In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. Thi
An issue in the component hang.wasm of WebAssembly 1.0 causes an infinite loop.
In elfutils 0.183, an infinite loop was found in the function handle_symtab in readelf.c .Which allows attackers to caus
ngiflib commit 5e7292 was discovered to contain an infinite loop via the function DecodeGifImg at ngiflib.c.
An issue was discovered in GetByte function in miniupnp ngiflib version 0.4, allows local attackers to cause a denial of
A vulnerability was found in libX11 due to an infinite loop within the PutSubImage() function. This flaw allows a local
An issue in the component IPAddressBitsDivision of IPAddress v5.1.0 leads to an infinite loop. This is disputed because
PDFio is a C library for reading and writing PDF files. In versions prior to 1.1.0 a denial of service (DOS) vulnerabil
XRA dissector infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injectio
BT SDP dissector infinite loop in Wireshark 4.0.0 to 4.0.7 and 3.6.0 to 3.6.15 allows denial of service via packet injec
Versions of the package asyncua before 0.9.96 are vulnerable to Denial of Service (DoS) such that an attacker can send a
pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions 3.7.0
OpenMage LTS is an e-commerce platform. Versions prior to 19.4.22 and 20.0.19 contain an infinite loop in malicious code
A loop with unreachable exit condition ('infinite loop') in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS versio
A flaw was found in FRRouting when parsing certain babeld unicast hello messages that are intended to be ignored. This i
Cosign is a sigstore signing tool for OCI containers. Cosign is susceptible to a denial of service by an attacker contro
Kyverno is a policy engine designed for Kubernetes. A security vulnerability was found in Kyverno where an attacker coul
Kyverno is a policy engine designed for Kubernetes. A security vulnerability was found in Kyverno where an attacker coul
A vulnerability, which was classified as problematic, was found in InternalError503 Forget It up to 1.3. This affects an
Unisys ClearPath MCP TCP/IP Networking Services 59.1, 60.0, and 62.0 has an Infinite Loop.
The package colors after 1.4.0 are vulnerable to Denial of Service (DoS) that was introduced through an infinite loop in
Xerox VersaLink devices on specific versions of firmware before 2022-01-26 allow remote attackers to brick the device vi
An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation has an infinite lo
Junrar is an open source java RAR archive library. In affected versions A carefully crafted RAR archive can trigger an i
An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing
A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote att
The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for n
An issue in BigAnt Software BigAnt Server v5.6.06 can lead to a Denial of Service (DoS).
PJSIP is a free and open source multimedia communication library written in the C language. Versions 2.12 and prior cont
A denial of service vulnerability exists in the parseNormalModeParameters functionality of MZ Automation GmbH libiec6185
PJSIP is a free and open source multimedia communication library written in C. A denial-of-service vulnerability affects
Pion DTLS is a Go implementation of Datagram Transport Layer Security. Prior to version 2.1.4, an attacker can send pack
libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's c
The package jpeg-js before 0.4.4 are vulnerable to Denial of Service (DoS) where a particular piece of input will cause
An infinite loop in OPC UA .NET Standard Stack 1.04.368 allows a remote attackers to cause the application to hang via a
An infinite loop in the function httpRpmPass of TP-Link TL-WR741N/TL-WR742N V1/V2/V3_130415 allows attackers to cause a
A CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability exists that could cause a denial of serv
Infinite loop in Read in crypto/rand before Go 1.17.11 and Go 1.18.3 on Windows allows attacker to cause an indefinite h
In libtirpc before 1.3.3rc1, remote attackers could exhaust the file descriptors of a process that uses libtirpc because
In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, whe
It is possible to provide data to be read that leads the reader to loop in cycles endlessly, consuming CPU. This issue a
A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.15), Teamcenter V13.0 (All versions < V1
Endless Infinite loop in Blender-thumnailing due to logical bugs.
libjpeg commit 281daa9 was discovered to contain an infinite loop via the component Frame::ParseTrailer.
PDF Labs pdftk-java v3.2.3 was discovered to contain an infinite loop via the component /text/pdf/PdfReader.java.
Improper detection of complete HTTP body decompression SwiftNIO Extras provides a pair of helpers for transparently deco
An external attacker is able to send a specially crafted email (with many recipients) and trigger a potential DoS of the
Denial of service in modem due to infinite loop while parsing IGMPv2 packet from server in Snapdragon Consumer IOT, Snap
Transient DOS due to loop with unreachable exit condition in WLAN firmware while parsing IPV6 extension header. in Snapd
Frequently Asked Questions
What is CWE-835?
CWE-835 (CWE-835) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-835?
There are 1,051 CVE records associated with CWE-835 in our database. Of these, 9 are critical severity, 388 are high severity, and 449 are medium severity.
How can I protect against CWE-835 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-835 using AI-powered security agents.
Detect CWE-835 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-835 vulnerabilities across your infrastructure.
Get Started