A regression was introduced in the Red Hat build of python-eventlet due to a change in the patch application strategy, r
Mattermost fails to properly sanitize the request to /api/v4/redirect_location allowing an attacker, sending a specially
A vulnerability of Uncontrolled Resource Consumption has been identified in STARDOM provided by Yokogawa Electric Corpor
lestrrat-go/jwx is a Go module implementing various JWx (JWA/JWE/JWK/JWS/JWT, otherwise known as JOSE) technologies. A p
The tokio-boring library in version 4.0.0 is affected by a memory leak issue that can lead to excessive resource consump
Uncontrolled Resource Consumption vulnerability in Saturday Drive Ninja Forms Contact Form – The Drag and Drop Form Buil
quiche v. 0.15.0 through 0.19.0 was discovered to be vulnerable to unbounded queuing of path validation messages, which
In parseUsesPermission of ParsingPackageUtils.java, there is a possible boot loop due to resource exhaustion. This could
Uncontrolled resource consumption in the Intel(R) Connect M Android application before version 1.82 may allow an authent
Uncontrolled resource consumption in the Intel(R) Smart Campus Android application before version 9.9 may allow an authe
Uncontrolled resource consumption in the Intel(R) Unite(R) android application before Release 17 may allow an authentica
An issue was discovered in Couchbase Server 7.x before 7.0.5 and 7.1.x before 7.1.2. A crafted HTTP REST request from an
Wagtail is an open source content management system built on Django. Prior to versions 4.1.4 and 4.2.2, a memory exhaust
Due to an error in the software interface to the secure element chip on Bosch IP cameras of family CPP13 and CPP14, the
IBM TXSeries for Multiplatforms, 8.1, 8.2, and 9.1, CICS TX Standard CICS TX Advanced 10.1 and 11.1 could allow a privil
RabbitMQ is a multi-protocol messaging and streaming broker. HTTP API did not enforce an HTTP request body limit, making
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes.
A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by add
Denial-of-service vulnerability in the web server of the Eaton SMP Gateway allows attacker to potentially force an une
A vulnerability in the packet processing functionality of Cisco access point (AP) software could allow an unauthenticate
An improper privilege management issue that could allow an attacker to cause a denial of service over the OTA mechanism
An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to co
In list_key_entries of utils.rs, there is a possible way to disable user credentials due to resource exhaustion. This co
A segmentation fault can occur in Brocade Fabric OS after Brocade Fabric OS v9.0 and before Brocade Fabric OS v9.2.0a
A vulnerability has been identified in SIMATIC CP 1604 (All versions), SIMATIC CP 1616 (All versions), SIMATIC CP 1623 (
A denial of service vulnerability was reported in the Lenovo HardwareScanPlugin versions prior to 1.3.1.2 and Len
A denial of service vulnerability was reported in the Lenovo HardwareScanPlugin versions prior to 1.3.1.2 and Len
An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.3 before 15.6.7, all versions start
An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 before 15.6.7, all versions start
Nextcloud is an Open Source private cloud software. Versions 25.0.0 and above, prior to 25.0.3, are subject to Uncontrol
An issue has been discovered in GitLab affecting all versions starting from 9.0 before 15.7.8, all versions starting fro
An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting fr
Mattermost fails to properly truncate the postgres error log message of a search query failure allowing an attacker to c
Mattermost fails to unescape Markdown strings in a memory-efficient way, allowing an attacker to cause a Denial of Servi
When adding an external mail account, processing of SMTP "capabilities" responses are not limited to plausible sizes. At
When adding an external mail account, processing of IMAP "capabilities" responses are not limited to plausible sizes. At
When adding an external mail account, processing of POP3 "capabilities" responses are not limited to plausible sizes. At
Mattermost Boards fail to properly validate a board link, allowing an attacker to crash a channel by posting a specially
Mattermost fails to properly validate markdown, allowing an attacker to crash the server via a specially crafted markdow
Mattermost fails to properly validate a gif image file, allowing an attacker to consume a significant amount of server r
An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user t
Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 o
Mattermost fails to enforce a limit for the size of the cache entry for OpenGraph data allowing an attacker to send a s
Mattermost fails to deduplicate input IDs allowing a simple user to cause the application to consume excessive resources
Nextcloud calendar is a calendar app for the Nextcloud server platform. Due to missing precondition checks the server wa
Mattermost Mobile fails to limit the maximum number of Markdown elements in a post allowing an attacker to send a post w
Connections to external data sources, like e-mail autoconfiguration, were not terminated in case they hit a timeout, ins
Mattermost fails to properly limit the characters allowed in different fields of a block in Mattermost Boards allowing a
Mattermost fails to limit the amount of data extracted from compressed archives during board import in Mattermost Boards
Mattermost fails to limit the log size of server logs allowing an attacker sending specially crafted requests to differe
Frequently Asked Questions
What is CWE-400?
CWE-400 (CWE-400) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-400?
There are 3,937 CVE records associated with CWE-400 in our database. Of these, 58 are critical severity, 1666 are high severity, and 1500 are medium severity.
How can I protect against CWE-400 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-400 using AI-powered security agents.
Detect CWE-400 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-400 vulnerabilities across your infrastructure.
Get Started