Falhas do tipo CWE-770

1.861 resultados

Alocação de recursos sem limite (negação de serviço por esgotamento)

A aplicação aloca recursos (memória, conexões, arquivos, threads) a pedido de um usuário sem impor limites, permitindo que um atacante esgote todos os recursos disponíveis e derrube o serviço. É basicamente deixar a porta aberta para qualquer um encher a caixa d'água até transbordar.

Exemplo

Um servidor web que cria uma nova thread para cada requisição HTTP recebida, sem limite. Um atacante envia milhares de requisições simultâneas e esgota o pool de threads, tornando o servidor inresponsivo para usuários legítimos — é negação de serviço puro.

Como mitigar

Implemente limites rigorosos: rate limiting (requisições por IP/usuário), quotas de recursos, pool de threads/conexões com tamanho máximo, timeout em operações, e monitoramento de consumo. Valide tamanhos de entrada e rejeite alocações que excedam os limites configurados.

CVE-2026-96609HIGHRobur Albatross 1.0.0 through 2.x before 2.7.2 does not limit use of the ring buffer, leading to an albatross-console loop with no recognizeEPSS 0.2%CVE-2025-5683MEDIUMWhen loading a specifically crafted ICNS format image file in QImage then it will trigger a crash.  This issue affects Qt from versions 6.3EPSS 0.2%CVE-2024-50271MEDIUMsignal: restore the override_rlimit logicEPSS 0.2%CVE-2021-47784MEDIUMCyberfox Web Browser 52.9.1 - Denial of Service (PoC)EPSS 0.2%CVE-2023-32385—A denial-of-service issue was addressed with improved memory handling. This issue is fixed in iOS 16.5 and iPadOS 16.5, macOS Ventura 13.4. EPSS 0.2%CVE-2023-52529MEDIUMHID: sony: Fix a potential memory leak in sony_probe()EPSS 0.2%CVE-2026-10533MEDIUMOpenshift: openshift: non-admin user can bypass resourcequota and flood etcd with events causing cluster-wide api degradationEPSS 0.2%CVE-2025-21866MEDIUMpowerpc/code-patching: Fix KASAN hit by not flagging text patching area as VM_ALLOCEPSS 0.2%CVE-2024-6176MEDIUMPort scanning vulnerability in LG SuperSign CMSEPSS 0.2%CVE-2024-58089HIGHbtrfs: fix double accounting race when btrfs_run_delalloc_range() failedEPSS 0.2%CVE-2024-26276MEDIUMA vulnerability has been identified in JT2Go (All versions < V2312.0004), Parasolid V35.1 (All versions < V35.1.254), Parasolid V36.0 (All vEPSS 0.2%CVE-2024-56722MEDIUMRDMA/hns: Fix cpu stuck caused by printings during resetEPSS 0.2%CVE-2021-47057MEDIUMcrypto: sun8i-ss - Fix memory leak of object d when dma_iv fails to mapEPSS 0.2%CVE-2023-28428MEDIUMPDFio vulnerable to Denial Of Service when opening a corrupt PDF fileEPSS 0.2%CVE-2025-14341HIGHInput Data Manipulation in DivvyDrive Information Technologies' DivvyDriveEPSS 0.2%CVE-2021-1121MEDIUMNVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager kernel driver, where a vGPU can cause resource starvation among othEPSS 0.2%CVE-2025-21690MEDIUMscsi: storvsc: Ratelimit warning logs to prevent VM denial of serviceEPSS 0.2%CVE-2024-25969MEDIUMDell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an allocation of resources without limits or throttling vulnerability. A localEPSS 0.2%CVE-2025-1823LOWIBM Jazz Reporting Service Denial of ServiceEPSS 0.2%CVE-2024-45484HIGHEnabled ICMP redirection in B&R APROLEPSS 0.2%