Vulnerabilities > Loop with Unreachable Exit Condition ('Infinite Loop')

DATE CVE VULNERABILITY TITLE RISK
2019-04-29 CVE-2019-3560 Infinite Loop vulnerability in Facebook Fizz
An improperly performed length calculation on a buffer in PlaintextRecordLayer could lead to an infinite loop and denial-of-service based on user input.
network
low complexity
facebook CWE-835
7.5
2019-04-25 CVE-2019-3900 Infinite Loop vulnerability in multiple products
An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx().
7.7
2019-04-09 CVE-2019-10900 Infinite Loop vulnerability in multiple products
In Wireshark 3.0.0, the Rbm dissector could go into an infinite loop.
network
low complexity
wireshark fedoraproject CWE-835
7.5
2019-04-09 CVE-2019-10898 Infinite Loop vulnerability in multiple products
In Wireshark 3.0.0, the GSUP dissector could go into an infinite loop.
network
low complexity
wireshark fedoraproject CWE-835
7.5
2019-04-09 CVE-2019-10897 Infinite Loop vulnerability in multiple products
In Wireshark 3.0.0, the IEEE 802.11 dissector could go into an infinite loop.
network
low complexity
wireshark fedoraproject CWE-835
7.5
2019-03-21 CVE-2018-16789 Infinite Loop vulnerability in Shellinabox Project Shellinabox
libhttp/url.c in shellinabox through 2.20 has an implementation flaw in the HTTP request parsing logic.
network
low complexity
shellinabox-project CWE-835
7.8
2019-03-14 CVE-2019-3833 Infinite Loop vulnerability in multiple products
Openwsman, versions up to and including 2.6.9, are vulnerable to infinite loop in process_connection() when parsing specially crafted HTTP requests.
7.5
2019-03-13 CVE-2019-9747 Infinite Loop vulnerability in Tinysvcmdns Project Tinysvcmdns 20160718/20171105/20180116
In tinysvcmdns through 2018-01-16, a maliciously crafted mDNS (Multicast DNS) packet triggers an infinite loop while parsing an mDNS query.
network
low complexity
tinysvcmdns-project CWE-835
5.0
2019-02-26 CVE-2019-6594 Infinite Loop vulnerability in F5 products
On BIG-IP 11.5.1-11.6.3.2, 12.1.3.4-12.1.3.7, 13.0.0 HF1-13.1.1.1, and 14.0.0-14.0.0.2, Multi-Path TCP (MPTCP) does not protect against multiple zero length DATA_FINs in the reassembly queue, which can lead to an infinite loop in some circumstances.
network
f5 CWE-835
4.3
2019-02-22 CVE-2018-20784 Infinite Loop vulnerability in multiple products
In the Linux kernel before 4.20.2, kernel/sched/fair.c mishandles leaf cfs_rq's, which allows attackers to cause a denial of service (infinite loop in update_blocked_averages) or possibly have unspecified other impact by inducing a high load.
network
low complexity
linux canonical redhat CWE-835
7.5