CWE-834 · 89 записей
Excessive Iteration
CVE этого класса
89 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
36Наблюдать | CVE-2017-12587Эксплойта нет | ImageMagick 7.0.6-1 has a large loop vulnerability in the ReadPWPImage function in coders\pwp.c.imagemagick · imagemagick · CWE-834 | Высокая8,8 | — | 2,0 % | 6 авг. 2017 г. |
34Наблюдать | CVE-2026-59644Эксплойта нет | MLS hash-ratchet honours arbitrary 32-bit generation counter from senderbouncycastle · bc-java · CWE-834 | Высокая8,7 | — | 0,5 % | 2 авг. 2026 г. |
33Наблюдать | CVE-2021-35515Эксплойта нет | Apache Commons Compress 1.6 to 1.20 denial of service vulnerabilityapache · commons compress · CWE-834 | Высокая7,5 | — | 11,6 % | 13 июл. 2021 г. |
32Наблюдать | CVE-2021-39924Эксплойта нет | Large loop in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or cwireshark · wireshark · CWE-834 | Высокая7,5 | — | 5,3 % | 19 нояб. 2021 г. |
32Наблюдать | CVE-2026-64641Эксплойта нет | Next.js: Denial of Service in App Router using Server Actionsvercel · next.js · CWE-834 | Высокая8,2 | — | 0,9 % | 27 июл. 2026 г. |
31Наблюдать | CVE-2018-14342Эксплойта нет | In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the BGP protocol dissector could go into a large loop.wireshark · wireshark · CWE-834 | Высокая7,5 | — | 3,7 % | 18 июл. 2018 г. |
31Наблюдать | CVE-2020-14303Эксплойта нет | A flaw was found in the AD DC NBT server in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4.samba · samba · CWE-834 | Высокая7,5 | — | 3,5 % | 6 июл. 2020 г. |
31Наблюдать | CVE-2018-11813Эксплойта нет | libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF.ijg · libjpeg · CWE-834 | Высокая7,5 | — | 3,2 % | 5 июн. 2018 г. |
31Наблюдать | CVE-2021-4190Эксплойта нет | Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service via packet injection or crafted capture filewireshark · wireshark · CWE-834 | Высокая7,5 | — | 3,1 % | 30 дек. 2021 г. |
31Наблюдать | CVE-2018-9261Эксплойта нет | In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the NBAP dissector could crash with a large loop that ends with a heap-based buffer overflowireshark · wireshark · CWE-834 | Высокая7,5 | — | 2,8 % | 4 апр. 2018 г. |
31Наблюдать | CVE-2019-3565Эксплойта нет | Legacy C++ Facebook Thrift servers (using cpp instead of cpp2) would not error upon receiving messages with containers of fields of unknown facebook · thrift · CWE-834 | Высокая7,5 | — | 2,8 % | 6 мая 2019 г. |
31Наблюдать | CVE-2020-35573Эксплойта нет | srs2.c in PostSRSd before 1.10 allows remote attackers to cause a denial of service (CPU consumption) via a long timestamp tag in an SRS addpostsrsd project · postsrsd · CWE-834 | Высокая7,5 | — | 2,7 % | 20 дек. 2020 г. |
31Наблюдать | CVE-2018-7323Эксплойта нет | In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-wccp.c had a large loop that was addressed by ensuring that a calculwireshark · wireshark · CWE-834 | Высокая7,5 | — | 2,5 % | 23 февр. 2018 г. |
31Наблюдать | CVE-2017-11409Эксплойта нет | In Wireshark 2.0.0 to 2.0.13, the GPRS LLC dissector could go into a large loop.wireshark · wireshark · CWE-834 | Высокая7,5 | — | 2,3 % | 18 июл. 2017 г. |
31Наблюдать | CVE-2021-3128Эксплойта нет | In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42095 or < 9.0.0.4.386.41994, when IPv6 isasus · zenwifi ax \(xt8\) firmware · CWE-834 | Высокая7,5 | — | 2,2 % | 12 апр. 2021 г. |
31Наблюдать | CVE-2019-3558Эксплойта нет | Python Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type.facebook · thrift · CWE-834 | Высокая7,5 | — | 2,0 % | 6 мая 2019 г. |
31Наблюдать | CVE-2019-3559Эксплойта нет | Java Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type.facebook · thrift · CWE-834 | Высокая7,5 | — | 2,0 % | 6 мая 2019 г. |
31Наблюдать | CVE-2019-3564Эксплойта нет | Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type.facebook · thrift · CWE-834 | Высокая7,5 | — | 2,0 % | 6 мая 2019 г. |
31Наблюдать | CVE-2019-3552Эксплойта нет | C++ Facebook Thrift servers (using cpp2) would not error upon receiving messages with containers of fields of unknown type.facebook · thrift · CWE-834 | Высокая7,5 | — | 2,0 % | 6 мая 2019 г. |
31Наблюдать | CVE-2017-11188Эксплойта нет | The ReadDPXImage function in coders\dpx.c in ImageMagick 7.0.6-0 has a large loop vulnerability that can cause CPU exhaustion via a crafted imagemagick · imagemagick · CWE-834 | Высокая7,5 | — | 1,8 % | 12 июл. 2017 г. |
31Наблюдать | CVE-2018-7321Эксплойта нет | In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-thrift.c had a large loop that was addressed by not proceeding with wireshark · wireshark · CWE-834 | Высокая7,5 | — | 1,7 % | 23 февр. 2018 г. |
30Наблюдать | CVE-2021-39204Эксплойта нет | Excessive CPU usage in Pomeriumpomerium · pomerium · CWE-834 | Высокая7,5 | — | 1,7 % | 9 сент. 2021 г. |
30Наблюдать | CVE-2021-39923Эксплойта нет | Large loop in the PNRP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted cawireshark · wireshark · CWE-834 | Высокая7,5 | — | 1,6 % | 19 нояб. 2021 г. |
30Наблюдать | CVE-2021-3125Эксплойта нет | In TP-Link TL-XDR3230 < 1.0.12, TL-XDR1850 < 1.0.9, TL-XDR1860 < 1.0.14, TL-XDR3250 < 1.0.2, TL-XDR6060 Turbo < 1.1.8, TL-XDR5430 < 1.0.11, tp-link · tl-xdr3230 firmware · CWE-834 | Высокая7,5 | — | 1,5 % | 12 апр. 2021 г. |
30Наблюдать | CVE-2023-26513Эксплойта нет | Apache Sling Resource Merger: Requests to certain paths managed by the Apache Sling Resource Merger can lead to DoSapache · sling resource merger · CWE-834 | Высокая7,5 | — | 1,5 % | 20 мар. 2023 г. |
- CVE-2017-1258736Наблюдать
ImageMagick 7.0.6-1 has a large loop vulnerability in the ReadPWPImage function in coders\pwp.c.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %imagemagick · imagemagick6 авг. 2017 г.
