CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
Parent: CWE-834 - Excessive Iteration
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
887 vulnerabilities with CWE-835
CVE-2025-38727
MEDIUM
Linux Kernel - Denial of Service via Infinite Loop in netlink_unicast()
CVSS 5.5
CVE-2025-38692
MEDIUM
Linux Kernel 5.7-6.6.102, 6.7-6.12.42, 6.13-6.15.10, 6.16-6.16.1 - Denial of Service via exFAT Cluster Chain Loop
CVSS 5.5
CVE-2025-38649
MEDIUM
Linux Kernel 6.14-6.15.9, 6.16.0 - Denial of Service via Coresight Infinite Loop
CVSS 5.5
CVE-2025-38588
MEDIUM
Linux Kernel - Infinite Loop in rt6_nlmsg_size() via fib6_siblings List Traversal
CVSS 5.5
CVE-2025-38587
MEDIUM
Linux Kernel - Infinite Loop in fib6_info_uses_dev()
CVSS 5.5
CVE-2025-51986
HIGH
cwalter-at freemodbus <2018-09-12 - DoS
CVSS 7.5
CVE-2025-20253
HIGH
Cisco Adaptive Security Appliance (ASA) Software - Denial of Service via IKEv2 Packet Processing
CVSS 8.6
CVE-2025-20243
HIGH
Cisco Secure Firewall ASA/FTD - DoS
CVSS 8.6
CVE-2025-20217
HIGH
Cisco Firepower Threat Defense Software - Denial of Service via Snort 3 Packet Inspection
CVSS 8.6
CVE-2025-20136
HIGH
Cisco ASA Software Unauthenticated DoS via NAT DNS Inspection Infinite Loop
CVSS 8.6
CVE-2025-7054
MEDIUM
Cloudflare quiche 0.15.0-0.24.5 - Unauthenticated Denial of Service via RETIRE_CONNECTION_ID Frame Infinite Loop
CVSS 6.5
CVE-2025-8194
HIGH
CPython TarFile Extraction Infinite Loop Vulnerability
CVSS 7.5
CVE-2025-53015
HIGH
ImageMagick 7.1.1-7 - Denial of Service via Infinite Loop in XMP File Conversion
CVSS 7.5
CVE-2025-53628
HIGH
cpp-httplib <0.20.1 - Memory Corruption
CVSS 8.8
CVE-2025-42954
LOW
SAP NetWeaver Business Warehouse CCAW - DoS
CVSS 2.7
CVE-2025-2962
HIGH
Zephyr < 4.1.0 - Denial of Service via DNS Infinite Loop
CVSS 7.5
CVE-2025-6365
MEDIUM
HobbesOSR Kitten < 2023-05-18 - Denial of Service via set_pte_at Function
CVSS 5.7
CVE-2025-0673
HIGH
GitLab CE/EE <17.10.8-18.0.2 - Open Redirect
CVSS 7.5
CVE-2025-48879
MEDIUM
OctoPrint <= 1.11.1 - Unauthenticated Denial of Service via Malformed Multipart Form Data
CVSS 6.5
CVE-2025-30145
HIGH
GeoServer <2.27.0-2.26.3-2.25.7 - DoS
CVSS 7.5
CVE-2025-5399
HIGH
curl 8.13.0-8.14.1 - Denial of Service via WebSocket Packet Processing
CVSS 7.5
CVE-2025-38001
HIGH
Linux Kernel 5.0.1-6.15.0 Use-After-Free and Infinite Loop via HFSC and NETEM
CVSS 7.8
CVE-2025-37859
MEDIUM
Linux Kernel 5.3.18-5.3.99 - Infinite Loop in Page Pool Release Retry
CVSS 5.5
CVE-2025-3857
HIGH
Amazon.IonDotnet < 1.3.1 - Denial of Service via RawBinaryReader Binary Deserialization
CVSS 7.5
CVE-2025-32947
HIGH
PeerTube < 7.1.1 - Denial of Service via ActivityPub Inbox Endpoint
CVSS 7.5
Details
Vulnerabilities
887