CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')

Parent: CWE-834 - Excessive Iteration

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

829 vulnerabilities with CWE-835
CVE-2018-18024 MEDIUM
ImageMagick 7.0.8-13 - Denial of Service via Crafted BMP File
CVSS 6.5
CVE-2018-17846 HIGH
golang/net < 2018-09-25 - Infinite Loop via Malformed HTML Table Parsing
CVSS 7.5
CVE-2018-8017 MEDIUM
Apache Tika <1.19 - Info Disclosure
CVSS 5.5
CVE-2018-17042 MEDIUM
dbf2txt <2012-07-19 - Info Disclosure
CVSS 5.5
CVE-2018-16646 MEDIUM
Poppler 0.68.0 - Denial of Service via Infinite Recursion in Parser::getObj()
CVSS 6.5
CVE-2018-14621 MEDIUM
libtirpc < 1.0.2-rc2 - Denial of Service via Infinite Loop
CVSS 5.3
CVE-2018-10938 MEDIUM
Linux Kernel 4.0-rc1-4.13-rc4 - Denial of Service via Crafted Network Packet in cipso_v4_optptr
CVSS 5.9
CVE-2018-15856 MEDIUM
xkbcommon < 0.8.1 - Denial of Service via Keymap Parser Infinite Loop
CVSS 5.5
CVE-2018-1999044 MEDIUM
Jenkins < 2.138 - Denial of Service via Infinite Loop in CronTab.java
CVSS 6.5
CVE-2018-14567 MEDIUM
libxml2 2.9.8 - Denial of Service via Crafted XML File with LZMA Decompression
CVSS 6.5
CVE-2018-11771 MEDIUM
Apache Commons Compress 1.7-1.17 - Denial of Service via Malformed ZIP Archive
CVSS 5.5
CVE-2018-1336 HIGH
Apache Tomcat 7.0.28-7.0.86, 8.0.0.RC1-8.0.51, 8.5.0-8.5.30, 9.0.0.M9-9.0.7 DoS via UTF-8 Decoder Infinite Loop
CVSS 7.5
CVE-2018-10912 MEDIUM
Keycloak < 4.0.0 - Authenticated Denial of Service via Session Replacement Infinite Loop
CVSS 4.9
CVE-2018-1999012 MEDIUM
FFmpeg <9807d3976be0e92e4ece3b4b1701be894cd7c2e1 - Infinite Loop
CVSS 6.5
CVE-2018-14445 MEDIUM
Bento4 1.5.1-624 - Denial of Service via Crafted MP4 File
CVSS 6.5
CVE-2018-14368 HIGH
Wireshark <2.6.1, <2.4.7, <2.2.15 - DoS
CVSS 7.5
CVE-2018-14341 HIGH
Wireshark <2.6.1,<2.4.7,<2.2.15 - DoS
CVSS 7.5
CVE-2018-14339 HIGH
Wireshark <2.6.1, <2.4.7, <2.2.15 - DoS
CVSS 7.5
CVE-2018-14347 MEDIUM
GNU Libextractor <1.7 - Infinite Loop
CVSS 6.5
CVE-2018-14051 HIGH
libwav < 2017-04-20 - Infinite Loop in wav_read Function
CVSS 7.5
CVE-2018-8036 MEDIUM
Apache PDFBox <2.0.11 - Memory Corruption
CVSS 6.5
CVE-2018-12913 HIGH
miniz 2.0.7 - Denial of Service via Infinite Loop in tinfl_decompress
CVSS 7.5
CVE-2018-12418 MEDIUM
junrar < 1.0.1 - Denial of Service via Corrupt RAR File Handling
CVSS 5.5
CVE-2018-12228 MEDIUM
Asterisk 15.x < 15.4.1 - Denial of Service via TCP/TLS Disconnect
CVSS 6.5
CVE-2018-11657 HIGH
ngiflib 0.4 - Denial of Service via Infinite Loop in DecodeGifImg and LoadGif
CVSS 7.5
Details
Vulnerabilities 829