Fallos del tipo CWE-770
1850 resultadosAlocação sem limite de recursos
A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.
Ejemplo
Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.
Cómo mitigar
Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.
CVE-2019-15165MEDIUMsf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.EPSS 2.8%CVE-2026-26130HIGHASP.NET Core Denial of Service VulnerabilityEPSS 2.8%CVE-2022-23913—Apache ActiveMQ Artemis DoSEPSS 2.7%CVE-2019-14834LOWA vulnerability was found in dnsmasq before version 2.81, where the memory leak allows remote attackers to cause a denial of service (memoryEPSS 2.7%CVE-2021-34710HIGHCisco ATA 190 Series Analog Telephone Adapter Software VulnerabilitiesEPSS 2.6%CVE-2024-57972MEDIUMThe pairing API request handler in Microsoft HoloLens 1 (Windows Holographic) through 10.0.17763.3046 and HoloLens 2 (Windows Holographic) tEPSS 2.5%CVE-2016-9578HIGHA vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server coEPSS 2.5%CVE-2026-45591HIGHASP.NET Core Denial of Service VulnerabilityEPSS 2.5%CVE-2021-40114MEDIUMMultiple Cisco Products Snort Memory Leak Denial of Service VulnerabilityEPSS 2.4%CVE-2025-9784HIGHUndertow: undertow madeyoureset http/2 ddos vulnerabilityEPSS 2.3%CVE-2024-43567HIGHWindows Hyper-V Denial of Service VulnerabilityEPSS 2.3%CVE-2024-22255HIGHInformation disclosure vulnerabilityEPSS 2.3%CVE-2019-11938—Java Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malEPSS 2.3%CVE-2021-36630HIGHDDOS reflection amplification vulnerability in eAut module of Ruckus Wireless SmartZone controller that allows remote attackers to perform DEPSS 2.2%CVE-2025-61726HIGHMemory exhaustion in query parameter parsing in net/urlEPSS 2.2%CVE-2018-16846MEDIUMIt was found in Ceph versions before 13.2.4 that authenticated ceph RGW users can cause a denial of service against OMAPs holding bucket indEPSS 2.1%CVE-2019-3553—C++ Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, maliEPSS 2.1%CVE-2024-1975HIGHSIG(0) can be used to exhaust CPU resourcesEPSS 2.1%CVE-2024-1737HIGHBIND's database will be slow if a very large number of RRs exist at the same nameEPSS 2.1%CVE-2024-35176MEDIUMREXML contains a denial of service vulnerabilityEPSS 2.1%