Weaknesses of type CWE-399
160 resultsErros de Gestão de Recursos
É quando o código falha em alocar, usar ou liberar corretamente recursos do sistema (memória, conexões, arquivos, sockets, threads). O resultado é vazamento de recursos, esgotamento de limites do sistema ou comportamento imprevisível que abre portas para negação de serviço ou exploração.
Example
Uma aplicação web abre uma conexão com banco de dados em cada requisição, mas não a fecha quando ocorre uma exceção. Depois de centenas de requisições, o pool de conexões está saturado e novas requisições falham, derrubando o serviço.
How to mitigate
Use padrões de cleanup garantido (try-finally, context managers, RAII) para liberar recursos. Implemente monitoramento de limites de recursos e testes de carga que exponham vazamentos antes da produção.
CVE-2017-6613—A vulnerability in the DNS input packet processor for Cisco Prime Network Registrar could allow an unauthenticated, remote attacker to causeEPSS 2.0%CVE-2017-6779—Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco collaboration productEPSS 2.0%CVE-2019-12646HIGHCisco IOS XE Software NAT Session Initiation Protocol Application Layer Gateway Denial of Service VulnerabilityEPSS 2.0%CVE-2019-15256HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software IKEv1 Denial of Service VulnerabilityEPSS 2.0%CVE-2019-1635HIGHCisco IP Phone 7800 Series and 8800 Series Session Initiation Protocol XML Denial of Service VulnerabilityEPSS 2.0%CVE-2019-1957MEDIUMCisco IoT Field Network Director TLS Renegotiation Denial of Service VulnerabilityEPSS 2.0%CVE-2020-3499HIGHCisco Firepower Management Center Software Denial of Service VulnerabilityEPSS 2.0%CVE-2021-1313HIGHCisco IOS XR Software Enf Broker Denial of Service VulnerabilityEPSS 2.0%CVE-2021-1288HIGHCisco IOS XR Software Enf Broker Denial of Service VulnerabilityEPSS 2.0%CVE-2022-20653HIGHCisco Email Security Appliance DNS Verification Denial of Service VulnerabilityEPSS 1.8%CVE-2018-0164—A vulnerability in the Switch Integrated Security Features of Cisco IOS XE Software could allow an unauthenticated, remote attacker to causeEPSS 1.8%CVE-2017-6625—A "Cisco Firepower Threat Defense 6.0.0 through 6.2.2 and Cisco ASA with FirePOWER Module Denial of Service" vulnerability in the access conEPSS 1.8%CVE-2019-12659MEDIUMCisco IOS XE Software HTTP Server Denial of Service VulnerabilityEPSS 1.8%CVE-2018-15396—Cisco Unity Connection File Upload Denial of Service VulnerabilityEPSS 1.8%CVE-2017-6631—A vulnerability in the HTTP remote procedure call (RPC) service of set-top box (STB) receivers manufactured by Cisco for Yes could allow an EPSS 1.7%CVE-2017-6780—A vulnerability in the TCP throttling process for Cisco IoT Field Network Director (IoT-FND) could allow an unauthenticated, remote attackerEPSS 1.7%CVE-2017-6678—A vulnerability in the ingress UDP packet processing functionality of Cisco Virtualized Packet Core-Distributed Instance (VPC-DI) Software 1EPSS 1.7%CVE-2020-3188MEDIUMCisco Firepower Threat Defense Software Management Interface Denial of Service VulnerabilityEPSS 1.7%CVE-2018-0457—Cisco Webex Player WRF Files Denial of Service VulnerabilityEPSS 1.7%CVE-2017-3793—A vulnerability in the TCP normalizer of Cisco Adaptive Security Appliance (ASA) Software (8.0 through 8.7 and 9.0 through 9.6) and Cisco FiEPSS 1.7%