Fallos del tipo CWE-770

1864 resultados

Alocação sem limite de recursos

A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.

Ejemplo

Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.

Cómo mitigar

Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.

CVE-2022-0480—A flaw was found in the filelock_init in fs/locks.c function in the Linux kernel. This issue can lead to host memory exhaustion due to memcgEPSS 0.3%CVE-2025-14525MEDIUMKubevirt: kubevirt: vm administration denial of service via guest agentEPSS 0.3%CVE-2025-21494MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected aEPSS 0.3%CVE-2026-47859MEDIUMUnbounded memory allocation in RFC6587SyslogDeserializer (octet-counted framing) — remote DoSEPSS 0.3%CVE-2023-29570MEDIUMCesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_ffi_cb_free at src/mjs_ffi.c. This vulnerability can lead to a DeEPSS 0.3%CVE-2021-47551HIGHdrm/amd/amdkfd: Fix kernel panic when reset failed and been triggered againEPSS 0.3%CVE-2025-36008MEDIUMIBM Db2 denial of serviceEPSS 0.3%CVE-2020-36943MEDIUMaSc TimeTables 2021.6.2 - Denial of ServiceEPSS 0.3%CVE-2021-47894MEDIUMManaged Switch Port Mapping Tool 2.85.2 - Denial of ServiceEPSS 0.3%CVE-2021-47893MEDIUMAgataSoft PingMaster Pro 2.1 - Denial of ServiceEPSS 0.3%CVE-2026-27663HIGHA vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.10), RTUM85 RTU Base (All versions < V26.EPSS 0.3%CVE-2026-24738MEDIUMgmrtd ReadFile Vulnerable to Denial of Service via Excessive TLV Length ValuesEPSS 0.3%CVE-2025-36140MEDIUMIBM watsonx.data Denial of ServiceEPSS 0.3%CVE-2025-43736MEDIUMA Denial Of Service via File Upload (DOS) vulnerability in the Liferay Portal 7.4.3.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2EPSS 0.3%CVE-2026-30961MEDIUMGokapi's File Request MaxSize Limit Bypassed via Multi-Chunk UploadEPSS 0.3%CVE-2026-40990MEDIUMUnbounded cache for function definitionsEPSS 0.3%CVE-2024-52917MEDIUMBitcoin Core before 22.0 has a miniupnp infinite loop in which it allocates memory on the basis of random data received over the network, e.EPSS 0.3%CVE-2026-66080MEDIUMRabbitMQ: Super-stream partitions unbounded allocationEPSS 0.3%CVE-2024-48843HIGHDenial of Service, DoSEPSS 0.3%CVE-2024-4029MEDIUMWildfly: no timeout for eap management interface may lead to denial of service (dos)EPSS 0.3%