Vulnerabilities > Loop with Unreachable Exit Condition ('Infinite Loop')

DATE CVE VULNERABILITY TITLE RISK
2022-08-18 CVE-2022-37768 Infinite Loop vulnerability in Jpeg Libjpeg
libjpeg commit 281daa9 was discovered to contain an infinite loop via the component Frame::ParseTrailer.
network
low complexity
jpeg CWE-835
7.5
2022-08-18 CVE-2022-35165 Infinite Loop vulnerability in Axiosys Bento4 1.6.0639
An issue in AP4_SgpdAtom::AP4_SgpdAtom() of Bento4-1.6.0-639 allows attackers to cause a Denial of Service (DoS) via a crafted mp4 input.
local
low complexity
axiosys CWE-835
5.5
2022-08-18 CVE-2022-35166 Infinite Loop vulnerability in Jpeg Libjpeg 20220615
libjpeg commit 842c7ba was discovered to contain an infinite loop via the component JPEG::ReadInternal.
local
low complexity
jpeg CWE-835
5.5
2022-08-17 CVE-2020-14394 Infinite Loop vulnerability in multiple products
An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer Request Block (TRB) Ring.
local
low complexity
qemu fedoraproject redhat CWE-835
3.2
2022-08-16 CVE-2022-2833 Infinite Loop vulnerability in Blender 3.3.0
Endless Infinite loop in Blender-thumnailing due to logical bugs.
network
low complexity
blender CWE-835
7.5
2022-08-09 CVE-2022-35724 Infinite Loop vulnerability in Apache Avro
It is possible to provide data to be read that leads the reader to loop in cycles endlessly, consuming CPU.
network
low complexity
apache CWE-835
7.5
2022-08-04 CVE-2022-34862 Infinite Loop vulnerability in F5 products
In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when an LTM virtual server is configured to perform normalization, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate.
network
low complexity
f5 CWE-835
7.5
2022-07-21 CVE-2022-36313 Infinite Loop vulnerability in File-Type Project File-Type
An issue was discovered in the file-type package before 16.5.4 and 17.x before 17.1.3 for Node.js.
local
low complexity
file-type-project CWE-835
5.5
2022-07-20 CVE-2021-46828 Infinite Loop vulnerability in multiple products
In libtirpc before 1.3.3rc1, remote attackers could exhaust the file descriptors of a process that uses libtirpc because idle TCP connections are mishandled.
network
low complexity
libtirpc-project debian CWE-835
7.5
2022-07-15 CVE-2022-30634 Infinite Loop vulnerability in multiple products
Infinite loop in Read in crypto/rand before Go 1.17.11 and Go 1.18.3 on Windows allows attacker to cause an indefinite hang by passing a buffer larger than 1 << 32 - 1 bytes.
network
low complexity
golang netapp CWE-835
7.5