An attacker could send a specially crafted message to Crimson 3.1 (Build versions prior to 3119.001) that could leak arb
In Phoenix Contact FL SWITCH SMCS series products in multiple versions fragmented TCP-Packets may cause a Denial of Serv
The unity-firefox-extension package could be tricked into destroying the Unity webapps context, causing Firefox to crash
The unity-firefox-extension package could be tricked into dropping a C callback which was still in use, which Firefox wo
Firefox for Android would become unstable and hard-to-recover when a website opened too many popups. *This bug only affe
A vulnerability in the ingress packet processing function of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation
In freeIsolatedUidLocked of ProcessList.java, there is a possible UID reuse due to improper cleanup. This could lead to
Trustwave ModSecurity 3.0.0 through 3.0.3 allows an attacker to send crafted requests that may, when sent quickly in lar
HashiCorp Vault Enterprise 0.11.0 through 1.3.1 fails, in certain circumstances, to revoke dynamic secrets for a mount i
Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00SPC100; and Secospace USG6600 and USG9500 version
In Couchbase Server 6.0.3 and Couchbase Sync Gateway through 2.7.0, the Cluster management, views, query, and full-text
HashiCorp Consul and Consul Enterprise could crash when configured with an abnormally-formed service-router entry. Intro
The Apache server on port 80 that host the web interface is vulnerable to a DoS by spamming incomplete HTTP headers, eff
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow an unauthe
Vulnerability in the Oracle Enterprise Session Border Controller product of Oracle Communications Applications (componen
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: CacheStore). Supported versions th
In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, and 14.1.0-14.1.2.6, a BIG-IP virtual server with a Session Initiat
A vulnerability in the Protocol Independent Multicast (PIM) feature for IPv6 networks (PIM6) of Cisco NX-OS Software cou
It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service's DCOM websoc
An attacker could send a specially crafted packet that could have CodeMeter (All versions prior to 7.10) send back packe
An issue with ARP packets in Arista’s EOS affecting the 7800R3, 7500R3, and 7280R3 series of products may result in issu
A vulnerability in the SIP inspection process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Th
The IBM Process Federation Server 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, and 19.0.0.3 Global Teams REST API does not pr
A vulnerability was found in Wildfly's Enterprise Java Beans (EJB) versions shipped with Red Hat JBoss EAP 7, where Sess
Cloud Foundry Routing (Gorouter), versions prior to 0.204.0, when used in a deployment with NGINX reverse proxies in fro
In AudioFlinger::RecordThread::threadLoop of audioflinger/Threads.cpp, there is a possible non-silenced audio buffer due
Cleanup errors in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure
Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially
An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file d
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Packaging Scripts). The supported version that
u'Information disclosure issue can occur due to partial secure display-touch session tear-down' in Snapdragon Auto, Snap
u'Information disclosure issue occurs as in current logic Secure Touch session is released without terminating display s
IBM Spectrum Scale V4.2.0.0 through V4.2.3.23 and V5.0.0.0 through V5.0.5.2 as well as IBM Elastic Storage System 6.0.0
In onUserStopped of Vpn.java, there is a possible resetting of user preferences due to a logic issue. This could lead to
Grin before 3.1.0 allows attackers to adversely affect availability of data on a Mimblewimble blockchain.
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows crafted posts that potentially ca
A res_pjsip_session crash was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x before 1
In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edi
A potential DOS vulnerability was discovered in all versions of Gitlab starting from 13.4.x (>=13.4 to <13.4.7, >=13.5 t
A vulnerability in the software cryptography module of the Cisco Adaptive Security Virtual Appliance (ASAv) and Firepowe
A vulnerability in the Internet Key Exchange Version 2 Mobility and Multihoming Protocol (MOBIKE) feature for the Cisco
The string component in the GNU C Library (aka glibc or libc6) through 2.28, when running on the x32 architecture, incor
In FreeBSD 12.0-STABLE before r350261, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r350263, 11.3-RELEASE bef
In FreeBSD 12.0-STABLE before r350222, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r350223, 11.3-RELEASE bef
When BGP tracing is enabled an incoming BGP message may cause the Junos OS routing protocol daemon (rpd) process to cras
On Junos devices with the BGP graceful restart helper mode enabled or the BGP graceful restart mechanism enabled, a BGP
In MPLS environments, receipt of a specific SNMP packet may cause the routing protocol daemon (RPD) process to crash and
Receipt of a specific packet on the out-of-band management interface fxp0 may cause the system to crash and restart (vmc
On Junos devices with the BGP graceful restart helper mode enabled or the BGP graceful restart mechanism enabled, a cert
The srxpfe process may crash on SRX Series services gateways when the UTM module processes a specific fragmented HTTP pa
Frequently Asked Questions
What is CWE-404?
CWE-404 (CWE-404) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-404?
There are 847 CVE records associated with CWE-404 in our database. Of these, 2 are critical severity, 161 are high severity, and 412 are medium severity.
How can I protect against CWE-404 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-404 using AI-powered security agents.
Detect CWE-404 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-404 vulnerabilities across your infrastructure.
Get Started