Falhas do tipo CWE-400

3.026 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2024-44169HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia EPSS 0.6%CVE-2026-9322HIGHIBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilitiesEPSS 0.6%CVE-2024-27100MEDIUMDenial of service via Staff Actions in DiscourseEPSS 0.6%CVE-2023-39327MEDIUMOpenjpeg: malicious files can cause the program to enter a large loopEPSS 0.6%CVE-2025-62854LOWFile Station 5EPSS 0.6%CVE-2023-7326HIGHEpson Stylus SX510W Printer Remote Power Off DoSEPSS 0.6%CVE-2021-47208MEDIUMThe Mojolicious module before 9.11 for Perl has a bug in format detection that can potentially be exploited for denial of service.EPSS 0.6%CVE-2026-22258HIGHSuricata DCERPC: unbounded fragment buffering leads to memory exhaustionEPSS 0.6%CVE-2024-20500MEDIUMA vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unEPSS 0.6%CVE-2024-42969HIGHTenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromSafeUrlFilter function. This vulnerabEPSS 0.6%CVE-2024-42951HIGHTenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the mit_pptpusrpw parameter in the fromWizardHandle function. ThEPSS 0.6%CVE-2024-42950HIGHTenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the Go parameter in the fromSafeClientFilter function. This vulnEPSS 0.6%CVE-2022-41932HIGHCreation of new database tables through login form on PostgreSQLEPSS 0.6%CVE-2026-26477MEDIUMAn issue in Dokuwiki v.2025-05-14b "Librarian" [56.2] allows a remote attacker to cause a denial of service via the media_upload_xhr() functEPSS 0.6%CVE-2024-42980HIGHTenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the frmL7ImForm function. This vulnerability EPSS 0.6%CVE-2024-42981HIGHTenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the delno parameter in the fromPptpUserSetting function. This vulneEPSS 0.6%CVE-2024-27862MEDIUMA logic issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.6. Enabling Lockdown Mode while setting uEPSS 0.6%CVE-2023-42358HIGHAn issue was discovered in O-RAN Software Community ric-plt-e2mgr in the G-Release environment, allows remote attackers to cause a denial ofEPSS 0.6%CVE-2024-8451HIGHPLANET Technology switch devices - SSH server DoS attackEPSS 0.6%CVE-2026-85703MEDIUMramon-victor freegpt-webui Jailbreak Mode backend.py getJailbreak allocation of resourcesEPSS 0.6%