Weaknesses of type CWE-770

1,861 results

Alocação irrestrita de recursos

É quando a aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem limites, permitindo que um atacante esgote os recursos disponíveis do servidor. O código não valida quantidade nem tamanho, criando uma porta aberta para negação de serviço.

Example

Um endpoint HTTP que processa uploads sem validar tamanho máximo: um atacante envia múltiplos arquivos gigantes ou faz requisições em loop, consumindo toda a memória/disco até o servidor ficar indisponível para usuários legítimos.

How to mitigate

Implemente cotas e limites: defina tamanho máximo de upload, máximo de conexões por cliente, timeout para operações, e use rate limiting. Monitore consumo de recursos e rejeite requisições que violem as políticas de limite.

CVE-2025-21494MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected aEPSS 0.3%CVE-2026-47859MEDIUMUnbounded memory allocation in RFC6587SyslogDeserializer (octet-counted framing) — remote DoSEPSS 0.3%CVE-2025-36008MEDIUMIBM Db2 denial of serviceEPSS 0.3%CVE-2021-47551HIGHdrm/amd/amdkfd: Fix kernel panic when reset failed and been triggered againEPSS 0.3%CVE-2023-29570MEDIUMCesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_ffi_cb_free at src/mjs_ffi.c. This vulnerability can lead to a DeEPSS 0.3%CVE-2020-36943MEDIUMaSc TimeTables 2021.6.2 - Denial of ServiceEPSS 0.3%CVE-2021-47894MEDIUMManaged Switch Port Mapping Tool 2.85.2 - Denial of ServiceEPSS 0.3%CVE-2021-47893MEDIUMAgataSoft PingMaster Pro 2.1 - Denial of ServiceEPSS 0.3%CVE-2025-43736MEDIUMA Denial Of Service via File Upload (DOS) vulnerability in the Liferay Portal 7.4.3.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2EPSS 0.3%CVE-2025-36140MEDIUMIBM watsonx.data Denial of ServiceEPSS 0.3%CVE-2026-27663HIGHA vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.10), RTUM85 RTU Base (All versions < V26.EPSS 0.3%CVE-2026-24738MEDIUMgmrtd ReadFile Vulnerable to Denial of Service via Excessive TLV Length ValuesEPSS 0.3%CVE-2026-40990MEDIUMUnbounded cache for function definitionsEPSS 0.3%CVE-2026-30961MEDIUMGokapi's File Request MaxSize Limit Bypassed via Multi-Chunk UploadEPSS 0.3%CVE-2024-52917MEDIUMBitcoin Core before 22.0 has a miniupnp infinite loop in which it allocates memory on the basis of random data received over the network, e.EPSS 0.3%CVE-2026-66080MEDIUMRabbitMQ: Super-stream partitions unbounded allocationEPSS 0.3%CVE-2024-48843HIGHDenial of Service, DoSEPSS 0.3%CVE-2024-4029MEDIUMWildfly: no timeout for eap management interface may lead to denial of service (dos)EPSS 0.3%CVE-2022-20489HIGHIn many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This couEPSS 0.3%CVE-2021-47877MEDIUMGeoGebra Graphing Calculato‪r‬ 6.0.631.0 - Denial Of ServiceEPSS 0.3%