Vulnerabilities > Resource Management Errors

DATE CVE VULNERABILITY TITLE RISK
2011-02-25 CVE-2011-0388 Resource Management Errors vulnerability in Cisco products
Cisco TelePresence Recording Server devices with software 1.6.x and Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x do not properly restrict remote access to the Java servlet RMI interface, which allows remote attackers to cause a denial of service (memory consumption and web outage) via multiple crafted requests, aka Bug IDs CSCtg35830 and CSCtg35825.
network
low complexity
cisco CWE-399
7.8
2011-02-25 CVE-2011-0377 Resource Management Errors vulnerability in Cisco products
Cisco TelePresence endpoint devices with software 1.2.x through 1.6.x allow remote attackers to cause a denial of service (service crash) via a malformed SOAP request in conjunction with a spoofed TelePresence Manager that supplies an invalid IP address, aka Bug ID CSCth03605.
network
low complexity
cisco CWE-399
7.8
2011-02-23 CVE-2011-0414 Resource Management Errors vulnerability in ISC Bind 9.7.1/9.7.2
ISC BIND 9.7.1 through 9.7.2-P3, when configured as an authoritative server, allows remote attackers to cause a denial of service (deadlock and daemon hang) by sending a query at the time of (1) an IXFR transfer or (2) a DDNS update.
network
isc CWE-399
7.1
2011-02-23 CVE-2011-0022 Resource Management Errors vulnerability in multiple products
The setup scripts in 389 Directory Server 1.2.x (aka Red Hat Directory Server 8.2.x), when multiple unprivileged instances are configured, use 0777 permissions for the /var/run/dirsrv directory, which allows local users to cause a denial of service (daemon outage or arbitrary process termination) by replacing PID files contained in this directory.
4.7
2011-02-23 CVE-2010-4746 Resource Management Errors vulnerability in Fedoraproject 389 Directory Server
Multiple memory leaks in the normalization functionality in 389 Directory Server before 1.2.7.5 allow remote attackers to cause a denial of service (memory consumption) via "badly behaved applications," related to (1) Slapi_Attr mishandling in the DN normalization code and (2) pointer mishandling in the syntax normalization code, a different issue than CVE-2011-0019.
network
low complexity
fedoraproject CWE-399
5.0
2011-02-19 CVE-2011-0430 Resource Management Errors vulnerability in Openafs 1.4.12/1.4.14/1.4.7
Double free vulnerability in the Rx server process in OpenAFS 1.4.14, 1.4.12, 1.4.7, and possibly other versions allows remote attackers to cause a denial of service and execute arbitrary code via unknown vectors.
network
low complexity
openafs CWE-399
7.5
2011-02-19 CVE-2011-0014 Resource Management Errors vulnerability in Openssl
ssl/t1_lib.c in OpenSSL 0.9.8h through 0.9.8q and 1.0.0 through 1.0.0c allows remote attackers to cause a denial of service (crash), and possibly obtain sensitive information in applications that use OpenSSL, via a malformed ClientHello handshake message that triggers an out-of-bounds memory access, aka "OCSP stapling vulnerability."
network
low complexity
openssl CWE-399
5.0
2011-02-18 CVE-2011-1042 Resource Management Errors vulnerability in Google Chrome OS
Use-after-free vulnerability in flimflamd in flimflam in Google Chrome OS before 0.9.130.14 Beta allows user-assisted remote attackers to cause a denial of service (daemon crash) by providing the name of a hidden WiFi network that does not respond to connection attempts.
network
google CWE-399
4.3
2011-02-17 CVE-2011-0355 Resource Management Errors vulnerability in multiple products
Cisco Nexus 1000V Virtual Ethernet Module (VEM) 4.0(4) SV1(1) through SV1(3b), as used in VMware ESX 4.0 and 4.1 and ESXi 4.0 and 4.1, does not properly handle dropped packets, which allows guest OS users to cause a denial of service (ESX or ESXi host OS crash) by sending an 802.1Q tagged packet over an access vEthernet port, aka Cisco Bug ID CSCtj17451.
network
low complexity
cisco vmware CWE-399
7.8
2011-02-10 CVE-2011-0977 Resource Management Errors vulnerability in Microsoft Excel 2007
Use-after-free vulnerability in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via malformed shape data in the Office drawing file format, aka "Microsoft Office Graphic Object Dereferencing Vulnerability."
network
microsoft CWE-399
critical
9.3