Falhas do tipo CWE-404

695 resultados

Liberação inadequada de recursos

Ocorre quando o software não libera corretamente recursos como conexões de banco de dados, arquivos abertos, memória ou sockets de rede. Isso leva a esgotamento de recursos (resource leak), causando travamentos, negação de serviço ou comportamento imprevisível da aplicação ao longo do tempo.

Exemplo

Um servidor web que abre uma conexão com banco de dados para cada requisição, mas não a fecha adequadamente em caso de erro — após milhares de requisições, todas as conexões disponíveis se esgotam e novas requisições falham ou travam.

Como mitigar

Use padrões como try-finally ou try-with-resources (em Java) para garantir que recursos sejam liberados mesmo em exceções. Implemente timeouts e monitoramento de recursos abertos; realize testes de carga para detectar leaks antes da produção.

CVE-2026-60624MEDIUMVulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.7.0-9.7.EPSS 0.4%CVE-2024-1186LOWMunsoft Easy Archive Recovery Registration Key denial of serviceEPSS 0.4%CVE-2024-1185LOWNsasoft NBMonitor Network Bandwidth Monitor Registration denial of serviceEPSS 0.4%CVE-2025-0222MEDIUMIObit Protected Folder IOCTL IUProcessFilter.sys 0x8001E004 null pointer dereferenceEPSS 0.4%CVE-2025-0221MEDIUMIOBit Protected Folder IOCTL pffilter.sys 0x22200c null pointer dereferenceEPSS 0.4%CVE-2025-0223MEDIUMIObit Protected Folder IOCTL IURegistryFilter.sys 0x8001E010 null pointer dereferenceEPSS 0.4%CVE-2025-58473HIGHAutomationDirect CLICK PLUS Improper Resource Shutdown or ReleaseEPSS 0.4%CVE-2023-2870LOWEnTech Monitor Asset Manager IoControlCode 0x80002014 denial of serviceEPSS 0.3%CVE-2024-1193LOWNavicat MySQL Conecction denial of serviceEPSS 0.3%CVE-2024-12345MEDIUMINW Krbyyyzo Daily Huddle Site gbo.aspx resource consumptionEPSS 0.3%CVE-2023-1487MEDIUMLespeed WiseCleaner Wise System Monitor IoControlCode WiseHDInfo64.dll 0x9C40A0E0 denial of serviceEPSS 0.3%CVE-2025-1632MEDIUMlibarchive bsdunzip.c list null pointer dereferenceEPSS 0.3%CVE-2025-11638MEDIUMTomofun Furbo 360/Furbo Mini Bluetooth denial of serviceEPSS 0.3%CVE-2022-3606LOWLinux Kernel BPF libbpf.c find_prog_by_sec_insn null pointer dereferenceEPSS 0.3%CVE-2025-57882HIGHAutomationDirect CLICK PLUS Improper Resource Shutdown or ReleaseEPSS 0.3%CVE-2025-3730MEDIUMPyTorch LossCTC.cpp torch.nn.functional.ctc_loss denial of serviceEPSS 0.3%CVE-2023-1643MEDIUMIObit Malware Fighter IOCTL ImfHpRegFilter.sys 0x8001E040 denial of serviceEPSS 0.3%CVE-2023-1446MEDIUMWatchdog Anti-Virus IoControlCode wsdk-driver.sys 0x80002008 denial of serviceEPSS 0.3%CVE-2026-60397MEDIUMVulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.EPSS 0.3%CVE-2025-1377MEDIUMGNU elfutils eu-strip strip.c gelf_getsymshndx denial of serviceEPSS 0.3%