Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally
In validateIpConfiguration of WifiConfigurationUtil.java, there is a possible way to trigger a permanent DoS due to a mi
In setupAccessibilityServices of AccessibilityFragment.java , there is a possible way to hide an enabled accessibility s
An issue was discovered in the NDIS Usermode IO driver (RtkIOAC60.sys, version 6.0.5600.16348) allowing local authentica
A vulnerability in an AOS firmware binary allows an authenticated malicious actor to permanently delete necessary boot i
A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some
Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacke
An issue was discovered in O-RAN Near Realtime RIC H-Release. To trigger the crashing of the e2mgr, an adversary must fl
A vulnerability was found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750
A Developer persona can bring down the Authorino service, preventing the evaluation of all AuthPolicies on the cluster
A vulnerability was found in HobbesOSR Kitten up to c4f8b7c3158983d1020af432be1b417b28686736 and classified as critical.
An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __
Uncontrolled resource consumption in Windows Print Spooler Components allows an authorized attacker to deny service over
Uncontrolled resource consumption for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge
An issue in Open Network Foundation ONOS v2.7.0 allows attackers to cause a Denial of Service (DoS) via supplying crafte
Worker process denial of service through file read operation. .A vulnerability exists in the Master's “pub_ret” method w
Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which mea
In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible way to crash the emergency callback mode due to
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, m
An issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module, Topolo
An issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module and Lin
Netty, an asynchronous, event-driven network application framework, has a vulnerability in versions up to and including
The issue was addressed with improved checks. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15,
An uncontrolled format string issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 1
A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, ma
An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the function consume_event.
An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the cfl_list_size in cfl_list.h:
A vulnerability in the kernel of the Cray Operating System (COS) could allow an attacker to perform a local Denial of Se
NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it a
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS
The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequ
The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7
Uncontrolled resource consumption for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an aut
VMware ESXi, Workstation, and Fusion contain a denial-of-service vulnerability due to certain guest options. A malicious
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. An app may be able to
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected a
In multiple locations, there is a possible crash loop due to resource exhaustion. This could lead to local denial of ser
In multiple locations, there is a possible permanent denial of service due to resource exhaustion. This could lead to lo
In allowPackageAccess of multiple files, resource exhaustion is possible when repeatedly adding allowed packages. This c
In multiple functions of AccountManagerService.java, there is a possible permanent denial of service due to resource exh
A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7 and iPadOS 18.7, macOS
NVIDIA Jetson Linux and IGX OS contain a vulnerability in NvMap, where improper tracking of memory allocations could all
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affecte
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are
The GameDriverX64.sys kernel-mode anti-cheat driver (v7.23.4.7 and earlier) contains an access control vulnerability in
If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding env
An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c whe
Uncontrolled resource consumption for some Gaudi software before version 1.21.0 within Ring 3: User Applications may all
When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file
In updateNotificationChannelGroupFromPrivilegedListener of NotificationManagerService.java, there is a possible permanen
Frequently Asked Questions
What is CWE-400?
CWE-400 (CWE-400) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-400?
There are 3,937 CVE records associated with CWE-400 in our database. Of these, 58 are critical severity, 1666 are high severity, and 1500 are medium severity.
How can I protect against CWE-400 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-400 using AI-powered security agents.
Detect CWE-400 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-400 vulnerabilities across your infrastructure.
Get Started