An always-incorrect control flow implementation in the implicit filter terms of Juniper Networks Junos OS and Junos OS E
A vulnerability affecting F-Secure Antivirus engine was discovered whereby scanning WIM archive file can lead to denial-
kaml is an open source implementation of the YAML format with support for kotlinx.serialization. In affected versions at
Remote Denial of Service in LwM2M do_write_op_tlv. Zephyr versions >= 1.14.2, >= 2.2.0 contain Improper Input Validation
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.6 where an infinite loop exist when
Pydantic is a data validation and settings management using Python type hinting. In affected versions passing either `'i
Infinite Loop in zziplib v0.13.69 allows remote attackers to cause a denial of service via the return value "zzip_file_r
xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
In Jp2Image::readMetadata() in jp2image.cpp in Exiv2 0.27.2, an input file can result in an infinite loop and hang, with
pmm-server in Percona Monitoring and Management (PMM) 2.2.x before 2.2.1 allows unauthenticated denial of service.
lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command paramet
A Denial of Service (infinite loop) exists in OpenSIPS before 1.10 in lookup.c.
A denial of service issue was addressed with improved input validation.
The Library API in buger jsonparser through 2019-12-04 allows attackers to cause a denial of service (infinite loop) via
perl-Convert-ASN1 (aka the Convert::ASN1 module for Perl) through 0.27 allows remote attackers to cause an infinite loop
Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers.
An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has circular reference mishandling that causes a
An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows resource consumption via crafted cross-re
An issue was discovered in LibVNCServer before 0.9.13. An improperly closed TCP connection causes an infinite loop in li
The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder ent
An infinite loop was discovered in the CoAP library in Arm Mbed OS 5.15.3. The CoAP parser is responsible for parsing re
An issue was discovered in Mattermost Server before 5.23.0. Large webhook requests allow attackers to cause a denial of
An issue was discovered in Mattermost Server before 5.23.0. Automatic direct message replies allow attackers to cause a
Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a denial of service, caused by an error in the "homeplugd"
In Wireshark 3.2.0 to 3.2.4, the GVCP dissector could go into an infinite loop. This was addressed in epan/dissectors/pa
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when o
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to
Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to CPU exhaustion due to an infinite loop in
Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary
ise smart connect KNX Vaillant 1.2.839 contain a Denial of Service.
An issue was discovered in wolfSSL before 4.5.0. It mishandles the change_cipher_spec (CCS) message processing logic for
An issue was discovered in the http crate before 0.1.20 for Rust. An integer overflow in HeaderMap::reserve() could resu
Trustwave ModSecurity 3.x through 3.0.4 allows denial of service via a special request. NOTE: The discoverer reports "Tr
In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector could enter an infinite loop. This was add
In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed in epan/dissectors/packet-gquic.c by co
An issue was discovered in Contiki through 3.0. An infinite loop exists in the uIP TCP/IP stack component when processin
An issue was discovered in Contiki through 3.0. An infinite loop exists in the uIP TCP/IP stack component when handling
An issue was discovered in picoTCP 1.7.0. The routine for processing the next header field (and deducing whether the IPv
An issue was discovered in picoTCP and picoTCP-NG through 1.7.0. When an unsupported TCP option with zero length is prov
On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, a large HTTP POST request sent to the change password API will tr
In a Point-to-Multipoint (P2MP) Label Switched Path (LSP) scenario, an uncontrolled resource consumption vulnerability i
Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process c
The ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows attackers to cause a denial of service (inf
A large or infinite loop vulnerability in the JOC Cockpit component of SOS JobScheduler 1.11 and 1.13.2 allows attackers
In RTTTL_Event of eas_rtttl.c, there is possible resource exhaustion due to a missing bounds check. This could lead to r
In IMY_Event of eas_imelody.c, there is possible resource exhaustion due to a missing bounds check. This could lead to r
In Parse_lart of eas_mdls.c, there is possible resource exhaustion due to a missing bounds check. This could lead to rem
In Parse_art of eas_mdls.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remo
In Parse_ptbl of eas_mdls.c, there is possible resource exhaustion due to a missing bounds check. This could lead to rem
In ihevcd_ref_list() of ihevcd_ref_list.c, there is a possible infinite loop due to a missing bounds check. This could l
Frequently Asked Questions
What is CWE-835?
CWE-835 (CWE-835) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-835?
There are 1,051 CVE records associated with CWE-835 in our database. Of these, 9 are critical severity, 388 are high severity, and 449 are medium severity.
How can I protect against CWE-835 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-835 using AI-powered security agents.
Detect CWE-835 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-835 vulnerabilities across your infrastructure.
Get Started