Weaknesses of type CWE-400

3,000 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2020-3554HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software Denial of Service VulnerabilityEPSS 2.7%CVE-2018-4837—A vulnerability has been identified in TeleControl Server Basic < V3.1. An attacker with access to the TeleControl Server Basic's webserver EPSS 2.7%CVE-2023-28320MEDIUMA denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, seEPSS 2.7%CVE-2018-14638HIGHA flaw was found in 389-ds-base before version 1.3.8.4-13. The process ns-slapd crashes in delete_passwdPolicy function when persistent searEPSS 2.6%CVE-2017-6024—A Resource Exhaustion issue was discovered in Rockwell Automation ControlLogix 5580 controllers V28.011, V28.012, and V28.013; ControlLogix EPSS 2.6%CVE-2025-26673HIGHWindows Lightweight Directory Access Protocol (LDAP) Denial of Service VulnerabilityEPSS 2.6%CVE-2023-29331HIGH.NET, .NET Framework, and Visual Studio Denial of Service VulnerabilityEPSS 2.6%CVE-2024-49075HIGHWindows Remote Desktop Services Denial of Service VulnerabilityEPSS 2.6%CVE-2024-30019MEDIUMDHCP Server Service Denial of Service VulnerabilityEPSS 2.6%CVE-2020-12667HIGHKnot Resolver before 5.1.1 allows traffic amplification via a crafted DNS answer from an attacker-controlled server, aka an "NXNSAttack" issEPSS 2.6%CVE-2019-1737HIGHCisco IOS and IOS XE Software IP Service Level Agreement Denial of Service VulnerabilityEPSS 2.6%CVE-2016-8627MEDIUMadmin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulnerable to an EAP feature to download server log files that allows logs to be availEPSS 2.6%CVE-2009-3791HIGHUnspecified vulnerability in Adobe Flash Media Server (FMS) before 3.5.3 allows attackers to cause a denial of service (resource exhaustion)EPSS 2.6%CVE-2025-21251HIGHMicrosoft Message Queuing (MSMQ) Denial of Service VulnerabilityEPSS 2.6%CVE-2025-21231HIGHIP Helper Denial of Service VulnerabilityEPSS 2.6%CVE-2023-38178HIGH.NET Core and Visual Studio Denial of Service VulnerabilityEPSS 2.6%CVE-2025-21218HIGHWindows Kerberos Denial of Service VulnerabilityEPSS 2.6%CVE-2026-23864HIGHMultiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, reacEPSS 2.6%CVE-2021-27385HIGHA vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 UpdatEPSS 2.6%CVE-2023-5870LOWPostgresql: role pg_signal_backend can signal certain superuser processes.EPSS 2.6%