Falhas do tipo CWE-400

2.982 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2018-6922One of the data structures that holds TCP segments in all versions of FreeBSD prior to 11.2-RELEASE-p1, 11.1-RELEASE-p12, and 10.4-RELEASE-pEPSS 3.2%CVE-2022-21366MEDIUMVulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions thEPSS 3.2%CVE-2018-10607Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior allow the creation of new connections to one or more EPSS 3.2%CVE-2014-5418GE Multilink Uncontrolled Resource ConsumptionEPSS 3.2%CVE-2019-1010266lodash prior to 4.17.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: DateEPSS 3.2%CVE-2021-4040A flaw was found in AMQ Broker. This issue can cause a partial interruption to the availability of AMQ Broker via an Out of memory (OOM) conEPSS 3.1%CVE-2017-15132A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0. An abort of SASL authentication results in a memory leak in dovecot's auth client usEPSS 3.1%CVE-2022-1708A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSEPSS 3.1%CVE-2022-21277MEDIUMVulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions thEPSS 3.1%CVE-2024-21392HIGH.NET and Visual Studio Denial of Service VulnerabilityEPSS 3.1%CVE-2018-16853HIGHSamba from version 4.7.0 has a vulnerability that allows a user in a Samba AD domain to crash the KDC when Samba is built in the non-defaultEPSS 3.1%CVE-2021-20609HIGHUncontrolled Resource Consumption vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/08/16/32/120(EPSS 3.1%CVE-2018-16492A prototype pollution vulnerability was found in module extend <2.0.2, ~<3.0.2 that allows an attacker to inject arbitrary properties onto OEPSS 3.0%CVE-2023-24860HIGHMicrosoft Defender Denial of Service VulnerabilityEPSS 3.0%CVE-2026-25667HIGHASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to cause excessive CPU consumptEPSS 3.0%CVE-2022-31028HIGHPossible DDOS by establishing keep-alive connections with anonymous HTTP clients in MinIOEPSS 3.0%CVE-2024-26190HIGHMicrosoft QUIC Denial of Service VulnerabilityEPSS 3.0%CVE-2016-9589Undertow in Red Hat wildfly before version 11.0.0.Beta1 is vulnerable to a resource exhaustion resulting in a denial of service. Undertow keEPSS 3.0%CVE-2019-11060HIGHHG100 contains an Uncontrolled Resource Consumption vulnerabilityEPSS 3.0%CVE-2024-30105HIGH.NET and Visual Studio Denial of Service VulnerabilityEPSS 2.9%