CWE-834 · 89 records
Excessive Iteration
CVEs in this class
89 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2017-12587No exploit | ImageMagick 7.0.6-1 has a large loop vulnerability in the ReadPWPImage function in coders\pwp.c.imagemagick · imagemagick · CWE-834 | High8.8 | — | 2.0% | Aug 6, 2017 |
34Monitor | CVE-2026-59644No exploit | MLS hash-ratchet honours arbitrary 32-bit generation counter from senderbouncycastle · bc-java · CWE-834 | High8.7 | — | 0.5% | Aug 2, 2026 |
33Monitor | CVE-2021-35515No exploit | Apache Commons Compress 1.6 to 1.20 denial of service vulnerabilityapache · commons compress · CWE-834 | High7.5 | — | 11.6% | Jul 13, 2021 |
32Monitor | CVE-2021-39924No exploit | Large loop in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or cwireshark · wireshark · CWE-834 | High7.5 | — | 5.3% | Nov 19, 2021 |
32Monitor | CVE-2026-64641No exploit | Next.js: Denial of Service in App Router using Server Actionsvercel · next.js · CWE-834 | High8.2 | — | 0.9% | Jul 27, 2026 |
31Monitor | CVE-2018-14342No exploit | In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the BGP protocol dissector could go into a large loop.wireshark · wireshark · CWE-834 | High7.5 | — | 3.7% | Jul 18, 2018 |
31Monitor | CVE-2020-14303No exploit | A flaw was found in the AD DC NBT server in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4.samba · samba · CWE-834 | High7.5 | — | 3.5% | Jul 6, 2020 |
31Monitor | CVE-2018-11813No exploit | libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF.ijg · libjpeg · CWE-834 | High7.5 | — | 3.2% | Jun 5, 2018 |
31Monitor | CVE-2021-4190No exploit | Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service via packet injection or crafted capture filewireshark · wireshark · CWE-834 | High7.5 | — | 3.1% | Dec 30, 2021 |
31Monitor | CVE-2018-9261No exploit | In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the NBAP dissector could crash with a large loop that ends with a heap-based buffer overflowireshark · wireshark · CWE-834 | High7.5 | — | 2.8% | Apr 4, 2018 |
31Monitor | CVE-2019-3565No exploit | Legacy C++ Facebook Thrift servers (using cpp instead of cpp2) would not error upon receiving messages with containers of fields of unknown facebook · thrift · CWE-834 | High7.5 | — | 2.8% | May 6, 2019 |
31Monitor | CVE-2020-35573No exploit | srs2.c in PostSRSd before 1.10 allows remote attackers to cause a denial of service (CPU consumption) via a long timestamp tag in an SRS addpostsrsd project · postsrsd · CWE-834 | High7.5 | — | 2.7% | Dec 20, 2020 |
31Monitor | CVE-2018-7323No exploit | In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-wccp.c had a large loop that was addressed by ensuring that a calculwireshark · wireshark · CWE-834 | High7.5 | — | 2.5% | Feb 23, 2018 |
31Monitor | CVE-2017-11409No exploit | In Wireshark 2.0.0 to 2.0.13, the GPRS LLC dissector could go into a large loop.wireshark · wireshark · CWE-834 | High7.5 | — | 2.3% | Jul 18, 2017 |
31Monitor | CVE-2021-3128No exploit | In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42095 or < 9.0.0.4.386.41994, when IPv6 isasus · zenwifi ax \(xt8\) firmware · CWE-834 | High7.5 | — | 2.2% | Apr 12, 2021 |
31Monitor | CVE-2019-3558No exploit | Python Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type.facebook · thrift · CWE-834 | High7.5 | — | 2.0% | May 6, 2019 |
31Monitor | CVE-2019-3559No exploit | Java Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type.facebook · thrift · CWE-834 | High7.5 | — | 2.0% | May 6, 2019 |
31Monitor | CVE-2019-3564No exploit | Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type.facebook · thrift · CWE-834 | High7.5 | — | 2.0% | May 6, 2019 |
31Monitor | CVE-2019-3552No exploit | C++ Facebook Thrift servers (using cpp2) would not error upon receiving messages with containers of fields of unknown type.facebook · thrift · CWE-834 | High7.5 | — | 2.0% | May 6, 2019 |
31Monitor | CVE-2018-7321No exploit | In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-thrift.c had a large loop that was addressed by not proceeding with wireshark · wireshark · CWE-834 | High7.5 | — | 1.7% | Feb 23, 2018 |
30Monitor | CVE-2021-39204No exploit | Excessive CPU usage in Pomeriumpomerium · pomerium · CWE-834 | High7.5 | — | 1.7% | Sep 9, 2021 |
30Monitor | CVE-2021-39923No exploit | Large loop in the PNRP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted cawireshark · wireshark · CWE-834 | High7.5 | — | 1.6% | Nov 19, 2021 |
30Monitor | CVE-2017-11188No exploit | The ReadDPXImage function in coders\dpx.c in ImageMagick 7.0.6-0 has a large loop vulnerability that can cause CPU exhaustion via a crafted imagemagick · imagemagick · CWE-834 | High7.5 | — | 1.6% | Jul 12, 2017 |
30Monitor | CVE-2021-3125No exploit | In TP-Link TL-XDR3230 < 1.0.12, TL-XDR1850 < 1.0.9, TL-XDR1860 < 1.0.14, TL-XDR3250 < 1.0.2, TL-XDR6060 Turbo < 1.1.8, TL-XDR5430 < 1.0.11, tp-link · tl-xdr3230 firmware · CWE-834 | High7.5 | — | 1.5% | Apr 12, 2021 |
30Monitor | CVE-2023-26513No exploit | Apache Sling Resource Merger: Requests to certain paths managed by the Apache Sling Resource Merger can lead to DoSapache · sling resource merger · CWE-834 | High7.5 | — | 1.5% | Mar 20, 2023 |
- CVE-2017-1258736Monitor
ImageMagick 7.0.6-1 has a large loop vulnerability in the ReadPWPImage function in coders\pwp.c.
