i18n-node-angular is a module used to interact between i18n and angular without using additional resources. A REST API e
Apport through 2.20.7 does not properly handle core dumps from setuid binaries allowing local users to create certain fi
Apport before 2.13 does not properly handle crashes originating from a PID namespace allowing local users to create cert
Apport 2.13 through 2.20.7 does not properly handle crashes originating from a PID namespace allowing local users to cre
An exploitable denial of service vulnerability exists in the processing of snmp-set commands of the Allen Bradley Microl
A vulnerability in the implementation of a specific CLI command and the associated Simple Network Management Protocol (S
In bta_scan_results_cb_impl of btif_ble_scanner.cc, there is possible resource exhaustion if a large number of repeated
A vulnerability in management interface access control list (ACL) configuration of Cisco NX-OS System Software could all
A vulnerability in IPv6 ingress packet processing for Cisco UCS Central Software could allow an unauthenticated, remote
A vulnerability has been identified in TeleControl Server Basic < V3.1. An attacker with access to the TeleControl Serve
qemu/qemu_monitor.c in libvirt allows attackers to cause a denial of service (memory consumption) via a large QEMU reply
phpFreeChat 1.7 and earlier allows remote attackers to cause a denial of service by sending a large number of connect co
A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0. An abort of SASL authentication results in a memory leak in dove
An unprivileged attacker with connectivity to the IMM2 could cause a denial of service attack on the IMM2 (Versions earl
A denial of service flaw was found in miekg-dns before 1.0.4. A remote attacker could use carefully timed TCP packets to
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
The Light Directory Access Protocol (LDAP) clients of Huawei TE60 with software V600R006C00, ViewPoint 9030 with softwar
An issue was discovered in Icinga 2.x through 2.8.1. By sending specially crafted (authenticated and unauthenticated) re
An issue was discovered in Wowza Streaming Engine before 4.7.1. There is a denial of service (memory consumption) via a
The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string
Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vuln
It was found that when Artemis and HornetQ before 2.4.0 are configured with UDP discovery and JGroups discovery a huge b
Undertow in Red Hat wildfly before version 11.0.0.Beta1 is vulnerable to a resource exhaustion resulting in a denial of
libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-57
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. watc
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker can p
A Junos device with VPLS routing-instances configured on one or more interfaces may be susceptible to an mbuf leak when
A vulnerability in MikroTik Version 6.41.4 could allow an unauthenticated remote attacker to exhaust all available CPU a
LogMeIn LastPass through 4.15.0 allows remote attackers to cause a denial of service (browser hang) via an HTML document
Huawei AR1200 V200R006C10SPC300, AR160 V200R006C10SPC300, AR200 V200R006C10SPC300, AR2200 V200R006C10SPC300, AR3200 V200
In Eclipse Mosquitto 1.4.14, a user can shutdown the Mosquitto server simply by filling the RAM memory with a lot of con
LiteCart before 2.1.2 allows remote attackers to cause a denial of service (memory consumption) via URIs that do not exi
A vulnerability in Trend Micro Smart Protection Server (Standalone) 3.x could allow an unauthenticated remote attacker t
Certain input passed into the If-Modified-Since or Last-Modified headers will cause an 'illegal access' exception to be
Certain input strings when passed to new Date() or Date.parse() in ecstatic node module before 1.4.0 will cause v8 to ra
The qs module before 1.0.0 does not have an option or default for specifying object depth and when parsing a string repr
ansi2html is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in.
jadedown is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in.
jshamcrest is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in t
MQTT before 3.4.6 and 4.0.x before 4.0.5 allows specifically crafted MQTT packets to crash the application, making a DoS
The riot-compiler version version 2.3.21 has an issue in a regex (Catastrophic Backtracking) thats make it unusable unde
negotiator is an HTTP content negotiator for Node.js and is used by many modules and frameworks including Express and Ko
Minimatch is a minimal matching utility that works by converting glob expressions into JavaScript `RegExp` objects. The
ws is a "simple to use, blazing fast and thoroughly tested websocket client, server and console for node.js, up-to-date
hapi is a web and services application framework. When hapi >= 15.0.0 <= 16.1.0 encounters a malformed `accept-encoding`
Decamelize is used to convert a dash/dot/underscore/space separated string to camelCase. Decamelize 1.1.0 through 1.1.1
Useragent is used to parse useragent headers. It uses several regular expressions to accomplish this. An attacker could
ua-parser is a port of Browserscope's user agent parser. ua-parser is vulnerable to a ReDoS (Regular Expression Denial o
charset 1.0.0 and below are vulnerable to regular expression denial of service. Input of around 50k characters is requir
The no-case module is vulnerable to regular expression denial of service. When malicious untrusted user input is passed
Frequently Asked Questions
What is CWE-400?
CWE-400 (CWE-400) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-400?
There are 3,937 CVE records associated with CWE-400 in our database. Of these, 58 are critical severity, 1666 are high severity, and 1500 are medium severity.
How can I protect against CWE-400 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-400 using AI-powered security agents.
Detect CWE-400 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-400 vulnerabilities across your infrastructure.
Get Started