CWE-674

Uncontrolled Recursion

Parent: CWE-834 - Excessive Iteration

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

474 vulnerabilities with CWE-674
CVE-2017-11556 HIGH
libsass 3.4.5 - Denial of Service via Parser::advanceToNextToken Stack Consumption
CVSS 7.5
CVE-2017-11554 HIGH
libsass 3.4.5 - Denial of Service via Stack Consumption in Lex Function
CVSS 7.5
CVE-2017-11164 HIGH
PCRE 8.41 - Uncontrolled Recursion via OP_KETRMAX in pcre_exec.c
CVSS 7.5
CVE-2017-0692 MEDIUM
Android 4.4.4 5.0.2 5.1.1 6.0 6.0.1 7.0 7.1.1 7.1.2 - Denial of Service in Media Framework
CVSS 5.5
CVE-2017-9766 HIGH
Wireshark 2.2.7 - Denial of Service via PROFINET IO Data Recursion
CVSS 7.5
CVE-2017-9729 HIGH
uClibc 0.9.33.2 - Memory Corruption
CVSS 7.5
CVE-2017-9617 MEDIUM
Wireshark 2.2.7 - Memory Corruption
CVSS 5.5
CVE-2017-9616 MEDIUM
Wireshark 2.2.7 - Memory Corruption
CVSS 5.5
CVE-2017-7515 MEDIUM
poppler <= 0.55.0 - Denial of Service via Uncontrolled Recursion in pdfunite
CVSS 5.5
CVE-2017-9438 HIGH
YARA 3.5.0 - Denial of Service via Crafted Regex Rule
CVSS 7.5
CVE-2017-9304 HIGH
YARA 3.5.0 - Denial of Service via Regexp Rule Stack Consumption
CVSS 7.5
CVE-2017-8542 MEDIUM
Microsoft Malware Protection Engine < 1.1.13704.0 - Denial of Service via Crafted File Scan
CVSS 5.5
CVE-2017-8539 MEDIUM
Microsoft Malware Protection Engine < 1.1.13704.0 - Denial of Service via Crafted File Scan
CVSS 5.5
CVE-2017-8537 MEDIUM
Microsoft Malware Protection Engine - Denial of Service via Crafted File Scan
CVSS 5.5
CVE-2017-8536 MEDIUM
Microsoft Malware Protection Engine - Denial of Service via Crafted File Scan
CVSS 5.5
CVE-2017-8535 MEDIUM
Microsoft Malware Protection Engine - Denial of Service via Crafted File Scan
CVSS 5.5
CVE-2017-0886 MEDIUM
Nextcloud Server <9.0.55,10.0.2 - DoS
CVSS 6.5
CVE-2017-5839 HIGH
GStreamer < 1.10.2 - Denial of Service via Uncontrolled Recursion in WAVEFORMATEX Parsing
CVSS 7.5
CVE-2016-9597 HIGH
Ubuntu Linux - Denial of Service via Stack Overflow in libxml2
CVSS 7.5
CVE-2016-10707 HIGH
jQuery 3.0.0-rc.1 - Denial of Service via Mixed-Case Boolean Attribute Recursion
CVSS 7.5
CVE-2016-4425 MEDIUM
jansson < 2.7 - Denial of Service via Deep Recursion in JSON Parser
CVSS 6.5
CVE-2016-3627 HIGH
libxml2 <2.9.3 - DoS
CVSS 7.5
CVE-2007-3409 HIGH
Net::DNS < 0.60 - Denial of Service via Malformed Compressed DNS Packet
CVSS 7.5
CVE-2007-1285 HIGH
PHP 4.x < 4.4.7 and 5.x < 5.2.2 - Denial of Service via Deeply Nested Arrays
CVSS 7.5
Details
Vulnerabilities 474