Fallos del tipo CWE-400

3053 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2025-48615HIGHIn getComponentName of MediaButtonReceiverHolder.java, there is a possible desync in persistence due to resource exhaustion. This could leadEPSS 0.1%CVE-2026-20780MEDIUMUncontrolled resource consumption for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow a deniEPSS 0.1%CVE-2025-46593MEDIUMProcess residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulnerability may affect aEPSS 0.1%CVE-2024-40575MEDIUMAn issue in Huawei Technologies opengauss (openGauss 5.0.0 build) v.7.3.0 allows a local attacker to cause a denial of service via the modifEPSS 0.1%CVE-2022-33303MEDIUMUncontrolled resource consumption in Linux kernelEPSS 0.1%CVE-2026-0049MEDIUMIn onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead EPSS 0.1%CVE-2026-18822MEDIUMVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.1%CVE-2026-22003MEDIUMVulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions tEPSS 0.1%CVE-2026-19653MEDIUMVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.1%CVE-2024-49740MEDIUMIn multiple locations, there is a possible crash loop due to resource exhaustion. This could lead to local denial of service with no additioEPSS 0.1%CVE-2025-48590MEDIUMIn verifyAndGetBypass of AppOpsService.java, there is a possible method for a malicious app to prevent dialing emergency services under limiEPSS 0.1%CVE-2024-0026MEDIUMIn multiple functions of SnoozeHelper.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to EPSS 0.1%CVE-2025-48584MEDIUMIn multiple functions of NotificationManagerService.java, there is a possible way to bypass the per-package channel limits causing resource EPSS 0.1%CVE-2023-21090MEDIUMIn parseUsesPermission of ParsingPackageUtils.java, there is a possible boot loop due to resource exhaustion. This could lead to local deniaEPSS 0.1%CVE-2025-26423MEDIUMIn validateIpConfiguration of WifiConfigurationUtil.java, there is a possible way to trigger a permanent DoS due to a missing bounds check. EPSS 0.1%CVE-2022-38674MEDIUMIn wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2018-9447MEDIUMIn onCreate of EmergencyCallbackModeExitDialog.java, there is a possible way to crash the emergency callback mode due to a missing null checEPSS 0.1%CVE-2026-55595MEDIUMImageMagick: Infinite Loop in connected-components when providing invalid argumentsEPSS 0.1%CVE-2022-47370MEDIUMIn wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2023-21033MEDIUMIn addNetwork of WifiManager.java, there is a possible way to trigger a persistent DoS due to resource exhaustion. This could lead to local EPSS 0.1%