Fallos del tipo CWE-404
695 resultadosLiberação ou encerramento inadequado de recursos
Quando o software não libera corretamente recursos (conexões de banco, arquivo aberto, memória alocada, socket de rede) após o uso. O programa continua consumindo esses recursos até ficar sem espaço ou conexões disponíveis, causando falhas, lentidão ou negação de serviço.
Ejemplo
Um servidor web abre uma conexão com banco de dados para cada requisição, mas esquece de fechar a conexão quando termina. Após centenas de requisições, todas as conexões disponíveis estão esgotadas e novas requisições falham.
Cómo mitigar
Use padrões como try-with-resources (Java), context managers (Python), ou equivalentes na sua linguagem para garantir liberação automática. Implemente timeouts e monitore uso de recursos em produção para detectar vazamentos cedo.
CVE-2023-1641MEDIUMIObit Malware Fighter IOCTL ObCallbackProcess.sys 0x222018 denial of serviceEPSS 0.3%CVE-2023-1645MEDIUMIObit Malware Fighter IOCTL IMFCameraProtect.sys 0x8018E008 denial of serviceEPSS 0.3%CVE-2023-1642MEDIUMIObit Malware Fighter IOCTL ObCallbackProcess.sys 0x222040 denial of serviceEPSS 0.3%CVE-2023-1493MEDIUMMax Secure Anti Virus Plus IoControlCode MaxProctetor64.sys 0x220019 denial of serviceEPSS 0.3%CVE-2023-1627MEDIUMJianming Antivirus IoControlCode kvcore.sys denial of serviceEPSS 0.3%CVE-2023-1492MEDIUMMax Secure Anti Virus Plus IoControlCode MaxProc64.sys 0x220019 denial of serviceEPSS 0.3%CVE-2023-1644MEDIUMIObit Malware Fighter IOCTL IMFCameraProtect.sys 0x8018E010 denial of serviceEPSS 0.3%CVE-2025-1373MEDIUMFFmpeg MOV Parser mov.c mov_read_trak null pointer dereferenceEPSS 0.3%CVE-2024-12656MEDIUMFabulaTech USB over Network IOCT ftusbbus2.sys 0x220448 null pointer dereferenceEPSS 0.3%CVE-2025-63895HIGHAn issue in the Bluetooth firmware of JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to cause a Denial of Service (EPSS 0.3%CVE-2026-82589MEDIUMOpen5GS N1-N2 Message namf-handler.c amf_namf_comm_handle_n1_n2_message_transfer denial of serviceEPSS 0.3%CVE-2026-10802MEDIUMkeystonejs keystone GraphQL API Endpoint output-field.ts resource consumptionEPSS 0.3%CVE-2026-82588MEDIUMOpen5GS Transfer Endpoint namf-handler.c null pointer dereferenceEPSS 0.3%CVE-2022-4296MEDIUMTP-Link TL-WR740N ARP resource consumptionEPSS 0.3%CVE-2025-1376LOWGNU elfutils eu-strip elf_strptr.c elf_strptr denial of serviceEPSS 0.3%CVE-2026-10115MEDIUMOpen5GS Shared NF-profile nnrf-handler.c denial of serviceEPSS 0.3%CVE-2025-25899LOWA buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the 'gw' parameter at /userRpm/WanDynamicIpV6CfgRpm.htm. This vEPSS 0.3%CVE-2026-7587MEDIUMOpen5GS AMF nsmf-handler.c amf_nsmf_pdusession_handle_update_sm_context denial of serviceEPSS 0.3%CVE-2025-15686MEDIUMOpen5GS HSS Service fd_msg_sess_get denial of serviceEPSS 0.3%CVE-2024-1190LOWGlobal Scape CuteFTP denial of serviceEPSS 0.3%