CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')

Parent: CWE-834 - Excessive Iteration

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

829 vulnerabilities with CWE-835
CVE-2017-7542 MEDIUM
Linux kernel <= 4.12.3 - Denial of Service via Integer Overflow in ip6_find_1stfragopt
CVSS 5.5
CVE-2017-11478 MEDIUM
ImageMagick < 6.9.9-0 - Denial of Service via Malformed DJVU Image
CVSS 6.5
CVE-2017-11446 MEDIUM
ImageMagick 7.0.6-1 - Denial of Service via Infinite Loop in ReadPESImage
CVSS 6.5
CVE-2017-11410 HIGH
Wireshark <= 2.0.13 and 2.2.x <= 2.2.7 - Denial of Service via WBXML Dissector Infinite Loop
CVSS 7.5
CVE-2017-11406 HIGH
Wireshark 2.0.0-2.0.13 and 2.2.0-2.2.7 - Denial of Service via DOCSIS Dissector Infinite Loop
CVSS 7.5
CVE-2017-10986 HIGH
FreeRADIUS 3.x - Denial of Service via DHCP Attribute Parsing
CVSS 7.5
CVE-2017-10985 HIGH
FreeRADIUS 3.x - Denial of Service via Concat Attribute Infinite Loop
CVSS 7.5
CVE-2017-11338 MEDIUM
exiv2 - Denial of Service via Infinite Loop in Image::printIFDStructure
CVSS 6.5
CVE-2017-11171 MEDIUM
gnome-session < 2.29.92 - Denial of Service via ICE Connection Authentication Bypass
CVSS 5.5
CVE-2017-0685 MEDIUM
Android 6.0 6.0.1 7.0 7.1.1 7.1.2 - Denial of Service in Media Framework
CVSS 5.5
CVE-2017-9222 MEDIUM
Freeware Advanced Audio Decoder 2 <2.7 - DoS
CVSS 5.5
CVE-2017-9375 MEDIUM
QEMU < 2.8.1.1 - Denial of Service via USB xHCI Controller Emulator
CVSS 5.5
CVE-2017-9122 MEDIUM
libquicktime 1.2.4 - Denial of Service via Crafted MP4 File
CVSS 6.5
CVE-2017-8871 MEDIUM
libcroco 0.6.12 - Denial of Service via Crafted CSS File
CVSS 6.5
CVE-2017-9330 MEDIUM
QEMU < 2.9.0 - Denial of Service via USB OHCI Emulation Infinite Loop
CVSS 5.6
CVE-2017-9310 MEDIUM
QEMU < 2.8.1.1 - Denial of Service via e1000e NIC Descriptor Buffer Handling
CVSS 5.6
CVE-2017-9023 HIGH
strongSwan < 5.5.3 - Denial of Service via ASN.1 CHOICE Type Parsing
CVSS 7.5
CVE-2017-9461 MEDIUM
Samba < 4.4.10 and 4.5.x < 4.5.6 - Denial of Service via Dangling Symlink Handling
CVSS 6.5
CVE-2017-9358 HIGH
Asterisk Open Source <14.4.1 - Memory Corruption
CVSS 7.5
CVE-2017-9352 HIGH
Wireshark 2.0.0-2.0.12 - Denial of Service via Bazaar Dissector Infinite Loop
CVSS 7.5
CVE-2017-9349 HIGH
Wireshark 2.0.0-2.0.12 and 2.2.0-2.2.6 - Denial of Service via DICOM Dissector Infinite Loop
CVSS 7.5
CVE-2017-9346 HIGH
Wireshark 2.0.0-2.0.12 - Denial of Service via SoulSeek Dissector Infinite Loop
CVSS 7.5
CVE-2017-9345 HIGH
Wireshark 2.0.0-2.0.12 - Denial of Service via DNS Dissector Infinite Loop
CVSS 7.5
CVE-2017-9210 MEDIUM
QPDF 6.0.0 - Denial of Service via Crafted PDF Document
CVSS 5.5
CVE-2017-9209 MEDIUM
QPDF 6.0.0 - Denial of Service via Crafted PDF Document
CVSS 5.5
Details
Vulnerabilities 829