Falhas do tipo CWE-400

2.995 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2023-35921HIGHA vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3.4), SIMATIC MV540 S (All versions < V3.3.4), SIMATIC MV550 H (AlEPSS 0.9%CVE-2024-21185MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.38, 8.4.1 and EPSS 0.9%CVE-2023-25568HIGHBoxo bitswap/server: DOS unbounded persistent memory leakEPSS 0.9%CVE-2022-24035HIGHAn issue was discovered in ONOS 2.5.1. The purge-requested intent remains on the list, but it does not respond to changes in topology (e.g.,EPSS 0.9%CVE-2022-32927HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16. Joining EPSS 0.9%CVE-2024-35270MEDIUMWindows iSCSI Service Denial of Service VulnerabilityEPSS 0.9%CVE-2024-12864HIGHUnauthenticated DoS by Sending Large Filename at File Upload Endpoint in netease-youdao/qanythingEPSS 0.9%CVE-2024-12070HIGHDenial of Service in haotian-liu/llavaEPSS 0.9%CVE-2024-21194MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.39 and prior, 8EPSS 0.9%CVE-2023-21838HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.9%CVE-2018-0441HIGHCisco IOS Access Points Software 802.11r Fast Transition Denial of Service VulnerabilityEPSS 0.9%CVE-2022-2406MEDIUMMalicious imports can lead to Denial of ServiceEPSS 0.9%CVE-2022-24109MEDIUMAn issue was discovered in ONOS 2.5.1. To attack an intent installed by a normal user, a remote attacker can install a duplicate intent withEPSS 0.9%CVE-2023-26470MEDIUMIn XWiki Platform, saving a document with a large object number leads to persistent OOM errorsEPSS 0.9%CVE-2024-47850HIGHCUPS cups-browsed before 2.5b1 will send an HTTP POST request to an arbitrary destination and port in response to a single IPP UDP packet reEPSS 0.9%CVE-2026-47073HIGHUnbounded memory consumption in WebSocket client in hackneyEPSS 0.9%CVE-2024-38809MEDIUMApplications that parse ETags from "If-Match" or "If-None-Match" request headers are vulnerable to DoS attack. Users of affected versions sEPSS 0.9%CVE-2021-22642HIGHOvarro TBox Uncontrolled Resource ConsumptionEPSS 0.9%CVE-2024-21142MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected aEPSS 0.9%CVE-2021-3912MEDIUMOctoRPKI crashes when processing GZIP bomb returned via malicious repositoryEPSS 0.9%