Weaknesses of type CWE-400

2,995 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2021-0202HIGHJunos OS: MX Series, EX9200 Series: Trio-based MPC memory leak when Integrated Routing and Bridging (IRB) interface is mapped to a VPLS instance or a Bridge-DomainEPSS 1.0%CVE-2024-20978MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 aEPSS 1.0%CVE-2024-8184MEDIUMJetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacksEPSS 1.0%CVE-2023-26485MEDIUMQuadratic complexity may lead to a denial of service in cmark-gfmEPSS 1.0%CVE-2020-1901—Receiving a large text message containing URLs in WhatsApp for iOS prior to v2.20.91.4 could have caused the application to freeze while proEPSS 1.0%CVE-2023-26151MEDIUMVersions of the package asyncua before 0.9.96 are vulnerable to Denial of Service (DoS) such that an attacker can send a malformed packet anEPSS 1.0%CVE-2023-30999HIGHIBM Security Access Manager denial of serviceEPSS 1.0%CVE-2023-42031MEDIUMIBM CICS TX denial of serviceEPSS 1.0%CVE-2023-40408—An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.1, watchOS 10.1, iEPSS 1.0%CVE-2022-20808HIGHCisco Smart Software Manager On-Prem Denial of Service VulnerabilityEPSS 1.0%CVE-2024-20964MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected aEPSS 1.0%CVE-2022-27508HIGHUnauthenticated denial of service EPSS 1.0%CVE-2021-22964—A redirect vulnerability in the `fastify-static` module version >= 4.2.4 and < 4.4.1 allows remote attackers to redirect Mozilla Firefox useEPSS 1.0%CVE-2023-42457HIGHplone.rest vulnerable to Denial of Service when ++api++ is used many timesEPSS 1.0%CVE-2022-23492HIGHgo-libp2p denial of service vulnerability from lack of resource managementEPSS 1.0%CVE-2021-32816MEDIUMRegular expression Denial of Service in ProtonMailEPSS 1.0%CVE-2024-38027MEDIUMWindows Line Printer Daemon Service Denial of Service VulnerabilityEPSS 1.0%CVE-2026-42579HIGHNetty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder)EPSS 1.0%CVE-2022-0476HIGHDenial of Service in radareorg/radare2EPSS 1.0%CVE-2024-10599MEDIUMTongda OA 2017 package_static_resources.php resource consumptionEPSS 1.0%