Fallos del tipo CWE-770
1864 resultadosAlocação sem limite de recursos
A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.
Ejemplo
Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.
Cómo mitigar
Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.
CVE-2023-30903—HP-UX could be exploited locally to create a Denial of Service (DoS) when any physical interface is configured with IPv6/inet6. EPSS 0.2%CVE-2026-31826MEDIUMpypdf: manipulated stream length values can exhaust RAMEPSS 0.2%CVE-2025-68138MEDIUMEVerest affected by memory exhaustion in libocppEPSS 0.2%CVE-2026-44931MEDIUMmalcontent: Disk Space Exhaustion via Globally Accessible D-Bus APIEPSS 0.2%CVE-2019-25464MEDIUMInputMapper 1.6.10 Local Denial of Service via Username FieldEPSS 0.2%CVE-2022-20484HIGHIn NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. EPSS 0.2%CVE-2022-20478HIGHIn NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. EPSS 0.2%CVE-2022-20479HIGHIn NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. EPSS 0.2%CVE-2025-55079MEDIUMMissing check for thread priorityEPSS 0.2%CVE-2025-13751LOWInteractive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a local authenticated useEPSS 0.2%CVE-2025-59418MEDIUMBunnyPad Vulnerable to Buffer Overflow When Opening Files of Size 20MB or GreaterEPSS 0.2%CVE-2023-47717MEDIUMIBM Security Guardium denial of serviceEPSS 0.2%CVE-2026-45682MEDIUMOpenTelemetry eBPF Instrumentation: CappedConcurrentHashMap leaks keys after removalsEPSS 0.2%CVE-2026-71139MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2026-13585HIGHAllocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System ContEPSS 0.2%CVE-2025-52657LOWHCL MyXalytics is affected by multiple security vulnerabilities.EPSS 0.2%CVE-2025-58342MEDIUMAn issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480EPSS 0.2%CVE-2025-58344MEDIUMAn issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480EPSS 0.2%CVE-2025-58340MEDIUMAn issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480EPSS 0.2%CVE-2025-58341MEDIUMAn issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480EPSS 0.2%