Fallos del tipo CWE-400

3051 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2022-41801MEDIUMUncontrolled resource consumption in the Intel(R) Connect M Android application before version 1.82 may allow an authenticated user to potenEPSS 0.2%CVE-2026-49461MEDIUMpypdf: Possible large memory usage for form XObjects during text extractionEPSS 0.2%CVE-2022-46645MEDIUMUncontrolled resource consumption in the Intel(R) Smart Campus Android application before version 9.9 may allow an authenticated user to potEPSS 0.2%CVE-2024-57673MEDIUMAn issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module and Linkdiscovery moduleEPSS 0.2%CVE-2026-60747MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affeEPSS 0.2%CVE-2026-61147MEDIUMVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content AcquiEPSS 0.2%CVE-2022-43880MEDIUMIBM QRadar WinCollect AgentEPSS 0.2%CVE-2026-58045MEDIUMA flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing tEPSS 0.2%CVE-2025-69645MEDIUMBinutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logicEPSS 0.2%CVE-2022-30691MEDIUMUncontrolled resource consumption in the Intel(R) Support Android application before version 22.02.28 may allow an authenticated user to potEPSS 0.2%CVE-2026-87282MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2023-7258MEDIUMDenial-of-Service in GvisorEPSS 0.2%CVE-2026-47041MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2026-71128MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2026-87285MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2025-66676MEDIUMAn issue in IObit Unlocker v1.3.0.11 allows attackers to cause a Denial of Service (DoS) via a crafted request.EPSS 0.2%CVE-2026-87283MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2025-41227MEDIUMDenial-of-Service VulnerabilityEPSS 0.2%CVE-2025-23246MEDIUMNVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it allows a guest to conEPSS 0.2%CVE-2023-37195MEDIUMA vulnerability has been identified in SIMATIC CP 1604 (All versions), SIMATIC CP 1616 (All versions), SIMATIC CP 1623 (All versions), SIMATEPSS 0.2%