In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when a BIG-IP APM access poli
In BIG-IP Versions 16.1.x before 16.1.2.2, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when an HTTP2 profile is co
When a POST request comes through AJP and the request exceeds the max-post-size limit (maxEntitySize), Undertow's AjpSer
Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability
Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability
In Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause the Varnish Server to assert and automatically
A flaw was found in OpenEXR's B44Compressor. This flaw allows an attacker who can submit a crafted file to be processed
A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This f
The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excess
There is a NULL pointer dereference vulnerability in VTK before 9.2.5, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. T
nitrado.js is a type safe wrapper for the Nitrado API. Possible ReDoS with lib input of `{{` and with many repetitions o
A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause o
AutomationDirect DirectLOGIC is vulnerable to a a specially crafted packet can be sent continuously to the PLC to preven
libvncclient v0.9.13 was discovered to contain a memory leak via the function rfbClientCleanup().
indy-node is the server portion of Hyperledger Indy, a distributed ledger purpose-built for decentralized identity. In v
The CMS800 device fails while attempting to parse malformed network data sent by a threat actor. A threat actor with net
.NET Core and Visual Studio Denial of Service Vulnerability
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior to 0
A denial-of-service issue was discovered in MediaWiki 1.37.x before 1.37.2. Rendering of w/index.php?title=Special%3AWha
A vulnerability exists in the ClearPass Policy Manager Guest User Interface that can allow an unauthenticated attacker t
This issue was addressed with improved checks. This issue is fixed in tvOS 15.5, watchOS 8.6, iOS 15.5 and iPadOS 15.5,
A vulnerability named 'Non-Responsive Delegation Attack' (NRDelegation Attack) has been discovered in various DNS resolv
In ambiot amb1_sdk (aka SDK for Ameba1) before 2022-06-20 on Realtek RTL8195AM devices before 284241d70308ff2519e40afd7b
sflow decode package does not employ sufficient packet sanitisation which can lead to a denial of service attack. Attack
A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All ver
Traefik (pronounced traffic) is a modern HTTP reverse proxy and load balancer that assists in deploying microservices. T
An issue in the fetch() method in the BasicProfile class of org.ini4j through version v0.5.4 allows attackers to cause a
Istio is an open platform-independent service mesh that provides traffic management, policy enforcement, and telemetry c
A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting
A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before before 15.2.5, all versions s
A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when
In versions 16.1.x before 16.1.3.2 and 15.1.x before 15.1.5.1, when BIG-IP AFM Network Address Translation policy with I
In all BIG-IP 13.1.x versions, when an iRule containing the HTTP::collect command is configured on a virtual server, und
Apache IoTDB version 0.12.2 to 0.12.6, 0.13.0 to 0.13.2 are vulnerable to a Denial of Service attack when accepting untr
strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a craft
conduit-hyper integrates a conduit application with the hyper server. Prior to version 0.4.2, `conduit-hyper` did not ch
The issue was addressed with improved memory handling. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and
A vulnerability in Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated remote
In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, sending a malformed file through the Splunk-to-Splunk (S2S
Pillow before 9.3.0 allows denial of service via SAMPLESPERPIXEL.
The Diffie-Hellman Key Agreement Protocol allows use of long exponents that arguably make certain calculations unnecessa
A vulnerability in the processing of SSH connections of Cisco Firepower Management Center (FMC) and Cisco Firepower Thre
In Free5gc v3.0.5, the AMF breaks due to malformed NAS messages.
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible t
LINE client for iOS before 12.17.0 might be crashed by sharing an invalid shared key of e2ee in group chat.
A possible denial of service vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 in the multipart parsing compo
An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in vers
Uncontrolled resource consumption vulnerability in Cybozu Remote Service 4.0.0 to 4.0.3 allows a remote authenticated at
libp2p-rust is the official rust language Implementation of the libp2p networking stack. In versions prior to 0.45.1 an
js-libp2p is the official javascript Implementation of libp2p networking stack. Versions older than `v0.38.0` of js-libp
Frequently Asked Questions
What is CWE-400?
CWE-400 (CWE-400) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-400?
There are 3,937 CVE records associated with CWE-400 in our database. Of these, 58 are critical severity, 1666 are high severity, and 1500 are medium severity.
How can I protect against CWE-400 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-400 using AI-powered security agents.
Detect CWE-400 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-400 vulnerabilities across your infrastructure.
Get Started