CWE-835— Loop with Unreachable Exit Condition (Infinite Loop)
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.— MITRE CWE catalog
883 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-835page 11 of 18
- CVE-2022-35165MEDIUMCVSS 5.5EG 5.52022-08-18
An issue in AP4_SgpdAtom::AP4_SgpdAtom() of Bento4-1.6.0-639 allows attackers to cause a Denial of Service (DoS) via a crafted mp4 input.
- CVE-2022-35166MEDIUMCVSS 5.5EG 5.52022-08-18
libjpeg commit 842c7ba was discovered to contain an infinite loop via the component JPEG::ReadInternal.
- CVE-2022-35724HIGHCVSS 7.5EG 7.52022-08-09
It is possible to provide data to be read that leads the reader to loop in cycles endlessly, consuming CPU. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Users should update …
- CVE-2022-36313MEDIUMCVSS 5.5EG 5.52022-07-21
An issue was discovered in the file-type package before 16.5.4 and 17.x before 17.1.3 for Node.js. A malformed MKV file could cause the file type detector to get caught in an infinite loop. This would make the application become unresponsi…
- CVE-2022-37013HIGHCVSS 7.5EG 7.52023-03-29
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation OPC UA C++ Demo Server 1.7.6-537 [with vendor rollup]. Authentication is not required to exploit this vulner…
- CVE-2022-37768HIGHCVSS 7.5EG 7.52022-08-18
libjpeg commit 281daa9 was discovered to contain an infinite loop via the component Frame::ParseTrailer.
- CVE-2022-39052HIGHCVSS 7.5EG 7.52022-10-17
An external attacker is able to send a specially crafted email (with many recipients) and trigger a potential DoS of the system
- CVE-2022-40090MEDIUMCVSS 6.5EG 6.52023-08-22
An issue was discovered in function TIFFReadDirectory libtiff before 4.4.0 allows attackers to cause a denial of service via crafted TIFF file.
- CVE-2022-4104MEDIUMCVSS 5.5EG 5.52022-11-28
A loop with an unreachable exit condition can be triggered by passing a crafted JPEG file to the Lepton image compression tool, resulting in a denial-of-service.
- CVE-2022-42721MEDIUMCVSS 5.5EG 5.52022-10-14
A list management bug in BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to corrupt a linked list and, in turn, potentially execute code.
- CVE-2022-4345MEDIUMCVSS 6.3EG 6.52023-01-12
Infinite loops in the BPv6, OpenFlow, and Kafka protocol dissectors in Wireshark 4.0.0 to 4.0.1 and 3.6.0 to 3.6.9 allows denial of service via packet injection or crafted capture file
- CVE-2022-44617HIGHCVSS 7.5EG 7.52023-02-06
A flaw was found in libXpm. When processing a file with width of 0 and a very large height, some parser functions will be called repeatedly and can lead to an infinite loop, resulting in a Denial of Service in the application linked to the…
- CVE-2022-46285HIGHCVSS 7.5EG 7.52023-02-07
A flaw was found in libXpm. This issue occurs when parsing a file with a comment not closed; the end-of-file condition will not be detected, leading to an infinite loop and resulting in a Denial of Service in the application linked to the …
- CVE-2022-46770HIGHCVSS 7.5EG 7.52022-12-07
qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS users to cause a denial of service (CPU consumption and loss of forwarding) via a crafted multicast UDP packet (IP address range of 224.0.0.0 throu…
- CVE-2022-48256HIGHCVSS 7.5EG 7.52023-01-13
Technitium DNS Server before 10.0 allows a self-CNAME denial-of-service attack in which a CNAME loop causes an answer to contain hundreds of records.
