Vulnerabilities > Loop with Unreachable Exit Condition ('Infinite Loop')

DATE CVE VULNERABILITY TITLE RISK
2020-07-16 CVE-2019-20911 Infinite Loop vulnerability in GNU Libredwg
An issue was discovered in GNU LibreDWG through 0.9.3.
network
low complexity
gnu CWE-835
6.5
2020-07-14 CVE-2020-13935 Infinite Loop vulnerability in multiple products
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104.
7.5
2020-07-13 CVE-2019-20907 Infinite Loop vulnerability in multiple products
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.
7.5
2020-07-05 CVE-2020-15466 Infinite Loop vulnerability in multiple products
In Wireshark 3.2.0 to 3.2.4, the GVCP dissector could go into an infinite loop.
network
low complexity
wireshark opensuse debian CWE-835
7.5
2020-06-25 CVE-2019-19506 Infinite Loop vulnerability in Tendacn PA6 Firmware 1.0.1.21
Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a denial of service, caused by an error in the "homeplugd" process.
network
low complexity
tendacn CWE-835
7.5
2020-06-19 CVE-2020-14448 Infinite Loop vulnerability in Mattermost Server
An issue was discovered in Mattermost Server before 5.23.0.
network
low complexity
mattermost CWE-835
7.5
2020-06-19 CVE-2020-14447 Infinite Loop vulnerability in Mattermost Server
An issue was discovered in Mattermost Server before 5.23.0.
network
low complexity
mattermost CWE-835
7.5
2020-06-18 CVE-2020-12885 Infinite Loop vulnerability in ARM Mbed OS 5.15.3
An infinite loop was discovered in the CoAP library in Arm Mbed OS 5.15.3.
network
low complexity
arm CWE-835
7.5
2020-06-17 CVE-2020-14040 Infinite Loop vulnerability in multiple products
The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory.
network
low complexity
golang fedoraproject CWE-835
7.5
2020-06-17 CVE-2020-14398 Infinite Loop vulnerability in multiple products
An issue was discovered in LibVNCServer before 0.9.13.
7.5