CWE-835 · 843 записей
Loop with Unreachable Exit Condition ('Infinite Loop')
CVE этого класса
845 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
85Срочно | CVE-2024-20353Готовый эксплойт | A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defenscisco · adaptive security appliance software · CWE-835 | Высокая8,6 | KEV | 70,7 % | 24 апр. 2024 г. |
56В плане | CVE-2020-13935Proof of concept | The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.apache · tomcat · CWE-835 | Высокая7,5 | — | 86,6 % | 14 июл. 2020 г. |
53В плане | CVE-2020-36227Эксплойта нет | A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in deopenldap · openldap · CWE-835 | Высокая7,5 | — | 77,2 % | 26 янв. 2021 г. |
52В плане | CVE-2022-0778Proof of concept | Infinite loop in BN_mod_sqrt() reachable when parsing certificatesopenssl · openssl · CWE-835 | Высокая7,5 | — | 73,2 % | 15 мар. 2022 г. |
51В плане | CVE-2019-14241Эксплойта нет | HAProxy through 2.0.2 allows attackers to cause a denial of service (ha_panic) via vectors related to htx_manage_client_side_cookies in prothaproxy · haproxy · CWE-835 | Высокая7,5 | — | 70,2 % | 23 июл. 2019 г. |
49В плане | CVE-2017-16944Proof of concept | The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinitexim · exim · CWE-835 | Высокая7,5 | — | 63,3 % | 25 нояб. 2017 г. |
49В плане | CVE-2023-34966Эксплойта нет | Samba: infinite loop in mdssvc rpc service for spotlightsamba · samba · CWE-835 | Высокая7,5 | — | 62,4 % | 20 июл. 2023 г. |
45В плане | CVE-2020-7046Эксплойта нет | lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrateddovecot · dovecot · CWE-835 | Высокая7,5 | — | 51,3 % | 12 февр. 2020 г. |
45В плане | CVE-2021-4044Proof of concept | Invalid handling of X509_verify_cert() internal errors in libsslopenssl · openssl · CWE-835 | Высокая7,5 | — | 50,1 % | 14 дек. 2021 г. |
45В плане | CVE-2022-23833Эксплойта нет | An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2.djangoproject · django · CWE-835 | Высокая7,5 | — | 49,5 % | 2 февр. 2022 г. |
44В плане | CVE-2019-5097Эксплойта нет | A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web server application in veembedthis · goahead · CWE-835 | Высокая7,5 | — | 45,1 % | 3 дек. 2019 г. |
42В плане | CVE-2024-50320Эксплойта нет | An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.ivanti · avalanche · CWE-835 | Высокая7,5 | — | 39,6 % | 12 нояб. 2024 г. |
40В плане | CVE-2018-20784Эксплойта нет | In the Linux kernel before 4.20.2, kernel/sched/fair.c mishandles leaf cfs_rq's, which allows attackers to cause a denial of service (infinilinux · linux kernel · CWE-835 | Критическая9,8 | — | 4,2 % | 22 февр. 2019 г. |
40В плане | CVE-2017-12990Эксплойта нет | The ISAKMP parser in tcpdump before 4.9.2 could enter an infinite loop due to bugs in print-isakmp.c, several functions.tcpdump · tcpdump · CWE-835 | Критическая9,8 | — | 2,5 % | 14 сент. 2017 г. |
40В плане | CVE-2017-12997Эксплойта нет | The LLDP parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-lldp.c:lldp_private_8021_print().tcpdump · tcpdump · CWE-835 | Критическая9,8 | — | 2,5 % | 14 сент. 2017 г. |
40В плане | CVE-2017-12995Эксплойта нет | The DNS parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-domain.c:ns_print().tcpdump · tcpdump · CWE-835 | Критическая9,8 | — | 2,4 % | 14 сент. 2017 г. |
40В плане | CVE-2026-24816Эксплойта нет | Cookie Security Vulnerabilities in datavane/tisdatavane · tis · CWE-835 | Критическая10,0 | — | 0,3 % | 27 янв. 2026 г. |
37Наблюдать | CVE-2023-1718Proof of concept | Bitrix24 Denial-of-Service (DoS) via Improper File Stream Accessbitrix24 · bitrix24 · CWE-835 | Высокая7,5 | — | 24,1 % | 1 нояб. 2023 г. |
37Наблюдать | CVE-2017-15908Эксплойта нет | In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in thsystemd project · systemd · CWE-835 | Высокая7,5 | — | 23,6 % | 26 окт. 2017 г. |
37Наблюдать | CVE-2023-45363Эксплойта нет | An issue was discovered in ApiPageSet.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1.mediawiki · mediawiki · CWE-835 | Высокая7,5 | — | 22,7 % | 9 окт. 2023 г. |
37Наблюдать | CVE-2022-46770Готовый эксплойт | qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS users to cause a denial of service (CPU consumptlinuxfoundation · mirage firewall · CWE-835 | Высокая7,5 | — | 21,7 % | 7 дек. 2022 г. |
37Наблюдать | CVE-2018-8002Proof of concept | In PoDoFo 0.9.5, there exists an infinite loop vulnerability in PdfParserObject::ParseFileComplete() in PdfParserObject.cpp which may resultpodofo project · podofo · CWE-835 | Высокая8,8 | — | 8,0 % | 9 мар. 2018 г. |
37Наблюдать | CVE-2026-31448Эксплойта нет | ext4: avoid infinite loops caused by residual datalinux · linux kernel · CWE-835 | Критическая9,4 | — | 0,7 % | 22 апр. 2026 г. |
36Наблюдать | CVE-2018-1336Эксплойта нет | An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denapache · tomcat · CWE-835 | Высокая7,5 | — | 20,6 % | 2 авг. 2018 г. |
36Наблюдать | CVE-2019-18217Proof of concept | ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handling of overly long cproftpd · proftpd · CWE-835 | Высокая7,5 | — | 20,3 % | 21 окт. 2019 г. |
- CVE-2024-2035385Срочно
A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defens
ВысокаяCVSS 8,6KEVГотовый эксплойтEPSS 71 %cisco · adaptive security appliance software24 апр. 2024 г.
