Jawn is an open source JSON parser. Extenders of the `org.typelevel.jawn.SimpleFacade` and `org.typelevel.jawn.MutableFa
Go Ethereum is the official Golang implementation of the Ethereum protocol. Prior to version 1.10.17, a vulnerable node,
A flaw was found in Undertow. A potential security issue in flow control handling by the browser over http/2 may potenti
Shescape is a shell escape package for JavaScript. An Inefficient Regular Expression Complexity vulnerability impacts us
dparse is a parser for Python dependency files. dparse in versions before 0.5.2 contain a regular expression that is vul
Uncontrolled resource consumption in the Intel(R) Support Android application before version 22.02.28 may allow an authe
A vulnerability exists in the ArubaOS bootloader on 7xxx series controllers which can result in a denial of service (DoS
containerd is an open source container runtime. A bug was found in containerd's CRI implementation where a user can exha
MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact
There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor
Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.
Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.
fscrypt through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged
Uncontrolled resource consumption in the Linux kernel drivers for Intel(R) SGX may allow an authenticated user to potent
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where uncontrolled resource consum
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implem
containerd is an open source container runtime. A bug was found in the containerd's CRI implementation where programs in
A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a u
A memory leak flaw was found in the Linux kernel's ccp_run_aes_gcm_cmd() function that allows an attacker to cause a den
A vulnerability was found in rizin. The bug involves an ELF64 binary for the HPPA architecture. When a specially crafted
A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segme
A flaw was found in Clmg, where with the help of a maliciously crafted pandore or bmp file with modified dx and dy heade
In LibRaw, there is a memory corruption vulnerability within the "crxFreeSubbandData()" function (libraw\src\decoders\cr
In Keylime before 6.3.0, quote responses from the agent can contain possibly untrusted ZIP data which can lead to zip bo
In addAutomaticZenRule of ZenModeHelper.java, there is a possible permanent degradation of performance due to resource e
In cell service, there is a missing permission check. This could lead to local denial of service in cell service with no
In music service, there is a missing permission check. This could lead to local denial of service in music service with
In messaging service, there is a missing permission check. This could lead to local denial of service in messaging servi
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial
systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long back
In createNotificationChannel of NotificationManager.java, there is a possible way to make the device unusable and requir
A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versi
markdown-it is a Markdown parser. Prior to version 1.3.2, special patterns with length greater than 50 thousand characte
Micronaut is a JVM-based, full stack Java framework designed for building JVM web applications with support for Java, Ko
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). S
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supp
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). S
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). S
On version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x, when the BI
In cloud foundry CAPI versions prior to 1.122, a denial-of-service attack in which a developer can push a service broker
The PROFINET (PNIO) stack, when integrated with the Interniche IP stack, improperly handles internal resources for TCP s
Wire-server is the system server for the wire back-end services. Releases prior to v2022-03-01 are subject to a denial o
On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6
Frequently Asked Questions
What is CWE-400?
CWE-400 (CWE-400) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-400?
There are 3,937 CVE records associated with CWE-400 in our database. Of these, 58 are critical severity, 1666 are high severity, and 1500 are medium severity.
How can I protect against CWE-400 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-400 using AI-powered security agents.
Detect CWE-400 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-400 vulnerabilities across your infrastructure.
Get Started