CWE-834 · 89 kayıt
Excessive Iteration
Bu sınıftaki CVE’ler
89 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
36İzleyin | CVE-2017-12587İstismar yok | ImageMagick 7.0.6-1 has a large loop vulnerability in the ReadPWPImage function in coders\pwp.c.imagemagick · imagemagick · CWE-834 | Yüksek8,8 | — | %2,0 | 6 Ağu 2017 |
34İzleyin | CVE-2026-59644İstismar yok | MLS hash-ratchet honours arbitrary 32-bit generation counter from senderbouncycastle · bc-java · CWE-834 | Yüksek8,7 | — | %0,5 | 2 Ağu 2026 |
33İzleyin | CVE-2021-35515İstismar yok | Apache Commons Compress 1.6 to 1.20 denial of service vulnerabilityapache · commons compress · CWE-834 | Yüksek7,5 | — | %11,6 | 13 Tem 2021 |
32İzleyin | CVE-2021-39924İstismar yok | Large loop in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or cwireshark · wireshark · CWE-834 | Yüksek7,5 | — | %5,3 | 19 Kas 2021 |
32İzleyin | CVE-2026-64641İstismar yok | Next.js: Denial of Service in App Router using Server Actionsvercel · next.js · CWE-834 | Yüksek8,2 | — | %0,9 | 27 Tem 2026 |
31İzleyin | CVE-2018-14342İstismar yok | In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the BGP protocol dissector could go into a large loop.wireshark · wireshark · CWE-834 | Yüksek7,5 | — | %3,7 | 18 Tem 2018 |
31İzleyin | CVE-2020-14303İstismar yok | A flaw was found in the AD DC NBT server in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4.samba · samba · CWE-834 | Yüksek7,5 | — | %3,5 | 6 Tem 2020 |
31İzleyin | CVE-2018-11813İstismar yok | libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF.ijg · libjpeg · CWE-834 | Yüksek7,5 | — | %3,2 | 5 Haz 2018 |
31İzleyin | CVE-2021-4190İstismar yok | Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service via packet injection or crafted capture filewireshark · wireshark · CWE-834 | Yüksek7,5 | — | %3,1 | 30 Ara 2021 |
31İzleyin | CVE-2018-9261İstismar yok | In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the NBAP dissector could crash with a large loop that ends with a heap-based buffer overflowireshark · wireshark · CWE-834 | Yüksek7,5 | — | %2,8 | 4 Nis 2018 |
31İzleyin | CVE-2019-3565İstismar yok | Legacy C++ Facebook Thrift servers (using cpp instead of cpp2) would not error upon receiving messages with containers of fields of unknown facebook · thrift · CWE-834 | Yüksek7,5 | — | %2,8 | 6 May 2019 |
31İzleyin | CVE-2020-35573İstismar yok | srs2.c in PostSRSd before 1.10 allows remote attackers to cause a denial of service (CPU consumption) via a long timestamp tag in an SRS addpostsrsd project · postsrsd · CWE-834 | Yüksek7,5 | — | %2,7 | 20 Ara 2020 |
31İzleyin | CVE-2018-7323İstismar yok | In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-wccp.c had a large loop that was addressed by ensuring that a calculwireshark · wireshark · CWE-834 | Yüksek7,5 | — | %2,5 | 23 Şub 2018 |
31İzleyin | CVE-2017-11409İstismar yok | In Wireshark 2.0.0 to 2.0.13, the GPRS LLC dissector could go into a large loop.wireshark · wireshark · CWE-834 | Yüksek7,5 | — | %2,3 | 18 Tem 2017 |
31İzleyin | CVE-2021-3128İstismar yok | In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42095 or < 9.0.0.4.386.41994, when IPv6 isasus · zenwifi ax \(xt8\) firmware · CWE-834 | Yüksek7,5 | — | %2,2 | 12 Nis 2021 |
