CWE-835— Loop with Unreachable Exit Condition (Infinite Loop)
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.— MITRE CWE catalog
981 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-835page 7 of 20
- CVE-2020-28030HIGHCVSS 7.5EG 7.52020-11-02
In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed in epan/dissectors/packet-gquic.c by correcting the implementation of offset advancement.
- CVE-2020-26575HIGHCVSS 7.5EG 7.52020-10-06
In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector could enter an infinite loop. This was addressed in epan/dissectors/packet-fbzero.c by correcting the implementation of offset advancement.
- CVE-2020-15598HIGHCVSS 7.5EG 7.52020-10-06
Trustwave ModSecurity 3.x through 3.0.4 allows denial of service via a special request. NOTE: The discoverer reports "Trustwave has signaled they are disputing our claims." The CVE suggests that there is a security issue with how ModSecuri…
- CVE-2020-25574HIGHCVSS 7.5EG 7.52020-09-14
An issue was discovered in the http crate before 0.1.20 for Rust. An integer overflow in HeaderMap::reserve() could result in denial of service (e.g., an infinite loop).
- CVE-2020-12457HIGHCVSS 7.5EG 7.52020-08-21
An issue was discovered in wolfSSL before 4.5.0. It mishandles the change_cipher_spec (CCS) message processing logic for TLS 1.3. If an attacker sends ChangeCipherSpec messages in a crafted way involving more than one in a row, the server …
- CVE-2019-19643HIGHCVSS 7.5EG 7.52020-08-14
ise smart connect KNX Vaillant 1.2.839 contain a Denial of Service.
- CVE-2020-16845HIGHCVSS 7.5EG 7.52020-08-06
Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary via invalid inputs.
- CVE-2020-5761HIGHCVSS 7.5EG 7.52020-07-29
Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to CPU exhaustion due to an infinite loop in the TR-069 service. Unauthenticated remote attackers can trigger this case by sending a one character TCP message to th…
- CVE-2019-20907HIGHCVSS 7.5EG 7.52020-07-13
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.
- CVE-2020-15466HIGHCVSS 7.5EG 7.52020-07-05
In Wireshark 3.2.0 to 3.2.4, the GVCP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-gvcp.c by ensuring that an offset increases in all situations.
- CVE-2019-19506HIGHCVSS 7.5EG 7.52020-06-25
Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a denial of service, caused by an error in the "homeplugd" process. By sending a specially crafted UDP packet, an attacker could exploit this vulnerability to cause the device to…
- CVE-2020-14448HIGHCVSS 7.5EG 7.52020-06-19
An issue was discovered in Mattermost Server before 5.23.0. Automatic direct message replies allow attackers to cause a denial of service (infinite loop), aka MMSA-2020-0020.
- CVE-2020-14447HIGHCVSS 7.5EG 7.52020-06-19
An issue was discovered in Mattermost Server before 5.23.0. Large webhook requests allow attackers to cause a denial of service (infinite loop), aka MMSA-2020-0021.
- CVE-2020-12885HIGHCVSS 7.5EG 7.52020-06-18
An infinite loop was discovered in the CoAP library in Arm Mbed OS 5.15.3. The CoAP parser is responsible for parsing received CoAP packets. The function sn_coap_parser_options_parse_multiple_options() parses CoAP options in a while loop. …
- CVE-2020-14040HIGHCVSS 7.5EG 7.52020-06-17
The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a…
- CVE-2020-14398HIGHCVSS 7.5EG 7.52020-06-17
An issue was discovered in LibVNCServer before 0.9.13. An improperly closed TCP connection causes an infinite loop in libvncclient/sockets.c.
- CVE-2020-13808HIGHCVSS 7.5EG 7.52020-06-04
An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows resource consumption via crafted cross-reference stream data.
- CVE-2020-13807HIGHCVSS 7.5EG 7.52020-06-04
An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has circular reference mishandling that causes a loop.
- CVE-2020-12663HIGHCVSS 7.5EG 7.52020-05-19
Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers.
- CVE-2013-7488HIGHCVSS 7.5EG 7.52020-04-07
perl-Convert-ASN1 (aka the Convert::ASN1 module for Perl) through 0.27 allows remote attackers to cause an infinite loop via unexpected input.
- CVE-2020-10675HIGHCVSS 7.5EG 7.52020-03-19
The Library API in buger jsonparser through 2019-12-04 allows attackers to cause a denial of service (infinite loop) via a Delete call.
- CVE-2019-8741HIGHCVSS 7.5EG 7.52020-02-28
A denial of service issue was addressed with improved input validation.
- CVE-2013-3722HIGHCVSS 7.5EG 7.52020-02-17
A Denial of Service (infinite loop) exists in OpenSIPS before 1.10 in lookup.c.
- CVE-2020-7920HIGHCVSS 7.5EG 7.52020-02-06
pmm-server in Percona Monitoring and Management (PMM) 2.2.x before 2.2.1 allows unauthenticated denial of service.
- CVE-2019-20421HIGHCVSS 7.5EG 7.52020-01-27
In Jp2Image::readMetadata() in jp2image.cpp in Exiv2 0.27.2, an input file can result in an infinite loop and hang, with high CPU consumption. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted fi…
- CVE-2020-7595HIGHCVSS 7.5EG 7.52020-01-21
xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
- CVE-2019-5274HIGHCVSS 7.5EG 7.52019-12-26
USG9500 with versions of V500R001C30;V500R001C60 have a denial of service vulnerability. Due to a flaw in the X.509 implementation in the affected products which can result in an infinite loop, an attacker may exploit the vulnerability via…
- CVE-2019-10485HIGHCVSS 7.5EG 7.52019-12-12
Infinite loop while decoding compressed data can lead to overrun condition in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon …
- CVE-2019-5091HIGHCVSS 7.5EG 7.52019-12-12
An exploitable denial-of-service vulnerability exists in the Dicom-packet parsing functionality of LEADTOOLS libltdic.so version 20.0.2019.3.15. A specially crafted packet can cause an infinite loop, resulting in a denial of service. An at…
- CVE-2019-19588HIGHCVSS 7.5EG 7.52019-12-05
The validators package 0.12.2 through 0.12.5 for Python enters an infinite loop when validators.domain is called with a crafted domain string. This is fixed in 0.12.6.
