Weaknesses of type CWE-400

2,995 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2023-49140HIGHDenial-of-service (DoS) vulnerability exists in commplex-link service of HMI GC-A2 series. If a remote unauthenticated attacker sends a specEPSS 1.0%CVE-2014-3648—The simplepush server iterates through the application installations and pushes a notification to the server provided by deviceToken. But thEPSS 1.0%CVE-2021-41546—A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.14.1), RUGGEDCOM ROX RX1400 (All versions < V2.14.1), RUGGEDCEPSS 1.0%CVE-2022-38100HIGHContec Health CMS8000EPSS 1.0%CVE-2023-25151HIGHDoS vulnerability for high cardinality metrics in opentelemetry-go-contribEPSS 1.0%CVE-2022-22161HIGHJunos OS: MX104 might become unresponsive if the out-of-band management port receives a flood of trafficEPSS 1.0%CVE-2024-29893MEDIUMUncontrolled Resource Consumption vulnerability in ArgoCD's repo serverEPSS 1.0%CVE-2023-41102HIGHAn issue was discovered in the captive portal in OpenNDS before version 10.1.3. It has multiple memory leaks due to not freeing up allocatedEPSS 1.0%CVE-2026-21945HIGHVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: SecuritEPSS 1.0%CVE-2023-20861—In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible fEPSS 1.0%CVE-2022-31075MEDIUMKubeEdge DoS when signing the CSR from EdgeCoreEPSS 1.0%CVE-2024-21057MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 aEPSS 1.0%CVE-2023-3398MEDIUMDenial of Service in jgraph/drawioEPSS 1.0%CVE-2018-15437MEDIUMCisco Immunet and Cisco AMP for Endpoints System Scan Denial of Service VulnerabilityEPSS 1.0%CVE-2024-28854HIGHSlow loris vulnerability with default configuration in tls-listenerEPSS 1.0%CVE-2023-37475HIGHAttacker-controlled parameter can cause denial of service in hamba avroEPSS 1.0%CVE-2021-0230HIGHJunos OS: SRX Series: Memory leak when querying Aggregated Ethernet (AE) interface statisticsEPSS 1.0%CVE-2021-23049—On BIG-IP version 16.0.x before 16.0.1.2 and 15.1.x before 15.1.3, when the iRules RESOLVER::summarize command is used on a virtual server, EPSS 1.0%CVE-2021-0233HIGHJunos OS: ACX500 Series, ACX4000 Series: Denial of Service due to FFEB crash while processing high rate of specific packets.EPSS 1.0%CVE-2021-3479—There's a flaw in OpenEXR's Scanline API functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to beEPSS 1.0%