Vulnerabilities > Loop with Unreachable Exit Condition ('Infinite Loop')

DATE CVE VULNERABILITY TITLE RISK
2021-12-22 CVE-2021-45257 Infinite Loop vulnerability in Nasm Netwide Assembler 2.16
An infinite loop vulnerability exists in nasm 2.16rc0 via the gpaste_tokens function.
local
low complexity
nasm CWE-835
5.5
2021-12-21 CVE-2021-44924 Infinite Loop vulnerability in Gpac 1.1.0
An infinite loop vulnerability exists in gpac 1.1.0 in the gf_log function, which causes a Denial of Service.
local
low complexity
gpac CWE-835
5.5
2021-12-21 CVE-2021-45297 Infinite Loop vulnerability in Gpac 1.1.0
An infinite loop vulnerability exists in Gpac 1.0.1 in gf_get_bit_size.
local
low complexity
gpac CWE-835
5.5
2021-12-14 CVE-2021-4044 Infinite Loop vulnerability in multiple products
Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server.
network
low complexity
openssl netapp nodejs CWE-835
7.5
2021-12-08 CVE-2021-20041 Infinite Loop vulnerability in Sonicwall products
An unauthenticated and remote adversary can consume all of the device's CPU due to crafted HTTP requests sent to SMA100 /fileshare/sonicfiles/sonicfiles resulting in a loop with unreachable exit condition.
network
low complexity
sonicwall CWE-835
7.5
2021-11-11 CVE-2021-3908 Infinite Loop vulnerability in multiple products
OctoRPKI does not limit the depth of a certificate chain, allowing for a CA to create children in an ad-hoc fashion, thereby making tree traversal never end.
network
low complexity
cloudflare debian CWE-835
7.5
2021-11-09 CVE-2021-43172 Infinite Loop vulnerability in Nlnetlabs Routinator
NLnet Labs Routinator prior to 0.10.2 happily processes a chain of RRDP repositories of infinite length causing it to never finish a validation run.
network
low complexity
nlnetlabs CWE-835
7.5
2021-11-05 CVE-2020-23566 Infinite Loop vulnerability in Irfanview 4.53
Irfanview v4.53 was discovered to contain an infinity loop via JPEG2000!ShowPlugInSaveOptions_W+0x1ecd8.
local
low complexity
irfanview CWE-835
5.5
2021-11-01 CVE-2021-41973 Infinite Loop vulnerability in multiple products
In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely.
network
low complexity
apache oracle CWE-835
6.5
2021-10-21 CVE-2021-42715 Infinite Loop vulnerability in multiple products
An issue was discovered in stb stb_image.h 1.33 through 2.27.
local
low complexity
nothings fedoraproject debian CWE-835
5.5