Weaknesses of type CWE-400

3,041 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2025-27576LOWUncontrolled resource consumption for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow EPSS 0.1%CVE-2025-55631MEDIUMReolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 was discovered to manage users' sessions system EPSS 0.1%CVE-2026-43806MEDIUMA denial of service issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26.6. A local attacker may be abEPSS 0.1%CVE-2026-38763MEDIUMAn issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service via the function sub_13828EPSS 0.1%CVE-2024-57672MEDIUMAn issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module, Topologylnstance module, REPSS 0.1%CVE-2026-21942MEDIUMVulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). Supported versions that are affected are 10 and 11EPSS 0.1%CVE-2025-26697MEDIUMUncontrolled resource consumption in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2.28.5 may allow an aEPSS 0.1%CVE-2025-26863MEDIUMUncontrolled resource consumption in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2.28.5 may allow an aEPSS 0.1%CVE-2025-60419MEDIUMAn issue was discovered in the NDIS Usermode IO driver (RtkIOAC60.sys, version 6.0.5600.16348) allowing local authenticated attackers to senEPSS 0.1%CVE-2023-20910MEDIUMIn add of WifiNetworkSuggestionsManager.java, there is a possible way to trigger permanent DoS due to resource exhaustion. This could lead tEPSS 0.1%CVE-2026-40951MEDIUMMemory corruption in Secure Access Windows clients prior to 14.50EPSS 0.1%CVE-2026-16952MEDIUMVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.1%CVE-2022-25326MEDIUMDenial of Service in fscryptEPSS 0.1%CVE-2025-61480HIGHAn issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial ofEPSS 0.1%CVE-2025-69644MEDIUMAn issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary witEPSS 0.1%CVE-2025-27249MEDIUMUncontrolled resource consumption for some Gaudi software before version 1.21.0 within Ring 3: User Applications may allow a denial of serviEPSS 0.1%CVE-2023-20922MEDIUMIn setMimeGroup of PackageManagerService.java, there is a possible crash loop due to resource exhaustion. This could lead to local denial ofEPSS 0.1%CVE-2023-20908MEDIUMIn several functions of SettingsState.java, there is a possible system crash loop due to resource exhaustion. This could lead to local deniaEPSS 0.1%CVE-2026-55595MEDIUMImageMagick: Infinite Loop in connected-components when providing invalid argumentsEPSS 0.1%CVE-2026-0064CRITICALIn multiple places, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service EPSS 0.1%