- CVE-2019-18455HIGHCVSS 7.5EG 7.52019-11-26
An issue was discovered in GitLab Community and Enterprise Edition 11 through 12.4 when building Nested GraphQL queries. It has a large or infinite loop.
- CVE-2019-2335HIGHCVSS 7.5EG 7.52019-11-21
While processing Attach Reject message, Valid exit condition is not met resulting into an infinite loop in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdrag…
- CVE-2019-18817HIGHCVSS 7.5EG 7.52019-11-12
Istio 1.3.x before 1.3.5 allows Denial of Service because continue_on_listener_filters_timeout is set to True, a related issue to CVE-2019-18836.
- CVE-2019-18836HIGHCVSS 7.5EG 7.52019-11-11
Envoy 1.12.0 allows a remote denial of service because of resource loops, as demonstrated by a single idle TCP connection being able to keep a worker thread in an infinite busy loop when continue_on_listener_filters_timeout is used."
- CVE-2019-0205HIGHCVSS 7.5EG 7.52019-10-29
In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed …
- CVE-2019-18217HIGHCVSS 7.5EG 7.52019-10-21
ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handling of overly long commands because main.c in a child process enters an infinite loop.
- CVE-2019-16413HIGHCVSS 7.5EG 7.52019-09-19
An issue was discovered in the Linux kernel before 5.0.4. The 9p filesystem did not protect i_size_write() properly, which causes an i_size_read() infinite loop and denial of service on SMP systems.
- CVE-2019-16319HIGHCVSS 7.5EG 7.52019-09-15
In Wireshark 3.0.0 to 3.0.3 and 2.6.0 to 2.6.10, the Gryphon dissector could go into an infinite loop. This was addressed in plugins/epan/gryphon/packet-gryphon.c by checking for a message length of zero.
- CVE-2019-12402HIGHCVSS 7.5EG 7.52019-08-30
The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file…
- CVE-2019-15702HIGHCVSS 7.5EG 7.52019-08-27
In the TCP implementation (gnrc_tcp) in RIOT through 2019.07, the parser for TCP options does not terminate on all inputs, allowing a denial-of-service, because sys/net/gnrc/transport_layer/tcp/gnrc_tcp_option.c has an infinite loop for an…
- CVE-2019-14207HIGHCVSS 7.5EG 7.52019-07-21
An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash when calling the clone function due to an endless loop resulting from confusing relationships between a child and parent object (caused by an append err…
- CVE-2019-1010142HIGHCVSS 7.5EG 7.52019-07-19
scapy 2.4.0 is affected by: Denial of Service. The impact is: infinite loop, resource consumption and program unresponsive. The component is: _RADIUSAttrPacketListField.getfield(self..). The attack vector is: over the network or in a pcap.…
- CVE-2018-17202HIGHCVSS 7.5EG 7.52019-05-06
Certain input files could make the code to enter into an infinite loop when Apache Sanselan 0.97-incubator was used to parse them, which could be used in a DoS attack. Note that Apache Sanselan (incubating) was renamed to Apache Commons Im…
- CVE-2019-3560HIGHCVSS 7.5EG 7.52019-04-29
An improperly performed length calculation on a buffer in PlaintextRecordLayer could lead to an infinite loop and denial-of-service based on user input. This issue affected versions of fizz prior to v2019.03.04.00.
- CVE-2019-10900HIGHCVSS 7.5EG 7.52019-04-09
In Wireshark 3.0.0, the Rbm dissector could go into an infinite loop. This was addressed in epan/dissectors/file-rbm.c by handling unknown object types safely.
- CVE-2019-10898HIGHCVSS 7.5EG 7.52019-04-09
In Wireshark 3.0.0, the GSUP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-gsm_gsup.c by rejecting an invalid Information Element length.
- CVE-2019-10897HIGHCVSS 7.5EG 7.52019-04-09
In Wireshark 3.0.0, the IEEE 802.11 dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-ieee80211.c by detecting cases in which the bit offset does not advance.
- CVE-2018-16789HIGHCVSS 7.5EG 7.52019-03-21
libhttp/url.c in shellinabox through 2.20 has an implementation flaw in the HTTP request parsing logic. By sending a crafted multipart/form-data HTTP request, an attacker could exploit this to force shellinaboxd into an infinite loop, exha…
- CVE-2019-3833HIGHCVSS 7.5EG 7.52019-03-14
Openwsman, versions up to and including 2.6.9, are vulnerable to infinite loop in process_connection() when parsing specially crafted HTTP requests. A remote, unauthenticated attacker can exploit this vulnerability by sending malicious HTT…
- CVE-2019-9747HIGHCVSS 7.5EG 7.52019-03-13
In tinysvcmdns through 2018-01-16, a maliciously crafted mDNS (Multicast DNS) packet triggers an infinite loop while parsing an mDNS query. When mDNS compressed labels point to each other, the function uncompress_nlabel goes into an infini…
Map vulnerabilities like CWE-835 to your infrastructure
EchelonGraph correlates every CVE — across CWE-835 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →