Weaknesses of type CWE-400

3,039 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2021-47284MEDIUMisdn: mISDN: netjet: Fix crash in nj_probe:EPSS 0.2%CVE-2021-4440HIGHx86/xen: Drop USERGS_SYSRET64 paravirt callEPSS 0.2%CVE-2024-35948HIGHbcachefs: Check for journal entries overruning end of sb clean sectionEPSS 0.2%CVE-2025-13837LOWOut-of-memory when loading PlistEPSS 0.2%CVE-2024-39479HIGHdrm/i915/hwmon: Get rid of devmEPSS 0.2%CVE-2025-55028MEDIUMJavaScript alerts could impede UI interaction or allow denial of service attacksEPSS 0.2%CVE-2024-34036MEDIUMAn issue was discovered in O-RAN Near Realtime RIC I-Release. To exploit this vulnerability, an attacker can disrupt the initial connection EPSS 0.2%CVE-2021-25701—The fUSBHub driver in the PCoIP Software Client prior to version 21.07.0 had an error in object management during the handling of a variety EPSS 0.2%CVE-2025-20616LOWUncontrolled resource consumption for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to pEPSS 0.2%CVE-2024-25112MEDIUMDenial of service due to unbounded recursion in QuickTimeVideo::multipleEntriesDecoder in Exiv2EPSS 0.2%CVE-2026-12759MEDIUMMultiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for August 2026.EPSS 0.2%CVE-2026-49762MEDIUMUnbounded integer parsing in the Version module enables CPU and memory exhaustion denial of serviceEPSS 0.2%CVE-2023-4394MEDIUMMemory leak in btrfs_get_dev_args_from_path()EPSS 0.2%CVE-2025-20084MEDIUMUncontrolled resource consumption for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to pEPSS 0.2%CVE-2025-20057MEDIUMUncontrolled resource consumption for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to pEPSS 0.2%CVE-2026-21500MEDIUMStack Overflow in iccDEV XML Calculator Macro ExpansionEPSS 0.2%CVE-2025-31245MEDIUMThe issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS SonoEPSS 0.2%CVE-2023-28938LOWUncontrolled resource consumption in some Intel(R) SSD Tools software before version mdadm-4.2-rc2 may allow a priviledged user to potentialEPSS 0.2%CVE-2025-26500MEDIUMVxWorks 7 USB FailureEPSS 0.2%CVE-2026-42626MEDIUMHP ENVY 5000 series printers VERBASPP1N003.2237A.00 do not properly manage concurrent TCP connections to port 9100 (JetDirect/RAW printing).EPSS 0.2%