Vulnerabilities > Excessive Iteration

DATE CVE VULNERABILITY TITLE RISK
2021-03-19 CVE-2021-27807 Excessive Iteration vulnerability in multiple products
A carefully crafted PDF file can trigger an infinite loop while loading the file.
local
low complexity
apache fedoraproject oracle CWE-834
5.5
2020-12-20 CVE-2020-35573 Excessive Iteration vulnerability in multiple products
srs2.c in PostSRSd before 1.10 allows remote attackers to cause a denial of service (CPU consumption) via a long timestamp tag in an SRS address.
network
low complexity
postsrsd-project debian CWE-834
7.5
2020-11-23 CVE-2018-20805 Excessive Iteration vulnerability in Mongodb
A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which perform an $elemMatch .
network
low complexity
mongodb CWE-834
6.5
2020-07-06 CVE-2020-14303 Excessive Iteration vulnerability in multiple products
A flaw was found in the AD DC NBT server in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4.
7.5
2020-06-11 CVE-2020-0175 Excessive Iteration vulnerability in Google Android 10.0
In XMF_ReadNode of eas_xmf.c, there is possible resource exhaustion due to improper input validation.
network
low complexity
google CWE-834
6.5
2020-02-14 CVE-2020-8992 Excessive Iteration vulnerability in multiple products
ext4_protect_reserved_inode in fs/ext4/block_validity.c in the Linux kernel through 5.5.3 allows attackers to cause a denial of service (soft lockup) via a crafted journal size.
local
low complexity
linux canonical opensuse netapp CWE-834
5.5
2019-09-27 CVE-2019-9376 Excessive Iteration vulnerability in Google Android 8.0/8.1/9.0
In Account of Account.java, there is a possible boot loop due to improper input validation.
local
low complexity
google CWE-834
5.5
2019-06-26 CVE-2019-12973 Excessive Iteration vulnerability in multiple products
In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c.
local
low complexity
uclouvain opensuse debian oracle CWE-834
5.5
2019-03-01 CVE-2019-9547 Excessive Iteration vulnerability in Spdk Storage Performance Development KIT
In Storage Performance Development Kit (SPDK) before 19.01, a malicious vhost client (i.e., virtual machine) could carefully construct a circular descriptor chain that would result in a partial denial of service in the SPDK vhost target, because the vhost target did not properly detect such chains.
network
low complexity
spdk CWE-834
5.3
2018-10-25 CVE-2018-18651 Excessive Iteration vulnerability in Xpdfreader Xpdf 4.00
An issue was discovered in Xpdf 4.00.
local
low complexity
xpdfreader CWE-834
5.5