Falhas do tipo CWE-404

695 resultados

Liberação inadequada de recursos

Ocorre quando o software não libera corretamente recursos como conexões de banco de dados, arquivos abertos, memória ou sockets de rede. Isso leva a esgotamento de recursos (resource leak), causando travamentos, negação de serviço ou comportamento imprevisível da aplicação ao longo do tempo.

Exemplo

Um servidor web que abre uma conexão com banco de dados para cada requisição, mas não a fecha adequadamente em caso de erro — após milhares de requisições, todas as conexões disponíveis se esgotam e novas requisições falham ou travam.

Como mitigar

Use padrões como try-finally ou try-with-resources (em Java) para garantir que recursos sejam liberados mesmo em exceções. Implemente timeouts e monitoramento de recursos abertos; realize testes de carga para detectar leaks antes da produção.

CVE-2023-51332MEDIUMA lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Meeting Room Booking System v1.0 allows attackers to send an excessivEPSS 0.4%CVE-2024-1191LOWHyper CdCatalog HCF File denial of serviceEPSS 0.4%CVE-2026-3206LOWImproper management of context cancelationsEPSS 0.4%CVE-2025-41399HIGHSCTP VulnerabilityEPSS 0.4%CVE-2024-47213HIGHAn issue was discovered affecting Enrich 5.1.0 and below. It involves sending a maliciously crafted Snowplow event to the pipeline. Upon recEPSS 0.4%CVE-2023-5255MEDIUMDenial of Service for Revocation of Auto Renewed CertificatesEPSS 0.4%CVE-2025-22846HIGHBIG-IP SIP VulnerabilityEPSS 0.4%CVE-2025-55102HIGHA denial-of-service vulnerability exists in the NetX IPv6 component functionality of Eclipse ThreadX NetX Duo. A specially crafted network pEPSS 0.4%CVE-2022-3533LOWLinux Kernel BPF usdt.c parse_usdt_arg memory leakEPSS 0.4%CVE-2025-7462MEDIUMArtifex GhostPDL New Output File Open Error gdevpdf.c pdf_ferror null pointer dereferenceEPSS 0.4%CVE-2023-34059HIGHopen-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges maEPSS 0.4%CVE-2022-28887MEDIUMMultiple Denial of Service VulnerabilityEPSS 0.4%CVE-2022-3563LOWLinux Kernel BlueZ mgmt-tester.c read_50_controller_cap_complete null pointer dereferenceEPSS 0.4%CVE-2024-1194LOWArmcode AlienIP Locate Host denial of serviceEPSS 0.4%CVE-2025-29313HIGHUse of incorrectly resolved name or reference in OpenDaylight Service Function Chaining (SFC) Subproject SFC Sodium-SR4 and below allows attEPSS 0.4%CVE-2025-47148HIGHBIG-IP APM and SSL Orchestrator vulnerabilityEPSS 0.4%CVE-2026-10116MEDIUMOpen5GS ue-authentications Endpoint ogs-timer.c ogs_sbi_xact_add denial of serviceEPSS 0.4%CVE-2025-2956HIGHTRENDnet TI-G102i HTTP Request lighttpd plugins_call_handle_uri_raw null pointer dereferenceEPSS 0.4%CVE-2024-1184LOWNsasoft Network Sleuth Registration denial of serviceEPSS 0.4%CVE-2025-2957HIGHTRENDnet TEW-411BRP+ HTTP Request httpd sub_401DB0 null pointer dereferenceEPSS 0.4%