CWE-835 · 843 kayıt
Loop with Unreachable Exit Condition ('Infinite Loop')
Bu sınıftaki CVE’ler
845 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
85Hemen | CVE-2024-20353Silahlaştırılmış | A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defenscisco · adaptive security appliance software · CWE-835 | Yüksek8,6 | KEV | %70,7 | 24 Nis 2024 |
56Planlayın | CVE-2020-13935Kavram kanıtı | The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.apache · tomcat · CWE-835 | Yüksek7,5 | — | %86,6 | 14 Tem 2020 |
53Planlayın | CVE-2020-36227İstismar yok | A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in deopenldap · openldap · CWE-835 | Yüksek7,5 | — | %77,2 | 26 Oca 2021 |
52Planlayın | CVE-2022-0778Kavram kanıtı | Infinite loop in BN_mod_sqrt() reachable when parsing certificatesopenssl · openssl · CWE-835 | Yüksek7,5 | — | %73,2 | 15 Mar 2022 |
51Planlayın | CVE-2019-14241İstismar yok | HAProxy through 2.0.2 allows attackers to cause a denial of service (ha_panic) via vectors related to htx_manage_client_side_cookies in prothaproxy · haproxy · CWE-835 | Yüksek7,5 | — | %70,2 | 23 Tem 2019 |
49Planlayın | CVE-2017-16944Kavram kanıtı | The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinitexim · exim · CWE-835 | Yüksek7,5 | — | %63,3 | 25 Kas 2017 |
49Planlayın | CVE-2023-34966İstismar yok | Samba: infinite loop in mdssvc rpc service for spotlightsamba · samba · CWE-835 | Yüksek7,5 | — | %62,4 | 20 Tem 2023 |
45Planlayın | CVE-2020-7046İstismar yok | lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrateddovecot · dovecot · CWE-835 | Yüksek7,5 | — | %51,3 | 12 Şub 2020 |
45Planlayın | CVE-2021-4044Kavram kanıtı | Invalid handling of X509_verify_cert() internal errors in libsslopenssl · openssl · CWE-835 | Yüksek7,5 | — | %50,1 | 14 Ara 2021 |
45Planlayın | CVE-2022-23833İstismar yok | An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2.djangoproject · django · CWE-835 | Yüksek7,5 | — | %49,5 | 2 Şub 2022 |
44Planlayın | CVE-2019-5097İstismar yok | A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web server application in veembedthis · goahead · CWE-835 | Yüksek7,5 | — | %45,1 | 3 Ara 2019 |
42Planlayın | CVE-2024-50320İstismar yok | An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.ivanti · avalanche · CWE-835 | Yüksek7,5 | — | %39,6 | 12 Kas 2024 |
40Planlayın | CVE-2018-20784İstismar yok | In the Linux kernel before 4.20.2, kernel/sched/fair.c mishandles leaf cfs_rq's, which allows attackers to cause a denial of service (infinilinux · linux kernel · CWE-835 | Kritik9,8 | — | %4,2 | 22 Şub 2019 |
40Planlayın | CVE-2017-12990İstismar yok | The ISAKMP parser in tcpdump before 4.9.2 could enter an infinite loop due to bugs in print-isakmp.c, several functions.tcpdump · tcpdump · CWE-835 | Kritik9,8 | — | %2,5 | 14 Eyl 2017 |
40Planlayın | CVE-2017-12997İstismar yok | The LLDP parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-lldp.c:lldp_private_8021_print().tcpdump · tcpdump · CWE-835 | Kritik9,8 | — | %2,5 | 14 Eyl 2017 |
40Planlayın | CVE-2017-12995İstismar yok | The DNS parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-domain.c:ns_print().tcpdump · tcpdump · CWE-835 | Kritik9,8 | — | %2,4 | 14 Eyl 2017 |
40Planlayın | CVE-2026-24816İstismar yok | Cookie Security Vulnerabilities in datavane/tisdatavane · tis · CWE-835 | Kritik10,0 | — | %0,3 | 27 Oca 2026 |
37İzleyin | CVE-2023-1718Kavram kanıtı | Bitrix24 Denial-of-Service (DoS) via Improper File Stream Accessbitrix24 · bitrix24 · CWE-835 | Yüksek7,5 | — | %24,1 | 1 Kas 2023 |
37İzleyin | CVE-2017-15908İstismar yok | In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in thsystemd project · systemd · CWE-835 | Yüksek7,5 | — | %23,6 | 26 Eki 2017 |
37İzleyin | CVE-2023-45363İstismar yok | An issue was discovered in ApiPageSet.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1.mediawiki · mediawiki · CWE-835 | Yüksek7,5 | — | %22,7 | 9 Eki 2023 |
37İzleyin | CVE-2022-46770Silahlaştırılmış | qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS users to cause a denial of service (CPU consumptlinuxfoundation · mirage firewall · CWE-835 | Yüksek7,5 | — | %21,7 | 7 Ara 2022 |
37İzleyin | CVE-2018-8002Kavram kanıtı | In PoDoFo 0.9.5, there exists an infinite loop vulnerability in PdfParserObject::ParseFileComplete() in PdfParserObject.cpp which may resultpodofo project · podofo · CWE-835 | Yüksek8,8 | — | %8,0 | 9 Mar 2018 |
37İzleyin | CVE-2026-31448İstismar yok | ext4: avoid infinite loops caused by residual datalinux · linux kernel · CWE-835 | Kritik9,4 | — | %0,7 | 22 Nis 2026 |
36İzleyin | CVE-2018-1336İstismar yok | An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denapache · tomcat · CWE-835 | Yüksek7,5 | — | %20,6 | 2 Ağu 2018 |
36İzleyin | CVE-2019-18217Kavram kanıtı | ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handling of overly long cproftpd · proftpd · CWE-835 | Yüksek7,5 | — | %20,3 | 21 Eki 2019 |
- CVE-2024-2035385Hemen
A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defens
YüksekCVSS 8,6KEVSilahlaştırılmışEPSS %71cisco · adaptive security appliance software24 Nis 2024
- CVE-2020-1393556Planlayın
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.
