Falhas do tipo CWE-400

2.995 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2021-3478There's a flaw in OpenEXR's scanline input file functionality in versions before 3.0.0-beta. An attacker able to submit a crafted file to beEPSS 1.0%CVE-2024-0842HIGHBackuply - Backup, Restore, Migrate and Clone <= 1.2.6 - Denial of ServiceEPSS 1.0%CVE-2023-22484LOWInefficient Quadratic complexity bug in handle_pointy_brace may lead to a denial of serviceEPSS 1.0%CVE-2022-0695MEDIUMDenial of Service in radareorg/radare2EPSS 1.0%CVE-2024-32663HIGHSuricata 's http2 parser contains an improper compressed header handling can lead to resource starvationEPSS 1.0%CVE-2022-42950MEDIUMAn issue was discovered in Couchbase Server 7.x before 7.0.5 and 7.1.x before 7.1.2. A crafted HTTP REST request from an administrator accouEPSS 1.0%CVE-2023-30635HIGHTiKV 6.1.2 allows remote attackers to cause a denial of service (fatal error) upon an attempt to get a timestamp from the Placement Driver.EPSS 1.0%CVE-2023-20125HIGHCisco BroadWorks Network Server TCP Denial of Service VulnerabilityEPSS 1.0%CVE-2023-40583HIGHlibp2p nodes vulnerable to OOM attackEPSS 1.0%CVE-2022-3509HIGHParsing issue in protobuf textformatEPSS 1.0%CVE-2024-21219MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.39 and priEPSS 0.9%CVE-2024-21218MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.39 and prior, 8EPSS 0.9%CVE-2022-28204HIGHA denial-of-service issue was discovered in MediaWiki 1.37.x before 1.37.2. Rendering of w/index.php?title=Special%3AWhatLinksHere&target=PrEPSS 0.9%CVE-2023-5759HIGHUnauthenticated Remote Denial-of-Service via Buffer in Helix CoreEPSS 0.9%CVE-2023-35767HIGHUnauthenticated Remote Denial-of-Service via Shutdown Function in Helix CoreEPSS 0.9%CVE-2021-21565MEDIUMDell PowerScale OneFS versions 9.1.0.3 and earlier contain a denial of service vulnerability. SmartConnect had an error condition that may bEPSS 0.9%CVE-2022-36114MEDIUMExtracting malicious crates can fill the file systemEPSS 0.9%CVE-2022-27889MEDIUMThe Foundry Multipass service contains code paths that could be abused to cause a denial of service for authentication and authorization operations.EPSS 0.9%CVE-2023-45319HIGHUnauthenticated Remote Denial-of-Service (Commit) in Helix Core EPSS 0.9%CVE-2021-33609MEDIUMDenial of service in DataCommunicator class in Vaadin 8EPSS 0.9%