CWE-835

CWE-835 · 8 records · 6 with a public proof-of-concept

Records the NVD classes under CWE-835, highest CVSS first.

  1. HIGH 7.5CVE-2026-97362public PoC

    HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause a complete and persistent loss of availability by sending a single crafted request. Attackers can trigger a hung serving thread that enters…

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 7.5CVE-2026-6668

    Integer overflow in the packet buffer growth logic in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to cause a denial of service. Sufficiently large input makes the buffer size computation overflow, leaving the growth loop unable to termin…

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 7.5CVE-2026-87082public PoC

    Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in encode_punycode. Neither backend checks that its input is well-formed UTF-8, so a string with the UTF-8 flag set over malformed bytes, as …

    AI risk analysis on Exploit-DB.ai →

  4. HIGH 7.5CVE-2026-82560public PoC

    Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width. Each =over adds its indent to the margin, which wrap() subtracts from the output width to get the spa…

    AI risk analysis on Exploit-DB.ai →

  5. HIGH 7.5CVE-2026-85715public PoC

    ExifReader is a JavaScript Exif information parser. Prior to 4.41.1, ExifReader parses attacker-controlled HEIC or AVIF ISO-BMFF files in getItems() within src/image-header-iso-bmff-iloc.js and trusts iloc itemCount and extentCount values while allocating an e…

    AI risk analysis on Exploit-DB.ai →

  6. HIGH 7.5CVE-2026-84997public PoC

    react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. From 0.6.0 until 1.11.1, React\Http\Io\ChunkedDecoder could enter an infinite loop while processing a malformed Transfer-Encoding: chunked body because handleData requ…

    AI risk analysis on Exploit-DB.ai →

  7. MEDIUM 5.5CVE-2026-81885public PoC

    radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's NE relocation fixup-chain parser was vulnerable because the NE relocation parser followed fixup chains without an active iteration limit or cycle detection…

    radare2

    AI risk analysis on Exploit-DB.ai →

  8. MEDIUM 5.1CVE-2026-71227

    A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating…

    AI risk analysis on Exploit-DB.ai →