Falhas do tipo CWE-400

2.951 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2022-39158MEDIUMA vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC,EPSS 1.5%CVE-2017-16023Decamelize is used to convert a dash/dot/underscore/space separated string to camelCase. Decamelize 1.1.0 through 1.1.1 uses regular expressEPSS 1.5%CVE-2019-13925A vulnerability has been identified in SCALANCE S602 (All versions >= V3.0 and < V4.1), SCALANCE S612 (All versions >= V3.0 and < V4.1), SCAEPSS 1.5%CVE-2018-3767`memjs` versions <= 1.1.0 allocates and stores buffers on typed input, resulting in DoS and uninitialized memory usage.EPSS 1.5%CVE-2023-38200HIGHKeylime: registrar is subject to a dos against ssl connectionsEPSS 1.4%CVE-2024-24575HIGHlibgit2 is vulnerable to a denial of service attack in `git_revparse_single`EPSS 1.4%CVE-2023-27334HIGHSofting edgeConnector Siemens ConditionRefresh Resource Exhaustion Denial-of-Service VulnerabilityEPSS 1.4%CVE-2023-39180MEDIUMKernel: ksmbd: read request memory leak denial-of-service vulnerabilityEPSS 1.4%CVE-2020-3528HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software OSPFv2 Link-Local Signaling Denial of Service VulnerabilityEPSS 1.4%CVE-2024-22201HIGHJetty connection leaking on idle timeout when TCP congestedEPSS 1.4%CVE-2022-27194A vulnerability has been identified in SIMATIC PCS neo (Administration Console) (All versions < V3.1 SP1), SINETPLAN (All versions), TIA PorEPSS 1.4%CVE-2021-34792HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software Resource Exhaustion Denial of Service VulnerabilityEPSS 1.4%CVE-2022-43766HIGHApache IoTDB prior to 0.13.3 allows DoSEPSS 1.4%CVE-2021-32723HIGHRegular Expression Denial of Service (ReDoS) in PrismEPSS 1.4%CVE-2022-41404HIGHAn issue in the fetch() method in the BasicProfile class of org.ini4j through version v0.5.4 allows attackers to cause a Denial of Service (EPSS 1.4%CVE-2023-40584MEDIUMDenial of Service to Argo CD repo-server EPSS 1.4%CVE-2022-3283HIGHA potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before before 15.2.5, all versions starting from 15.3 beEPSS 1.4%CVE-2020-3560HIGHCisco Aironet Access Points UDP Flooding Denial of Service VulnerabilityEPSS 1.4%CVE-2020-3563HIGHCisco Firepower Threat Defense Software TCP Flood Denial of Service VulnerabilityEPSS 1.4%CVE-2022-36049HIGHFlux2 Helm Controller denial of serviceEPSS 1.4%