Falhas do tipo CWE-400

2.982 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2022-24464HIGH.NET and Visual Studio Denial of Service VulnerabilityEPSS 3.6%CVE-2019-10977In Mitsubishi Electric MELSEC-Q series Ethernet module QJ71E71-100 serial number 20121 and prior, an attacker could send crafted TCP packetsEPSS 3.5%CVE-2019-14232HIGHAn issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If django.utils.text.Truncator's charsEPSS 3.5%CVE-2022-24836HIGHInefficient Regular Expression Complexity in NokogiriEPSS 3.5%CVE-2025-21181HIGHMicrosoft Message Queuing (MSMQ) Denial of Service VulnerabilityEPSS 3.5%CVE-2022-21360MEDIUMVulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions thEPSS 3.5%CVE-2023-5685HIGHXnio: stackoverflowexception when the chain of notifier states becomes problematically bigEPSS 3.5%CVE-2022-21299MEDIUMVulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that EPSS 3.5%CVE-2025-5115HIGHMadeYouReset HTTP/2 vulnerabilityEPSS 3.5%CVE-2009-2541HIGHThe web browser on the Sony PLAYSTATION 3 (PS3) allows remote attackers to cause a denial of service (memory consumption and console hang) vEPSS 3.4%CVE-2021-21252MEDIUMRegular expression denial of service in jquery-validationEPSS 3.4%CVE-2020-15166HIGHDenial of Service in ZeroMQEPSS 3.4%CVE-2019-10953HIGHABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some conEPSS 3.4%CVE-2017-15119MEDIUMThe Network Block Device (NBD) server in Quick Emulator (QEMU) before 2.11 is vulnerable to a denial of service issue. It could occur if a cEPSS 3.3%CVE-2020-3569HIGHCisco IOS XR Software DVMRP Memory Exhaustion VulnerabilitiesEPSS 3.3%KEVCVE-2017-12741HIGHSpecially crafted packets sent to port 161/udp could cause a denial of service condition. The affected devices must be restarted manually.EPSS 3.3%CVE-2021-33580regex injection leading to DoSEPSS 3.3%CVE-2021-21285MEDIUMDocker daemon crash during image pull of malicious imageEPSS 3.3%CVE-2023-26048MEDIUMOutOfMemoryError for large multipart without filename in Eclipse JettyEPSS 3.3%CVE-2020-27827HIGHA flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to hanEPSS 3.2%