Fallos del tipo CWE-770
1864 resultadosAlocação sem limite de recursos
A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.
Ejemplo
Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.
Cómo mitigar
Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.
CVE-2024-25969MEDIUMDell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an allocation of resources without limits or throttling vulnerability. A localEPSS 0.2%CVE-2025-1823LOWIBM Jazz Reporting Service Denial of ServiceEPSS 0.2%CVE-2024-45484HIGHEnabled ICMP redirection in B&R APROLEPSS 0.2%CVE-2026-42626MEDIUMHP ENVY 5000 series printers VERBASPP1N003.2237A.00 do not properly manage concurrent TCP connections to port 9100 (JetDirect/RAW printing).EPSS 0.2%CVE-2026-11993MEDIUMFix authenticated members disabling file content indexing server-wide via extraction pool exhaustionEPSS 0.2%CVE-2026-20406MEDIUMIn Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if a UE has connected EPSS 0.2%CVE-2026-59303LOWDynamic destination cache size is not properly bound in Spring Cloud StreamEPSS 0.2%CVE-2025-12748MEDIUMLibvirt: denial of service in xml parsingEPSS 0.2%CVE-2026-10573MEDIUM1734 POINT I/OTM - Denial of Service via Malformed Inputs on CIP ObjectEPSS 0.2%CVE-2022-28655HIGHis_closing_session() allows users to create arbitrary tcp dbus connectionsEPSS 0.2%CVE-2022-49035MEDIUMmedia: s5p_cec: limit msg.len to CEC_MAX_MSG_SIZEEPSS 0.2%CVE-2025-30409MEDIUMDenial of service due to allocation of resources without limits. The following products are affected: Acronis Cyber Protect Cloud Agent (WinEPSS 0.2%CVE-2025-11274MEDIUMOpen Asset Import Library Assimp Q3DLoader.cpp InternReadFile allocation of resourcesEPSS 0.2%CVE-2024-39876MEDIUMA vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected applications do not properly handle EPSS 0.2%CVE-2022-41288LOWA vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), TeamcenEPSS 0.2%CVE-2022-22240MEDIUMJunos OS and Junos OS Evolved: An rpd memory leak might be observed while running a specific cli command in a RIB sharding scenarioEPSS 0.2%CVE-2022-42531HIGHIn mmu_map_for_fw of gs_ldfw_load.c, there is a possible mitigation bypass due to Permissive Memory Allocation. This could lead to local escEPSS 0.2%CVE-2022-28656MEDIUMis_closing_session() allows users to consume RAM in the Apport processEPSS 0.2%CVE-2025-40570LOWA vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V10.0), SIPROTEC 5 6MD85 (CP300) (All versions >= V7.80 < V1EPSS 0.2%CVE-2023-38532MEDIUMA vulnerability has been identified in Parasolid V34.1 (All versions < V34.1.258), Parasolid V35.0 (All versions < V35.0.254), Parasolid V35EPSS 0.2%