Falhas do tipo CWE-404

695 resultados

Liberação inadequada de recursos

Ocorre quando o software não libera corretamente recursos como conexões de banco de dados, arquivos abertos, memória ou sockets de rede. Isso leva a esgotamento de recursos (resource leak), causando travamentos, negação de serviço ou comportamento imprevisível da aplicação ao longo do tempo.

Exemplo

Um servidor web que abre uma conexão com banco de dados para cada requisição, mas não a fecha adequadamente em caso de erro — após milhares de requisições, todas as conexões disponíveis se esgotam e novas requisições falham ou travam.

Como mitigar

Use padrões como try-finally ou try-with-resources (em Java) para garantir que recursos sejam liberados mesmo em exceções. Implemente timeouts e monitoramento de recursos abertos; realize testes de carga para detectar leaks antes da produção.

CVE-2025-14953LOWOpen5GS FAR-ID handler.c ogs_pfcp_handle_create_pdr null pointer dereferenceEPSS 0.5%CVE-2022-35272HIGHBIG-IP HTTP MRF vulnerability CVE-2022-35272EPSS 0.5%CVE-2026-6797MEDIUMSanluan PublicCMS DocToHtmlUtils.java ZipSecureFile.setMinflateRatio resource consumptionEPSS 0.5%CVE-2025-13901MEDIUMCWE-404 Improper Resource Shutdown or Release vulnerability exists that could cause partial Denial of Service on Machine Expert protocol wheEPSS 0.5%CVE-2025-11635MEDIUMTomofun Furbo 360 File Upload resource consumptionEPSS 0.5%CVE-2024-4292MEDIUMContemporary Controls BASrouter BACnet BASRT-B Device-Communication-Control Service denial of serviceEPSS 0.4%CVE-2025-69821HIGHAn issue in Beat XP VEGA Smartwatch (Firmware Version - RB303ATV006229) allows an attacker to cause a denial of service via the BLE connectiEPSS 0.4%CVE-2026-3465LOWTuya App/SDK JSON Data Point denial of serviceEPSS 0.4%CVE-2026-10069HIGHShibby Tomato miniupnpd resource consumptionEPSS 0.4%CVE-2026-15690LOWopen62541 Shared Client ua_client_connect.c responseReadNamespacesArray null pointer dereferenceEPSS 0.4%CVE-2026-47213MEDIUMBoxLite: Timeout Bypass VulnerabilityEPSS 0.4%CVE-2022-48489—Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.EPSS 0.4%CVE-2022-48499HIGHConfiguration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.EPSS 0.4%CVE-2022-48500HIGHConfiguration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.EPSS 0.4%CVE-2022-46314HIGHThe IPC module has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability.EPSS 0.4%CVE-2026-10650MEDIUMwarmcat libwebsockets SSH Protocol sshd.c lws_ssh_parse_plaintext resource consumptionEPSS 0.4%CVE-2025-5031LOWAckites KillWxapkg wxapkg File Decompression resource consumptionEPSS 0.4%CVE-2026-29771HIGHNetmaker: Denial of Service via Server Shutdown EndpointEPSS 0.4%CVE-2026-1876HIGHDenial-of-Service (DoS) vulnerability in Ethernet function of MELSEC iQ-F Series Ethernet moduleEPSS 0.4%CVE-2026-1875HIGHDenial-of-Service (DoS) vulnerability in Ethernet function of MELSEC iQ-F Series EtherNet/IP moduleEPSS 0.4%