CWE-834

CWE-834 · 4 records · 3 with a public proof-of-concept

Records the NVD classes under CWE-834, highest CVSS first.

  1. MEDIUM 6.5CVE-2026-77399public PoC

    icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 6.1.0 until 7.2.2, vInt.from_ical accepts an attacker-controlled VALARM REPEAT value and applications that request alarm times can eagerly expand it without an applica…

    AI risk analysis on Exploit-DB.ai →

  2. MEDIUM 5.5CVE-2026-81880public PoC

    radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Apple Preferred Executable Format loader was vulnerable because the PEF loader accepted relocSecCount values that were not bounded by the number of section…

    radare2

    AI risk analysis on Exploit-DB.ai →

  3. UNSCOREDCVE-2026-53493public PoC

    containerd is an open-source container runtime. Prior to versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1, a crafted OCI index graph can force very high CPU/memory usage during PullImage (before container start), causing long ContainerCreating stalls and, at l…

    AI risk analysis on Exploit-DB.ai →

  4. UNSCOREDCVE-2026-87721

    Uncontrolled Resource Consumption (CWE-400 / CWE-407) in the ANTLR 3 search query parser (QueryParser / Query.g) in Gerrit Code Review versions 2.0.19 through 3.12.9, 3.13.0 through 3.13.8, and 3.14.0 through 3.14.2 allows an unauthenticated remote attacker (o…

    AI risk analysis on Exploit-DB.ai →