The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.
474 vulnerabilities with CWE-674
CVE-2019-20395
MEDIUM
libyang <v1.0-r1 - Memory Corruption
CVSS 6.5
CVE-2019-20334
MEDIUM
Netwide Assembler <2.14.02 - Buffer Overflow
CVSS 5.5
CVE-2019-20198
MEDIUM
ezxml 0.8.3-0.8.6 - Uncontrolled Recursion in ezxml_ent_ok()
CVSS 6.5
CVE-2019-19645
MEDIUM
SQLite < 3.30.1 - Denial of Service via Infinite Recursion in ALTER TABLE
CVSS 5.5
CVE-2019-11937
HIGH
facebook/mcrouter < 0.41.0 - Denial of Service via Carbon Protocol Struct Input
CVSS 7.5
CVE-2019-18854
HIGH
Safe SVG < 1.9.4 - Denial of Service via Uncontrolled Recursion in xlink:href Attribute
CVSS 7.5
CVE-2019-18853
MEDIUM
ImageMagick 7.0.0-0-7.0.8-0 - Denial of Service via SVG XML Parser
CVSS 6.5
CVE-2019-18797
MEDIUM
libsass < 3.6.1 - Uncontrolled Recursion in Binary Expression Evaluation
CVSS 6.5
CVE-2019-17450
MEDIUM
GNU Binutils 2.32 - Denial of Service via Crafted ELF File
CVSS 6.5
CVE-2019-13124
HIGH
Foxit Reader <9.6.0.25114 - Memory Corruption
CVSS 7.5
CVE-2019-13123
HIGH
Foxit Reader <9.6.0.25114 - Memory Corruption
CVSS 7.5
CVE-2019-11779
MEDIUM
Eclipse Mosquitto <1.7 - Buffer Overflow
CVSS 6.5
CVE-2019-16163
HIGH
Oniguruma <6.9.3 - Memory Corruption
CVSS 7.5
CVE-2019-16088
MEDIUM
Xpdf 3.04 - Memory Corruption
CVSS 5.5
CVE-2019-15542
HIGH
ammonia < 2.1.0 - Uncontrolled Recursion during HTML DOM Tree Serialization
CVSS 7.5
CVE-2019-15144
MEDIUM
DjVuLibre 3.5.27 - Denial of Service via PBM Image Parsing
CVSS 5.5
CVE-2019-15118
MEDIUM
Linux kernel <5.2.9 - Buffer Overflow
CVSS 5.5
CVE-2019-14235
HIGH
Django 1.11-1.11.22, 2.1-2.1.10, 2.2-2.2.3 - Denial of Service via Recursion in uri_to_iri
CVSS 7.5
CVE-2019-13103
HIGH
denx/u-boot < 2019.04 - Denial of Service via Crafted DOS Partition Table
CVSS 7.1
CVE-2019-13955
MEDIUM
Mikrotik RouterOS < 6.44.5 - Authenticated Denial of Service via Recursive JSON Parsing
CVSS 6.5
CVE-2019-1010182
MEDIUM
yaml-rust < 0.4.0 - Denial of Service via YamlLoader::load_from_str Recursion
CVSS 6.5
CVE-2019-1010183
MEDIUM
serde-yaml 0.6.0-0.8.3 - Denial of Service via Uncontrolled Recursion in Deserialization Functions
CVSS 6.5
CVE-2019-13288
MEDIUM
Glyphandcog Xpdfreader - Denial of Service
CVSS 5.5
CVE-2019-13129
HIGH
Motorola router CX2L MWR04L 1.01 - Buffer Overflow
CVSS 7.5
CVE-2019-12295
HIGH
Wireshark <3.0.1, <2.6.8, <2.4.14 - DoS
CVSS 7.5
Details
Vulnerabilities
474