Weaknesses of type CWE-400

3,000 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2023-35339HIGHWindows CryptoAPI Denial of Service VulnerabilityEPSS 1.9%CVE-2020-26264MEDIUMLES Server DoS via GetProofsV2EPSS 1.9%CVE-2018-10924MEDIUMIt was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch aEPSS 1.9%CVE-2019-12700HIGHCisco FTD, FMC, and FXOS Software Pluggable Authentication Module Denial of Service VulnerabilityEPSS 1.9%CVE-2026-34473HIGHUnauthenticated DoS in ZTE H8102E, H168N, H167A, H199A, H288A, H198A, H267A, H267N, H268A, H388X, H196A, H369A, H268N, H208N, H367N, H181A, EPSS 1.9%CVE-2024-12254HIGHUnbounded memory buffering in SelectorSocketTransport.writelines()EPSS 1.9%CVE-2021-32823LOWPotential Denial-of-Service in bindataEPSS 1.9%CVE-2021-32838HIGHRegular Expression Denial of Service in flask-restxEPSS 1.9%CVE-2020-3529HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software SSL VPN Direct Memory Access Denial of Service VulnerabilityEPSS 1.9%CVE-2017-15133—A denial of service flaw was found in miekg-dns before 1.0.4. A remote attacker could use carefully timed TCP packets to block the DNS serveEPSS 1.9%CVE-2025-24190CRITICALThe issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, mEPSS 1.9%CVE-2025-24211CRITICALThis issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, EPSS 1.9%CVE-2022-1210MEDIUMLibTIFF tiff2ps resource consumptionEPSS 1.9%CVE-2018-10935MEDIUMA flaw was found in the 389 Directory Server that allows users to cause a crash in the LDAP server using ldapsearch with server side sort.EPSS 1.8%CVE-2018-15399—Cisco Adaptive Security Appliance TCP Syslog Denial of Service VulnerabilityEPSS 1.8%CVE-2020-3255HIGHCisco Firepower Threat Defense Software Packet Flood Denial of Service VulnerabilityEPSS 1.8%CVE-2020-3189HIGHCisco Firepower Threat Defense Software VPN System Logging Denial of Service VulnerabilityEPSS 1.8%CVE-2021-21328MEDIUMDenial of ServiceEPSS 1.8%CVE-2018-16489—A prototype pollution vulnerability was found in just-extend <4.0.0 that allows attack to inject properties onto Object.prototype through itEPSS 1.8%CVE-2023-0056MEDIUMAn uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenEPSS 1.8%