Fallos del tipo CWE-404

695 resultados

Liberação ou encerramento inadequado de recursos

Quando o software não libera corretamente recursos (conexões de banco, arquivo aberto, memória alocada, socket de rede) após o uso. O programa continua consumindo esses recursos até ficar sem espaço ou conexões disponíveis, causando falhas, lentidão ou negação de serviço.

Ejemplo

Um servidor web abre uma conexão com banco de dados para cada requisição, mas esquece de fechar a conexão quando termina. Após centenas de requisições, todas as conexões disponíveis estão esgotadas e novas requisições falham.

Cómo mitigar

Use padrões como try-with-resources (Java), context managers (Python), ou equivalentes na sua linguagem para garantir liberação automática. Implemente timeouts e monitore uso de recursos em produção para detectar vazamentos cedo.

CVE-2025-8805MEDIUMOpen5GS SMF gsm-sm.c smf_gsm_state_wait_pfcp_deletion denial of serviceEPSS 0.7%CVE-2024-57623HIGHAn issue in the HEAP_malloc component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statemeEPSS 0.7%CVE-2024-2363MEDIUMAOL AIM Triton Invite denial of serviceEPSS 0.7%CVE-2026-2108MEDIUMjsbroks COCO Annotator Endpoint long_task denial of serviceEPSS 0.7%CVE-2025-4533MEDIUMJeecgBoot Document Library Upload zip unzipFile resource consumptionEPSS 0.7%CVE-2025-14747MEDIUMNingyuanda TC155 RTSP Service denial of serviceEPSS 0.7%CVE-2022-3669MEDIUMAxiomatic Bento4 mp4edit Create memory leakEPSS 0.7%CVE-2026-1682MEDIUMFree5GC SMF PFCP UDP Endpoint handler.go HandlePfcpAssociationReleaseRequest null pointer dereferenceEPSS 0.7%CVE-2022-4246MEDIUMKakao PotPlayer MID File denial of serviceEPSS 0.7%CVE-2022-3668MEDIUMAxiomatic Bento4 mp4edit CreateAtomFromStream memory leakEPSS 0.7%CVE-2022-3663MEDIUMAxiomatic Bento4 MP4fragment Ap4StsdAtom.cpp AP4_StsdAtom null pointer dereferenceEPSS 0.7%CVE-2024-57659HIGHAn issue in the sqlg_parallel_ts_seq component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) vEPSS 0.7%CVE-2024-57654HIGHAn issue in the qst_vec_get_int64 component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via EPSS 0.7%CVE-2026-1522MEDIUMOpen5GS SGWC s5c-handler.c sgwc_s5c_handle_modify_bearer_response denial of serviceEPSS 0.7%CVE-2024-1189MEDIUMAMPPS Encryption Passphrase denial of serviceEPSS 0.7%CVE-2026-0731MEDIUMTOTOLINK WA1200 HTTP Request cstecgi.cgi null pointer dereferenceEPSS 0.7%CVE-2024-1199MEDIUMCodeAstro Employee Task Management System attendance-info.php denial of serviceEPSS 0.7%CVE-2024-5095HIGHVictor Zsviot Camera MQTT Packet denial of serviceEPSS 0.7%CVE-2025-0704MEDIUMJoeyBling bootplus QrCodeController.java qrCode resource consumptionEPSS 0.7%CVE-2021-4280MEDIUMstyler_praat_scripts Slash file_segmenter.praat denial of serviceEPSS 0.7%