CWE-835— Loop with Unreachable Exit Condition (Infinite Loop)
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.— MITRE CWE catalog
981 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-835page 11 of 20
- CVE-2021-20257MEDIUMCVSS 6.5EG 6.52022-03-16
An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descriptors in process_tx_desc if various descriptor fields are initialized with invalid values. This flaw allows a gu…
- CVE-2022-23641MEDIUMCVSS 6.5EG 6.52022-02-15
Discourse is an open source discussion platform. In versions prior to 2.8.1 in the `stable` branch, 2.9.0.beta2 in the `beta` branch, and 2.9.0.beta2 in the `tests-passed` branch, users can trigger a Denial of Service attack by posting a s…
- CVE-2022-23437MEDIUMCVSS 6.5EG 6.52022-01-24
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources…
- CVE-2021-40111MEDIUMCVSS 6.5EG 6.52022-01-04
In Apache James, while fuzzing with Jazzer the IMAP parsing stack, we discover that crafted APPEND and STATUS IMAP command could be used to trigger infinite loops resulting in expensive CPU computations and OutOfMemory exceptions. This can…
- CVE-2021-41973MEDIUMCVSS 6.5EG 6.52021-11-01
In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expe…
- CVE-2021-31363MEDIUMCVSS 6.5EG 6.52021-10-19
In an MPLS P2MP environment a Loop with Unreachable Exit Condition vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker to cause high load on RPD w…
- CVE-2021-42084MEDIUMCVSS 6.5EG 6.52021-10-07
An issue was discovered in Zammad before 4.1.1. An attacker with valid agent credentials may send a series of crafted requests that cause an endless loop and thus cause denial of service.
- CVE-2020-9307MEDIUMCVSS 6.5EG 6.52021-02-11
Hirschmann OS2, RSP, and RSPE devices before HiOS 08.3.00 allow a denial of service. An unauthenticated, adjacent attacker can cause an infinite loop on one of the HSR ring ports of the device. This effectively breaks the redundancy of the…
- CVE-2021-22161MEDIUMCVSS 6.5EG 6.52021-02-07
In OpenWrt 19.07.x before 19.07.7, when IPv6 is used, a routing loop can occur that generates excessive network traffic between an affected device and its upstream ISP's router. This occurs when a link prefix route points to a point-to-poi…
- CVE-2021-0221MEDIUMCVSS 6.5EG 6.52021-01-15
In an EVPN/VXLAN scenario, if an IRB interface with a virtual gateway address (VGA) is configured on a PE, a traffic loop may occur upon receipt of specific IP multicast traffic. The traffic loop will cause interface traffic to increase ab…
- CVE-2018-20803MEDIUMCVSS 6.5EG 6.52020-11-23
A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which loop indefinitely in mathematics processing while retaining locks. This issue affects MongoDB Server v4.0 versions prio…
- CVE-2019-18796MEDIUMCVSS 6.5EG 6.52020-10-16
The BASS Audio Library 2.4.14 under Windows is prone to a BASS_StreamCreateFile Denial of Service vulnerability (infinite loop) via a crafted .mp3 file. This weakness could allow attackers to consume excessive CPU and the application becom…
- CVE-2020-15654MEDIUMCVSS 6.5EG 6.52020-08-10
When in an endless loop, a website specifying a custom cursor using CSS could make it look like the user is interacting with the user interface, when they are not. This could lead to a perceived broken state, especially when interactions w…
- CVE-2019-20911MEDIUMCVSS 6.5EG 6.52020-07-16
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to denial of service in bit_calc_CRC in bits.c, related to a for loop.
