CWE-674

Uncontrolled Recursion

Parent: CWE-834 - Excessive Iteration

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

430 vulnerabilities with CWE-674
CVE-2024-29904 HIGH
CodeIgniter < 4.4.7 - Denial of Service via Language Class
CVSS 7.5
CVE-2024-20311 HIGH
Cisco IOS - Unauthenticated Denial of Service via LISP Packet Handling
CVSS 8.6
CVE-2024-28244 MEDIUM
KaTeX 0.15.4-0.16.9 - Denial of Service via Unicode Subscript/Superscript Bypass
CVSS 6.5
CVE-2024-28243 MEDIUM
KaTeX 0.1.0-0.16.9 - Denial of Service via \edef Recursion Bypass
CVSS 6.5
CVE-2024-25111 HIGH
Squid 3.5.27-6.7 - Denial of Service via HTTP Chunked Decoder Uncontrolled Recursion
CVSS 8.6
CVE-2024-1899 MEDIUM
showdownjs < 2.1.0 - Denial of Service via Anchors Subparser
CVSS 5.3
CVE-2024-27454 HIGH
orjson <3.9.15 - Stack-Based Buffer Overflow
CVSS 7.5
CVE-2024-25112 MEDIUM
Exiv2 0.28.0-0.28.1 - Denial of Service via Unbounded Recursion in QuickTimeVideo::multipleEntriesDecoder
CVSS 5.5
CVE-2024-0210 HIGH
Wireshark 4.2.0 - Denial of Service via Zigbee TLV Dissector
CVSS 7.8
CVE-2023-53655 MEDIUM
Linux Kernel 5.8-5.10.180 - Kernel Stack Overflow via Kprobe on __rcu_irq_enter_check_tick
CVSS 5.5
CVE-2023-53513 MEDIUM
Linux Kernel - Integer Overflow via NBD ioctl Argument
CVSS 5.5
CVE-2023-53428 MEDIUM
Linux Kernel - Denial of Service via Recursive Powercap Zone Parsing
CVSS 5.5
CVE-2023-52986 MEDIUM
Linux Kernel 5.7 - Infinite Recursion via BPF Sockmap Listener Clone
CVSS 5.5
CVE-2023-29001 HIGH
Contiki-NG RPL Source Routing - Stack Overflow Denial of Service
CVSS 7.5
CVE-2023-52761 MEDIUM
Linux Kernel 4.15-6.7 - Denial of Service via VMAP_STACK Overflow Detection Race Condition
CVSS 5.5
CVE-2023-51803 CRITICAL
LinuxServer.io Heimdall <2.5.7 - Info Disclosure
CVSS 9.8
CVE-2023-52079 MEDIUM
msgpackr < 1.10.1 - Denial of Service via Crafted MessagePack Message
CVSS 6.8
CVE-2023-50269 HIGH
Squid 2.6-2.7.STABLE9 3.1-5.9 6.0.1-6.5 - Denial of Service via Large X-Forwarded-For Header
CVSS 8.6
CVE-2023-50262 MEDIUM
dompdf < 2.0.4 - Uncontrolled Recursion via Chained SVG Image References
CVSS 5.3
CVE-2023-50251 MEDIUM
php-svg-lib <0.5.1 - Memory Corruption
CVSS 5.3
CVE-2023-49800 HIGH
nuxt-api-party < 0.22.1 - Denial of Service via Recursive Retry Logic
CVSS 7.5
CVE-2023-47163 HIGH
remarshal < 0.17.1 - Denial of Service via YAML Alias Node Expansion
CVSS 7.5
CVE-2023-31794 MEDIUM
MuPDF 1.21.1 - Denial of Service via Infinite Recursion in pdf_mark_list_push
CVSS 5.5
CVE-2023-4512 MEDIUM
Wireshark 4.0.0-4.0.6 - Denial of Service via CBOR Dissector
CVSS 5.3
CVE-2023-36632 HIGH
Python < 3.11.4 - Denial of Service via email.utils.parseaddr Recursion
CVSS 7.5
Details
Vulnerabilities 430