Fallos del tipo CWE-400

3053 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2022-38677MEDIUMIn cell service, there is a missing permission check. This could lead to local denial of service in cell service with no additional executioEPSS 0.1%CVE-2025-48603MEDIUMIn InputMethodInfo of InputMethodInfo.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to lEPSS 0.1%CVE-2026-28596MEDIUMIn parseInterventionFromXml of GameManagerService.java, there is a possible permanent denial of service due to resource exhaustion. This couEPSS 0.1%CVE-2025-48576MEDIUMIn updateNotificationChannelGroupFromPrivilegedListener of NotificationManagerService.java, there is a possible permanent denial of service EPSS 0.1%CVE-2026-28617MEDIUMIn add of WifiNetworkSuggestionsManager.java, there is a possible persistent DOS due to resource exhaustion. This could lead to local denialEPSS 0.1%CVE-2025-26463MEDIUMIn allowPackageAccess of multiple files, resource exhaustion is possible when repeatedly adding allowed packages. This could lead to a localEPSS 0.1%CVE-2024-23712MEDIUMIn multiple functions of AppOpsService.java, there is a possible way to saturate the content of /data/system/appops_accesses.xml due to resoEPSS 0.1%CVE-2018-9412MEDIUMIn removeUnsynchronization of ID3.cpp there is a possible resource exhaustion due to improper input validation. This could lead to denial ofEPSS 0.1%CVE-2025-48542MEDIUMIn multiple functions of AccountManagerService.java, there is a possible permanent denial of service due to resource exhaustion. This could EPSS 0.1%CVE-2022-47355MEDIUMIn log service, there is a missing permission check. This could lead to local denial of service in log service.EPSS 0.1%CVE-2024-40664MEDIUMIn setupAccessibilityServices of AccessibilityFragment.java , there is a possible way to hide an enabled accessibility service due to a logiEPSS 0.1%CVE-2022-47354MEDIUMIn log service, there is a missing permission check. This could lead to local denial of service in log service.EPSS 0.1%CVE-2025-26449MEDIUMIn multiple locations, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of servicEPSS 0.1%CVE-2022-47356MEDIUMIn log service, there is a missing permission check. This could lead to local denial of service in log service.EPSS 0.1%CVE-2024-32912MEDIUMthere is a possible persistent Denial of Service due to test/debugging code left in a production build. This could lead to local denial of sEPSS 0.1%CVE-2025-48569MEDIUMIn multiple locations, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of servicEPSS 0.1%CVE-2026-0074MEDIUMIn getPreferredSize of LauncherProcessImageListener.kt, there is a possible denial of service due to resource exhaustion. This could lead tEPSS 0.1%CVE-2026-0069MEDIUMIn verifySignature of ApkChecksums.java, there is a possible way to cause a crash due to resource exhaustion. This could lead to local deniaEPSS 0.1%CVE-2026-0042MEDIUMIn multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to resource exhaustion. This couldEPSS 0.1%CVE-2025-48648MEDIUMIn isSameApp of NotificationManagerService.java, there is a possible persistent dos due to resource exhaustion. This could lead to local denEPSS 0.1%