Falhas do tipo CWE-400

2.995 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2021-0202HIGHJunos OS: MX Series, EX9200 Series: Trio-based MPC memory leak when Integrated Routing and Bridging (IRB) interface is mapped to a VPLS instance or a Bridge-DomainEPSS 1.0%CVE-2024-20978MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 aEPSS 1.0%CVE-2024-8184MEDIUMJetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacksEPSS 1.0%CVE-2023-26485MEDIUMQuadratic complexity may lead to a denial of service in cmark-gfmEPSS 1.0%CVE-2020-1901Receiving a large text message containing URLs in WhatsApp for iOS prior to v2.20.91.4 could have caused the application to freeze while proEPSS 1.0%CVE-2023-26151MEDIUMVersions of the package asyncua before 0.9.96 are vulnerable to Denial of Service (DoS) such that an attacker can send a malformed packet anEPSS 1.0%CVE-2023-30999HIGHIBM Security Access Manager denial of serviceEPSS 1.0%CVE-2023-42031MEDIUMIBM CICS TX denial of serviceEPSS 1.0%CVE-2023-40408An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.1, watchOS 10.1, iEPSS 1.0%CVE-2022-20808HIGHCisco Smart Software Manager On-Prem Denial of Service VulnerabilityEPSS 1.0%CVE-2024-20964MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected aEPSS 1.0%CVE-2022-27508HIGHUnauthenticated denial of service EPSS 1.0%CVE-2021-22964A redirect vulnerability in the `fastify-static` module version >= 4.2.4 and < 4.4.1 allows remote attackers to redirect Mozilla Firefox useEPSS 1.0%CVE-2023-42457HIGHplone.rest vulnerable to Denial of Service when ++api++ is used many timesEPSS 1.0%CVE-2022-23492HIGHgo-libp2p denial of service vulnerability from lack of resource managementEPSS 1.0%CVE-2021-32816MEDIUMRegular expression Denial of Service in ProtonMailEPSS 1.0%CVE-2024-38027MEDIUMWindows Line Printer Daemon Service Denial of Service VulnerabilityEPSS 1.0%CVE-2026-42579HIGHNetty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder)EPSS 1.0%CVE-2022-0476HIGHDenial of Service in radareorg/radare2EPSS 1.0%CVE-2024-10599MEDIUMTongda OA 2017 package_static_resources.php resource consumptionEPSS 1.0%