VYPR

CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')

BaseIncomplete

Description

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (909)

page 22 of 46
  • CVE-2019-18817HigNov 12, 2019
    risk 0.42cvss 7.5epss 0.01

    Istio 1.3.x before 1.3.5 allows Denial of Service because continue_on_listener_filters_timeout is set to True, a related issue to CVE-2019-18836.

  • CVE-2019-14442MedJul 30, 2019
    risk 0.42cvss 6.5epss 0.01

    In mpc8_read_header in libavformat/mpc8.c in Libav 12.3, an input file can result in an avio_seek infinite loop and hang, with 100% CPU consumption. Attackers could leverage this vulnerability to cause a denial of service via a crafted file.

  • CVE-2019-14372MedJul 28, 2019
    risk 0.42cvss 6.5epss 0.01

    In Libav 12.3, there is an infinite loop in the function wv_read_block_header() in the file wvdec.c.

  • CVE-2019-14371MedJul 28, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Libav 12.3. There is an infinite loop in the function mov_probe in the file libavformat/mov.c, related to offset and tag.

  • CVE-2019-13453MedJul 17, 2019
    risk 0.42cvss 6.5epss 0.02

    Zipios before 0.1.7 does not properly handle certain malformed zip archives and can go into an infinite loop, causing a denial of service. This is related to zipheadio.h:readUint32() and zipfile.cpp:Zipfile::Zipfile().

  • CVE-2019-6638MedJul 3, 2019
    risk 0.42cvss 6.5epss 0.02

    On BIG-IP 14.1.0-14.1.0.5 and 14.0.0-14.0.0.4, Malformed http requests made to an undisclosed iControl REST endpoint can lead to infinite loop of the restjavad process.

  • CVE-2018-5818HigFeb 20, 2019
    risk 0.42cvss 7.5epss 0.02

    An error within the "parse_rollei()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can be exploited to trigger an infinite loop.

  • CVE-2017-18361HigFeb 1, 2019
    risk 0.42cvss 7.5epss 0.02

    In Pylons Colander through 1.6, the URL validator allows an attacker to potentially cause an infinite loop thereby causing a denial of service via an unclosed parenthesis.

  • CVE-2019-6462MedJan 16, 2019
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in cairo 1.16.0. There is an infinite loop in the function _arc_error_normalized in the file cairo-arc.c, related to _arc_max_angle_for_tolerance_normalized.

  • CVE-2018-20021HigDec 19, 2018
    risk 0.42cvss 7.5epss 0.04

    LibVNC before commit c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c contains a CWE-835: Infinite loop vulnerability in VNC client code. Vulnerability allows attacker to consume excessive amount of resources like CPU and RAM

  • CVE-2018-20099MedDec 12, 2018
    risk 0.42cvss 6.5epss 0.02

    There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.

  • CVE-2017-15835MedDec 7, 2018
    risk 0.42cvss 6.5epss 0.00

    In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, While processing the RIC Data Descriptor IE in an artificially crafted 802.11 frame with IE length more than 255, an infinite loop may potentially occur resulting in a…

  • CVE-2018-19826MedDec 3, 2018
    risk 0.42cvss 6.5epss 0.01

    In inspect.cpp in LibSass 3.5.5, a high memory footprint caused by an endless loop (containing a Sass::Inspect::operator()(Sass::String_Quoted*) stack frame) may cause a Denial of Service via crafted sass input files with stray '&' or '/' characters. NOTE: Upstream comments…

  • CVE-2018-18915MedNov 3, 2018
    risk 0.42cvss 6.5epss 0.02

    There is an infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp in Exiv2 0.27-RC1. A crafted input will lead to a remote denial of service attack.

  • CVE-2018-6977MedOct 9, 2018
    risk 0.42cvss 6.5epss 0.00

    VMware ESXi (6.7, 6.5, 6.0), Workstation (15.x and 14.x) and Fusion (11.x and 10.x) contain a denial-of-service vulnerability due to an infinite loop in a 3D-rendering shader. Successfully exploiting this issue may allow an attacker with normal user privileges in the guest to…

  • CVE-2018-18024MedOct 7, 2018
    risk 0.42cvss 6.5epss 0.03

    In ImageMagick 7.0.8-13 Q16, there is an infinite loop in the ReadBMPImage function of the coders/bmp.c file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file.

  • CVE-2018-16646MedSep 6, 2018
    risk 0.42cvss 6.5epss 0.03

    In Poppler 0.68.0, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote attacker can leverage this for a DoS attack.

  • CVE-2018-14445MedJul 20, 2018
    risk 0.42cvss 6.5epss 0.01

    In Bento4 v1.5.1-624, AP4_File::ParseStream in Ap4File.cpp allows remote attackers to cause a denial of service (infinite loop) via a crafted MP4 file.

  • CVE-2018-14347MedJul 17, 2018
    risk 0.42cvss 6.5epss 0.02

    GNU Libextractor before 1.7 contains an infinite loop vulnerability in EXTRACTOR_mpeg_extract_method (mpeg_extractor.c).

  • CVE-2017-18273MedMay 18, 2018
    risk 0.42cvss 6.5epss 0.02

    In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-22, an infinite loop vulnerability was found in the function ReadTXTImage in coders/txt.c, which allows attackers to cause a denial of service (CPU exhaustion) via a crafted image file that is mishandled in a GetImageIndexInList call.