Weaknesses of type CWE-400

3,039 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-60747MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affeEPSS 0.2%CVE-2022-43880MEDIUMIBM QRadar WinCollect AgentEPSS 0.2%CVE-2026-58045MEDIUMA flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing tEPSS 0.2%CVE-2025-69645MEDIUMBinutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logicEPSS 0.2%CVE-2022-30691MEDIUMUncontrolled resource consumption in the Intel(R) Support Android application before version 22.02.28 may allow an authenticated user to potEPSS 0.2%CVE-2023-7258MEDIUMDenial-of-Service in GvisorEPSS 0.2%CVE-2026-87285MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2026-87283MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2026-47041MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2025-66676MEDIUMAn issue in IObit Unlocker v1.3.0.11 allows attackers to cause a Denial of Service (DoS) via a crafted request.EPSS 0.2%CVE-2026-71128MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2026-87282MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2025-23246MEDIUMNVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it allows a guest to conEPSS 0.2%CVE-2025-41227MEDIUMDenial-of-Service VulnerabilityEPSS 0.2%CVE-2023-37195MEDIUMA vulnerability has been identified in SIMATIC CP 1604 (All versions), SIMATIC CP 1616 (All versions), SIMATIC CP 1623 (All versions), SIMATEPSS 0.2%CVE-2026-53495MEDIUMcontainerd CRI ExecSync Goroutine Leak Leading to Node-Level Denial of ServiceEPSS 0.2%CVE-2026-28932MEDIUMA logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue is fixed in macOS SequoiEPSS 0.2%CVE-2022-4816MEDIUMA denial-of-service vulnerability has been identified in Lenovo Safecenter that could allow a local user to crash the application.EPSS 0.2%CVE-2026-43768MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. AEPSS 0.2%CVE-2022-20482MEDIUMIn createNotificationChannel of NotificationManager.java, there is a possible way to make the device unusable and require factory reset due EPSS 0.2%