Falhas do tipo CWE-400

2.988 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2021-43843MEDIUMInsufficient patch for Regular Expression Denial of Service (ReDoS) to jsx-slack v4.5.1EPSS 1.9%CVE-2017-16025Nes is a websocket extension library for hapi. Hapi is a webserver framework. Versions below and including 6.4.0 have a denial of service vuEPSS 1.9%CVE-2021-39229HIGHRegular expression deinal of service in appriseEPSS 1.9%CVE-2023-24534HIGHExcessive memory allocation in net/http and net/textprotoEPSS 1.9%CVE-2020-12516HIGHWAGO: PLC families 750-88x and 750-352 prone to DoS attackEPSS 1.9%CVE-2023-35339HIGHWindows CryptoAPI Denial of Service VulnerabilityEPSS 1.9%CVE-2020-26264MEDIUMLES Server DoS via GetProofsV2EPSS 1.9%CVE-2018-10924MEDIUMIt was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch aEPSS 1.9%CVE-2019-12700HIGHCisco FTD, FMC, and FXOS Software Pluggable Authentication Module Denial of Service VulnerabilityEPSS 1.9%CVE-2024-12254HIGHUnbounded memory buffering in SelectorSocketTransport.writelines()EPSS 1.9%CVE-2021-32823LOWPotential Denial-of-Service in bindataEPSS 1.9%CVE-2021-32838HIGHRegular Expression Denial of Service in flask-restxEPSS 1.9%CVE-2020-3529HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software SSL VPN Direct Memory Access Denial of Service VulnerabilityEPSS 1.9%CVE-2017-15133A denial of service flaw was found in miekg-dns before 1.0.4. A remote attacker could use carefully timed TCP packets to block the DNS serveEPSS 1.9%CVE-2025-24211CRITICALThis issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, EPSS 1.9%CVE-2025-24190CRITICALThe issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, mEPSS 1.9%CVE-2022-1210MEDIUMLibTIFF tiff2ps resource consumptionEPSS 1.9%CVE-2026-46522HIGHImageMagick: Infinite Loop in the MIFF decoder can lead to CPU exhaustionEPSS 1.8%CVE-2018-10935MEDIUMA flaw was found in the 389 Directory Server that allows users to cause a crash in the LDAP server using ldapsearch with server side sort.EPSS 1.8%CVE-2018-15399Cisco Adaptive Security Appliance TCP Syslog Denial of Service VulnerabilityEPSS 1.8%