In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Serv
In pushDynamicShortcut of ShortcutPackage.java, there is a possible way to get the device into a boot loop due to resour
A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the a
An issue found in edjing Mix v.7.09.01 for Android allows a local attacker to cause a denial of service via the database
Transient DOS due to uncontrolled resource consumption in Linux kernel when malformed messages are sent from the Gunyah
An issue found in CrossX v.1.15.3 for Android allows a local attacker to cause a persistent denial of service via the da
In Policy of Policy.java, there is a possible boot loop due to resource exhaustion. This could lead to local denial of s
ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::DiagScopeVariable
ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::ProfilingHelpers:
ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::EntryPointInfo::H
ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function BackwardPass::IsEmpty
A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (
Adobe XMP Toolkit versions 2022.06 is affected by a Uncontrolled Resource Consumption vulnerability. An unauthenticated
In setMediaButtonBroadcastReceiver of MediaSessionRecord.java, there is a possible permanent DoS due to resource exhaust
An issue was discovered in function zzip_disk_entry_to_file_header in mmapped.c in zziplib 0.13.69, which will lead to a
GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function load_s
Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.Thi
A flaw was found in GLib. GVariant deserialization fails to validate that the input conforms to the expected format, lea
A flaw was found in GLib. GVariant deserialization is vulnerable to a slowdown issue where a crafted GVariant can cause
A flaw was found in GLib. GVariant deserialization is vulnerable to an exponential blowup issue where a crafted GVariant
An issue was discovered in ImfHpRegFilter.sys in IOBit Malware Fighter version 8.0.2, allows local attackers to cause a
In nqptp-message-handlers.c in nqptp before 1.2.3, crafted packets received on the control port could crash the program.
In multiple locations, there is a possible way to crash multiple system services due to resource exhaustion. This could
A vulnerability was found in libX11 due to an infinite loop within the PutSubImage() function. This flaw allows a local
Denial of Service in GitHub repository gpac/gpac prior to 2.3.0-DEV.
Uncontrolled resource consumption in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated us
An issue in Free5gc v.3.3.0 allows a local attacker to cause a denial of service via the free5gc-compose component.
Bouncy Castle for Java before 1.73 contains a potential Denial of Service (DoS) issue within the Bouncy Castle org.bounc
notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry
For certain systems running EOS, a Precision Time Protocol (PTP) packet of a management/signaling message with an invali
Dell PowerScale nodes A200, A2000, H400, H500, H600, H5600, F800, F810 integrated hardware management software contains
comrak is a CommonMark + GFM compatible Markdown parser and renderer written in rust. A range of quadratic parsing issue
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. A polynomial time comp
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. A polynomial time comp
SAP NetWeaver AS for ABAP (Business Server Pages) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756,
Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Su
Jetty is a java based web server and servlet engine. In affected versions servlets with multipart support (e.g. annotate
Ribose RNP before 0.16.3 may hang when the input is malformed.
When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accelera
Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120
react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. Previous versions of React
Windows Hyper-V Denial of Service Vulnerability
A memory leak in the EFR32 Bluetooth LE stack 5.1.0 through 5.1.1 allows an attacker to send an invalid pairing message
Extremely large RSA keys in certificate chains can cause a client/server to expend significant CPU time verifying signat
Versions of the package graphql from 16.3.0 and before 16.8.1 are vulnerable to Denial of Service (DoS) due to insuffici
Versions of the package asyncua before 0.9.96 are vulnerable to Denial of Service (DoS) such that an attacker can send a
A flaw was found in Open Virtual Network where the service monitor MAC does not properly rate limit. This issue could al
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earl
OpenFGA is a flexible authorization/permission engine built for developers and inspired by Google Zanzibar. Affected ver
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS Sonoma 1
Frequently Asked Questions
What is CWE-400?
CWE-400 (CWE-400) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-400?
There are 3,937 CVE records associated with CWE-400 in our database. Of these, 58 are critical severity, 1666 are high severity, and 1500 are medium severity.
How can I protect against CWE-400 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-400 using AI-powered security agents.
Detect CWE-400 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-400 vulnerabilities across your infrastructure.
Get Started