CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')

Parent: CWE-834 - Excessive Iteration

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

825 vulnerabilities with CWE-835
CVE-2019-19588 HIGH
Validators <0.12.6 - Info Disclosure
CVSS 7.5
CVE-2019-5097 HIGH
GoAhead <v5.0.1, v4.1.1, v3.6.5 - DoS
CVSS 7.5
CVE-2019-19451 MEDIUM
GNOME Dia <2019-11-27 - Info Disclosure
CVSS 5.5
CVE-2019-18455 HIGH
GitLab 11.0.0-12.4.0 - Denial of Service via Nested GraphQL Query Loop
CVSS 7.5
CVE-2019-19307 CRITICAL
Cesanta Mongoose 6.16 - Remote Denial of Service via Crafted MQTT Packet
CVSS 9.8
CVE-2019-2335 HIGH
Qualcomm Snapdragon Firmware - Denial of Service via Infinite Loop in Attach Reject Message Processing
CVSS 7.5
CVE-2019-18817 HIGH
Istio 1.3.0-1.3.4 - Denial of Service via Listener Filter Timeout Configuration
CVSS 7.5
CVE-2019-18836 HIGH
Envoy 1.12.0 - Denial of Service via Resource Loop with continue_on_listener_filters_timeout
CVSS 7.5
CVE-2019-0205 HIGH
Apache Thrift <= 0.12.0 - Denial of Service via Infinite Loop
CVSS 7.5
CVE-2019-18217 HIGH
ProFTPD < 1.3.6b and 1.3.7rc < 1.3.7rc2 - Unauthenticated Denial of Service via Long Command Handling
CVSS 7.5
CVE-2019-17349 MEDIUM
Xen < 4.12.1 - Denial of Service via LoadExcl or StoreExcl Operation
CVSS 5.5
CVE-2019-17350 MEDIUM
Xen < 4.12.1 - Denial of Service via Compare-and-Exchange Operation
CVSS 5.5
CVE-2019-12068 LOW
QEMU - Denial of Service via Infinite Loop in LSI SCSI Adapter Emulator
CVSS 3.8
CVE-2019-16413 HIGH
Linux Kernel < 5.0.4 - Denial of Service via 9p Filesystem i_size_write Infinite Loop
CVSS 7.5
CVE-2019-16319 HIGH
Wireshark 2.6.0-2.6.10 and 3.0.0-3.0.3 - Denial of Service via Gryphon Dissector Infinite Loop
CVSS 7.5
CVE-2019-12402 HIGH
Apache Commons Compress <1.19 - DoS
CVSS 7.5
CVE-2019-15702 HIGH
RIOT < 2019.07 - Denial of Service via TCP Option Parser Infinite Loop
CVSS 7.5
CVE-2019-15143 MEDIUM
DjVuLibre 3.5.27 - Denial of Service via Crafted Image File
CVSS 5.5
CVE-2019-14442 MEDIUM
Libav 12.3 - Denial of Service via Crafted File in mpc8_read_header
CVSS 6.5
CVE-2019-14372 MEDIUM
Libav 12.3 - Infinite Loop in wv_read_block_header()
CVSS 6.5
CVE-2019-14371 MEDIUM
Libav 12.3 - Denial of Service via Infinite Loop in mov_probe
CVSS 6.5
CVE-2019-1010189 MEDIUM
mgetty < 1.2.1 - Denial of Service via Infinite Loop in g3/g32pbm.c
CVSS 5.5
CVE-2019-14241 HIGH
HAProxy 1.4-1.9.8 - Denial of Service via HTX Client-Side Cookie Handling
CVSS 7.5
CVE-2019-14207 HIGH
Foxit PhantomPDF <8.3.11 - Use After Free
CVSS 7.5
CVE-2019-1010142 HIGH
scapy 2.4.0 - Denial of Service via RADIUS Attribute Packet List Field
CVSS 7.5
Details
Vulnerabilities 825