Fallos del tipo CWE-400

3000 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2022-4899HIGHA vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause bufferEPSS 1.6%CVE-2018-15377—Cisco IOS and IOS XE Software Plug and Play Agent Memory Leak VulnerabilityEPSS 1.6%CVE-2019-18904MEDIUMMigrations requests can cause DoS on rmtEPSS 1.6%CVE-2017-16117—slug is a module to slugify strings, even if they contain unicode. slug is vulnerable to regular expression denial of service is specially cEPSS 1.6%CVE-2017-16119—Fresh is a module used by the Express.js framework for HTTP response freshness testing. It is vulnerable to a regular expression denial of sEPSS 1.6%CVE-2017-16013—hapi is a web and services application framework. When hapi >= 15.0.0 <= 16.1.0 encounters a malformed `accept-encoding` header an uncaught EPSS 1.6%CVE-2017-16099—The no-case module is vulnerable to regular expression denial of service. When malicious untrusted user input is passed into no-case it can EPSS 1.6%CVE-2022-29225HIGHZip bomb vulnerability in EnvoyEPSS 1.6%CVE-2023-2295HIGHA vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unEPSS 1.6%CVE-2023-32067HIGH0-byte UDP payload DoS in c-aresEPSS 1.6%CVE-2019-0033HIGHSRX Series: A remote attacker may cause a high CPU Denial of Service to the device when proxy ARP is configured.EPSS 1.6%CVE-2022-31054HIGHUses of deprecated API can be used to cause DoS in user-facing endpoints in Argo EventsEPSS 1.6%CVE-2019-6578—A vulnerability has been identified in SINAMICS PERFECT HARMONY GH180 with NXG I control, MLFBs: 6SR2...-, 6SR3...-, 6SR4...- (All Versions EPSS 1.6%CVE-2019-10948—Fujifilm FCR Capsula X/ Carbon X/ FCR XC-2, model versions CR-IR 357 FCR Carbon X, CR-IR 357 FCR XC-2, FCR-IR 357 FCR Capsula X are susceptiEPSS 1.6%CVE-2020-3181MEDIUMCisco Email Security Appliance Uncontrolled Resource Exhaustion VulnerabilityEPSS 1.6%CVE-2021-3909MEDIUMInfinite open connection causes OctoRPKI to hang foreverEPSS 1.6%CVE-2020-6986HIGHIn all versions of Omron PLC CJ Series, an attacker can send a series of specific data packets within a short period, causing a service erroEPSS 1.6%CVE-2020-8293—A missing input validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows users to store unlimited data in workflow rules causingEPSS 1.6%CVE-2020-8246—Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 1EPSS 1.6%CVE-2021-24893—Stars Rating < 3.5.1 - Comments Denial of ServiceEPSS 1.6%