Fallos del tipo CWE-770

1864 resultados

Alocação sem limite de recursos

A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.

Ejemplo

Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.

Cómo mitigar

Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.

CVE-2024-6004MEDIUMA denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to dEPSS 0.3%CVE-2026-94455HIGHUnauthenticated /enterprise/create-user mints lifetime top-tier organizations and discloses their API keyEPSS 0.3%CVE-2025-24112MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3. Parsing a file may lead to an EPSS 0.3%CVE-2026-67219MEDIUMRabbitMQ: Consistent-hash exchange unbounded weightEPSS 0.3%CVE-2025-48074MEDIUMOpenEXR's Unbounded File Header Values can Lead to Out-Of-Memory ErrorsEPSS 0.3%CVE-2026-67235HIGHRabbitMQ: AMQP 0-9-1 body assembly never validates accumulated sizeEPSS 0.3%CVE-2019-25350MEDIUMXMedia Recode 3.4.8.6 - '.m3u' Denial Of ServiceEPSS 0.3%CVE-2024-10307MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.3%CVE-2022-42314MEDIUMXenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/EPSS 0.3%CVE-2025-52889LOWIncus vulnerable to DoS through antispoofing nftables firewall rule bypass on bridge networks with ACLsEPSS 0.3%CVE-2024-26894MEDIUMACPI: processor_idle: Fix memory leak in acpi_processor_power_exit()EPSS 0.3%CVE-2021-47771MEDIUMRDP Manager 4.9.9.3 - Denial-of-Service (PoC)EPSS 0.3%CVE-2025-54151MEDIUMQsync CentralEPSS 0.3%CVE-2026-1850HIGHAn authorized user may disable the MongoDB server by issuing a certain type of complex query due to boolean expression simplificationEPSS 0.3%CVE-2025-54149MEDIUMQsync CentralEPSS 0.3%CVE-2026-1847HIGHMongoDB Server may crash when inserting large documentsEPSS 0.3%CVE-2022-42317MEDIUMXenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/EPSS 0.3%CVE-2022-42316MEDIUMXenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/EPSS 0.3%CVE-2022-28654MEDIUMis_closing_session() allows users to fill up apport.logEPSS 0.3%CVE-2022-42313MEDIUMXenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/EPSS 0.3%