Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2022-41861MEDIUMA flaw was found in freeradius. A malicious RADIUS client or home server can send a malformed abinary attribute which can cause the server tEPSS 1.1%CVE-2024-0241HIGHencoded_id-rails Denial of Service VulnerabilityEPSS 1.1%CVE-2024-4549HIGHDelta Electronics DIAEnergie SQL Injection EPSS 1.1%CVE-2023-22486LOWcmark-gfm Quadratic complexity bug in handle_close_bracket may lead to a denial of serviceEPSS 1.1%CVE-2022-33142HIGHWordPress Better Messages plugin <= 1.9.10.57 - Denial Of Service (DoS) vulnerabilityEPSS 1.1%CVE-2024-20961MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 aEPSS 1.1%CVE-2022-31006HIGHHyperledger Indy DOS vulnerabilityEPSS 1.1%CVE-2024-20985MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: UDF). Supported versions that are affected are 8.0.35 and priEPSS 1.1%CVE-2018-10868—redhat-certification 7 does not properly restrict the number of recursive definitions of entities in XML documents, allowing an unauthenticaEPSS 1.1%CVE-2022-2455MEDIUMA business logic issue in the handling of large repositories in all versions of GitLab CE/EE from 10.0 before 15.1.6, all versions starting EPSS 1.1%CVE-2023-42670MEDIUMSamba: ad dc busy rpc multiple listener dosEPSS 1.1%CVE-2018-16490—A prototype pollution vulnerability was found in module mpath <0.5.1 that allows an attacker to inject arbitrary properties onto Object.protEPSS 1.1%CVE-1999-0159LOWAttackers can crash a Cisco IOS router or device, provided they can get to an interactive prompt (such as a login). This applies to some IOEPSS 1.1%CVE-2026-25673HIGHPotential denial-of-service vulnerability in URLField via Unicode normalization on WindowsEPSS 1.1%CVE-2021-26260—An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could EPSS 1.1%CVE-2024-20976MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 aEPSS 1.1%CVE-2018-7821HIGHAn Environment (CWE-2) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmwarEPSS 1.1%CVE-2024-20972MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 aEPSS 1.1%CVE-2024-49767MEDIUMWerkzeug possible resource exhaustion when parsing file data in formsEPSS 1.1%CVE-2022-22275—Improper Restriction of TCP Communication Channel in HTTP/S inbound traffic from WAN to DMZ bypassing security policy until TCP handshake poEPSS 1.1%