Falhas do tipo CWE-400

2.995 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2023-49140HIGHDenial-of-service (DoS) vulnerability exists in commplex-link service of HMI GC-A2 series. If a remote unauthenticated attacker sends a specEPSS 1.0%CVE-2014-3648The simplepush server iterates through the application installations and pushes a notification to the server provided by deviceToken. But thEPSS 1.0%CVE-2021-41546A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.14.1), RUGGEDCOM ROX RX1400 (All versions < V2.14.1), RUGGEDCEPSS 1.0%CVE-2022-38100HIGHContec Health CMS8000EPSS 1.0%CVE-2023-25151HIGHDoS vulnerability for high cardinality metrics in opentelemetry-go-contribEPSS 1.0%CVE-2022-22161HIGHJunos OS: MX104 might become unresponsive if the out-of-band management port receives a flood of trafficEPSS 1.0%CVE-2024-29893MEDIUMUncontrolled Resource Consumption vulnerability in ArgoCD's repo serverEPSS 1.0%CVE-2023-41102HIGHAn issue was discovered in the captive portal in OpenNDS before version 10.1.3. It has multiple memory leaks due to not freeing up allocatedEPSS 1.0%CVE-2026-21945HIGHVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: SecuritEPSS 1.0%CVE-2023-20861In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible fEPSS 1.0%CVE-2022-31075MEDIUMKubeEdge DoS when signing the CSR from EdgeCoreEPSS 1.0%CVE-2024-21057MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 aEPSS 1.0%CVE-2023-3398MEDIUMDenial of Service in jgraph/drawioEPSS 1.0%CVE-2018-15437MEDIUMCisco Immunet and Cisco AMP for Endpoints System Scan Denial of Service VulnerabilityEPSS 1.0%CVE-2024-28854HIGHSlow loris vulnerability with default configuration in tls-listenerEPSS 1.0%CVE-2023-37475HIGHAttacker-controlled parameter can cause denial of service in hamba avroEPSS 1.0%CVE-2021-0230HIGHJunos OS: SRX Series: Memory leak when querying Aggregated Ethernet (AE) interface statisticsEPSS 1.0%CVE-2021-23049On BIG-IP version 16.0.x before 16.0.1.2 and 15.1.x before 15.1.3, when the iRules RESOLVER::summarize command is used on a virtual server, EPSS 1.0%CVE-2021-0233HIGHJunos OS: ACX500 Series, ACX4000 Series: Denial of Service due to FFEB crash while processing high rate of specific packets.EPSS 1.0%CVE-2021-3479There's a flaw in OpenEXR's Scanline API functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to beEPSS 1.0%