Fallos del tipo CWE-400

3026 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2023-37022HIGHOpen5GS MME versions <= 2.6.4 contain a reachable assertion in the `UE Context Release Request` packet handler. A packet containing an invalEPSS 0.8%CVE-2023-32636MEDIUMA flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validaEPSS 0.8%CVE-2026-1174MEDIUMbirkir prime GraphQL Alias graphql resource consumptionEPSS 0.8%CVE-2025-24269CRITICALThe issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4. An app may be able to cause unexpected sysEPSS 0.8%CVE-2024-3569HIGHDenial of Service (DoS) Vulnerability in mintplex-labs/anything-llmEPSS 0.8%CVE-2022-35915MEDIUMUnbounded gas consumption in @openzeppelin/contractsEPSS 0.8%CVE-2023-24545HIGHOn affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch.EPSS 0.8%CVE-2023-54365HIGHTraefik - Denial of Service via HTTP/2 Request HandlingEPSS 0.8%CVE-2024-12063HIGHDenial of Service in imartinez/privategptEPSS 0.8%CVE-2022-34326HIGHIn ambiot amb1_sdk (aka SDK for Ameba1) before 2022-06-20 on Realtek RTL8195AM devices before 284241d70308ff2519e40afd7b284ba892c730a3, the EPSS 0.8%CVE-2025-43193CRITICALThe issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7.EPSS 0.8%CVE-2024-45163CRITICALThe Mirai botnet through 2024-08-19 mishandles simultaneous TCP connections to the CNC (command and control) server. Unauthenticated sessionEPSS 0.8%CVE-2024-4436HIGHEtcd: incomplete fix for cve-2022-41723 in openstack platformEPSS 0.8%CVE-2024-4437HIGHEtcd: incomplete fix for cve-2021-44716 in openstack platformEPSS 0.8%CVE-2024-39462CRITICALclk: bcm: dvp: Assign ->num before accessing ->hwsEPSS 0.8%CVE-2023-29499MEDIUMGvariant offset table entry size is not checked in is_normal()EPSS 0.8%CVE-2022-38871HIGHIn Free5gc v3.0.5, the AMF breaks due to malformed NAS messages.EPSS 0.8%CVE-2026-69208HIGHHttp4s: DigestAuth nonce map grows unboundedEPSS 0.8%CVE-2025-21577MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0EPSS 0.8%CVE-2022-33168HIGHIBM Security Directory Suite VA denial of serviceEPSS 0.8%