Falhas do tipo CWE-404

695 resultados

Liberação inadequada de recursos

Ocorre quando o software não libera corretamente recursos como conexões de banco de dados, arquivos abertos, memória ou sockets de rede. Isso leva a esgotamento de recursos (resource leak), causando travamentos, negação de serviço ou comportamento imprevisível da aplicação ao longo do tempo.

Exemplo

Um servidor web que abre uma conexão com banco de dados para cada requisição, mas não a fecha adequadamente em caso de erro — após milhares de requisições, todas as conexões disponíveis se esgotam e novas requisições falham ou travam.

Como mitigar

Use padrões como try-finally ou try-with-resources (em Java) para garantir que recursos sejam liberados mesmo em exceções. Implemente timeouts e monitoramento de recursos abertos; realize testes de carga para detectar leaks antes da produção.

CVE-2024-57618HIGHAn issue in the bind_col_exp component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL stateEPSS 0.5%CVE-2024-33844HIGHThe 'control' in Parrot ANAFI USA firmware 1.10.4 does not check the MAV_MISSION_TYPE(0, 1, 2, 255), which allows attacker to cut off the coEPSS 0.5%CVE-2026-1684MEDIUMFree5GC SMF PFCP UDP Endpoint pfcp_reports.go HandleReports denial of serviceEPSS 0.5%CVE-2026-14629MEDIUMRT-Thread Parameter lwp_syscall.c sys_ioctl divide by zeroEPSS 0.5%CVE-2026-8781MEDIUMomec-project amf handler.go RANConfiguration null pointer dereferenceEPSS 0.5%CVE-2026-7707MEDIUMOpen5GS UDR nudr-handler.c udr_nudr_dr_handle_subscription_context denial of serviceEPSS 0.5%CVE-2026-8783MEDIUMomec-project amf dispatcher.go UERadioCapabilityCheckResponse null pointer dereferenceEPSS 0.5%CVE-2026-8782MEDIUMomec-project amf NGAP Message handler.go null pointer dereferenceEPSS 0.5%CVE-2026-90878MEDIUMvllm-project vLLM Jinja Template Rendering completions resource consumptionEPSS 0.5%CVE-2026-92361MEDIUMag-ui-protocol ag-ui SSE Client client.go resource consumptionEPSS 0.5%CVE-2026-7601MEDIUMOpen5GS AMF gmm-handler.c denial of serviceEPSS 0.5%CVE-2025-15686MEDIUMOpen5GS HSS Service fd_msg_sess_get denial of serviceEPSS 0.5%CVE-2024-20995LOWVulnerability in the Oracle Database Sharding component of Oracle Database Server. Supported versions that are affected are 19.3-19.22 and EPSS 0.5%CVE-2026-1586MEDIUMOpen5GS SGWC s11-handler.c ogs_gtp2_f_teid_to_ip denial of serviceEPSS 0.5%CVE-2026-1587MEDIUMOpen5GS SGWC s11-handler.c sgwc_s11_handle_modify_bearer_request denial of serviceEPSS 0.5%CVE-2023-1488LOWLespeed WiseCleaner Wise System Monitor IoControlCode WiseHDInfo64.dll 0x9C40A0E0 denial of serviceEPSS 0.5%CVE-2025-1816MEDIUMFFmpeg IAMF File iamf_parse.c audio_element_obu memory leakEPSS 0.5%CVE-2026-92362MEDIUMag-ui-protocol ag-ui SSE Frame sse.rs resource consumptionEPSS 0.5%CVE-2024-13009HIGHEclipse Jetty GZIP buffer releaseEPSS 0.5%CVE-2026-7535MEDIUMOpen5GS transfer-update denial of serviceEPSS 0.5%