A vulnerability in the Secure Shell (SSH) session management for Cisco Wireless LAN Controller (WLC) Software could allo
ClamAV versions prior to 0.101.3 are susceptible to a zip bomb vulnerability where an unauthenticated attacker can cause
kde-workspace before 4.10.5 has a memory leak in plasma desktop
knot-resolver before version 4.3.0 is vulnerable to denial of service through high CPU utilization. DNS replies with ver
The pad management logic in XWiki labs CryptPad before 3.0.0 allows a remote attacker (who has access to a Rich Text pad
A denial of service vulnerability was reported in Lenovo System Update before version 5.07.0084 that could allow service
A vulnerability in the remote access VPN session manager of Cisco Adaptive Security Appliance (ASA) Software could allow
When a Beckhoff TwinCAT Runtime receives a malformed UDP packet, the ADS Discovery Service shuts down. Note that the Twi
Juniper Identity Management Service (JIMS) for Windows versions prior to 1.1.4 may send an incorrect message to associat
A remote code execution vulnerability exists when Windows Search handles objects in memory, aka "Windows Search Remote C
Unisys Stealth 3.3 Windows endpoints before 3.3.016.1 allow local users to gain access to Stealth-enabled devices by lev
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles obje
A remote code execution vulnerability exists when Windows improperly handles objects in memory, aka "Windows Remote Code
A remote code execution vulnerability exists when Windows improperly handles objects in memory, aka "Windows Remote Code
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle o
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles obje
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles obje
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles obje
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles obje
An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka "Window
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles obje
An Elevation of Privilege vulnerability exists in Windows Subsystem for Linux when it fails to properly handle objects i
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles obje
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka "Window
An elevation of privilege vulnerability exists in the way that the Microsoft RemoteFX Virtual GPU miniport driver handle
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka "DirectX Elevation
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka "DirectX Elevation
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka "DirectX Elevation
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle o
OpenFlow Plugin and OpenDayLight Controller versions Nitrogen, Carbon, Boron, Robert Varga, Anil Vishnoi contain a flaw
In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles
An elevation of privilege vulnerability exists in the way that the Windows kernel image handles objects in memory, aka "
An elevation of privilege vulnerability exists when the (Human Interface Device) HID Parser Library driver improperly ha
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
An Elevation of Privilege vulnerability exists in Filter Manager when it improperly handles objects in memory, aka "Micr
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "
Python Cryptographic Authority pyopenssl version Before 17.5.0 contains a CWE - 401 : Failure to Release Memory Before R
RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x), contains an Improper
Frequently Asked Questions
What is CWE-404?
CWE-404 (CWE-404) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-404?
There are 847 CVE records associated with CWE-404 in our database. Of these, 2 are critical severity, 161 are high severity, and 412 are medium severity.
How can I protect against CWE-404 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-404 using AI-powered security agents.
Detect CWE-404 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-404 vulnerabilities across your infrastructure.
Get Started