A vulnerability in the TCP/IP traffic handling function of the Snort Detection Engine of Cisco Firepower Threat Defense
A vulnerability in the local interface of Cisco BroadWorks Network Server could allow an unauthenticated, remote attacke
Altair is a fork of Misskey v12. Affected versions lack of request validation and lack of authentication in the image pr
In the Linux kernel, the following vulnerability has been resolved: cpufreq: CPPC: Fix potential memleak in cppc_cpufre
In the Linux kernel, the following vulnerability has been resolved: net: marvell: prestera: fix port event handling on
In the Linux kernel, the following vulnerability has been resolved: wifi: carl9170: re-fix fortified-memset warning Th
A vulnerability was discovered in Samsung Mobile Processor, Wearable Processor, and Modems with versions Exynos 9820, Ex
In the Linux kernel, the following vulnerability has been resolved: net: Only allow init netns to set default tcp cong
In the Linux kernel, the following vulnerability has been resolved: jfs: fix slab-out-of-bounds Read in dtSearch Curre
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 16.7.6 and iPadOS 16.7
In the Linux kernel, the following vulnerability has been resolved: lan966x: Fix crash when adding interface under a la
In the Linux kernel, the following vulnerability has been resolved: KVM: Always flush async #PF workqueue when vCPU is
In the Linux kernel, the following vulnerability has been resolved: bcachefs: Check for journal entries overruning end
Apport does not disable python crash handler before entering chroot
In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: wcd938x: fix incorrect used of portid
In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: fix list corruption from reorder of WRI
In the Linux kernel, the following vulnerability has been resolved: drm/i915/hwmon: Get rid of devm When both hwmon an
An issue was discovered in O-RAN Software Community ric-plt-e2mgr in the G-Release environment, allows remote attackers
A Denial of Service vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause unbounded
A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container that, when configur
An issue was discovered in open5gs v2.6.6. SIGPIPE can be used to crash AMF.
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs+0x4ec508 component.
encoded_id-rails versions before 1.0.0.beta2 are affected by an uncontrolled resource consumption vulnerability. A remot
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user able to
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
.NET Denial of Service Vulnerability
Cloud Foundry routing release versions from v0.163.0 to v0.283.0 are vulnerable to a DOS attack. An unauthenticated att
Drupal contains a vulnerability with improper handling of structural elements. If this vulnerability is exploited, an at
launchAnyWhere vulnerability in the ActivityManagerService module. Successful exploitation of this vulnerability will af
Denial of Service (DoS) vulnerability in the DMS module. Successful exploitation of this vulnerability will affect avail
This High severity DoS (Denial of Service) vulnerability was introduced in version 5.6.0 of Confluence Data Center and S
An issue was discovered in Mbed TLS 3.5.1. There is persistent handshake denial if a client sends a TLS 1.3 ClientHello
In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security V
libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in th
`python-multipart` is a streaming multipart parser for Python. When using form data, `python-multipart` uses a Regular E
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing
The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Denial of Service in all version
An unauthenticated remote attacker can use an uncontrolled resource consumption vulnerability to DoS the affected device
Windows DNS Client Denial of Service Vulnerability
.NET Denial of Service Vulnerability
mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server that imp
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote atta
Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality.
A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protoco
Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. P
In Srelay (the SOCKS proxy and Relay) v.0.4.8p3, a specially crafted network payload can trigger a denial of service con
An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. An attacker can constr
An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. When processing the AS
Frequently Asked Questions
What is CWE-400?
CWE-400 (CWE-400) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-400?
There are 3,937 CVE records associated with CWE-400 in our database. Of these, 58 are critical severity, 1666 are high severity, and 1500 are medium severity.
How can I protect against CWE-400 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-400 using AI-powered security agents.
Detect CWE-400 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-400 vulnerabilities across your infrastructure.
Get Started