Fallos del tipo CWE-400

3039 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2024-57074HIGHA prototype pollution in the lib.merge function of xe-utils v3.5.31 allows attackers to cause a Denial of Service (DoS) via supplying a crafEPSS 0.4%CVE-2024-24424HIGHA reachable assertion in the decode_access_point_name_ie function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2EPSS 0.4%CVE-2026-41310MEDIUMOpenTelemetry .NET Zipkin exporter has unbounded remote endpoint cache leading to memory growthEPSS 0.4%CVE-2026-55594MEDIUMImageMagick: Stack Overflow in MVG decoder due to missing depth check.EPSS 0.4%CVE-2023-40594MEDIUMDenial of Service (DoS) via the ‘printf’ Search FunctionEPSS 0.4%CVE-2024-38826MEDIUMCVE-2024-38826 Cloud Controller Denial of Service AttackEPSS 0.4%CVE-2024-52974MEDIUMAn issue has been identified where a specially crafted request sent to an Observability API could cause the kibana server to crash. A succeEPSS 0.4%CVE-2025-55128MEDIUMHackerOne community member Dang Hung Vi (vidang04) has reported an uncontrolled resource consumption vulnerability in the “userlog-index.phpEPSS 0.4%CVE-2024-0157MEDIUMDell Storage Resource Manager, 4.9.0.0 and below, contain(s) a Session Fixation Vulnerability in SRM Windows Host Agent. An adjacent networkEPSS 0.4%CVE-2026-52687MEDIUMAn attacker that has valid credentials can select a compression algorithm for the IMAP connection whose decompression state requires a largeEPSS 0.4%CVE-2025-55588HIGHTOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the fw_ip parameter at /boafrm/formPortFw. This vulneraEPSS 0.4%CVE-2026-83345HIGHVulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install). Supported versions that are affected are 1EPSS 0.4%CVE-2025-55586HIGHTOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the url parameter at /boafrm/formFilter. This vulnerabiEPSS 0.4%CVE-2026-87126HIGHVulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Reports Security). Supported versions that are afEPSS 0.4%CVE-2026-49249HIGHBoruta: Authenticated atom-exhaustion DoS in BorutaIdentityWeb.UserSettingsController.update/2EPSS 0.4%CVE-2026-58486HIGHHedgeDoc: Denial-of-service via YAML alias expansion in note frontmatterEPSS 0.4%CVE-2026-83436HIGHVulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Recall Management). Supported versions that are affEPSS 0.4%CVE-2021-31365MEDIUMJunos OS: EX2300, EX3400 and EX4300 Series: An Aggregated Ethernet (AE) interface will go down due to a stream of specific layer 2 framesEPSS 0.4%CVE-2025-55587HIGHTOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the hostname parameter at /boafrm/formMapDelDevice. ThiEPSS 0.4%CVE-2025-50615HIGHA buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_00470c50 function of the cgitest.cgi file. AttackeEPSS 0.4%