CWE-407

Low likelihood

Inefficient Algorithmic Complexity

Parent: CWE-405 - Asymmetric Resource Consumption (Amplification)

An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.

124 vulnerabilities with CWE-407
CVE-2025-64458 HIGH
Django 4.2-4.2.25, 5.1-5.1.13, 5.2-5.2.7 - Denial of Service via NFKC Unicode Normalization
CVSS 7.5
CVE-2025-58187 HIGH
Certificate Validation - Info Disclosure
CVSS 7.5
CVE-2025-62727 HIGH
Starlette 0.39.0-0.49.0 - Unauthenticated Denial of Service via HTTP Range Header
CVSS 7.5
CVE-2025-55304 MEDIUM
Exiv2 < 0.28.6 - Denial of Service via Crafted JPEG ICC Profile
CVSS 5.5
CVE-2025-27209 HIGH
Node.js 24.0.0-24.4.0 - Denial of Service via Hash Collision in String Hashing
CVSS 7.5
CVE-2025-29908 MEDIUM
Netty QUIC codec <0.0.71. Final - Hash DoS
CVSS 5.3
CVE-2025-30348 MEDIUM
Qt < 5.15.19 - Inefficient Algorithmic Complexity in QDom encodeText
CVSS 5.8
CVE-2025-24947 MEDIUM
LSQUIC < 4.2.0 - Denial of Service via Hash Collision in Connection ID Hash Table
CVSS 5.3
CVE-2025-24946 MEDIUM
picoquic < b80fd3f5903279ae3e7714ee4109363d9ab4491a - Denial of Service via Hash Table Collision
CVSS 5.3
CVE-2025-23020 MEDIUM
Kwik < 0.10.1 - Denial of Service via Hash Collision in Connection ID Management
CVSS 5.3
CVE-2024-12243 MEDIUM
GnuTLS - Denial of Service
CVSS 5.3
CVE-2024-12133 MEDIUM
libtasn1 - Denial of Service
CVSS 5.3
CVE-2024-9631 HIGH
GitLab CE/EE <17.2.9-17.4.2 - Info Disclosure
CVSS 7.5
CVE-2024-6324 MEDIUM
GitLab 15.7-17.5.4, 17.6-17.6.2, 17.7 - Denial of Service via Cyclic Epic References
CVSS 4.3
CVE-2024-8233 HIGH
GitLab 9.4.0-17.4.5, 17.5.0-17.5.3, 17.6.0-17.6.1 - Denial of Service via Diff File Requests
CVSS 7.5
CVE-2024-8237 MEDIUM
GitLab CE/EE <12.6-17.4.5, <17.5-17.5.3, <17.6-17.6.1 - DoS
CVSS 6.5
CVE-2024-8177 MEDIUM
GitLab CE/EE <17.4.5/<17.5.3/<17.6.1 - DoS
CVSS 5.3
CVE-2024-11828 MEDIUM
GitLab 13.2.4-17.4.4, 17.5-17.5.2, 17.6-17.6.0 - Denial of Service via Crafted API Calls
CVSS 4.3
CVE-2024-43485 HIGH
.NET 6.0.0-6.0.34 and Visual Studio 2022 17.6.0-17.6.19 - Denial of Service
CVSS 7.5
CVE-2024-43484 HIGH
.NET Framework - Denial of Service via Inefficient Algorithmic Complexity
CVSS 7.5
CVE-2024-43483 HIGH
.NET Framework - Denial of Service via Inefficient Algorithmic Complexity
CVSS 7.5
CVE-2024-39702 MEDIUM
OpenResty 1.19.3.1-1.25.3.1 - Denial of Service via HashDoS in String Hashing Function
CVSS 5.9
CVE-2024-29916 MEDIUM
dormakaba Saflok - Unauthenticated Door Unlock via Forged Keycard
CVSS 5.6
CVE-2024-23684 HIGH
peteroupc/cbor 4.0.0-4.5.1 - Denial of Service via DecodeFromBytes Function
CVSS 7.5
CVE-2024-21909 HIGH
PeterO.Cbor 4.0.0-4.5.0 - Denial of Service via Crafted DecodeFromBytes Input
CVSS 7.5
Details
Vulnerabilities 124
Exploit Likelihood Low