Weaknesses of type CWE-399
160 resultsErros de Gestão de Recursos
É quando o código falha em alocar, usar ou liberar corretamente recursos do sistema (memória, conexões, arquivos, sockets, threads). O resultado é vazamento de recursos, esgotamento de limites do sistema ou comportamento imprevisível que abre portas para negação de serviço ou exploração.
Example
Uma aplicação web abre uma conexão com banco de dados em cada requisição, mas não a fecha quando ocorre uma exceção. Depois de centenas de requisições, o pool de conexões está saturado e novas requisições falham, derrubando o serviço.
How to mitigate
Use padrões de cleanup garantido (try-finally, context managers, RAII) para liberar recursos. Implemente monitoramento de limites de recursos e testes de carga que exponham vazamentos antes da produção.
CVE-2018-0389HIGHCisco Small Business SPA514G IP Phones SIP Denial of Service VulnerabilityEPSS 2.5%CVE-2018-0316—A vulnerability in the Session Initiation Protocol (SIP) call-handling functionality of Cisco IP Phone 6800, 7800, and 8800 Series Phones wiEPSS 2.5%CVE-2017-3876—A vulnerability in the Event Management Service daemon (emsd) of Cisco IOS XR routers could allow an unauthenticated, remote attacker to cauEPSS 2.5%CVE-2017-3856—A vulnerability in the web user interface of Cisco IOS XE 3.1 through 3.17 could allow an unauthenticated, remote attacker to cause an affecEPSS 2.5%CVE-2017-6607—A vulnerability in the DNS code of Cisco ASA Software could allow an unauthenticated, remote attacker to cause an affected device to reload EPSS 2.4%CVE-2018-0252—A vulnerability in the IP Version 4 (IPv4) fragment reassembly function of Cisco 3500, 5500, and 8500 Series Wireless LAN Controller SoftwarEPSS 2.4%CVE-2017-6632—A vulnerability in the logging configuration of Secure Sockets Layer (SSL) policies for Cisco FirePOWER System Software 5.3.0 through 6.2.2 EPSS 2.4%CVE-2017-6641—A vulnerability in the TCP connection handling functionality of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, EPSS 2.4%CVE-2017-6630—A vulnerability in the Session Initiation Protocol (SIP) implementation of Cisco IP Phone 8851 11.0(0.1) could allow an unauthenticated, remEPSS 2.4%CVE-2017-12362—A vulnerability in Cisco Meeting Server versions prior to 2.2.2 could allow an authenticated, remote attacker to cause the system to reload,EPSS 2.3%CVE-2018-0385—A vulnerability in the detection engine parsing of Security Socket Layer (SSL) protocol packets for Cisco Firepower System Software could alEPSS 2.3%CVE-2018-15617MEDIUMCommunication Manager Denial of ServiceEPSS 2.2%CVE-2017-12311—A vulnerability in the H.264 decoder function of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a Cisco MeetiEPSS 2.2%CVE-2018-0370—A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause one of tEPSS 2.2%CVE-2017-12232MEDIUMA vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15.EPSS 2.2%KEVCVE-2017-6653—A vulnerability in the TCP throttling process for the GUI of the Cisco Identity Services Engine (ISE) 2.1(0.474) could allow an unauthenticaEPSS 2.1%CVE-2018-15462HIGHCisco Firepower Threat Defense Software TCP Ingress Handler Denial of Service VulnerabilityEPSS 2.1%CVE-2019-1693HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software WebVPN Denial of Service VulnerabilityEPSS 2.0%CVE-2017-12238MEDIUMA vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could EPSS 2.0%KEVCVE-2017-6613—A vulnerability in the DNS input packet processor for Cisco Prime Network Registrar could allow an unauthenticated, remote attacker to causeEPSS 2.0%