CWE-674: CWE-674

70
Total CVEs
1
Critical
36
High
6.7
Avg CVSS

Yearly Trend

2026
10
2025
30
2024
15
2023
4
2022
4

Top Affected Vendors

1 Linux 9
2 Debian 8
3 Netapp 4
4 Imagemagick 3
5 Fedoraproject 3
6 Ibm 3
7 Squid Cache 2
8 Wireshark 2
9 Golang 2
10 Sap 1

All CWE-674 CVEs (70)

CVE-2024-58102
5.7

This vulnerability in Datalust Seq allows attackers to cause denial of service through stack exhaustion by submitting queries with deeply nested expre...

Mar 11, 2025
CVE-2026-27014
5.5

This vulnerability in NanaZip's ROMFS archive parser allows attackers to create malicious archives that cause infinite loops or stack overflows when p...

Feb 19, 2026
CVE-2025-50537
5.5

A stack overflow vulnerability in ESLint versions before 9.26.0 allows denial of service when processing test cases with circular references. This aff...

Jan 26, 2026
CVE-2025-40090
5.5

This CVE describes a deadlock vulnerability in the Linux kernel's ksmbd SMB server module. When clients attempt to open named pipes via RPC calls, the...

Oct 30, 2025
CVE-2023-53513
5.5

This CVE-2023-53513 is an integer overflow vulnerability in the Linux kernel's NBD (Network Block Device) driver. It allows local attackers to trigger...

Oct 1, 2025
CVE-2025-39704
5.5

A stack buffer overflow vulnerability exists in the Linux kernel's KVM (Kernel-based Virtual Machine) implementation for LoongArch architecture. When ...

Sep 5, 2025
CVE-2025-38614
5.5

This CVE addresses a semi-unbounded recursion vulnerability in the Linux kernel's eventpoll (epoll) subsystem. Attackers could potentially cause kerne...

Aug 19, 2025
CVE-2025-38315
5.5

A stack buffer overflow vulnerability in the Linux kernel's Bluetooth Intel driver allows attackers to execute arbitrary code or cause denial of servi...

Jul 10, 2025
CVE-2025-37851
5.5

A buffer overflow vulnerability exists in the Linux kernel's OMAPFB display driver when processing certain 'plane' parameter values. This could allow ...

May 9, 2025
CVE-2023-52986
5.5

A Linux kernel vulnerability in the BPF sockmap subsystem allows improper handling of cloned listening sockets, potentially leading to denial of servi...

Mar 27, 2025
CVE-2024-31228
5.5

Authenticated Redis users can cause denial-of-service by using specially crafted long string patterns in commands like KEYS, SCAN, PSUBSCRIBE, FUNCTIO...

Oct 7, 2024
CVE-2025-68618
5.3

ImageMagick versions before 7.1.2-12 contain a denial-of-service vulnerability when processing malicious SVG files. Attackers can cause the applicatio...

Dec 30, 2025
CVE-2025-36158
5.1

IBM Concert versions 1.0.0 through 2.0.0 contain an uncontrolled recursive directory copying vulnerability that allows local users with specific permi...

Nov 20, 2025
CVE-2024-2965
4.7

This CVE describes a Denial-of-Service vulnerability in LangChain's SitemapLoader class where the parse_sitemap method can enter infinite recursion if...

Jun 6, 2024
CVE-2025-20025
4.4

This vulnerability in Intel's TinyCBOR libraries allows authenticated users to trigger uncontrolled recursion, potentially causing denial of service t...

Aug 12, 2025
CVE-2025-68950
4.0

ImageMagick versions before 7.1.2-12 contain a denial-of-service vulnerability where circular references between two MVG (Magick Vector Graphics) file...

Dec 30, 2025
CVE-2024-54731
4.0

CVE-2024-54731 is a stack consumption vulnerability in cpdf that allows denial of service through crafted PDF documents. Attackers can cause the appli...

Jan 8, 2025
CVE-2026-0989
3.7

A denial-of-service vulnerability exists in libxml2's RelaxNG parser where nested <include> directives can cause unlimited recursion, leading to stack...

Jan 15, 2026
CVE-2025-67899
2.9

CVE-2025-67899 is an unbounded recursion vulnerability in uriparser library versions through 0.9.9 that allows stack exhaustion via specially crafted ...

Dec 14, 2025
CVE-2026-0994
N/A

A denial-of-service vulnerability exists in Google's Protocol Buffers Python library where the max_recursion_depth limit can be bypassed when parsing ...

Jan 23, 2026

About CWE-674 (CWE-674)

Our database tracks 70 CVEs classified as CWE-674, with 1 rated critical and 36 rated high severity. The average CVSS score for CWE-674 vulnerabilities is 6.7.

External reference: View CWE-674 on MITRE CWE →

Monitor CWE-674 Vulnerabilities

Get alerted when new CWE-674 CVEs affect your infrastructure.

Start Monitoring Free