Weaknesses of type CWE-400

3,000 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2017-14028—A Resource Exhaustion issue was discovered in Moxa NPort 5110 Version 2.2, NPort 5110 Version 2.4, NPort 5110 Version 2.6, NPort 5110 VersioEPSS 2.1%CVE-2019-7620—Logstash versions before 7.4.1 and 6.8.4 contain a denial of service flaw in the Logstash Beats input plugin. An unauthenticated user who isEPSS 2.1%CVE-2021-21375MEDIUMCrash in receiving updated SDP answer after initial SDP negotiation failedEPSS 2.1%CVE-2022-1797MEDIUMRockwell Automation Logix Controllers Uncontrolled Resource ConsumptionEPSS 2.1%CVE-2022-32790HIGHThis issue was addressed with improved checks. This issue is fixed in tvOS 15.5, watchOS 8.6, iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4,EPSS 2.1%CVE-2019-10936HIGHAffected devices improperly handle large amounts of specially crafted UDP packets. This could allow an unauthenticated remote attacker toEPSS 2.1%CVE-2024-35176MEDIUMREXML contains a denial of service vulnerabilityEPSS 2.1%CVE-2023-31418HIGHElasticsearch uncontrolled resource consumptionEPSS 2.1%CVE-2018-16470—There is a possible DoS vulnerability in the multipart parser in Rack before 2.0.6. Specially crafted requests can cause the multipart parseEPSS 2.0%CVE-2018-0309—A vulnerability in the implementation of a specific CLI command and the associated Simple Network Management Protocol (SNMP) MIB for Cisco NEPSS 2.0%CVE-2023-5157HIGHMariadb: node crashes with transport endpoint is not connected mysqld got signal 6EPSS 2.0%CVE-2018-3739—https-proxy-agent before 2.1.1 passes auth option to the Buffer constructor without proper sanitization, resulting in DoS and uninitialized EPSS 2.0%CVE-2025-53506HIGHApache Tomcat: DoS via excessive h2 streams at connection startEPSS 2.0%CVE-2023-21728HIGHWindows Netlogon Denial of Service VulnerabilityEPSS 2.0%CVE-2025-46392MEDIUMApache Commons Configuration: Uncontrolled Resource Consumption when loading untrusted configurations in 1.xEPSS 2.0%CVE-2020-3373HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software IP Fragment Memory Leak VulnerabilityEPSS 2.0%CVE-2025-26680HIGHWindows Standards-Based Storage Management Service Denial of Service VulnerabilityEPSS 2.0%CVE-2020-3254HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software Media Gateway Control Protocol Denial of Service VulnerabilitiesEPSS 2.0%CVE-2019-12658HIGHCisco IOS XE Software Filesystem Exhaustion Denial of Service VulnerabilityEPSS 2.0%CVE-2018-15388HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software WebVPN Denial of Service VulnerabilityEPSS 2.0%