Falhas do tipo CWE-400

2.995 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2024-20976MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 aEPSS 1.1%CVE-2018-7821HIGHAn Environment (CWE-2) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmwarEPSS 1.1%CVE-2024-20972MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 aEPSS 1.1%CVE-2024-49767MEDIUMWerkzeug possible resource exhaustion when parsing file data in formsEPSS 1.1%CVE-2022-22275Improper Restriction of TCP Communication Channel in HTTP/S inbound traffic from WAN to DMZ bypassing security policy until TCP handshake poEPSS 1.1%CVE-2016-10521jshamcrest is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in to the emailAddress vEPSS 1.1%CVE-2020-35510A flaw was found in jboss-remoting in versions before 5.0.20.SP1-redhat-00001. A malicious attacker could cause threads to hold up forever iEPSS 1.1%CVE-2022-39280MEDIUMRegular expression denial of service in dparseEPSS 1.1%CVE-2018-6332MEDIUMA potential denial-of-service issue in the Proxygen handling of invalid HTTP2 settings which can cause the server to spend disproportionate EPSS 1.1%CVE-2023-46118MEDIUMDenial of Service by publishing large messages over the HTTP APIEPSS 1.1%CVE-2022-37050MEDIUMIn Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (application crashes with SIGABRT) by crafEPSS 1.1%CVE-2023-29013HIGHHTTP header parsing could cause a deny of serviceEPSS 1.1%CVE-2021-31368HIGHJunos OS: EX2300 Series, EX3400 Series, and ACX710 might become unresponsive if the out-of-band management port receives a flood of trafficEPSS 1.1%CVE-2020-12524HIGHPhoenix Contact BTP Touch Panels uncontrolled resource consumptionEPSS 1.1%CVE-2019-16764MEDIUMPowAssent is susceptible to denial of service attacksEPSS 1.1%CVE-2025-15532MEDIUMOpen5GS Timer resource consumptionEPSS 1.1%CVE-2020-19850MEDIUMAn issue found in Directus API v.2.2.0 allows a remote attacker to cause a denial of service via a great amount of HTTP requests.EPSS 1.1%CVE-2020-8175Uncontrolled resource consumption in `jpeg-js` before 0.4.0 may allow attacker to launch denial of service attacks using specially a craftedEPSS 1.1%CVE-2023-40692MEDIUMIBM Db2 denial of serviceEPSS 1.1%CVE-2023-22483LOWcmark-gfm Quadratic complexity bugs may lead to a denial of serviceEPSS 1.1%