CWE-674

Uncontrolled Recursion

Parent: CWE-834 - Excessive Iteration

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

430 vulnerabilities with CWE-674
CVE-2020-10089 HIGH
GitLab 8.11-12.8.1 - Denial of Service via Recursive Feature Requests
CVSS 7.5
CVE-2019-10761 HIGH
vm2 <3.6.11 - Code Injection
CVSS 8.3
CVE-2019-20819 HIGH
Foxit Reader & PhantomPDF <9.7 - Memory Corruption
CVSS 7.5
CVE-2019-20815 HIGH
Foxit PhantomPDF <8.3.12 - Memory Corruption
CVSS 7.5
CVE-2019-8961 HIGH
FlexNet Publisher 11.16.2 - Unauthenticated Denial of Service via Recursive Message Handling
CVSS 7.5
CVE-2019-18936 HIGH
bloq/univalue < 1.0.5 - Denial of Service via UniValue::read() Error Handling
CVSS 7.5
CVE-2019-20395 MEDIUM
libyang <v1.0-r1 - Memory Corruption
CVSS 6.5
CVE-2019-20334 MEDIUM
Netwide Assembler <2.14.02 - Buffer Overflow
CVSS 5.5
CVE-2019-20198 MEDIUM
ezxml 0.8.3-0.8.6 - Uncontrolled Recursion in ezxml_ent_ok()
CVSS 6.5
CVE-2019-19645 MEDIUM
SQLite < 3.30.1 - Denial of Service via Infinite Recursion in ALTER TABLE
CVSS 5.5
CVE-2019-11937 HIGH
facebook/mcrouter < 0.41.0 - Denial of Service via Carbon Protocol Struct Input
CVSS 7.5
CVE-2019-18854 HIGH
Safe SVG < 1.9.4 - Denial of Service via Uncontrolled Recursion in xlink:href Attribute
CVSS 7.5
CVE-2019-18853 MEDIUM
ImageMagick 7.0.0-0-7.0.8-0 - Denial of Service via SVG XML Parser
CVSS 6.5
CVE-2019-18797 MEDIUM
libsass < 3.6.1 - Uncontrolled Recursion in Binary Expression Evaluation
CVSS 6.5
CVE-2019-17450 MEDIUM
GNU Binutils 2.32 - Denial of Service via Crafted ELF File
CVSS 6.5
CVE-2019-13124 HIGH
Foxit Reader <9.6.0.25114 - Memory Corruption
CVSS 7.5
CVE-2019-13123 HIGH
Foxit Reader <9.6.0.25114 - Memory Corruption
CVSS 7.5
CVE-2019-11779 MEDIUM
Eclipse Mosquitto <1.7 - Buffer Overflow
CVSS 6.5
CVE-2019-16163 HIGH
Oniguruma <6.9.3 - Memory Corruption
CVSS 7.5
CVE-2019-16088 MEDIUM
Xpdf 3.04 - Memory Corruption
CVSS 5.5
CVE-2019-15542 HIGH
ammonia < 2.1.0 - Uncontrolled Recursion during HTML DOM Tree Serialization
CVSS 7.5
CVE-2019-15144 MEDIUM
DjVuLibre 3.5.27 - Denial of Service via PBM Image Parsing
CVSS 5.5
CVE-2019-15118 MEDIUM
Linux kernel <5.2.9 - Buffer Overflow
CVSS 5.5
CVE-2019-14235 HIGH
Django 1.11-1.11.22, 2.1-2.1.10, 2.2-2.2.3 - Denial of Service via Recursion in uri_to_iri
CVSS 7.5
CVE-2019-13103 HIGH
denx/u-boot < 2019.04 - Denial of Service via Crafted DOS Partition Table
CVSS 7.1
Details
Vulnerabilities 430