CWE-834

Excessive Iteration

Parent: CWE-691 - Insufficient Control Flow Management

The product performs an iteration or loop without sufficiently limiting the number of times that the loop is executed.

107 vulnerabilities with CWE-834
CVE-2023-38200 HIGH
Keylime < 7.4.0 - Denial of Service via SSL Connection Exhaustion
CVSS 7.5
CVE-2023-30226 MEDIUM
rizin < 0.5.0 - Denial of Service via Crafted ELF File in get_gnu_verneed
CVSS 5.5
CVE-2023-1993 MEDIUM
Wireshark 3.6.0-3.6.12 and 4.0.0-4.0.4 - Denial of Service via LISP Dissector Large Loop
CVSS 6.3
CVE-2023-26513 HIGH
Apache Sling Resource Merger <1.4.2 - Info Disclosure
CVSS 7.5
CVE-2023-0411 MEDIUM
Wireshark 3.6.0-3.6.10 - Denial of Service via Excessive Iteration in Packet Dissectors
CVSS 6.3
CVE-2022-48939 LOW
Linux Kernel 5.6-5.10.102, 5.11-5.15.25, 5.16-5.16.11 - Denial of Service via BPF Batch Operations
CVSS 3.3
CVE-2022-3616 MEDIUM
cloudflare/octorpki < 1.4.4 - Denial of Service via CA Chain Length Exceeding Max Iterations
CVSS 5.4
CVE-2022-36083 MEDIUM
jose < 1.28.2, < 3.20.4, < 4.9.2 - Uncontrolled Resource Consumption via PBES2 Count Parameter
CVSS 5.3
CVE-2022-0585 MEDIUM
Wireshark 3.4.0-3.4.11 and 3.6.0-3.6.1 - Denial of Service via Large Loops in Protocol Dissectors
CVSS 4.3
CVE-2021-4021 HIGH
radare2 < 5.5.0 - Uncontrolled Resource Consumption via ELF64 MIPS Section Mapping
CVSS 7.5
CVE-2021-4190 HIGH
Wireshark 3.6.0 - Denial of Service via Kafka Dissector Excessive Iteration
CVSS 7.5
CVE-2021-43545 MEDIUM
Firefox < 95.0 - Denial of Service via Location API Loop
CVSS 6.5
CVE-2021-39924 HIGH
Wireshark 3.2.0-3.2.17 and 3.4.0-3.4.9 - Denial of Service via Bluetooth DHT Dissector
CVSS 7.5
CVE-2021-39923 HIGH
Wireshark 3.2.0-3.2.17 and 3.4.0-3.4.9 - Denial of Service via PNRP Dissector Large Loop
CVSS 7.5
CVE-2021-0687 MEDIUM
Android 8.1-11 - Denial of Service via Ellipsize Input Validation
CVSS 5.0
CVE-2021-39204 HIGH
Envoy < 1.16.4 and Pomerium < 0.14.8 - Denial of Service via HTTP/2 Stream Reset
CVSS 7.5
CVE-2021-32778 MEDIUM
Envoy 1.16.0-1.16.4 - Denial of Service via HTTP/2 Stream Reset
CVSS 5.8
CVE-2021-21565 MEDIUM
Dell PowerScale OneFS < 9.1.0.3 - Denial of Service via SmartConnect Error Condition
CVSS 5.3
CVE-2021-35515 HIGH
Apache Commons Compress 1.6-1.19 - Denial of Service via Crafted 7Z Archive
CVSS 7.5
CVE-2021-31812 MEDIUM
Apache PDFBox 2.0.0-2.0.23 - Denial of Service via Infinite Loop
CVSS 5.5
CVE-2021-3128 HIGH
ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U < 3.0.0.4.386.42095 - IPv6 Routing Loop DoS
CVSS 7.5
CVE-2021-3125 HIGH
TP-Link TL-XDR Series Firmware - Denial of Service via IPv6 Routing Loop
CVSS 7.5
CVE-2021-23270 HIGH
Gargoyle OS 1.12.0 - Excessive Network Traffic via IPv6 Routing Loop
CVSS 7.5
CVE-2021-28950 MEDIUM
Linux Kernel < 5.11.8 - Denial of Service via FUSE Bad Inode Retry Loop
CVSS 5.5
CVE-2021-27807 MEDIUM
Apache PDFBox <2.0.22 - Info Disclosure
CVSS 5.5
Details
Vulnerabilities 107