Skip to main content

CWE archive

CWE-674 CVEs

Programmatic archive

497 CVEs tagged with CWE-6747 Critical, 221 High, 239 Medium, 30 Low, 0 Unrated.

CVE-2025-46206

Published Aug 4, 2025

An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion in the `mutool clean` utility. When processing a crafted P…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
29.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-50420

Published Aug 4, 2025

An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an infinite recursion via supplying a crafted PDF file. This can lead to a Denial of…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-38493

Published Jul 28, 2025

In the Linux kernel, the following vulnerability has been resolved: tracing/osnoise: Fix crash in timerlat_dump_stack() We have observed kernel panics when using timerlat with s…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2025-38459

Published Jul 25, 2025

In the Linux kernel, the following vulnerability has been resolved: atm: clip: Fix infinite recursive call of clip_push(). syzbot reported the splat below. [0] This happens if…

CVSS 7.8 · High
evidence mentions
10
Buzz score
34.0
Vendor/product tagsBeta · best-effort

CVE-2025-48924

Published Jul 11, 2025

Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.comm…

CVSS 5.3 · Medium
evidence mentions
6
Buzz score
31.0
Vendor/product tagsBeta · best-effort

CVE-2025-53864

Published Jul 11, 2025

Connect2id Nimbus JOSE + JWT 10.0.x before 10.0.2 and 9.37.x before 9.37.4 allows a remote attacker to cause a denial of service via a deeply nested JSON object supplied in a JWT…

CVSS 5.8 · Medium
evidence mentions
5
Buzz score
27.9

CVE-2025-38315

Published Jul 10, 2025

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel: Check dsbr size from EFI variable Since the size of struct btintel_dsbr is already known,…

CVSS 5.5 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-5472

Published Jul 7, 2025

The JSONReader in run-llama/llama_index versions 0.12.28 is vulnerable to a stack overflow due to uncontrolled recursive JSON parsing. This vulnerability allows attackers to trigg…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-53605

Published Jul 5, 2025

The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::coded_input_stream::CodedInputStream::skip_group parsing of unknown fields in untrusted inp…

CVSS 5.9 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2025-6710

Published Jun 26, 2025

MongoDB Server may be susceptible to stack overflow due to JSON parsing mechanism, where specifically crafted JSON inputs may induce unwarranted levels of recursion, resulting in…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-50118

Published Jun 18, 2025

In the Linux kernel, the following vulnerability has been resolved: powerpc/perf: Optimize clearing the pending PMI and remove WARN_ON for PMI check in power_pmu_disable commit…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-4565

Published Jun 16, 2025

Any project that uses Protobuf Pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of S…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-30193

Published May 20, 2025

In some circumstances, when DNSdist is configured to allow an unlimited number of queries on a single, incoming TCP connection from a client, an attacker can cause a denial of ser…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-1752

Published May 10, 2025

A Denial of Service (DoS) vulnerability has been identified in the KnowledgeBaseWebReader class of the run-llama/llama_index project, affecting version ~ latest(v0.12.15). The vul…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-37851

Published May 9, 2025

In the Linux kernel, the following vulnerability has been resolved: fbdev: omapfb: Add 'plane' value check Function dispc_ovl_setup is not intended to work with the value OMAP_D…

CVSS 5.5 · Medium
evidence mentions
11
Buzz score
34.9
Vendor/product tagsBeta · best-effort

CVE-2022-49782

Published May 1, 2025

In the Linux kernel, the following vulnerability has been resolved: perf: Improve missing SIGTRAP checking To catch missing SIGTRAP we employ a WARN in __perf_event_overflow(),…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-43708

Published Apr 17, 2025

VisiCut 2.1 allows stack consumption via an XML document with nested set elements, as demonstrated by a java.util.HashMap StackOverflowError when reference='../../../set/set[2]' i…

CVSS 3.3 · Low
evidence mentions
3
Buzz score
28.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-32387

Published Apr 9, 2025

Helm is a package manager for Charts for Kubernetes. A JSON Schema file within a chart can be crafted with a deeply nested chain of references, leading to parser recursion that ca…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2023-52986

Published Mar 27, 2025

In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Check for any of tcp_bpf_prots when cloning a listener A listening socket linked to a sockmap h…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-12910

Published Mar 20, 2025

A vulnerability in the `KnowledgeBaseWebReader` class of the run-llama/llama_index repository, version latest, allows an attacker to cause a Denial of Service (DoS) by controlling…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-58103

Published Mar 16, 2025

Square Wire before 5.2.0 does not enforce a recursion limit on nested groups in ByteArrayProtoReader32.kt and ProtoReader.kt.

CVSS 5.8 · Medium

CVE-2024-8176

Published Mar 14, 2025

A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply neste…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Showing 201-225 of 497 CVEsPage 9 of 20