The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.
474 vulnerabilities with CWE-674
CVE-2024-27454
HIGH
orjson <3.9.15 - Stack-Based Buffer Overflow
CVSS 7.5
CVE-2024-25112
MEDIUM
Exiv2 0.28.0-0.28.1 - Denial of Service via Unbounded Recursion in QuickTimeVideo::multipleEntriesDecoder
CVSS 5.5
CVE-2024-0210
HIGH
Wireshark 4.2.0 - Denial of Service via Zigbee TLV Dissector
CVSS 7.8
CVE-2023-53655
MEDIUM
Linux Kernel 5.8-5.10.180 - Kernel Stack Overflow via Kprobe on __rcu_irq_enter_check_tick
CVSS 5.5
CVE-2023-53513
MEDIUM
Linux Kernel - Integer Overflow via NBD ioctl Argument
CVSS 5.5
CVE-2023-53428
MEDIUM
Linux Kernel - Denial of Service via Recursive Powercap Zone Parsing
CVSS 5.5
CVE-2023-52986
MEDIUM
Linux Kernel 5.7 - Infinite Recursion via BPF Sockmap Listener Clone
CVSS 5.5
CVE-2023-29001
HIGH
Contiki-NG RPL Source Routing - Stack Overflow Denial of Service
CVSS 7.5
CVE-2023-52761
MEDIUM
Linux Kernel 4.15-6.7 - Denial of Service via VMAP_STACK Overflow Detection Race Condition
CVSS 5.5
CVE-2023-51803
CRITICAL
LinuxServer.io Heimdall <2.5.7 - Info Disclosure
CVSS 9.8
CVE-2023-52079
MEDIUM
msgpackr < 1.10.1 - Denial of Service via Crafted MessagePack Message
CVSS 6.8
CVE-2023-50269
HIGH
Squid 2.6-2.7.STABLE9 3.1-5.9 6.0.1-6.5 - Denial of Service via Large X-Forwarded-For Header
CVSS 8.6
CVE-2023-50262
MEDIUM
dompdf < 2.0.4 - Uncontrolled Recursion via Chained SVG Image References
CVSS 5.3
CVE-2023-50251
MEDIUM
php-svg-lib <0.5.1 - Memory Corruption
CVSS 5.3
CVE-2023-49800
HIGH
nuxt-api-party < 0.22.1 - Denial of Service via Recursive Retry Logic
CVSS 7.5
CVE-2023-47163
HIGH
remarshal < 0.17.1 - Denial of Service via YAML Alias Node Expansion
CVSS 7.5
CVE-2023-31794
MEDIUM
MuPDF 1.21.1 - Denial of Service via Infinite Recursion in pdf_mark_list_push
CVSS 5.5
CVE-2023-4512
MEDIUM
Wireshark 4.0.0-4.0.6 - Denial of Service via CBOR Dissector
CVSS 5.3
CVE-2023-36632
HIGH
Python < 3.11.4 - Denial of Service via email.utils.parseaddr Recursion
CVSS 7.5
CVE-2023-2990
HIGH
Globalscape EFT Server < 8.1.0.16 - Denial of Service via Recursive Deflate Stream
CVSS 7.5
CVE-2023-31893
HIGH
Telefnica Brasil Vivo Play Firmware 2023.04.04.01.06.15 - Denial of Service via DNS Recursion
CVSS 7.5
CVE-2023-2664
LOW
Xpdf < 4.04 - Denial of Service via PDF Object Loop Recursion
CVSS 2.9
CVE-2023-2663
LOW
Xpdf < 4.04 - Denial of Service via Page Label Tree Recursion
CVSS 2.9
CVE-2023-24472
HIGH
OpenImageIO v2.4.7.1 - Denial of Service via FitsOutput::close()
CVSS 7.5
CVE-2023-1436
MEDIUM
Jettison < 1.5.4 - Denial of Service via Infinite Recursion in JSONArray Construction
CVSS 5.9
Details
Vulnerabilities
474