Weaknesses of type CWE-399

160 results

Erros de Gestão de Recursos

É quando o código falha em alocar, usar ou liberar corretamente recursos do sistema (memória, conexões, arquivos, sockets, threads). O resultado é vazamento de recursos, esgotamento de limites do sistema ou comportamento imprevisível que abre portas para negação de serviço ou exploração.

Example

Uma aplicação web abre uma conexão com banco de dados em cada requisição, mas não a fecha quando ocorre uma exceção. Depois de centenas de requisições, o pool de conexões está saturado e novas requisições falham, derrubando o serviço.

How to mitigate

Use padrões de cleanup garantido (try-finally, context managers, RAII) para liberar recursos. Implemente monitoramento de limites de recursos e testes de carga que exponham vazamentos antes da produção.

CVE-2019-1799HIGHCisco Wireless LAN Controller Software IAPP Message Handling Denial of Service VulnerabilitiesEPSS 0.6%CVE-2018-0331—A vulnerability in the Cisco Discovery Protocol (formerly known as CDP) subsystem of devices running, or based on, Cisco NX-OS Software contEPSS 0.6%CVE-2019-1684MEDIUMCisco IP Phone 7800 and 8800 Series Cisco Discovery Protocol and Link Layer Discovery Protocol Denial of Service VulnerabilityEPSS 0.6%CVE-2023-29267MEDIUMIBM Db2 denial of serviceEPSS 0.6%CVE-2019-1800HIGHCisco Wireless LAN Controller Software IAPP Message Handling Denial of Service VulnerabilitiesEPSS 0.5%CVE-2019-1700MEDIUMCisco Firepower 9000 Series Firepower 2-Port 100G Double-Width Network Module Queue Wedge Denial of Service VulnerabilityEPSS 0.5%CVE-2020-3260HIGHCisco Aironet Series Access Points Client Packet Processing Denial of Service VulnerabilityEPSS 0.5%CVE-2018-15392—Cisco Industrial Network Director DHCP Request Processing Denial of Service VulnerabilityEPSS 0.4%CVE-2020-3334HIGHCisco Firepower 2100 Series Security Appliances ARP Denial of Service VulnerabilityEPSS 0.4%CVE-2024-20407MEDIUMA vulnerability in the interaction between the TCP Intercept feature and the Snort 3 detection engine on Cisco Firepower Threat Defense (FTDEPSS 0.4%CVE-2018-0088—A vulnerability in one of the diagnostic test CLI commands on Cisco Industrial Ethernet 4010 Series Switches running Cisco IOS Software coulEPSS 0.4%CVE-2024-58113MEDIUMVulnerability of improper resource management in the memory management module Impact: Successful exploitation of this vulnerability may affeEPSS 0.4%CVE-2021-1621HIGHCisco IOS XE Software Interface Queue Wedge Denial of Service VulnerabilityEPSS 0.4%CVE-2021-34713HIGHCisco IOS XR Software for ASR 9000 Series Routers Denial of Service VulnerabilityEPSS 0.4%CVE-2021-1281MEDIUMCisco IOS XE SD-WAN Software Privilege Escalation VulnerabilityEPSS 0.3%CVE-2022-43381MEDIUMIBM AIX denial of service EPSS 0.2%CVE-2022-43380MEDIUMIBM AIX denial of serviceEPSS 0.2%CVE-2022-43382MEDIUMIBM AIX denial of serviceEPSS 0.2%CVE-2022-43855MEDIUMIBM SPSS Statistics denial of serviceEPSS 0.2%CVE-2026-41983MEDIUMNull pointer dereference vulnerability in the browser module. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%