Falhas do tipo CWE-770

1.864 resultados

Alocação de recursos sem limite (negação de serviço por esgotamento)

A aplicação aloca recursos (memória, conexões, arquivos, threads) a pedido de um usuário sem impor limites, permitindo que um atacante esgote todos os recursos disponíveis e derrube o serviço. É basicamente deixar a porta aberta para qualquer um encher a caixa d'água até transbordar.

Exemplo

Um servidor web que cria uma nova thread para cada requisição HTTP recebida, sem limite. Um atacante envia milhares de requisições simultâneas e esgota o pool de threads, tornando o servidor inresponsivo para usuários legítimos — é negação de serviço puro.

Como mitigar

Implemente limites rigorosos: rate limiting (requisições por IP/usuário), quotas de recursos, pool de threads/conexões com tamanho máximo, timeout em operações, e monitoramento de consumo. Valide tamanhos de entrada e rejeite alocações que excedam os limites configurados.

CVE-2025-14435MEDIUMApplication-Level DoS via infinite re-render loop in user profile handlingEPSS 0.3%CVE-2023-24785MEDIUMAn issue in Giorgio Tani peazip v.9.0.0 allows attackers to cause a denial of service via the End of Archive tag function of the peazip/pea EPSS 0.3%CVE-2024-39724MEDIUMIBM Db2 Big SQL on Cloud Pak for Data is vulnerable to a denial of service due to lack of throttling on an APIEPSS 0.3%CVE-2026-24661LOWUnbounded Request Body Read in MS Teams Plugin {{/changes}} Webhook EndpointEPSS 0.3%CVE-2026-21388LOWUnbounded Request Body Read in MS Teams Plugin {{/lifecycle}} Webhook EndpointEPSS 0.3%CVE-2026-19204HIGHA client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memoryEPSS 0.3%CVE-2026-100649MEDIUMvLLM before 0.29.0 Resource Limit Bypass via Sampler SubclassEPSS 0.3%CVE-2022-41846MEDIUMAn issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in the function AP4_DataBuffer::ReallocateBuffer in Core/EPSS 0.3%CVE-2026-20431MEDIUMIn Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE has connected to a rogEPSS 0.3%CVE-2022-35089MEDIUMSWFTools commit 772e55a2 was discovered to contain a heap-buffer-overflow via getTransparentColor at /home/bupt/Desktop/swftools/src/gif2swfEPSS 0.3%CVE-2026-44219LOWciguard: SCA HTTP client reads response body without size capEPSS 0.3%CVE-2026-14514MEDIUMReliable Scalable Cluster Technology Denial-of-ServiceEPSS 0.3%CVE-2025-54869MEDIUMFPDI is Vulnerable to Memory Exhaustion (OOM) through its PDF ParserEPSS 0.3%CVE-2025-55670HIGHBIG-IP Next (CNF, SPK, and Kubernetes) vulnerabilityEPSS 0.3%CVE-2025-25207MEDIUMRhcl: authpolicy callbacks result in denial of service in authorino severityEPSS 0.3%CVE-2023-20067HIGHCisco IOS XE Software for Wireless LAN Controllers HTTP Client Profiling Denial of Service VulnerabilityEPSS 0.3%CVE-2025-4097MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.3%CVE-2025-46687MEDIUMquickjs-ng through 0.9.0 has a missing length check in JS_ReadString for a string, leading to a heap-based buffer overflow. QuickJS before 2EPSS 0.3%CVE-2025-24127MEDIUMThe issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS SonoEPSS 0.3%CVE-2026-1387MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.3%