The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
Volume of CVEs assigned to CWE-835 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
876 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-20353HIGH A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthen | Apr 24, 2024 | 8.6 | 92 | YES | NO |
CVE-2020-13935HIGH The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payl | Jul 14, 2020 | 7.5 | 77 | NO | YES |
CVE-2017-16944HIGH The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinite loop and stack exhaustion) via vectors | Nov 25, 2017 | 7.5 | 71 | NO | YES |
CVE-2020-36227HIGH A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in denial of service. | Jan 26, 2021 | 7.5 | 67 | NO | NO |
CVE-2022-0778HIGH The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsi | Mar 15, 2022 | 7.5 | 65 | NO | NO |
CVE-2019-14241HIGH HAProxy through 2.0.2 allows attackers to cause a denial of service (ha_panic) via vectors related to htx_manage_client_side_cookies in proto_htx.c. | Jul 23, 2019 | 7.5 | 63 | NO | NO |
CVE-2023-34966HIGH An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets sent by the client, the core unmarshalling function | Jul 20, 2023 | 7.5 | 55 | NO | NO |
CVE-2020-7046HIGH lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the unauthenticated triggering of a | Feb 12, 2020 | 7.5 | 53 | NO | NO |
CVE-2022-23833HIGH An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart forms could result in an infini | Feb 3, 2022 | 7.5 | 52 | NO | NO |
CVE-2019-19307CRITICAL An integer overflow in parse_mqtt in mongoose.c in Cesanta Mongoose 6.16 allows an attacker to achieve remote DoS (infinite loop), or possibly cause an out-of-bounds write, by send | Nov 26, 2019 | 9.8 | 51 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.