In Contiki 3.0, a Telnet server that silently quits (before disconnection with clients) leads to connected clients enter
jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML
An issue was discovered in tcp_pulloutofband() in tcp_in.c in HCC embedded InterNiche 4.0.1. The TCP out-of-band urgent-
The web server in InterNiche NicheStack through 4.0.1 allows remote attackers to cause a denial of service (infinite loo
Loop with unreachable exit condition may occur due to improper handling of unsupported input in Snapdragon Auto, Snapdra
The rencode package through 1.0.6 for Python allows an infinite loop in typecode decoding (such as via ;\x2f\x7f), enabl
Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets
An infinite loop in Open Robotics ros_comm XMLRPC server in ROS Melodic through 1.4.11 and ROS Noetic through1.15.11 all
An issue was discovered in MediaWiki through 1.36.2. A parser function related to loop control allowed for an infinite l
TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxmlparser.cpp via the TIXML_UTF_LEAD_0 case
NLnet Labs Routinator prior to 0.10.2 happily processes a chain of RRDP repositories of infinite length causing it to ne
An unauthenticated and remote adversary can consume all of the device's CPU due to crafted HTTP requests sent to SMA100
Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server. T
Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or
Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet
Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injectio
TensorFlow is an end-to-end open source platform for machine learning. TFlite graphs must not have loops between nodes.
In an EVPN/VXLAN scenario, if an IRB interface with a virtual gateway address (VGA) is configured on a PE, a traffic loo
In OpenWrt 19.07.x before 19.07.7, when IPv6 is used, a routing loop can occur that generates excessive network traffic
Hirschmann OS2, RSP, and RSPE devices before HiOS 08.3.00 allow a denial of service. An unauthenticated, adjacent attack
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
An issue was discovered in Zammad before 4.1.1. An attacker with valid agent credentials may send a series of crafted re
In an MPLS P2MP environment a Loop with Unreachable Exit Condition vulnerability in the routing protocol daemon (RPD) of
In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. T
A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in versions up to and incl
OctoRPKI does not limit the depth of a certificate chain, allowing for a CA to create children in an ad-hoc fashion, the
kamadak-exif is an exif parsing library written in pure Rust. In kamadak-exif version 0.5.2, there is an infinite loop i
The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input
A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU. This
A vulnerability has been identified in SIMATIC S7-PLCSIM V5.4 (All versions). An attacker with local access to the syste
Modem will enter into busy mode in an infinite loop while parsing histogram dimension due to improper validation of inpu
A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apac
An issue was discovered in the Linux kernel before 5.8. arch/x86/kvm/svm/svm.c allows a set_memory_region_test infinite
A flaw was found in PDFResurrect in version 0.22b. There is an infinite loop in get_xref_linear_skipped() in pdf.c via a
A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection o
In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects A
A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). Th
A lack of CPU resource in the Linux kernel tracing module functionality in versions prior to 5.14-rc3 was found in the w
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file
TensorFlow is an end-to-end open source platform for machine learning. In affected versions the strided slice implementa
long running loops in grant table handling In order to properly monitor resource use, Xen maintains information on the g
Irfanview 4.57 is affected by an infinite loop when processing a crafted BMP file in the EFFECTS!AutoCrop_W component. T
An issue was discovered in stb stb_image.h 1.33 through 2.27. The HDR loader parsed truncated end-of-file RLE scanlines
Irfanview v4.53 was discovered to contain an infinity loop via JPEG2000!ShowPlugInSaveOptions_W+0x1ecd8.
An infinite loop vulnerability exists in Gpac 1.0.1 in gf_get_bit_size.
An infinite loop vulnerability exists in gpac 1.1.0 in the gf_log function, which causes a Denial of Service.
An infinite loop vulnerability exists in nasm 2.16rc0 via the gpaste_tokens function.
Frequently Asked Questions
What is CWE-835?
CWE-835 (CWE-835) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-835?
There are 1,051 CVE records associated with CWE-835 in our database. Of these, 9 are critical severity, 388 are high severity, and 449 are medium severity.
How can I protect against CWE-835 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-835 using AI-powered security agents.
Detect CWE-835 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-835 vulnerabilities across your infrastructure.
Get Started