Vulnerabilities > Loop with Unreachable Exit Condition ('Infinite Loop')

DATE CVE VULNERABILITY TITLE RISK
2018-01-29 CVE-2017-12626 Infinite Loop vulnerability in Apache POI
Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks: 1) Infinite Loops while parsing crafted WMF, EMF, MSG and macros (POI bugs 61338 and 61294), and 2) Out of Memory Exceptions while parsing crafted DOC, PPT and XLS (POI bugs 52372 and 61295).
network
low complexity
apache CWE-835
7.5
2018-01-25 CVE-2018-6196 Infinite Loop vulnerability in multiple products
w3m through 0.5.3 is prone to an infinite recursion flaw in HTMLlineproc0 because the feed_table_block_tag function in table.c does not prevent a negative indent value.
network
low complexity
tats canonical CWE-835
7.5
2018-01-19 CVE-2018-5786 Infinite Loop vulnerability in multiple products
In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the get_fileinfo function (lrzip.c).
local
low complexity
long-range-zip-project debian CWE-835
5.5
2018-01-16 CVE-2018-5711 Infinite Loop vulnerability in multiple products
gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1, has an integer signedness error that leads to an infinite loop via a crafted GIF file, as demonstrated by a call to the imagecreatefromgif or imagecreatefromstring PHP function.
local
low complexity
php debian canonical CWE-835
5.5
2018-01-14 CVE-2018-5686 Infinite Loop vulnerability in multiple products
In MuPDF 1.12.0, there is an infinite loop vulnerability and application hang in the pdf_parse_array function (pdf/pdf-parse.c) because EOF is not considered.
local
low complexity
artifex debian CWE-835
5.5
2018-01-14 CVE-2018-5685 Infinite Loop vulnerability in multiple products
In GraphicsMagick 1.3.27, there is an infinite loop and application hang in the ReadBMPImage function (coders/bmp.c).
network
low complexity
graphicsmagick debian CWE-835
6.5
2018-01-12 CVE-2017-13195 Infinite Loop vulnerability in Google Android
In the ihevcd_parse_sps function of ihevcd_parse_headers.c, several parameter values could be negative which could lead to negative indexes which could lead to an infinite loop.
network
low complexity
google CWE-835
7.5
2018-01-12 CVE-2017-13193 Infinite Loop vulnerability in Google Android
In ihevcd_decode.c there is a possible infinite loop due to bytes for an sps of unsupported resolution resulting in the same sps being fed in over and over.
network
low complexity
google CWE-835
7.5
2018-01-12 CVE-2017-13192 Infinite Loop vulnerability in Google Android
In the ihevcd_parse_slice_header function of ihevcd_parse_slice_header.c a slice address of zero after the first slice could result in an infinite loop.
network
low complexity
google CWE-835
7.5
2018-01-12 CVE-2017-13191 Infinite Loop vulnerability in Google Android
In the ihevcd_decode function of ihevcd_decode.c, there is an infinite loop due to an incomplete frame error.
network
low complexity
google CWE-835
7.5