CWE-835
874 CVEs • Abstraction: Base
Loop with Unreachable Exit Condition ('Infinite Loop')
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
CVEs (874)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Fedoraproject OracleWireshark4Fedora Http ServerWireshark+1 moreJun 17, 2026 Dec 30, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file |
An infinite loop vulnerability exists in nasm 2.16rc0 via the gpaste_tokens function. |
An infinite loop vulnerability exists in gpac 1.1.0 in the gf_log function, which causes a Denial of Service. |
An infinite loop vulnerability exists in Gpac 1.0.1 in gf_get_bit_size. |
3Netapp NodejsOpenssl16500f Firmware A250 FirmwareCloud Backup+13 moreJun 17, 2026 Dec 14, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server. That function may return a negative return value to indicate an internal error (for example out of me...Show more |
1Sonicwall 5Sma 200 Firmware Sma 210 FirmwareSma 400 Firmware+2 moreJun 17, 2026 Dec 8, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 An unauthenticated and remote adversary can consume all of the device's CPU due to crafted HTTP requests sent to SMA100 /fileshare/sonicfiles/sonicfiles resulting in a loop with unreachable exit condition. This vulnerabi...Show more |
2Cloudflare Debian2Debian Linux OctorpkiJun 17, 2026 Nov 11, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 OctoRPKI does not limit the depth of a certificate chain, allowing for a CA to create children in an ad-hoc fashion, thereby making tree traversal never end. |
NLnet Labs Routinator prior to 0.10.2 happily processes a chain of RRDP repositories of infinite length causing it to never finish a validation run. In RPKI, a CA can choose the RRDP repository it wishes to publish its d...Show more |
Irfanview v4.53 was discovered to contain an infinity loop via JPEG2000!ShowPlugInSaveOptions_W+0x1ecd8. |
2Apache Oracle9Banking Payments Banking Trade Finance Process ManagementBanking Treasury Management+6 moreJun 17, 2026 Nov 1, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is...Show more |
3Debian FedoraprojectNothings3Debian Linux FedoraStb Image.hJun 17, 2026 Oct 21, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in stb stb_image.h 1.33 through 2.27. The HDR loader parsed truncated end-of-file RLE scanlines as an infinite sequence of zero-length runs. An attacker could potentially have caused denial of ser...Show more |
1Juniper 2Junos Junos Os EvolvedJun 17, 2026 Oct 19, 2021 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 In an MPLS P2MP environment a Loop with Unreachable Exit Condition vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker to cause...Show more |
2Debian Tinyxml Project2Debian Linux TinyxmlJun 17, 2026 Oct 11, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxmlparser.cpp via the TIXML_UTF_LEAD_0 case. It can be triggered by a crafted XML message and leads to a denial of service. |
An issue was discovered in Zammad before 4.1.1. An attacker with valid agent credentials may send a series of crafted requests that cause an endless loop and thus cause denial of service. |
An issue was discovered in MediaWiki through 1.36.2. A parser function related to loop control allowed for an infinite loop (and php-fpm hang) within the Loops extension because egLoopsCountLimit is mishandled. This coul...Show more |
Irfanview 4.57 is affected by an infinite loop when processing a crafted BMP file in the EFFECTS!AutoCrop_W component. This can cause a denial of service (DOS). |
An infinite loop in Open Robotics ros_comm XMLRPC server in ROS Melodic through 1.4.11 and ROS Noetic through1.15.11 allows remote attackers to cause a Denial of Service in ros_comm via a crafted XMLRPC call. |
3Apache DebianNetapp3Debian Linux Management Services For Element Software And Netapp HciTomcatJun 17, 2026 Sep 16, 2021 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet...Show more |
2Fedoraproject Rencode Project2Fedora RencodeJun 17, 2026 Sep 10, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The rencode package through 1.0.6 for Python allows an infinite loop in typecode decoding (such as via ;\x2f\x7f), enabling a remote attack that consumes CPU and memory. |
1Qualcomm 155Apq8009 Firmware Apq8009w FirmwareApq8017 Firmware+152 moreJun 17, 2026 Sep 8, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Loop with unreachable exit condition may occur due to improper handling of unsupported input in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon...Show more |