Weaknesses of type CWE-1284

325 results

Validação inadequada da quantidade de dados em entrada

A aplicação não valida corretamente a quantidade, tamanho ou volume de dados que recebe do usuário, permitindo que entradas maiores ou menores que o esperado passem pelo controle. Isso abre espaço para ataques de negação de serviço, estouro de buffer, consumo excessivo de recursos ou processamento de dados malformados.

Example

Um serviço web aceita um parâmetro 'quantidade' para retornar registros, mas não limita o valor máximo. Um atacante envia quantidade=999999999, forçando a aplicação a alocar gigabytes de memória ou executar query que consome toda a CPU, derrubando o serviço para usuários legítimos.

How to mitigate

Implemente validação explícita para toda entrada numérica ou de tamanho: defina limites mínimos e máximos aceitáveis, rejeite silenciosamente o que sair desses intervalos e registre tentativas suspeitas. Use whitelist de valores válidos quando possível.

CVE-2024-3036MEDIUMCommunication DoS vulnerabilityEPSS 0.3%CVE-2026-45441HIGHWordPress WpEvently plugin <= 5.3.3 - Other Vulnerability Type vulnerabilityEPSS 0.3%CVE-2025-36423MEDIUMIBM Db2 Denial of ServiceEPSS 0.3%CVE-2026-59532HIGHWordPress Booking and Rental Manager plugin <= 2.7.2 - Price Manipulation vulnerabilityEPSS 0.3%CVE-2026-49078HIGHWordPress WP Travel Engine plugin <= 6.7.10 - Other Vulnerability Type vulnerabilityEPSS 0.3%CVE-2026-30573HIGHA Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0. The vulnerability is located in the add-saleEPSS 0.3%CVE-2024-48290MEDIUMAn issue in the Bluetooth Low Energy implementation of Realtek RTL8762E BLE SDK v1.4.0 allows attackers to cause a Denial of Service (DoS) vEPSS 0.2%CVE-2025-14689MEDIUMIBM Db2 Denial of ServiceEPSS 0.2%CVE-2026-42732MEDIUMWordPress Ads by WPQuads plugin <= 3.0.2 - Broken Authentication vulnerabilityEPSS 0.2%CVE-2024-6068HIGHInput Validation Vulnerability exists in Arena® Input AnalyzerEPSS 0.2%CVE-2026-81851MEDIUMFireware OS Heap-Based Buffer Overflow in iked Allows Denial of ServiceEPSS 0.2%CVE-2025-24100LOWA logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3EPSS 0.2%CVE-2026-93015HIGHBlueKitchen BTstack through 1.8.2 A2DP SEP Discovery Out-of-Bounds WriteEPSS 0.2%CVE-2025-13867MEDIUMIBM Db2 Denial of ServiceEPSS 0.2%CVE-2024-53878LOWNVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in the cuobjdump binary, where a user could cause a crash by passing a maEPSS 0.2%CVE-2023-27961MEDIUMMultiple validation issues were addressed with improved input sanitization. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 1EPSS 0.2%CVE-2026-7254MEDIUMOpen BMC Denial of ServiceEPSS 0.2%CVE-2026-11596MEDIUMIn ScreenConnect™ versions prior to 26.2, input validation within the Host Pass creation functionality could allow an authenticated user witEPSS 0.2%CVE-2026-49110HIGHWordPress Upsell Order Bump Offer for WooCommerce plugin <= 3.1.4 - Price Manipulation vulnerabilityEPSS 0.2%CVE-2026-73436MEDIUMSecurity Advisory 0171EPSS 0.2%