The content module is a module to parse HTTP Content-* headers. It is used by the hapijs framework to provide this funct
The parsejson module is vulnerable to regular expression denial of service when untrusted user input is passed into it t
The marked module is vulnerable to a regular expression denial of service. Based on the information published in the pub
The timespan module is vulnerable to regular expression denial of service. Given 50k characters of untrusted user input
The string module is a module that provides extra string operations. The string module is vulnerable to regular expressi
slug is a module to slugify strings, even if they contain unicode. slug is vulnerable to regular expression denial of se
The forwarded module is used by the Express.js framework to handle the X-Forwarded-For header. It is vulnerable to a reg
Fresh is a module used by the Express.js framework for HTTP response freshness testing. It is vulnerable to a regular ex
method-override is a module used by the Express.js framework to let you use HTTP verbs such as PUT or DELETE in places w
The mime module < 1.4.1, 2.0.1, 2.0.2 is vulnerable to regular expression denial of service when a mime lookup is perfor
Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco c
Node.js versions 9.7.0 and later and 10.x are vulnerable and the severity is MEDIUM. A bug introduced in 9.7.0 increases
By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker ex
aaugustin websockets version 4 contains a CWE-409: Improper Handling of Highly Compressed Data (Data Amplification) vuln
Bitcoin Core before v0.13.0 allows denial of service (memory exhaustion) triggered by the remote network alert system (d
Receipt of a specific MPLS packet may cause MPC7/8/9, PTX-FPC3 (FPC-P1, FPC-P2) line cards or PTX1K to crash and restart
A vulnerability in the DHCPv6 feature of the Cisco Nexus 9000 Series Fabric Switches in Application-Centric Infrastructu
SEL AcSELerator Architect version 2.2.24.0 and prior can be exploited when the AcSELerator Architect FTP client connects
In Moxa NPort 5210, 5230, and 5232 versions 2.9 build 17030709 and prior, the amount of resources requested by a malicio
wancms 1.0 through 5.0 allows remote attackers to cause a denial of service (resource consumption) via a checkcode (aka
F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, or 11.6.0-11.6.3.1 virtual servers with HTTP/2 profiles enabled are vulnerab
When F5 BIG-IP ASM 13.0.0-13.1.0.1, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, or 11.5.1-11.5.6 is processing HTTP requests, an u
Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior allow the creation of new connect
Firmware in the Intel Puma 5, 6, and 7 Series might experience resource depletion or timeout, which allows a network att
PHPCMS 9 allows remote attackers to cause a denial of service (resource consumption) via large font_size, height, and wi
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queu
The Symantec Encryption Management Server (SEMS) product, prior to version 3.4.2 MP1, may be susceptible to a denial of
The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10.1.x through 10.1.4 and 10.0.x through 10.0.
In FreeBSD before 11.1-STABLE, 11.2-RELEASE-p2, 11.1-RELEASE-p13, ip fragment reassembly code is vulnerable to a denial
The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packet
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. Several data types used as RPC input variables
A flaw was found in 389-ds-base before version 1.3.8.4-13. The process ns-slapd crashes in delete_passwdPolicy function
IBM Tivoli Monitoring 6.2.3 through 6.2.3.5 and 6.3.0 through 6.3.0.7 are vulnerable to both TEPS user privilege escalat
Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. A remote, unauthenticated threat actor may intentionally
There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x throu
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software does not properly restrict the size or a
A flaw was found in 389 Directory Server. A specially crafted search query could lead to excessive CPU consumption in th
A vulnerability in the cryptographic hardware accelerator driver of Cisco Adaptive Security Appliance (ASA) Software and
A vulnerability has been identified in SIMATIC ET 200SP Open Controller (All versions >= V2.0 and < V2.1.6), SIMATIC S7-
A vulnerability in the Routing Protocols Daemon (RPD) with Juniper Extension Toolkit (JET) support can allow a network b
Yokogawa STARDOM Controllers FCJ,FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The controller application fai
When FW tries to get random mac address generated from new SW RNG and ADC values read are constant then DUT get struck i
The merge.recursive function in the merge package <1.2.1 can be tricked into adding or modifying properties of the Objec
Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) bec
Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) bec
An exploitable code execution vulnerability exists in the UDP network functionality of Yi Home Camera 27US 1.8.7.0D. A s
A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive
There is a possible DoS vulnerability in the multipart parser in Rack before 2.0.6. Specially crafted requests can cause
Frequently Asked Questions
What is CWE-400?
CWE-400 (CWE-400) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-400?
There are 3,937 CVE records associated with CWE-400 in our database. Of these, 58 are critical severity, 1666 are high severity, and 1500 are medium severity.
How can I protect against CWE-400 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-400 using AI-powered security agents.
Detect CWE-400 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-400 vulnerabilities across your infrastructure.
Get Started