CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
Parent: CWE-834 - Excessive Iteration
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
887 vulnerabilities with CWE-835
CVE-2023-1718
HIGH
Bitrix24 22.0.300 - Unauthenticated Denial of Service via Crafted tmp_url Parameter
CVSS 7.5
CVE-2023-46250
MEDIUM
pypdf 3.7.0-3.16.4 - Denial of Service via Infinite Loop
CVSS 5.1
CVE-2023-44181
HIGH
Junos OS QFX5k DoS via Storm Control ICMPv6 Packet Handling
CVSS 7.5
CVE-2023-22325
MEDIUM
SoftEther VPN 4.41-9782-beta, 5.01.9674, 5.02 - Denial of Service via DCRegister DDNS_RPC_MAX_RECV_SIZE
CVSS 5.9
CVE-2023-43786
MEDIUM
libX11 < 1.8.7 - Denial of Service via PutSubImage Infinite Loop
CVSS 5.5
CVE-2023-45363
HIGH
MediaWiki < 1.35.12, 1.36.x-1.39.x < 1.39.5, 1.40.x < 1.40.1 - Denial of Service via Redirect and ConvertTitles Query
CVSS 7.5
CVE-2023-26151
MEDIUM
freeopcua/opcua-asyncio < 0.9.96 - Denial of Service via Malformed Packet
CVSS 5.3
CVE-2023-43645
MEDIUM
OpenFGA < 1.3.2 - Denial of Service via Circular Relationship Definitions
CVSS 5.9
CVE-2023-43761
HIGH
WithSecure Linux Protection 12.0 - Denial of Service via Infinite Loop
CVSS 7.5
CVE-2023-42525
HIGH
WithSecure Client Security 15 - Denial of Service via Infinite Loop in Scanning Engine
CVSS 7.5
CVE-2023-42524
HIGH
WithSecure Client Security 15 - Denial of Service via Infinite Loop in Scanning Engine
CVSS 7.5
CVE-2023-1108
HIGH
Redhat Build OF Quarkus < 2.2.24 - Infinite Loop
CVSS 7.5
CVE-2023-3255
MEDIUM
QEMU < 8.0.3 - Authenticated Denial of Service via VNC ClientCutText Message Handling
CVSS 6.5
CVE-2023-4511
MEDIUM
Wireshark 3.6.0-3.6.15 4.0.0-4.0.7 - Denial of Service via BT SDP Dissector Infinite Loop
CVSS 5.3
CVE-2023-20200
HIGH
Cisco Firepower and UCS Fabric Interconnect Firmware - Authenticated Denial of Service via SNMP Request
CVSS 7.7
CVE-2023-20197
HIGH
Cisco Secure Endpoint - Denial of Service via HFS+ Filesystem Image Parser
CVSS 7.5
CVE-2023-30188
HIGH
ONLYOFFICE Document Server 4.0.3-7.3.2 - Denial of Service via Crafted JavaScript File
CVSS 7.5
CVE-2023-4010
MEDIUM
Linux Kernel - Denial of Service via USB Host Controller Driver Descriptor Handling
CVSS 4.6
CVE-2023-3748
LOW
FRRouting < 8.5 - Denial of Service via Malformed Babeld Unicast Hello Message
CVSS 3.5
CVE-2023-34966
HIGH
Samba < 4.16.11 - Denial of Service via Spotlight mdssvc RPC Packet Parsing
CVSS 7.5
CVE-2023-37748
MEDIUM
ngiflib - Denial of Service via Infinite Loop in DecodeGifImg
CVSS 5.5
CVE-2023-38197
HIGH
Qt <5.15.15, <6.2.10, <=6.5.3 - Info Disclosure
CVSS 7.5
CVE-2023-36807
MEDIUM
pypdf 2.10.5 - Denial of Service via Infinite Loop in PDF Metadata Extraction
CVSS 6.2
CVE-2023-20116
MEDIUM
Cisco Unified Communications Manager - Authenticated Denial of Service via AXL API Input Validation
CVSS 6.8
CVE-2023-36464
MEDIUM
pypdf < 3.9.0 - Denial of Service via Infinite Loop in Content Stream Parser
CVSS 6.2
Details
Vulnerabilities
887