CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')

Parent: CWE-834 - Excessive Iteration

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

829 vulnerabilities with CWE-835
CVE-2017-14932 MEDIUM
GNU Binutils 2.29 - Denial of Service via Crafted ELF File
CVSS 5.5
CVE-2017-14929 HIGH
Poppler 0.59.0 - Denial of Service via Infinite Loop in Gfx.cc
CVSS 7.5
CVE-2017-14741 MEDIUM
ImageMagick 7.0.7-3 - Denial of Service via Crafted Font File
CVSS 6.5
CVE-2017-6267 MEDIUM
NVIDIA GPU Display Driver - Denial of Service via Kernel Mode Layer Handler
CVSS 5.5
CVE-2017-14339 HIGH
YADIFA < 2.2.6 - Denial of Service via DNS Packet Parser Infinite Loop
CVSS 7.5
CVE-2017-14519 HIGH
Poppler 0.59.0 - Infinite Loop via Repeated Gfx Display Operations
CVSS 7.5
CVE-2017-12997 CRITICAL
tcpdump < 4.9.2 - Denial of Service via LLDP Parser Infinite Loop
CVSS 9.8
CVE-2017-12995 CRITICAL
tcpdump < 4.9.2 - Denial of Service via DNS Parser Infinite Loop
CVSS 9.8
CVE-2017-12990 CRITICAL
tcpdump < 4.9.2 - Denial of Service via ISAKMP Parser Infinite Loop
CVSS 9.8
CVE-2017-12989 HIGH
tcpdump < 4.9.2 - Denial of Service via RESP Parser Infinite Loop
CVSS 7.5
CVE-2017-14229 HIGH
Jasper 2.0.13 - Denial of Service via Infinite Loop in jpc_dec_tileinit
CVSS 7.5
CVE-2017-14173 MEDIUM
ImageMagick 7.0.6-10 - Buffer Overflow
CVSS 6.5
CVE-2017-14058 MEDIUM
FFmpeg 2.4 and 3.3.3 - Denial of Service via Infinite Loop in HLS Playlist Reload
CVSS 6.5
CVE-2017-13767 HIGH
Wireshark 2.4.0 2.2.0-2.2.8 2.0.0-2.0.14 - Denial of Service via MSDP Dissector Infinite Loop
CVSS 7.5
CVE-2017-13756 MEDIUM
The Sleuth Kit 4.4.2 - Denial of Service via Infinite Recursion in dos_load_ext_table()
CVSS 5.5
CVE-2017-13728 HIGH
ncurses 6.0 - Denial of Service via Infinite Loop in next_char Function
CVSS 7.5
CVE-2017-12852 HIGH
numpy < 1.13.1 - Denial of Service via Empty Input to numpy.pad
CVSS 7.5
CVE-2017-11118 MEDIUM
OpenExif 2.1.4 - Denial of Service via Crafted JPG File
CVSS 5.5
CVE-2017-9258 MEDIUM
SoundTouch 1.9.2 - Denial of Service via Crafted WAV File
CVSS 5.5
CVE-2017-11627 MEDIUM
QPDF 6.0.0 - Denial of Service via Crafted File in PointerHolder
CVSS 5.5
CVE-2017-11626 MEDIUM
qpdf 6.0.0 - Denial of Service via Crafted File in QPDFTokenizer
CVSS 5.5
CVE-2017-11625 MEDIUM
qpdf 6.0.0 - Denial of Service via Infinite Loop in QPDF::resolveObjectsInStream
CVSS 5.5
CVE-2017-11624 MEDIUM
qpdf 6.0.0 - Denial of Service via Infinite Loop in QPDFTokenizer
CVSS 5.5
CVE-2017-9233 HIGH
libexpat < 2.2.0 - XML External Entity Injection via Malformed External Entity Definition
CVSS 7.5
CVE-2017-11523 MEDIUM
ImageMagick < 6.9.9-0 and 7.x through 7.0.6-1 - Denial of Service via Crafted TXT File
CVSS 6.5
Details
Vulnerabilities 829