CWE-835— Loop with Unreachable Exit Condition (Infinite Loop)
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.— MITRE CWE catalog
981 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-835page 5 of 20
- CVE-2023-51075HIGHCVSS 7.5EG 7.52023-12-27
hutool-core v5.8.23 was discovered to contain an infinite loop in the StrSplitter.splitByRegex function. This vulnerability allows attackers to cause a Denial of Service (DoS) via manipulation of the first two parameters.
- CVE-2023-50981HIGHCVSS 7.5EG 7.52023-12-18
ModularSquareRoot in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (infinite loop) via crafted DER public-key data associated with squared odd numbers, such as the square of 268995137513890432434389773…
- CVE-2023-6245HIGHCVSS 7.5EG 7.52023-12-08
The Candid library causes a Denial of Service while parsing a specially crafted payload with 'empty' data type. For example, if the payload is `record { * ; empty }` and the canister interface expects `record { * }` then the Rust candid …
- CVE-2023-40458HIGHCVSS 7.5EG 7.52023-11-29
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Sierra Wireless, Inc ALEOS could potentially allow a remote attacker to trigger a Denial of Service (DoS) condition for ACEManager without impairing other router fun…
- CVE-2023-1718HIGHCVSS 7.5EG 7.52023-11-01
Improper file stream access in /desktop_app/file.ajax.php?action=uploadfile in Bitrix24 22.0.300 allows unauthenticated remote attackers to cause denial-of-service via a crafted "tmp_url".
- CVE-2023-44181HIGHCVSS 7.5EG 7.52023-10-13
An Improperly Implemented Security Check for Standard vulnerability in storm control of Juniper Networks Junos OS QFX5k devices allows packets to be punted to ARP queue causing a l2 loop resulting in a DDOS violations and DDOS syslog. Th…
- CVE-2023-45363HIGHCVSS 7.5EG 7.52023-10-09
An issue was discovered in ApiPageSet.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. It allows attackers to cause a denial of service (unbounded loop and RequestTimeoutException) when queryi…
- CVE-2023-43761HIGHCVSS 7.5EG 7.52023-09-22
Certain WithSecure products allow Denial of Service (infinite loop). This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, …
- CVE-2023-42525HIGHCVSS 7.5EG 7.52023-09-18
Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements End…
- CVE-2023-42524HIGHCVSS 7.5EG 7.52023-09-18
Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements End…
- CVE-2023-1108HIGHCVSS 7.5EG 7.52023-09-14
A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
- CVE-2023-4540HIGHCVSS 7.5EG 7.52023-09-05
Improper Handling of Exceptional Conditions vulnerability in Daurnimator lua-http library allows Excessive Allocation and a denial of service (DoS) attack to be executed by sending a properly crafted request to the server. Such a request …
- CVE-2023-4511HIGHCVSS 7.5EG 7.52023-08-24
BT SDP dissector infinite loop in Wireshark 4.0.0 to 4.0.7 and 3.6.0 to 3.6.15 allows denial of service via packet injection or crafted capture file
- CVE-2023-20197HIGHCVSS 7.5EG 7.52023-08-16
A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is …
- CVE-2023-30188HIGHCVSS 7.5EG 7.52023-08-14
Memory Exhaustion vulnerability in ONLYOFFICE Document Server 4.0.3 through 7.3.2 allows remote attackers to cause a denial of service via crafted JavaScript file.
- CVE-2020-35141HIGHCVSS 7.5EG 7.52023-08-11
An issue was discovered in OFPQueueGetConfigReply in parser.py in Faucet SDN Ryu version 4.34, allows remote attackers to cause a denial of service (DoS) (infinite loop).
- CVE-2020-35139HIGHCVSS 7.5EG 7.52023-08-11
An issue was discovered in OFPBundleCtrlMsg in parser.py in Faucet SDN Ryu version 4.34, allows remote attackers to cause a denial of service (DoS) (infinite loop).