- CVE-2026-5964434Наблюдать
MLS hash-ratchet honours arbitrary 32-bit generation counter from sender
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %bouncycastle · bc-java2 авг. 2026 г.
- CVE-2021-3551533Наблюдать
Apache Commons Compress 1.6 to 1.20 denial of service vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 12 %apache · commons compress13 июл. 2021 г.
- CVE-2021-3992432Наблюдать
Large loop in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or c
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %wireshark · wireshark19 нояб. 2021 г.
- CVE-2026-6464132Наблюдать
Next.js: Denial of Service in App Router using Server Actions
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %vercel · next.js27 июл. 2026 г.
- CVE-2018-1434231Наблюдать
In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the BGP protocol dissector could go into a large loop.
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %wireshark · wireshark18 июл. 2018 г.
- CVE-2020-1430331Наблюдать
A flaw was found in the AD DC NBT server in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4.
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %samba · samba6 июл. 2020 г.
- CVE-2018-1181331Наблюдать
libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %ijg · libjpeg5 июн. 2018 г.
- CVE-2021-419031Наблюдать
Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service via packet injection or crafted capture file
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %wireshark · wireshark30 дек. 2021 г.
- CVE-2018-926131Наблюдать
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the NBAP dissector could crash with a large loop that ends with a heap-based buffer overflo
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %wireshark · wireshark4 апр. 2018 г.
- CVE-2019-356531Наблюдать
Legacy C++ Facebook Thrift servers (using cpp instead of cpp2) would not error upon receiving messages with containers of fields of unknown
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %facebook · thrift6 мая 2019 г.
- CVE-2020-3557331Наблюдать
srs2.c in PostSRSd before 1.10 allows remote attackers to cause a denial of service (CPU consumption) via a long timestamp tag in an SRS add
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %postsrsd project · postsrsd20 дек. 2020 г.
- CVE-2018-732331Наблюдать
In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-wccp.c had a large loop that was addressed by ensuring that a calcul
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %wireshark · wireshark23 февр. 2018 г.
- CVE-2017-1140931Наблюдать
In Wireshark 2.0.0 to 2.0.13, the GPRS LLC dissector could go into a large loop.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %wireshark · wireshark18 июл. 2017 г.
- CVE-2021-312831Наблюдать
In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42095 or < 9.0.0.4.386.41994, when IPv6 is
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %asus · zenwifi ax \(xt8\) firmware12 апр. 2021 г.
- CVE-2019-355831Наблюдать
Python Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %facebook · thrift6 мая 2019 г.
- CVE-2019-355931Наблюдать
Java Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %facebook · thrift6 мая 2019 г.
- CVE-2019-356431Наблюдать
Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %facebook · thrift6 мая 2019 г.
- CVE-2019-355231Наблюдать
C++ Facebook Thrift servers (using cpp2) would not error upon receiving messages with containers of fields of unknown type.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %facebook · thrift6 мая 2019 г.
- CVE-2017-1118831Наблюдать
The ReadDPXImage function in coders\dpx.c in ImageMagick 7.0.6-0 has a large loop vulnerability that can cause CPU exhaustion via a crafted
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %imagemagick · imagemagick12 июл. 2017 г.
- CVE-2018-732131Наблюдать
In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-thrift.c had a large loop that was addressed by not proceeding with
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %wireshark · wireshark23 февр. 2018 г.
- CVE-2021-3920430Наблюдать
Excessive CPU usage in Pomerium
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %pomerium · pomerium9 сент. 2021 г.
- CVE-2021-3992330Наблюдать
Large loop in the PNRP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted ca
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %wireshark · wireshark19 нояб. 2021 г.
- CVE-2021-312530Наблюдать
In TP-Link TL-XDR3230 < 1.0.12, TL-XDR1850 < 1.0.9, TL-XDR1860 < 1.0.14, TL-XDR3250 < 1.0.2, TL-XDR6060 Turbo < 1.1.8, TL-XDR5430 < 1.0.11,
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %tp-link · tl-xdr3230 firmware12 апр. 2021 г.
- CVE-2023-2651330Наблюдать
Apache Sling Resource Merger: Requests to certain paths managed by the Apache Sling Resource Merger can lead to DoS
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %apache · sling resource merger20 мар. 2023 г.