Vulnerabilities > Loop with Unreachable Exit Condition ('Infinite Loop')

DATE CVE VULNERABILITY TITLE RISK
2024-01-16 CVE-2023-45233 Infinite Loop vulnerability in Tianocore Edk2
EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6.
network
low complexity
tianocore CWE-835
7.5
2024-01-12 CVE-2023-0437 Infinite Loop vulnerability in Mongodb C Driver
When calling bson_utf8_validate on some inputs a loop with an exit condition that cannot be reached may occur, i.e.
network
low complexity
mongodb CWE-835
7.5
2024-01-10 CVE-2023-50120 Infinite Loop vulnerability in Gpac 2.3
MP4Box GPAC version 2.3-DEV-rev636-gfbd7e13aa-master was discovered to contain an infinite loop in the function av1_uvlc at media_tools/av_parsers.c.
local
low complexity
gpac CWE-835
5.5
2024-01-10 CVE-2023-47997 Infinite Loop vulnerability in Freeimage Project Freeimage 3.18.0
An issue discovered in BitmapAccess.cpp::FreeImage_AllocateBitmap in FreeImage 3.18.0 leads to an infinite loop and allows attackers to cause a denial of service.
network
low complexity
freeimage-project CWE-835
6.5
2024-01-03 CVE-2024-0211 Infinite Loop vulnerability in Wireshark 4.2.0
DOCSIS dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file
network
low complexity
wireshark CWE-835
7.5
2024-01-02 CVE-2023-43511 Infinite Loop vulnerability in Qualcomm products
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header.
network
low complexity
qualcomm CWE-835
7.5
2023-12-29 CVE-2023-50570 Infinite Loop vulnerability in Seancfoley Ipaddress 5.1.0
An issue in the component IPAddressBitsDivision of IPAddress v5.1.0 leads to an infinite loop.
local
low complexity
seancfoley CWE-835
5.5
2023-12-27 CVE-2023-51075 Infinite Loop vulnerability in Hutool 5.8.23
hutool-core v5.8.23 was discovered to contain an infinite loop in the StrSplitter.splitByRegex function.
network
low complexity
hutool CWE-835
7.5
2023-12-18 CVE-2023-50981 Infinite Loop vulnerability in Cryptopp Crypto++
ModularSquareRoot in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (infinite loop) via crafted DER public-key data associated with squared odd numbers, such as the square of 268995137513890432434389773128616504853.
network
low complexity
cryptopp CWE-835
7.5
2023-12-08 CVE-2023-6245 Infinite Loop vulnerability in Dfinity Candid
The Candid library causes a Denial of Service while parsing a specially crafted payload with 'empty' data type.
network
low complexity
dfinity CWE-835
7.5