CWE-834

Excessive Iteration

Parent: CWE-691 - Insufficient Control Flow Management

The product performs an iteration or loop without sufficiently limiting the number of times that the loop is executed.

107 vulnerabilities with CWE-834
CVE-2020-35573 HIGH
PostSRSd < 1.10 - Denial of Service via Long Timestamp Tag in SRS Address
CVSS 7.5
CVE-2020-14303 HIGH
Samba < 4.10.17 - Denial of Service via Empty UDP Packet
CVSS 7.5
CVE-2020-0175 MEDIUM
Android 10 - Denial of Service via XMF_ReadNode Input Validation
CVSS 6.5
CVE-2020-0174 MEDIUM
Android 10 - Remote Denial of Service via Parse_ptbl Bounds Check Exhaustion
CVSS 6.5
CVE-2020-0172 MEDIUM
Android 10 - Remote Denial of Service via Missing Bounds Check in Parse_art
CVSS 6.5
CVE-2020-0171 MEDIUM
Android 10 - Denial of Service via Parse_lart Bounds Check Exhaustion
CVSS 6.5
CVE-2020-0170 MEDIUM
Android 10 - Remote Denial of Service via IMY_Event Bounds Check
CVSS 6.5
CVE-2020-0169 MEDIUM
Android 10 - Denial of Service via RTTTL_Event Bounds Check Exhaustion
CVSS 6.5
CVE-2020-8992 MEDIUM
Linux Kernel < 5.5.3 - Denial of Service via Crafted Journal Size
CVSS 5.5
CVE-2019-9376 MEDIUM
Android 8.0-9 - Denial of Service via Account Input Validation
CVSS 5.5
CVE-2019-12973 MEDIUM
OpenJPEG 2.3.1 - Denial of Service via Excessive Iteration in opj_t1_encode_cblks
CVSS 5.5
CVE-2019-3565 HIGH
Facebook Thrift < 2019.05.06.00 - Denial of Service via Malicious Container Fields
CVSS 7.5
CVE-2019-3564 HIGH
Facebook Thrift < 2019.03.04.00 - Denial of Service via Malicious Container Fields
CVSS 7.5
CVE-2019-3559 HIGH
Facebook Thrift < 2019.02.18.00 - Denial of Service via Malicious Container Fields
CVSS 7.5
CVE-2019-3558 HIGH
Facebook Thrift < 2019.02.18.00 - Denial of Service via Malicious Container Field Messages
CVSS 7.5
CVE-2019-3552 HIGH
Facebook Thrift < 2019.02.18.00 - Denial of Service via Malformed Container Fields
CVSS 7.5
CVE-2019-9547 MEDIUM
Storage Performance Development Kit < 19.01 - Partial Denial of Service via Circular Descriptor Chain
CVSS 5.3
CVE-2018-20805 MEDIUM
MongoDB 3.6.0-3.6.9 - Denial of Service via $elemMatch Query
CVSS 6.5
CVE-2018-18651 MEDIUM
Xpdf 4.00 - Denial of Service via Large Loop in AcroForm.cc
CVSS 5.5
CVE-2018-14342 HIGH
Wireshark <2.6.1, <2.4.7, <2.2.15 - DoS
CVSS 7.5
CVE-2018-11813 HIGH
libjpeg 9c - Denial of Service via Excessive Iteration in read_pixel
CVSS 7.5
CVE-2018-11507 MEDIUM
Free Lossless Image Format <0.3 - Memory Corruption
CVSS 6.5
CVE-2018-9261 HIGH
Wireshark 2.2.0-2.2.13 and 2.4.0-2.4.5 - Denial of Service via NBAP Dissector
CVSS 7.5
CVE-2018-9133 MEDIUM
ImageMagick 7.0.7-26 Q16 - Denial of Service via Excessive Iteration in TIFF Decoder
CVSS 6.5
CVE-2018-7323 HIGH
Wireshark 2.2.0-2.2.12 and 2.4.0-2.4.4 - Denial of Service via WCCP Packet Dissector
CVSS 7.5
Details
Vulnerabilities 107