Fallos del tipo CWE-400

3026 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2024-32476MEDIUMDenial of Service via malicious jqPathExpressions in ignoreDifferencesEPSS 1.0%CVE-2021-22101—Cloud Controller versions prior to 1.118.0 are vulnerable to unauthenticated denial of Service(DoS) vulnerability allowing unauthenticated aEPSS 1.0%CVE-2021-28510MEDIUMFor certain systems running EOS, a Precision Time Protocol (PTP) packet of a management/signaling message with an invalid Type-Length-Value (TLV) causes the PTP agent to restart. Repeated restarts of the service will make the service unavailable.EPSS 1.0%CVE-2021-29453MEDIUMDenial of service through memory exhaustionEPSS 1.0%CVE-2023-44321MEDIUMAffected devices do not properly validate the length of inputs when performing certain configuration changes in the web interface allowing aEPSS 1.0%CVE-2021-22139—Kibana versions before 7.12.1 contain a denial of service vulnerability was found in the webhook actions due to a lack of timeout or a limitEPSS 1.0%CVE-2024-3789MEDIUMUncontrolled Resource Consumption vulnerability in WBSAirbackEPSS 1.0%CVE-2022-43740HIGHIBM Security Verify Access denial of serviceEPSS 1.0%CVE-2022-2053—When a POST request comes through AJP and the request exceeds the max-post-size limit (maxEntitySize), Undertow's AjpServerRequestConduit imEPSS 1.0%CVE-2024-21051MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.34 and priEPSS 1.0%CVE-2023-3153MEDIUMService monitor mac flow is not rate limitedEPSS 1.0%CVE-2023-1605HIGHDenial of Service in radareorg/radare2EPSS 1.0%CVE-2022-27507MEDIUMAuthenticated denial of service EPSS 1.0%CVE-2024-1309MEDIUMResource Consumption Identified in NTP before 4.2.4p8 and 4.2.5EPSS 1.0%CVE-2021-31340—A vulnerability has been identified in SIMATIC RF166C (All versions > V1.1 and < V1.3.2), SIMATIC RF185C (All versions > V1.1 and < V1.3.2),EPSS 1.0%CVE-2024-21050MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.34 and priEPSS 1.0%CVE-2022-2004HIGHAutomationDirect DirectLOGIC with Ethernet Communication Uncontrolled Resource ConsumptionEPSS 1.0%CVE-2022-3613MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versioEPSS 1.0%CVE-2014-3648—The simplepush server iterates through the application installations and pushes a notification to the server provided by deviceToken. But thEPSS 1.0%CVE-2023-49140HIGHDenial-of-service (DoS) vulnerability exists in commplex-link service of HMI GC-A2 series. If a remote unauthenticated attacker sends a specEPSS 1.0%