The IFrame widget in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before u
A denial of service vulnerability exists in the Web Application functionality of LevelOne WBR-6012 R0.40e6. A specially
A vulnerability has been found in GPAC 2.5-DEV-rev228-g11067ea92-master and classified as problematic. Affected by this
A vulnerability has been found in SourceCodester Student Record Management System 1.0 and classified as problematic. Thi
sigstore-go, a Go library for Sigstore signing and verification, is susceptible to a denial of service attack in version
There is a HIGH severity vulnerability affecting the CPython "zipfile" module affecting "zipfile.Path". Note that the mo
A vulnerability in the Device Management Servlet application of Cisco BroadWorks Application Delivery Platform and Cisco
A vulnerability in ICMPv6 inspection when configured with the Snort 2 detection engine for Cisco Firepower Threat Defens
A vulnerability in the Simple Network Management Protocol (SNMP) service of Cisco FXOS Software for Firepower 4100 Serie
Technitium DNS Server before 10.0 allows a self-CNAME denial-of-service attack in which a CNAME loop causes an answer to
A flaw was found in libXpm. When processing a file with width of 0 and a very large height, some parser functions will b
A flaw was found in libXpm. This issue occurs when parsing a file with a comment not closed; the end-of-file condition w
Denial of service in modem due to missing null check while processing IP packets with padding
node-jose is a JavaScript implementation of the JSON Object Signing and Encryption (JOSE) for web browsers and node.js-b
Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. Versions from 0.9.0 to 0.12.0 (including) did not properly
Math/PrimeField.php in phpseclib 3.x before 3.0.19 has an infinite loop with composite primefields.
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified
An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinit
An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC
An issue was discovered in OFPBundleCtrlMsg in parser.py in Faucet SDN Ryu version 4.34, allows remote attackers to caus
An issue was discovered in OFPQueueGetConfigReply in parser.py in Faucet SDN Ryu version 4.34, allows remote attackers t
Memory Exhaustion vulnerability in ONLYOFFICE Document Server 4.0.3 through 7.3.2 allows remote attackers to cause a den
A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthe
A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake sta
Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types. This affects WithSec
Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types. This affects WithSec
Certain WithSecure products allow Denial of Service (infinite loop). This affects WithSecure Client Security 15, WithSec
An issue was discovered in ApiPageSet.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x b
An Improperly Implemented Security Check for Standard vulnerability in storm control of Juniper Networks Junos OS QFX5k
Improper file stream access in /desktop_app/file.ajax.php?action=uploadfile in Bitrix24 22.0.300 allows unauthenticated
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Sierra Wireless, Inc ALEOS could potentially all
The Candid library causes a Denial of Service while parsing a specially crafted payload with 'empty' data type. For exa
ModularSquareRoot in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (infinite loop)
hutool-core v5.8.23 was discovered to contain an infinite loop in the StrSplitter.splitByRegex function. This vulnerabil
A vulnerability in the Administrative XML Web Service (AXL) API of Cisco Unified Communications Manager (Unified CM) and
An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (Do
An issue was discovered in function TIFFReadDirectory libtiff before 4.4.0 allows attackers to cause a denial of service
A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. A wrong exit condition may lea
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.2 before 16.3.6, all versions start
Infinite loops in the BPv6, OpenFlow, and Kafka protocol dissectors in Wireshark 4.0.0 to 4.0.1 and 3.6.0 to 3.6.9 allow
GDSDB infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or cra
pypdf is an open source, pure-python PDF library. In affected versions an attacker may craft a PDF which leads to an inf
pypdf is a pure-python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF files. In
OPenFGA is an open source authorization/permission engine built for developers. OpenFGA versions v1.1.0 and prior are vu
OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA is vulnerabl
A denial of service vulnerability exists in the DCRegister DDNS_RPC_MAX_RECV_SIZE functionality of SoftEther VPN 4.41-97
When a file is processed, an infinite loop occurs in next_inline() of the more_curly() function.
In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. Thi
In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. Thi
In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. Thi
Frequently Asked Questions
What is CWE-835?
CWE-835 (CWE-835) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-835?
There are 1,051 CVE records associated with CWE-835 in our database. Of these, 9 are critical severity, 388 are high severity, and 449 are medium severity.
How can I protect against CWE-835 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-835 using AI-powered security agents.
Detect CWE-835 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-835 vulnerabilities across your infrastructure.
Get Started