$_SecureScope악용 확인 · 악용 확률 · 한국어 권고
CVE Ledger

CWE-835 관련 취약점

같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.

원장 17,280건이 중 악용 확인 1,734건분류: CWE-835

전체 목록

47건

CVE-2026-68523`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tena…0.6%높음7.5
CVE-2026-84997react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. From 0.6.0 until …0.5%높음7.5
CVE-2026-86537Uncaught exception, Loop with unreachable exit condition ('infinite loop'), Integer underflow (wrap or wraparo…0.6%높음8.7
CVE-2026-69210Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, WebSocket FrameTranscoder.bodyL…0.5%높음7.5
CVE-2026-93925Stack-based buffer overflow, Incorrect bitwise shift of integer vulnerability in Apache Thrift C++ THeaderProt…0.5%높음8.7
CVE-2026-85715ExifReader is a JavaScript Exif information parser. Prior to 4.41.1, ExifReader parses attacker-controlled HEI…0.4%높음7.5
CVE-2026-102253iperf3 versions prior to 3.22 contains a denial of service vulnerability that allows unauthenticated remote at…0.4%높음8.7
CVE-2026-80489Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv…0.4%보통5.9
CVE-2026-77117Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with ico…0.4%보통5.9
CVE-2026-78129strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption.0.4%보통5.9
CVE-2026-20154A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptiv…0.4%높음8.6
CVE-2026-94654Loop with unreachable exit condition ('infinite loop') vulnerability in Apache Thrift python bindings. This is…0.4%높음8.2
CVE-2026-85476Loop with unreachable exit condition ('infinite loop') vulnerability in Apache Thrift c_glib bindings. This is…0.4%높음8.2
CVE-2026-62949AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 prot…0.4%보통6.5
CVE-2026-96780figlet.js is a FIG driver written in JavaScript that aims to implement the FIGfont specification. Prior to 1.1…0.4%높음8.2
CVE-2026-6668Integer overflow in the packet buffer growth logic in PgBouncer through 1.25.2 allows an unauthenticated remot…0.4%높음7.5
CVE-2026-85730smol-toml is a small, fast, and correct TOML parser and serializer. Prior to 1.7.1, parse() can enter an infin…0.4%높음8.2
CVE-2026-78543IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus …0.4%보통5.3
CVE-2026-91952FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function whe…0.3%높음7.1
CVE-2026-88000Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1…0.3%보통6.5
CVE-2026-88002Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.1,…0.3%보통6.5
CVE-2026-86535Loop with unreachable exit condition ('infinite loop'), Improperly controlled modification of object prototype…0.3%높음8.7
CVE-2026-61633NanoMQ is an MQTT broker. Prior to 0.24.14, the NanoMQ client function nni_mqtt_msg_decode_unsubscribe() in nn…0.3%낮음2.0
CVE-2026-78132strongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parser for ietf…0.3%높음7.5
CVE-2026-97688urllib3 is an HTTP client library for Python. From 2.6.2 until 2.8.0, HTTPResponse.stream and HTTPResponse.rea…0.3%보통6.9
CVE-2026-97362HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attacker…0.3%높음8.7
CVE-2026-87013Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1…0.3%보통4.3
CVE-2026-63570Loop with unreachable exit condition in Pkcs12Store.GetCertificateChain in Legion of the Bouncy Castle Inc. bc…0.2%높음7.1
CVE-2026-63575Loop with unreachable exit condition in the PKCS#12 key derivation (Pkcs12ParametersGenerator) in Legion of th…0.2%높음7.1
CVE-2026-102511Improper Verification of Source of a Communication Channel in the ADS discovery of the Go implementation of Ap…0.2%높음8.5
CVE-2026-15923The Zephyr SDIO subsystem function sdio_io_rw_extended_helper() in subsys/sd/sdio.c finishes transfers with a …0.2%보통4.6
CVE-2026-102726Unbounded PPP IPCP Option Parsing Causes a Worker Stall and Out-of-bounds Read0.2%보통6.0
CVE-2026-102714`_nx_icmpv6_validate_options()` scans the option area with `while (length > 2)` (`common/src/nx_icmpv6_validat…0.2%높음7.1
CVE-2026-95386TTL file parser infinite loop in 4.6.0 to 4.6.8 allows denial of service0.1%보통5.5
CVE-2026-96418TIFF protocol dissector infinite loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service0.1%보통5.5
CVE-2026-89045zstd-jni versions 1.4.8-4 through 1.5.7-13 fail to validate negative length parameters in ZstdInputStreamNoFin…0.1%보통5.1
CVE-2026-81885radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's NE re…0.1%보통5.5
CVE-2026-6554libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction as a signed integer to implement loopi…0.1%보통5.5
CVE-2023-37366An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem Exynos 9810, Exyno…0.1%낮음2.8
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.