Uncontrolled resource consumption in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow a
In the Linux kernel, the following vulnerability has been resolved: tracing: Restructure trace_clock_global() to never
Jerryscript commit cefd391 was discovered to contain a segmentation violation via the component scanner_seek at jerry-co
An issue discovered in httpd in ASUS RT-AC51U with firmware version up to and including 3.0.0.4.380.8591 allows local at
In multiple functions of SnoozeHelper.java, there is a possible persistent denial of service due to resource exhaustion.
In multiple functions of AppOpsService.java, there is a possible way to saturate the content of /data/system/appops_acce
In the Linux kernel, the following vulnerability has been resolved: pipe: wakeup wr_wait after setting max_usage Commi
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Prevent crash when disable stream
In the Linux kernel, the following vulnerability has been resolved: net: ipv4: fix memory leak in ip_mc_add1_src BUG:
there is a possible persistent Denial of Service due to test/debugging code left in a production build. This could lead
Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.6.0 allows local attackers to cause a Windows blue sc
Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.5.1 allows local attackers to cause a Windows blue screen
A vulnerability was found in OpenJPEG similar to CVE-2019-6988. This flaw allows an attacker to bypass existing protecti
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a
An issue in Huawei Technologies opengauss (openGauss 5.0.0 build) v.7.3.0 allows a local attacker to cause a denial of s
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15, macOS
A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15, macO
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15, macOS Sono
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadO
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 17.7 and iPadOS 17
A logic error was addressed with improved error handling. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iP
gnark is a fast zk-SNARK library that offers a high-level API to design circuits. In gnark 0.11.0 and earlier, deseriali
Vulnerability of processes not being fully terminated in the VPN module Impact: Successful exploitation of this vulnerab
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performan
In removeUnsynchronization of ID3.cpp there is a possible resource exhaustion due to improper input validation. This cou
In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image
A vulnerability was found in JWCrypto. This flaw allows an attacker to cause a denial of service (DoS) attack and possib
Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Collapse of Data into
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions
A vulnerability in system resource management in Cisco UCS 6400 and 6500 Series Fabric Interconnects that are in Intersi
An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Spectrum service accessed via the PAPI protocol
Discourse is an open source platform for community discussion. Without a rate limit on the POST /uploads endpoint, it ma
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumptio
Bref is an open-source project that helps users go serverless on Amazon Web Services with PHP. When Bref prior to versio
Certain HP OfficeJet Pro printers are potentially vulnerable to a Denial of Service when using an improper eSCL URL GET
The Mojolicious module before 7.66 for Perl may leak cookies in certain situations related to multiple similar cookies f
A vulnerability exists in the affected product that allows a malicious user to restart the Rockwell Automation PanelVie
oidcc is the OpenID Connect client library for Erlang. Denial of Service (DoS) by Atom exhaustion is possible by calling
python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a cra
An issue in Open5GS v.2.7.0 allows an attacker to cause a denial of service via the 64 unsuccessful UE/gnb registration
A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC
REXML is an XML toolkit for Ruby. The REXML gem before 3.2.6 has a denial of service vulnerability when it parses an XM
Minder is a software supply chain security platform. Prior to version 0.0.49, the Minder REST ingester is vulnerable to
Minder is a software supply chain security platform. Prior to version 0.0.50, Minder engine is susceptible to a denial o
SoftEtherVPN is a an open-source cross-platform multi-protocol VPN Program. When SoftEtherVPN is deployed with L2TP enab
An issue was discovered in GitLab CE/EE affecting all versions starting from 12.0 prior to 16.11.5, starting from 17.0 p
Windows iSCSI Service Denial of Service Vulnerability
REXML is an XML toolkit for Ruby. The REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has
REXML is an XML toolkit for Ruby. The REXML gem 3.3.2 has a DoS vulnerability when it parses an XML that has many entity
Frequently Asked Questions
What is CWE-400?
CWE-400 (CWE-400) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-400?
There are 3,937 CVE records associated with CWE-400 in our database. Of these, 58 are critical severity, 1666 are high severity, and 1500 are medium severity.
How can I protect against CWE-400 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-400 using AI-powered security agents.
Detect CWE-400 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-400 vulnerabilities across your infrastructure.
Get Started