Falhas do tipo CWE-400

3.039 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2023-27734MEDIUMAn issue found in Eteran edb-debugger v.1.3.0 allows a local attacker to causea denial of service via the collect_symbols function in pluginEPSS 0.2%CVE-2025-43235MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. An app may be able to cause a denial-of-seEPSS 0.2%CVE-2023-3108MEDIUMKernel: a race condition in crypto module in the function skcipher_recvmsgEPSS 0.2%CVE-2026-8124MEDIUMGPAC box_code_base.c sidx_box_read allocation of resourcesEPSS 0.2%CVE-2025-4001MEDIUMscipopt scip File Descriptor genRandomLOPInstance.c main file descriptor consumptionEPSS 0.2%CVE-2025-27087MEDIUMA vulnerability in the kernel of the Cray Operating System (COS) could allow an attacker to perform a local Denial of Service (DoS) attack.EPSS 0.2%CVE-2019-25721HIGHDräger Infinity M300 VG2.3.1 Network-Based Denial of ServiceEPSS 0.2%CVE-2025-50096MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.42, 8.4.0EPSS 0.2%CVE-2026-53937MEDIUMMCP Kotlin SDK's unbounded line buffer in StdioServerTransport/StdioClientTransport leads to memory exhaustion (DoS)EPSS 0.2%CVE-2026-28575CRITICALIn PackageInstaller.Session#transfer of frameworks/base/services/core/java/com/android/server/pm/PackageInstallerSession.java, there is a poEPSS 0.2%CVE-2022-39164MEDIUMIBM AIX denial of serviceEPSS 0.2%CVE-2026-81720MEDIUMopenssl_encrypt before 1.4.9 Denial of Service via Unbounded Argon2EPSS 0.2%CVE-2022-39165MEDIUMIBM AIX denial of serviceEPSS 0.2%CVE-2026-58203MEDIUMNestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_sizeEPSS 0.2%CVE-2026-63119MEDIUMMCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)EPSS 0.2%CVE-2024-20959MEDIUMVulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected EPSS 0.2%CVE-2026-30980MEDIUMiccDEV has a stack overflow in CIccBasicStructFactory::CreateStruct()EPSS 0.2%CVE-2025-40766MEDIUMA vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected application runs dockEPSS 0.2%CVE-2026-71870MEDIUMpypdf: Possible large memory usage for large /ToUnicode streamsEPSS 0.2%CVE-2023-31348HIGHA DLL hijacking vulnerability in AMD μProf could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code EPSS 0.2%