- CVE-2022-48630MEDIUMCVSS 5.5EG 5.52024-03-05
In the Linux kernel, the following vulnerability has been resolved: crypto: qcom-rng - fix infinite loop on requests not multiple of WORD_SZ The commit referenced in the Fixes tag removed the 'break' from the else branch in qcom_rng_read…
- CVE-2022-48635MEDIUMCVSS 6.2EG 6.22024-04-28
In the Linux kernel, the following vulnerability has been resolved: fsdax: Fix infinite loop in dax_iomap_rw() I got an infinite loop and a WARNING report when executing a tail command in virtiofs. WARNING: CPU: 10 PID: 964 at fs/ioma…
- CVE-2022-48780MEDIUMCVSS 5.5EG 5.52024-07-16
In the Linux kernel, the following vulnerability has been resolved: net/smc: Avoid overwriting the copies of clcsock callback functions The callback functions of clcsock will be saved and replaced during the fallback. But if the fallback…
- CVE-2022-48840MEDIUMCVSS 5.5EG 5.52024-07-16
In the Linux kernel, the following vulnerability has been resolved: iavf: Fix hang during reboot/shutdown Recent commit 974578017fc1 ("iavf: Add waiting so the port is initialized in remove") adds a wait-loop at the beginning of iavf_rem…
- CVE-2022-48862MEDIUMCVSS 5.5EG 5.52024-07-16
In the Linux kernel, the following vulnerability has been resolved: vhost: fix hung thread due to erroneous iotlb entries In vhost_iotlb_add_range_ctx(), range size can overflow to 0 when start is 0 and last is ULONG_MAX. One instance wh…
- CVE-2022-49097MEDIUMCVSS 5.5EG 5.52025-02-26
In the Linux kernel, the following vulnerability has been resolved: NFS: Avoid writeback threads getting stuck in mempool_alloc() In a low memory situation, allow the NFS writeback code to fail without getting stuck in infinite loops in …
- CVE-2022-49317MEDIUMCVSS 5.5EG 5.52025-02-26
In the Linux kernel, the following vulnerability has been resolved: f2fs: avoid infinite loop to flush node pages xfstests/generic/475 can give EIO all the time which give an infinite loop to flush node page like below. Let's avoid it. …
- CVE-2022-50008MEDIUMCVSS 5.5EG 5.52025-06-18
In the Linux kernel, the following vulnerability has been resolved: kprobes: don't call disarm_kprobe() for disabled kprobes The assumption in __disable_kprobe() is wrong, and it could try to disarm an already disarmed kprobe and fire th…
- CVE-2023-0437MEDIUMCVSS 5.3EG 5.32024-01-12
When calling bson_utf8_validate on some inputs a loop with an exit condition that cannot be reached may occur, i.e. an infinite loop. This issue affects All MongoDB C Driver versions prior to versions 1.25.0.
- CVE-2023-1108HIGHCVSS 7.5EG 7.52023-09-14
A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
- CVE-2023-1718HIGHCVSS 7.5EG 7.52023-11-01
Improper file stream access in /desktop_app/file.ajax.php?action=uploadfile in Bitrix24 22.0.300 allows unauthenticated remote attackers to cause denial-of-service via a crafted "tmp_url".
- CVE-2023-20020HIGHCVSS 8.6EG 8.62023-01-20
A vulnerability in the Device Management Servlet application of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to cause a denial of service (DoS…
- CVE-2023-20083HIGHCVSS 8.6EG 8.62023-11-01
A vulnerability in ICMPv6 inspection when configured with the Snort 2 detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the CPU of an affected device to spike to 100…
- CVE-2023-20116MEDIUMCVSS 6.8EG 6.82023-06-28
A vulnerability in the Administrative XML Web Service (AXL) API of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote …
- CVE-2023-20197HIGHCVSS 7.5EG 7.52023-08-16
A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is …
- CVE-2023-20200HIGHCVSS 7.7EG 7.72023-08-23
A vulnerability in the Simple Network Management Protocol (SNMP) service of Cisco FXOS Software for Firepower 4100 Series and Firepower 9300 Security Appliances and of Cisco UCS 6300 Series Fabric Interconnects could allow an authenticated…
- CVE-2023-20996MEDIUMCVSS 5.5EG 5.52023-03-24
In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for explo…
- CVE-2023-20997MEDIUMCVSS 5.5EG 5.52023-03-24
In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for explo…
- CVE-2023-20998MEDIUMCVSS 5.5EG 5.52023-03-24
In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for explo…
- CVE-2023-20999MEDIUMCVSS 5.5EG 5.52023-03-24
In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for explo…
- CVE-2023-22325MEDIUMCVSS 5.9EG 5.92023-10-12
A denial of service vulnerability exists in the DCRegister DDNS_RPC_MAX_RECV_SIZE functionality of SoftEther VPN 4.41-9782-beta, 5.01.9674 and 5.02. A specially crafted network packet can lead to denial of service. An attacker can perform …
- CVE-2023-23617MEDIUMCVSS 4.9EG 4.92023-01-28
OpenMage LTS is an e-commerce platform. Versions prior to 19.4.22 and 20.0.19 contain an infinite loop in malicious code filter in certain conditions. Versions 19.4.22 and 20.0.19 have a fix for this issue. There are no known workarounds.
