Falhas do tipo CWE-400

2.995 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2023-28626MEDIUMQuadratic runtime when parsing Markdown in comrakEPSS 1.1%CVE-2024-20962MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 aEPSS 1.1%CVE-2023-23447HIGHUncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 112252EPSS 1.1%CVE-2026-26018HIGHCoreDNS Loop Detection Denial of Service VulnerabilityEPSS 1.1%CVE-2023-43646HIGHInefficient Regular Expression Complexity in get-func-nameEPSS 1.1%CVE-2022-29167HIGHReDoS vulnerability in header parsing in hawkEPSS 1.1%CVE-2024-0241HIGHencoded_id-rails Denial of Service VulnerabilityEPSS 1.1%CVE-2022-41861MEDIUMA flaw was found in freeradius. A malicious RADIUS client or home server can send a malformed abinary attribute which can cause the server tEPSS 1.1%CVE-2024-4549HIGHDelta Electronics DIAEnergie SQL Injection EPSS 1.1%CVE-2023-22486LOWcmark-gfm Quadratic complexity bug in handle_close_bracket may lead to a denial of serviceEPSS 1.1%CVE-2022-33142HIGHWordPress Better Messages plugin <= 1.9.10.57 - Denial Of Service (DoS) vulnerabilityEPSS 1.1%CVE-2024-20985MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: UDF). Supported versions that are affected are 8.0.35 and priEPSS 1.1%CVE-2018-10868redhat-certification 7 does not properly restrict the number of recursive definitions of entities in XML documents, allowing an unauthenticaEPSS 1.1%CVE-2022-31006HIGHHyperledger Indy DOS vulnerabilityEPSS 1.1%CVE-2024-20961MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 aEPSS 1.1%CVE-2022-2455MEDIUMA business logic issue in the handling of large repositories in all versions of GitLab CE/EE from 10.0 before 15.1.6, all versions starting EPSS 1.1%CVE-2023-42670MEDIUMSamba: ad dc busy rpc multiple listener dosEPSS 1.1%CVE-1999-0159LOWAttackers can crash a Cisco IOS router or device, provided they can get to an interactive prompt (such as a login). This applies to some IOEPSS 1.1%CVE-2018-16490A prototype pollution vulnerability was found in module mpath <0.5.1 that allows an attacker to inject arbitrary properties onto Object.protEPSS 1.1%CVE-2021-26260An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could EPSS 1.1%