CWE-835— Loop with Unreachable Exit Condition (Infinite Loop)
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.— MITRE CWE catalog
883 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-835page 10 of 18
- CVE-2021-42715MEDIUMCVSS 5.5EG 5.52021-10-21
An issue was discovered in stb stb_image.h 1.33 through 2.27. The HDR loader parsed truncated end-of-file RLE scanlines as an infinite sequence of zero-length runs. An attacker could potentially have caused denial of service in application…
- CVE-2021-43172HIGHCVSS 7.5EG 7.52021-11-09
NLnet Labs Routinator prior to 0.10.2 happily processes a chain of RRDP repositories of infinite length causing it to never finish a validation run. In RPKI, a CA can choose the RRDP repository it wishes to publish its data in. By continuo…
- CVE-2021-44718MEDIUMCVSS 5.9EG 5.92022-09-02
wolfSSL through 5.0.0 allows an attacker to cause a denial of service and infinite loop in the client component by sending crafted traffic from a Machine-in-the-Middle (MITM) position. The root cause is that the client module accepts TLS m…
- CVE-2021-44924MEDIUMCVSS 5.5EG 5.52021-12-21
An infinite loop vulnerability exists in gpac 1.1.0 in the gf_log function, which causes a Denial of Service.
- CVE-2021-45257MEDIUMCVSS 5.5EG 5.52021-12-22
An infinite loop vulnerability exists in nasm 2.16rc0 via the gpaste_tokens function.
- CVE-2021-45297MEDIUMCVSS 5.5EG 5.52021-12-21
An infinite loop vulnerability exists in Gpac 1.0.1 in gf_get_bit_size.
- CVE-2021-45445HIGHCVSS 7.5EG 7.52022-01-12
Unisys ClearPath MCP TCP/IP Networking Services 59.1, 60.0, and 62.0 has an Infinite Loop.
- CVE-2021-46828HIGHCVSS 7.5EG 7.52022-07-20
In libtirpc before 1.3.3rc1, remote attackers could exhaust the file descriptors of a process that uses libtirpc because idle TCP connections are mishandled. This can, in turn, lead to an svc_run infinite loop without accepting new connect…
- CVE-2021-47159MEDIUMCVSS 5.5EG 5.52024-03-25
In the Linux kernel, the following vulnerability has been resolved: net: dsa: fix a crash if ->get_sset_count() fails If ds->ops->get_sset_count() fails then it "count" is a negative error code such as -EOPNOTSUPP. Because "i" is an uns…
- CVE-2021-47406MEDIUMCVSS 5.5EG 5.52024-05-21
In the Linux kernel, the following vulnerability has been resolved: ext4: add error checking to ext4_ext_replay_set_iblocks() If the call to ext4_map_blocks() fails due to an corrupted file system, ext4_ext_replay_set_iblocks() can get s…
- CVE-2021-47448MEDIUMCVSS 5.5EG 5.52024-05-22
In the Linux kernel, the following vulnerability has been resolved: mptcp: fix possible stall on recvmsg() recvmsg() can enter an infinite loop if the caller provides the MSG_WAITALL, the data present in the receive queue is not sufficie…
- CVE-2021-47617MEDIUMCVSS 5.5EG 5.52024-06-20
In the Linux kernel, the following vulnerability has been resolved: PCI: pciehp: Fix infinite loop in IRQ handler upon power fault The Power Fault Detected bit in the Slot Status register differs from all other hotplug events in that it …
- CVE-2022-0586HIGHCVSS 6.3EG 7.52022-02-14
Infinite loop in RTMPT protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file
- CVE-2022-0711HIGHCVSS 7.5EG 7.52022-03-02
A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of s…
- CVE-2022-0778HIGHCVSS 7.5EG 8.62022-03-15
The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in …
- CVE-2022-1222MEDIUMCVSS 5.5EG 5.52022-04-04
Inf loop in GitHub repository gpac/gpac prior to 2.1.0-DEV.
- CVE-2022-20476MEDIUMCVSS 5.5EG 5.52022-12-13
In setEnabledSetting of PackageManager.java, there is a possible way to get the device into an infinite reboot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User…
- CVE-2022-21159HIGHCVSS 7.5EG 7.52022-04-15
A denial of service vulnerability exists in the parseNormalModeParameters functionality of MZ Automation GmbH libiec61850 1.5.0. A specially-crafted series of network requests can lead to denial of service. An attacker can send a sequence …
- CVE-2022-23098HIGHCVSS 7.5EG 7.52022-01-28
An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation has an infinite loop if no data is received.
- CVE-2022-23352HIGHCVSS 7.5EG 7.52022-03-21
An issue in BigAnt Software BigAnt Server v5.6.06 can lead to a Denial of Service (DoS).
- CVE-2022-23437MEDIUMCVSS 6.5EG 6.52022-01-24
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources…
- CVE-2022-23596HIGHCVSS 7.5EG 7.52022-02-01
Junrar is an open source java RAR archive library. In affected versions A carefully crafted RAR archive can trigger an infinite loop while extracting said archive. The impact depends solely on how the application uses the library, and whet…
- CVE-2022-23641MEDIUMCVSS 6.5EG 6.52022-02-15
Discourse is an open source discussion platform. In versions prior to 2.8.1 in the `stable` branch, 2.9.0.beta2 in the `beta` branch, and 2.9.0.beta2 in the `tests-passed` branch, users can trigger a Denial of Service attack by posting a s…
- CVE-2022-23833HIGHCVSS 7.5EG 8.02022-02-03
An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart forms could result in an infinite loop when parsing files.
- CVE-2022-23968HIGHCVSS 7.5EG 7.52022-01-26
Xerox VersaLink devices on specific versions of firmware before 2022-01-26 allow remote attackers to brick the device via a crafted TIFF file in an unauthenticated HTTP POST request. There is a permanent denial of service because image par…
- CVE-2022-24191MEDIUMCVSS 5.5EG 5.52022-04-04
In HTMLDOC 1.9.14, an infinite loop in the gif_read_lzw function can lead to a pointer arbitrarily pointing to heap memory and resulting in a buffer overflow.
- CVE-2022-24763HIGHCVSS 7.5EG 7.52022-03-30
PJSIP is a free and open source multimedia communication library written in the C language. Versions 2.12 and prior contain a denial-of-service vulnerability that affects PJSIP users that consume PJSIP's XML parsing in their apps. Users ar…
- CVE-2022-24792HIGHCVSS 7.5EG 7.52022-04-25
PJSIP is a free and open source multimedia communication library written in C. A denial-of-service vulnerability affects applications on a 32-bit systems that use PJSIP versions 2.12 and prior to play/read invalid WAV files. The vulnerabil…
- CVE-2022-24859MEDIUMCVSS 6.2EG 6.22022-04-18
PyPDF2 is an open source python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF files. In versions prior to 1.27.5 an attacker who uses this vulnerability can craft a PDF which leads to an infinite lo…
- CVE-2022-25734HIGHCVSS 7.5EG 7.52023-02-12
Denial of service in modem due to missing null check while processing IP packets with padding
- CVE-2022-25742HIGHCVSS 7.5EG 7.52022-11-15
Denial of service in modem due to infinite loop while parsing IGMPv2 packet from server in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music
- CVE-2022-25851HIGHCVSS 7.5EG 7.52022-06-10
The package jpeg-js before 0.4.4 are vulnerable to Denial of Service (DoS) where a particular piece of input will cause to enter an infinite loop and never return.
- CVE-2022-27781HIGHCVSS 7.5EG 7.52022-06-02
libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.Due to an erroneous function, a malicious server could make libcurl built withNSS get stuck in a never…
- CVE-2022-2833HIGHCVSS 7.5EG 7.52022-08-16
Endless Infinite loop in Blender-thumnailing due to logical bugs.