- CVE-2023-24808MEDIUMCVSS 5.3EG 5.32023-02-07
PDFio is a C library for reading and writing PDF files. In versions prior to 1.1.0 a denial of service (DOS) vulnerability exists in the pdfio parser. Crafted pdf files can cause the program to run at 100% utilization and never terminate.…
- CVE-2023-25653HIGHCVSS 7.5EG 7.52023-02-16
node-jose is a JavaScript implementation of the JSON Object Signing and Encryption (JOSE) for web browsers and node.js-based servers. Prior to version 2.2.0, when using the non-default "fallback" crypto back-end, ECC operations in `node-jo…
- CVE-2023-25824HIGHCVSS 7.5EG 7.52023-02-23
Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. Versions from 0.9.0 to 0.12.0 (including) did not properly fail blocking read operations on TLS connections when the transport hit timeouts. Instead it entered an endless loop re…
- CVE-2023-2593MEDIUMCVSS 5.9EG 5.92025-07-30
A flaw exists within the Linux kernel's handling of new TCP connections. The issue results from the lack of memory release after its effective lifetime. This vulnerability allows an unauthenticated attacker to create a denial of service co…
- CVE-2023-26151MEDIUMCVSS 5.3EG 5.32023-10-03
Versions of the package asyncua before 0.9.96 are vulnerable to Denial of Service (DoS) such that an attacker can send a malformed packet and as a result, the server will enter into an infinite loop and consume excessive memory.
- CVE-2023-27560HIGHCVSS 7.5EG 7.52023-03-03
Math/PrimeField.php in phpseclib 3.x before 3.0.19 has an infinite loop with composite primefields.
- CVE-2023-2879MEDIUMCVSS 6.3EG 6.32023-05-26
GDSDB infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or crafted capture file
- CVE-2023-2952MEDIUMCVSS 5.3EG 5.32023-05-30
XRA dissector infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or crafted capture file
- CVE-2023-30188HIGHCVSS 7.5EG 7.52023-08-14
Memory Exhaustion vulnerability in ONLYOFFICE Document Server 4.0.3 through 7.3.2 allows remote attackers to cause a denial of service via crafted JavaScript file.
- CVE-2023-30300MEDIUMCVSS 5.5EG 5.52023-05-03
An issue in the component hang.wasm of WebAssembly 1.0 causes an infinite loop.
- CVE-2023-3255MEDIUMCVSS 6.5EG 6.52023-09-13
A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. A wrong exit condition may lead to an infinite loop when inflating an attacker controlled zlib buffer in the `inflate_buffer` function. This could al…
- CVE-2023-33305MEDIUMCVSS 4.9EG 4.92023-06-13
A loop with unreachable exit condition ('infinite loop') in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS version 7.0.0 through 7.0.10, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0 all versions, FortiProxy versi…
- CVE-2023-34966HIGHCVSS 7.5EG 8.32023-07-20
An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets sent by the client, the core unmarshalling function sl_unpack_loop() did not validate a field in the network pa…
Map vulnerabilities like CWE-835 to your infrastructure
EchelonGraph correlates every CVE — across CWE-835 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →