CWE-835 · 843 records
Loop with Unreachable Exit Condition ('Infinite Loop')
CVEs in this class
845 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
85Now | CVE-2024-20353Weaponized | A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defenscisco · adaptive security appliance software · CWE-835 | High8.6 | KEV | 70.7% | Apr 24, 2024 |
56Plan | CVE-2020-13935Proof of concept | The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.apache · tomcat · CWE-835 | High7.5 | — | 86.6% | Jul 14, 2020 |
53Plan | CVE-2020-36227No exploit | A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in deopenldap · openldap · CWE-835 | High7.5 | — | 77.2% | Jan 26, 2021 |
52Plan | CVE-2022-0778Proof of concept | Infinite loop in BN_mod_sqrt() reachable when parsing certificatesopenssl · openssl · CWE-835 | High7.5 | — | 73.2% | Mar 15, 2022 |
51Plan | CVE-2019-14241No exploit | HAProxy through 2.0.2 allows attackers to cause a denial of service (ha_panic) via vectors related to htx_manage_client_side_cookies in prothaproxy · haproxy · CWE-835 | High7.5 | — | 70.2% | Jul 23, 2019 |
49Plan | CVE-2017-16944Proof of concept | The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinitexim · exim · CWE-835 | High7.5 | — | 63.3% | Nov 25, 2017 |
49Plan | CVE-2023-34966No exploit | Samba: infinite loop in mdssvc rpc service for spotlightsamba · samba · CWE-835 | High7.5 | — | 62.4% | Jul 20, 2023 |
45Plan | CVE-2020-7046No exploit | lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrateddovecot · dovecot · CWE-835 | High7.5 | — | 51.3% | Feb 12, 2020 |
45Plan | CVE-2021-4044Proof of concept | Invalid handling of X509_verify_cert() internal errors in libsslopenssl · openssl · CWE-835 | High7.5 | — | 50.1% | Dec 14, 2021 |
45Plan | CVE-2022-23833No exploit | An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2.djangoproject · django · CWE-835 | High7.5 | — | 49.5% | Feb 2, 2022 |
44Plan | CVE-2019-5097No exploit | A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web server application in veembedthis · goahead · CWE-835 | High7.5 | — | 45.1% | Dec 3, 2019 |
42Plan | CVE-2024-50320No exploit | An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.ivanti · avalanche · CWE-835 | High7.5 | — | 39.6% | Nov 12, 2024 |
40Plan | CVE-2018-20784No exploit | In the Linux kernel before 4.20.2, kernel/sched/fair.c mishandles leaf cfs_rq's, which allows attackers to cause a denial of service (infinilinux · linux kernel · CWE-835 | Critical9.8 | — | 4.2% | Feb 22, 2019 |
40Plan | CVE-2017-12990No exploit | The ISAKMP parser in tcpdump before 4.9.2 could enter an infinite loop due to bugs in print-isakmp.c, several functions.tcpdump · tcpdump · CWE-835 | Critical9.8 | — | 2.5% | Sep 14, 2017 |
40Plan | CVE-2017-12997No exploit | The LLDP parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-lldp.c:lldp_private_8021_print().tcpdump · tcpdump · CWE-835 | Critical9.8 | — | 2.5% | Sep 14, 2017 |
40Plan | CVE-2017-12995No exploit | The DNS parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-domain.c:ns_print().tcpdump · tcpdump · CWE-835 | Critical9.8 | — | 2.4% | Sep 14, 2017 |
40Plan | CVE-2026-24816No exploit | Cookie Security Vulnerabilities in datavane/tisdatavane · tis · CWE-835 | Critical10.0 | — | 0.3% | Jan 27, 2026 |
37Monitor | CVE-2023-1718Proof of concept | Bitrix24 Denial-of-Service (DoS) via Improper File Stream Accessbitrix24 · bitrix24 · CWE-835 | High7.5 | — | 24.1% | Nov 1, 2023 |
37Monitor | CVE-2017-15908No exploit | In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in thsystemd project · systemd · CWE-835 | High7.5 | — | 23.6% | Oct 26, 2017 |
37Monitor | CVE-2023-45363No exploit | An issue was discovered in ApiPageSet.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1.mediawiki · mediawiki · CWE-835 | High7.5 | — | 22.7% | Oct 9, 2023 |
37Monitor | CVE-2022-46770Weaponized | qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS users to cause a denial of service (CPU consumptlinuxfoundation · mirage firewall · CWE-835 | High7.5 | — | 21.7% | Dec 7, 2022 |
37Monitor | CVE-2018-8002Proof of concept | In PoDoFo 0.9.5, there exists an infinite loop vulnerability in PdfParserObject::ParseFileComplete() in PdfParserObject.cpp which may resultpodofo project · podofo · CWE-835 | High8.8 | — | 8.0% | Mar 9, 2018 |
37Monitor | CVE-2026-31448No exploit | ext4: avoid infinite loops caused by residual datalinux · linux kernel · CWE-835 | Critical9.4 | — | 0.7% | Apr 22, 2026 |
36Monitor | CVE-2018-1336No exploit | An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denapache · tomcat · CWE-835 | High7.5 | — | 20.6% | Aug 2, 2018 |
36Monitor | CVE-2019-18217Proof of concept | ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handling of overly long cproftpd · proftpd · CWE-835 | High7.5 | — | 20.3% | Oct 21, 2019 |
- CVE-2024-2035385Now
A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defens
HighCVSS 8.6KEVWeaponizedEPSS 71%cisco · adaptive security appliance softwareApr 24, 2024
- CVE-2020-1393556Plan
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.
HighCVSS 7.5Proof of conceptEPSS 87%apache · tomcatJul 14, 2020
- CVE-2020-3622753Plan
A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in de
HighCVSS 7.5No exploitEPSS 77%openldap · openldapJan 26, 2021
- CVE-2022-077852Plan
Infinite loop in BN_mod_sqrt() reachable when parsing certificates
HighCVSS 7.5Proof of conceptEPSS 73%openssl · opensslMar 15, 2022
- CVE-2019-1424151Plan
HAProxy through 2.0.2 allows attackers to cause a denial of service (ha_panic) via vectors related to htx_manage_client_side_cookies in prot
HighCVSS 7.5No exploitEPSS 70%haproxy · haproxyJul 23, 2019
- CVE-2017-1694449Plan
The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinit
HighCVSS 7.5Proof of conceptEPSS 63%exim · eximNov 25, 2017
- CVE-2023-3496649Plan
Samba: infinite loop in mdssvc rpc service for spotlight
HighCVSS 7.5No exploitEPSS 62%samba · sambaJul 20, 2023
- CVE-2020-704645Plan
lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated
HighCVSS 7.5No exploitEPSS 51%dovecot · dovecotFeb 12, 2020
- CVE-2021-404445Plan
Invalid handling of X509_verify_cert() internal errors in libssl
HighCVSS 7.5Proof of conceptEPSS 50%openssl · opensslDec 14, 2021
- CVE-2022-2383345Plan
An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2.
HighCVSS 7.5No exploitEPSS 50%djangoproject · djangoFeb 2, 2022
- CVE-2019-509744Plan
A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web server application in ve
HighCVSS 7.5No exploitEPSS 45%embedthis · goaheadDec 3, 2019
- CVE-2024-5032042Plan
An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
HighCVSS 7.5No exploitEPSS 40%ivanti · avalancheNov 12, 2024
- CVE-2018-2078440Plan
In the Linux kernel before 4.20.2, kernel/sched/fair.c mishandles leaf cfs_rq's, which allows attackers to cause a denial of service (infini
CriticalCVSS 9.8No exploitEPSS 4%linux · linux kernelFeb 22, 2019
- CVE-2017-1299040Plan
The ISAKMP parser in tcpdump before 4.9.2 could enter an infinite loop due to bugs in print-isakmp.c, several functions.
CriticalCVSS 9.8No exploitEPSS 3%tcpdump · tcpdumpSep 14, 2017
- CVE-2017-1299740Plan
The LLDP parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-lldp.c:lldp_private_8021_print().
CriticalCVSS 9.8No exploitEPSS 2%tcpdump · tcpdumpSep 14, 2017
- CVE-2017-1299540Plan
The DNS parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-domain.c:ns_print().
CriticalCVSS 9.8No exploitEPSS 2%tcpdump · tcpdumpSep 14, 2017
- CVE-2026-2481640Plan
Cookie Security Vulnerabilities in datavane/tis
CriticalCVSS 10.0No exploitEPSS 0%datavane · tisJan 27, 2026
- CVE-2023-171837Monitor
Bitrix24 Denial-of-Service (DoS) via Improper File Stream Access
HighCVSS 7.5Proof of conceptEPSS 24%bitrix24 · bitrix24Nov 1, 2023
- CVE-2017-1590837Monitor
In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in th
HighCVSS 7.5No exploitEPSS 24%systemd project · systemdOct 26, 2017
- CVE-2023-4536337Monitor
An issue was discovered in ApiPageSet.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1.
HighCVSS 7.5No exploitEPSS 23%mediawiki · mediawikiOct 9, 2023
- CVE-2022-4677037Monitor
qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS users to cause a denial of service (CPU consumpt
HighCVSS 7.5WeaponizedEPSS 22%linuxfoundation · mirage firewallDec 7, 2022
- CVE-2018-800237Monitor
In PoDoFo 0.9.5, there exists an infinite loop vulnerability in PdfParserObject::ParseFileComplete() in PdfParserObject.cpp which may result
HighCVSS 8.8Proof of conceptEPSS 8%podofo project · podofoMar 9, 2018
- CVE-2026-3144837Monitor
ext4: avoid infinite loops caused by residual data
CriticalCVSS 9.4No exploitEPSS 1%linux · linux kernelApr 22, 2026
- CVE-2018-133636Monitor
An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Den
HighCVSS 7.5No exploitEPSS 21%apache · tomcatAug 2, 2018
- CVE-2019-1821736Monitor
ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handling of overly long c
HighCVSS 7.5Proof of conceptEPSS 20%proftpd · proftpdOct 21, 2019