Falhas do tipo CWE-400

2.982 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2021-20201A flaw was found in spice in versions before 0.14.92. A DoS tool might make it easier for remote attackers to cause a denial of service (CPUEPSS 2.7%CVE-2024-38168HIGH.NET and Visual Studio Denial of Service VulnerabilityEPSS 2.7%CVE-2025-21230HIGHMicrosoft Message Queuing (MSMQ) Denial of Service VulnerabilityEPSS 2.7%CVE-2018-0285A vulnerability in service logging for Cisco Prime Service Catalog could allow an authenticated, remote attacker to deny service to the userEPSS 2.7%CVE-2024-26215HIGHDHCP Server Service Denial of Service VulnerabilityEPSS 2.7%CVE-2021-43854HIGHInefficient Regular Expression Complexity in nltkEPSS 2.7%CVE-2020-3554HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software Denial of Service VulnerabilityEPSS 2.7%CVE-2018-4837A vulnerability has been identified in TeleControl Server Basic < V3.1. An attacker with access to the TeleControl Server Basic's webserver EPSS 2.7%CVE-2023-28320MEDIUMA denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, seEPSS 2.7%CVE-2018-14638HIGHA flaw was found in 389-ds-base before version 1.3.8.4-13. The process ns-slapd crashes in delete_passwdPolicy function when persistent searEPSS 2.6%CVE-2026-38361HIGHMultiple unauthenticated denial-of-service (DoS) issues in fohrloop dash-uploader v0.1.0 through v0.7.0a2. The chunked-upload handler (dash_EPSS 2.6%CVE-2017-6024A Resource Exhaustion issue was discovered in Rockwell Automation ControlLogix 5580 controllers V28.011, V28.012, and V28.013; ControlLogix EPSS 2.6%CVE-2023-29331HIGH.NET, .NET Framework, and Visual Studio Denial of Service VulnerabilityEPSS 2.6%CVE-2025-26673HIGHWindows Lightweight Directory Access Protocol (LDAP) Denial of Service VulnerabilityEPSS 2.6%CVE-2024-49075HIGHWindows Remote Desktop Services Denial of Service VulnerabilityEPSS 2.6%CVE-2024-30019MEDIUMDHCP Server Service Denial of Service VulnerabilityEPSS 2.6%CVE-2020-12667HIGHKnot Resolver before 5.1.1 allows traffic amplification via a crafted DNS answer from an attacker-controlled server, aka an "NXNSAttack" issEPSS 2.6%CVE-2019-1737HIGHCisco IOS and IOS XE Software IP Service Level Agreement Denial of Service VulnerabilityEPSS 2.6%CVE-2016-8627MEDIUMadmin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulnerable to an EAP feature to download server log files that allows logs to be availEPSS 2.6%CVE-2009-3791HIGHUnspecified vulnerability in Adobe Flash Media Server (FMS) before 3.5.3 allows attackers to cause a denial of service (resource exhaustion)EPSS 2.6%