Falhas do tipo CWE-400

2.994 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2021-29509HIGHKeepalive Connections Causing Denial Of Service in pumaEPSS 1.6%CVE-2023-5724HIGHDrivers are not always robust to extremely large draw calls and in some cases this scenario could have led to a crash. This vulnerability afEPSS 1.6%CVE-2016-10527The riot-compiler version version 2.3.21 has an issue in a regex (Catastrophic Backtracking) thats make it unusable under certain conditionsEPSS 1.6%CVE-2022-20760HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software DNS Inspection Denial of Service VulnerabilityEPSS 1.6%CVE-2022-24726HIGHUnauthenticated control plane denial of service attack in IstioEPSS 1.6%CVE-2022-4899HIGHA vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause bufferEPSS 1.6%CVE-2018-15377Cisco IOS and IOS XE Software Plug and Play Agent Memory Leak VulnerabilityEPSS 1.6%CVE-2019-18904MEDIUMMigrations requests can cause DoS on rmtEPSS 1.6%CVE-2017-16099The no-case module is vulnerable to regular expression denial of service. When malicious untrusted user input is passed into no-case it can EPSS 1.6%CVE-2017-16119Fresh is a module used by the Express.js framework for HTTP response freshness testing. It is vulnerable to a regular expression denial of sEPSS 1.6%CVE-2017-16117slug is a module to slugify strings, even if they contain unicode. slug is vulnerable to regular expression denial of service is specially cEPSS 1.6%CVE-2017-16013hapi is a web and services application framework. When hapi >= 15.0.0 <= 16.1.0 encounters a malformed `accept-encoding` header an uncaught EPSS 1.6%CVE-2022-29225HIGHZip bomb vulnerability in EnvoyEPSS 1.6%CVE-2023-2295HIGHA vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unEPSS 1.6%CVE-2023-32067HIGH0-byte UDP payload DoS in c-aresEPSS 1.6%CVE-2019-0033HIGHSRX Series: A remote attacker may cause a high CPU Denial of Service to the device when proxy ARP is configured.EPSS 1.6%CVE-2022-31054HIGHUses of deprecated API can be used to cause DoS in user-facing endpoints in Argo EventsEPSS 1.6%CVE-2019-6578A vulnerability has been identified in SINAMICS PERFECT HARMONY GH180 with NXG I control, MLFBs: 6SR2...-, 6SR3...-, 6SR4...- (All Versions EPSS 1.6%CVE-2019-10948Fujifilm FCR Capsula X/ Carbon X/ FCR XC-2, model versions CR-IR 357 FCR Carbon X, CR-IR 357 FCR XC-2, FCR-IR 357 FCR Capsula X are susceptiEPSS 1.6%CVE-2020-3181MEDIUMCisco Email Security Appliance Uncontrolled Resource Exhaustion VulnerabilityEPSS 1.6%