← Back
CWE-834

108 CVEs • Abstraction: Class

Excessive Iteration

The product performs an iteration or loop without sufficiently limiting the number of times that the loop is executed.

JSON object

Loading...

CVEs (108)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Imagemagick
1Imagemagick
May 13, 2026
Jul 12, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The ReadDPXImage function in coders\dpx.c in ImageMagick 7.0.6-0 has a large loop vulnerability that can cause CPU exhaustion via a crafted DPX file, related to lack of an EOF check.
1Audiocoding
1Freeware Advanced Audio Decoder 2
May 13, 2026
Jun 27, 2017
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
The mp4ff_read_ctts function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file.
1Audiocoding
1Freeware Advanced Audio Decoder 2
May 13, 2026
Jun 27, 2017
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
The mp4ff_read_stco function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file.
1Audiocoding
1Freeware Advanced Audio Decoder 2
May 13, 2026
Jun 27, 2017
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
The mp4ff_read_stsc function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file.
1Audiocoding
1Freeware Advanced Audio Decoder 2
May 13, 2026
Jun 27, 2017
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
The mp4ff_read_stts function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file.
1Audiocoding
1Freeware Advanced Audio Decoder 2
May 13, 2026
Jun 27, 2017
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
The mp4ff_read_stsd function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file.
1Juniper
1Northstar Controller
May 13, 2026
Apr 24, 2017
N/A· v4
6.2 MEDIUM· v3
4.9 MEDIUM· v2
A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, local user, to create a fork bomb scenario, also known as a rabbi...Show more
A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, local user, to create a fork bomb scenario, also known as a rabbit virus, or wabbit, which will create processes that replicate themselves, until all resources are consumed on the system, leading to a denial of service to the entire system until it is restarted. Continued attacks by an unauthenticated, local user, can lead to persistent denials of services.Show less
2Debian
Qemu
2Debian Linux
Qemu
May 6, 2026
Dec 10, 2016
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
The pvscsi_ring_pop_req_descr function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure t...Show more
The pvscsi_ring_pop_req_descr function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure to limit process IO loop to the ring size.Show less