Weaknesses of type CWE-399
160 resultsErros de Gestão de Recursos
É quando o código falha em alocar, usar ou liberar corretamente recursos do sistema (memória, conexões, arquivos, sockets, threads). O resultado é vazamento de recursos, esgotamento de limites do sistema ou comportamento imprevisível que abre portas para negação de serviço ou exploração.
Example
Uma aplicação web abre uma conexão com banco de dados em cada requisição, mas não a fecha quando ocorre uma exceção. Depois de centenas de requisições, o pool de conexões está saturado e novas requisições falham, derrubando o serviço.
How to mitigate
Use padrões de cleanup garantido (try-finally, context managers, RAII) para liberar recursos. Implemente monitoramento de limites de recursos e testes de carga que exponham vazamentos antes da produção.
CVE-2019-1599HIGHCisco NX-OS Software Netstack Denial of Service VulnerabilityEPSS 14.3%CVE-2018-0476—Cisco IOS XE Software NAT Session Initiation Protocol Application Layer Gateway Denial of Service VulnerabilityEPSS 13.7%CVE-2022-20623HIGHCisco Nexus 9000 Series Switches Bidirectional Forwarding Detection Denial of Service VulnerabilityEPSS 11.9%CVE-2018-0156HIGHA vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attackerEPSS 8.2%KEVCVE-2017-12231HIGHA vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12.4 through 15.6 could allow an unautEPSS 7.1%KEVCVE-2017-12237HIGHA vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 couldEPSS 7.1%KEVCVE-2018-0154HIGHA vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unaEPSS 7.1%KEVCVE-2022-20770HIGHClamAV CHM File Parsing Denial of Service Vulnerability Affecting Cisco Products: April 2022EPSS 7.0%CVE-2017-12246—A vulnerability in the implementation of the direct authentication feature in Cisco Adaptive Security Appliance (ASA) Software could allow aEPSS 6.5%CVE-2017-6627HIGHA vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, reEPSS 6.0%KEVCVE-2022-20771HIGHClamAV TIFF File Parsing Denial of Service Vulnerability Affecting Cisco Products: April 2022EPSS 5.8%CVE-2018-0180MEDIUMMultiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attackEPSS 5.0%KEVCVE-2018-0179MEDIUMMultiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attackEPSS 5.0%KEVCVE-2018-0161MEDIUMA vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco CatalystEPSS 4.7%KEVCVE-2017-6608—A vulnerability in the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) code of Cisco ASA Software could allow an unauthenticatEPSS 4.6%CVE-2018-0470—Cisco IOS XE Software HTTP Denial of Service VulnerabilityEPSS 4.4%CVE-2018-0310—A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remotEPSS 4.2%CVE-2018-0240—Multiple vulnerabilities in the Application Layer Protocol Inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco EPSS 3.9%CVE-2017-6648—A vulnerability in the Session Initiation Protocol (SIP) of the Cisco TelePresence Codec (TC) and Collaboration Endpoint (CE) Software couldEPSS 3.6%CVE-2018-0473—Cisco IOS Software Precision Time Protocol Denial of Service VulnerabilityEPSS 3.5%