Fallos del tipo CWE-400

3026 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2023-35920HIGHA vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3.4), SIMATIC MV540 S (All versions < V3.3.4), SIMATIC MV550 H (AlEPSS 0.9%CVE-2023-20051MEDIUMCisco Packet Data Network Gateway IPsec ICMP Denial of Service VulnerabilityEPSS 0.9%CVE-2023-35921HIGHA vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3.4), SIMATIC MV540 S (All versions < V3.3.4), SIMATIC MV550 H (AlEPSS 0.9%CVE-2020-26302HIGHis.js is a general-purpose check library. Versions 0.9.0 and prior contain one or more regular expressions that are vulnerable to Regular ExEPSS 0.9%CVE-2026-68763HIGHApache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is resetEPSS 0.9%CVE-2022-32927HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16. Joining EPSS 0.9%CVE-2024-21185MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.38, 8.4.1 and EPSS 0.9%CVE-2023-25568HIGHBoxo bitswap/server: DOS unbounded persistent memory leakEPSS 0.9%CVE-2024-35270MEDIUMWindows iSCSI Service Denial of Service VulnerabilityEPSS 0.9%CVE-2024-12864HIGHUnauthenticated DoS by Sending Large Filename at File Upload Endpoint in netease-youdao/qanythingEPSS 0.9%CVE-2024-12070HIGHDenial of Service in haotian-liu/llavaEPSS 0.9%CVE-2023-21838HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.9%CVE-2024-21194MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.39 and prior, 8EPSS 0.9%CVE-2022-24035HIGHAn issue was discovered in ONOS 2.5.1. The purge-requested intent remains on the list, but it does not respond to changes in topology (e.g.,EPSS 0.9%CVE-2022-2406MEDIUMMalicious imports can lead to Denial of ServiceEPSS 0.9%CVE-2018-0441HIGHCisco IOS Access Points Software 802.11r Fast Transition Denial of Service VulnerabilityEPSS 0.9%CVE-2022-24109MEDIUMAn issue was discovered in ONOS 2.5.1. To attack an intent installed by a normal user, a remote attacker can install a duplicate intent withEPSS 0.9%CVE-2023-26470MEDIUMIn XWiki Platform, saving a document with a large object number leads to persistent OOM errorsEPSS 0.9%CVE-2026-66143HIGHApache Neethi: Missing global alternative-output budget across policy computation pathsEPSS 0.9%CVE-2024-47850HIGHCUPS cups-browsed before 2.5b1 will send an HTTP POST request to an arbitrary destination and port in response to a single IPP UDP packet reEPSS 0.9%