The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.
430 vulnerabilities with CWE-674
CVE-2018-6003
HIGH
GNU Libtasn1 < 4.13 - Denial of Service via Unlimited Recursion in BER Decoder
CVSS 7.5
CVE-2018-5772
MEDIUM
Exiv2 0.26 - Denial of Service via Crafted TIF File
CVSS 5.5
CVE-2017-10910
MEDIUM
MQTT.js 2.x.x < 2.15.0 - Denial of Service via PUBLISH Ticket Handling
CVSS 6.5
CVE-2017-16419
MEDIUM
Adobe Acrobat <2017.012.20098 - Stack Exhaustion
CVSS 6.5
CVE-2017-14861
MEDIUM
exiv2 - Denial of Service via Stack Consumption in stringFormat Function
CVSS 5.5
CVE-2017-12964
HIGH
libsass 3.4.5 - Denial of Service via Stack Consumption in Sass::Eval::operator()
CVSS 7.5
CVE-2017-11556
HIGH
libsass 3.4.5 - Denial of Service via Parser::advanceToNextToken Stack Consumption
CVSS 7.5
CVE-2017-11554
HIGH
libsass 3.4.5 - Denial of Service via Stack Consumption in Lex Function
CVSS 7.5
CVE-2017-11164
HIGH
PCRE 8.41 - Uncontrolled Recursion via OP_KETRMAX in pcre_exec.c
CVSS 7.5
CVE-2017-0692
MEDIUM
Android 4.4.4 5.0.2 5.1.1 6.0 6.0.1 7.0 7.1.1 7.1.2 - Denial of Service in Media Framework
CVSS 5.5
CVE-2017-9766
HIGH
Wireshark 2.2.7 - Denial of Service via PROFINET IO Data Recursion
CVSS 7.5
CVE-2017-9729
HIGH
uClibc 0.9.33.2 - Memory Corruption
CVSS 7.5
CVE-2017-9617
MEDIUM
Wireshark 2.2.7 - Memory Corruption
CVSS 5.5
CVE-2017-9616
MEDIUM
Wireshark 2.2.7 - Memory Corruption
CVSS 5.5
CVE-2017-7515
MEDIUM
poppler <= 0.55.0 - Denial of Service via Uncontrolled Recursion in pdfunite
CVSS 5.5
CVE-2017-9438
HIGH
YARA 3.5.0 - Denial of Service via Crafted Regex Rule
CVSS 7.5
CVE-2017-9304
HIGH
YARA 3.5.0 - Denial of Service via Regexp Rule Stack Consumption
CVSS 7.5
CVE-2017-8542
MEDIUM
Microsoft Malware Protection Engine < 1.1.13704.0 - Denial of Service via Crafted File Scan
CVSS 5.5
CVE-2017-8539
MEDIUM
Microsoft Malware Protection Engine < 1.1.13704.0 - Denial of Service via Crafted File Scan
CVSS 5.5
CVE-2017-8537
MEDIUM
Microsoft Malware Protection Engine - Denial of Service via Crafted File Scan
CVSS 5.5
CVE-2017-8536
MEDIUM
Microsoft Malware Protection Engine - Denial of Service via Crafted File Scan
CVSS 5.5
CVE-2017-8535
MEDIUM
Microsoft Malware Protection Engine - Denial of Service via Crafted File Scan
CVSS 5.5
CVE-2017-0886
MEDIUM
Nextcloud Server <9.0.55,10.0.2 - DoS
CVSS 6.5
CVE-2017-5839
HIGH
GStreamer < 1.10.2 - Denial of Service via Uncontrolled Recursion in WAVEFORMATEX Parsing
CVSS 7.5
CVE-2016-9597
HIGH
Ubuntu Linux - Denial of Service via Stack Overflow in libxml2
CVSS 7.5
Details
Vulnerabilities
430