An Uncontrolled Resource Consumption vulnerability in the http daemon (httpd) of Juniper Networks Junos OS on SRX Series
Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Serv
Werkzeug is a Web Server Gateway Interface web application library. Applications using `werkzeug.formparser.MultiPartPar
By sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to
CWE-400: An Uncontrolled Resource Consumption vulnerability exists that could cause the device to become unresponsive re
A vulnerability in the PROFINET stack implementation of the IndraDrive (all versions) of Bosch Rexroth allows an attacke
Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in To
There exists a stack buffer overflow in libjxl. A specifically-crafted file can cause the JPEG XL decoder to use large a
Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines() method would not "pause" writing and signa
Windows Remote Desktop Services Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability
Uncontrolled Resource Consumption vulnerability in PlexTrac allows WebSocket DoS.This issue affects PlexTrac: from 1.61.
A DLL hijacking vulnerability in AMD μProf could allow an attacker to achieve privilege escalation, potentially resultin
An issue was discovered on certain Nuki Home Solutions devices. It is possible to send multiple BLE malformed packets to
In the Linux kernel, the following vulnerability has been resolved: enetc: Fix illegal access when reading affinity_hin
In the Linux kernel, the following vulnerability has been resolved: nexthop: Fix memory leaks in nexthop notification c
JWX is Go module implementing various JWx (JWA/JWE/JWK/JWS/JWT, otherwise known as JOSE) technologies. This vulnerabili
Uncontrolled resource consumption for some Intel(R) SPS firmware versions may allow a privileged user to potentially ena
An uncontrolled resource consumption vulnerability has been reported to affect several QNAP operating system versions. I
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: UDF). Supported versions that are affecte
Bref enable serverless PHP on AWS Lambda. When Bref is used with the Event-Driven Function runtime and the handler is a
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security V
IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.3 could allow an authenticated user to cau
The IBM Integration Bus for z/OS 10.1 through 10.1.0.2 AdminAPI is vulnerable to a denial of service due to file system
Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_DataBuffer::ReallocateBuffer() function.
Processing of user-defined DAV user-agent strings is not limited. Availability of OX App Suite could be reduced due to h
Processing time of drive search expressions now gets monitored, and the related request is terminated if a resource thre
Processing of user-defined mail search expressions is not limited. Availability of OX App Suite could be reduced due to
Uncontrolled Resource Consumption vulnerability in Honeywell Niagara Framework on Windows, Linux, QNX allows Content Spo
This is a duplicate for CVE-2023-46104. With correct CVE version ranges for affected Apache Superset. Uncontrolled res
Undici is an HTTP/1.1 client, written from scratch for Node.js. In affected versions calling `fetch(url)` and not consum
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a
The jose4j component before 0.9.4 for Java allows attackers to cause a denial of service (CPU consumption) via a large p
The issue was addressed with improved checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 1
Discourse is an open source platform for community discussion. In affected versions users that are allowed to invite oth
Discourse is an open source platform for community discussion. In affected versions the endpoints for suspending users,
Uncontrolled Resource Consumption vulnerability in David Artiss Code Embed.This issue affects Code Embed: from n/a throu
node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of ArgoCD starting from v2.4 have
Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, the safe_scrape_html function utilizes a user-c
Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, an attacker can point the image request to an a
No Limit on Number of Open Sessions / Bad Session Close Behaviour in dnf5daemon-server before 5.1.17 allows a malicious
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. There is a Denial of Service (DoS) vulnerabili
A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formWlanSetup_Wizard allows remote authe
Uncontrolled resource consumption vulnerability in White Bear Solutions WBSAirback, version 21.02.04. This vulnerability
DHCP Server Service Denial of Service Vulnerability
Kwik commit 745fd4e2 does not discard unused encryption keys.
Frequently Asked Questions
What is CWE-400?
CWE-400 (CWE-400) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-400?
There are 3,937 CVE records associated with CWE-400 in our database. Of these, 58 are critical severity, 1666 are high severity, and 1500 are medium severity.
How can I protect against CWE-400 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-400 using AI-powered security agents.
Detect CWE-400 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-400 vulnerabilities across your infrastructure.
Get Started