Fallos del tipo CWE-770

1864 resultados

Alocação sem limite de recursos

A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.

Ejemplo

Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.

Cómo mitigar

Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.

CVE-2026-1847HIGHMongoDB Server may crash when inserting large documentsEPSS 0.3%CVE-2022-42318MEDIUMXenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/EPSS 0.3%CVE-2022-42315MEDIUMXenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/EPSS 0.3%CVE-2022-28654MEDIUMis_closing_session() allows users to fill up apport.logEPSS 0.3%CVE-2025-54150MEDIUMQsync CentralEPSS 0.3%CVE-2025-68659MEDIUMDiscourse has DoS vulnerability in username change endpointEPSS 0.2%CVE-2026-88359MEDIUMlibfyaml 0.9.6 contains a stack exhaustion vulnerability in fy_atom_iter_format(). When processing a specially crafted YAML document containEPSS 0.2%CVE-2026-49324MEDIUMIndian Scout Bobber 2025 WCM brute-forceEPSS 0.2%CVE-2025-64529LOWSpiceDB's WriteRelationships fails silently if payload is too bigEPSS 0.2%CVE-2025-21866MEDIUMpowerpc/code-patching: Fix KASAN hit by not flagging text patching area as VM_ALLOCEPSS 0.2%CVE-2025-4437MEDIUMCri-o: large /etc/passwd file may lead to denial of serviceEPSS 0.2%CVE-2026-55996MEDIUMUnauthenticated Denial-of-Service via TLS SAN Stuffing in Rancher and cattle-cluster-agentEPSS 0.2%CVE-2022-40885MEDIUMBento4 v1.6.0-639 has a memory allocation issue that can cause denial of service.EPSS 0.2%CVE-2025-36122MEDIUMIBM® Db2® is vulnerable to a denial of service with a specially crafted query when stmtheap is set to automaticEPSS 0.2%CVE-2025-14299HIGHImproper Content-Length Validation in HTTPS Requests on Tapo C200EPSS 0.2%CVE-2025-48467MEDIUMDenial of Service via Malformed Modbus PacketsEPSS 0.2%CVE-2026-78321MEDIUMDJI Drone HTTP Media Server Denial of Service via Connection Pool ExhaustionEPSS 0.2%CVE-2026-2325MEDIUMImproper Input Validation in MS Teams Meetings API HandlerEPSS 0.2%CVE-2023-52518MEDIUMBluetooth: hci_codec: Fix leaking content of local_codecsEPSS 0.2%CVE-2026-14539MEDIUMDenial of Service via Unrestricted Payload Buffering in MCP ToolboxEPSS 0.2%