CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
Parent: CWE-834 - Excessive Iteration
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
825 vulnerabilities with CWE-835
CVE-2023-50120
MEDIUM
GPAC 2.3-DEV-rev636-gfbd7e13aa-master - Denial of Service via Infinite Loop in av1_uvlc Function
CVSS 5.5
CVE-2023-47997
MEDIUM
FreeImage 3.18.0 - Denial of Service via Infinite Loop in BitmapAccess.cpp
CVSS 6.5
CVE-2023-43511
HIGH
Qualcomm WLAN Firmware - Denial of Service via IPv6 Extension Header Parsing
CVSS 7.5
CVE-2023-50570
MEDIUM
seancfoley/ipaddress 5.1.0 - Denial of Service via Infinite Loop in IPAddressBitsDivision
CVSS 5.5
CVE-2023-51075
HIGH
hutool < 5.8.24 - Denial of Service via StrSplitter.splitByRegex Infinite Loop
CVSS 7.5
CVE-2023-50981
HIGH
Crypto++ < 8.9.0 - Denial of Service via ModularSquareRoot Infinite Loop
CVSS 7.5
CVE-2023-6245
HIGH
Candid 0.9.0-0.9.9 - Denial of Service via Empty Data Type Parsing
CVSS 7.5
CVE-2023-40458
HIGH
Sierra Wireless ALEOS < 4.9.8 - Denial of Service via ACEManager Infinite Loop
CVSS 7.5
CVE-2023-42815
LOW
Kyverno - Denial of Service via Malicious Notary Verifier Response
CVSS 3.1
CVE-2023-42814
LOW
Kyverno - Denial of Service in Notary Verifier
CVSS 3.1
CVE-2023-46737
LOW
sigstore/cosign < 2.2.1 - Denial of Service via High Number of Attestations
CVSS 3.1
CVE-2023-5825
MEDIUM
GitLab 16.2-16.3.5, 16.4-16.4.1, 16.5 - Denial of Service via CI/CD Component Path Manipulation
CVSS 6.5
CVE-2023-20083
HIGH
Cisco Firepower Threat Defense 6.2.3-6.2.3.18 - Unauthenticated Denial of Service via ICMPv6 Header Parsing
CVSS 8.6
CVE-2023-1718
HIGH
Bitrix24 22.0.300 - Unauthenticated Denial of Service via Crafted tmp_url Parameter
CVSS 7.5
CVE-2023-46250
MEDIUM
pypdf 3.7.0-3.16.4 - Denial of Service via Infinite Loop
CVSS 5.1
CVE-2023-44181
HIGH
Junos OS QFX5k DoS via Storm Control ICMPv6 Packet Handling
CVSS 7.5
CVE-2023-22325
MEDIUM
SoftEther VPN 4.41-9782-beta, 5.01.9674, 5.02 - Denial of Service via DCRegister DDNS_RPC_MAX_RECV_SIZE
CVSS 5.9
CVE-2023-43786
MEDIUM
libX11 < 1.8.7 - Denial of Service via PutSubImage Infinite Loop
CVSS 5.5
CVE-2023-45363
HIGH
MediaWiki < 1.35.12, 1.36.x-1.39.x < 1.39.5, 1.40.x < 1.40.1 - Denial of Service via Redirect and ConvertTitles Query
CVSS 7.5
CVE-2023-26151
MEDIUM
freeopcua/opcua-asyncio < 0.9.96 - Denial of Service via Malformed Packet
CVSS 5.3
CVE-2023-43645
MEDIUM
OpenFGA < 1.3.2 - Denial of Service via Circular Relationship Definitions
CVSS 5.9
CVE-2023-43761
HIGH
WithSecure Linux Protection 12.0 - Denial of Service via Infinite Loop
CVSS 7.5
CVE-2023-42525
HIGH
WithSecure Client Security 15 - Denial of Service via Infinite Loop in Scanning Engine
CVSS 7.5
CVE-2023-42524
HIGH
WithSecure Client Security 15 - Denial of Service via Infinite Loop in Scanning Engine
CVSS 7.5
CVE-2023-1108
HIGH
Redhat Build OF Quarkus < 2.2.24 - Infinite Loop
CVSS 7.5
Details
Vulnerabilities
825