- CVE-2023-38197HIGHCVSS 7.5EG 7.52023-07-13
An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion.
- CVE-2022-37013HIGHCVSS 7.5EG 7.52023-03-29
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation OPC UA C++ Demo Server 1.7.6-537 [with vendor rollup]. Authentication is not required to exploit this vulner…
- CVE-2023-27560HIGHCVSS 7.5EG 7.52023-03-03
Math/PrimeField.php in phpseclib 3.x before 3.0.19 has an infinite loop with composite primefields.
- CVE-2023-25824HIGHCVSS 7.5EG 7.52023-02-23
Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. Versions from 0.9.0 to 0.12.0 (including) did not properly fail blocking read operations on TLS connections when the transport hit timeouts. Instead it entered an endless loop re…
- CVE-2023-25653HIGHCVSS 7.5EG 7.52023-02-16
node-jose is a JavaScript implementation of the JSON Object Signing and Encryption (JOSE) for web browsers and node.js-based servers. Prior to version 2.2.0, when using the non-default "fallback" crypto back-end, ECC operations in `node-jo…
- CVE-2022-25734HIGHCVSS 7.5EG 7.52023-02-12
Denial of service in modem due to missing null check while processing IP packets with padding
- CVE-2022-46285HIGHCVSS 7.5EG 7.52023-02-07
A flaw was found in libXpm. This issue occurs when parsing a file with a comment not closed; the end-of-file condition will not be detected, leading to an infinite loop and resulting in a Denial of Service in the application linked to the …
- CVE-2022-44617HIGHCVSS 7.5EG 7.52023-02-06
A flaw was found in libXpm. When processing a file with width of 0 and a very large height, some parser functions will be called repeatedly and can lead to an infinite loop, resulting in a Denial of Service in the application linked to the…
- CVE-2022-48256HIGHCVSS 7.5EG 7.52023-01-13
Technitium DNS Server before 10.0 allows a self-CNAME denial-of-service attack in which a CNAME loop causes an answer to contain hundreds of records.
- CVE-2013-10005HIGHCVSS 7.5EG 7.52022-12-27
The RemoteAddr and LocalAddr methods on the returned net.Conn may call themselves, leading to an infinite loop which will crash the program due to a stack overflow.
- CVE-2022-33238HIGHCVSS 7.5EG 7.52022-12-13
Transient DOS due to loop with unreachable exit condition in WLAN while processing an incoming FTM frames. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer I…
- CVE-2022-46770HIGHCVSS 7.5EG 7.52022-12-07
qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS users to cause a denial of service (CPU consumption and loss of forwarding) via a crafted multicast UDP packet (IP address range of 224.0.0.0 throu…
- CVE-2022-33239HIGHCVSS 7.5EG 7.52022-11-15
Transient DOS due to loop with unreachable exit condition in WLAN firmware while parsing IPV6 extension header. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consu…
- CVE-2022-25742HIGHCVSS 7.5EG 7.52022-11-15
Denial of service in modem due to infinite loop while parsing IGMPv2 packet from server in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music
- CVE-2022-39052HIGHCVSS 7.5EG 7.52022-10-17
An external attacker is able to send a specially crafted email (with many recipients) and trigger a potential DoS of the system
- CVE-2022-3252HIGHCVSS 7.5EG 7.52022-09-21
Improper detection of complete HTTP body decompression SwiftNIO Extras provides a pair of helpers for transparently decompressing received HTTP request or response bodies. These two objects (HTTPRequestDecompressor and HTTPResponseDecompre…
- CVE-2021-37819HIGHCVSS 7.5EG 7.52022-09-09
PDF Labs pdftk-java v3.2.3 was discovered to contain an infinite loop via the component /text/pdf/PdfReader.java.
- CVE-2022-37768HIGHCVSS 7.5EG 7.52022-08-18
libjpeg commit 281daa9 was discovered to contain an infinite loop via the component Frame::ParseTrailer.
