Weaknesses of type CWE-400

3,041 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2022-39124MEDIUMIn sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kerneEPSS 0.1%CVE-2022-39127MEDIUMIn sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kerneEPSS 0.1%CVE-2022-39128MEDIUMIn sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kerneEPSS 0.1%CVE-2022-39126MEDIUMIn sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kerneEPSS 0.1%CVE-2022-39125MEDIUMIn sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kerneEPSS 0.1%CVE-2022-39123MEDIUMIn sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kerneEPSS 0.1%CVE-2025-33177MEDIUMNVIDIA Jetson Linux and IGX OS contain a vulnerability in NvMap, where improper tracking of memory allocations could allow a local attacker EPSS 0.1%CVE-2022-20455MEDIUMIn addAutomaticZenRule of ZenModeHelper.java, there is a possible persistent denial of service due to resource exhaustion. This could lead tEPSS 0.1%CVE-2026-87274MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.1%CVE-2022-38679MEDIUMIn music service, there is a missing permission check. This could lead to local denial of service in music service with no additional executEPSS 0.1%CVE-2024-43763MEDIUMIn build_read_multi_rsp of gatt_sr.cc, there is a possible denial of service due to a logic error in the code. This could lead to remote (prEPSS 0.1%CVE-2026-11478MEDIUMkokke tiny-regex-c Pattern re.c matchstar redosEPSS 0.1%CVE-2026-76702MEDIUMAuthenticated Local Denial-of-Service Vulnerability in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.1%CVE-2026-25122MEDIUMapko is vulnerable to unbounded resource consumption in expandapk.Split on attacker-controlled .apk streamsEPSS 0.1%CVE-2024-51513MEDIUMVulnerability of processes not being fully terminated in the VPN module Impact: Successful exploitation of this vulnerability will affect poEPSS 0.1%CVE-2025-48615HIGHIn getComponentName of MediaButtonReceiverHolder.java, there is a possible desync in persistence due to resource exhaustion. This could leadEPSS 0.1%CVE-2026-20780MEDIUMUncontrolled resource consumption for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow a deniEPSS 0.1%CVE-2025-46593MEDIUMProcess residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulnerability may affect aEPSS 0.1%CVE-2024-40575MEDIUMAn issue in Huawei Technologies opengauss (openGauss 5.0.0 build) v.7.3.0 allows a local attacker to cause a denial of service via the modifEPSS 0.1%CVE-2022-33303MEDIUMUncontrolled resource consumption in Linux kernelEPSS 0.1%