Weaknesses of type CWE-400

3,039 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-21955HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.EPSS 0.3%CVE-2024-57082MEDIUMA prototype pollution in the lib.createUploader function of @rpldy/uploader v1.8.1 allows attackers to cause a Denial of Service (DoS) via sEPSS 0.3%CVE-2026-21956HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.EPSS 0.3%CVE-2026-6051MEDIUMIBM® Db2® is vulnerable to a denial of service when executing a specially crafted query with a small statement heapEPSS 0.3%CVE-2022-0669—A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USEPSS 0.3%CVE-2024-53647MEDIUMTrend Micro ID Security, version 3.0 and below contains a vulnerability that could allow an attacker to send an unlimited number of email veEPSS 0.3%CVE-2024-1930MEDIUMNo Limit on Number of Open Sessions / Bad Session Close BehaviourEPSS 0.3%CVE-2023-20047MEDIUMA vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco Webex Room Phone and Cisco Webex Share devices could allow an uEPSS 0.3%CVE-2022-36329MEDIUMDenial of Service over OTA mechanism in Western Digital My Cloud Home and ibi devicesEPSS 0.3%CVE-2020-37277HIGHPocketMine-MP before 3.15.4 Denial of Service via InventoryTransactionEPSS 0.3%CVE-2025-53636MEDIUMOpen OnDemand Shell App closed websocket DoSEPSS 0.3%CVE-2026-65827MEDIUMDocmost: Unbounded ZIP decompression (zip-bomb) in page import allows denial of serviceEPSS 0.3%CVE-2026-61048LOWVulnerability in the Oracle Inventory Optimization product of Oracle E-Business Suite (component: User Interface). Supported versions that EPSS 0.3%CVE-2026-60936LOWVulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations). Supported versions thatEPSS 0.3%CVE-2026-83369LOWVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Access SDK). Supported versions that are affecteEPSS 0.3%CVE-2026-62508LOWVulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that areEPSS 0.3%CVE-2026-34277MEDIUMVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Fluid Core). Supported versions that are afEPSS 0.3%CVE-2023-5595MEDIUMDenial of Service in gpac/gpacEPSS 0.3%CVE-2026-22541HIGHDENIAL OF SERVICE VIA ICMP PACKETSEPSS 0.3%CVE-2026-73746LOWAuthenticated Denial of Service Vulnerability in HPE Networking Fabric Composer APIEPSS 0.3%