31İzleyin | CVE-2019-3558İstismar yok | Python Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type.facebook · thrift · CWE-834 | Yüksek7,5 | — | %2,0 | 6 May 2019 |
31İzleyin | CVE-2019-3559İstismar yok | Java Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type.facebook · thrift · CWE-834 | Yüksek7,5 | — | %2,0 | 6 May 2019 |
31İzleyin | CVE-2019-3564İstismar yok | Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type.facebook · thrift · CWE-834 | Yüksek7,5 | — | %2,0 | 6 May 2019 |
31İzleyin | CVE-2019-3552İstismar yok | C++ Facebook Thrift servers (using cpp2) would not error upon receiving messages with containers of fields of unknown type.facebook · thrift · CWE-834 | Yüksek7,5 | — | %2,0 | 6 May 2019 |
31İzleyin | CVE-2018-7321İstismar yok | In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-thrift.c had a large loop that was addressed by not proceeding with wireshark · wireshark · CWE-834 | Yüksek7,5 | — | %1,7 | 23 Şub 2018 |
30İzleyin | CVE-2021-39204İstismar yok | Excessive CPU usage in Pomeriumpomerium · pomerium · CWE-834 | Yüksek7,5 | — | %1,7 | 9 Eyl 2021 |
30İzleyin | CVE-2021-39923İstismar yok | Large loop in the PNRP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted cawireshark · wireshark · CWE-834 | Yüksek7,5 | — | %1,6 | 19 Kas 2021 |
30İzleyin | CVE-2017-11188İstismar yok | The ReadDPXImage function in coders\dpx.c in ImageMagick 7.0.6-0 has a large loop vulnerability that can cause CPU exhaustion via a crafted imagemagick · imagemagick · CWE-834 | Yüksek7,5 | — | %1,6 | 12 Tem 2017 |
30İzleyin | CVE-2021-3125İstismar yok | In TP-Link TL-XDR3230 < 1.0.12, TL-XDR1850 < 1.0.9, TL-XDR1860 < 1.0.14, TL-XDR3250 < 1.0.2, TL-XDR6060 Turbo < 1.1.8, TL-XDR5430 < 1.0.11, tp-link · tl-xdr3230 firmware · CWE-834 | Yüksek7,5 | — | %1,5 | 12 Nis 2021 |
30İzleyin | CVE-2023-26513İstismar yok | Apache Sling Resource Merger: Requests to certain paths managed by the Apache Sling Resource Merger can lead to DoSapache · sling resource merger · CWE-834 | Yüksek7,5 | — | %1,5 | 20 Mar 2023 |
- CVE-2017-1258736İzleyin
ImageMagick 7.0.6-1 has a large loop vulnerability in the ReadPWPImage function in coders\pwp.c.
YüksekCVSS 8,8İstismar yokEPSS %2imagemagick · imagemagick6 Ağu 2017
- CVE-2026-5964434İzleyin
MLS hash-ratchet honours arbitrary 32-bit generation counter from sender
YüksekCVSS 8,7İstismar yokEPSS %0bouncycastle · bc-java2 Ağu 2026
- CVE-2021-3551533İzleyin
Apache Commons Compress 1.6 to 1.20 denial of service vulnerability
YüksekCVSS 7,5İstismar yokEPSS %12apache · commons compress13 Tem 2021
- CVE-2021-3992432İzleyin
Large loop in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or c
YüksekCVSS 7,5İstismar yokEPSS %5wireshark · wireshark19 Kas 2021
- CVE-2026-6464132İzleyin
Next.js: Denial of Service in App Router using Server Actions
YüksekCVSS 8,2İstismar yokEPSS %1vercel · next.js27 Tem 2026
- CVE-2018-1434231İzleyin
In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the BGP protocol dissector could go into a large loop.
YüksekCVSS 7,5İstismar yokEPSS %4wireshark · wireshark18 Tem 2018
- CVE-2020-1430331İzleyin
A flaw was found in the AD DC NBT server in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4.
YüksekCVSS 7,5İstismar yokEPSS %4samba · samba6 Tem 2020
- CVE-2018-1181331İzleyin
libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF.
