← Back
CWE-835

874 CVEs • Abstraction: Base

Loop with Unreachable Exit Condition ('Infinite Loop')

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

JSON object

Loading...

CVEs (874)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Qemu
2Debian Linux
Qemu
May 13, 2026
Jun 8, 2017
N/A· v4
5.6 MEDIUM· v3
1.9 LOW· v2
QEMU (aka Quick Emulator), when built with the e1000e NIC emulation support, allows local guest OS privileged users to cause a denial of service (infinite loop) via vectors related to setting the initial receive / transm...Show more
QEMU (aka Quick Emulator), when built with the e1000e NIC emulation support, allows local guest OS privileged users to cause a denial of service (infinite loop) via vectors related to setting the initial receive / transmit descriptor head (TDH/RDH) outside the allocated descriptor buffer.Show less
1Strongswan
1Strongswan
May 13, 2026
Jun 8, 2017
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
The ASN.1 parser in strongSwan before 5.5.3 improperly handles CHOICE types when the x509 plugin is enabled, which allows remote attackers to cause a denial of service (infinite loop) via a crafted certificate.
3Debian
RedhatSamba
8Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+5 more
May 13, 2026
Jun 6, 2017
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulnerability (fd_open_atomic infinite loop with high CPU usage and memory consumption) due to wrongly handling dangling symlinks.
2Asterisk
Sangoma
2Asterisk
Certified Asterisk
May 13, 2026
Jun 2, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A memory exhaustion vulnerability exists in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1 and Certified Asterisk 13.13 before 13.13-cert4, which can be triggered by sending specially crafted SCCP packet...Show more
A memory exhaustion vulnerability exists in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1 and Certified Asterisk 13.13 before 13.13-cert4, which can be triggered by sending specially crafted SCCP packets causing an infinite loop and leading to memory exhaustion (by message logging in that loop).Show less
1Wireshark
1Wireshark
May 13, 2026
Jun 2, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the Bazaar dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-bzr.c by ensuring that backwards parsing cannot occur.
2Debian
Wireshark
2Debian Linux
Wireshark
May 13, 2026
Jun 2, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DICOM dissector has an infinite loop. This was addressed in epan/dissectors/packet-dcm.c by validating a length value.
1Wireshark
1Wireshark
May 13, 2026
Jun 2, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the SoulSeek dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-slsk.c by making loop bounds more explicit.
1Wireshark
1Wireshark
May 13, 2026
Jun 2, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DNS dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-dns.c by trying to detect self-referencing pointers.
2Canonical
Qpdf Project
2Qpdf
Ubuntu Linux
May 13, 2026
May 23, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to unparse functions, aka qpdf-infiniteloop3.
2Canonical
Qpdf Project
2Qpdf
Ubuntu Linux
May 13, 2026
May 23, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to QPDFObjectHandle::parseInternal, aka qpdf-infiniteloop2.
2Canonical
Qpdf Project
2Qpdf
Ubuntu Linux
May 13, 2026
May 23, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to releaseResolved functions, aka qpdf-infiniteloop1.
1Entropymine
1Imageworsener
May 13, 2026
May 19, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The lzw_add_to_dict function in imagew-gif.c in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted image.
1Entropymine
1Imageworsener
May 13, 2026
May 19, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The my_skip_input_data_fn function in imagew-jpeg.c in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted image.
2Debian
Qemu
2Debian Linux
Qemu
May 13, 2026
May 2, 2017
N/A· v4
6.5 MEDIUM· v3
4.9 MEDIUM· v2
hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (infinite loop and CPU consumption) via the message ring page count.
1Podofo Project
1Podofo
May 13, 2026
Apr 22, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The function PdfPagesTree::GetPageNodeFromArray in PdfPageTree.cpp:464 in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (infinite recursion and application crash) via a crafted PDF document.
1Podofo Project
1Podofo
May 13, 2026
Apr 22, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
PoDoFo 0.9.5 allows denial of service (infinite recursion and stack consumption) via a crafted PDF file in PoDoFo::PdfParser::ReadDocumentStructure (PdfParser.cpp).
3Apache
NettyRedhat
4Cassandra
Jboss Data GridJboss Middleware Text Only Advisories+1 more
May 13, 2026
Apr 13, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop).
1Wireshark
1Wireshark
May 13, 2026
Apr 12, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the WSP dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-wsp.c by adding a...Show more
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the WSP dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-wsp.c by adding a length check.Show less
2Debian
Wireshark
2Debian Linux
Wireshark
May 13, 2026
Apr 12, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the SLSK dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-slsk.c by adding...Show more
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the SLSK dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-slsk.c by adding checks for the remaining length.Show less
1Wireshark
1Wireshark
May 13, 2026
Apr 12, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the SIGCOMP dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-sigcomp.c by...Show more
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the SIGCOMP dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-sigcomp.c by correcting a memory-size check.Show less