VYPR

CWE-606

Unchecked Input for Loop Condition

BaseDraft

Description

The product does not properly check inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (42)

page 2 of 3
  • CVE-2026-33891HigMar 27, 2026
    risk 0.42cvss 7.5epss 0.01

    Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, a Denial of Service (DoS) vulnerability exists in the node-forge library due to an infinite loop in the BigInteger.modInverse() function (inherited from…

  • CVE-2025-42930MedSep 9, 2025
    risk 0.42cvss 6.5epss 0.00

    SAP Business Planning and Consolidation allows an authenticated standard user to call a function module by crafting specific parameters that causes a loop, consuming excessive resources and resulting in system unavailability. This leads to high impact on the availability of the…

  • CVE-2022-3252HigSep 21, 2022
    risk 0.42cvss 7.5epss 0.01

    Improper detection of complete HTTP body decompression SwiftNIO Extras provides a pair of helpers for transparently decompressing received HTTP request or response bodies. These two objects (HTTPRequestDecompressor and HTTPResponseDecompressor) both failed to detect when the…

  • CVE-2019-25624MedMar 23, 2026
    risk 0.40cvss 6.2epss 0.00

    Liquid Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can trigger the vulnerability by entering arbitrary characters during application runtime,…

  • CVE-2026-27145MedJun 2, 2026
    risk 0.35cvss 6.5epss 0.01

    (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled…

  • CVE-2026-5950MedMay 20, 2026
    risk 0.35cvss 5.3epss 0.01

    An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger specific retry conditions. This issue affects BIND 9…

  • CVE-2024-28244MedMar 25, 2024
    risk 0.35cvss 6.5epss 0.02

    KaTeX is a JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressions could encounter malicious input using `\def` or `\newcommand` that causes a near-infinite loop, despite setting `maxExpand` to avoid such loops. KaTeX…

  • CVE-2024-28243MedMar 25, 2024
    risk 0.35cvss 6.5epss 0.01

    KaTeX is a JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressions could encounter malicious input using `\edef` that causes a near-infinite loop, despite setting `maxExpand` to avoid such loops. This can be used as an…

  • CVE-2023-5678MedNov 6, 2023
    risk 0.35cvss 5.3epss 0.04

    Issue summary: Generating excessively long X9.42 DH keys or checking excessively long X9.42 DH keys or parameters may be very slow. Impact summary: Applications that use the functions DH_generate_key() to generate an X9.42 DH key may experience long delays. Likewise,…

  • CVE-2023-3817MedJul 31, 2023
    risk 0.35cvss 5.3epss 0.03

    Issue summary: Checking excessively long DH keys or parameters may be very slow. Impact summary: Applications that use the functions DH_check(), DH_check_ex() or EVP_PKEY_param_check() to check a DH key or DH parameters may experience long delays. Where the key or parameters…

  • CVE-2023-3446MedJul 19, 2023
    risk 0.35cvss 5.3epss 0.07

    Issue summary: Checking excessively long DH keys or parameters may be very slow. Impact summary: Applications that use the functions DH_check(), DH_check_ex() or EVP_PKEY_param_check() to check a DH key or DH parameters may experience long delays. Where the key or parameters…

  • CVE-2025-32399MedMay 7, 2025
    risk 0.34cvss 5.3epss 0.01

    An Unchecked Input for Loop Condition in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to cause IO devices that use the library to enter an infinite loop by sending a malicious RPC packet.

  • CVE-2024-13930MedMay 22, 2025
    risk 0.32cvss 4.9epss 0.00

    An Unchecked Loop Condition in ASPECT provides an attacker the ability to maliciously consume system resources if session administrator credentials become compromised This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through…

  • CVE-2023-6237MedApr 25, 2024
    risk 0.32cvss 5.9epss 0.02

    Issue summary: Checking excessively long invalid RSA public keys may take a long time. Impact summary: Applications that use the function EVP_PKEY_public_check() to check RSA public keys may experience long delays. Where the key that is being checked has been obtained from an…

  • CVE-2026-15172MedJul 8, 2026
    risk 0.29cvss 5.5epss 0.00

    FMP/NOTIFY protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

  • CVE-2026-41606MedApr 28, 2026
    risk 0.28cvss 5.3epss 0.01

    Uncontrolled Recursion vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

  • CVE-2024-8508MedOct 3, 2024
    risk 0.28cvss 5.3epss 0.01

    NLnet Labs Unbound up to and including version 1.21.0 contains a vulnerability when handling replies with very large RRsets that it needs to perform name compression for. Malicious upstreams responses with very large RRsets can cause Unbound to spend a considerable time applying…

  • CVE-2024-4603MedMay 16, 2024
    risk 0.28cvss 5.3epss 0.01

    Issue summary: Checking excessively long DSA keys or parameters may be very slow. Impact summary: Applications that use the functions EVP_PKEY_param_check() or EVP_PKEY_public_check() to check a DSA public key or DSA parameters may experience long delays. Where the key or…

  • CVE-2026-71439MedAug 6, 2026
    risk 0.27cvss epss 0.00

    Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.6.0 until 11.16.1, Mermaid Radar Diagrams allow arbitrary large values for the ticks parameter, which can cause high CPU usage and freeze the rendering webpage…

  • CVE-2026-41986LowJun 9, 2026
    risk 0.16cvss 2.4epss 0.00

    Logic bypass vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect availability.