CWE-674

Uncontrolled Recursion

Parent: CWE-834 - Excessive Iteration

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

430 vulnerabilities with CWE-674
CVE-2019-13955 MEDIUM
Mikrotik RouterOS < 6.44.5 - Authenticated Denial of Service via Recursive JSON Parsing
CVSS 6.5
CVE-2019-1010182 MEDIUM
yaml-rust < 0.4.0 - Denial of Service via YamlLoader::load_from_str Recursion
CVSS 6.5
CVE-2019-1010183 MEDIUM
serde-yaml 0.6.0-0.8.3 - Denial of Service via Uncontrolled Recursion in Deserialization Functions
CVSS 6.5
CVE-2019-13288 MEDIUM
Glyphandcog Xpdfreader - Denial of Service
CVSS 5.5
CVE-2019-13129 HIGH
Motorola router CX2L MWR04L 1.01 - Buffer Overflow
CVSS 7.5
CVE-2019-12295 HIGH
Wireshark <3.0.1, <2.6.8, <2.4.14 - DoS
CVSS 7.5
CVE-2019-12213 MEDIUM
FreeImage 3.18.0 - Denial of Service via TIFFReadDirectory Stack Exhaustion
CVSS 6.5
CVE-2019-12212 HIGH
FreeImage 3.18.0 - Denial of Service via JXR File Recursion in StreamCalcIFDSize
CVSS 7.5
CVE-2019-11413 HIGH
Artifex MuJS 1.0.5 - Buffer Overflow
CVSS 7.5
CVE-2019-11026 MEDIUM
Poppler 0.75.0 - Denial of Service via Infinite Recursion in FontInfoScanner
CVSS 6.5
CVE-2019-11024 MEDIUM
libsixel 1.8.2 - Uncontrolled Recursion in load_pnm Function
CVSS 5.5
CVE-2019-9904 MEDIUM
graphviz 2.40.1 - Stack Overflow via Recursive agclose Calls
CVSS 6.5
CVE-2019-9545 HIGH
Poppler 0.74.0 - Denial of Service via Recursive Function Call in JBIG2Stream::readTextRegion
CVSS 8.8
CVE-2019-9543 HIGH
Poppler 0.74.0 - Denial of Service via Recursive Function Call in JBIG2Stream
CVSS 8.8
CVE-2019-9192 HIGH
GNU C Library <2.29 - Uncontrolled Recursion
CVSS 7.5
CVE-2019-9144 HIGH
Exiv2 0.27 - Denial of Service via Infinite Recursion in BigTiffImage::printIFD
CVSS 8.8
CVE-2019-9143 HIGH
Exiv2 0.27 - Denial of Service via Infinite Recursion in Image::printTiffStructure
CVSS 8.8
CVE-2019-9071 MEDIUM
GNU Binutils - Denial of Service via Recursive Template Scope Counting
CVSS 5.5
CVE-2019-1003011 HIGH
Jenkins Token Macro Plugin <2.5 - Info Disclosure & DoS
CVSS 8.1
CVE-2019-0001 HIGH
Juniper Junos OS - Denial of Service via Malformed Packet in BBE-SMGD
CVSS 7.5
CVE-2019-6293 MEDIUM
flex 2.6.4 - Denial of Service via Recursive mark_beginning_as_normal Calls
CVSS 5.5
CVE-2019-6292 MEDIUM
yaml-cpp 0.6.2 - Denial of Service via Recursive Stack Exhaustion in SingleDocParser
CVSS 6.5
CVE-2019-6291 MEDIUM
Netwide Assembler < 2.14.02 - Denial of Service via Recursive Expression Parsing
CVSS 5.5
CVE-2019-6290 MEDIUM
Netwide Assembler (NASM) <2.14.02 - DoS
CVSS 5.5
CVE-2019-6285 MEDIUM
yaml-cpp 0.6.2 - Denial of Service via Crafted YAML File
CVSS 6.5
Details
Vulnerabilities 430