Show filters
243 Total Results
Displaying 71-80 of 243
Sort by:
Attacker Value
Unknown

CVE-2022-23437

Disclosure Date: January 24, 2022 (last updated February 23, 2025)
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.
Attacker Value
Unknown

CVE-2021-23567

Disclosure Date: January 14, 2022 (last updated February 23, 2025)
The package colors after 1.4.0 are vulnerable to Denial of Service (DoS) that was introduced through an infinite loop in the americanFlag module. Unfortunately this appears to have been a purposeful attempt by a maintainer of colors to make the package unusable, other maintainers' controls over this package appear to have been revoked in an attempt to prevent them from fixing the issue. Vulnerable Code js for (let i = 666; i < Infinity; i++;) { Alternative Remediation Suggested * Pin dependancy to 1.4.0
Attacker Value
Unknown

CVE-2021-45445

Disclosure Date: January 12, 2022 (last updated February 23, 2025)
Unisys ClearPath MCP TCP/IP Networking Services 59.1, 60.0, and 62.0 has an Infinite Loop.
Attacker Value
Unknown

CVE-2021-40111

Disclosure Date: January 04, 2022 (last updated February 23, 2025)
In Apache James, while fuzzing with Jazzer the IMAP parsing stack, we discover that crafted APPEND and STATUS IMAP command could be used to trigger infinite loops resulting in expensive CPU computations and OutOfMemory exceptions. This can be used for a Denial Of Service attack. The IMAP user needs to be authenticated to exploit this vulnerability. This affected Apache James prior to version 3.6.1. This vulnerability had been patched in Apache James 3.6.1 and higher. We recommend the upgrade.
Attacker Value
Unknown

CVE-2021-4182

Disclosure Date: December 30, 2021 (last updated February 23, 2025)
Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
Attacker Value
Unknown

CVE-2021-4185

Disclosure Date: December 30, 2021 (last updated February 23, 2025)
Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
Attacker Value
Unknown

CVE-2021-4190

Disclosure Date: December 30, 2021 (last updated February 23, 2025)
Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service via packet injection or crafted capture file
Attacker Value
Unknown

CVE-2021-4184

Disclosure Date: December 30, 2021 (last updated February 23, 2025)
Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
Attacker Value
Unknown

CVE-2021-45257

Disclosure Date: December 22, 2021 (last updated February 23, 2025)
An infinite loop vulnerability exists in nasm 2.16rc0 via the gpaste_tokens function.
Attacker Value
Unknown

CVE-2021-44924

Disclosure Date: December 21, 2021 (last updated February 23, 2025)
An infinite loop vulnerability exists in gpac 1.1.0 in the gf_log function, which causes a Denial of Service.