Skip to main content

CWE archive

CWE-1333 CVEs

Programmatic archive

464 CVEs tagged with CWE-13335 Critical, 221 High, 200 Medium, 37 Low, 1 Unrated.

CVE-2024-26146

Published Feb 29, 2024

Rack is a modular Ruby web server interface. Carefully crafted headers can cause header parsing in Rack to take longer than expected resulting in a possible denial of service issu…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-25126

Published Feb 29, 2024

Rack is a modular Ruby web server interface. Carefully crafted content type headers can cause Rack’s media type parser to take much longer than expected, leading to a possible den…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1892

Published Feb 28, 2024

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the XMLFeedSpider class of the scrapy/scrapy project, specifically in the parsing of XML content. By craftin…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-26142

Published Feb 27, 2024

Rails is a web-application framework. Starting in version 7.1.0, there is a possible ReDoS vulnerability in the Accept header parsing routines of Action Dispatch. This vulnerabili…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-27088

Published Feb 26, 2024

es5-ext contains ECMAScript 5 extensions. Passing functions with very long names or complex default argument names into `function#copy` or `function#toStringTokens` may cause the…

CVSS 0.0 · Unrated
Vendor/product tagsBeta · best-effort

CVE-2023-51931

Published Feb 16, 2024

An issue in alanclarke URLite v.3.1.0 allows an attacker to cause a denial of service (DoS) via a crafted payload to the parsing function.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-4437

Published Feb 12, 2024

A vulnerability, which was classified as problematic, has been found in dbartholomae lambda-middleware frameguard up to 1.0.4. Affected by this issue is some unknown functionality…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-21490

Published Feb 10, 2024

This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0. A regular expression used to split the value of the ng-srcset directive is v…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-6736

Published Feb 7, 2024

An issue has been discovered in GitLab EE affecting all versions starting from 11.3 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 b…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6159

Published Jan 26, 2024

An issue has been discovered in GitLab CE/EE affecting all versions from 12.7 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 It was possible for an attacker to tr…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-23732

Published Jan 21, 2024

The JSON loader in Embedchain before 0.1.57 allows a ReDoS (regular expression denial of service) via a long string to json.py.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50249

Published Dec 20, 2023

Sentry-Javascript is official Sentry SDKs for JavaScript. A ReDoS (Regular expression Denial of Service) vulnerability has been identified in Sentry's Astro SDK 7.78.0-7.86.0. Und…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-48631

Published Dec 14, 2023

@adobe/css-tools versions 4.3.1 and earlier are affected by an Improper Input Validation vulnerability that could result in a denial of service while attempting to parse CSS.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45806

Published Nov 10, 2023

Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, if…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3909

Published Nov 6, 2023

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.3 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-39619

Published Oct 25, 2023

ReDos in NPMJS Node Email Check v.1.0.4 allows an attacker to cause a denial of service via a crafted string to the scpSyntax component.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-4316

Published Sep 28, 2023

Zod in versions 3.21.0 up to and including 3.22.3 allows an attacker to perform a denial of service while validating emails.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-43646

Published Sep 27, 2023

get-func-name is a module to retrieve a function's name securely and consistently both in NodeJS and the browser. Versions prior to 2.0.1 are subject to a regular expression denia…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-3210

Published Sep 1, 2023

An issue has been discovered in GitLab affecting all versions starting from 15.11 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 bef…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3205

Published Sep 1, 2023

An issue has been discovered in GitLab affecting all versions starting from 15.11 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 bef…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 251-275 of 464 CVEsPage 11 of 19