Fallos del tipo CWE-400

3026 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2020-3203HIGHCisco IOS XE Software Catalyst 9800 Series Wireless Controllers Denial of Service VulnerabilityEPSS 0.8%CVE-2022-41969LOWNextcloud Server has no password length limit when creating a user as an administratorEPSS 0.8%CVE-2022-24040—A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXEPSS 0.8%CVE-2023-21996HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affeEPSS 0.8%CVE-2023-21964HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.8%CVE-2026-39244HIGHadm-zip before 0.5.18 is vulnerable to denial of service via a crafted ZIP file with a manipulated uncompressed size header field. In zipEntEPSS 0.8%CVE-2022-4006LOWWBCE CMS Header class.login.php increase_attempts excessive authenticationEPSS 0.8%CVE-2024-21062MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.36 aEPSS 0.8%CVE-2026-27980MEDIUMNext.js: Unbounded next/image disk cache growth can exhaust storageEPSS 0.8%CVE-2023-41121—Array AG OS before 9.4.0.499 allows denial of service: remote attackers can cause system service processes to crash through abnormal HTTP opEPSS 0.8%CVE-2021-47023HIGHnet: marvell: prestera: fix port event handling on initEPSS 0.8%CVE-2021-38465HIGHAUVESY VersiondogEPSS 0.8%CVE-2022-35776MEDIUMAzure Site Recovery Denial of Service VulnerabilityEPSS 0.8%CVE-2026-45759HIGHSuricata http1: quadratic Content-Disposition processing can lead to denial of serviceEPSS 0.8%CVE-2021-23852MEDIUMDenial of Service (DoS) due to invalid web parameterEPSS 0.8%CVE-2022-37884HIGHA vulnerability exists in the ClearPass Policy Manager Guest User Interface that can allow an unauthenticated attacker to send specific operEPSS 0.8%CVE-2022-20960HIGHA vulnerability in Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated remote attacker to cause aEPSS 0.8%CVE-2022-23580MEDIUMAbort caused by allocating a vector that is too large in TensorflowEPSS 0.8%CVE-2024-41818HIGHReDOS at currency parsing fast-xml-parserEPSS 0.8%CVE-2023-50730HIGHGrackle has StackOverflowError in GraphQL query processingEPSS 0.8%