YüksekCVSS 7,5İstismar yokEPSS %3ijg · libjpeg5 Haz 2018
- CVE-2021-419031İzleyin
Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service via packet injection or crafted capture file
YüksekCVSS 7,5İstismar yokEPSS %3wireshark · wireshark30 Ara 2021
- CVE-2018-926131İzleyin
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the NBAP dissector could crash with a large loop that ends with a heap-based buffer overflo
YüksekCVSS 7,5İstismar yokEPSS %3wireshark · wireshark4 Nis 2018
- CVE-2019-356531İzleyin
Legacy C++ Facebook Thrift servers (using cpp instead of cpp2) would not error upon receiving messages with containers of fields of unknown
YüksekCVSS 7,5İstismar yokEPSS %3facebook · thrift6 May 2019
- CVE-2020-3557331İzleyin
srs2.c in PostSRSd before 1.10 allows remote attackers to cause a denial of service (CPU consumption) via a long timestamp tag in an SRS add
YüksekCVSS 7,5İstismar yokEPSS %3postsrsd project · postsrsd20 Ara 2020
- CVE-2018-732331İzleyin
In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-wccp.c had a large loop that was addressed by ensuring that a calcul
YüksekCVSS 7,5İstismar yokEPSS %2wireshark · wireshark23 Şub 2018
- CVE-2017-1140931İzleyin
In Wireshark 2.0.0 to 2.0.13, the GPRS LLC dissector could go into a large loop.
YüksekCVSS 7,5İstismar yokEPSS %2wireshark · wireshark18 Tem 2017
- CVE-2021-312831İzleyin
In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42095 or < 9.0.0.4.386.41994, when IPv6 is
YüksekCVSS 7,5İstismar yokEPSS %2asus · zenwifi ax \(xt8\) firmware12 Nis 2021
- CVE-2019-355831İzleyin
Python Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type.
YüksekCVSS 7,5İstismar yokEPSS %2facebook · thrift6 May 2019
- CVE-2019-355931İzleyin
Java Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type.
YüksekCVSS 7,5İstismar yokEPSS %2facebook · thrift6 May 2019
- CVE-2019-356431İzleyin
Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type.
YüksekCVSS 7,5İstismar yokEPSS %2facebook · thrift6 May 2019
- CVE-2019-355231İzleyin
C++ Facebook Thrift servers (using cpp2) would not error upon receiving messages with containers of fields of unknown type.
YüksekCVSS 7,5İstismar yokEPSS %2facebook · thrift6 May 2019
- CVE-2018-732131İzleyin
In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-thrift.c had a large loop that was addressed by not proceeding with
YüksekCVSS 7,5İstismar yokEPSS %2wireshark · wireshark23 Şub 2018
- CVE-2021-3920430İzleyin
Excessive CPU usage in Pomerium
YüksekCVSS 7,5İstismar yokEPSS %2pomerium · pomerium9 Eyl 2021
- CVE-2021-3992330İzleyin
Large loop in the PNRP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted ca
YüksekCVSS 7,5İstismar yokEPSS %2wireshark · wireshark19 Kas 2021
- CVE-2017-1118830İzleyin
The ReadDPXImage function in coders\dpx.c in ImageMagick 7.0.6-0 has a large loop vulnerability that can cause CPU exhaustion via a crafted
YüksekCVSS 7,5İstismar yokEPSS %2imagemagick · imagemagick12 Tem 2017
- CVE-2021-312530İzleyin
In TP-Link TL-XDR3230 < 1.0.12, TL-XDR1850 < 1.0.9, TL-XDR1860 < 1.0.14, TL-XDR3250 < 1.0.2, TL-XDR6060 Turbo < 1.1.8, TL-XDR5430 < 1.0.11,
YüksekCVSS 7,5İstismar yokEPSS %2tp-link · tl-xdr3230 firmware12 Nis 2021
- CVE-2023-2651330İzleyin
Apache Sling Resource Merger: Requests to certain paths managed by the Apache Sling Resource Merger can lead to DoS
YüksekCVSS 7,5İstismar yokEPSS %1apache · sling resource merger20 Mar 2023