Fallos del tipo CWE-399

160 resultados

Erros de Gerenciamento de Recursos

Fraqueza genérica que abrange falhas na alocação, uso e liberação de recursos do sistema (memória, conexões, arquivos, sockets). O código não rastreia ou libera corretamente esses recursos, causando vazamentos, esgotamento ou acesso inválido que leva a crash, negação de serviço ou exploração.

Ejemplo

Um servidor web abre uma conexão com banco de dados para cada requisição, mas não a fecha se uma exceção ocorre no meio do processamento. Após centenas de requisições, todas as conexões disponíveis estão em uso e novas requisições falham. Um atacante pode disparar requisições malformadas para manter conexões abertas indefinidamente.

Cómo mitigar

Use padrões de limpeza automática (try-finally, context managers em Python, using em C#) para garantir liberação de recursos mesmo em erro. Implemente timeouts, limites de recursos por processo e monitoramento de vazamento. Audite rotineiramente código que abre/fecha conexões, arquivos ou aloca memória.

CVE-2017-6613A vulnerability in the DNS input packet processor for Cisco Prime Network Registrar could allow an unauthenticated, remote attacker to causeEPSS 2.0%CVE-2017-6779Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco collaboration productEPSS 2.0%CVE-2019-12646HIGHCisco IOS XE Software NAT Session Initiation Protocol Application Layer Gateway Denial of Service VulnerabilityEPSS 2.0%CVE-2019-15256HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software IKEv1 Denial of Service VulnerabilityEPSS 2.0%CVE-2019-1635HIGHCisco IP Phone 7800 Series and 8800 Series Session Initiation Protocol XML Denial of Service VulnerabilityEPSS 2.0%CVE-2019-1957MEDIUMCisco IoT Field Network Director TLS Renegotiation Denial of Service VulnerabilityEPSS 2.0%CVE-2020-3499HIGHCisco Firepower Management Center Software Denial of Service VulnerabilityEPSS 2.0%CVE-2021-1313HIGHCisco IOS XR Software Enf Broker Denial of Service VulnerabilityEPSS 2.0%CVE-2021-1288HIGHCisco IOS XR Software Enf Broker Denial of Service VulnerabilityEPSS 2.0%CVE-2022-20653HIGHCisco Email Security Appliance DNS Verification Denial of Service VulnerabilityEPSS 1.8%CVE-2018-0164A vulnerability in the Switch Integrated Security Features of Cisco IOS XE Software could allow an unauthenticated, remote attacker to causeEPSS 1.8%CVE-2017-6625A "Cisco Firepower Threat Defense 6.0.0 through 6.2.2 and Cisco ASA with FirePOWER Module Denial of Service" vulnerability in the access conEPSS 1.8%CVE-2019-12659MEDIUMCisco IOS XE Software HTTP Server Denial of Service VulnerabilityEPSS 1.8%CVE-2018-15396Cisco Unity Connection File Upload Denial of Service VulnerabilityEPSS 1.8%CVE-2017-6631A vulnerability in the HTTP remote procedure call (RPC) service of set-top box (STB) receivers manufactured by Cisco for Yes could allow an EPSS 1.7%CVE-2017-6780A vulnerability in the TCP throttling process for Cisco IoT Field Network Director (IoT-FND) could allow an unauthenticated, remote attackerEPSS 1.7%CVE-2017-6678A vulnerability in the ingress UDP packet processing functionality of Cisco Virtualized Packet Core-Distributed Instance (VPC-DI) Software 1EPSS 1.7%CVE-2020-3188MEDIUMCisco Firepower Threat Defense Software Management Interface Denial of Service VulnerabilityEPSS 1.7%CVE-2018-0457Cisco Webex Player WRF Files Denial of Service VulnerabilityEPSS 1.7%CVE-2017-3793A vulnerability in the TCP normalizer of Cisco Adaptive Security Appliance (ASA) Software (8.0 through 8.7 and 9.0 through 9.6) and Cisco FiEPSS 1.7%