Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2021-3478—There's a flaw in OpenEXR's scanline input file functionality in versions before 3.0.0-beta. An attacker able to submit a crafted file to beEPSS 1.0%CVE-2024-0842HIGHBackuply - Backup, Restore, Migrate and Clone <= 1.2.6 - Denial of ServiceEPSS 1.0%CVE-2022-42950MEDIUMAn issue was discovered in Couchbase Server 7.x before 7.0.5 and 7.1.x before 7.1.2. A crafted HTTP REST request from an administrator accouEPSS 1.0%CVE-2024-32663HIGHSuricata 's http2 parser contains an improper compressed header handling can lead to resource starvationEPSS 1.0%CVE-2023-22484LOWInefficient Quadratic complexity bug in handle_pointy_brace may lead to a denial of serviceEPSS 1.0%CVE-2022-0695MEDIUMDenial of Service in radareorg/radare2EPSS 1.0%CVE-2023-30635HIGHTiKV 6.1.2 allows remote attackers to cause a denial of service (fatal error) upon an attempt to get a timestamp from the Placement Driver.EPSS 1.0%CVE-2023-20125HIGHCisco BroadWorks Network Server TCP Denial of Service VulnerabilityEPSS 1.0%CVE-2023-40583HIGHlibp2p nodes vulnerable to OOM attackEPSS 1.0%CVE-2022-3509HIGHParsing issue in protobuf textformatEPSS 1.0%CVE-2024-21218MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.39 and prior, 8EPSS 0.9%CVE-2024-21219MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.39 and priEPSS 0.9%CVE-2026-42304HIGHTwisted: Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer ChainsEPSS 0.9%CVE-2022-28204HIGHA denial-of-service issue was discovered in MediaWiki 1.37.x before 1.37.2. Rendering of w/index.php?title=Special%3AWhatLinksHere&target=PrEPSS 0.9%CVE-2023-5759HIGHUnauthenticated Remote Denial-of-Service via Buffer in Helix CoreEPSS 0.9%CVE-2023-35767HIGHUnauthenticated Remote Denial-of-Service via Shutdown Function in Helix CoreEPSS 0.9%CVE-2022-27889MEDIUMThe Foundry Multipass service contains code paths that could be abused to cause a denial of service for authentication and authorization operations.EPSS 0.9%CVE-2021-21565MEDIUMDell PowerScale OneFS versions 9.1.0.3 and earlier contain a denial of service vulnerability. SmartConnect had an error condition that may bEPSS 0.9%CVE-2022-36114MEDIUMExtracting malicious crates can fill the file systemEPSS 0.9%CVE-2023-45319HIGHUnauthenticated Remote Denial-of-Service (Commit) in Helix Core EPSS 0.9%