Vulnerabilities > Resource Management Errors

DATE CVE VULNERABILITY TITLE RISK
2012-03-29 CVE-2012-1310 Resource Management Errors vulnerability in Cisco IOS
Memory leak in the Zone-Based Firewall in Cisco IOS 12.4, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted IP packets, aka Bug ID CSCto89536.
network
low complexity
cisco CWE-399
7.8
2012-03-29 CVE-2012-0388 Resource Management Errors vulnerability in Cisco IOS
Memory leak in the H.323 inspection feature in the Zone-Based Firewall in Cisco IOS 12.4, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (memory consumption or device reload) via malformed transit H.323 traffic, aka Bug ID CSCtq45553.
network
low complexity
cisco CWE-399
7.8
2012-03-29 CVE-2012-0387 Resource Management Errors vulnerability in Cisco IOS
Memory leak in the HTTP Inspection Engine feature in the Zone-Based Firewall in Cisco IOS 12.4, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted transit HTTP traffic, aka Bug ID CSCtq36153.
network
low complexity
cisco CWE-399
7.8
2012-03-29 CVE-2012-0383 Resource Management Errors vulnerability in Cisco IOS 12.4/15.0/15.1
Memory leak in the NAT feature in Cisco IOS 12.4, 15.0, and 15.1 allows remote attackers to cause a denial of service (memory consumption, and device hang or reload) via SIP packets that require translation, related to a "memory starvation vulnerability," aka Bug ID CSCti35326.
network
low complexity
cisco CWE-399
7.8
2012-03-20 CVE-2012-0712 Resource Management Errors vulnerability in IBM DB2 9.5/9.7/9.8
The XML feature in IBM DB2 9.5 before FP9, 9.7 through FP5, and 9.8 through FP4 allows remote authenticated users to cause a denial of service (infinite loop) by calling the XMLPARSE function with a crafted string expression.
network
low complexity
ibm CWE-399
4.0
2012-03-15 CVE-2012-1165 Resource Management Errors vulnerability in Openssl
The mime_param_cmp function in crypto/asn1/asn_mime.c in OpenSSL before 0.9.8u and 1.x before 1.0.0h allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted S/MIME message, a different vulnerability than CVE-2006-7250.
network
low complexity
openssl CWE-399
5.0
2012-03-15 CVE-2012-1178 Resource Management Errors vulnerability in Pidgin
The msn_oim_report_to_user function in oim.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.2 allows remote servers to cause a denial of service (application crash) via an OIM message that lacks UTF-8 encoding.
network
low complexity
pidgin CWE-399
5.0
2012-03-14 CVE-2012-0464 Resource Management Errors vulnerability in Mozilla products
Use-after-free vulnerability in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allows remote attackers to execute arbitrary code via vectors involving an empty argument to the array.join function in conjunction with the triggering of garbage collection.
network
low complexity
mozilla CWE-399
7.5
2012-03-14 CVE-2012-0457 Resource Management Errors vulnerability in Mozilla products
Use-after-free vulnerability in the nsSMILTimeValueSpec::ConvertBetweenTimeContainer function in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 might allow remote attackers to execute arbitrary code via an SVG animation.
network
mozilla CWE-399
critical
9.3
2012-03-14 CVE-2012-0454 Resource Management Errors vulnerability in Mozilla products
Use-after-free vulnerability in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 on 32-bit Windows 7 platforms allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving use of the file-open dialog in a child window, related to the IUnknown_QueryService function in the Windows shlwapi.dll library.
network
low complexity
mozilla microsoft CWE-399
7.5