Falhas do tipo CWE-770

1.846 resultados

Alocação de recursos sem limite (negação de serviço por esgotamento)

A aplicação aloca recursos (memória, conexões, arquivos, threads) a pedido de um usuário sem impor limites, permitindo que um atacante esgote todos os recursos disponíveis e derrube o serviço. É basicamente deixar a porta aberta para qualquer um encher a caixa d'água até transbordar.

Exemplo

Um servidor web que cria uma nova thread para cada requisição HTTP recebida, sem limite. Um atacante envia milhares de requisições simultâneas e esgota o pool de threads, tornando o servidor inresponsivo para usuários legítimos — é negação de serviço puro.

Como mitigar

Implemente limites rigorosos: rate limiting (requisições por IP/usuário), quotas de recursos, pool de threads/conexões com tamanho máximo, timeout em operações, e monitoramento de consumo. Valide tamanhos de entrada e rejeite alocações que excedam os limites configurados.

CVE-2023-25414MEDIUMAten PE8108 2.4.232 is vulnerable to denial of service (DOS).EPSS 0.7%CVE-2024-37309MEDIUMClient initialized Session-Renegotiation DoSEPSS 0.7%CVE-2023-46130MEDIUMBypassing height value allowed in some theme componentsEPSS 0.7%CVE-2023-32186HIGHA Allocation of Resources Without Limits or Throttling vulnerability in SUSE RKE2 allows attackers with access to K3s servers apiserver/supEPSS 0.7%CVE-2024-36403MEDIUMDenial of service/high operating costs through unauthenticated downloads in Matrix Media RepoEPSS 0.7%CVE-2020-11862HIGHInsecure renegotiation in SSL protocol caused Denial of service attack in Privileged Account ManagerEPSS 0.7%CVE-2024-0563MEDIUMDenial of service condition in M-Files ServerEPSS 0.7%CVE-2025-6203HIGHVault unauthenticated denial of service through complex json payloadEPSS 0.7%CVE-2023-38498MEDIUMDiscourse vulnerable to DoS via defer queueEPSS 0.7%CVE-2021-25666—A vulnerability has been identified in SCALANCE W780 and W740 (IEEE 802.11n) family (All versions < V6.3). Sending specially crafted packetsEPSS 0.7%CVE-2024-57663HIGHAn issue in the sqlg_place_dpipes component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via EPSS 0.7%CVE-2024-46666MEDIUMAn allocation of resources without limits or throttling [CWE-770] vulnerability in FortiOS versions 7.6.0, versions 7.4.4 through 7.4.0, 7.2EPSS 0.7%CVE-2024-25143MEDIUMThe Document and Media widget In Liferay Portal 7.2.0 through 7.3.6, and older unsupported versions, and Liferay DXP 7.3 before service packEPSS 0.7%CVE-2025-21509MEDIUMVulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are EPSS 0.7%CVE-2025-21508MEDIUMVulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are EPSS 0.7%CVE-2025-32952MEDIUMio.jmix.localfs:jmix-localfs affected by DoS in the Local File StorageEPSS 0.7%CVE-2023-27492MEDIUMEnvoy may crash when a large request body is processed in Lua filterEPSS 0.7%CVE-2025-29907HIGHjsPDF Bypass Regular Expression Denial of Service (ReDoS)EPSS 0.7%CVE-2025-2559MEDIUMOrg.keycloak/keycloak-services: jwt token cache exhaustion leading to denial of service (dos) in keycloakEPSS 0.7%CVE-2023-22740MEDIUMDiscourse vulnerable to Allocation of Resources Without Limits via Chat draftsEPSS 0.7%