Vulnerabilities > Loop with Unreachable Exit Condition ('Infinite Loop')

DATE CVE VULNERABILITY TITLE RISK
2020-10-06 CVE-2020-15598 Infinite Loop vulnerability in multiple products
Trustwave ModSecurity 3.x through 3.0.4 allows denial of service via a special request.
network
low complexity
trustwave debian CWE-835
7.5
2020-10-06 CVE-2020-25641 Infinite Loop vulnerability in multiple products
A flaw was found in the Linux kernel's implementation of biovecs in versions before 5.9-rc7.
local
low complexity
linux redhat opensuse debian canonical CWE-835
5.5
2020-09-25 CVE-2020-25625 Infinite Loop vulnerability in multiple products
hw/usb/hcd-ohci.c in QEMU 5.0.0 has an infinite loop when a TD list has a loop.
local
high complexity
qemu debian CWE-835
5.3
2020-09-14 CVE-2020-25574 Infinite Loop vulnerability in Hyper Http
An issue was discovered in the http crate before 0.1.20 for Rust.
network
low complexity
hyper CWE-835
7.5
2020-08-21 CVE-2020-12457 Infinite Loop vulnerability in Wolfssl
An issue was discovered in wolfSSL before 4.5.0.
network
low complexity
wolfssl CWE-835
7.5
2020-08-14 CVE-2019-19643 Infinite Loop vulnerability in ISE Smart Connect KNX Vaillant 1.2.839
ise smart connect KNX Vaillant 1.2.839 contain a Denial of Service.
network
low complexity
ise CWE-835
7.5
2020-08-11 CVE-2020-0247 Infinite Loop vulnerability in Google Android 10.0/8.0/8.1
In Threshold::getHistogram of ImageProcessHelper.java, there is a possible crash loop due to an uncaught exception.
local
low complexity
google CWE-835
5.5
2020-08-10 CVE-2020-15654 Infinite Loop vulnerability in multiple products
When in an endless loop, a website specifying a custom cursor using CSS could make it look like the user is interacting with the user interface, when they are not.
network
low complexity
mozilla canonical CWE-835
6.5
2020-08-06 CVE-2020-16845 Infinite Loop vulnerability in multiple products
Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary via invalid inputs.
network
low complexity
golang opensuse debian fedoraproject CWE-835
7.5
2020-07-29 CVE-2020-5761 Infinite Loop vulnerability in Grandstream products
Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to CPU exhaustion due to an infinite loop in the TR-069 service.
network
low complexity
grandstream CWE-835
7.5