Fallos del tipo CWE-404

695 resultados

Liberação ou encerramento inadequado de recursos

Quando o software não libera corretamente recursos (conexões de banco, arquivo aberto, memória alocada, socket de rede) após o uso. O programa continua consumindo esses recursos até ficar sem espaço ou conexões disponíveis, causando falhas, lentidão ou negação de serviço.

Ejemplo

Um servidor web abre uma conexão com banco de dados para cada requisição, mas esquece de fechar a conexão quando termina. Após centenas de requisições, todas as conexões disponíveis estão esgotadas e novas requisições falham.

Cómo mitigar

Use padrões como try-with-resources (Java), context managers (Python), ou equivalentes na sua linguagem para garantir liberação automática. Implemente timeouts e monitore uso de recursos em produção para detectar vazamentos cedo.

CVE-2024-12658MEDIUMIObit Advanced SystemCare Utimate IOCTL AscRegistryFilter.sys 0x8001E01C null pointer dereferenceEPSS 0.5%CVE-2024-12659MEDIUMIObit Advanced SystemCare Utimate IOCTL AscRegistryFilter.sys 0x8001E004 null pointer dereferenceEPSS 0.5%CVE-2024-27527HIGHwasm3 139076a is vulnerable to Denial of Service (DoS).EPSS 0.5%CVE-2026-8251MEDIUMOpen5GS SMF npcf-handler.c update_authorized_pcc_rule_and_qos denial of serviceEPSS 0.5%CVE-2026-8266MEDIUMOpen5GS SMF gsm-build.c gsm_build_pdu_session_establishment_accept denial of serviceEPSS 0.5%CVE-2026-12575HIGHDVP80ES3 Improper Resource Shutdown or Release VulnerabilityEPSS 0.5%CVE-2025-14953LOWOpen5GS FAR-ID handler.c ogs_pfcp_handle_create_pdr null pointer dereferenceEPSS 0.5%CVE-2022-35272HIGHBIG-IP HTTP MRF vulnerability CVE-2022-35272EPSS 0.5%CVE-2026-8744MEDIUMOpen5GS NRF context.c ogs_sbi_nf_service_add denial of serviceEPSS 0.5%CVE-2025-13901MEDIUMCWE-404 Improper Resource Shutdown or Release vulnerability exists that could cause partial Denial of Service on Machine Expert protocol wheEPSS 0.5%CVE-2025-11635MEDIUMTomofun Furbo 360 File Upload resource consumptionEPSS 0.5%CVE-2024-4292MEDIUMContemporary Controls BASrouter BACnet BASRT-B Device-Communication-Control Service denial of serviceEPSS 0.4%CVE-2025-69821HIGHAn issue in Beat XP VEGA Smartwatch (Firmware Version - RB303ATV006229) allows an attacker to cause a denial of service via the BLE connectiEPSS 0.4%CVE-2026-10069HIGHShibby Tomato miniupnpd resource consumptionEPSS 0.4%CVE-2026-15690LOWopen62541 Shared Client ua_client_connect.c responseReadNamespacesArray null pointer dereferenceEPSS 0.4%CVE-2026-92879MEDIUMvgmstream mus_acm.c parse_mus resource consumptionEPSS 0.4%CVE-2022-48489—Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.EPSS 0.4%CVE-2022-46314HIGHThe IPC module has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability.EPSS 0.4%CVE-2022-48499HIGHConfiguration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.EPSS 0.4%CVE-2026-92413MEDIUMArtifex MuPDF PDF Xref Loading pdf-stream.c pdf_open_filter null pointer dereferenceEPSS 0.4%