Weaknesses of type CWE-400

3,000 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2017-15130—A denial of service flaw was found in dovecot before 2.2.34. An attacker able to generate random SNI server names could exploit TLS SNI confEPSS 2.6%CVE-2024-21342HIGHWindows DNS Client Denial of Service VulnerabilityEPSS 2.5%CVE-2025-21300HIGHWindows Universal Plug and Play (UPnP) Device Host Denial of Service VulnerabilityEPSS 2.5%CVE-2021-1312MEDIUMCisco Elastic Services Controller Denial of Service VulnerabilityEPSS 2.5%CVE-2018-8854—Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software does not properly restrict the size or amount of resources rEPSS 2.5%CVE-2024-38068HIGHWindows Online Certificate Status Protocol (OCSP) Server Denial of Service VulnerabilityEPSS 2.5%CVE-2024-38067HIGHWindows Online Certificate Status Protocol (OCSP) Server Denial of Service VulnerabilityEPSS 2.5%CVE-2024-38031HIGHWindows Online Certificate Status Protocol (OCSP) Server Denial of Service VulnerabilityEPSS 2.5%CVE-2021-21317MEDIUMDenial of Service in uap-coreEPSS 2.5%CVE-2018-14660MEDIUMA flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr. A remote, authEPSS 2.5%CVE-2018-0372—A vulnerability in the DHCPv6 feature of the Cisco Nexus 9000 Series Fabric Switches in Application-Centric Infrastructure (ACI) Mode could EPSS 2.5%CVE-2020-24686HIGHAC500 V2 webserver denial of service vulnerabilityEPSS 2.5%CVE-2025-21351HIGHWindows Active Directory Domain Services API Denial of Service VulnerabilityEPSS 2.5%CVE-2018-15383—Cisco Adaptive Security Appliance Direct Memory Access Denial of Service VulnerabilityEPSS 2.5%CVE-2022-24729MEDIUMRegular expression Denial of Service in dialog pluginEPSS 2.5%CVE-2020-7587—A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2EPSS 2.5%CVE-2025-27469HIGHWindows Lightweight Directory Access Protocol (LDAP) Denial of Service VulnerabilityEPSS 2.5%CVE-2019-1873HIGHCisco ASA and FTD Software Cryptographic TLS and SSL Driver Denial of Service VulnerabilityEPSS 2.5%CVE-2021-21306MEDIUMDenial of Service in MarkedEPSS 2.5%CVE-2020-8220—A denial of service vulnerability exists in Pulse Connect Secure <9.1R8 that allows an authenticated attacker to perform command injection vEPSS 2.5%