Fallos del tipo CWE-410

21 resultados

Pool de recursos insuficiente

Ocorre quando uma aplicação aloca um número fixo ou limitado de recursos (conexões de banco, threads, memória) sem mecanismo adequado de reciclagem ou expansão dinâmica. Um atacante ou carga legítima acima do esperado esgota o pool, causando negação de serviço ou falhas em cascata.

Ejemplo

Um servidor web cria um pool com apenas 10 conexões de banco de dados. Quando 11 requisições simultâneas chegam, a 11ª fica bloqueada ou falha; se o timeout for longo, o pool fica saturado e novas usuários não conseguem conectar.

Cómo mitigar

Implemente detecção de esgotamento do pool com alertas, configure timeouts agressivos para liberar recursos presos, use filas de espera com limite e considere auto-scaling do pool baseado em demanda. Revise logs de conexões rejeitadas em produção.

CVE-2022-40224MEDIUMA denial of service vulnerability exists in the web server functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A speciallyEPSS 64.7%CVE-2025-0453MEDIUMDenial of Service through Batched Queries in GraphQL in mlflow/mlflowEPSS 10.4%CVE-2022-2048HIGHIn Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up noEPSS 2.3%CVE-2025-27479HIGHKerberos Key Distribution Proxy Service Denial of Service VulnerabilityEPSS 2.0%CVE-2018-13815A vulnerability has been identified in SIMATIC S7-1200 (All versions), SIMATIC S7-1500 (All Versions < V2.6). An attacker could exhaust the EPSS 1.8%CVE-2019-13921A vulnerability has been identified in SIMATIC WinAC RTX (F) 2010 (All versions < SP3 Update 1). Affected versions of the software contain aEPSS 1.4%CVE-2021-1615HIGHCisco Embedded Wireless Controller Software for Catalyst Access Points Denial of Service VulnerabilityEPSS 1.3%CVE-2019-0056HIGHJunos OS: MX Series: An MPC10 Denial of Service (DoS) due to OSPF states transitioning to Down, causes traffic to stop forwarding through the device.EPSS 1.3%CVE-2026-58218MEDIUMSamba: dns signing dos via tkey name cache exhaustionEPSS 1.1%CVE-2023-7033MEDIUMInsufficient Resource Pool vulnerability in Ethernet function of Mitsubishi Electric Corporation MELSEC iQ-R series CPU module, MELSEC iQ-L EPSS 0.9%CVE-2022-20937MEDIUMA vulnerability in a feature that monitors RADIUS requests on Cisco Identity Services Engine (ISE) Software could allow an unauthenticated, EPSS 0.8%CVE-2023-38505HIGHDietPi-Dashboard Insufficient TLS Handshake PoolEPSS 0.8%CVE-2022-46679MEDIUM Dell PowerScale OneFS 8.2.x, 9.0.0.x - 9.4.0.x, contain an insufficient resource pool vulnerability. A remote unauthenticated attacker coulEPSS 0.8%CVE-2024-7392MEDIUMChargePoint Home Flex Bluetooth Low Energy Denial-of-Service VulnerabilityEPSS 0.5%CVE-2025-41653HIGHWeidmueller: Denial-of-Service Vulnerability in the web server functionality of Industrial Ethernet SwitchesEPSS 0.5%CVE-2025-27694MEDIUMDell Wyse Management Suite, versions prior to WMS 5.1, contains an Insufficient Resource Pool vulnerability. An unauthenticated attacker wiEPSS 0.4%CVE-2022-22191MEDIUMJunos OS: EX4300: PFE Denial of Service (DoS) upon receipt of a flood of specific ARP trafficEPSS 0.4%CVE-2026-34019MEDIUMBIG-IP BFD vulnerabilityEPSS 0.3%CVE-2025-2134LOWIBM Jazz Reporting Service Denial of ServiceEPSS 0.2%CVE-2025-12986MEDIUMDenial of Service Vulnerability in Silicon Labs WF200 and WGM160P DevicesEPSS 0.2%