CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')

Parent: CWE-834 - Excessive Iteration

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

825 vulnerabilities with CWE-835
CVE-2021-20257 MEDIUM
QEMU < 6.2.0 - Denial of Service via e1000 NIC Emulator Infinite Loop
CVSS 6.5
CVE-2021-3737 HIGH
Python >=3.6.0 <3.6.14 - Denial of Service via HTTP Response Handling
CVSS 7.5
CVE-2021-23567 HIGH
colors.js > 1.4.0 - Denial of Service via Infinite Loop in americanFlag Module
CVSS 7.5
CVE-2021-45445 HIGH
Unisys ClearPath MCP TCP/IP Networking Services 59.1, 60.0, and 62.0 - Infinite Loop
CVSS 7.5
CVE-2021-40111 MEDIUM
Apache James < 3.6.1 - Authenticated Denial of Service via Crafted IMAP APPEND and STATUS Commands
CVSS 6.5
CVE-2021-4185 HIGH
Wireshark 3.4.0-3.4.10 and 3.6.0 - Denial of Service via RTMPT Dissector Infinite Loop
CVSS 7.5
CVE-2021-4184 HIGH
Wireshark 3.4.0-3.4.10 and 3.6.0 - Denial of Service via BitTorrent DHT Dissector Infinite Loop
CVSS 7.5
CVE-2021-4182 HIGH
Wireshark 3.4.0-3.4.10 and 3.6.0 - Denial of Service via RFC 7468 Dissector
CVSS 7.5
CVE-2021-45257 MEDIUM
NASM 2.16rc0 - Infinite Loop via gpaste_tokens Function
CVSS 5.5
CVE-2021-44924 MEDIUM
gpac 1.1.0 - Denial of Service via Infinite Loop in gf_log
CVSS 5.5
CVE-2021-45297 MEDIUM
Gpac 1.0.1 - Infinite Loop in gf_get_bit_size
CVSS 5.5
CVE-2021-4044 HIGH
OpenSSL 3.0.0 - Infinite Loop via Certificate Verification Error Handling
CVSS 7.5
CVE-2021-20041 HIGH
SonicWall SMA 200/210/400/410/500v Firmware - Unauthenticated Denial of Service via Crafted HTTP Requests
CVSS 7.5
CVE-2021-3908 MEDIUM
cloudflare/octorpki < 1.3.0 - Uncontrolled Resource Consumption via Certificate Chain Depth
CVSS 5.9
CVE-2021-43172 HIGH
NLnet Labs Routinator <0.10.2 - DoS
CVSS 7.5
CVE-2021-41973 MEDIUM
Apache MINA < 2.0.22 - Denial of Service via Malformed HTTP Request
CVSS 6.5
CVE-2021-42715 MEDIUM
stb_image.h 1.33-2.27 - Denial of Service via Truncated HDR RLE Scanlines
CVSS 5.5
CVE-2021-31363 MEDIUM
Juniper Junos OS and Junos OS Evolved - Denial of Service via LDP FEC Handling
CVSS 6.5
CVE-2021-42260 HIGH
TinyXML < 2.6.2 - Denial of Service via Infinite Loop in TiXmlParsingData::Stamp
CVSS 7.5
CVE-2021-42084 MEDIUM
Zammad < 4.1.1 - Authenticated Denial of Service via Crafted Request Loop
CVSS 6.5
CVE-2021-42040 HIGH
MediaWiki < 1.36.2 - Denial of Service via Loops Extension Infinite Loop
CVSS 7.5
CVE-2021-29365 MEDIUM
Irfanview 4.57 - Denial of Service via Crafted BMP File in EFFECTS!AutoCrop_W
CVSS 5.5
CVE-2021-37146 HIGH
ros-comm < 1.4.11 - Denial of Service via Crafted XMLRPC Call
CVSS 7.5
CVE-2021-41079 HIGH
Apache Tomcat 8.5.0-8.5.63 9.0.0-M1-9.0.43 10.0.0-M1-10.0.2 - Denial of Service via TLS Packet Validation Bypass
CVSS 7.5
CVE-2021-40839 HIGH
rencode < 1.0.6 - Denial of Service via Malformed Typecode Decoding
CVSS 7.5
Details
Vulnerabilities 825