HighCVSS 8.8No exploitEPSS 2%imagemagick · imagemagickAug 6, 2017
- CVE-2026-5964434Monitor
MLS hash-ratchet honours arbitrary 32-bit generation counter from sender
HighCVSS 8.7No exploitEPSS 0%bouncycastle · bc-javaAug 2, 2026
- CVE-2021-3551533Monitor
Apache Commons Compress 1.6 to 1.20 denial of service vulnerability
HighCVSS 7.5No exploitEPSS 12%apache · commons compressJul 13, 2021
- CVE-2021-3992432Monitor
Large loop in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or c
HighCVSS 7.5No exploitEPSS 5%wireshark · wiresharkNov 19, 2021
- CVE-2026-6464132Monitor
Next.js: Denial of Service in App Router using Server Actions
HighCVSS 8.2No exploitEPSS 1%vercel · next.jsJul 27, 2026
- CVE-2018-1434231Monitor
In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the BGP protocol dissector could go into a large loop.
HighCVSS 7.5No exploitEPSS 4%wireshark · wiresharkJul 18, 2018
- CVE-2020-1430331Monitor
A flaw was found in the AD DC NBT server in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4.
HighCVSS 7.5No exploitEPSS 4%samba · sambaJul 6, 2020
- CVE-2018-1181331Monitor
libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF.
HighCVSS 7.5No exploitEPSS 3%ijg · libjpegJun 5, 2018
- CVE-2021-419031Monitor
Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service via packet injection or crafted capture file
HighCVSS 7.5No exploitEPSS 3%wireshark · wiresharkDec 30, 2021
- CVE-2018-926131Monitor
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the NBAP dissector could crash with a large loop that ends with a heap-based buffer overflo
HighCVSS 7.5No exploitEPSS 3%wireshark · wiresharkApr 4, 2018
- CVE-2019-356531Monitor
Legacy C++ Facebook Thrift servers (using cpp instead of cpp2) would not error upon receiving messages with containers of fields of unknown
HighCVSS 7.5No exploitEPSS 3%facebook · thriftMay 6, 2019
- CVE-2020-3557331Monitor
srs2.c in PostSRSd before 1.10 allows remote attackers to cause a denial of service (CPU consumption) via a long timestamp tag in an SRS add
HighCVSS 7.5No exploitEPSS 3%postsrsd project · postsrsdDec 20, 2020
- CVE-2018-732331Monitor
In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-wccp.c had a large loop that was addressed by ensuring that a calcul
HighCVSS 7.5No exploitEPSS 2%wireshark · wiresharkFeb 23, 2018
- CVE-2017-1140931Monitor
In Wireshark 2.0.0 to 2.0.13, the GPRS LLC dissector could go into a large loop.
HighCVSS 7.5No exploitEPSS 2%wireshark · wiresharkJul 18, 2017
- CVE-2021-312831Monitor
In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42095 or < 9.0.0.4.386.41994, when IPv6 is
HighCVSS 7.5No exploitEPSS 2%asus · zenwifi ax \(xt8\) firmwareApr 12, 2021
- CVE-2019-355831Monitor
Python Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type.
HighCVSS 7.5No exploitEPSS 2%facebook · thriftMay 6, 2019
- CVE-2019-355931Monitor
Java Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type.
HighCVSS 7.5No exploitEPSS 2%facebook · thriftMay 6, 2019
- CVE-2019-356431Monitor
Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type.
HighCVSS 7.5No exploitEPSS 2%facebook · thriftMay 6, 2019
- CVE-2019-355231Monitor
C++ Facebook Thrift servers (using cpp2) would not error upon receiving messages with containers of fields of unknown type.
HighCVSS 7.5No exploitEPSS 2%facebook · thriftMay 6, 2019
- CVE-2018-732131Monitor
In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-thrift.c had a large loop that was addressed by not proceeding with
HighCVSS 7.5No exploitEPSS 2%wireshark · wiresharkFeb 23, 2018
- CVE-2021-3920430Monitor
Excessive CPU usage in Pomerium
HighCVSS 7.5No exploitEPSS 2%pomerium · pomeriumSep 9, 2021
- CVE-2021-3992330Monitor
Large loop in the PNRP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted ca
HighCVSS 7.5No exploitEPSS 2%wireshark · wiresharkNov 19, 2021
- CVE-2017-1118830Monitor
The ReadDPXImage function in coders\dpx.c in ImageMagick 7.0.6-0 has a large loop vulnerability that can cause CPU exhaustion via a crafted
HighCVSS 7.5No exploitEPSS 2%imagemagick · imagemagickJul 12, 2017
- CVE-2021-312530Monitor
In TP-Link TL-XDR3230 < 1.0.12, TL-XDR1850 < 1.0.9, TL-XDR1860 < 1.0.14, TL-XDR3250 < 1.0.2, TL-XDR6060 Turbo < 1.1.8, TL-XDR5430 < 1.0.11,
HighCVSS 7.5No exploitEPSS 2%tp-link · tl-xdr3230 firmwareApr 12, 2021
- CVE-2023-2651330Monitor
Apache Sling Resource Merger: Requests to certain paths managed by the Apache Sling Resource Merger can lead to DoS
HighCVSS 7.5No exploitEPSS 1%apache · sling resource mergerMar 20, 2023