Fallos del tipo CWE-770

1864 resultados

Alocação sem limite de recursos

A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.

Ejemplo

Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.

Cómo mitigar

Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.

CVE-2025-58347MEDIUMAn issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480EPSS 0.1%CVE-2025-58343MEDIUMAn issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480EPSS 0.1%CVE-2025-58348MEDIUMAn issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480EPSS 0.1%CVE-2026-71224MEDIUMGfs2-utils: gfs2-utils: stack overflow via alloca(i_height) in metadata walkEPSS 0.1%CVE-2026-71219MEDIUMGfs2-utils: gfs2-utils: stack overflow via alloca(1<<di_depth) in hash table traversalEPSS 0.1%CVE-2025-14876MEDIUMQemu-kvm: unbounded allocation in virtio-cryptoEPSS 0.1%CVE-2025-45526LOWA denial of service (DoS) vulnerability has been identified in the JavaScript library microlight version 0.0.7. This library, used for syntaEPSS 0.1%CVE-2026-19617MEDIUMLibdm: lvm2: libdm: denial of service via uncontrolled recursion in config parserEPSS 0.1%CVE-2026-31961MEDIUMUnbounded memory allocation in Quill via unvalidated size fields in Mach-O binary parsingEPSS 0.1%CVE-2026-6053MEDIUMIBM® Db2® is vulnerable to a denial of service when a specially crafted query is run with range partitioned tablesEPSS 0.1%CVE-2026-28237MEDIUMUnrestricted resource allocation in AMD uProf may be exploitable to consume excessive system resources, potentially leading to a loss of avaEPSS 0.1%CVE-2023-28899MEDIUMDenial of Service via ECU reset serviceEPSS 0.1%CVE-2026-13322LOWKubevirt: virt-handler-rhel9: kubevirt: unbounded virtio-serial readline in virt-handler causes oom denial of serviceEPSS 0.1%CVE-2026-45078MEDIUMSynapse CPU starvation (Denial of Service)EPSS 0.1%CVE-2026-39959HIGHTmds.DBus: malicious D-Bus peers can spoof signals, exhaust file descriptor resources, and cause denial of serviceEPSS 0.1%CVE-2025-36035MEDIUMIBM PowerVM Hypervisor denial of serviceEPSS 0.1%CVE-2026-18096LOWIBM® Db2® could allow a local attacker to cause a denial of service due to a memory leakEPSS 0.1%CVE-2026-12570MEDIUMDenial of Service via HDF5 Shape Bomb in keras.models.load_model() in keras-team/kerasEPSS 0.1%CVE-2022-20487HIGHIn NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. EPSS 0.1%CVE-2022-20486HIGHIn NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. EPSS 0.1%