Weaknesses of type CWE-399
160 resultsErros de Gestão de Recursos
É quando o código falha em alocar, usar ou liberar corretamente recursos do sistema (memória, conexões, arquivos, sockets, threads). O resultado é vazamento de recursos, esgotamento de limites do sistema ou comportamento imprevisível que abre portas para negação de serviço ou exploração.
Example
Uma aplicação web abre uma conexão com banco de dados em cada requisição, mas não a fecha quando ocorre uma exceção. Depois de centenas de requisições, o pool de conexões está saturado e novas requisições falham, derrubando o serviço.
How to mitigate
Use padrões de cleanup garantido (try-finally, context managers, RAII) para liberar recursos. Implemente monitoramento de limites de recursos e testes de carga que exponham vazamentos antes da produção.
CVE-2019-16018HIGHCisco IOS XR Software EVPN Operational Routes Denial of Service VulnerabilityEPSS 1.1%CVE-2017-12360—A vulnerability in Cisco WebEx Network Recording Player for WebEx Recording Format (WRF) files could allow an attacker to cause a denial of EPSS 1.0%CVE-2018-0189—A vulnerability in the Forwarding Information Base (FIB) code of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticatedEPSS 1.0%CVE-2024-20467HIGHA vulnerability in the implementation of the IPv4 fragmentation reassembly code in Cisco IOS XE Software could allow an unauthenticated, remEPSS 1.0%CVE-2023-20014HIGHA vulnerability in the DNS functionality of Cisco Nexus Dashboard Software could allow an unauthenticated, remote attacker to cause a denialEPSS 1.0%CVE-2018-0466—Cisco IOS and IOS XE Software OSPFv3 Denial of Service VulnerabilityEPSS 1.0%CVE-2022-20848HIGHCisco IOS XE Software for Embedded Wireless Controllers on Catalyst 9100 Series Access Points UDP Processing Denial of Service VulnerabilityEPSS 0.9%CVE-2023-20243HIGHA vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attaEPSS 0.9%CVE-2018-0241—A vulnerability in the UDP broadcast forwarding function of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to causeEPSS 0.8%CVE-2021-1569MEDIUMCisco Jabber Desktop and Mobile Client Software VulnerabilitiesEPSS 0.8%CVE-2018-0102—A vulnerability in the Pong tool of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a reload of an affected EPSS 0.8%CVE-2018-0257—A vulnerability in Cisco IOS XE Software running on Cisco cBR Series Converged Broadband Routers could allow an unauthenticated, adjacent atEPSS 0.8%CVE-2021-1570MEDIUMCisco Jabber Desktop and Mobile Client Software VulnerabilitiesEPSS 0.8%CVE-2016-9194—A vulnerability in 802.11 Wireless Multimedia Extensions (WME) action frame processing in Cisco Wireless LAN Controller (WLC) Software couldEPSS 0.8%CVE-2017-12222—A vulnerability in the wireless controller manager of Cisco IOS XE could allow an unauthenticated, adjacent attacker to cause a restart of tEPSS 0.7%CVE-2023-20262MEDIUMA vulnerability in the SSH service of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to cause a process crashEPSS 0.7%CVE-2022-20949MEDIUMA vulnerability in the management web server of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker EPSS 0.7%CVE-2018-0165—A vulnerability in the Internet Group Management Protocol (IGMP) packet-processing functionality of Cisco IOS XE Software could allow an unaEPSS 0.7%CVE-2018-15373—Cisco IOS and IOS XE Software Cisco Discovery Protocol Denial of Service VulnerabilityEPSS 0.7%CVE-2019-1796HIGHCisco Wireless LAN Controller Software IAPP Message Handling Denial of Service VulnerabilitiesEPSS 0.6%