Falhas do tipo CWE-400

2.995 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2022-47932MEDIUMBrave Browser before 1.43.34 allowed a remote attacker to cause a denial of service via a crafted HTML file that mentions an ipfs:// or ipnsEPSS 1.0%CVE-2022-36055MEDIUMDenial of service in HelmEPSS 1.0%CVE-2021-4021A vulnerability was found in Radare2 in versions prior to 5.6.2, 5.6.0, 5.5.4 and 5.5.2. Mapping a huge section filled with zeros of an ELF6EPSS 1.0%CVE-2024-45166CRITICALAn issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper deserialization, and iEPSS 1.0%CVE-2020-7584A vulnerability has been identified in SIMATIC S7-200 SMART CPU family (All versions >= V2.2 < V2.5.1). Affected devices do not properly hanEPSS 1.0%CVE-2020-5347MEDIUMDell EMC Isilon OneFS versions 8.2.2 and earlier contain a denial of service vulnerability. SmartConnect had an error condition that may be EPSS 1.0%CVE-2024-52804HIGHTornado has HTTP cookie parsing DoS vulnerabilityEPSS 1.0%CVE-2025-21352MEDIUMInternet Connection Sharing (ICS) Denial of Service VulnerabilityEPSS 1.0%CVE-2024-20971MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 aEPSS 1.0%CVE-2024-20981MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.35 and priEPSS 1.0%CVE-2021-25659A vulnerability has been identified in Automation License Manager 5 (All versions), Automation License Manager 6 (All versions < V6.0 SP9 UpEPSS 1.0%CVE-2022-45003HIGHGophish through 0.12.1 allows attackers to cause a Denial of Service (DoS) via a crafted payload involving autofocus.EPSS 1.0%CVE-2022-39346LOWMissing length validation of user displayname in nextcloud serverEPSS 1.0%CVE-2023-24824MEDIUMQuadratic complexity may lead to a denial of service in cmark-gfmEPSS 1.0%CVE-2024-21536HIGHVersions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an EPSS 1.0%CVE-2024-33774MEDIUMA buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formWlanSetup_Wizard allows remote authenticated users to trEPSS 1.0%CVE-2023-28846MEDIUMDenial of Service in unpoly-railsEPSS 1.0%CVE-2023-38741HIGHIBM TXSeries for Multiplatforms denial of serviceEPSS 1.0%CVE-2026-19446HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 1.0%CVE-2022-47934MEDIUMBrave Browser before 1.43.88 allowed a remote attacker to cause a denial of service in private and guest windows via a crafted HTML file thaEPSS 1.0%