Falhas do tipo CWE-400

2.979 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2020-3190MEDIUMCisco IOS XR Software IPsec Packet Processor Denial of Service VulnerabilityEPSS 1.3%CVE-2021-22882UniFi Protect before v1.17.1 allows an attacker to use spoofed cameras to perform a denial-of-service attack that may cause the UniFi ProtecEPSS 1.3%CVE-2024-47554MEDIUMApache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReaderEPSS 1.3%CVE-2001-0827HIGHCerberus FTP server 1.0 - 1.5 allows remote attackers to cause a denial of service (crash) via a large number of "PASV" requests.EPSS 1.3%CVE-2022-1259A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial EPSS 1.3%CVE-2021-1460MEDIUMCisco IOx Application Framework Denial of Service VulnerabilityEPSS 1.3%CVE-2023-3637MEDIUMOpenstack-neutron: unrestricted creation of security groups (fix for cve-2022-3277)EPSS 1.3%CVE-2023-30798HIGHMultipartParser DOS with too many fields or files in Starlette FrameworkEPSS 1.3%CVE-2021-25909HIGHZIV AUTOMATION 4CCT Denial of Service vulnerabilityEPSS 1.3%CVE-2021-3629A flaw was found in Undertow. A potential security issue in flow control handling by the browser over http/2 may potentially cause overhead EPSS 1.3%CVE-2016-10544uws is a WebSocket server library. By sending a 256mb websocket message to a uws server instance with permessage-deflate enabled, there is aEPSS 1.3%CVE-2021-42521There is a NULL pointer dereference vulnerability in VTK before 9.2.5, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. The vendor didn't cheEPSS 1.3%CVE-2023-35945HIGHEnvoy vulnerable to HTTP/2 memory leak in nghttp2 codecEPSS 1.3%CVE-2019-5445DoS in EdgeMAX EdgeSwitch prior to 1.8.2 allow an Admin user to Crash the SSH CLI interface by using crafted commands.EPSS 1.3%CVE-2020-36620LOWBrondahl EnumStringValues EnumExtensions.cs GetStringValuesWithPreferences_Uncache resource consumptionEPSS 1.3%CVE-2024-41123MEDIUMREXML DoS vulnerabilityEPSS 1.3%CVE-2021-39295HIGHIn OpenBMC 2.9, crafted IPMI messages allow an attacker to cause a denial of service to the BMC via the netipmid (IPMI lan+) interface.EPSS 1.3%CVE-2022-32508HIGHAn issue was discovered on certain Nuki Home Solutions devices. By sending a malformed HTTP verb, it is possible to force a reboot of the deEPSS 1.3%CVE-2024-32007HIGHApache CXF Denial of Service vulnerability in JOSEEPSS 1.3%CVE-2020-7507A CWE-400: Uncontrolled Resource Consumption vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an atEPSS 1.3%