CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
Parent: CWE-834 - Excessive Iteration
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
887 vulnerabilities with CWE-835
CVE-2024-45506
HIGH
HAProxy <2.9.10, <3.0.4, <=3.1-dev6 - DoS
CVSS 7.5
CVE-2024-8088
HIGH
CPython - Zip File Path Traversal
CVE-2024-43828
MEDIUM
Linux Kernel 5.10-6.10.2 - Infinite Loop via Uninitialized Extent Status in Fast Commit Replay
CVSS 5.5
CVE-2024-43366
HIGH
zkvyper 1.3.12-1.5.3 - Infinite Loop via LLL IR Compilation
CVSS 7.5
CVE-2024-42246
MEDIUM
Linux Kernel 4.17-6.9.10 - Denial of Service via Infinite Loop in xs_tcp_setup_socket
CVSS 5.5
CVE-2024-42240
MEDIUM
Linux Kernel - Infinite Loop in BHI Mitigation #DB Handler
CVSS 5.5
CVE-2024-42358
MEDIUM
PDFio < 1.3.1 - Denial of Service via TTF Parser Infinite Loop
CVSS 6.2
CVE-2024-23352
HIGH
Qualcomm Snapdragon 855+/860 Mobile Platform (SM8150-AC) Firmware - Denial of Service via NAS ODAC Criteria Handling
CVSS 7.5
CVE-2024-41088
MEDIUM
Linux Kernel 5.10-6.1.96, 6.2-6.6.36, 6.7-6.9.7 - Denial of Service via Infinite Loop in mcp251xfd CAN Driver
CVSS 5.5
CVE-2024-40060
HIGH
go-chart < 2.1.1 - Denial of Service via Infinite Loop in drawCanvas()
CVSS 7.5
CVE-2024-40995
MEDIUM
Linux Kernel 4.19-6.9.7 - DoS via Infinite Loop in tcf_idr_check_alloc()
CVSS 5.5
CVE-2024-6614
MEDIUM
Firefox < 128 - Denial of Service via WASM Frame Iterator Loop
CVSS 4.3
CVE-2024-5569
MEDIUM
zipp < 3.19.1 - Denial of Service via Infinite Loop in Path Module Functions
CVSS 6.2
CVE-2024-6227
HIGH
aim 3.19.3 - Denial of Service via Remote Tracking Server Loop
CVSS 7.5
CVE-2024-36990
MEDIUM
Splunk Enterprise <9.2.2, <9.1.5, <9.0.10 & Splunk Cloud <9.2.2403.100 - Authenticated DoS via Datamodel/Web REST
CVSS 6.5
CVE-2024-36288
MEDIUM
Linux Kernel - Denial of Service via Infinite Loop in gss_free_in_token_pages
CVSS 5.5
CVE-2024-6061
LOW
GPAC 2.5-DEV-rev228-g11067ea92-master - Infinite Loop in MP4Box isoffin_process Function
CVSS 3.3
CVE-2024-5949
MEDIUM
Deep Sea Electronics DSE855 - Unauthenticated Denial of Service via Multipart Boundary Handling
CVSS 6.5
CVE-2024-36732
HIGH
OneFlow v0.9.1 - Denial of Service via Empty Array in tensordot
CVSS 7.5
CVE-2024-32976
HIGH
Envoy 1.18.0-1.27.5 - Denial of Service via Brotli Decompression Infinite Loop
CVSS 7.5
CVE-2024-35982
MEDIUM
Linux Kernel 3.13-6.8.6 - Infinite Loop in batman-adv Local TT Resize
CVSS 5.5
CVE-2024-35981
MEDIUM
Linux Kernel 5.18-6.1.89, 6.2-6.6.28, 6.7-6.8.6 - Denial of Service via RSS Key Handling
CVSS 5.5
CVE-2024-4854
MEDIUM
Fedora < 3.6.22 - Infinite Loop
CVSS 6.4
CVE-2024-24788
MEDIUM
Go standard library net 1.22.0-1.22.2 - Denial of Service via Malformed DNS Response
CVSS 5.9
CVE-2024-32886
MEDIUM
Vitess < 19.0.4, < 18.0.5, < 17.0.7 - Denial of Service via Infinite Loop in Query Execution
CVSS 4.9
Details
Vulnerabilities
887