Falhas do tipo CWE-400

2.993 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2014-2342Triangle MicroWorks SCADA Data Gateway Resource ExhaustionEPSS 1.8%CVE-2020-3572HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software SSL/TLS Session Denial of Service VulnerabilityEPSS 1.8%CVE-2023-35298HIGHHTTP.sys Denial of Service VulnerabilityEPSS 1.8%CVE-2019-3874MEDIUMThe SCTP socket buffer used by a userspace application is not accounted by the cgroups subsystem. An attacker can use this flaw to cause a dEPSS 1.8%CVE-2024-23443MEDIUMA high-privileged user, allowed to create custom osquery packs 17 could affect the availability of Kibana by uploading a maliciously craftedEPSS 1.8%CVE-2020-3533HIGHCisco Firepower Threat Defense Software SNMP Denial of Service VulnerabilityEPSS 1.8%CVE-2018-13296HIGHUncontrolled resource consumption vulnerability in TLS configuration in Synology MailPlus Server before 2.0.5-0606 allows remote attackers tEPSS 1.8%CVE-2016-10540Minimatch is a minimal matching utility that works by converting glob expressions into JavaScript `RegExp` objects. The primary function, `mEPSS 1.8%CVE-2017-16114The marked module is vulnerable to a regular expression denial of service. Based on the information published in the public issue, 1k characEPSS 1.8%CVE-2026-26171HIGH.NET Denial of Service VulnerabilityEPSS 1.8%CVE-2025-33068HIGHWindows Standards-Based Storage Management Service Denial of Service VulnerabilityEPSS 1.8%CVE-2024-33655HIGHThe DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS quEPSS 1.7%CVE-2022-40617HIGHstrongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and iEPSS 1.7%CVE-2021-21271MEDIUMDenial of service in TenderMint CoreEPSS 1.7%CVE-2021-41115MEDIUMRegular expression denial-of-service in ZulipEPSS 1.7%CVE-2023-21543HIGHWindows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution VulnerabilityEPSS 1.7%CVE-2023-42669MEDIUMSamba: "rpcecho" development server allows denial of service via sleep() call on ad dcEPSS 1.7%CVE-2019-19300HIGHA vulnerability has been identified in Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200, Development/Evaluation Kits for PROFINET IEPSS 1.7%CVE-2018-16491A prototype pollution vulnerability was found in node.extend <1.1.7, ~<2.0.1 that allows an attacker to inject arbitrary properties onto ObjEPSS 1.7%CVE-2019-18336HIGHA vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions < V3.X.17), SIEPSS 1.7%