Show filters
439 Total Results
Displaying 381-390 of 439
Sort by:
Attacker Value
Unknown
CVE-2020-28030
Disclosure Date: November 02, 2020 (last updated February 22, 2025)
In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed in epan/dissectors/packet-gquic.c by correcting the implementation of offset advancement.
0
Attacker Value
Unknown
CVE-2019-18796
Disclosure Date: October 16, 2020 (last updated February 22, 2025)
The BASS Audio Library 2.4.14 under Windows is prone to a BASS_StreamCreateFile Denial of Service vulnerability (infinite loop) via a crafted .mp3 file. This weakness could allow attackers to consume excessive CPU and the application becomes unresponsive.
0
Attacker Value
Unknown
CVE-2020-26575
Disclosure Date: October 06, 2020 (last updated February 22, 2025)
In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector could enter an infinite loop. This was addressed in epan/dissectors/packet-fbzero.c by correcting the implementation of offset advancement.
0
Attacker Value
Unknown
CVE-2020-15598
Disclosure Date: October 06, 2020 (last updated February 22, 2025)
Trustwave ModSecurity 3.x through 3.0.4 allows denial of service via a special request. NOTE: The discoverer reports "Trustwave has signaled they are disputing our claims." The CVE suggests that there is a security issue with how ModSecurity handles regular expressions that can result in a Denial of Service condition. The vendor does not consider this as a security issue because1) there is no default configuration issue here. An attacker would need to know that a rule using a potentially problematic regular expression was in place, 2) the attacker would need to know the basic nature of the regular expression itself to exploit any resource issues. It's well known that regular expression usage can be taxing on system resources regardless of the use case. It is up to the administrator to decide on when it is appropriate to trade resources for potential security benefit
0
Attacker Value
Unknown
CVE-2020-25641
Disclosure Date: October 06, 2020 (last updated February 22, 2025)
A flaw was found in the Linux kernel's implementation of biovecs in versions before 5.9-rc7. A zero-length biovec request issued by the block subsystem could cause the kernel to enter an infinite loop, causing a denial of service. This flaw allows a local attacker with basic privileges to issue requests to a block device, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
0
Attacker Value
Unknown
CVE-2020-25625
Disclosure Date: September 25, 2020 (last updated February 22, 2025)
hw/usb/hcd-ohci.c in QEMU 5.0.0 has an infinite loop when a TD list has a loop.
0
Attacker Value
Unknown
CVE-2020-14525
Disclosure Date: September 18, 2020 (last updated February 22, 2025)
Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a webpage that is served to other users.
0
Attacker Value
Unknown
CVE-2020-25574
Disclosure Date: September 14, 2020 (last updated February 22, 2025)
An issue was discovered in the http crate before 0.1.20 for Rust. An integer overflow in HeaderMap::reserve() could result in denial of service (e.g., an infinite loop).
0
Attacker Value
Unknown
CVE-2020-12457
Disclosure Date: August 21, 2020 (last updated February 22, 2025)
An issue was discovered in wolfSSL before 4.5.0. It mishandles the change_cipher_spec (CCS) message processing logic for TLS 1.3. If an attacker sends ChangeCipherSpec messages in a crafted way involving more than one in a row, the server becomes stuck in the ProcessReply() loop, i.e., a denial of service.
0
Attacker Value
Unknown
CVE-2019-19643
Disclosure Date: August 14, 2020 (last updated February 21, 2025)
ise smart connect KNX Vaillant 1.2.839 contain a Denial of Service.
0