Fallos del tipo CWE-770

1851 resultados

Alocação sem limite de recursos

A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.

Ejemplo

Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.

Cómo mitigar

Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.

CVE-2024-54497MEDIUMThe issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.4, macOS Sequoia 15.2, macOS SonoEPSS 1.0%CVE-2021-31369MEDIUMJunos OS: MX Series: Traffic drops will be observed if MS-MPC/MS-PIC resources are consumed by certain traffic causing a partial DoSEPSS 1.0%CVE-2025-21536MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.39 aEPSS 1.0%CVE-2025-21534MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Performance Schema). Supported versions that are affected areEPSS 1.0%CVE-2026-39803HIGHHTTP/1 chunked body reader ignores length cap in banditEPSS 1.0%CVE-2026-57220HIGHRabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoSEPSS 1.0%CVE-2026-33176MEDIUMRails Active Support has a possible DoS vulnerability in its number helpersEPSS 1.0%CVE-2026-42039MEDIUMAxios: unbounded recursion in toFormData causes DoS via deeply nested request dataEPSS 1.0%CVE-2023-38507HIGHStrapi Improper Rate Limiting vulnerabilityEPSS 1.0%CVE-2025-21499MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.4.3 and prioEPSS 1.0%CVE-2026-18649HIGHGstreamer1-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay and rtph265depay rtp depayloadersEPSS 1.0%CVE-2021-0285HIGHJunos OS: QFX5000 Series and EX4600 Series: Continuous traffic destined to a device configured with MC-LAG leading to nodes losing their control connection which can impact trafficEPSS 1.0%CVE-2018-3738—protobufjs is vulnerable to ReDoS when parsing crafted invalid .proto files.EPSS 1.0%CVE-2025-21492MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.36 aEPSS 1.0%CVE-2023-28119HIGHcrewjam/saml vulnerable to Denial Of Service Via Deflate Decompression BombEPSS 1.0%CVE-2024-32663HIGHSuricata 's http2 parser contains an improper compressed header handling can lead to resource starvationEPSS 1.0%CVE-2022-22278—A vulnerability in SonicOS CFS (Content filtering service) returns a large 403 forbidden HTTP response message to the source address when usEPSS 1.0%CVE-2026-40073HIGHSvelteKit has a BODY_SIZE_LIMIT bypass in @sveltejs/adapter-nodeEPSS 1.0%CVE-2023-30636HIGHTiKV 6.1.2 allows remote attackers to cause a denial of service (fatal error, with RpcStatus UNAVAILABLE for "not leader") upon an attempt tEPSS 1.0%CVE-2022-43768HIGHA vulnerability has been identified in SIMATIC CP 1242-7 V2 (6GK7242-7KX31-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 (6GK7243-1BX30-EPSS 1.0%