Vulnerabilities > Loop with Unreachable Exit Condition ('Infinite Loop')

DATE CVE VULNERABILITY TITLE RISK
2018-07-03 CVE-2018-8036 Infinite Loop vulnerability in Apache Pdfbox
In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser.
network
low complexity
apache CWE-835
6.5
2018-06-27 CVE-2018-12913 Infinite Loop vulnerability in Miniz Project Miniz 2.0.7
In Miniz 2.0.7, tinfl_decompress in miniz_tinfl.c has an infinite loop because sym2 and counter can both remain equal to zero.
network
low complexity
miniz-project CWE-835
7.5
2018-06-14 CVE-2018-12418 Infinite Loop vulnerability in Junrar Project Junrar 0.6/0.7/1.0.0
Archive.java in Junrar before 1.0.1, as used in Apache Tika and other products, is affected by a denial of service vulnerability due to an infinite loop when handling corrupt RAR files.
local
low complexity
junrar-project CWE-835
5.5
2018-06-12 CVE-2018-12228 Infinite Loop vulnerability in Sangoma Asterisk
An issue was discovered in Asterisk Open Source 15.x before 15.4.1.
network
low complexity
sangoma CWE-835
6.5
2018-06-01 CVE-2018-11657 Infinite Loop vulnerability in Miniupnp Project Ngiflib 0.4
ngiflib.c in MiniUPnP ngiflib 0.4 has an infinite loop in DecodeGifImg and LoadGif.
network
low complexity
miniupnp-project CWE-835
7.5
2018-05-22 CVE-2018-11365 Infinite Loop vulnerability in Wizardmac Readstat 0.1.1
sas/readstat_sas7bcat_read.c in libreadstat.a in ReadStat 0.1.1 has an infinite loop.
network
low complexity
wizardmac CWE-835
7.5
2018-05-18 CVE-2017-18273 Infinite Loop vulnerability in multiple products
In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-22, an infinite loop vulnerability was found in the function ReadTXTImage in coders/txt.c, which allows attackers to cause a denial of service (CPU exhaustion) via a crafted image file that is mishandled in a GetImageIndexInList call.
network
low complexity
imagemagick debian canonical CWE-835
6.5
2018-05-18 CVE-2017-18271 Infinite Loop vulnerability in multiple products
In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-22, an infinite loop vulnerability was found in the function ReadMIFFImage in coders/miff.c, which allows attackers to cause a denial of service (CPU exhaustion) via a crafted MIFF image file.
network
low complexity
imagemagick canonical debian CWE-835
6.5
2018-05-10 CVE-2018-10981 Infinite Loop vulnerability in multiple products
An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to cause a denial of service (host OS infinite loop) in situations where a QEMU device model attempts to make invalid transitions between states of a request.
local
low complexity
debian xen CWE-835
6.5
2018-05-10 CVE-2017-18267 Infinite Loop vulnerability in multiple products
The FoFiType1C::cvtGlyph function in fofi/FoFiType1C.cc in Poppler through 0.64.0 allows remote attackers to cause a denial of service (infinite recursion) via a crafted PDF file, as demonstrated by pdftops.
local
low complexity
freedesktop canonical redhat debian CWE-835
5.5