CWE-400 未加控制的资源消耗(资源穷尽) 类弱点 1457 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-400 指资源消耗不受控漏洞,属于资源管理缺陷。攻击者通常通过发送大量请求或构造复杂查询,耗尽服务器 CPU、内存或带宽,导致服务拒绝。开发者应避免此类问题,需实施严格的速率限制、请求大小校验及资源配额管理,并设置合理的超时机制与异常处理逻辑,确保有限资源在预期范围内被安全分配与维护。
class Worker implements Executor { ... public void execute(Runnable r) { try { ... } catch (InterruptedException ie) { // postpone response Thread.currentThread().interrupt(); } } public Worker(Channel ch, int nworkers) { ... } protected void activate() { Runnable loop = new Runnable() { public void run() { try { for (;;) { Runnable r = ...; r.run(); } } catch (InterruptedException ie) { ... } } }; new Thread(loop).start(); } }sock=socket(AF_INET, SOCK_STREAM, 0); while (1) { newsock=accept(sock, ...); printf("A connection has been accepted\n"); pid = fork(); }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2018-0086 | Cisco Unified Customer Voice Portal application server 安全漏洞 — Cisco Unified Customer Voice Portal | 8.6 | - | 2018-01-18 |
| CVE-2017-12741 | 多款Siemens产品资源管理错误漏洞 — Development/Evaluation Kits for PROFINET IO: DK Standard Ethernet Controller | 7.5 | High | 2017-12-26 |
| CVE-2017-12190 | Linux kernel 资源管理错误漏洞 — Linux kernel through v4.14-rc5 | 6.5 | - | 2017-11-22 |
| CVE-2017-14028 | Moxa NPort 5110、5130和5150 安全漏洞 — Moxa NPort 5110, 5130, and 5150 | 7.5 | - | 2017-11-16 |
| CVE-2016-8610 | OpenSSL 资源管理错误漏洞 — OpenSSL | 7.5 | - | 2017-11-13 |
| CVE-2017-9627 | Schneider Electric Wonderware ArchestrA Logger 安全漏洞 — Schneider Electric Wonderware ArchestrA Logger | 7.7 | - | 2017-07-07 |
| CVE-2017-6017 | 多款Schneider Electric产品安全漏洞 — Schneider Electric Modicon M340 PLC | 7.5 | - | 2017-06-30 |
| CVE-2017-7521 | OpenVPN 安全漏洞 — OpenVPN | 5.9 | - | 2017-06-27 |
| CVE-2017-6043 | Trihedral VTScada 安全漏洞 — Trihedral VTScada | 7.5 | - | 2017-06-21 |
| CVE-2017-7935 | Phoenix Contact GmbH mGuard 资源管理错误漏洞 — Phoenix Contact GmbH mGuard | 7.5 | - | 2017-05-19 |
| CVE-2017-2681 | 多款Siemens产品资源管理错误漏洞 — Development/Evaluation Kits for PROFINET IO: DK Standard Ethernet Controller | 6.5 | Medium | 2017-05-11 |
| CVE-2017-2680 | Siemens SIMATIC 资源管理错误漏洞 — Development/Evaluation Kits for PROFINET IO: DK Standard Ethernet Controller | 6.5 | Medium | 2017-05-11 |
| CVE-2017-6024 | 多款Rockwell Automation产品安全漏洞 — Rockwell Automation ControlLogix 5580 and CompactLogix 5380 | 5.9 | - | 2017-05-06 |
| CVE-2017-6019 | Schneider Electric Conext ComBox 865-1058 安全漏洞 — Schneider Electric Conext ComBox | 7.5 | - | 2017-04-07 |
| CVE-2014-5418 | 多款General Electric交换机拒绝服务漏洞 — Multilink ML800/1200/1600/2400 | 7.5 | - | 2015-01-17 |
| CVE-2014-2342 | Triangle MicroWorks SCADA Data Gateway 输入验证漏洞 — SCADA Data Gateway | 7.5 | - | 2014-05-30 |
| CVE-2014-2343 | Triangle MicroWorks SCADA Data Gateway 输入验证漏洞 — SCADA Data Gateway | 4.6 | - | 2014-05-30 |
CWE-400(未加控制的资源消耗(资源穷尽)) 是常见的弱点类别,本平台收录该类弱点关联的 1457 条 CVE 漏洞。