Weaknesses of type CWE-400

2,995 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2023-34458HIGHmx-chain-go's relayed transactions always increment nonceEPSS 1.3%CVE-2020-3190MEDIUMCisco IOS XR Software IPsec Packet Processor Denial of Service VulnerabilityEPSS 1.3%CVE-2021-22882—UniFi Protect before v1.17.1 allows an attacker to use spoofed cameras to perform a denial-of-service attack that may cause the UniFi ProtecEPSS 1.3%CVE-2024-47554MEDIUMApache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReaderEPSS 1.3%CVE-2001-0827HIGHCerberus FTP server 1.0 - 1.5 allows remote attackers to cause a denial of service (crash) via a large number of "PASV" requests.EPSS 1.3%CVE-2021-1460MEDIUMCisco IOx Application Framework Denial of Service VulnerabilityEPSS 1.3%CVE-2022-1259—A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial EPSS 1.3%CVE-2023-3637MEDIUMOpenstack-neutron: unrestricted creation of security groups (fix for cve-2022-3277)EPSS 1.3%CVE-2023-30798HIGHMultipartParser DOS with too many fields or files in Starlette FrameworkEPSS 1.3%CVE-2021-25909HIGHZIV AUTOMATION 4CCT Denial of Service vulnerabilityEPSS 1.3%CVE-2023-35945HIGHEnvoy vulnerable to HTTP/2 memory leak in nghttp2 codecEPSS 1.3%CVE-2021-42521—There is a NULL pointer dereference vulnerability in VTK before 9.2.5, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. The vendor didn't cheEPSS 1.3%CVE-2014-10064—The qs module before 1.0.0 does not have an option or default for specifying object depth and when parsing a string representing a deeply neEPSS 1.3%CVE-2019-5445—DoS in EdgeMAX EdgeSwitch prior to 1.8.2 allow an Admin user to Crash the SSH CLI interface by using crafted commands.EPSS 1.3%CVE-2024-41123MEDIUMREXML DoS vulnerabilityEPSS 1.3%CVE-2020-36620LOWBrondahl EnumStringValues EnumExtensions.cs GetStringValuesWithPreferences_Uncache resource consumptionEPSS 1.3%CVE-2021-39295HIGHIn OpenBMC 2.9, crafted IPMI messages allow an attacker to cause a denial of service to the BMC via the netipmid (IPMI lan+) interface.EPSS 1.3%CVE-2022-32508HIGHAn issue was discovered on certain Nuki Home Solutions devices. By sending a malformed HTTP verb, it is possible to force a reboot of the deEPSS 1.3%CVE-2024-32007HIGHApache CXF Denial of Service vulnerability in JOSEEPSS 1.3%CVE-2020-7507—A CWE-400: Uncontrolled Resource Consumption vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an atEPSS 1.3%