Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2020-3203HIGHCisco IOS XE Software Catalyst 9800 Series Wireless Controllers Denial of Service VulnerabilityEPSS 0.8%CVE-2022-41969LOWNextcloud Server has no password length limit when creating a user as an administratorEPSS 0.8%CVE-2022-24040—A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXEPSS 0.8%CVE-2023-21996HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affeEPSS 0.8%CVE-2023-21964HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.8%CVE-2026-39244HIGHadm-zip before 0.5.18 is vulnerable to denial of service via a crafted ZIP file with a manipulated uncompressed size header field. In zipEntEPSS 0.8%CVE-2022-4006LOWWBCE CMS Header class.login.php increase_attempts excessive authenticationEPSS 0.8%CVE-2024-21062MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.36 aEPSS 0.8%CVE-2026-27980MEDIUMNext.js: Unbounded next/image disk cache growth can exhaust storageEPSS 0.8%CVE-2023-41121—Array AG OS before 9.4.0.499 allows denial of service: remote attackers can cause system service processes to crash through abnormal HTTP opEPSS 0.8%CVE-2021-47023HIGHnet: marvell: prestera: fix port event handling on initEPSS 0.8%CVE-2021-38465HIGHAUVESY VersiondogEPSS 0.8%CVE-2022-35776MEDIUMAzure Site Recovery Denial of Service VulnerabilityEPSS 0.8%CVE-2026-45759HIGHSuricata http1: quadratic Content-Disposition processing can lead to denial of serviceEPSS 0.8%CVE-2021-23852MEDIUMDenial of Service (DoS) due to invalid web parameterEPSS 0.8%CVE-2022-37884HIGHA vulnerability exists in the ClearPass Policy Manager Guest User Interface that can allow an unauthenticated attacker to send specific operEPSS 0.8%CVE-2022-20960HIGHA vulnerability in Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated remote attacker to cause aEPSS 0.8%CVE-2022-23580MEDIUMAbort caused by allocating a vector that is too large in TensorflowEPSS 0.8%CVE-2024-41818HIGHReDOS at currency parsing fast-xml-parserEPSS 0.8%CVE-2023-50730HIGHGrackle has StackOverflowError in GraphQL query processingEPSS 0.8%