Weaknesses of type CWE-400

2,995 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2019-13946HIGHProfinet-IO (PNIO) stack versions prior V06.00 do not properly limit internal resource allocation when multiple legitimate diagnostic packagEPSS 1.5%CVE-2022-39158MEDIUMA vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC,EPSS 1.5%CVE-2017-16023—Decamelize is used to convert a dash/dot/underscore/space separated string to camelCase. Decamelize 1.1.0 through 1.1.1 uses regular expressEPSS 1.5%CVE-2023-26144MEDIUMVersions of the package graphql from 16.3.0 and before 16.8.1 are vulnerable to Denial of Service (DoS) due to insufficient checks in the OvEPSS 1.5%CVE-2018-3767—`memjs` versions <= 1.1.0 allocates and stores buffers on typed input, resulting in DoS and uninitialized memory usage.EPSS 1.5%CVE-2019-13925—A vulnerability has been identified in SCALANCE S602 (All versions >= V3.0 and < V4.1), SCALANCE S612 (All versions >= V3.0 and < V4.1), SCAEPSS 1.5%CVE-2023-38200HIGHKeylime: registrar is subject to a dos against ssl connectionsEPSS 1.4%CVE-2022-3283HIGHA potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before before 15.2.5, all versions starting from 15.3 beEPSS 1.4%CVE-2024-24575HIGHlibgit2 is vulnerable to a denial of service attack in `git_revparse_single`EPSS 1.4%CVE-2023-27334HIGHSofting edgeConnector Siemens ConditionRefresh Resource Exhaustion Denial-of-Service VulnerabilityEPSS 1.4%CVE-2023-39180MEDIUMKernel: ksmbd: read request memory leak denial-of-service vulnerabilityEPSS 1.4%CVE-2024-22201HIGHJetty connection leaking on idle timeout when TCP congestedEPSS 1.4%CVE-2020-3528HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software OSPFv2 Link-Local Signaling Denial of Service VulnerabilityEPSS 1.4%CVE-2022-27194—A vulnerability has been identified in SIMATIC PCS neo (Administration Console) (All versions < V3.1 SP1), SINETPLAN (All versions), TIA PorEPSS 1.4%CVE-2021-34792HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software Resource Exhaustion Denial of Service VulnerabilityEPSS 1.4%CVE-2022-43766HIGHApache IoTDB prior to 0.13.3 allows DoSEPSS 1.4%CVE-2022-36064MEDIUMShescape Inefficient Regular Expression Complexity vulnerabilityEPSS 1.4%CVE-2021-32723HIGHRegular Expression Denial of Service (ReDoS) in PrismEPSS 1.4%CVE-2022-41404HIGHAn issue in the fetch() method in the BasicProfile class of org.ini4j through version v0.5.4 allows attackers to cause a Denial of Service (EPSS 1.4%CVE-2023-40584MEDIUMDenial of Service to Argo CD repo-server EPSS 1.4%