VYPR

CWE-606

Unchecked Input for Loop Condition

BaseDraft

Description

The product does not properly check inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (46)

page 3 of 3
  • CVE-2024-8508MedOct 3, 2024
    risk 0.28cvss 5.3epss 0.01

    NLnet Labs Unbound up to and including version 1.21.0 contains a vulnerability when handling replies with very large RRsets that it needs to perform name compression for. Malicious upstreams responses with very large RRsets can cause Unbound to spend a considerable time applying…

  • CVE-2024-4603MedMay 16, 2024
    risk 0.28cvss 5.3epss 0.01

    Issue summary: Checking excessively long DSA keys or parameters may be very slow. Impact summary: Applications that use the functions EVP_PKEY_param_check() or EVP_PKEY_public_check() to check a DSA public key or DSA parameters may experience long delays. Where the key or…

  • CVE-2026-71439MedAug 6, 2026
    risk 0.27cvss —epss 0.00

    Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.6.0 until 11.16.1, Mermaid Radar Diagrams allow arbitrary large values for the ticks parameter, which can cause high CPU usage and freeze the rendering webpage…

  • CVE-2026-16599MedAug 25, 2026
    risk 0.26cvss —epss 0.00

    GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line is used as an iteration count for an MD5 key-derivation loop without any upper bound validation. A malicious FTP server…

  • CVE-2026-41986LowJun 9, 2026
    risk 0.16cvss 2.4epss 0.00

    Logic bypass vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-55731MedJul 24, 2026
    risk 0.00cvss —epss 0.00

    Unchecked input for loop condition (CWE-606) in the SNMP agent in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an unauthenticated remote attacker to cause persistent denial of service (CPU exhaustion) via a crafted…