CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')

Parent: CWE-834 - Excessive Iteration

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

825 vulnerabilities with CWE-835
CVE-2020-26575 HIGH
Wireshark < 3.2.7 - Denial of Service via Infinite Loop in FBZERO Dissector
CVSS 7.5
CVE-2020-25641 MEDIUM
Linux Kernel < 5.9-rc7 - Denial of Service via Zero-Length Biovec Request
CVSS 5.5
CVE-2020-15598 HIGH
OWASP ModSecurity 3.0.0-3.0.4 - Denial of Service via Regular Expression Handling
CVSS 7.5
CVE-2020-25625 MEDIUM
QEMU 5.0.0 - Infinite Loop via TD List in hw/usb/hcd-ohci.c
CVSS 5.3
CVE-2020-25574 HIGH
hyper/http < 0.1.20 - Denial of Service via Integer Overflow in HeaderMap::reserve()
CVSS 7.5
CVE-2020-12457 HIGH
wolfssl < 4.5.0 - Denial of Service via TLS 1.3 ChangeCipherSpec Message Processing
CVSS 7.5
CVE-2020-0247 MEDIUM
Android - Denial of Service via Uncaught Exception in Threshold::getHistogram
CVSS 5.5
CVE-2020-15654 MEDIUM
Firefox < 79.0 and Firefox ESR < 78.1 - Denial of Service via Infinite Loop with Custom CSS Cursor
CVSS 6.5
CVE-2020-16845 HIGH
GO < 1.13.15 - Infinite Loop
CVSS 7.5
CVE-2020-5761 HIGH
Grandstream HT800 Series Firmware < 1.0.17.5 - Unauthenticated Denial of Service via TR-069 Service
CVSS 7.5
CVE-2020-13935 HIGH
Apache Tomcat 7.0.27-7.0.104, 8.5.0-8.5.56, 9.0.0.M1-9.0.36, 10.0.0-M1-M6 DoS via WebSocket Frame Payload Length
CVSS 7.5
CVE-2020-15466 HIGH
Wireshark 3.2.0-3.2.4 - Denial of Service via GVCP Dissector Infinite Loop
CVSS 7.5
CVE-2020-14448 HIGH
Mattermost Server < 5.23.0 - Denial of Service via Automatic Direct Message Replies
CVSS 7.5
CVE-2020-14447 HIGH
Mattermost Server < 5.23.0 - Denial of Service via Large Webhook Requests
CVSS 7.5
CVE-2020-12885 HIGH
Arm Mbed OS 5.15.3 - Denial of Service via CoAP Parser Infinite Loop
CVSS 7.5
CVE-2020-14040 HIGH
golang/text < 0.3.3 - Denial of Service via UTF-16 Decoder Infinite Loop
CVSS 7.5
CVE-2020-14398 HIGH
LibVNCServer < 0.9.13 - Denial of Service via Infinite Loop in TCP Connection Handling
CVSS 7.5
CVE-2020-0189 MEDIUM
Android 10 - Denial of Service via Infinite Loop in ihevcd_decode()
CVSS 6.5
CVE-2020-0184 MEDIUM
Android 10 - Denial of Service via Missing Bounds Check in ihevcd_ref_list()
CVSS 6.5
CVE-2020-0174 MEDIUM
Android 10 - Remote Denial of Service via Parse_ptbl Bounds Check Exhaustion
CVSS 6.5
CVE-2020-0172 MEDIUM
Android 10 - Remote Denial of Service via Missing Bounds Check in Parse_art
CVSS 6.5
CVE-2020-0171 MEDIUM
Android 10 - Denial of Service via Parse_lart Bounds Check Exhaustion
CVSS 6.5
CVE-2020-0170 MEDIUM
Android 10 - Remote Denial of Service via IMY_Event Bounds Check
CVSS 6.5
CVE-2020-0169 MEDIUM
Android 10 - Denial of Service via RTTTL_Event Bounds Check Exhaustion
CVSS 6.5
CVE-2020-13808 HIGH
Foxit Reader and PhantomPDF < 9.7.2 - Denial of Service via Crafted Cross-Reference Stream Data
CVSS 7.5
Details
Vulnerabilities 825