Skip to content
Noroxi

CWE-834 · 89 records

Excessive Iteration

CVEs in this class

89 records

  • ImageMagick 7.0.6-1 has a large loop vulnerability in the ReadPWPImage function in coders\pwp.c.

    HighCVSS 8.8No exploitEPSS 2%

    imagemagick · imagemagickAug 6, 2017

  • MLS hash-ratchet honours arbitrary 32-bit generation counter from sender

    HighCVSS 8.7No exploitEPSS 0%

    bouncycastle · bc-javaAug 2, 2026

  • Apache Commons Compress 1.6 to 1.20 denial of service vulnerability

    HighCVSS 7.5No exploitEPSS 12%

    apache · commons compressJul 13, 2021

  • Large loop in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or c

    HighCVSS 7.5No exploitEPSS 5%

    wireshark · wiresharkNov 19, 2021

  • Next.js: Denial of Service in App Router using Server Actions

    HighCVSS 8.2No exploitEPSS 1%

    vercel · next.jsJul 27, 2026

  • In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the BGP protocol dissector could go into a large loop.

    HighCVSS 7.5No exploitEPSS 4%

    wireshark · wiresharkJul 18, 2018

  • A flaw was found in the AD DC NBT server in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4.

    HighCVSS 7.5No exploitEPSS 4%

    samba · sambaJul 6, 2020

  • libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF.

    HighCVSS 7.5No exploitEPSS 3%

    ijg · libjpegJun 5, 2018

  • CVE-2021-4190
    31Monitor

    Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service via packet injection or crafted capture file

    HighCVSS 7.5No exploitEPSS 3%

    wireshark · wiresharkDec 30, 2021

  • CVE-2018-9261
    31Monitor

    In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the NBAP dissector could crash with a large loop that ends with a heap-based buffer overflo

    HighCVSS 7.5No exploitEPSS 3%

    wireshark · wiresharkApr 4, 2018

  • CVE-2019-3565
    31Monitor

    Legacy C++ Facebook Thrift servers (using cpp instead of cpp2) would not error upon receiving messages with containers of fields of unknown

    HighCVSS 7.5No exploitEPSS 3%

    facebook · thriftMay 6, 2019

  • srs2.c in PostSRSd before 1.10 allows remote attackers to cause a denial of service (CPU consumption) via a long timestamp tag in an SRS add

    HighCVSS 7.5No exploitEPSS 3%

    postsrsd project · postsrsdDec 20, 2020

  • CVE-2018-7323
    31Monitor

    In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-wccp.c had a large loop that was addressed by ensuring that a calcul

    HighCVSS 7.5No exploitEPSS 2%

    wireshark · wiresharkFeb 23, 2018

  • In Wireshark 2.0.0 to 2.0.13, the GPRS LLC dissector could go into a large loop.

    HighCVSS 7.5No exploitEPSS 2%

    wireshark · wiresharkJul 18, 2017

  • CVE-2021-3128
    31Monitor

    In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42095 or < 9.0.0.4.386.41994, when IPv6 is

    HighCVSS 7.5No exploitEPSS 2%

    asus · zenwifi ax \(xt8\) firmwareApr 12, 2021

  • CVE-2019-3558
    31Monitor

    Python Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type.

    HighCVSS 7.5No exploitEPSS 2%

    facebook · thriftMay 6, 2019

  • CVE-2019-3559
    31Monitor

    Java Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type.

    HighCVSS 7.5No exploitEPSS 2%

    facebook · thriftMay 6, 2019

  • CVE-2019-3564
    31Monitor

    Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type.

    HighCVSS 7.5No exploitEPSS 2%

    facebook · thriftMay 6, 2019

  • CVE-2019-3552
    31Monitor

    C++ Facebook Thrift servers (using cpp2) would not error upon receiving messages with containers of fields of unknown type.

    HighCVSS 7.5No exploitEPSS 2%

    facebook · thriftMay 6, 2019

  • CVE-2018-7321
    31Monitor

    In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-thrift.c had a large loop that was addressed by not proceeding with

    HighCVSS 7.5No exploitEPSS 2%

    wireshark · wiresharkFeb 23, 2018

  • Excessive CPU usage in Pomerium

    HighCVSS 7.5No exploitEPSS 2%

    pomerium · pomeriumSep 9, 2021

  • Large loop in the PNRP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted ca

    HighCVSS 7.5No exploitEPSS 2%

    wireshark · wiresharkNov 19, 2021

  • The ReadDPXImage function in coders\dpx.c in ImageMagick 7.0.6-0 has a large loop vulnerability that can cause CPU exhaustion via a crafted

    HighCVSS 7.5No exploitEPSS 2%

    imagemagick · imagemagickJul 12, 2017

  • CVE-2021-3125
    30Monitor

    In TP-Link TL-XDR3230 < 1.0.12, TL-XDR1850 < 1.0.9, TL-XDR1860 < 1.0.14, TL-XDR3250 < 1.0.2, TL-XDR6060 Turbo < 1.1.8, TL-XDR5430 < 1.0.11,

    HighCVSS 7.5No exploitEPSS 2%

    tp-link · tl-xdr3230 firmwareApr 12, 2021

  • Apache Sling Resource Merger: Requests to certain paths managed by the Apache Sling Resource Merger can lead to DoS

    HighCVSS 7.5No exploitEPSS 1%

    apache · sling resource mergerMar 20, 2023

All vulnerability classes