Picotls is a TLS protocol library that allows users select different crypto backends based on their use case. Picotls im
The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can
This affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state
file-type detects the file type of a file, stream, or data. Prior to 21.3.1, a denial of service vulnerability exists in
A weakness has been identified in Cesanta Mongoose up to 7.20. This vulnerability affects the function handle_opt of the
A security flaw has been discovered in VectifyAI PageIndex up to f50e52975313c6716c02b20a119577a1929decba. Affected by t
Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.6.6, protobufjs parsed opt
Pillow is a Python imaging library. From 12.0.0 through 12.2.0, Pillow's EPS parser in PIL/EpsImagePlugin.py accepts a n
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Ident
A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO
HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of service
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
pam_usb provides hardware authentication for Linux using removable media. In pam_usb 0.9.1 and earlier, usb_get_process_
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
The Zephyr PL011 UART driver (drivers/serial/uart_pl011.c) contains an unbounded software loop in pl011_irq_tx_enable()
FatFs prior to R0.16 that use GPT scanning with 'FF_LBA64 = 1' contains an issue where an unbounded loop count derived f
The ARM PL011 UART driver in drivers/serial/uart_pl011.c fails to acknowledge receive error interrupts. On the PL011, th
A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls
pypdf is a free and open-source pure-python PDF library. An attacker who uses an infinite loop vulnerability that is pre
In OpenBSD through 7.8, the slaacd and rad daemons have an infinite loop when they receive a crafted ICMPv6 Neighbor Dis
A flaw was found in glib-networking. A remote attacker can exploit this vulnerability by presenting a specially crafted
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an auth
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which ma
A vulnerability was identified in bytebot-ai bytebot 0.0.1. The affected element is an unknown function of the component
libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clien
In the Synopsys DesignWare I2C driver (drivers/i2c/i2c_dw.c) operating in target/slave mode, the rx_full interrupt handl
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in briandilley jsonrpc4j (src/main/java/com/googlec
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in coolsnowwolf lede (package/lean/mt/drivers/mt761
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in coolsnowwolf lede (package/lean/mt/drivers/mt760
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in datavane tis (tis-console/src/main/java/com/qlan
A reachable infinite loop via an integer wraparound is present in Silicon Labs' Matter SDK which allows an attacker to t
Loop with unreachable exit condition ('infinite loop') vulnerability in The Wikimedia Foundation Mediawiki - GrowthExper
facil.io is a C micro-framework for web applications. Prior to commit 5128747363055201d3ecf0e29bf0a961703c9fa0, `fio_jso
In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-ch
Python Liquid is a Python engine for the Liquid template language. Prior to 2.2.1, given a malformed {% case %} tag with
Denial-of-Service in Thinkst Applied Research OpenCanary (MongoDB module) allows Excessive Allocation. This issue affe
Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 10.
In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.1.3, the native entropy source used on Intel platforms retried
LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. From 10.26.0 until 10.27.1, the stri
Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can infl
In the Linux kernel, the following vulnerability has been resolved: nvmet: Fix crash when a namespace is disabled The
Memory corruptions can be remotely triggered in the Control-M/Agent when SSL/TLS communication is configured. The issu
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.20.1, cpp-httplib does not
A vulnerability in the function that performs IPv4 and IPv6 Network Address Translation (NAT) DNS inspection for Cisco S
A vulnerability in the packet inspection functionality of the Snort 3 Detection Engine of Cisco Secure Firewall Threat D
A vulnerability in the management and VPN web servers of Cisco Secure Firewall ASA Software and Secure FTD Software coul
A vulnerability in the IKEv2 feature of Cisco IOS Software, IOS XE Software, Secure Firewall ASA Software, and Secure FT
In the Linux kernel, the following vulnerability has been resolved: bpf: Prevent tailcall infinite loop caused by frepl
Frequently Asked Questions
What is CWE-835?
CWE-835 (CWE-835) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-835?
There are 1,051 CVE records associated with CWE-835 in our database. Of these, 9 are critical severity, 388 are high severity, and 449 are medium severity.
How can I protect against CWE-835 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-835 using AI-powered security agents.
Detect CWE-835 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-835 vulnerabilities across your infrastructure.
Get Started