Fallos del tipo CWE-770

1864 resultados

Alocação sem limite de recursos

A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.

Ejemplo

Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.

Cómo mitigar

Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.

CVE-2025-14435MEDIUMApplication-Level DoS via infinite re-render loop in user profile handlingEPSS 0.3%CVE-2023-24785MEDIUMAn issue in Giorgio Tani peazip v.9.0.0 allows attackers to cause a denial of service via the End of Archive tag function of the peazip/pea EPSS 0.3%CVE-2024-39724MEDIUMIBM Db2 Big SQL on Cloud Pak for Data is vulnerable to a denial of service due to lack of throttling on an APIEPSS 0.3%CVE-2026-24661LOWUnbounded Request Body Read in MS Teams Plugin {{/changes}} Webhook EndpointEPSS 0.3%CVE-2026-21388LOWUnbounded Request Body Read in MS Teams Plugin {{/lifecycle}} Webhook EndpointEPSS 0.3%CVE-2026-19204HIGHA client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memoryEPSS 0.3%CVE-2026-100649MEDIUMvLLM before 0.29.0 Resource Limit Bypass via Sampler SubclassEPSS 0.3%CVE-2022-41846MEDIUMAn issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in the function AP4_DataBuffer::ReallocateBuffer in Core/EPSS 0.3%CVE-2026-20431MEDIUMIn Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE has connected to a rogEPSS 0.3%CVE-2022-35089MEDIUMSWFTools commit 772e55a2 was discovered to contain a heap-buffer-overflow via getTransparentColor at /home/bupt/Desktop/swftools/src/gif2swfEPSS 0.3%CVE-2026-44219LOWciguard: SCA HTTP client reads response body without size capEPSS 0.3%CVE-2026-14514MEDIUMReliable Scalable Cluster Technology Denial-of-ServiceEPSS 0.3%CVE-2025-54869MEDIUMFPDI is Vulnerable to Memory Exhaustion (OOM) through its PDF ParserEPSS 0.3%CVE-2025-55670HIGHBIG-IP Next (CNF, SPK, and Kubernetes) vulnerabilityEPSS 0.3%CVE-2025-25207MEDIUMRhcl: authpolicy callbacks result in denial of service in authorino severityEPSS 0.3%CVE-2023-20067HIGHCisco IOS XE Software for Wireless LAN Controllers HTTP Client Profiling Denial of Service VulnerabilityEPSS 0.3%CVE-2025-4097MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.3%CVE-2025-46687MEDIUMquickjs-ng through 0.9.0 has a missing length check in JS_ReadString for a string, leading to a heap-based buffer overflow. QuickJS before 2EPSS 0.3%CVE-2025-24127MEDIUMThe issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS SonoEPSS 0.3%CVE-2026-1387MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.3%