Weaknesses of type CWE-399

160 results

Erros de Gestão de Recursos

É quando o código falha em alocar, usar ou liberar corretamente recursos do sistema (memória, conexões, arquivos, sockets, threads). O resultado é vazamento de recursos, esgotamento de limites do sistema ou comportamento imprevisível que abre portas para negação de serviço ou exploração.

Example

Uma aplicação web abre uma conexão com banco de dados em cada requisição, mas não a fecha quando ocorre uma exceção. Depois de centenas de requisições, o pool de conexões está saturado e novas requisições falham, derrubando o serviço.

How to mitigate

Use padrões de cleanup garantido (try-finally, context managers, RAII) para liberar recursos. Implemente monitoramento de limites de recursos e testes de carga que exponham vazamentos antes da produção.

CVE-2017-6613A vulnerability in the DNS input packet processor for Cisco Prime Network Registrar could allow an unauthenticated, remote attacker to causeEPSS 2.0%CVE-2017-6779Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco collaboration productEPSS 2.0%CVE-2019-12646HIGHCisco IOS XE Software NAT Session Initiation Protocol Application Layer Gateway Denial of Service VulnerabilityEPSS 2.0%CVE-2019-15256HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software IKEv1 Denial of Service VulnerabilityEPSS 2.0%CVE-2019-1635HIGHCisco IP Phone 7800 Series and 8800 Series Session Initiation Protocol XML Denial of Service VulnerabilityEPSS 2.0%CVE-2019-1957MEDIUMCisco IoT Field Network Director TLS Renegotiation Denial of Service VulnerabilityEPSS 2.0%CVE-2020-3499HIGHCisco Firepower Management Center Software Denial of Service VulnerabilityEPSS 2.0%CVE-2021-1313HIGHCisco IOS XR Software Enf Broker Denial of Service VulnerabilityEPSS 2.0%CVE-2021-1288HIGHCisco IOS XR Software Enf Broker Denial of Service VulnerabilityEPSS 2.0%CVE-2022-20653HIGHCisco Email Security Appliance DNS Verification Denial of Service VulnerabilityEPSS 1.8%CVE-2018-0164A vulnerability in the Switch Integrated Security Features of Cisco IOS XE Software could allow an unauthenticated, remote attacker to causeEPSS 1.8%CVE-2017-6625A "Cisco Firepower Threat Defense 6.0.0 through 6.2.2 and Cisco ASA with FirePOWER Module Denial of Service" vulnerability in the access conEPSS 1.8%CVE-2019-12659MEDIUMCisco IOS XE Software HTTP Server Denial of Service VulnerabilityEPSS 1.8%CVE-2018-15396Cisco Unity Connection File Upload Denial of Service VulnerabilityEPSS 1.8%CVE-2017-6631A vulnerability in the HTTP remote procedure call (RPC) service of set-top box (STB) receivers manufactured by Cisco for Yes could allow an EPSS 1.7%CVE-2017-6780A vulnerability in the TCP throttling process for Cisco IoT Field Network Director (IoT-FND) could allow an unauthenticated, remote attackerEPSS 1.7%CVE-2017-6678A vulnerability in the ingress UDP packet processing functionality of Cisco Virtualized Packet Core-Distributed Instance (VPC-DI) Software 1EPSS 1.7%CVE-2020-3188MEDIUMCisco Firepower Threat Defense Software Management Interface Denial of Service VulnerabilityEPSS 1.7%CVE-2018-0457Cisco Webex Player WRF Files Denial of Service VulnerabilityEPSS 1.7%CVE-2017-3793A vulnerability in the TCP normalizer of Cisco Adaptive Security Appliance (ASA) Software (8.0 through 8.7 and 9.0 through 9.6) and Cisco FiEPSS 1.7%