Falhas do tipo CWE-400

3.041 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2022-39124MEDIUMIn sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kerneEPSS 0.1%CVE-2022-39127MEDIUMIn sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kerneEPSS 0.1%CVE-2022-39128MEDIUMIn sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kerneEPSS 0.1%CVE-2022-39126MEDIUMIn sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kerneEPSS 0.1%CVE-2022-39125MEDIUMIn sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kerneEPSS 0.1%CVE-2022-39123MEDIUMIn sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kerneEPSS 0.1%CVE-2025-33177MEDIUMNVIDIA Jetson Linux and IGX OS contain a vulnerability in NvMap, where improper tracking of memory allocations could allow a local attacker EPSS 0.1%CVE-2022-20455MEDIUMIn addAutomaticZenRule of ZenModeHelper.java, there is a possible persistent denial of service due to resource exhaustion. This could lead tEPSS 0.1%CVE-2026-87274MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.1%CVE-2022-38679MEDIUMIn music service, there is a missing permission check. This could lead to local denial of service in music service with no additional executEPSS 0.1%CVE-2024-43763MEDIUMIn build_read_multi_rsp of gatt_sr.cc, there is a possible denial of service due to a logic error in the code. This could lead to remote (prEPSS 0.1%CVE-2026-11478MEDIUMkokke tiny-regex-c Pattern re.c matchstar redosEPSS 0.1%CVE-2026-76702MEDIUMAuthenticated Local Denial-of-Service Vulnerability in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.1%CVE-2026-25122MEDIUMapko is vulnerable to unbounded resource consumption in expandapk.Split on attacker-controlled .apk streamsEPSS 0.1%CVE-2024-51513MEDIUMVulnerability of processes not being fully terminated in the VPN module Impact: Successful exploitation of this vulnerability will affect poEPSS 0.1%CVE-2025-48615HIGHIn getComponentName of MediaButtonReceiverHolder.java, there is a possible desync in persistence due to resource exhaustion. This could leadEPSS 0.1%CVE-2026-20780MEDIUMUncontrolled resource consumption for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow a deniEPSS 0.1%CVE-2025-46593MEDIUMProcess residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulnerability may affect aEPSS 0.1%CVE-2024-40575MEDIUMAn issue in Huawei Technologies opengauss (openGauss 5.0.0 build) v.7.3.0 allows a local attacker to cause a denial of service via the modifEPSS 0.1%CVE-2022-33303MEDIUMUncontrolled resource consumption in Linux kernelEPSS 0.1%