- CVE-2022-28882HIGHCVSS 4.3EG 7.52022-08-23
A Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aegen.dll will go into an infinite loop when unpacking PE files. This eventually leads to scanning engine crash. The exploit can be trigge…
- CVE-2022-28884HIGHCVSS 4.3EG 7.52022-09-06
A Denial-of-Service vulnerability was discovered in the F-Secure and WithSecure products where aerdl.dll may go into an infinite loop when unpacking PE files. It is possible that this can crash the scanning engine.
- CVE-2022-28886MEDIUMCVSS 4.3EG 5.52022-09-23
A Denial-of-Service vulnerability was discovered in the F-Secure and WithSecure products where aerdl.so/aerdl.dll may go into an infinite loop when unpacking PE files. It is possible that this can crash the scanning engine
- CVE-2022-29028MEDIUMCVSS 5.5EG 5.52022-05-20
A vulnerability has been identified in JT2Go (All versions < V13.3.0.3), Teamcenter Visualization V13.3 (All versions < V13.3.0.3), Teamcenter Visualization V14.0 (All versions < V14.0.0.1). The Tiff_Loader.dll is vulnerable to infinite lo…
- CVE-2022-29190HIGHCVSS 7.5EG 7.52022-05-21
Pion DTLS is a Go implementation of Datagram Transport Layer Security. Prior to version 2.1.4, an attacker can send packets that sends Pion DTLS into an infinite loop when processing. Version 2.1.4 contains a patch for this issue. There ar…
- CVE-2022-29862HIGHCVSS 7.5EG 7.52022-06-16
An infinite loop in OPC UA .NET Standard Stack 1.04.368 allows a remote attackers to cause the application to hang via a crafted message.
- CVE-2022-30634HIGHCVSS 7.5EG 7.52022-07-15
Infinite loop in Read in crypto/rand before Go 1.17.11 and Go 1.18.3 on Windows allows attacker to cause an indefinite hang by passing a buffer larger than 1 << 32 - 1 bytes.
- CVE-2022-31628MEDIUMCVSS 2.3EG 5.52022-09-28
In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.
- CVE-2022-3190MEDIUMCVSS 6.3EG 6.32022-09-13
Infinite loop in the F5 Ethernet Trailer protocol dissector in Wireshark 3.6.0 to 3.6.7 and 3.4.0 to 3.4.15 allows denial of service via packet injection or crafted capture file
- CVE-2022-32058HIGHCVSS 7.5EG 7.52022-07-07
An infinite loop in the function httpRpmPass of TP-Link TL-WR741N/TL-WR742N V1/V2/V3_130415 allows attackers to cause a Denial of Service (DoS) via a crafted packet.
- CVE-2022-3252HIGHCVSS 7.5EG 7.52022-09-21
Improper detection of complete HTTP body decompression SwiftNIO Extras provides a pair of helpers for transparently decompressing received HTTP request or response bodies. These two objects (HTTPRequestDecompressor and HTTPResponseDecompre…
- CVE-2022-33238HIGHCVSS 7.5EG 7.52022-12-13
Transient DOS due to loop with unreachable exit condition in WLAN while processing an incoming FTM frames. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer I…
- CVE-2022-33239HIGHCVSS 7.5EG 7.52022-11-15
Transient DOS due to loop with unreachable exit condition in WLAN firmware while parsing IPV6 extension header. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consu…
- CVE-2022-34661HIGHCVSS 7.5EG 7.52022-08-10
A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.15), Teamcenter V13.0 (All versions < V13.0.0.10), Teamcenter V13.1 (All versions < V13.1.0.10), Teamcenter V13.2 (All versions < V13.2.0.9), Teamcenter V13.3 …
- CVE-2022-34760HIGHCVSS 7.5EG 7.52022-07-13
A CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability exists that could cause a denial of service of the webserver due to improper handling of the cookies. Affected Products: X80 advanced RTU Communication Module …
- CVE-2022-34862HIGHCVSS 7.5EG 7.52022-08-04
In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when an LTM virtual server is configured to perform normalization, undisclosed requests can cause the Traffic Management M…
Map vulnerabilities like CWE-835 to your infrastructure
EchelonGraph correlates every CVE — across CWE-835 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →