CWE-834: CWE-834

15
Total CVEs
0
Critical
12
High
7.2
Avg CVSS

Yearly Trend

2026
1
2025
4
2024
2
2023
3
2021
5

Top Affected Vendors

1 Apache 2
2 Pypdf Project 2
3 Wireshark 2
4 Pomerium 1
5 Phpseclib 1
6 Fedoraproject 1
7 Eclipse 1
8 Envoyproxy 1
9 Progress 1
10 Netapp 1

All CWE-834 CVEs (15)

CVE-2025-62707
7.5

CVE-2025-62707 is a denial-of-service vulnerability in pypdf, a popular Python PDF library. Attackers can craft malicious PDFs with inline images usin...

Oct 22, 2025
CVE-2025-56571
7.5

Finance.js v4.1.0 contains a Denial of Service vulnerability in its IRR function where improper handling of the depth parameter can cause excessive CP...

Sep 30, 2025
CVE-2024-4227
7.5

This vulnerability in Genivia gSOAP allows unauthenticated remote attackers to cause a denial of service by sending specially crafted XML with duplica...

Jan 15, 2025
CVE-2024-0842
7.5

The Backuply WordPress plugin is vulnerable to Denial of Service attacks in versions up to 1.2.5. Unauthenticated attackers can directly access the re...

Feb 9, 2024
CVE-2023-49316
7.5

This vulnerability in phpseclib 3 allows attackers to cause denial of service by providing excessively large degree values to BinaryField.php. It affe...

Nov 27, 2023
CVE-2023-5632
7.5

This vulnerability in Eclipse Mosquitto allows denial-of-service attacks by establishing connections without sending data, causing excessive CPU consu...

Oct 18, 2023
CVE-2023-26513
7.5

CVE-2023-26513 is an excessive iteration vulnerability in Apache Sling Resource Merger that allows attackers to cause denial of service through resour...

Mar 20, 2023
CVE-2021-4190
7.5

This vulnerability in Wireshark's Kafka dissector allows attackers to cause a denial of service by triggering an infinite loop when processing special...

Dec 30, 2021
CVE-2021-39923
7.5

A denial-of-service vulnerability in Wireshark's PNRP dissector allows attackers to crash the application by processing specially crafted network pack...

Nov 19, 2021
CVE-2021-39204
7.5

This CVE describes a denial-of-service vulnerability in Envoy's HTTP/2 stream reset handling that affects Pomerium identity-aware access proxies. Atta...

Sep 9, 2021
CVE-2021-35515
7.5

CVE-2021-35515 is a denial-of-service vulnerability in Apache Commons Compress's 7Z archive handling. When processing a specially crafted 7Z file, the...

Jul 13, 2021
CVE-2021-3125
7.5

This CVE describes an IPv6 routing loop vulnerability in multiple TP-Link router models. When IPv6 is enabled and specific routing conditions occur, a...

Apr 12, 2021
CVE-2024-8049
6.5

This vulnerability in Progress Telerik Document Processing Libraries allows attackers to cause denial of service by submitting specially crafted docum...

Nov 13, 2024
CVE-2026-27025
5.5

This vulnerability in pypdf allows attackers to craft malicious PDF files that cause excessive memory consumption and long processing times when parsi...

Feb 20, 2026
CVE-2025-55181
5.3

This vulnerability in Proxygen's HTTPQuicCoroSession allows an attacker to trigger an infinite loop and unbounded memory growth by sending HTTP reques...

Dec 2, 2025

About CWE-834 (CWE-834)

Our database tracks 15 CVEs classified as CWE-834, with 0 rated critical and 12 rated high severity. The average CVSS score for CWE-834 vulnerabilities is 7.2.

External reference: View CWE-834 on MITRE CWE →

Monitor CWE-834 Vulnerabilities

Get alerted when new CWE-834 CVEs affect your infrastructure.

Start Monitoring Free