Vulnerabilities > Uncontrolled Recursion

DATE CVE VULNERABILITY TITLE RISK
2023-01-05 CVE-2022-47662 Uncontrolled Recursion vulnerability in Gpac
GPAC MP4Box 2.1-DEV-rev649-ga8f438d20 has a segment fault (/stack overflow) due to infinite recursion in Media_GetSample isomedia/media.c:662
local
low complexity
gpac CWE-674
5.5
2022-12-28 CVE-2022-41966 Uncontrolled Recursion vulnerability in Xstream Project Xstream
XStream serializes Java objects to XML and back again.
network
low complexity
xstream-project CWE-674
7.5
2022-12-12 CVE-2022-41881 Uncontrolled Recursion vulnerability in multiple products
Netty project is an event-driven asynchronous network application framework.
network
low complexity
netty debian CWE-674
7.5
2022-12-04 CVE-2022-46405 Uncontrolled Recursion vulnerability in Joinmastodon Mastodon
Mastodon through 4.0.2 allows attackers to cause a denial of service (large Sidekiq pull queue) by creating bot accounts that follow attacker-controlled accounts on certain other servers associated with a wildcard DNS A record, such that there is uncontrolled recursion of attacker-generated messages.
network
low complexity
joinmastodon CWE-674
7.5
2022-11-01 CVE-2022-42321 Uncontrolled Recursion vulnerability in multiple products
Xenstore: Guests can crash xenstored via exhausting the stack Xenstored is using recursion for some Xenstore operations (e.g.
local
low complexity
xen debian fedoraproject CWE-674
6.5
2022-10-06 CVE-2022-27810 Uncontrolled Recursion vulnerability in Facebook Hermes
It was possible to trigger an infinite recursion condition in the error handler when Hermes executed specific maliciously formed JavaScript.
network
low complexity
facebook CWE-674
7.5
2022-09-19 CVE-2022-28201 Uncontrolled Recursion vulnerability in multiple products
An issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2.
local
low complexity
mediawiki debian CWE-674
4.4
2022-09-16 CVE-2022-40150 Uncontrolled Recursion vulnerability in multiple products
Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS).
network
low complexity
jettison-project debian CWE-674
7.5
2022-09-15 CVE-2022-38334 Uncontrolled Recursion vulnerability in Xpdfreader Xpdf
XPDF v4.04 and earlier was discovered to contain a stack overflow via the function Catalog::countPageTree() at Catalog.cc.
local
low complexity
xpdfreader CWE-674
5.5
2022-09-14 CVE-2022-3216 Uncontrolled Recursion vulnerability in Nintendo Game BOY Color Firmware
A vulnerability has been found in Nintendo Game Boy Color and classified as problematic.
network
low complexity
nintendo CWE-674
8.8