Fallos del tipo CWE-770
1864 resultadosAlocação sem limite de recursos
A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.
Ejemplo
Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.
Cómo mitigar
Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.
CVE-2026-20608MEDIUMThis issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iEPSS 0.2%CVE-2024-34027HIGHf2fs: compress: fix to cover {reserve,release}_compress_blocks() w/ cp_rwsem lockEPSS 0.2%CVE-2025-20141HIGHCisco IOS XR Software Release 7.9.2 Denial of Service VulnerabillityEPSS 0.2%CVE-2025-5683MEDIUMWhen loading a specifically crafted ICNS format image file in QImage then it will trigger a crash.
This issue affects Qt from versions 6.3EPSS 0.2%CVE-2026-96609HIGHRobur Albatross 1.0.0 through 2.x before 2.7.2 does not limit use of the ring buffer, leading to an albatross-console loop with no recognizeEPSS 0.2%CVE-2024-50271MEDIUMsignal: restore the override_rlimit logicEPSS 0.2%CVE-2023-32385—A denial-of-service issue was addressed with improved memory handling. This issue is fixed in iOS 16.5 and iPadOS 16.5, macOS Ventura 13.4. EPSS 0.2%CVE-2021-47784MEDIUMCyberfox Web Browser 52.9.1 - Denial of Service (PoC)EPSS 0.2%CVE-2026-92078MEDIUMDenial-of-service in the Security componentEPSS 0.2%CVE-2023-52529MEDIUMHID: sony: Fix a potential memory leak in sony_probe()EPSS 0.2%CVE-2026-10533MEDIUMOpenshift: openshift: non-admin user can bypass resourcequota and flood etcd with events causing cluster-wide api degradationEPSS 0.2%CVE-2024-6176MEDIUMPort scanning vulnerability in LG SuperSign CMSEPSS 0.2%CVE-2024-58089HIGHbtrfs: fix double accounting race when btrfs_run_delalloc_range() failedEPSS 0.2%CVE-2024-26276MEDIUMA vulnerability has been identified in JT2Go (All versions < V2312.0004), Parasolid V35.1 (All versions < V35.1.254), Parasolid V36.0 (All vEPSS 0.2%CVE-2024-56722MEDIUMRDMA/hns: Fix cpu stuck caused by printings during resetEPSS 0.2%CVE-2021-47057MEDIUMcrypto: sun8i-ss - Fix memory leak of object d when dma_iv fails to mapEPSS 0.2%CVE-2023-28428MEDIUMPDFio vulnerable to Denial Of Service when opening a corrupt PDF fileEPSS 0.2%CVE-2025-14341HIGHInput Data Manipulation in DivvyDrive Information Technologies' DivvyDriveEPSS 0.2%CVE-2021-1121MEDIUMNVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager kernel driver, where a vGPU can cause resource starvation among othEPSS 0.2%CVE-2025-1823LOWIBM Jazz Reporting Service Denial of ServiceEPSS 0.2%