The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.
430 vulnerabilities with CWE-674
CVE-2020-36368
MEDIUM
Cesanta MJS 1.20.1 - Denial of Service via Crafted File
CVSS 5.5
CVE-2020-36367
MEDIUM
Cesanta MJS 1.20.1 - Denial of Service via Crafted File in parse_block
CVSS 5.5
CVE-2020-36366
MEDIUM
Cesanta MJS 1.20.1 - Denial of Service via Stack Overflow in parse_value
CVSS 5.5
CVE-2020-18392
MEDIUM
Cesanta MJS 1.20.1 - Buffer Overflow
CVSS 5.5
CVE-2020-1898
HIGH
HHVM <4.32.3, 4.33.0-4.62.0 - Use After Free
CVSS 7.5
CVE-2020-29566
MEDIUM
Xen < 4.14.0 - Denial of Service via Recursive De-Schedule/Re-Schedule
CVSS 5.5
CVE-2020-8285
HIGH
libcurl 7.21.0-7.73.0 - Uncontrolled Recursion via FTP Wildcard Match Parsing
CVSS 7.5
CVE-2020-26883
HIGH
Play Framework <2.9 - Info Disclosure
CVSS 7.5
CVE-2020-26882
HIGH
Play Framework <2.9 - Info Disclosure
CVSS 7.5
CVE-2020-28196
HIGH
MIT Kerberos <1.17.2, <1.18.x-1.18.3 - RCE
CVSS 7.5
CVE-2020-28242
MEDIUM
Asterisk Open Source <13.37.1,16.14.1,17.8.1,18.0.1 - DoS
CVSS 6.5
CVE-2020-9861
HIGH
Swift < 5.1.4 - Denial of Service via Malicious JSON Input
CVSS 7.5
CVE-2020-25219
HIGH
libproxy 0.4.0-0.4.15 - Denial of Service via Infinite HTTP Response Stream
CVSS 7.5
CVE-2020-12100
HIGH
Dovecot < 2.3.11.3 - Denial of Service via Deeply Nested MIME Parts
CVSS 7.5
CVE-2020-9243
MEDIUM
HUAWEI Mate 30 Firmware < 10.1.0.150(C00E136R5P3) - Denial of Service via Uncontrolled Recursion
CVSS 5.5
CVE-2020-16094
HIGH
Claws Mail <3.17.6 - Stack Consumption
CVSS 7.5
CVE-2020-15101
LOW
freewvs < 0.1.1 - Denial of Service via Deep Directory Recursion
CVSS 2.8
CVE-2020-5591
HIGH
XACK DNS < 1.7.18 - Denial of Service via Uncontrolled Recursion
CVSS 7.5
CVE-2020-13800
MEDIUM
QEMU 4.2.0 - Uncontrolled Recursion in ATI VGA mm_index Handling
CVSS 6.0
CVE-2020-13164
HIGH
Wireshark <3.2.4, <3.0.11, <2.6.17 - DoS
CVSS 7.5
CVE-2020-12825
HIGH
libcroco <= 0.6.13 - Uncontrolled Recursion in cr_parser_parse_any_core
CVSS 7.1
CVE-2020-10704
HIGH
Samba < 4.10.15 - Denial of Service via LDAP Request Handling
CVSS 7.5
CVE-2020-12243
HIGH
OpenLDAP < 2.4.50 - Denial of Service via Nested Boolean Search Filter
CVSS 7.5
CVE-2020-11647
HIGH
Wireshark <3.2.2,<3.0.9,<2.6.15 - DoS
CVSS 7.5
CVE-2020-6071
HIGH
libmicrodns 0.1.0 - Denial of Service via Recursive Compression Pointer in mDNS Message
CVSS 7.5
Details
Vulnerabilities
430