The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.
430 vulnerabilities with CWE-674
CVE-2020-10089
HIGH
GitLab 8.11-12.8.1 - Denial of Service via Recursive Feature Requests
CVSS 7.5
CVE-2019-10761
HIGH
vm2 <3.6.11 - Code Injection
CVSS 8.3
CVE-2019-20819
HIGH
Foxit Reader & PhantomPDF <9.7 - Memory Corruption
CVSS 7.5
CVE-2019-20815
HIGH
Foxit PhantomPDF <8.3.12 - Memory Corruption
CVSS 7.5
CVE-2019-8961
HIGH
FlexNet Publisher 11.16.2 - Unauthenticated Denial of Service via Recursive Message Handling
CVSS 7.5
CVE-2019-18936
HIGH
bloq/univalue < 1.0.5 - Denial of Service via UniValue::read() Error Handling
CVSS 7.5
CVE-2019-20395
MEDIUM
libyang <v1.0-r1 - Memory Corruption
CVSS 6.5
CVE-2019-20334
MEDIUM
Netwide Assembler <2.14.02 - Buffer Overflow
CVSS 5.5
CVE-2019-20198
MEDIUM
ezxml 0.8.3-0.8.6 - Uncontrolled Recursion in ezxml_ent_ok()
CVSS 6.5
CVE-2019-19645
MEDIUM
SQLite < 3.30.1 - Denial of Service via Infinite Recursion in ALTER TABLE
CVSS 5.5
CVE-2019-11937
HIGH
facebook/mcrouter < 0.41.0 - Denial of Service via Carbon Protocol Struct Input
CVSS 7.5
CVE-2019-18854
HIGH
Safe SVG < 1.9.4 - Denial of Service via Uncontrolled Recursion in xlink:href Attribute
CVSS 7.5
CVE-2019-18853
MEDIUM
ImageMagick 7.0.0-0-7.0.8-0 - Denial of Service via SVG XML Parser
CVSS 6.5
CVE-2019-18797
MEDIUM
libsass < 3.6.1 - Uncontrolled Recursion in Binary Expression Evaluation
CVSS 6.5
CVE-2019-17450
MEDIUM
GNU Binutils 2.32 - Denial of Service via Crafted ELF File
CVSS 6.5
CVE-2019-13124
HIGH
Foxit Reader <9.6.0.25114 - Memory Corruption
CVSS 7.5
CVE-2019-13123
HIGH
Foxit Reader <9.6.0.25114 - Memory Corruption
CVSS 7.5
CVE-2019-11779
MEDIUM
Eclipse Mosquitto <1.7 - Buffer Overflow
CVSS 6.5
CVE-2019-16163
HIGH
Oniguruma <6.9.3 - Memory Corruption
CVSS 7.5
CVE-2019-16088
MEDIUM
Xpdf 3.04 - Memory Corruption
CVSS 5.5
CVE-2019-15542
HIGH
ammonia < 2.1.0 - Uncontrolled Recursion during HTML DOM Tree Serialization
CVSS 7.5
CVE-2019-15144
MEDIUM
DjVuLibre 3.5.27 - Denial of Service via PBM Image Parsing
CVSS 5.5
CVE-2019-15118
MEDIUM
Linux kernel <5.2.9 - Buffer Overflow
CVSS 5.5
CVE-2019-14235
HIGH
Django 1.11-1.11.22, 2.1-2.1.10, 2.2-2.2.3 - Denial of Service via Recursion in uri_to_iri
CVSS 7.5
CVE-2019-13103
HIGH
denx/u-boot < 2019.04 - Denial of Service via Crafted DOS Partition Table
CVSS 7.1
Details
Vulnerabilities
430