Weaknesses of type CWE-400

3,043 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2024-23712MEDIUMIn multiple functions of AppOpsService.java, there is a possible way to saturate the content of /data/system/appops_accesses.xml due to resoEPSS 0.1%CVE-2018-9412MEDIUMIn removeUnsynchronization of ID3.cpp there is a possible resource exhaustion due to improper input validation. This could lead to denial ofEPSS 0.1%CVE-2025-26449MEDIUMIn multiple locations, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of servicEPSS 0.1%CVE-2022-47356MEDIUMIn log service, there is a missing permission check. This could lead to local denial of service in log service.EPSS 0.1%CVE-2025-48542MEDIUMIn multiple functions of AccountManagerService.java, there is a possible permanent denial of service due to resource exhaustion. This could EPSS 0.1%CVE-2024-40664MEDIUMIn setupAccessibilityServices of AccessibilityFragment.java , there is a possible way to hide an enabled accessibility service due to a logiEPSS 0.1%CVE-2022-47354MEDIUMIn log service, there is a missing permission check. This could lead to local denial of service in log service.EPSS 0.1%CVE-2022-47355MEDIUMIn log service, there is a missing permission check. This could lead to local denial of service in log service.EPSS 0.1%CVE-2024-32912MEDIUMthere is a possible persistent Denial of Service due to test/debugging code left in a production build. This could lead to local denial of sEPSS 0.1%CVE-2025-48569MEDIUMIn multiple locations, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of servicEPSS 0.1%CVE-2026-0074MEDIUMIn getPreferredSize of LauncherProcessImageListener.kt, there is a possible denial of service due to resource exhaustion. This could lead tEPSS 0.1%CVE-2026-0069MEDIUMIn verifySignature of ApkChecksums.java, there is a possible way to cause a crash due to resource exhaustion. This could lead to local deniaEPSS 0.1%CVE-2026-0042MEDIUMIn multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to resource exhaustion. This couldEPSS 0.1%CVE-2025-48648MEDIUMIn isSameApp of NotificationManagerService.java, there is a possible persistent dos due to resource exhaustion. This could lead to local denEPSS 0.1%CVE-2026-100242—DataTransfer depends on phpspreadsheet version vulnerable to CVE-2026-59933 (XLS/OLE memory exhaustion)EPSS —CVE-2026-102993HIGHpypdf: Possible large memory usage when retrieving Roman page labelsEPSS —CVE-2026-18105HIGHFireware OS Uncontrolled Resource Consumption in Diagnostic Tasks Allows Denial of ServiceEPSS —CVE-2026-47568MEDIUMNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could cause uncontrolled kernel log generEPSS —CVE-2026-102821MEDIUMRussh: Unbounded memory exhaustion via CHANNEL_OPEN flood during a client-stalled rekeyEPSS —CVE-2026-86104HIGHFireware OS Resource Exhaustion in Login Process Allows Denial of ServiceEPSS —