Weaknesses of type CWE-400

3,000 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2022-21360MEDIUMVulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions thEPSS 3.5%CVE-2023-5685HIGHXnio: stackoverflowexception when the chain of notifier states becomes problematically bigEPSS 3.5%CVE-2022-21299MEDIUMVulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that EPSS 3.5%CVE-2025-5115HIGHMadeYouReset HTTP/2 vulnerabilityEPSS 3.5%CVE-2026-33623MEDIUMPinchTab: OS Command Injection via Profile Name in Windows Cleanup Routine Enables Arbitrary Command ExecutionEPSS 3.4%CVE-2009-2541HIGHThe web browser on the Sony PLAYSTATION 3 (PS3) allows remote attackers to cause a denial of service (memory consumption and console hang) vEPSS 3.4%CVE-2021-21252MEDIUMRegular expression denial of service in jquery-validationEPSS 3.4%CVE-2020-15166HIGHDenial of Service in ZeroMQEPSS 3.4%CVE-2019-10953HIGHABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some conEPSS 3.4%CVE-2017-15119MEDIUMThe Network Block Device (NBD) server in Quick Emulator (QEMU) before 2.11 is vulnerable to a denial of service issue. It could occur if a cEPSS 3.3%CVE-2020-3569HIGHCisco IOS XR Software DVMRP Memory Exhaustion VulnerabilitiesEPSS 3.3%KEVCVE-2017-12741HIGHSpecially crafted packets sent to port 161/udp could cause a denial of service condition. The affected devices must be restarted manually.EPSS 3.3%CVE-2021-33580—regex injection leading to DoSEPSS 3.3%CVE-2021-21285MEDIUMDocker daemon crash during image pull of malicious imageEPSS 3.3%CVE-2021-20609HIGHUncontrolled Resource Consumption vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/08/16/32/120(EPSS 3.3%CVE-2023-26048MEDIUMOutOfMemoryError for large multipart without filename in Eclipse JettyEPSS 3.3%CVE-2020-27827HIGHA flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to hanEPSS 3.2%CVE-2018-6922—One of the data structures that holds TCP segments in all versions of FreeBSD prior to 11.2-RELEASE-p1, 11.1-RELEASE-p12, and 10.4-RELEASE-pEPSS 3.2%CVE-2022-21366MEDIUMVulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions thEPSS 3.2%CVE-2018-10607—Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior allow the creation of new connections to one or more EPSS 3.2%