Vulnerabilities > Loop with Unreachable Exit Condition ('Infinite Loop')

DATE CVE VULNERABILITY TITLE RISK
2019-03-14 CVE-2019-3833 Infinite Loop vulnerability in multiple products
Openwsman, versions up to and including 2.6.9, are vulnerable to infinite loop in process_connection() when parsing specially crafted HTTP requests.
7.5
2019-03-13 CVE-2019-9747 Infinite Loop vulnerability in Tinysvcmdns Project Tinysvcmdns 20160718/20171105/20180116
In tinysvcmdns through 2018-01-16, a maliciously crafted mDNS (Multicast DNS) packet triggers an infinite loop while parsing an mDNS query.
network
low complexity
tinysvcmdns-project CWE-835
7.5
2019-02-26 CVE-2019-6594 Infinite Loop vulnerability in F5 products
On BIG-IP 11.5.1-11.6.3.2, 12.1.3.4-12.1.3.7, 13.0.0 HF1-13.1.1.1, and 14.0.0-14.0.0.2, Multi-Path TCP (MPTCP) does not protect against multiple zero length DATA_FINs in the reassembly queue, which can lead to an infinite loop in some circumstances.
network
high complexity
f5 CWE-835
5.9
2019-02-22 CVE-2018-20784 Infinite Loop vulnerability in multiple products
In the Linux kernel before 4.20.2, kernel/sched/fair.c mishandles leaf cfs_rq's, which allows attackers to cause a denial of service (infinite loop in update_blocked_averages) or possibly have unspecified other impact by inducing a high load.
network
low complexity
linux canonical redhat CWE-835
critical
9.8
2019-02-21 CVE-2018-6687 Infinite Loop vulnerability in Mcafee Getsusp 3.0.0.461
Loop with Unreachable Exit Condition ('Infinite Loop') in McAfee GetSusp (GetSusp) 3.0.0.461 and earlier allows attackers to DoS a manual GetSusp scan via while scanning a specifically crafted file .
local
low complexity
mcafee CWE-835
5.5
2019-02-20 CVE-2018-5818 Infinite Loop vulnerability in multiple products
An error within the "parse_rollei()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can be exploited to trigger an infinite loop.
network
low complexity
libraw debian CWE-835
7.5
2019-02-04 CVE-2019-1000020 Infinite Loop vulnerability in multiple products
libarchive version commit 5a98dcf8a86364b3c2c469c85b93647dfb139961 onwards (version v2.8.0 onwards) contains a CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in ISO9660 parser, archive_read_support_format_iso9660.c, read_CE()/parse_rockridge() that can result in DoS by infinite loop.
6.5
2019-02-01 CVE-2017-18361 Infinite Loop vulnerability in Pylonsproject Colander
In Pylons Colander through 1.6, the URL validator allows an attacker to potentially cause an infinite loop thereby causing a denial of service via an unclosed parenthesis.
network
low complexity
pylonsproject CWE-835
7.5
2019-01-25 CVE-2019-3819 Infinite Loop vulnerability in multiple products
A flaw was found in the Linux kernel in the function hid_debug_events_read() in drivers/hid/hid-debug.c file which may enter an infinite loop with certain parameters passed from a userspace.
local
low complexity
linux debian canonical opensuse CWE-835
4.4
2019-01-16 CVE-2019-6462 Infinite Loop vulnerability in Cairographics Cairo 1.16.0
An issue was discovered in cairo 1.16.0.
network
low complexity
cairographics CWE-835
6.5