YüksekCVSS 7,5Kavram kanıtıEPSS %87apache · tomcat14 Tem 2020
- CVE-2020-3622753Planlayın
A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in de
YüksekCVSS 7,5İstismar yokEPSS %77openldap · openldap26 Oca 2021
- CVE-2022-077852Planlayın
Infinite loop in BN_mod_sqrt() reachable when parsing certificates
YüksekCVSS 7,5Kavram kanıtıEPSS %73openssl · openssl15 Mar 2022
- CVE-2019-1424151Planlayın
HAProxy through 2.0.2 allows attackers to cause a denial of service (ha_panic) via vectors related to htx_manage_client_side_cookies in prot
YüksekCVSS 7,5İstismar yokEPSS %70haproxy · haproxy23 Tem 2019
- CVE-2017-1694449Planlayın
The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinit
YüksekCVSS 7,5Kavram kanıtıEPSS %63exim · exim25 Kas 2017
- CVE-2023-3496649Planlayın
Samba: infinite loop in mdssvc rpc service for spotlight
YüksekCVSS 7,5İstismar yokEPSS %62samba · samba20 Tem 2023
- CVE-2020-704645Planlayın
lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated
YüksekCVSS 7,5İstismar yokEPSS %51dovecot · dovecot12 Şub 2020
- CVE-2021-404445Planlayın
Invalid handling of X509_verify_cert() internal errors in libssl
YüksekCVSS 7,5Kavram kanıtıEPSS %50openssl · openssl14 Ara 2021
- CVE-2022-2383345Planlayın
An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2.
YüksekCVSS 7,5İstismar yokEPSS %50djangoproject · django2 Şub 2022
- CVE-2019-509744Planlayın
A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web server application in ve
YüksekCVSS 7,5İstismar yokEPSS %45embedthis · goahead3 Ara 2019
- CVE-2024-5032042Planlayın
An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
YüksekCVSS 7,5İstismar yokEPSS %40ivanti · avalanche12 Kas 2024
- CVE-2018-2078440Planlayın
In the Linux kernel before 4.20.2, kernel/sched/fair.c mishandles leaf cfs_rq's, which allows attackers to cause a denial of service (infini
KritikCVSS 9,8İstismar yokEPSS %4linux · linux kernel22 Şub 2019
- CVE-2017-1299040Planlayın
The ISAKMP parser in tcpdump before 4.9.2 could enter an infinite loop due to bugs in print-isakmp.c, several functions.
KritikCVSS 9,8İstismar yokEPSS %3tcpdump · tcpdump14 Eyl 2017
- CVE-2017-1299740Planlayın
The LLDP parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-lldp.c:lldp_private_8021_print().
KritikCVSS 9,8İstismar yokEPSS %2tcpdump · tcpdump14 Eyl 2017
- CVE-2017-1299540Planlayın
The DNS parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-domain.c:ns_print().
KritikCVSS 9,8İstismar yokEPSS %2tcpdump · tcpdump14 Eyl 2017
- CVE-2026-2481640Planlayın
Cookie Security Vulnerabilities in datavane/tis
KritikCVSS 10,0İstismar yokEPSS %0datavane · tis27 Oca 2026
- CVE-2023-171837İzleyin
Bitrix24 Denial-of-Service (DoS) via Improper File Stream Access
YüksekCVSS 7,5Kavram kanıtıEPSS %24bitrix24 · bitrix241 Kas 2023
- CVE-2017-1590837İzleyin
In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in th
YüksekCVSS 7,5İstismar yokEPSS %24systemd project · systemd26 Eki 2017
- CVE-2023-4536337İzleyin
An issue was discovered in ApiPageSet.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1.
YüksekCVSS 7,5İstismar yokEPSS %23mediawiki · mediawiki9 Eki 2023
- CVE-2022-4677037İzleyin
qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS users to cause a denial of service (CPU consumpt
YüksekCVSS 7,5SilahlaştırılmışEPSS %22linuxfoundation · mirage firewall7 Ara 2022
- CVE-2018-800237İzleyin
In PoDoFo 0.9.5, there exists an infinite loop vulnerability in PdfParserObject::ParseFileComplete() in PdfParserObject.cpp which may result
YüksekCVSS 8,8Kavram kanıtıEPSS %8podofo project · podofo9 Mar 2018
- CVE-2026-3144837İzleyin
ext4: avoid infinite loops caused by residual data
KritikCVSS 9,4İstismar yokEPSS %1linux · linux kernel22 Nis 2026
- CVE-2018-133636İzleyin
An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Den
YüksekCVSS 7,5İstismar yokEPSS %21apache · tomcat2 Ağu 2018
- CVE-2019-1821736İzleyin
ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handling of overly long c
YüksekCVSS 7,5Kavram kanıtıEPSS %20proftpd · proftpd21 Eki 2019