VYPR

CWE-674

Uncontrolled Recursion

ClassDraft

Description

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-230 · CAPEC-231

CVEs mapped to this weakness (496)

page 4 of 25
  • CVE-2023-36632HigJun 25, 2023
    risk 0.49cvss 7.5epss 0.02

    The legacy email.utils.parseaddr function in Python through 3.11.4 allows attackers to trigger "RecursionError: maximum recursion depth exceeded while calling a Python object" via a crafted argument. This argument is plausibly an untrusted value from an application's input data…

  • CVE-2023-2990HigJun 22, 2023
    risk 0.49cvss 7.5epss 0.01

    Fortra Globalscape EFT versions before 8.1.0.16 suffer from a denial of service vulnerability, where a compressed message that decompresses to itself can cause infinite recursion and crash the service

  • CVE-2023-31893HigJun 5, 2023
    risk 0.49cvss 7.5epss 0.01

    Telefnica Brasil Vivo Play (IPTV) Firmware: 2023.04.04.01.06.15 is vulnerable to Denial of Service (DoS) via DNS Recursion.

  • CVE-2023-24472HigMar 30, 2023
    risk 0.49cvss 7.5epss 0.01

    A denial of service vulnerability exists in the FitsOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.7.1. A specially crafted ImageOutput Object can lead to denial of service. An attacker can provide malicious input to trigger this vulnerability.

  • CVE-2021-36395HigMar 6, 2023
    risk 0.49cvss 7.5epss 0.01

    In Moodle, the file repository's URL parsing required additional recursion handling to mitigate the risk of recursion denial of service.

  • CVE-2023-22617HigJan 21, 2023
    risk 0.49cvss 7.5epss 0.07

    A remote attacker might be able to cause infinite recursion in PowerDNS Recursor 4.8.0 via a DNS query that retrieves DS records for a misconfigured domain, because QName minimization is used in QM fallback mode. This is fixed in 4.8.1.

  • CVE-2022-46405HigDec 4, 2022
    risk 0.49cvss 7.5epss 0.01

    Mastodon through 4.0.2 allows attackers to cause a denial of service (large Sidekiq pull queue) by creating bot accounts that follow attacker-controlled accounts on certain other servers associated with a wildcard DNS A record, such that there is uncontrolled recursion of…

  • CVE-2022-27810HigOct 6, 2022
    risk 0.49cvss 7.5epss 0.01

    It was possible to trigger an infinite recursion condition in the error handler when Hermes executed specific maliciously formed JavaScript. This condition was only possible to trigger in dev-mode (when asserts were enabled). This issue affects Hermes versions prior to v0.12.0.

  • CVE-2022-30635HigAug 10, 2022
    risk 0.49cvss 7.5epss 0.02

    Uncontrolled recursion in Decoder.Decode in encoding/gob before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a message which contains deeply nested structures.

  • CVE-2022-30633HigAug 10, 2022
    risk 0.49cvss 7.5epss 0.02

    Uncontrolled recursion in Unmarshal in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via unmarshalling an XML document into a Go struct which has a nested field that uses the 'any' field tag.

  • CVE-2022-30632HigAug 10, 2022
    risk 0.49cvss 7.5epss 0.02

    Uncontrolled recursion in Glob in path/filepath before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a path containing a large number of path separators.

  • CVE-2022-30631HigAug 10, 2022
    risk 0.49cvss 7.5epss 0.02

    Uncontrolled recursion in Reader.Read in compress/gzip before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via an archive containing a large number of concatenated 0-length compressed files.

  • CVE-2022-30630HigAug 10, 2022
    risk 0.49cvss 7.5epss 0.02

    Uncontrolled recursion in Glob in io/fs before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a path which contains a large number of path separators.

  • CVE-2022-28131HigAug 10, 2022
    risk 0.49cvss 7.5epss 0.02

    Uncontrolled recursion in Decoder.Skip in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a deeply nested XML document.

  • CVE-2022-24675HigApr 20, 2022
    risk 0.49cvss 7.5epss 0.10

    encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data.

  • CVE-2022-28773HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Due to an uncontrolled recursion in SAP Web Dispatcher and SAP Internet Communication Manager, the application may crash, leading to denial of service, but can be restarted automatically.

  • CVE-2022-24921HigMar 5, 2022
    risk 0.49cvss 7.5epss 0.03

    regexp.Compile in Go before 1.16.15 and 1.17.x before 1.17.8 allows stack exhaustion via a deeply nested expression.

  • CVE-2021-42717HigDec 7, 2021
    risk 0.49cvss 7.5epss 0.03

    ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a moderately large (e.g., 300KB) HTTP request can occupy one of the…

  • CVE-2021-39929HigNov 19, 2021
    risk 0.49cvss 7.5epss 0.04

    Uncontrolled Recursion in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file

  • CVE-2021-38569HigAug 11, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows stack consumption via recursive function calls during the handling of XFA forms or link objects.