Weaknesses of type CWE-400

2,994 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2021-29509HIGHKeepalive Connections Causing Denial Of Service in pumaEPSS 1.6%CVE-2023-5724HIGHDrivers are not always robust to extremely large draw calls and in some cases this scenario could have led to a crash. This vulnerability afEPSS 1.6%CVE-2016-10527—The riot-compiler version version 2.3.21 has an issue in a regex (Catastrophic Backtracking) thats make it unusable under certain conditionsEPSS 1.6%CVE-2022-20760HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software DNS Inspection Denial of Service VulnerabilityEPSS 1.6%CVE-2022-24726HIGHUnauthenticated control plane denial of service attack in IstioEPSS 1.6%CVE-2022-4899HIGHA vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause bufferEPSS 1.6%CVE-2018-15377—Cisco IOS and IOS XE Software Plug and Play Agent Memory Leak VulnerabilityEPSS 1.6%CVE-2019-18904MEDIUMMigrations requests can cause DoS on rmtEPSS 1.6%CVE-2017-16099—The no-case module is vulnerable to regular expression denial of service. When malicious untrusted user input is passed into no-case it can EPSS 1.6%CVE-2017-16119—Fresh is a module used by the Express.js framework for HTTP response freshness testing. It is vulnerable to a regular expression denial of sEPSS 1.6%CVE-2017-16117—slug is a module to slugify strings, even if they contain unicode. slug is vulnerable to regular expression denial of service is specially cEPSS 1.6%CVE-2017-16013—hapi is a web and services application framework. When hapi >= 15.0.0 <= 16.1.0 encounters a malformed `accept-encoding` header an uncaught EPSS 1.6%CVE-2022-29225HIGHZip bomb vulnerability in EnvoyEPSS 1.6%CVE-2023-2295HIGHA vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unEPSS 1.6%CVE-2023-32067HIGH0-byte UDP payload DoS in c-aresEPSS 1.6%CVE-2019-0033HIGHSRX Series: A remote attacker may cause a high CPU Denial of Service to the device when proxy ARP is configured.EPSS 1.6%CVE-2022-31054HIGHUses of deprecated API can be used to cause DoS in user-facing endpoints in Argo EventsEPSS 1.6%CVE-2019-6578—A vulnerability has been identified in SINAMICS PERFECT HARMONY GH180 with NXG I control, MLFBs: 6SR2...-, 6SR3...-, 6SR4...- (All Versions EPSS 1.6%CVE-2019-10948—Fujifilm FCR Capsula X/ Carbon X/ FCR XC-2, model versions CR-IR 357 FCR Carbon X, CR-IR 357 FCR XC-2, FCR-IR 357 FCR Capsula X are susceptiEPSS 1.6%CVE-2020-3181MEDIUMCisco Email Security Appliance Uncontrolled Resource Exhaustion VulnerabilityEPSS 1.6%