Weaknesses of type CWE-400

2,993 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2014-2342—Triangle MicroWorks SCADA Data Gateway Resource ExhaustionEPSS 1.8%CVE-2020-3572HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software SSL/TLS Session Denial of Service VulnerabilityEPSS 1.8%CVE-2023-35298HIGHHTTP.sys Denial of Service VulnerabilityEPSS 1.8%CVE-2019-3874MEDIUMThe SCTP socket buffer used by a userspace application is not accounted by the cgroups subsystem. An attacker can use this flaw to cause a dEPSS 1.8%CVE-2024-23443MEDIUMA high-privileged user, allowed to create custom osquery packs 17 could affect the availability of Kibana by uploading a maliciously craftedEPSS 1.8%CVE-2020-3533HIGHCisco Firepower Threat Defense Software SNMP Denial of Service VulnerabilityEPSS 1.8%CVE-2018-13296HIGHUncontrolled resource consumption vulnerability in TLS configuration in Synology MailPlus Server before 2.0.5-0606 allows remote attackers tEPSS 1.8%CVE-2016-10540—Minimatch is a minimal matching utility that works by converting glob expressions into JavaScript `RegExp` objects. The primary function, `mEPSS 1.8%CVE-2017-16114—The marked module is vulnerable to a regular expression denial of service. Based on the information published in the public issue, 1k characEPSS 1.8%CVE-2026-26171HIGH.NET Denial of Service VulnerabilityEPSS 1.8%CVE-2025-33068HIGHWindows Standards-Based Storage Management Service Denial of Service VulnerabilityEPSS 1.8%CVE-2024-33655HIGHThe DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS quEPSS 1.7%CVE-2022-40617HIGHstrongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and iEPSS 1.7%CVE-2021-21271MEDIUMDenial of service in TenderMint CoreEPSS 1.7%CVE-2021-41115MEDIUMRegular expression denial-of-service in ZulipEPSS 1.7%CVE-2023-21543HIGHWindows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution VulnerabilityEPSS 1.7%CVE-2023-42669MEDIUMSamba: "rpcecho" development server allows denial of service via sleep() call on ad dcEPSS 1.7%CVE-2019-19300HIGHA vulnerability has been identified in Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200, Development/Evaluation Kits for PROFINET IEPSS 1.7%CVE-2018-16491—A prototype pollution vulnerability was found in node.extend <1.1.7, ~<2.0.1 that allows an attacker to inject arbitrary properties onto ObjEPSS 1.7%CVE-2019-18336HIGHA vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions < V3.X.17), SIEPSS 1.7%