Weaknesses of type CWE-770
1,861 resultsAlocação irrestrita de recursos
É quando a aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem limites, permitindo que um atacante esgote os recursos disponíveis do servidor. O código não valida quantidade nem tamanho, criando uma porta aberta para negação de serviço.
Example
Um endpoint HTTP que processa uploads sem validar tamanho máximo: um atacante envia múltiplos arquivos gigantes ou faz requisições em loop, consumindo toda a memória/disco até o servidor ficar indisponível para usuários legítimos.
How to mitigate
Implemente cotas e limites: defina tamanho máximo de upload, máximo de conexões por cliente, timeout para operações, e use rate limiting. Monitore consumo de recursos e rejeite requisições que violem as políticas de limite.
CVE-2026-96609HIGHRobur Albatross 1.0.0 through 2.x before 2.7.2 does not limit use of the ring buffer, leading to an albatross-console loop with no recognizeEPSS 0.2%CVE-2025-5683MEDIUMWhen loading a specifically crafted ICNS format image file in QImage then it will trigger a crash.
This issue affects Qt from versions 6.3EPSS 0.2%CVE-2024-50271MEDIUMsignal: restore the override_rlimit logicEPSS 0.2%CVE-2021-47784MEDIUMCyberfox Web Browser 52.9.1 - Denial of Service (PoC)EPSS 0.2%CVE-2023-32385—A denial-of-service issue was addressed with improved memory handling. This issue is fixed in iOS 16.5 and iPadOS 16.5, macOS Ventura 13.4. EPSS 0.2%CVE-2023-52529MEDIUMHID: sony: Fix a potential memory leak in sony_probe()EPSS 0.2%CVE-2026-10533MEDIUMOpenshift: openshift: non-admin user can bypass resourcequota and flood etcd with events causing cluster-wide api degradationEPSS 0.2%CVE-2025-21866MEDIUMpowerpc/code-patching: Fix KASAN hit by not flagging text patching area as VM_ALLOCEPSS 0.2%CVE-2024-6176MEDIUMPort scanning vulnerability in LG SuperSign CMSEPSS 0.2%CVE-2024-58089HIGHbtrfs: fix double accounting race when btrfs_run_delalloc_range() failedEPSS 0.2%CVE-2024-26276MEDIUMA vulnerability has been identified in JT2Go (All versions < V2312.0004), Parasolid V35.1 (All versions < V35.1.254), Parasolid V36.0 (All vEPSS 0.2%CVE-2024-56722MEDIUMRDMA/hns: Fix cpu stuck caused by printings during resetEPSS 0.2%CVE-2021-47057MEDIUMcrypto: sun8i-ss - Fix memory leak of object d when dma_iv fails to mapEPSS 0.2%CVE-2023-28428MEDIUMPDFio vulnerable to Denial Of Service when opening a corrupt PDF fileEPSS 0.2%CVE-2025-14341HIGHInput Data Manipulation in DivvyDrive Information Technologies' DivvyDriveEPSS 0.2%CVE-2021-1121MEDIUMNVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager kernel driver, where a vGPU can cause resource starvation among othEPSS 0.2%CVE-2025-21690MEDIUMscsi: storvsc: Ratelimit warning logs to prevent VM denial of serviceEPSS 0.2%CVE-2024-25969MEDIUMDell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an allocation of resources without limits or throttling vulnerability. A localEPSS 0.2%CVE-2025-1823LOWIBM Jazz Reporting Service Denial of ServiceEPSS 0.2%CVE-2024-45484HIGHEnabled ICMP redirection in B&R APROLEPSS 0.2%