Weaknesses of type CWE-770

1,861 results

Alocação irrestrita de recursos

É quando a aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem limites, permitindo que um atacante esgote os recursos disponíveis do servidor. O código não valida quantidade nem tamanho, criando uma porta aberta para negação de serviço.

Example

Um endpoint HTTP que processa uploads sem validar tamanho máximo: um atacante envia múltiplos arquivos gigantes ou faz requisições em loop, consumindo toda a memória/disco até o servidor ficar indisponível para usuários legítimos.

How to mitigate

Implemente cotas e limites: defina tamanho máximo de upload, máximo de conexões por cliente, timeout para operações, e use rate limiting. Monitore consumo de recursos e rejeite requisições que violem as políticas de limite.

CVE-2026-42626MEDIUMHP ENVY 5000 series printers VERBASPP1N003.2237A.00 do not properly manage concurrent TCP connections to port 9100 (JetDirect/RAW printing).EPSS 0.2%CVE-2026-11993MEDIUMFix authenticated members disabling file content indexing server-wide via extraction pool exhaustionEPSS 0.2%CVE-2026-20406MEDIUMIn Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if a UE has connected EPSS 0.2%CVE-2026-59303LOWDynamic destination cache size is not properly bound in Spring Cloud StreamEPSS 0.2%CVE-2026-10573MEDIUM1734 POINT I/OTM - Denial of Service via Malformed Inputs on CIP ObjectEPSS 0.2%CVE-2025-12748MEDIUMLibvirt: denial of service in xml parsingEPSS 0.2%CVE-2022-49035MEDIUMmedia: s5p_cec: limit msg.len to CEC_MAX_MSG_SIZEEPSS 0.2%CVE-2022-28655HIGHis_closing_session() allows users to create arbitrary tcp dbus connectionsEPSS 0.2%CVE-2025-30409MEDIUMDenial of service due to allocation of resources without limits. The following products are affected: Acronis Cyber Protect Cloud Agent (WinEPSS 0.2%CVE-2024-39876MEDIUMA vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected applications do not properly handle EPSS 0.2%CVE-2025-11274MEDIUMOpen Asset Import Library Assimp Q3DLoader.cpp InternReadFile allocation of resourcesEPSS 0.2%CVE-2022-41288LOWA vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), TeamcenEPSS 0.2%CVE-2022-22240MEDIUMJunos OS and Junos OS Evolved: An rpd memory leak might be observed while running a specific cli command in a RIB sharding scenarioEPSS 0.2%CVE-2022-42531HIGHIn mmu_map_for_fw of gs_ldfw_load.c, there is a possible mitigation bypass due to Permissive Memory Allocation. This could lead to local escEPSS 0.2%CVE-2022-28656MEDIUMis_closing_session() allows users to consume RAM in the Apport processEPSS 0.2%CVE-2025-40570LOWA vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V10.0), SIPROTEC 5 6MD85 (CP300) (All versions >= V7.80 < V1EPSS 0.2%CVE-2023-38532MEDIUMA vulnerability has been identified in Parasolid V34.1 (All versions < V34.1.258), Parasolid V35.0 (All versions < V35.0.254), Parasolid V35EPSS 0.2%CVE-2025-37805MEDIUMsound/virtio: Fix cancel_sync warnings on uninitialized work_structsEPSS 0.2%CVE-2020-37139MEDIUMOdin Secure FTP Expert 7.6.3 - 'Site Info' Denial of ServiceEPSS 0.2%CVE-2025-48462MEDIUMLogin Session ExhaustionEPSS 0.2%