Falhas do tipo CWE-400

2.995 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2024-20983MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.34 and priEPSS 0.9%CVE-2022-36034HIGHPossible Regular Expression Denial of Service (ReDoS) used on uncontrolled data in nitrado.jsEPSS 0.9%CVE-2006-6025HIGHQUALCOMM Eudora WorldMail 4.0 allows remote attackers to cause a denial of service, as demonstrated by a certain module in VulnDisco Pack. EPSS 0.9%CVE-2022-20854HIGHA vulnerability in the processing of SSH connections of Cisco Firepower Management Center (FMC) and Cisco Firepower Threat Defense (FTD) SofEPSS 0.9%CVE-2023-28507CRITICALMemory exhaustion in LZ4 decompression in UniRPC daemonEPSS 0.9%CVE-2021-32763MEDIUMRegular Expression Denial of Service in OpenProject forum messagesEPSS 0.9%CVE-2021-23053On version 15.1.x before 15.1.3, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.6, when the brute force protection feature of BIG-IP AdvanEPSS 0.9%CVE-2020-20813Control Channel in OpenVPN 2.4.7 and earlier allows remote attackers to cause a denial of service via crafted reset packet.EPSS 0.9%CVE-2023-46442MEDIUMAn infinite loop in the retrieveActiveBody function of Soot before v4.4.1 under Java 8 allows attackers to cause a Denial of Service (DoS).EPSS 0.9%CVE-2022-1337MEDIUMOOM DoS in Mattermost image proxyEPSS 0.9%CVE-2022-43780HIGHCertain HP ENVY, OfficeJet, and DeskJet printers may be vulnerable to a Denial of Service attack.EPSS 0.9%CVE-2022-28701HIGHOn F5 BIG-IP 16.1.x versions prior to 16.1.2.2, when the stream profile is configured on a virtual server, undisclosed requests can cause anEPSS 0.9%CVE-2022-28691HIGHOn F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prioEPSS 0.9%CVE-2023-30769CRITICALRab13s ExploitEPSS 0.9%CVE-2021-22100In cloud foundry CAPI versions prior to 1.122, a denial-of-service attack in which a developer can push a service broker that (accidentally EPSS 0.9%CVE-2025-21575MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 8.0.0-8.0.4EPSS 0.9%CVE-2022-43238MEDIUMLibde265 v1.0.8 was discovered to contain an unknown crash via ff_hevc_put_hevc_qpel_h_3_v_3_sse in sse-motion.cc. This vulnerability allowsEPSS 0.9%CVE-2023-20883HIGHIn Spring Boot versions 3.0.0 - 3.0.6, 2.7.0 - 2.7.11, 2.6.0 - 2.6.14, 2.5.0 - 2.5.14 and older unsupported versions, there is potential forEPSS 0.9%CVE-2023-23631MEDIUMHAMT Decoding Panics in github.com/ipfs/go-unixfsnodeEPSS 0.9%CVE-2023-2798HIGHDenial of service in HtmlUnitEPSS 0.9%