Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2023-35920HIGHA vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3.4), SIMATIC MV540 S (All versions < V3.3.4), SIMATIC MV550 H (AlEPSS 0.9%CVE-2023-20051MEDIUMCisco Packet Data Network Gateway IPsec ICMP Denial of Service VulnerabilityEPSS 0.9%CVE-2023-35921HIGHA vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3.4), SIMATIC MV540 S (All versions < V3.3.4), SIMATIC MV550 H (AlEPSS 0.9%CVE-2020-26302HIGHis.js is a general-purpose check library. Versions 0.9.0 and prior contain one or more regular expressions that are vulnerable to Regular ExEPSS 0.9%CVE-2026-68763HIGHApache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is resetEPSS 0.9%CVE-2022-32927HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16. Joining EPSS 0.9%CVE-2024-21185MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.38, 8.4.1 and EPSS 0.9%CVE-2023-25568HIGHBoxo bitswap/server: DOS unbounded persistent memory leakEPSS 0.9%CVE-2024-35270MEDIUMWindows iSCSI Service Denial of Service VulnerabilityEPSS 0.9%CVE-2024-12864HIGHUnauthenticated DoS by Sending Large Filename at File Upload Endpoint in netease-youdao/qanythingEPSS 0.9%CVE-2024-12070HIGHDenial of Service in haotian-liu/llavaEPSS 0.9%CVE-2023-21838HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.9%CVE-2024-21194MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.39 and prior, 8EPSS 0.9%CVE-2022-24035HIGHAn issue was discovered in ONOS 2.5.1. The purge-requested intent remains on the list, but it does not respond to changes in topology (e.g.,EPSS 0.9%CVE-2022-2406MEDIUMMalicious imports can lead to Denial of ServiceEPSS 0.9%CVE-2018-0441HIGHCisco IOS Access Points Software 802.11r Fast Transition Denial of Service VulnerabilityEPSS 0.9%CVE-2022-24109MEDIUMAn issue was discovered in ONOS 2.5.1. To attack an intent installed by a normal user, a remote attacker can install a duplicate intent withEPSS 0.9%CVE-2023-26470MEDIUMIn XWiki Platform, saving a document with a large object number leads to persistent OOM errorsEPSS 0.9%CVE-2026-66143HIGHApache Neethi: Missing global alternative-output budget across policy computation pathsEPSS 0.9%CVE-2024-47850HIGHCUPS cups-browsed before 2.5b1 will send an HTTP POST request to an arbitrary destination and port in response to a single IPP UDP packet reEPSS 0.9%