Falhas do tipo CWE-400

2.995 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2024-21142MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected aEPSS 0.9%CVE-2024-23259MEDIUMThe issue was addressed with improved checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14EPSS 0.9%CVE-2024-20996MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.37 and prior anEPSS 0.9%CVE-2026-54772HIGHCoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp / net.pipe / net.uds framing handshakeEPSS 0.8%CVE-2018-0471Cisco IOS XE Software Cisco Discovery Protocol Memory Leak VulnerabilityEPSS 0.8%CVE-2024-5013HIGHWhatsUp Gold InstallController Denial-of-Service VulnerabilityEPSS 0.8%CVE-2022-43564MEDIUMDenial of Service in Splunk Enterprise through search macrosEPSS 0.8%CVE-2024-32972HIGHgo-ethereum denial of service via malicious p2p messageEPSS 0.8%CVE-2020-9059Z-Wave devices based on Silicon Labs 500 series chipsets using S0 authentication are susceptible to uncontrolled resource consumption leadinEPSS 0.8%CVE-2024-49129HIGHWindows Remote Desktop Gateway (RD Gateway) Denial of Service VulnerabilityEPSS 0.8%CVE-2020-3203HIGHCisco IOS XE Software Catalyst 9800 Series Wireless Controllers Denial of Service VulnerabilityEPSS 0.8%CVE-2022-41969LOWNextcloud Server has no password length limit when creating a user as an administratorEPSS 0.8%CVE-2026-33176MEDIUMRails Active Support has a possible DoS vulnerability in its number helpersEPSS 0.8%CVE-2022-24040A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXEPSS 0.8%CVE-2023-21996HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affeEPSS 0.8%CVE-2023-21964HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.8%CVE-2026-39244HIGHadm-zip before 0.5.18 is vulnerable to denial of service via a crafted ZIP file with a manipulated uncompressed size header field. In zipEntEPSS 0.8%CVE-2022-4006LOWWBCE CMS Header class.login.php increase_attempts excessive authenticationEPSS 0.8%CVE-2023-41121Array AG OS before 9.4.0.499 allows denial of service: remote attackers can cause system service processes to crash through abnormal HTTP opEPSS 0.8%CVE-2021-47023HIGHnet: marvell: prestera: fix port event handling on initEPSS 0.8%