- CVE-2020-1393556В плане
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.
ВысокаяCVSS 7,5Proof of conceptEPSS 87 %apache · tomcat14 июл. 2020 г.
- CVE-2020-3622753В плане
A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in de
ВысокаяCVSS 7,5Эксплойта нетEPSS 77 %openldap · openldap26 янв. 2021 г.
- CVE-2022-077852В плане
Infinite loop in BN_mod_sqrt() reachable when parsing certificates
ВысокаяCVSS 7,5Proof of conceptEPSS 73 %openssl · openssl15 мар. 2022 г.
- CVE-2019-1424151В плане
HAProxy through 2.0.2 allows attackers to cause a denial of service (ha_panic) via vectors related to htx_manage_client_side_cookies in prot
ВысокаяCVSS 7,5Эксплойта нетEPSS 70 %haproxy · haproxy23 июл. 2019 г.
- CVE-2017-1694449В плане
The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinit
ВысокаяCVSS 7,5Proof of conceptEPSS 63 %exim · exim25 нояб. 2017 г.
- CVE-2023-3496649В плане
Samba: infinite loop in mdssvc rpc service for spotlight
ВысокаяCVSS 7,5Эксплойта нетEPSS 62 %samba · samba20 июл. 2023 г.
- CVE-2020-704645В плане
lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated
ВысокаяCVSS 7,5Эксплойта нетEPSS 51 %dovecot · dovecot12 февр. 2020 г.
- CVE-2021-404445В плане
Invalid handling of X509_verify_cert() internal errors in libssl
ВысокаяCVSS 7,5Proof of conceptEPSS 50 %openssl · openssl14 дек. 2021 г.
- CVE-2022-2383345В плане
An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2.
ВысокаяCVSS 7,5Эксплойта нетEPSS 50 %djangoproject · django2 февр. 2022 г.
- CVE-2019-509744В плане
A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web server application in ve
ВысокаяCVSS 7,5Эксплойта нетEPSS 45 %embedthis · goahead3 дек. 2019 г.
- CVE-2024-5032042В плане
An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
ВысокаяCVSS 7,5Эксплойта нетEPSS 40 %ivanti · avalanche12 нояб. 2024 г.
- CVE-2018-2078440В плане
In the Linux kernel before 4.20.2, kernel/sched/fair.c mishandles leaf cfs_rq's, which allows attackers to cause a denial of service (infini
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %linux · linux kernel22 февр. 2019 г.
- CVE-2017-1299040В плане
The ISAKMP parser in tcpdump before 4.9.2 could enter an infinite loop due to bugs in print-isakmp.c, several functions.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %tcpdump · tcpdump14 сент. 2017 г.
- CVE-2017-1299740В плане
The LLDP parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-lldp.c:lldp_private_8021_print().
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %tcpdump · tcpdump14 сент. 2017 г.
- CVE-2017-1299540В плане
The DNS parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-domain.c:ns_print().
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %tcpdump · tcpdump14 сент. 2017 г.
- CVE-2026-2481640В плане
Cookie Security Vulnerabilities in datavane/tis
КритическаяCVSS 10,0Эксплойта нетEPSS 0 %datavane · tis27 янв. 2026 г.
- CVE-2023-171837Наблюдать
Bitrix24 Denial-of-Service (DoS) via Improper File Stream Access
ВысокаяCVSS 7,5Proof of conceptEPSS 24 %bitrix24 · bitrix241 нояб. 2023 г.
- CVE-2017-1590837Наблюдать
In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in th
ВысокаяCVSS 7,5Эксплойта нетEPSS 24 %systemd project · systemd26 окт. 2017 г.
- CVE-2023-4536337Наблюдать
An issue was discovered in ApiPageSet.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1.
ВысокаяCVSS 7,5Эксплойта нетEPSS 23 %mediawiki · mediawiki9 окт. 2023 г.
- CVE-2022-4677037Наблюдать
qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS users to cause a denial of service (CPU consumpt
ВысокаяCVSS 7,5Готовый эксплойтEPSS 22 %linuxfoundation · mirage firewall7 дек. 2022 г.
- CVE-2018-800237Наблюдать
In PoDoFo 0.9.5, there exists an infinite loop vulnerability in PdfParserObject::ParseFileComplete() in PdfParserObject.cpp which may result
ВысокаяCVSS 8,8Proof of conceptEPSS 8 %podofo project · podofo9 мар. 2018 г.
- CVE-2026-3144837Наблюдать
ext4: avoid infinite loops caused by residual data
КритическаяCVSS 9,4Эксплойта нетEPSS 1 %linux · linux kernel22 апр. 2026 г.
- CVE-2018-133636Наблюдать
An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Den
ВысокаяCVSS 7,5Эксплойта нетEPSS 21 %apache · tomcat2 авг. 2018 г.
- CVE-2019-1821736Наблюдать
ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handling of overly long c
ВысокаяCVSS 7,5Proof of conceptEPSS 20 %proftpd · proftpd21 окт. 2019 г.