Fallos del tipo CWE-400

3053 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2025-61480HIGHAn issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial ofEPSS 0.1%CVE-2025-27249MEDIUMUncontrolled resource consumption for some Gaudi software before version 1.21.0 within Ring 3: User Applications may allow a denial of serviEPSS 0.1%CVE-2023-20908MEDIUMIn several functions of SettingsState.java, there is a possible system crash loop due to resource exhaustion. This could lead to local deniaEPSS 0.1%CVE-2023-20922MEDIUMIn setMimeGroup of PackageManagerService.java, there is a possible crash loop due to resource exhaustion. This could lead to local denial ofEPSS 0.1%CVE-2026-0064CRITICALIn multiple places, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service EPSS 0.1%CVE-2022-39125MEDIUMIn sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kerneEPSS 0.1%CVE-2022-39128MEDIUMIn sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kerneEPSS 0.1%CVE-2022-39124MEDIUMIn sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kerneEPSS 0.1%CVE-2022-39123MEDIUMIn sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kerneEPSS 0.1%CVE-2022-39127MEDIUMIn sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kerneEPSS 0.1%CVE-2022-39126MEDIUMIn sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kerneEPSS 0.1%CVE-2022-20455MEDIUMIn addAutomaticZenRule of ZenModeHelper.java, there is a possible persistent denial of service due to resource exhaustion. This could lead tEPSS 0.1%CVE-2025-33177MEDIUMNVIDIA Jetson Linux and IGX OS contain a vulnerability in NvMap, where improper tracking of memory allocations could allow a local attacker EPSS 0.1%CVE-2026-87274MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.1%CVE-2022-38679MEDIUMIn music service, there is a missing permission check. This could lead to local denial of service in music service with no additional executEPSS 0.1%CVE-2024-43763MEDIUMIn build_read_multi_rsp of gatt_sr.cc, there is a possible denial of service due to a logic error in the code. This could lead to remote (prEPSS 0.1%CVE-2026-11478MEDIUMkokke tiny-regex-c Pattern re.c matchstar redosEPSS 0.1%CVE-2026-76702MEDIUMAuthenticated Local Denial-of-Service Vulnerability in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.1%CVE-2026-25122MEDIUMapko is vulnerable to unbounded resource consumption in expandapk.Split on attacker-controlled .apk streamsEPSS 0.1%CVE-2024-51513MEDIUMVulnerability of processes not being fully terminated in the VPN module Impact: Successful exploitation of this vulnerability will affect poEPSS 0.1%