Skip to content
Noroxi

CWE-835 · 843 records

Loop with Unreachable Exit Condition ('Infinite Loop')

CVEs in this class

845 records

  • A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defens

    HighCVSS 8.6KEVWeaponizedEPSS 71%

    cisco · adaptive security appliance softwareApr 24, 2024

  • The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.

    HighCVSS 7.5Proof of conceptEPSS 87%

    apache · tomcatJul 14, 2020

  • A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in de

    HighCVSS 7.5No exploitEPSS 77%

    openldap · openldapJan 26, 2021

  • Infinite loop in BN_mod_sqrt() reachable when parsing certificates

    HighCVSS 7.5Proof of conceptEPSS 73%

    openssl · opensslMar 15, 2022

  • HAProxy through 2.0.2 allows attackers to cause a denial of service (ha_panic) via vectors related to htx_manage_client_side_cookies in prot

    HighCVSS 7.5No exploitEPSS 70%

    haproxy · haproxyJul 23, 2019

  • The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinit

    HighCVSS 7.5Proof of conceptEPSS 63%

    exim · eximNov 25, 2017

  • Samba: infinite loop in mdssvc rpc service for spotlight

    HighCVSS 7.5No exploitEPSS 62%

    samba · sambaJul 20, 2023

  • lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated

    HighCVSS 7.5No exploitEPSS 51%

    dovecot · dovecotFeb 12, 2020

  • Invalid handling of X509_verify_cert() internal errors in libssl

    HighCVSS 7.5Proof of conceptEPSS 50%

    openssl · opensslDec 14, 2021

  • An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2.

    HighCVSS 7.5No exploitEPSS 50%

    djangoproject · djangoFeb 2, 2022

  • A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web server application in ve

    HighCVSS 7.5No exploitEPSS 45%

    embedthis · goaheadDec 3, 2019

  • An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.

    HighCVSS 7.5No exploitEPSS 40%

    ivanti · avalancheNov 12, 2024

  • In the Linux kernel before 4.20.2, kernel/sched/fair.c mishandles leaf cfs_rq's, which allows attackers to cause a denial of service (infini

    CriticalCVSS 9.8No exploitEPSS 4%

    linux · linux kernelFeb 22, 2019

  • The ISAKMP parser in tcpdump before 4.9.2 could enter an infinite loop due to bugs in print-isakmp.c, several functions.

    CriticalCVSS 9.8No exploitEPSS 3%

    tcpdump · tcpdumpSep 14, 2017

  • The LLDP parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-lldp.c:lldp_private_8021_print().

    CriticalCVSS 9.8No exploitEPSS 2%

    tcpdump · tcpdumpSep 14, 2017

  • The DNS parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-domain.c:ns_print().

    CriticalCVSS 9.8No exploitEPSS 2%

    tcpdump · tcpdumpSep 14, 2017

  • Cookie Security Vulnerabilities in datavane/tis

    CriticalCVSS 10.0No exploitEPSS 0%

    datavane · tisJan 27, 2026

  • CVE-2023-1718
    37Monitor

    Bitrix24 Denial-of-Service (DoS) via Improper File Stream Access

    HighCVSS 7.5Proof of conceptEPSS 24%

    bitrix24 · bitrix24Nov 1, 2023

  • In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in th

    HighCVSS 7.5No exploitEPSS 24%

    systemd project · systemdOct 26, 2017

  • An issue was discovered in ApiPageSet.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1.

    HighCVSS 7.5No exploitEPSS 23%

    mediawiki · mediawikiOct 9, 2023

  • qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS users to cause a denial of service (CPU consumpt

    HighCVSS 7.5WeaponizedEPSS 22%

    linuxfoundation · mirage firewallDec 7, 2022

  • CVE-2018-8002
    37Monitor

    In PoDoFo 0.9.5, there exists an infinite loop vulnerability in PdfParserObject::ParseFileComplete() in PdfParserObject.cpp which may result

    HighCVSS 8.8Proof of conceptEPSS 8%

    podofo project · podofoMar 9, 2018

  • ext4: avoid infinite loops caused by residual data

    CriticalCVSS 9.4No exploitEPSS 1%

    linux · linux kernelApr 22, 2026

  • CVE-2018-1336
    36Monitor

    An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Den

    HighCVSS 7.5No exploitEPSS 21%

    apache · tomcatAug 2, 2018

  • ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handling of overly long c

    HighCVSS 7.5Proof of conceptEPSS 20%

    proftpd · proftpdOct 21, 2019

All vulnerability classes