CWE-1333
High likelihoodInefficient Regular Expression Complexity
The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.
457 vulnerabilities with CWE-1333
CVE-2024-41655
HIGH
tf2-item-format 4.2.6-5.9.13 - Regular Expression Denial of Service via Crafted User Input
CVSS 7.5
CVE-2024-39317
MEDIUM
Wagtail 2.0-5.2.5, 6.0-6.0.5 - Denial of Service via parse_query_string Inefficient Regular Expression
CVSS 6.5
CVE-2024-3651
HIGH
kjd/idna < 3.7 - Denial of Service via Quadratic Complexity in idna.encode()
CVSS 7.5
CVE-2024-6434
LOW
Premium Addons for Elementor <4.10.35 - DoS
CVSS 3.1
CVE-2024-39316
MEDIUM
Rack 3.1.0-3.1.5 - Denial of Service via HTTP Accept Header Parsing
CVSS 6.5
CVE-2024-39249
HIGH
Async <= 2.6.4 and <= 3.2.5 - Denial of Service via Inefficient Regular Expression in autoInject
CVSS 7.5
CVE-2024-6038
HIGH
gaizhenbiao/chuanhuchatgpt - Regular Expression Denial of Service in filter_history Function
CVSS 7.5
CVE-2024-1493
MEDIUM
GitLab 9.2.0-16.11.4, 17.0.0-17.0.2, 17.1.0 - Denial of Service via Dependency File Link Processing
CVSS 6.5
CVE-2024-1963
MEDIUM
GitLab 8.4-16.10.6, 16.11-16.11.3, 17.0-17.0.1 - Regular Expression Denial of Service via Asana Integration
CVSS 6.5
CVE-2024-1736
MEDIUM
GitLab < 16.10.7, 16.11-16.11.4, 17.0-17.0.2 - Denial of Service via CI/CD Pipeline Editor
CVSS 6.5
CVE-2024-1495
MEDIUM
GitLab 13.1-16.10.6, 16.11-16.11.3, 17.0-17.0.1 - Denial of Service via Maliciously Crafted File
CVSS 6.5
CVE-2024-5552
HIGH
kubeflow/kubeflow < 1.9.0 - Unauthenticated Regular Expression Denial of Service via Email Validation
CVSS 7.5
CVE-2024-4148
HIGH
lunary 1.2.10 - Regular Expression Denial of Service
CVSS 7.5
CVE-2024-4067
MEDIUM
micromatch < 4.0.8 - Regular Expression Denial of Service via Greedy Pattern Matching
CVSS 5.3
CVE-2024-2651
MEDIUM
GitLab CE/EE <16.9.7-16.10.4-16.11.1 - DoS
CVSS 6.5
CVE-2024-28716
HIGH
OpenStack Storlets yoga-eom - Remote Code Execution via gateway.py
CVSS 7.5
CVE-2024-4056
HIGH
M-Files Server <24.4.13592.4, >23.11 - DoS
CVSS 7.5
CVE-2024-2829
HIGH
GitLab 12.5-16.9.5, 16.10-16.10.3, 16.11 - Denial of Service via FileFinder Wildcard Filter
CVSS 7.5
CVE-2024-22640
HIGH
TCPDF <=6.6.5 - Regular Expression Denial of Service via Crafted HTML Color
CVSS 7.5
CVE-2024-3772
MEDIUM
Pydantic < 1.10.13 and 2.0.0-2.4.0 - Denial of Service via Crafted Email String
CVSS 5.9
CVE-2024-22363
HIGH
SheetJS Community Edition <0.20.2 - DoS
CVSS 7.5
CVE-2024-21503
MEDIUM
black < 24.3.0 - Denial of Service via Inefficient Regular Expression in strings.py
CVSS 5.3
CVE-2024-28865
HIGH
django-wiki <0.10.1 - Info Disclosure
CVSS 7.5
CVE-2024-28864
LOW
SecureProps 1.2.0-1.2.1 - Info Disclosure
CVSS 2.6
CVE-2024-27351
MEDIUM
Django <3.2.25, <4.2.11, <5.0.3 - DoS
CVSS 5.3
Details
Vulnerabilities
457
Exploit Likelihood
High