CWE-674

Uncontrolled Recursion

Parent: CWE-834 - Excessive Iteration

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

474 vulnerabilities with CWE-674
CVE-2018-20994 HIGH
trust-dns-proto <0.5.0-alpha.3 - Info Disclosure
CVSS 7.5
CVE-2018-20993 HIGH
yaml-rust < 0.4.1 - Uncontrolled Recursion during Deserialization
CVSS 7.5
CVE-2018-20822 MEDIUM
libsass 3.5.4 - Denial of Service via Uncontrolled Recursion
CVSS 6.5
CVE-2018-20821 MEDIUM
libsass < 3.5.5 - Denial of Service via Uncontrolled Recursion in Parser
CVSS 6.5
CVE-2018-20796 HIGH
glibc < 2.29 - Uncontrolled Recursion in posix/regexec.c
CVSS 7.5
CVE-2018-18484 MEDIUM
GNU libiberty <2.31 - Use After Free
CVSS 5.5
CVE-2018-18020 LOW
qpdf 8.2.1 - Denial of Service via Recursive UnparseObject Calls
CVSS 3.3
CVE-2018-16426 MEDIUM
OpenSC <0.19.0-rc1 - Use After Free
CVSS 4.3
CVE-2018-1158 MEDIUM
Mikrotik RouterOS <6.42.7,6.40.9 - Memory Corruption
CVSS 6.5
CVE-2018-1000618 CRITICAL
EOSIO/eos > f1545dd0ae2b77580c2236fdb70ae7138d2c7168 - Buffer Overflow
CVSS 9.8
CVE-2018-11597 MEDIUM
Espruino < 1.99 - Denial of Service via Stack Exhaustion in jsparse.c
CVSS 5.5
CVE-2018-11254 MEDIUM
PoDoFo 0.9.5 - Denial of Service via Excessive Recursion in PdfPagesTree::GetPageNode()
CVSS 5.5
CVE-2018-8015 HIGH
Apache ORC 1.0.0-1.4.3 - Uncontrolled Recursion via Malformed ORC File
CVSS 7.5
CVE-2018-9996 MEDIUM
GNU libiberty <2.30 - Use After Free
CVSS 5.5
CVE-2018-9918 HIGH
qpdf < 8.0.2 - Denial of Service via Uncontrolled Recursion in QPDFObjectHandle
CVSS 7.8
CVE-2018-9138 MEDIUM
GNU libiberty <2.31 - Use After Free
CVSS 5.5
CVE-2018-0739 MEDIUM
OpenSSL 1.0.2b-1.0.2n - Denial of Service via ASN.1 Recursive Type Parsing
CVSS 6.5
CVE-2018-6544 MEDIUM
Artifex MuPDF 1.12.0 - Denial of Service via Recursive Object Stream Reference
CVSS 5.5
CVE-2018-5759 MEDIUM
Artifex MuJS < 1.0.2 - Denial of Service via Uncontrolled Recursion in Binary Expression Parsing
CVSS 5.5
CVE-2018-6003 HIGH
GNU Libtasn1 < 4.13 - Denial of Service via Unlimited Recursion in BER Decoder
CVSS 7.5
CVE-2018-5772 MEDIUM
Exiv2 0.26 - Denial of Service via Crafted TIF File
CVSS 5.5
CVE-2017-10910 MEDIUM
MQTT.js 2.x.x < 2.15.0 - Denial of Service via PUBLISH Ticket Handling
CVSS 6.5
CVE-2017-16419 MEDIUM
Adobe Acrobat <2017.012.20098 - Stack Exhaustion
CVSS 6.5
CVE-2017-14861 MEDIUM
exiv2 - Denial of Service via Stack Consumption in stringFormat Function
CVSS 5.5
CVE-2017-12964 HIGH
libsass 3.4.5 - Denial of Service via Stack Consumption in Sass::Eval::operator()
CVSS 7.5
Details
Vulnerabilities 474