Falhas do tipo CWE-404

695 resultados

Liberação inadequada de recursos

Ocorre quando o software não libera corretamente recursos como conexões de banco de dados, arquivos abertos, memória ou sockets de rede. Isso leva a esgotamento de recursos (resource leak), causando travamentos, negação de serviço ou comportamento imprevisível da aplicação ao longo do tempo.

Exemplo

Um servidor web que abre uma conexão com banco de dados para cada requisição, mas não a fecha adequadamente em caso de erro — após milhares de requisições, todas as conexões disponíveis se esgotam e novas requisições falham ou travam.

Como mitigar

Use padrões como try-finally ou try-with-resources (em Java) para garantir que recursos sejam liberados mesmo em exceções. Implemente timeouts e monitoramento de recursos abertos; realize testes de carga para detectar leaks antes da produção.

CVE-2026-13523MEDIUMGPAC ISOBMFF base_encoding.c data amplificationEPSS 0.2%CVE-2026-9567MEDIUMGPAC MP4Box isom_intern.c MergeFragment null pointer dereferenceEPSS 0.2%CVE-2026-14801MEDIUMGPAC TeXML File load_text.c txtin_probe_duration divide by zeroEPSS 0.2%CVE-2026-15276MEDIUMpdeljanov Symphonia Metadata denial of serviceEPSS 0.2%CVE-2026-9529MEDIUMGNU LibreDWG Dwggrep Utility dwggrep.c match_BLOCK_HEADER null pointer dereferenceEPSS 0.2%CVE-2026-76014MEDIUMBusyBox FEATURE_WGET_TIMEOUT wget.c null pointer dereferenceEPSS 0.2%CVE-2026-15274MEDIUMlo48576 fbxcel Node Header parser.rs denial of serviceEPSS 0.2%CVE-2026-14790MEDIUMGPAC Media File write_nhml.c nhmldump_send_frame null pointer dereferenceEPSS 0.2%CVE-2026-7740MEDIUMjustdan96 tsMuxer vvc.cpp setFPS denial of serviceEPSS 0.2%CVE-2026-94137MEDIUMHangzhou Shunwang Technology shzh IRP_MJ_DEVICE_CONTROL shdrv_x64.sys sub_180004AC0 denial of serviceEPSS 0.2%CVE-2026-17610MEDIUMRAIL 802.15.4 Mux missing ACK can lead to DoSEPSS 0.2%CVE-2026-1990MEDIUMoatpp Type.hpp ObjectWrapper null pointer dereferenceEPSS 0.2%CVE-2024-47972MEDIUMImproper resource management in firmware of some Solidigm DC Products may allow an attacker to potentially control the performance of the reEPSS 0.2%CVE-2026-35667MEDIUMOpenClaw < 2026.3.24 - Improper Process Termination via Unpatched killProcessTree in shell-utils.tsEPSS 0.2%CVE-2025-10475MEDIUMSpyShelter IOCTL SpyShelter.sys denial of serviceEPSS 0.1%CVE-2025-11642MEDIUMTomofun Furbo 360/Furbo Mini Registration denial of serviceEPSS 0.1%CVE-2025-8735MEDIUMGNU cflow Lexer c.c yylex null pointer dereferenceEPSS 0.1%CVE-2025-10823MEDIUMaxboe fio options.c str_buffer_pattern_cb null pointer dereferenceEPSS 0.1%CVE-2025-13397MEDIUMmrubyc alloc.c mrbc_raw_realloc null pointer dereferenceEPSS 0.1%CVE-2026-34317MEDIUMVulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are affected are 8.0.0-8.EPSS 0.1%