Falhas do tipo CWE-404

695 resultados

Liberação inadequada de recursos

Ocorre quando o software não libera corretamente recursos como conexões de banco de dados, arquivos abertos, memória ou sockets de rede. Isso leva a esgotamento de recursos (resource leak), causando travamentos, negação de serviço ou comportamento imprevisível da aplicação ao longo do tempo.

Exemplo

Um servidor web que abre uma conexão com banco de dados para cada requisição, mas não a fecha adequadamente em caso de erro — após milhares de requisições, todas as conexões disponíveis se esgotam e novas requisições falham ou travam.

Como mitigar

Use padrões como try-finally ou try-with-resources (em Java) para garantir que recursos sejam liberados mesmo em exceções. Implemente timeouts e monitoramento de recursos abertos; realize testes de carga para detectar leaks antes da produção.

CVE-2025-63895HIGHAn issue in the Bluetooth firmware of JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to cause a Denial of Service (EPSS 0.3%CVE-2026-10802MEDIUMkeystonejs keystone GraphQL API Endpoint output-field.ts resource consumptionEPSS 0.3%CVE-2026-10115MEDIUMOpen5GS Shared NF-profile nnrf-handler.c denial of serviceEPSS 0.3%CVE-2025-1376LOWGNU elfutils eu-strip elf_strptr.c elf_strptr denial of serviceEPSS 0.3%CVE-2022-4296MEDIUMTP-Link TL-WR740N ARP resource consumptionEPSS 0.3%CVE-2025-25899LOWA buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the 'gw' parameter at /userRpm/WanDynamicIpV6CfgRpm.htm. This vEPSS 0.3%CVE-2024-1190LOWGlobal Scape CuteFTP denial of serviceEPSS 0.3%CVE-2025-6202HIGHPhoenix: Rowhammer attack on Hynix DDR5 devicesEPSS 0.3%CVE-2017-20012LOWWEKA INTEREST Security Scanner Stresstest Scheme denial of serviceEPSS 0.3%CVE-2026-11317HIGHRockwell Automation Logix 5370 and 5570 Controllers Vulnerable To Denial of Service Via CIPEPSS 0.3%CVE-2025-14105MEDIUMTOZED ZLT M30S/ZLT M30S PRO Web proc_post denial of serviceEPSS 0.3%CVE-2024-11586MEDIUMUbuntu's implementation of pulseaudio can be crashed by a malicious program if a bluetooth headset is connected.EPSS 0.3%CVE-2026-10113MEDIUMOpen5GS Shared NF-profile nnrf-handler.c denial of serviceEPSS 0.3%CVE-2026-8232MEDIUMDotouch XproUPF UPF Process libvlib.so vlib_worker_loop denial of serviceEPSS 0.3%CVE-2017-20013LOWWEKA INTEREST Security Scanner Stresstest Configuration denial of serviceEPSS 0.3%CVE-2019-0042MEDIUMIncorrect messages from Juniper Identity Management Service (JIMS) can trigger Denial of Service or firewall bypass conditions for SRX series devicesEPSS 0.3%CVE-2025-36006MEDIUMIBM Db2 denial of serviceEPSS 0.3%CVE-2026-10705LOWdask HLL hyperloglog.py nunique_approx resource consumptionEPSS 0.3%CVE-2025-3198MEDIUMGNU Binutils objdump bucomm.c display_info memory leakEPSS 0.3%CVE-2024-2180MEDIUMZemana AntiLogger v2.74.204.664 - Kernel Memory LeakEPSS 0.3%