← Back
CWE-834

114 CVEs • Abstraction: Class

Excessive Iteration

The product performs an iteration or loop without sufficiently limiting the number of times that the loop is executed.

JSON object

Loading...

CVEs (114)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Imagemagick
1Imagemagick
May 13, 2026
Aug 7, 2017
N/A· v4
6.5 MEDIUM· v3
7.1 HIGH· v2
In ImageMagick 7.0.6-2, a CPU exhaustion vulnerability was found in the function ReadPDBImage in coders/pdb.c, which allows attackers to cause a denial of service.
1Imagemagick
1Imagemagick
May 13, 2026
Aug 6, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
ImageMagick 7.0.6-1 has a large loop vulnerability in the ReadPWPImage function in coders\pwp.c.
1Timidity++ Project
1Timidity++
May 13, 2026
Jul 31, 2017
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
The play_midi function in playmidi.c in TiMidity++ 2.14.0 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mid file. NOTE: CPU consumption might be relevant when using t...Show more
The play_midi function in playmidi.c in TiMidity++ 2.14.0 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mid file. NOTE: CPU consumption might be relevant when using the --background option.Show less
1Imagemagick
1Imagemagick
May 13, 2026
Jul 21, 2017
N/A· v4
6.5 MEDIUM· v3
7.1 HIGH· v2
The ReadOneJNGImage function in coders/png.c in ImageMagick through 6.9.9-0 and 7.x through 7.0.6-1 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a malformed JNG file.
2Debian
Wireshark
2Debian Linux
Wireshark
May 13, 2026
Jul 18, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
In Wireshark 2.0.0 to 2.0.13, the GPRS LLC dissector could go into a large loop. This was addressed in epan/dissectors/packet-gprs-llc.c by using a different integer data type.
1Imagemagick
1Imagemagick
May 13, 2026
Jul 17, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The ReadRLEImage function in coders\rle.c in ImageMagick 7.0.6-1 has a large loop vulnerability via a crafted rle file that triggers a huge number_pixels value.
1Imagemagick
1Imagemagick
May 13, 2026
Jul 12, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The ReadDPXImage function in coders\dpx.c in ImageMagick 7.0.6-0 has a large loop vulnerability that can cause CPU exhaustion via a crafted DPX file, related to lack of an EOF check.
1Audiocoding
1Freeware Advanced Audio Decoder 2
May 13, 2026
Jun 27, 2017
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
The mp4ff_read_ctts function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file.
1Audiocoding
1Freeware Advanced Audio Decoder 2
May 13, 2026
Jun 27, 2017
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
The mp4ff_read_stco function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file.
1Audiocoding
1Freeware Advanced Audio Decoder 2
May 13, 2026
Jun 27, 2017
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
The mp4ff_read_stsc function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file.
1Audiocoding
1Freeware Advanced Audio Decoder 2
May 13, 2026
Jun 27, 2017
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
The mp4ff_read_stts function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file.
1Audiocoding
1Freeware Advanced Audio Decoder 2
May 13, 2026
Jun 27, 2017
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
The mp4ff_read_stsd function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file.
1Juniper
1Northstar Controller
May 13, 2026
Apr 24, 2017
N/A· v4
6.2 MEDIUM· v3
4.9 MEDIUM· v2
A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, local user, to create a fork bomb scenario, also known as a rabbi...Show more
A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, local user, to create a fork bomb scenario, also known as a rabbit virus, or wabbit, which will create processes that replicate themselves, until all resources are consumed on the system, leading to a denial of service to the entire system until it is restarted. Continued attacks by an unauthenticated, local user, can lead to persistent denials of services.Show less
2Debian
Qemu
2Debian Linux
Qemu
May 6, 2026
Dec 10, 2016
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
The pvscsi_ring_pop_req_descr function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure t...Show more
The pvscsi_ring_pop_req_descr function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure to limit process IO loop to the ring size.Show less