Falhas do tipo CWE-400

3.043 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2024-23712MEDIUMIn multiple functions of AppOpsService.java, there is a possible way to saturate the content of /data/system/appops_accesses.xml due to resoEPSS 0.1%CVE-2018-9412MEDIUMIn removeUnsynchronization of ID3.cpp there is a possible resource exhaustion due to improper input validation. This could lead to denial ofEPSS 0.1%CVE-2025-26449MEDIUMIn multiple locations, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of servicEPSS 0.1%CVE-2022-47356MEDIUMIn log service, there is a missing permission check. This could lead to local denial of service in log service.EPSS 0.1%CVE-2025-48542MEDIUMIn multiple functions of AccountManagerService.java, there is a possible permanent denial of service due to resource exhaustion. This could EPSS 0.1%CVE-2024-40664MEDIUMIn setupAccessibilityServices of AccessibilityFragment.java , there is a possible way to hide an enabled accessibility service due to a logiEPSS 0.1%CVE-2022-47354MEDIUMIn log service, there is a missing permission check. This could lead to local denial of service in log service.EPSS 0.1%CVE-2022-47355MEDIUMIn log service, there is a missing permission check. This could lead to local denial of service in log service.EPSS 0.1%CVE-2024-32912MEDIUMthere is a possible persistent Denial of Service due to test/debugging code left in a production build. This could lead to local denial of sEPSS 0.1%CVE-2025-48569MEDIUMIn multiple locations, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of servicEPSS 0.1%CVE-2026-0074MEDIUMIn getPreferredSize of LauncherProcessImageListener.kt, there is a possible denial of service due to resource exhaustion. This could lead tEPSS 0.1%CVE-2026-0069MEDIUMIn verifySignature of ApkChecksums.java, there is a possible way to cause a crash due to resource exhaustion. This could lead to local deniaEPSS 0.1%CVE-2026-0042MEDIUMIn multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to resource exhaustion. This couldEPSS 0.1%CVE-2025-48648MEDIUMIn isSameApp of NotificationManagerService.java, there is a possible persistent dos due to resource exhaustion. This could lead to local denEPSS 0.1%CVE-2026-100242—DataTransfer depends on phpspreadsheet version vulnerable to CVE-2026-59933 (XLS/OLE memory exhaustion)EPSS —CVE-2026-102993HIGHpypdf: Possible large memory usage when retrieving Roman page labelsEPSS —CVE-2026-18105HIGHFireware OS Uncontrolled Resource Consumption in Diagnostic Tasks Allows Denial of ServiceEPSS —CVE-2026-47568MEDIUMNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could cause uncontrolled kernel log generEPSS —CVE-2026-102821MEDIUMRussh: Unbounded memory exhaustion via CHANNEL_OPEN flood during a client-stalled rekeyEPSS —CVE-2026-86104HIGHFireware OS Resource Exhaustion in Login Process Allows Denial of ServiceEPSS —