c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a quer
In Spring Boot versions 3.0.0 - 3.0.6, 2.7.0 - 2.7.11, 2.6.0 - 2.6.14, 2.5.0 - 2.5.14 and older unsupported versions, th
pluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticat
fast-xml-parser is an open source, pure javascript xml parser. fast-xml-parser allows special characters in entity names
In JetBrains YouTrack before 2023.1.10518 a DoS attack was possible via Helpdesk forms
A denial-of-service vulnerability exists in Rockwell Automation FactoryTalk Transaction Manager. This vulnerability can
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
IBM Security Directory Suite VA 8.0.1 could allow an attacker to cause a denial of service due to uncontrolled resource
Vulnerability of system restart triggered by abnormal callbacks passed to APIs.Successful exploitation of this vulnerabi
Fortra Globalscape EFT versions before 8.1.0.16 suffer from a denial of service vulnerability, where a compressed messag
Yet Another Reverse Proxy (YARP) Denial of Service Vulnerability
Denial of Service in GitHub repository jgraph/drawio prior to 18.1.3.
AnyDesk 7.0.8 allows remote Denial of Service.
A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3.4), SIMATIC MV540 S (All versions < V3.3.4),
A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3.4), SIMATIC MV540 S (All versions < V3.3.4),
HTTP.sys Denial of Service Vulnerability
Windows CryptoAPI Denial of Service Vulnerability
An issue discovered in MikroTik Router v6.46.3 and earlier allows attacker to cause denial of service via misconfigurati
Controller DoS due to buffer overflow in the handling of a specially crafted message received by the controller. See Hon
Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy’s HTTP/2 codec may leak a header map and bookk
Hamba avro is a go lang encoder/decoder implementation of the avro codec specification. In affected versions a well-craf
The Rockwell Automation Kinetix 5700 DC Bus Power Supply Series A is vulnerable to CIP fuzzing. The new ENIP connectio
goproxy v1.1 was discovered to contain an issue which can lead to a Denial of service (DoS) via unspecified vectors.
A flaw was found in Keylime. Due to their blocking nature, the Keylime registrar is subject to a remote denial of servic
PTC’s KEPServerEX Versions 6.0 to 6.14.263 are vulnerable to being made to read a recursively defined object that leads
.NET Core and Visual Studio Denial of Service Vulnerability
.NET and Visual Studio Denial of Service Vulnerability
IBM TXSeries for Multiplatforms 8.1, 8.2, and 9.1 is vulnerable to a denial of service, caused by improper enforcement
An issue in the component /userRpm/NetworkCfgRpm of TP-Link TL-WR1041N V2 allows attackers to cause a Denial of Service
Control Channel in OpenVPN 2.4.7 and earlier allows remote attackers to cause a denial of service via crafted reset pack
An issue was discovered in function nl80211_send_chandef in rtl8812au v5.6.4.2 allows attackers to cause a denial of ser
memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP.
A remote unprivileged attacker can sent multiple packages to the LMS5xx to disrupt its availability through a TCP SYN-ba
AdGuard DNS before 2.2 allows remote attackers to cause a denial of service via malformed UDP packets.
libp2p is a networking stack and library modularized out of The IPFS Project, and bundled separately for other tools to
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Due to the misuse of `log.Fatalf`,
Array AG OS before 9.4.0.499 allows denial of service: remote attackers can cause system service processes to crash thro
go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node, can be made t
Processing an incomplete post-handshake message for a QUIC connection can cause a panic.
An issue was discovered in Qubo Smart Plug 10A version HSP02_01_01_14_SYSTEM-10A, allows attackers to cause a denial of
Windows TCP/IP Denial of Service Vulnerability
DHCP Server Service Denial of Service Vulnerability
Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the
Certain WithSecure products allow a remote crash of a scanning engine via unpacking of crafted data files. This affects
Certain WithSecure products allow a remote crash of a scanning engine via decompression of crafted data files. This affe
Certain WithSecure products allow a remote crash of a scanning engine via processing of a compressed file. This affects
Certain WithSecure products allow a remote crash of a scanning engine via processing of an import struct in a PE file. T
Certain WithSecure products allow a remote crash of a scanning engine via unpacking of a PE file. This affects WithSecur
plone.rest allows users to use HTTP verbs such as GET, POST, PUT, DELETE, etc. in Plone. Starting in the 2.x branch and
Certain WithSecure products allow Denial of Service via the aepack archive unpack handler. This affects WithSecure Clien
Frequently Asked Questions
What is CWE-400?
CWE-400 (CWE-400) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-400?
There are 3,937 CVE records associated with CWE-400 in our database. Of these, 58 are critical severity, 1666 are high severity, and 1500 are medium severity.
How can I protect against CWE-400 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-400 using AI-powered security agents.
Detect CWE-400 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-400 vulnerabilities across your infrastructure.
Get Started