CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')

Parent: CWE-834 - Excessive Iteration

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

887 vulnerabilities with CWE-835
CVE-2020-14447 HIGH
Mattermost Server < 5.23.0 - Denial of Service via Large Webhook Requests
CVSS 7.5
CVE-2020-12885 HIGH
Arm Mbed OS 5.15.3 - Denial of Service via CoAP Parser Infinite Loop
CVSS 7.5
CVE-2020-14040 HIGH
golang/text < 0.3.3 - Denial of Service via UTF-16 Decoder Infinite Loop
CVSS 7.5
CVE-2020-14398 HIGH
LibVNCServer < 0.9.13 - Denial of Service via Infinite Loop in TCP Connection Handling
CVSS 7.5
CVE-2020-0189 MEDIUM
Android 10 - Denial of Service via Infinite Loop in ihevcd_decode()
CVSS 6.5
CVE-2020-0184 MEDIUM
Android 10 - Denial of Service via Missing Bounds Check in ihevcd_ref_list()
CVSS 6.5
CVE-2020-0174 MEDIUM
Android 10 - Remote Denial of Service via Parse_ptbl Bounds Check Exhaustion
CVSS 6.5
CVE-2020-0172 MEDIUM
Android 10 - Remote Denial of Service via Missing Bounds Check in Parse_art
CVSS 6.5
CVE-2020-0171 MEDIUM
Android 10 - Denial of Service via Parse_lart Bounds Check Exhaustion
CVSS 6.5
CVE-2020-0170 MEDIUM
Android 10 - Remote Denial of Service via IMY_Event Bounds Check
CVSS 6.5
CVE-2020-0169 MEDIUM
Android 10 - Denial of Service via RTTTL_Event Bounds Check Exhaustion
CVSS 6.5
CVE-2020-13808 HIGH
Foxit Reader and PhantomPDF < 9.7.2 - Denial of Service via Crafted Cross-Reference Stream Data
CVSS 7.5
CVE-2020-13807 HIGH
Foxit Reader and PhantomPDF < 9.7.2 - Denial of Service via Circular Reference Mishandling
CVSS 7.5
CVE-2020-12663 HIGH
Unbound < 1.10.1 - Denial of Service via Malformed DNS Answer
CVSS 7.5
CVE-2020-12655 MEDIUM
Linux Kernel < 5.6.10 - Denial of Service via Crafted XFS Metadata
CVSS 5.5
CVE-2020-9489 MEDIUM
Apache Tika < 1.24.1 - Denial of Service via Crafted File in Multiple Parsers
CVSS 5.5
CVE-2020-1951 MEDIUM
Apache Tika 1.0-1.23 - Denial of Service via Crafted PSD File
CVSS 5.5
CVE-2020-10675 HIGH
jsonparser < 1.0.0 - Denial of Service via Delete Call
CVSS 7.5
CVE-2020-7046 HIGH
Dovecot 2.3.9-2.3.9.3 - Unauthenticated Denial of Service via Truncated UTF-8 Data
CVSS 7.5
CVE-2020-7920 HIGH
Percona Monitoring and Management (PMM) <2.2.1 - DoS
CVSS 7.5
CVE-2020-6855 MEDIUM
SOS JobScheduler 1.11 and 1.13.2 - Denial of Service via JOC Cockpit Housekeeping Job Parameterization
CVSS 6.5
CVE-2020-7595 HIGH
libxml2 2.9.10 - Denial of Service via Infinite Loop in xmlStringLenDecodeEntities
CVSS 7.5
CVE-2020-1600 MEDIUM
Juniper Junos OS - Unauthenticated Denial of Service via SNMP Request
CVSS 6.5
CVE-2019-25040 HIGH
Unbound < 1.9.5 - Denial of Service via Compressed Name in dname_pkt_copy
CVSS 7.5
CVE-2019-18796 MEDIUM
BASS Audio Library < 2.4.14.1 - Denial of Service via Crafted MP3 File
CVSS 6.5
Details
Vulnerabilities 887