Falhas do tipo CWE-400

3.039 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2021-47284MEDIUMisdn: mISDN: netjet: Fix crash in nj_probe:EPSS 0.2%CVE-2021-4440HIGHx86/xen: Drop USERGS_SYSRET64 paravirt callEPSS 0.2%CVE-2024-35948HIGHbcachefs: Check for journal entries overruning end of sb clean sectionEPSS 0.2%CVE-2025-13837LOWOut-of-memory when loading PlistEPSS 0.2%CVE-2024-39479HIGHdrm/i915/hwmon: Get rid of devmEPSS 0.2%CVE-2025-55028MEDIUMJavaScript alerts could impede UI interaction or allow denial of service attacksEPSS 0.2%CVE-2024-34036MEDIUMAn issue was discovered in O-RAN Near Realtime RIC I-Release. To exploit this vulnerability, an attacker can disrupt the initial connection EPSS 0.2%CVE-2021-25701—The fUSBHub driver in the PCoIP Software Client prior to version 21.07.0 had an error in object management during the handling of a variety EPSS 0.2%CVE-2025-20616LOWUncontrolled resource consumption for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to pEPSS 0.2%CVE-2024-25112MEDIUMDenial of service due to unbounded recursion in QuickTimeVideo::multipleEntriesDecoder in Exiv2EPSS 0.2%CVE-2026-12759MEDIUMMultiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for August 2026.EPSS 0.2%CVE-2026-49762MEDIUMUnbounded integer parsing in the Version module enables CPU and memory exhaustion denial of serviceEPSS 0.2%CVE-2023-4394MEDIUMMemory leak in btrfs_get_dev_args_from_path()EPSS 0.2%CVE-2025-20084MEDIUMUncontrolled resource consumption for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to pEPSS 0.2%CVE-2025-20057MEDIUMUncontrolled resource consumption for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to pEPSS 0.2%CVE-2026-21500MEDIUMStack Overflow in iccDEV XML Calculator Macro ExpansionEPSS 0.2%CVE-2025-31245MEDIUMThe issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS SonoEPSS 0.2%CVE-2023-28938LOWUncontrolled resource consumption in some Intel(R) SSD Tools software before version mdadm-4.2-rc2 may allow a priviledged user to potentialEPSS 0.2%CVE-2025-26500MEDIUMVxWorks 7 USB FailureEPSS 0.2%CVE-2026-42626MEDIUMHP ENVY 5000 series printers VERBASPP1N003.2237A.00 do not properly manage concurrent TCP connections to port 9100 (JetDirect/RAW printing).EPSS 0.2%