VYPR

CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')

BaseIncomplete

Description

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (909)

page 7 of 46
  • CVE-2023-20197HigAug 16, 2023
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for completion…

  • CVE-2023-30188HigAug 14, 2023
    risk 0.49cvss 7.5epss 0.02

    Memory Exhaustion vulnerability in ONLYOFFICE Document Server 4.0.3 through 7.3.2 allows remote attackers to cause a denial of service via crafted JavaScript file.

  • CVE-2020-35141HigAug 11, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in OFPQueueGetConfigReply in parser.py in Faucet SDN Ryu version 4.34, allows remote attackers to cause a denial of service (DoS) (infinite loop).

  • CVE-2020-35139HigAug 11, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in OFPBundleCtrlMsg in parser.py in Faucet SDN Ryu version 4.34, allows remote attackers to cause a denial of service (DoS) (infinite loop).

  • CVE-2023-38197HigJul 13, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion.

  • CVE-2022-37013HigMar 29, 2023
    risk 0.49cvss 7.5epss 0.01

    This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation OPC UA C++ Demo Server 1.7.6-537 [with vendor rollup]. Authentication is not required to exploit this vulnerability. The specific flaw exists within…

  • CVE-2022-25734HigFeb 12, 2023
    risk 0.49cvss 7.5epss 0.00

    Denial of service in modem due to missing null check while processing IP packets with padding

  • CVE-2022-48256HigJan 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Technitium DNS Server before 10.0 allows a self-CNAME denial-of-service attack in which a CNAME loop causes an answer to contain hundreds of records.

  • CVE-2022-33238HigDec 13, 2022
    risk 0.49cvss 7.5epss 0.00

    Transient DOS due to loop with unreachable exit condition in WLAN while processing an incoming FTM frames. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…

  • CVE-2022-33239HigNov 15, 2022
    risk 0.49cvss 7.5epss 0.00

    Transient DOS due to loop with unreachable exit condition in WLAN firmware while parsing IPV6 extension header. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…

  • CVE-2022-25742HigNov 15, 2022
    risk 0.49cvss 7.5epss 0.00

    Denial of service in modem due to infinite loop while parsing IGMPv2 packet from server in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music

  • CVE-2022-39052HigOct 17, 2022
    risk 0.49cvss 7.5epss 0.01

    An external attacker is able to send a specially crafted email (with many recipients) and trigger a potential DoS of the system

  • CVE-2021-37819HigSep 9, 2022
    risk 0.49cvss 7.5epss 0.01

    PDF Labs pdftk-java v3.2.3 was discovered to contain an infinite loop via the component /text/pdf/PdfReader.java.

  • CVE-2022-37768HigAug 18, 2022
    risk 0.49cvss 7.5epss 0.01

    libjpeg commit 281daa9 was discovered to contain an infinite loop via the component Frame::ParseTrailer.

  • CVE-2022-2833HigAug 16, 2022
    risk 0.49cvss 7.5epss 0.01

    Endless Infinite loop in Blender-thumnailing due to logical bugs.

  • CVE-2022-34661HigAug 10, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.15), Teamcenter V13.0 (All versions < V13.0.0.10), Teamcenter V13.1 (All versions < V13.1.0.10), Teamcenter V13.2 (All versions < V13.2.0.9), Teamcenter V13.3 (All versions < V13.3.0.5), Teamcenter…

  • CVE-2022-35724HigAug 9, 2022
    risk 0.49cvss 7.5epss 0.02

    It is possible to provide data to be read that leads the reader to loop in cycles endlessly, consuming CPU. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Users should update to apache-avro version 0.14.0 which…

  • CVE-2022-34862HigAug 4, 2022
    risk 0.49cvss 7.5epss 0.01

    In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when an LTM virtual server is configured to perform normalization, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note:…

  • CVE-2021-46828HigJul 20, 2022
    risk 0.49cvss 7.5epss 0.03

    In libtirpc before 1.3.3rc1, remote attackers could exhaust the file descriptors of a process that uses libtirpc because idle TCP connections are mishandled. This can, in turn, lead to an svc_run infinite loop without accepting new connections.

  • CVE-2022-30634HigJul 15, 2022
    risk 0.49cvss 7.5epss 0.02

    Infinite loop in Read in crypto/rand before Go 1.17.11 and Go 1.18.3 on Windows allows attacker to cause an indefinite hang by passing a buffer larger than 1 << 32 - 1 bytes.