go-libp2p is the offical libp2p implementation in the Go programming language. Version `0.18.0` and older of go-libp2p a
Certain HP PageWide Pro Printers may be vulnerable to a potential denial of service attack.
A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3.21.7, 3
A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in protobuf-java core and lite versions prior
Certain HP ENVY, OfficeJet, and DeskJet printers may be vulnerable to a Denial of Service attack.
A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versi
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) is unresponsive w
The ProfileSDK has defects introduced in the design process. Successful exploitation of this vulnerability may affect sy
is.js is a general-purpose check library. Versions 0.9.0 and prior contain one or more regular expressions that are vuln
An issue discovered in Python Charmers Future 0.18.2 and earlier allows remote attackers to cause a denial of service vi
The hash functionality in userver before 42059b6319661583b3080cab9b595d4f8ac48128 allows attackers to cause a denial of
Denial of Service in GitHub repository usememos/memos prior to 0.9.1.
Due to support of Gzip compression in request bodies, as well as a lack of limiting response body sizes, a malicious ser
Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory.
Hawk is an HTTP authentication scheme providing mechanisms for making authenticated HTTP requests with partial cryptogra
A malformed Class 3 common industrial protocol message with a cached connection can cause a denial-of-service condition
Improper validation of LLM utility timers availability can lead to denial of service in Snapdragon Auto, Snapdragon Comp
Z-Wave devices based on Silicon Labs 500 series chipsets using S0 authentication are susceptible to uncontrolled resourc
Z-Wave devices based on Silicon Labs 500 series chipsets using S2, including but likely not limited to the ZooZ ZST10 ve
An Uncontrolled Resource Consumption vulnerability in the handling of IPv6 neighbor state change events in Juniper Netwo
graphql-go is a GraphQL server with a focus on ease of use. In versions prior to 1.3.0 there exists a DoS vulnerability
On BIG-IP version 16.1.x before 16.1.2.1, 15.1.x before 15.1.5, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 1
Tensorflow is an Open Source Machine Learning Framework. During shape inference, TensorFlow can allocate a large vector
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulne
A Denial of Service (DoS) vulnerability in the processing of a flood of specific ARP traffic in Juniper Networks Junos O
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.
A vulnerability has been identified in SIMATIC CP 442-1 RNA (All versions < V1.5.18), SIMATIC CP 443-1 RNA (All versions
Argo CD is a declarative continuous deployment for Kubernetes. Argo CD versions v0.7.0 and later are vulnerable to an un
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at
In versions 2.x before 2.3.1 and all versions of 1.x, when NGINX Instance Manager is in use, undisclosed requests can ca
PNGDec commit 8abf6be was discovered to contain a FPE via SaveBMP at /linux/main.cpp.
MaxQueryDuration not honoured in Samba AD DC LDAP
A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancill
Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. Fuzz testing, provided b
Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the pa
A business logic issue in the handling of large repositories in all versions of GitLab CE/EE from 10.0 before 15.1.6, al
In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, 14.1.x before 14.1.5.1, and all
Libde265 v1.0.8 was discovered to contain an unknown crash via ff_hevc_put_hevc_qpel_h_3_v_3_sse in sse-motion.cc. This
Synapse before 1.52.0 with URL preview functionality enabled will attempt to generate URL previews for media stream URLs
If a website called `window.print()` in a particular way, it could cause a denial of service of the browser, which may p
Brave Browser before 1.43.34 allowed a remote attacker to cause a denial of service via a crafted HTML file that mention
Brave Browser before 1.43.88 allowed a remote attacker to cause a denial of service in private and guest windows via a c
There is a denial of service vulnerability in the Wi-Fi module of the HUAWEI WS7100-20 Smart WiFi Router.Successful expl
In OpenShift Container Platform, a user with permissions to create or modify Routes can craft a payload that inserts a m
Azure Site Recovery Denial of Service Vulnerability
Denial of service in multimedia due to uncontrolled resource consumption while parsing an incoming HAB message in Snapdr
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in CAA to cause a
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in the AIX kernel
The affected product is vulnerable to a network-based attack by threat actors sending unimpeded requests to the receivin
Frequently Asked Questions
What is CWE-400?
CWE-400 (CWE-400) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-400?
There are 3,937 CVE records associated with CWE-400 in our database. Of these, 58 are critical severity, 1666 are high severity, and 1500 are medium severity.
How can I protect against CWE-400 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-400 using AI-powered security agents.
Detect CWE-400 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-400 vulnerabilities across your infrastructure.
Get Started