A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of
Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular us
Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular us
Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition. The vulnerability e
If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume e
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version
When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei
Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs could recu
Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.27, python-multipart has a denial of service v
kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in SCRAM authentication handling that allows a ma
Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.
A denial of service (DoS) vulnerability in Palo Alto Networks Prisma SD-WAN ION devices enables an unauthenticated attac
(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN
An Unchecked Input for Loop Condition vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS o
An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to
An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to
An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to
Liquid Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by pr
FMP/NOTIFY protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
Uncontrolled Recursion vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are reco
An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling
Logic bypass vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect availabi
When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly h
Unchecked input for loop condition (CWE-606) in the SNMP agent in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI
Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.
GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequ
Pega Platform versions 7.1.0 through 25.1.2 are affected by an improper validation of inputs that are used for loop cond
Frequently Asked Questions
What is CWE-606?
CWE-606 (CWE-606) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-606?
There are 28 CVE records associated with CWE-606 in our database. Of these, 0 are critical severity, 12 are high severity, and 10 are medium severity.
How can I protect against CWE-606 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-606 using AI-powered security agents.
Detect CWE-606 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-606 vulnerabilities across your infrastructure.
Get Started