- CVE-2022-2833HIGHCVSS 7.5EG 7.52022-08-16
Endless Infinite loop in Blender-thumnailing due to logical bugs.
- CVE-2022-34661HIGHCVSS 7.5EG 7.52022-08-10
A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.15), Teamcenter V13.0 (All versions < V13.0.0.10), Teamcenter V13.1 (All versions < V13.1.0.10), Teamcenter V13.2 (All versions < V13.2.0.9), Teamcenter V13.3 …
- CVE-2022-35724HIGHCVSS 7.5EG 7.52022-08-09
It is possible to provide data to be read that leads the reader to loop in cycles endlessly, consuming CPU. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Users should update …
- CVE-2022-34862HIGHCVSS 7.5EG 7.52022-08-04
In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when an LTM virtual server is configured to perform normalization, undisclosed requests can cause the Traffic Management M…
- CVE-2021-46828HIGHCVSS 7.5EG 7.52022-07-20
In libtirpc before 1.3.3rc1, remote attackers could exhaust the file descriptors of a process that uses libtirpc because idle TCP connections are mishandled. This can, in turn, lead to an svc_run infinite loop without accepting new connect…
- CVE-2022-30634HIGHCVSS 7.5EG 7.52022-07-15
Infinite loop in Read in crypto/rand before Go 1.17.11 and Go 1.18.3 on Windows allows attacker to cause an indefinite hang by passing a buffer larger than 1 << 32 - 1 bytes.
- CVE-2022-34760HIGHCVSS 7.5EG 7.52022-07-13
A CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability exists that could cause a denial of service of the webserver due to improper handling of the cookies. Affected Products: X80 advanced RTU Communication Module …
- CVE-2022-32058HIGHCVSS 7.5EG 7.52022-07-07
An infinite loop in the function httpRpmPass of TP-Link TL-WR741N/TL-WR742N V1/V2/V3_130415 allows attackers to cause a Denial of Service (DoS) via a crafted packet.
- CVE-2022-29862HIGHCVSS 7.5EG 7.52022-06-16
An infinite loop in OPC UA .NET Standard Stack 1.04.368 allows a remote attackers to cause the application to hang via a crafted message.
- CVE-2022-25851HIGHCVSS 7.5EG 7.52022-06-10
The package jpeg-js before 0.4.4 are vulnerable to Denial of Service (DoS) where a particular piece of input will cause to enter an infinite loop and never return.
- CVE-2022-27781HIGHCVSS 7.5EG 7.52022-06-02
libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.Due to an erroneous function, a malicious server could make libcurl built withNSS get stuck in a never…
- CVE-2022-29190HIGHCVSS 7.5EG 7.52022-05-21
Pion DTLS is a Go implementation of Datagram Transport Layer Security. Prior to version 2.1.4, an attacker can send packets that sends Pion DTLS into an infinite loop when processing. Version 2.1.4 contains a patch for this issue. There ar…
- CVE-2022-24792HIGHCVSS 7.5EG 7.52022-04-25
PJSIP is a free and open source multimedia communication library written in C. A denial-of-service vulnerability affects applications on a 32-bit systems that use PJSIP versions 2.12 and prior to play/read invalid WAV files. The vulnerabil…
- CVE-2022-21159HIGHCVSS 7.5EG 7.52022-04-15
A denial of service vulnerability exists in the parseNormalModeParameters functionality of MZ Automation GmbH libiec61850 1.5.0. A specially-crafted series of network requests can lead to denial of service. An attacker can send a sequence …
- CVE-2022-24763HIGHCVSS 7.5EG 7.52022-03-30
PJSIP is a free and open source multimedia communication library written in the C language. Versions 2.12 and prior contain a denial-of-service vulnerability that affects PJSIP users that consume PJSIP's XML parsing in their apps. Users ar…
Map vulnerabilities like CWE-835 to your infrastructure
EchelonGraph correlates every CVE — across CWE-835 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →