Fallos del tipo CWE-770
1864 resultadosAlocação sem limite de recursos
A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.
Ejemplo
Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.
Cómo mitigar
Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.
CVE-2022-20486HIGHIn NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. EPSS 0.1%CVE-2026-31960MEDIUMDoS in Quill via unbounded read of HTTP response body during notarizationEPSS 0.1%CVE-2026-81886MEDIUMradare2: Uncontrolled memory allocation in radare2 dmp64 parserEPSS 0.1%CVE-2026-81885MEDIUMradare2: Infinite relocation-chain loop causes denial of service in radare2 NE parserEPSS 0.1%CVE-2025-58346MEDIUMAn issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480EPSS 0.1%CVE-2025-58345MEDIUMAn issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480EPSS 0.1%CVE-2026-14330MEDIUMPipewire: pulse server alloca stack overflowEPSS 0.1%CVE-2024-58114MEDIUMResource allocation control failure vulnerability in the ArkUI framework
Impact: Successful exploitation of this vulnerability may affect avEPSS 0.1%CVE-2025-36136MEDIUMIBM denial of serviceEPSS 0.1%CVE-2024-31314MEDIUMIn multiple functions of ShortcutService.java, there is a possible persistent DOS due to resource exhaustion. This could lead to local deniaEPSS 0.1%CVE-2026-25281HIGHAllocation of Resources Without Limits or Throttling in OOBMEPSS 0.1%CVE-2024-43083MEDIUMIn validate of WifiConfigurationUtil.java , there is a possible persistent denial of service due to resource exhaustion. This could lead to EPSS 0.1%CVE-2023-21176—In list_key_entries of utils.rs, there is a possible way to disable user credentials due to resource exhaustion. This could lead to local deEPSS 0.1%CVE-2023-21110HIGHIn several functions of SnoozeHelper.java, there is a possible way to grant notifications access due to resource exhaustion. This could leadEPSS 0.1%CVE-2026-28633MEDIUMIn initForUserNoTracing of VoiceInteractionManagerService.java, there is a possible persistent denial of service due to resource exhaustion.EPSS 0.1%CVE-2023-20930MEDIUMIn pushDynamicShortcut of ShortcutPackage.java, there is a possible way to get the device into a boot loop due to resource exhaustion. This EPSS 0.1%CVE-2022-48440MEDIUMIn dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution priEPSS 0.1%CVE-2022-48441MEDIUMIn dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution priEPSS 0.1%CVE-2026-91043HIGHHPACK-indexed cookie fields in Mint HTTP/2 responses bypass max_header_list_size and exhaust client memoryEPSS —CVE-2026-101911MEDIUMip-address: Address6 builds a parse diagnostic proportional to the input with no length bound, allowing a single long string to stall or crash the processEPSS —