Show filters
439 Total Results
Displaying 391-400 of 439
Sort by:
Attacker Value
Unknown

CVE-2020-0247

Disclosure Date: August 11, 2020 (last updated February 21, 2025)
In Threshold::getHistogram of ImageProcessHelper.java, there is a possible crash loop due to an uncaught exception. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-8.0 Android-8.1Android ID: A-156087409
Attacker Value
Unknown

CVE-2020-15654

Disclosure Date: August 10, 2020 (last updated February 21, 2025)
When in an endless loop, a website specifying a custom cursor using CSS could make it look like the user is interacting with the user interface, when they are not. This could lead to a perceived broken state, especially when interactions with existing browser dialogs and warnings do not work. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
Attacker Value
Unknown

CVE-2020-16845

Disclosure Date: August 06, 2020 (last updated February 21, 2025)
Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary via invalid inputs.
Attacker Value
Unknown

CVE-2020-5761

Disclosure Date: July 29, 2020 (last updated February 21, 2025)
Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to CPU exhaustion due to an infinite loop in the TR-069 service. Unauthenticated remote attackers can trigger this case by sending a one character TCP message to the TR-069 service.
Attacker Value
Unknown

CVE-2019-20911

Disclosure Date: July 16, 2020 (last updated February 21, 2025)
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to denial of service in bit_calc_CRC in bits.c, related to a for loop.
Attacker Value
Unknown

CVE-2020-7292

Disclosure Date: July 15, 2020 (last updated February 21, 2025)
Inappropriate Encoding for output context vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows a remote attacker to cause MWG to return an ambiguous redirect response via getting a user to click on a malicious URL.
Attacker Value
Unknown

CVE-2020-13935

Disclosure Date: July 14, 2020 (last updated February 21, 2025)
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.
Attacker Value
Unknown

CVE-2019-20907

Disclosure Date: July 13, 2020 (last updated February 21, 2025)
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.
Attacker Value
Unknown

CVE-2020-14303

Disclosure Date: July 06, 2020 (last updated February 21, 2025)
A flaw was found in the AD DC NBT server in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4. A samba user could send an empty UDP packet to cause the samba server to crash.
Attacker Value
Unknown

CVE-2019-19506

Disclosure Date: June 25, 2020 (last updated February 21, 2025)
Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a denial of service, caused by an error in the "homeplugd" process. By sending a specially crafted UDP packet, an attacker could exploit this vulnerability to cause the device to reboot.