers of IPv6 network packets in rpl_remove_header in net/rpl/rpl-ext-header.c.
Attacker Value
Unknown

CVE-2020-28916

Disclosure Date: December 04, 2020 (last updated February 22, 2025)
hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address.
Attacker Value
Unknown

CVE-2018-20805

Disclosure Date: November 30, 2020 (last updated February 22, 2025)
A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which perform an $elemMatch . This issue affects MongoDB Server v4.0 versions prior to 4.0.5 and MongoDB Server v3.6 versions prior to 3.6.10.
Attacker Value
Unknown

CVE-2020-29135

Disclosure Date: November 27, 2020 (last updated February 22, 2025)
cPanel before 90.0.17 has multiple instances of URL parameter injection (SEC-567).
Attacker Value
Unknown

CVE-2019-20925

Disclosure Date: November 24, 2020 (last updated February 22, 2025)
An unauthenticated client can trigger denial of service by issuing specially crafted wire protocol messages, which cause the message decompressor to incorrectly allocate memory. This issue affects MongoDB Server v4.2 versions prior to 4.2.1; MongoDB Server v4.0 versions prior to 4.0.13; MongoDB Server v3.6 versions prior to 3.6.15 and MongoDB Server v3.4 versions prior to 3.4.24.
Attacker Value
Unknown

CVE-2018-20803

Disclosure Date: November 23, 2020 (last updated February 22, 2025)
A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which loop indefinitely in mathematics processing while retaining locks. This issue affects MongoDB Server v4.0 versions prior to 4.0.5; MongoDB Server v3.6 versions prior to 3.6.10 and MongoDB Server v3.4 versions prior to 3.4.19.
Attacker Value
Unknown

CVE-2020-27152

Disclosure Date: November 06, 2020 (last updated February 22, 2025)
An issue was discovered in ioapic_lazy_update_eoi in arch/x86/kvm/ioapic.c in the Linux kernel before 5.9.2. It has an infinite loop related to improper interaction between a resampler and edge triggering, aka CID-77377064c3a9.
Attacker Value
Unknown

CVE-2020-16127

Disclosure Date: November 03, 2020 (last updated February 22, 2025)
An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, would perform unbounded read operations on user-controlled ~/.pam_environment files, allowing an infinite loop if /dev/zero is symlinked to this location.