Falhas do tipo CWE-770

1.861 resultados

Alocação de recursos sem limite (negação de serviço por esgotamento)

A aplicação aloca recursos (memória, conexões, arquivos, threads) a pedido de um usuário sem impor limites, permitindo que um atacante esgote todos os recursos disponíveis e derrube o serviço. É basicamente deixar a porta aberta para qualquer um encher a caixa d'água até transbordar.

Exemplo

Um servidor web que cria uma nova thread para cada requisição HTTP recebida, sem limite. Um atacante envia milhares de requisições simultâneas e esgota o pool de threads, tornando o servidor inresponsivo para usuários legítimos — é negação de serviço puro.

Como mitigar

Implemente limites rigorosos: rate limiting (requisições por IP/usuário), quotas de recursos, pool de threads/conexões com tamanho máximo, timeout em operações, e monitoramento de consumo. Valide tamanhos de entrada e rejeite alocações que excedam os limites configurados.

CVE-2026-81885MEDIUMradare2: Infinite relocation-chain loop causes denial of service in radare2 NE parserEPSS 0.1%CVE-2025-58345MEDIUMAn issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480EPSS 0.1%CVE-2025-58346MEDIUMAn issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480EPSS 0.1%CVE-2026-14330MEDIUMPipewire: pulse server alloca stack overflowEPSS 0.1%CVE-2024-58114MEDIUMResource allocation control failure vulnerability in the ArkUI framework Impact: Successful exploitation of this vulnerability may affect avEPSS 0.1%CVE-2025-36136MEDIUMIBM denial of serviceEPSS 0.1%CVE-2024-31314MEDIUMIn multiple functions of ShortcutService.java, there is a possible persistent DOS due to resource exhaustion. This could lead to local deniaEPSS 0.1%CVE-2026-25281HIGHAllocation of Resources Without Limits or Throttling in OOBMEPSS 0.1%CVE-2024-43083MEDIUMIn validate of WifiConfigurationUtil.java , there is a possible persistent denial of service due to resource exhaustion. This could lead to EPSS 0.1%CVE-2023-21176—In list_key_entries of utils.rs, there is a possible way to disable user credentials due to resource exhaustion. This could lead to local deEPSS 0.1%CVE-2023-21110HIGHIn several functions of SnoozeHelper.java, there is a possible way to grant notifications access due to resource exhaustion. This could leadEPSS 0.1%CVE-2026-28633MEDIUMIn initForUserNoTracing of VoiceInteractionManagerService.java, there is a possible persistent denial of service due to resource exhaustion.EPSS 0.1%CVE-2023-20930MEDIUMIn pushDynamicShortcut of ShortcutPackage.java, there is a possible way to get the device into a boot loop due to resource exhaustion. This EPSS 0.1%CVE-2022-48441MEDIUMIn dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution priEPSS 0.1%CVE-2022-48440MEDIUMIn dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution priEPSS 0.1%CVE-2026-100656HIGHNetty HttpServerCodec Unbounded Queue Growth via HTTP/1.1 PipeliningEPSS —CVE-2026-100649MEDIUMvLLM before 0.29.0 Resource Limit Bypass via Sampler SubclassEPSS —CVE-2026-100655MEDIUMNetty before 4.1.138.Final Denial of Service via SpdySessionHandlerEPSS —CVE-2026-100658MEDIUMNetty before 4.1.138.Final Denial of Service via WebSocketServerExtensionHandlerEPSS —CVE-2026-100660HIGHNetty before 4.2.18.Final QpackEncoder Unbounded Memory RetentionEPSS —