CWE-407

Low likelihood

Inefficient Algorithmic Complexity

Parent: CWE-405 - Asymmetric Resource Consumption (Amplification)

An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.

90 vulnerabilities with CWE-407
CVE-2023-22484 LOW
cmark-gfm < 0.29.0.gfm.7 - Denial of Service via Polynomial Time Complexity Issue
CVSS 3.5
CVE-2023-22483 LOW
cmark-gfm < 0.29.0.gfm.7 - Denial of Service via Polynomial Time Complexity Issues
CVSS 3.5
CVE-2022-36021 MEDIUM
Redis <6.0.18, <6.2.11, <7.0.9 - DoS
CVSS 5.5
CVE-2022-45061 HIGH
Python < 3.11.1 - Denial of Service via IDNA Decoder Quadratic Algorithm
CVSS 7.5
CVE-2022-40188 HIGH
Knot Resolver < 5.5.3 - Denial of Service via Algorithmic Complexity
CVSS 7.5
CVE-2022-39209 HIGH
cmark-gfm < 0.29.0.gfm.6 - Denial of Service via Autolink Extension
CVSS 7.5
CVE-2022-22153 HIGH
Juniper Networks Junos OS - Info Disclosure
CVSS 7.5
CVE-2021-41168 MEDIUM
reddit/snudown < 1.7.0 - Denial of Service via Reference Table Hash Collision
CVSS 6.5
CVE-2021-33582 HIGH
Cyrus IMAP < 3.0.16 - Denial of Service via Hash Table Collision
CVSS 7.5
CVE-2020-3548 MEDIUM
Cisco Email Security Appliance < 13.5.1-277 - Unauthenticated Denial of Service via TLS Packet Processing
CVSS 5.3
CVE-2020-27223 MEDIUM
Eclipse Jetty 9.4.6-9.4.36, 10.0.0, 11.0.0 - Denial of Service via Multiple Accept Headers with Quality Parameters
CVSS 5.2
CVE-2019-19331 HIGH
knot_resolver < 4.3.0 - Denial of Service via Inefficient DNS Resource Record Processing
CVSS 7.5
CVE-2018-12558 HIGH
Email::Address < 1.909 - Denial of Service via Algorithmic Complexity in parse() Method
CVSS 7.5
CVE-2017-11343 HIGH
CHICKEN Scheme <4.12.0 - Info Disclosure
CVSS 7.5
CVE-2016-10396 HIGH
ipsec-tools 0.8.2 - Denial of Service via ISAKMP Fragment Reassembly
CVSS 7.5
Details
Vulnerabilities 90
Exploit Likelihood Low