An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to
Knative Serving builds on Kubernetes to support deploying and serving of applications and functions as serverless contai
Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import data
Grails is a framework used to build web applications with the Groovy programming language. A specially crafted web reque
cmark-gfm is an extended version of the C reference implementation of CommonMark, a rationalized version of Markdown syn
Memory exhaustion in the Kafka protocol dissector in Wireshark 4.0.0 to 4.0.1 and 3.6.0 to 3.6.9 allows denial of servic
RPCoRDMA dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection o
GQUIC dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or c
In Splunk Enterprise versions lower than 9.0.6 and 8.2.12, a malicious actor can send a malformed security assertion mar
MooTools is a collection of JavaScript utilities for JavaScript developers. All known versions include a CSS selector pa
A denial-of-service vulnerability has been identified in Lenovo Safecenter that could allow a local user to crash the ap
crossplane-runtime is a set of go libraries used to build Kubernetes controllers in Crossplane and its related stacks. I
FastAsyncWorldEdit (FAWE) is designed for efficient world editing. This vulnerability enables the attacker to select a r
A flaw was found in the subsequent get_user_pages_fast in the Linux kernel’s interface for symmetric key cipher algorith
IBM AIX's 7.3 Python implementation could allow a non-privileged local user to exploit a vulnerability to cause a denial
Visual Studio Denial of Service Vulnerability
Kyverno is a policy engine designed for Kubernetes. A security vulnerability was found in Kyverno where an attacker coul
go-unixfs is an implementation of a unix-like filesystem on top of an ipld merkledag. Trying to read malformed HAMT shar
github.com/ipfs/go-unixfsnode is an ADL IPLD prime node that wraps go-codec-dagpb's implementation of protobuf to enable
crossplane-runtime is a set of go libraries used to build Kubernetes controllers in Crossplane and its related stacks. A
Unpoly is a JavaScript framework for server-side web applications. There is a possible Denial of Service (DoS) vulnerabi
In Cloud foundry routing release versions from 0.262.0 and prior to 0.266.0,a bug in the gorouter process can lead to a
A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for reso
JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU, memory, and disk I/O utilization. Prep
DoS of the OkHttp client when using a BrotliInterceptor and surfing to a malicious web server, or when an attacker can p
IBM WebSphere Application Server Liberty 22.0.0.13 through 23.0.0.7 is vulnerable to a denial of service, caused by send
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, 11.5 is vulnerable to denial of service un
An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 befor
A vulnerability in the Vector Packet Processor (VPP) of Cisco Packet Data Network Gateway (PGW) could allow an unauthent
A denial of service condition exists in the Prometheus server bundled with GitLab affecting all versions from 11.10 to 1
A vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote a
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible t
Nextcloud server is an open source home cloud implementation. In releases of the 25.0.x branch before 25.0.3 an ineffici
A hash collision flaw was found in the IPv6 connection lookup table in the Linux kernel’s IPv6 functionality when a user
In several functions of SettingsState.java, there is a possible system crash loop due to resource exhaustion. This could
In setMimeGroup of PackageManagerService.java, there is a possible crash loop due to resource exhaustion. This could lea
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
In log service, there is a missing permission check. This could lead to local denial of service in log service.
In log service, there is a missing permission check. This could lead to local denial of service in log service.
In log service, there is a missing permission check. This could lead to local denial of service in log service.
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
In addAutomaticZenRule of ZenModeHelper.java, there is a possible persistent denial of service due to resource exhaustio
Windows Secure Channel Denial of Service Vulnerability
In add of WifiNetworkSuggestionsManager.java, there is a possible way to trigger permanent DoS due to resource exhaustio
In addNetwork of WifiManager.java, there is a possible way to trigger a persistent DoS due to resource exhaustion. This
An issue found in Eteran edb-debugger v.1.3.0 allows a local attacker to causea denial of service via the collect_symbol
An issue found in Ego Studio SuperClean v.1.1.9 and v.1.1.5 allows an attacker to gain privileges cause a denial of serv
Jerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component ecma_find_named_property
Jerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component build/bin/jerry.
IBM MQ Clients 9.2 CD, 9.3 CD, and 9.3 LTS are vulnerable to a denial of service attack when processing configuration fi
Frequently Asked Questions
What is CWE-400?
CWE-400 (CWE-400) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-400?
There are 3,937 CVE records associated with CWE-400 in our database. Of these, 58 are critical severity, 1666 are high severity, and 1500 are medium severity.
How can I protect against CWE-400 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-400 using AI-powered security agents.
Detect CWE-400 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-400 vulnerabilities across your infrastructure.
Get Started