Uncontrolled Resource Consumption vulnerability in benoitc hackney allows Flooding. The SOCKS5 transport in src/hackney_
Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. The WebSocket cli
Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. hackney_h3:await_
Versions of the package pacote from 11.2.7 and before 21.5.1 are vulnerable to Denial of Service (DoS) via the addGitSha
bird-lg-go is a BIRD looking glass in Go. Prior to 1.4.5, the apiHandler (and similarly webHandlerTelegramBot) processes
Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affected are 24.2.0-26.1.
Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-2
Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-2
A vulnerability has been found in Shibby Tomato 1.28. The impacted element is an unknown function of the file usr/sbin/m
iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, the Avro array and map decoders looped over an attacker-contro
Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with Integer.MAX_VALUE as the maxi
React Router is a router for React. In versions 7.0.0 through 7.14.x of react-router and versions 2.10.0 through 2.17.4
Dräger Core 1.0.5 and Dräger M540 Converter Service 1.0.9 contain a denial of service vulnerability that allows network-
SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication
In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (
In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (
Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources.
Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to
A segmentation violaton in the gf_hevc_read_sps_bs_internal function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allo
CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consu
SQLFluff is a modular SQL linter and auto-formatter with support for multiple dialects and templated code. Prior to vers
An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may be
Spring Data Commons applications may be vulnerable to denial of service through resource exhaustion when attacker-contro
kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in SCRAM authentication handling that allows a ma
libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 16.2.6, an unauthenticated remote pee
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.2
libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 15.0.23, three cooperating omissions
vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded f
Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and befor
Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to
Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to
Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final,
There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina
Impact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service via deeply nested fi
In Spring Cloud Sleuth, it is possible for a user to provide specially crafted calls that may cause a denial-of-service
An issue in the attachment handling component of Feuerhamster MailForm v1.1.0 allows attackers to cause a Denial of Serv
An issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.8 allows attackers to cause a Denial of Ser
An issue in the /api/v0/pastes endpoint of anna-is-cute paste v0.1.1 allows attackers to cause a Denial of Service (DoS)
An input handling flaw in the HTTP refresh token process of LLDAP v0.6.2 allows attackers to cause a Denial of Service (
Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General). Supported versions that are aff
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Connection Handling). Supp
ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, f
Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but d
Impact: The undici WebSocket client enforces maxPayloadSize per-frame but does not enforce the cumulative size of fragme
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati
LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below,
CometD is a scalable comet implementation for web messaging. In versions 5.0.0 through 5.0.22, 6.0.0 through 6.0.18, 7.0
Frequently Asked Questions
What is CWE-400?
CWE-400 (CWE-400) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-400?
There are 3,937 CVE records associated with CWE-400 in our database. Of these, 58 are critical severity, 1666 are high severity, and 1500 are medium severity.
How can I protect against CWE-400 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-400 using AI-powered security agents.
Detect CWE-400 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-400 vulnerabilities across your infrastructure.
Get Started