Vulnerabilities > Resource Management Errors

DATE CVE VULNERABILITY TITLE RISK
2011-09-22 CVE-2011-3210 Resource Management Errors vulnerability in Openssl
The ephemeral ECDH ciphersuite functionality in OpenSSL 0.9.8 through 0.9.8r and 1.0.x before 1.0.0e does not ensure thread safety during processing of handshake messages from clients, which allows remote attackers to cause a denial of service (daemon crash) via out-of-order messages that violate the TLS protocol.
network
low complexity
openssl CWE-399
5.0
2011-09-20 CVE-2011-3482 Resource Management Errors vulnerability in Wireshark 1.6.0/1.6.1
The csnStreamDissector function in epan/dissectors/packet-csn1.c in the CSN.1 dissector in Wireshark 1.6.x before 1.6.2 does not initialize a certain structure member, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.
network
wireshark CWE-399
4.3
2011-09-16 CVE-2011-3488 Resource Management Errors vulnerability in Equis Metastock
Use-after-free vulnerability in Equis MetaStock 11 and earlier allows remote attackers to execute arbitrary code via a malformed (1) mwc chart, (2) mws chart, (3) mwt template, or (4) mwl layout.
network
low complexity
equis CWE-399
critical
10.0
2011-09-15 CVE-2011-2440 Resource Management Errors vulnerability in Adobe Acrobat and Acrobat Reader
Use-after-free vulnerability in Adobe Reader and Acrobat 8.x before 8.3.1, 9.x before 9.4.6, and 10.x before 10.1.1 allows attackers to execute arbitrary code via unspecified vectors.
network
adobe CWE-399
critical
9.3
2011-09-15 CVE-2011-2439 Resource Management Errors vulnerability in Adobe Acrobat and Acrobat Reader
Adobe Reader and Acrobat 8.x before 8.3.1, 9.x before 9.4.6, and 10.x before 10.1.1 allow attackers to execute arbitrary code via unspecified vectors, related to a "memory leakage condition vulnerability."
network
adobe CWE-399
critical
9.3
2011-09-15 CVE-2011-1986 Resource Management Errors vulnerability in Microsoft Excel 2003
Use-after-free vulnerability in Microsoft Excel 2003 SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Use after Free WriteAV Vulnerability."
network
microsoft CWE-399
critical
9.3
2011-09-13 CVE-2009-5098 Resource Management Errors vulnerability in HP Palm PRE Webos 1.0.2/1.0.3/1.0.4
The LunaSysMgr process in Palm Pre WebOS 1.1 and earlier, when not viewing web pages in landscape mode, allows remote attackers to cause a denial of service (crash) via a web page containing a long string following a refresh tag, which triggers a floating point exception.
network
high complexity
hp CWE-399
5.4
2011-08-29 CVE-2011-3184 Resource Management Errors vulnerability in Pidgin
The msn_httpconn_parse_data function in httpconn.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.0 does not properly handle HTTP 100 responses, which allows remote attackers to cause a denial of service (incorrect memory access and application crash) via vectors involving a crafted server message.
network
pidgin CWE-399
4.3
2011-08-29 CVE-2011-2561 Resource Management Errors vulnerability in Cisco Unified Communications Manager
The SIP process in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 7.x before 7.1(5b)su4 and 8.x before 8.0(1) does not properly handle SDP data within a SIP call in certain situations related to use of the g729ar8 codec for a Media Termination Point (MTP), which allows remote attackers to cause a denial of service (service outage) via a crafted call, aka Bug ID CSCtc61990.
network
cisco CWE-399
7.1
2011-08-29 CVE-2011-2560 Resource Management Errors vulnerability in Cisco Unified Communications Manager
The Packet Capture Service in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x does not properly handle idle TCP connections, which allows remote attackers to cause a denial of service (memory consumption and restart) by making many connections, aka Bug ID CSCtf97162.
network
low complexity
cisco CWE-399
7.8