CWE-674

Uncontrolled Recursion

Parent: CWE-834 - Excessive Iteration

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

430 vulnerabilities with CWE-674
CVE-2021-36154 HIGH
gRPC Swift <= 1.1.1 - Denial of Service via HTTP/2 Frame Message Flood
CVSS 7.5
CVE-2021-28210 HIGH
EDK II < 202008 - Uncontrolled Recursion in DxeCore
CVSS 7.8
CVE-2021-3530 HIGH
GNU Binutils <2.36 - Memory Corruption
CVSS 7.5
CVE-2021-31525 MEDIUM
GO < 1.15.12 - Denial of Service
CVSS 5.9
CVE-2021-30471 MEDIUM
PoDoFo 0.9.7 - Stack Overflow via Uncontrolled Recursion in PdfNamesTree::AddToDictionary
CVSS 5.5
CVE-2021-30470 MEDIUM
PoDoFo 0.9.7 - Stack Overflow via Uncontrolled Recursion in PdfTokenizer
CVSS 5.5
CVE-2021-28903 HIGH
libyang <= 1.0.225 - Denial of Service via lyxml_parse_mem() Recursion
CVSS 7.5
CVE-2021-27432 HIGH
OPC Foundation UA <1.4.365.48 - Buffer Overflow
CVSS 7.5
CVE-2021-27434 HIGH
Unified-automation .net Based Opc UA Client/server SDK < 3.0.7 - Information Disclosure
CVSS 7.5
CVE-2021-29615 LOW
TensorFlow <2.5.0 - Buffer Overflow
CVSS 2.5
CVE-2021-29591 HIGH
TensorFlow < 2.1.4 - Denial of Service via Infinite Loop in TFlite Graph Evaluation
CVSS 7.3
CVE-2021-21359 MEDIUM
TYPO3 <9.5.25, 10.4.14, 11.1.1 - DoS
CVSS 5.9
CVE-2021-20255 MEDIUM
QEMU - Denial of Service via eepro100 i8255x Device Emulator Recursion
CVSS 5.5
CVE-2021-28040 HIGH
OSSEC 3.6.0 - Denial of Service via Uncontrolled Recursion in os_xml.c
CVSS 7.5
CVE-2020-23804 HIGH
poppler 0.89.0 - Denial of Service via Uncontrolled Recursion
CVSS 7.5
CVE-2020-36691 MEDIUM
Linux Kernel < 5.8 - Denial of Service via Unbounded Recursion in Netlink Policy
CVSS 5.5
CVE-2020-18898 MEDIUM
Exiv2 0.27 - Denial of Service via Stack Exhaustion in printIFDStructure
CVSS 6.5
CVE-2020-20213 MEDIUM
Mikrotik RouterOs 6.44.5 - Authenticated Denial of Service via Stack Exhaustion in /nova/bin/net
CVSS 6.5
CVE-2020-36375 MEDIUM
Cesanta MJS 1.20.1 - Denial of Service via Parse Equality Stack Overflow
CVSS 5.5
CVE-2020-36374 MEDIUM
Cesanta MJS 1.20.1 - Denial of Service via Stack Overflow in parse_comparison
CVSS 5.5
CVE-2020-36373 MEDIUM
Cesanta MJS 1.20.1 - Denial of Service via Stack Overflow in parse_shifts
CVSS 5.5
CVE-2020-36372 MEDIUM
Cesanta MJS 1.20.1 - Denial of Service via Parse Plus Minus
CVSS 5.5
CVE-2020-36371 MEDIUM
Cesanta MJS 1.20.1 - Denial of Service via Stack Overflow in parse_mul_div_rem
CVSS 5.5
CVE-2020-36370 MEDIUM
Cesanta MJS 1.20.1 - Denial of Service via Stack Overflow in parse_unary
CVSS 5.5
CVE-2020-36369 MEDIUM
Cesanta MJS 1.20.1 - Denial of Service via Crafted File
CVSS 5.5
Details
Vulnerabilities 430