A flaw was found in jboss-remoting in versions before 5.0.20.SP1-redhat-00001. A malicious attacker could cause threads
Uncontrolled resource consumption in Mitsubishi Electric MELSEC iQ-R series C Controller Module R12CCPU-V Firmware Versi
Fluentd collects events from various data sources and writes them to files to help unify logging infrastructure. The par
OctoRPKI does not limit the depth of a certificate chain, allowing for a CA to create children in an ad-hoc fashion, the
kamadak-exif is an exif parsing library written in pure Rust. In kamadak-exif version 0.5.2, there is an infinite loop i
CairoSVG is a Python (pypi) package. CairoSVG is an SVG converter based on Cairo. In CairoSVG before version 2.5.1, ther
matrix-media-repo is an open-source multi-domain media repository for Matrix. Versions 1.2.6 and earlier of matrix-media
A memory exhaustion vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow a local attacker to craft speci
A memory exhaustion vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow a local attacker to craft speci
A memory exhaustion vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow a local attacker to craft speci
Uncontrolled resource consumption in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 may allo
Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vuln
A flaw was found in the way memory resources were freed in the unix_stream_recvmsg function in the Linux kernel when a s
There's a flaw in OpenEXR's scanline input file functionality in versions before 3.0.0-beta. An attacker able to submit
There's a flaw in OpenEXR's Scanline API functionality in versions before 3.0.0-beta. An attacker who is able to submit
When a MX Series is configured as a Broadband Network Gateway (BNG) based on Layer 2 Tunneling Protocol (L2TP), executin
A vulnerability was found in Linux kernel where non-blocking socket in llcp_sock_connect() leads to leak and eventually
An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1
An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1
An integer overflow leading to a heap-buffer overflow was found in OpenEXR in versions before 3.0.1. An attacker could u
Uncontrolled resource consumption in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potent
Uncontrolled resource consumption in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potent
SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted
SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted
SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (CPU consumption) via a crafted .xl
The fUSBHub driver in the PCoIP Software Client prior to version 21.07.0 had an error in object management during the ha
A lack of CPU resource in the Linux kernel tracing module functionality in versions prior to 5.14-rc3 was found in the w
An issue was discoverered in in abhijitnathwani image-processing v0.1.0, allows local attackers to cause a denial of ser
Uncontrolled resource consumption in the Intel(R) Distribution of OpenVINOâ„¢ Toolkit before version 2021.4 may allow an
The jQuery Validation Plugin provides drop-in validation for your existing forms. It is published as an npm package "jqu
An attacker could cause a Prometheus denial of service in GitLab 13.7+ by sending an HTTP request with a malformed metho
A vulnerability in the system resource management of Cisco Elastic Services Controller (ESC) could allow an unauthentica
It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that messaging did not impose a character limit wh
This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation
Marked is an open-source markdown parser and compiler (npm package "marked"). In marked from version 1.1.1 and before ve
uap-core in an open-source npm package which contains the core of BrowserScope's original user agent string parser. In u
A vulnerability in the SSH service of the Cisco StarOS operating system could allow an unauthenticated, remote attacker
Vapor is a web framework for Swift. In Vapor before version 4.40.1, there is a DoS attack against anyone who Bootstraps
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne
A vulnerability in the Cisco IOx Application Framework of Cisco 809 Industrial Integrated Services Routers (Industrial I
It was discovered that the is-my-json-valid JavaScript library used an inefficient regular expression to validate JSON f
A vulnerability was found in Braces versions 2.2.0 and above, prior to 2.3.1. Affected versions of this package are vuln
A ZTE product has a configuration error vulnerability. Because a certain port is open by default, an attacker can consum
An uncontrolled resource consumption vulnerability in Message Queue Telemetry Transport (MQTT) server of Juniper Network
Node-redis is a Node.js Redis client. Before version 3.1.1, when a client is in monitoring mode, the regex begin used to
Eventlet is a concurrent networking library for Python. A websocket peer may exhaust memory on Eventlet side by sending
JPA Server in HAPI FHIR before 5.4.0 allows a user to deny service (e.g., disable access to the database after the attac
ws is an open source WebSocket client and server library for Node.js. A specially crafted value of the `Sec-Websocket-Pr
A flaw was found in spice in versions before 0.14.92. A DoS tool might make it easier for remote attackers to cause a de
This affects the package glob-parent before 5.1.2. The enclosure regex used to check for strings ending in enclosure con
Frequently Asked Questions
What is CWE-400?
CWE-400 (CWE-400) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-400?
There are 3,937 CVE records associated with CWE-400 in our database. Of these, 58 are critical severity, 1666 are high severity, and 1500 are medium severity.
How can I protect against CWE-400 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-400 using AI-powered security agents.
Detect CWE-400 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-400 vulnerabilities across your infrastructure.
Get Started