← Back
CWE-674

531 CVEs • Abstraction: Class

Uncontrolled Recursion

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

JSON object

Loading...

CVEs (531)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Artifex
Debian
2Debian Linux
Mupdf
Jun 17, 2026
Feb 2, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
pdf_load_obj_stm in pdf/pdf-xref.c in Artifex MuPDF 1.12.0 could reference the object stream recursively and therefore run out of error stack, which allows remote attackers to cause a denial of service via a crafted PDF...Show more
pdf_load_obj_stm in pdf/pdf-xref.c in Artifex MuPDF 1.12.0 could reference the object stream recursively and therefore run out of error stack, which allows remote attackers to cause a denial of service via a crafted PDF document.Show less
1Artifex
1Mujs
Jun 17, 2026
Jan 24, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
jsparse.c in Artifex MuJS through 1.0.2 does not properly maintain the AST depth for binary expressions, which allows remote attackers to cause a denial of service (excessive recursion) via a crafted file.
3Debian
FedoraprojectGnu
3Debian Linux
FedoraLibtasn1
Jun 17, 2026
Jan 22, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in the _asn1_decode_simple_ber function in decoding.c in GNU Libtasn1 before 4.13. Unlimited recursion in the BER decoder leads to stack exhaustion and DoS.
1Jquery
1Jquery
Nov 21, 2024
Jan 18, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
jQuery 3.0.0-rc.1 is vulnerable to Denial of Service (DoS) due to removing a logic that lowercased attribute names. Any attribute getter using a mixed-cased name for boolean attributes goes into an infinite recursion, ex...Show more
jQuery 3.0.0-rc.1 is vulnerable to Denial of Service (DoS) due to removing a logic that lowercased attribute names. Any attribute getter using a mixed-cased name for boolean attributes goes into an infinite recursion, exceeding the stack call limit.Show less
1Exiv2
1Exiv2
Jun 17, 2026
Jan 18, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In Exiv2 0.26, there is a segmentation fault caused by uncontrolled recursion in the Exiv2::Image::printIFDStructure function in the image.cpp file. Remote attackers could leverage this vulnerability to cause a denial of...Show more
In Exiv2 0.26, there is a segmentation fault caused by uncontrolled recursion in the Exiv2::Image::printIFDStructure function in the image.cpp file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tif file.Show less
1Mqtt.js Project
1Mqtt.js
May 13, 2026
Dec 28, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
MQTT.js 2.x.x prior to 2.15.0 issue in handling PUBLISH tickets may lead to an attacker causing a denial-of-service condition.
1Adobe
4Acrobat
Acrobat DcAcrobat Reader+1 more
May 13, 2026
Dec 9, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The issue is a stack e...Show more
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The issue is a stack exhaustion problem within the JavaScript API, where the computation does not correctly control the amount of recursion that can happen with respect to system resources.Show less
1Exiv2
1Exiv2
May 13, 2026
Sep 29, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
There is a stack consumption vulnerability in the Exiv2::Internal::stringFormat function of image.cpp in Exiv2 0.26. A Crafted input will lead to a remote denial of service attack.
1Libsass
1Libsass
May 13, 2026
Aug 18, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
There is a stack consumption issue in LibSass 3.4.5 that is triggered in the function Sass::Eval::operator() in eval.cpp. It will lead to a remote denial of service attack.
1Libsass
1Libsass
May 13, 2026
Jul 23, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
There is a stack consumption vulnerability in the Parser::advanceToNextToken function in parser.cpp in LibSass 3.4.5. A crafted input may lead to remote denial of service.
1Libsass
1Libsass
May 13, 2026
Jul 23, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
There is a stack consumption vulnerability in the lex function in parser.hpp (as used in sassc) in LibSass 3.4.5. A crafted input will lead to a remote denial of service.
1Pcre
1Pcre
May 13, 2026
Jul 11, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
In PCRE 8.41, the OP_KETRMAX feature in the match function in pcre_exec.c allows stack exhaustion (uncontrolled recursion) when processing a crafted regular expression.
1Google
1Android
May 13, 2026
Jul 6, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A denial of service vulnerability in the Android media framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36725407.
2Debian
Wireshark
2Debian Linux
Wireshark
May 13, 2026
Jun 21, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Wireshark 2.2.7, PROFINET IO data with a high recursion depth allows remote attackers to cause a denial of service (stack exhaustion) in the dissect_IODWriteReq function in plugins/profinet/packet-dcerpc-pn-io.c.
1Uclibc
1Uclibc
May 13, 2026
Jun 16, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In uClibc 0.9.33.2, there is stack exhaustion (uncontrolled recursion) in the check_dst_limits_calc_pos_1 function in misc/regex/regexec.c when processing a crafted regular expression.
1Wireshark
1Wireshark
May 13, 2026
Jun 14, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In Wireshark 2.2.7, deeply nested DAAP data may cause stack exhaustion (uncontrolled recursion) in the dissect_daap_one_tag function in epan/dissectors/packet-daap.c in the DAAP dissector.
1Wireshark
1Wireshark
May 13, 2026
Jun 14, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In Wireshark 2.2.7, overly deep mp4 chunks may cause stack exhaustion (uncontrolled recursion) in the dissect_mp4_box function in epan/dissectors/file-mp4.c.
1Freedesktop
1Poppler
May 13, 2026
Jun 6, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
poppler through version 0.55.0 is vulnerable to an uncontrolled recursion in pdfunite resulting into potential denial-of-service.
1Virustotal
1Yara
May 13, 2026
Jun 5, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
libyara/re.c in the regexp module in YARA 3.5.0 allows remote attackers to cause a denial of service (stack consumption) via a crafted rule (involving hex strings) that is mishandled in the _yr_re_emit function, a differ...Show more
libyara/re.c in the regexp module in YARA 3.5.0 allows remote attackers to cause a denial of service (stack consumption) via a crafted rule (involving hex strings) that is mishandled in the _yr_re_emit function, a different vulnerability than CVE-2017-9304.Show less
1Virustotal
1Yara
May 13, 2026
May 31, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
libyara/re.c in the regexp module in YARA 3.5.0 allows remote attackers to cause a denial of service (stack consumption) via a crafted rule that is mishandled in the _yr_re_emit function.