Weaknesses of type CWE-400

3,039 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2025-55559HIGHAn issue was discovered TensorFlow v2.18.0. A Denial of Service (DoS) occurs when padding is set to 'valid' in tf.keras.layers.Conv2D.EPSS 0.2%CVE-2021-47371HIGHnexthop: Fix memory leaks in nexthop notification chain listenersEPSS 0.2%CVE-2021-21529LOWDell System Update (DSU) 1.9 and earlier versions contain a denial of service vulnerability. A local authenticated malicious user with low pEPSS 0.2%CVE-2024-0581MEDIUMUncontrolled Resource Consumption vulnerability on Sandsprite scdbgEPSS 0.2%CVE-2026-12319MEDIUMDenial-of-service in the Audio/Video: Playback componentEPSS 0.2%CVE-2022-26523MEDIUMThe socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local attackers to executeEPSS 0.2%CVE-2025-27250MEDIUMUncontrolled resource consumption for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow EPSS 0.2%CVE-2025-9308MEDIUMyarnpkg Yarn request-manager.js setOptions redosEPSS 0.2%CVE-2025-27081MEDIUMHPE NonStop OSM Service Connection Suite, Denial of Service vulnerabilityEPSS 0.2%CVE-2025-11274MEDIUMOpen Asset Import Library Assimp Q3DLoader.cpp InternReadFile allocation of resourcesEPSS 0.2%CVE-2022-3698MEDIUM A denial of service vulnerability was reported in the Lenovo HardwareScanPlugin versions prior to 1.3.1.2 and  Lenovo Diagnostics versEPSS 0.2%CVE-2023-25949MEDIUMUncontrolled resource consumption in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enEPSS 0.2%CVE-2022-0353MEDIUM A denial of service vulnerability was reported in the Lenovo HardwareScanPlugin versions prior to 1.3.1.2 and  Lenovo Diagnostics versEPSS 0.2%CVE-2023-25769MEDIUMUncontrolled resource consumption in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated userEPSS 0.2%CVE-2025-29478MEDIUMAn issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the cfl_list_size in cfl_list.h:165.EPSS 0.2%CVE-2026-90554MEDIUMvLLM before 0.28.0 Denial of Service via audio extractionEPSS 0.2%CVE-2024-22102MEDIUMDenial of Service (DoS) vulnerability in Jungo WinDriver before 12.6.0 allows local attackers to cause a Windows blue screen error.EPSS 0.2%CVE-2024-13065MEDIUMBusiness Logic Error in Akinsoft's MyRezztaEPSS 0.2%CVE-2024-21823HIGHHardware logic with insecure de-synchronization in Intel(R) DSA and Intel(R) IAA for some Intel(R) 4th or 5th generation Xeon(R) processors EPSS 0.2%CVE-2026-3293MEDIUMsnowflakedb snowflake-jdbc JDBC URL SdkProxyRoutePlanner.java SdkProxyRoutePlanner redosEPSS 0.2%