- CVE-2020-0189MEDIUMCVSS 6.5EG 6.52020-06-11
In ihevcd_decode() of ihevcd_decode.c, there is possible resource exhaustion due to an infinite loop. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.P…
- CVE-2020-0184MEDIUMCVSS 6.5EG 6.52020-06-11
In ihevcd_ref_list() of ihevcd_ref_list.c, there is a possible infinite loop due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploita…
- CVE-2020-0174MEDIUMCVSS 6.5EG 6.52020-06-11
In Parse_ptbl of eas_mdls.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Produ…
- CVE-2020-0172MEDIUMCVSS 6.5EG 6.52020-06-11
In Parse_art of eas_mdls.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Produc…
- CVE-2020-0171MEDIUMCVSS 6.5EG 6.52020-06-11
In Parse_lart of eas_mdls.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Produ…
- CVE-2020-0170MEDIUMCVSS 6.5EG 6.52020-06-11
In IMY_Event of eas_imelody.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Pro…
- CVE-2020-0169MEDIUMCVSS 6.5EG 6.52020-06-11
In RTTTL_Event of eas_rtttl.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Pro…
- CVE-2020-6855MEDIUMCVSS 6.5EG 6.52020-02-06
A large or infinite loop vulnerability in the JOC Cockpit component of SOS JobScheduler 1.11 and 1.13.2 allows attackers to parameterize housekeeping jobs in a way that exhausts system resources and results in a denial of service.
- CVE-2015-5278MEDIUMCVSS 6.5EG 6.52020-01-23
The ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows attackers to cause a denial of service (infinite loop and instance crash) or possibly execute arbitrary code via vectors related to receiving packets.
- CVE-2015-5239MEDIUMCVSS 6.5EG 6.52020-01-23
Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop.
- CVE-2020-1600MEDIUMCVSS 6.5EG 6.52020-01-15
In a Point-to-Multipoint (P2MP) Label Switched Path (LSP) scenario, an uncontrolled resource consumption vulnerability in the Routing Protocol Daemon (RPD) in Juniper Networks Junos OS allows a specific SNMP request to trigger an infinite …
- CVE-2019-20201MEDIUMCVSS 6.5EG 6.52019-12-31
An issue was discovered in ezXML 0.8.3 through 0.8.6. The ezxml_parse_* functions mishandle XML entities, leading to an infinite loop in which memory allocations occur.
- CVE-2014-8561MEDIUMCVSS 6.5EG 6.52019-12-15
imagemagick 6.8.9.6 has remote DOS via infinite loop
- CVE-2019-19582MEDIUMCVSS 6.5EG 6.52019-12-11
An issue was discovered in Xen through 4.12.x allowing x86 guest OS users to cause a denial of service (infinite loop) because certain bit iteration is mishandled. In a number of places bitmaps are being used by the hypervisor to track cer…
- CVE-2015-5694MEDIUMCVSS 6.5EG 6.52019-11-22
Designate does not enforce the DNS protocol limit concerning record set sizes
- CVE-2019-14442MEDIUMCVSS 6.5EG 6.52019-07-30
In mpc8_read_header in libavformat/mpc8.c in Libav 12.3, an input file can result in an avio_seek infinite loop and hang, with 100% CPU consumption. Attackers could leverage this vulnerability to cause a denial of service via a crafted fil…
- CVE-2019-14372MEDIUMCVSS 6.5EG 6.52019-07-28
In Libav 12.3, there is an infinite loop in the function wv_read_block_header() in the file wvdec.c.
- CVE-2019-14371MEDIUMCVSS 6.5EG 6.52019-07-28
An issue was discovered in Libav 12.3. There is an infinite loop in the function mov_probe in the file libavformat/mov.c, related to offset and tag.
- CVE-2019-13453MEDIUMCVSS 6.5EG 6.52019-07-17
Zipios before 0.1.7 does not properly handle certain malformed zip archives and can go into an infinite loop, causing a denial of service. This is related to zipheadio.h:readUint32() and zipfile.cpp:Zipfile::Zipfile().
- CVE-2019-6638MEDIUMCVSS 6.5EG 6.52019-07-03
On BIG-IP 14.1.0-14.1.0.5 and 14.0.0-14.0.0.4, Malformed http requests made to an undisclosed iControl REST endpoint can lead to infinite loop of the restjavad process.
