Fallos del tipo CWE-400

3026 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2024-0241HIGHencoded_id-rails Denial of Service VulnerabilityEPSS 1.1%CVE-2022-41861MEDIUMA flaw was found in freeradius. A malicious RADIUS client or home server can send a malformed abinary attribute which can cause the server tEPSS 1.1%CVE-2024-4549HIGHDelta Electronics DIAEnergie SQL Injection EPSS 1.1%CVE-2023-22486LOWcmark-gfm Quadratic complexity bug in handle_close_bracket may lead to a denial of serviceEPSS 1.1%CVE-2022-33142HIGHWordPress Better Messages plugin <= 1.9.10.57 - Denial Of Service (DoS) vulnerabilityEPSS 1.1%CVE-2024-20985MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: UDF). Supported versions that are affected are 8.0.35 and priEPSS 1.1%CVE-2024-20961MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 aEPSS 1.1%CVE-2018-10868—redhat-certification 7 does not properly restrict the number of recursive definitions of entities in XML documents, allowing an unauthenticaEPSS 1.1%CVE-2022-2455MEDIUMA business logic issue in the handling of large repositories in all versions of GitLab CE/EE from 10.0 before 15.1.6, all versions starting EPSS 1.1%CVE-2023-42670MEDIUMSamba: ad dc busy rpc multiple listener dosEPSS 1.1%CVE-2018-16490—A prototype pollution vulnerability was found in module mpath <0.5.1 that allows an attacker to inject arbitrary properties onto Object.protEPSS 1.1%CVE-2022-29167HIGHReDoS vulnerability in header parsing in hawkEPSS 1.1%CVE-1999-0159LOWAttackers can crash a Cisco IOS router or device, provided they can get to an interactive prompt (such as a login). This applies to some IOEPSS 1.1%CVE-2026-25673HIGHPotential denial-of-service vulnerability in URLField via Unicode normalization on WindowsEPSS 1.1%CVE-2021-26260—An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could EPSS 1.1%CVE-2024-20976MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 aEPSS 1.1%CVE-2018-7821HIGHAn Environment (CWE-2) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmwarEPSS 1.1%CVE-2024-20972MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 aEPSS 1.1%CVE-2024-49767MEDIUMWerkzeug possible resource exhaustion when parsing file data in formsEPSS 1.1%CVE-2022-22275—Improper Restriction of TCP Communication Channel in HTTP/S inbound traffic from WAN to DMZ bypassing security policy until TCP handshake poEPSS 1.1%