Falhas do tipo CWE-770

1.861 resultados

Alocação de recursos sem limite (negação de serviço por esgotamento)

A aplicação aloca recursos (memória, conexões, arquivos, threads) a pedido de um usuário sem impor limites, permitindo que um atacante esgote todos os recursos disponíveis e derrube o serviço. É basicamente deixar a porta aberta para qualquer um encher a caixa d'água até transbordar.

Exemplo

Um servidor web que cria uma nova thread para cada requisição HTTP recebida, sem limite. Um atacante envia milhares de requisições simultâneas e esgota o pool de threads, tornando o servidor inresponsivo para usuários legítimos — é negação de serviço puro.

Como mitigar

Implemente limites rigorosos: rate limiting (requisições por IP/usuário), quotas de recursos, pool de threads/conexões com tamanho máximo, timeout em operações, e monitoramento de consumo. Valide tamanhos de entrada e rejeite alocações que excedam os limites configurados.

CVE-2026-44931MEDIUMmalcontent: Disk Space Exhaustion via Globally Accessible D-Bus APIEPSS 0.2%CVE-2019-25464MEDIUMInputMapper 1.6.10 Local Denial of Service via Username FieldEPSS 0.2%CVE-2022-20484HIGHIn NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. EPSS 0.2%CVE-2022-20478HIGHIn NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. EPSS 0.2%CVE-2022-20479HIGHIn NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. EPSS 0.2%CVE-2025-55079MEDIUMMissing check for thread priorityEPSS 0.2%CVE-2025-13751LOWInteractive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a local authenticated useEPSS 0.2%CVE-2025-59418MEDIUMBunnyPad Vulnerable to Buffer Overflow When Opening Files of Size 20MB or GreaterEPSS 0.2%CVE-2023-47717MEDIUMIBM Security Guardium denial of serviceEPSS 0.2%CVE-2026-45682MEDIUMOpenTelemetry eBPF Instrumentation: CappedConcurrentHashMap leaks keys after removalsEPSS 0.2%CVE-2026-71139MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2025-52657LOWHCL MyXalytics is affected by multiple security vulnerabilities.EPSS 0.2%CVE-2026-13585HIGHAllocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System ContEPSS 0.2%CVE-2025-58344MEDIUMAn issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480EPSS 0.2%CVE-2025-58340MEDIUMAn issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480EPSS 0.2%CVE-2025-58341MEDIUMAn issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480EPSS 0.2%CVE-2025-58342MEDIUMAn issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480EPSS 0.2%CVE-2024-47969MEDIUMImproper resource management in firmware of some Solidigm DC Products may allow an attacker to potentially enable denial of service.EPSS 0.2%CVE-2022-22491MEDIUMIBM App Connect Enterprise Certified Container denial of serviceEPSS 0.2%CVE-2026-24271MEDIUMNVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API, where an attacker could cause allocation of GPU resourcEPSS 0.2%