- CVE-2019-1000020MEDIUMCVSS 6.5EG 6.52019-02-04
libarchive version commit 5a98dcf8a86364b3c2c469c85b93647dfb139961 onwards (version v2.8.0 onwards) contains a CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in ISO9660 parser, archive_read_support_format_iso…
- CVE-2019-6462MEDIUMCVSS 6.5EG 6.52019-01-16
An issue was discovered in cairo 1.16.0. There is an infinite loop in the function _arc_error_normalized in the file cairo-arc.c, related to _arc_max_angle_for_tolerance_normalized.
- CVE-2018-20467MEDIUMCVSS 6.5EG 6.52018-12-26
In coders/bmp.c in ImageMagick before 7.0.8-16, an input file can result in an infinite loop and hang, with high CPU and memory consumption. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file.
- CVE-2018-17197MEDIUMCVSS 6.5EG 6.52018-12-24
A carefully crafted or corrupt sqlite file can cause an infinite loop in Apache Tika's SQLite3Parser in versions 1.8-1.19.1 of Apache Tika.
- CVE-2018-20099MEDIUMCVSS 6.5EG 6.52018-12-12
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.
- CVE-2018-1000864MEDIUMCVSS 6.5EG 6.52018-12-10
A denial of service vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in CronTab.java that allows attackers with Overall/Read permission to have a request handling thread enter an infinite loop.
- CVE-2018-5813MEDIUMCVSS 6.5EG 6.52018-12-07
An error within the "parse_minolta()" function (dcraw/dcraw.c) in LibRaw versions prior to 0.18.11 can be exploited to trigger an infinite loop via a specially crafted file.
- CVE-2017-15835MEDIUMCVSS 6.5EG 6.52018-12-07
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, While processing the RIC Data Descriptor IE in an artificially crafted 802.11 frame with IE length more than 255, an infinite loop m…
- CVE-2018-19826MEDIUMCVSS 6.5EG 6.52018-12-03
In inspect.cpp in LibSass 3.5.5, a high memory footprint caused by an endless loop (containing a Sass::Inspect::operator()(Sass::String_Quoted*) stack frame) may cause a Denial of Service via crafted sass input files with stray '&' or '/' …
- CVE-2018-14629MEDIUMCVSS 6.5EG 6.52018-11-28
A denial of service vulnerability was discovered in Samba's LDAP server before versions 4.7.12, 4.8.7, and 4.9.3. A CNAME loop could lead to infinite recursion in the server. An unprivileged local attacker could create such an entry, leadi…
- CVE-2018-19108MEDIUMCVSS 6.5EG 6.52018-11-08
In Exiv2 0.26, Exiv2::PsdImage::readMetadata in psdimage.cpp in the PSD image reader may suffer from a denial of service (infinite loop) caused by an integer overflow via a crafted PSD image file.
- CVE-2018-18915MEDIUMCVSS 6.5EG 6.52018-11-03
There is an infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp in Exiv2 0.27-RC1. A crafted input will lead to a remote denial of service attack.
- CVE-2018-6977MEDIUMCVSS 6.5EG 6.52018-10-09
VMware ESXi (6.7, 6.5, 6.0), Workstation (15.x and 14.x) and Fusion (11.x and 10.x) contain a denial-of-service vulnerability due to an infinite loop in a 3D-rendering shader. Successfully exploiting this issue may allow an attacker with n…
- CVE-2018-18024MEDIUMCVSS 6.5EG 6.52018-10-07
In ImageMagick 7.0.8-13 Q16, there is an infinite loop in the ReadBMPImage function of the coders/bmp.c file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file.
- CVE-2018-16646MEDIUMCVSS 6.5EG 6.52018-09-06
In Poppler 0.68.0, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote attacker can leverage this for a DoS attack.
- CVE-2018-1999044MEDIUMCVSS 6.5EG 6.52018-08-23
A denial of service vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in CronTab.java that allows attackers with Overall/Read permission to have a request handling thread enter an infinite loop.
Map vulnerabilities like CWE-835 to your infrastructure
EchelonGraph correlates every CVE — across CWE-835 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →