CWE-674— Uncontrolled Recursion
The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.— MITRE CWE catalog
469 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-674page 3 of 10
- CVE-2019-9543HIGHCVSS 8.8EG 8.82019-03-01
An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readGenericBitmap() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfseparate binary. It allows an attac…
- CVE-2019-9545HIGHCVSS 8.8EG 8.82019-03-01
An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readTextRegion() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker t…
- CVE-2019-9904MEDIUMCVSS 6.5EG 6.52019-03-21
An issue was discovered in lib\cdt\dttree.c in libcdt.a in graphviz 2.40.1. Stack consumption occurs because of recursive agclose calls in lib\cgraph\graph.c in libcgraph.a, related to agfstsubg in lib\cgraph\subg.c.
- CVE-2020-10089HIGHCVSS 7.5EG 7.52020-03-13
GitLab 8.11 through 12.8.1 allows a Denial of Service when using several features to recursively request eachother,
- CVE-2020-10704HIGHCVSS 7.5EG 7.52020-05-06
A flaw was found when using samba as an Active Directory Domain Controller. Due to the way samba handles certain requests as an Active Directory Domain Controller LDAP server, an unauthorized user can cause a stack overflow leading to a de…
- CVE-2020-10995HIGHCVSS 7.5EG 7.52020-05-19
PowerDNS Recursor from 4.1.0 up to and including 4.3.0 does not sufficiently defend against amplification attacks. An issue in the DNS protocol has been found that allow malicious parties to use recursive DNS services to attack third party…
- CVE-2020-11647HIGHCVSS 7.5EG 7.52020-04-10
In Wireshark 3.2.0 to 3.2.2, 3.0.0 to 3.0.9, and 2.6.0 to 2.6.15, the BACapp dissector could crash. This was addressed in epan/dissectors/packet-bacapp.c by limiting the amount of recursion.
- CVE-2020-12100HIGHCVSS 7.5EG 7.52020-08-12
In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resource consumption) via a crafted e-mail message with deeply nested MIME parts.
- CVE-2020-12243HIGHCVSS 7.5EG 7.52020-04-28
In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash).
- CVE-2020-12662HIGHCVSS 7.5EG 7.52020-05-19
Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NSDNAME in NS records.
- CVE-2020-12825HIGHCVSS 7.1EG 7.12020-05-12
libcroco through 0.6.13 has excessive recursion in cr_parser_parse_any_core in cr-parser.c, leading to stack consumption.
- CVE-2020-13164HIGHCVSS 7.5EG 7.52020-05-19
In Wireshark 3.2.0 to 3.2.3, 3.0.0 to 3.0.10, and 2.6.0 to 2.6.16, the NFS dissector could crash. This was addressed in epan/dissectors/packet-nfs.c by preventing excessive recursion, such as for a cycle in the directory graph on a filesys…
- CVE-2020-13800MEDIUMCVSS 6.0EG 6.02020-06-04
ati-vga in hw/display/ati.c in QEMU 4.2.0 allows guest OS users to trigger infinite recursion via a crafted mm_index value during an ati_mm_read or ati_mm_write call.
- CVE-2020-15101LOWCVSS 2.8EG 2.82020-07-14
In freewvs before 0.1.1, a directory structure of more than 1000 nested directories can interrupt a freewvs scan due to Python's recursion limit and os.walk(). This can be problematic in a case where an administrator scans the dirs of pote…
- CVE-2020-16094HIGHCVSS 7.5EG 7.52020-07-28
In imap_scan_tree_recursive in Claws Mail through 3.17.6, a malicious IMAP server can trigger stack consumption because of unlimited recursion into subdirectories during a rebuild of the folder tree.
- CVE-2020-18392MEDIUMCVSS 5.5EG 5.52021-05-28
Stack overflow vulnerability in parse_array Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.
- CVE-2020-18898MEDIUMCVSS 6.5EG 6.52021-08-19
A stack exhaustion issue in the printIFDStructure function of Exiv2 0.27 allows remote attackers to cause a denial of service (DOS) via a crafted file.
- CVE-2020-1898HIGHCVSS 7.5EG 7.52021-03-11
The fb_unserialize function did not impose a depth limit for nested deserialization. That meant a maliciously constructed string could cause deserialization to recurse, leading to stack exhaustion. This issue affected HHVM prior to v4.32.3…
- CVE-2020-20213MEDIUMCVSS 6.5EG 6.52021-07-07
Mikrotik RouterOs 6.44.5 (long-term tree) suffers from an stack exhaustion vulnerability in the /nova/bin/net process. An authenticated remote attacker can cause a Denial of Service due to overloading the systems CPU.
- CVE-2020-23804HIGHCVSS 7.5EG 7.52023-08-22
Uncontrolled Recursion in pdfinfo, and pdftops in poppler 0.89.0 allows remote attackers to cause a denial of service via crafted input.
- CVE-2020-25219HIGHCVSS 7.5EG 7.52020-09-09
url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a remote HTTP server to trigger uncontrolled recursion via a response composed of an infinite stream that lacks a newline character. This leads to stack exhaustion.
- CVE-2020-26882HIGHCVSS 7.5EG 7.52020-11-06
In Play Framework 2.6.0 through 2.8.2, data amplification can occur when an application accepts multipart/form-data JSON input.
- CVE-2020-26883HIGHCVSS 7.5EG 7.52020-11-06
In Play Framework 2.6.0 through 2.8.2, stack consumption can occur because of unbounded recursion during parsing of crafted JSON documents.
- CVE-2020-28196HIGHCVSS 7.5EG 7.52020-11-06
MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit.
- CVE-2020-28242MEDIUMCVSS 6.5EG 6.52020-11-06
An issue was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x before 17.8.1, and 18.x before 18.0.1 and Certified Asterisk before 16.8-cert5. If Asterisk is challenged on an outbound INVITE and the nonce is…
- CVE-2020-29566MEDIUMCVSS 5.5EG 5.52020-12-15
An issue was discovered in Xen through 4.14.x. When they require assistance from the device model, x86 HVM guests must be temporarily de-scheduled. The device model will signal Xen when it has completed its operation, via an event channel,…
- CVE-2020-36366MEDIUMCVSS 5.5EG 5.52021-05-28
Stack overflow vulnerability in parse_value Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.
- CVE-2020-36367MEDIUMCVSS 5.5EG 5.52021-05-28
Stack overflow vulnerability in parse_block Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.
- CVE-2020-36368MEDIUMCVSS 5.5EG 5.52021-05-28
Stack overflow vulnerability in parse_statement Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.
- CVE-2020-36369MEDIUMCVSS 5.5EG 5.52021-05-28
Stack overflow vulnerability in parse_statement_list Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.
- CVE-2020-36370MEDIUMCVSS 5.5EG 5.52021-05-28
Stack overflow vulnerability in parse_unary Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.
- CVE-2020-36371MEDIUMCVSS 5.5EG 5.52021-05-28
Stack overflow vulnerability in parse_mul_div_rem Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.
- CVE-2020-36372MEDIUMCVSS 5.5EG 5.52021-05-28
Stack overflow vulnerability in parse_plus_minus Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.
- CVE-2020-36373MEDIUMCVSS 5.5EG 5.52021-05-28
Stack overflow vulnerability in parse_shifts Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.
- CVE-2020-36374MEDIUMCVSS 5.5EG 5.52021-05-28
Stack overflow vulnerability in parse_comparison Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.
- CVE-2020-36375MEDIUMCVSS 5.5EG 5.52021-05-28
Stack overflow vulnerability in parse_equality Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.
- CVE-2020-36691MEDIUMCVSS 5.5EG 5.52023-03-24
An issue was discovered in the Linux kernel before 5.8. lib/nlattr.c allows attackers to cause a denial of service (unbounded recursion) via a nested Netlink policy with a back reference.
- CVE-2020-5591HIGHCVSS 7.5EG 7.52020-06-05
XACK DNS 1.11.0 to 1.11.4, 1.10.0 to 1.10.8, 1.8.0 to 1.8.23, 1.7.0 to 1.7.18, and versions before 1.7.0 allow remote attackers to cause a denial of service condition resulting in degradation of the recursive resolver's performance or comp…
- CVE-2020-6071HIGHCVSS 7.5EG 7.52020-03-24
An exploitable denial-of-service vulnerability exists in the resource record-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing compressed labels in mDNS messages, the compression pointer is followed without checking for re…
- CVE-2020-8285HIGHCVSS 7.5EG 7.52020-12-14
curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.
- CVE-2020-9243MEDIUMCVSS 5.5EG 5.52020-08-10
HUAWEI Mate 30 with versions earlier than 10.1.0.150(C00E136R5P3) have a denial of service vulnerability. The system does not properly limit the depth of recursion, an attacker should trick the user installing and execute a malicious appli…
- CVE-2020-9861HIGHCVSS 7.5EG 7.52020-11-02
A stack overflow issue existed in Swift for Linux. The issue was addressed with improved input validation for dealing with deeply nested malicious JSON input.
- CVE-2021-20255MEDIUMCVSS 5.5EG 5.52021-03-09
A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU. This issue occurs while processing controller commands due to a DMA reentry issue. This flaw allows a guest user or process …
- CVE-2021-21359MEDIUMCVSS 5.9EG 5.92021-03-23
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.25, 10.4.14, 11.1.1 requesting invalid or non-existing resources via HTTP triggers the page error handler which again could retrieve content to b…
- CVE-2021-22144MEDIUMCVSS 6.5EG 6.52021-07-26
In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial of service attack was identified in the Elasticsearch Grok parser. A user with the ability to submit arbitrary queries t…
- CVE-2021-22454MEDIUMCVSS 5.5EG 5.52021-10-28
A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause core dump.
- CVE-2021-27432HIGHCVSS 7.5EG 7.52021-05-20
OPC Foundation UA .NET Standard versions prior to 1.4.365.48 and OPC UA .NET Legacy are vulnerable to an uncontrolled recursion, which may allow an attacker to trigger a stack overflow.
- CVE-2021-27434HIGHCVSS 7.5EG 7.52021-05-20
Products with Unified Automation .NET based OPC UA Client/Server SDK Bundle: Versions V3.0.7 and prior (.NET 4.5, 4.0, and 3.5 Framework versions only) are vulnerable to an uncontrolled recursion, which may allow an attacker to trigger a s…
- CVE-2021-28040HIGHCVSS 7.5EG 7.52021-03-05
An issue was discovered in OSSEC 3.6.0. An uncontrolled recursion vulnerability in os_xml.c occurs when a large number of opening and closing XML tags is used. Because recursion is used in _ReadElem without restriction, an attacker can tri…
- CVE-2021-28210HIGHCVSS 7.8EG 7.82021-06-11
An unlimited recursion in DxeCore in EDK II.
Map vulnerabilities like CWE-674 to your infrastructure
EchelonGraph correlates every CVE — across CWE-674 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →