Vulnerabilities > Resource Management Errors

DATE CVE VULNERABILITY TITLE RISK
2010-09-09 CVE-2010-2767 Resource Management Errors vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
The navigator.plugins implementation in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle destruction of the DOM plugin array, which might allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via crafted access to the navigator object, related to a "dangling pointer vulnerability."
network
mozilla CWE-399
critical
9.3
2010-09-09 CVE-2010-2760 Resource Management Errors vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
Use-after-free vulnerability in the nsTreeSelection function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 might allow remote attackers to execute arbitrary code via vectors involving a XUL tree selection, related to a "dangling pointer vulnerability." NOTE: this issue exists because of an incomplete fix for CVE-2010-2753.
network
mozilla CWE-399
critical
9.3
2010-09-07 CVE-2010-2874 Resource Management Errors vulnerability in Adobe Shockwave Player
Unspecified vulnerability in Adobe Shockwave Player before 11.5.8.612 allows remote attackers to execute arbitrary code via unknown vectors that trigger memory corruption.
network
adobe CWE-399
critical
9.3
2010-08-26 CVE-2010-2839 Resource Management Errors vulnerability in Cisco Unified Presence Server
SIPD in Cisco Unified Presence 6.x before 6.0(7) and 7.x before 7.0(8) allows remote attackers to cause a denial of service (stack memory corruption and process failure) via a malformed SIP message, aka Bug ID CSCtd14474.
network
low complexity
cisco CWE-399
7.8
2010-08-20 CVE-2010-3058 Resource Management Errors vulnerability in IBM Tivoli Storage Manager Fastback
The Mount service in IBM Tivoli Storage Manager (TSM) FastBack 5.x.x before 5.5.7, and 6.1.0.0, establishes an open UDP port, which might allow remote attackers to overwrite memory locations and execute arbitrary code, or cause a denial of service (application hang), via unspecified vectors.
network
low complexity
ibm CWE-399
7.5
2010-08-19 CVE-2010-2813 Resource Management Errors vulnerability in Squirrelmail
functions/imap_general.php in SquirrelMail before 1.4.21 does not properly handle 8-bit characters in passwords, which allows remote attackers to cause a denial of service (disk consumption) by making many IMAP login attempts with different usernames, leading to the creation of many preferences files.
network
low complexity
squirrelmail CWE-399
5.0
2010-08-16 CVE-2010-3021 Resource Management Errors vulnerability in Opera Browser
Unspecified vulnerability in Opera before 10.61 allows remote attackers to cause a denial of service (CPU consumption and application hang) via an animated PNG image.
network
opera CWE-399
4.3
2010-08-11 CVE-2010-2219 Resource Management Errors vulnerability in Adobe Flash Media Server and Flash Media Server 2
Unspecified vulnerability in Adobe Flash Media Server (FMS) before 3.0.6, and 3.5.x before 3.5.4, allows attackers to cause a denial of service (memory consumption) via unknown vectors.
network
low complexity
adobe linux microsoft CWE-399
5.0
2010-08-09 CVE-2010-2800 Resource Management Errors vulnerability in Cabextract Project Cabextract
The MS-ZIP decompressor in cabextract before 1.3 allows remote attackers to cause a denial of service (infinite loop) via a malformed MSZIP archive in a .cab file during a (1) test or (2) extract action, related to the libmspack library.
4.3
2010-07-30 CVE-2010-1793 Resource Management Errors vulnerability in Apple Safari and Webkit
Multiple use-after-free vulnerabilities in WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4; and webkitgtk before 1.2.6; allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a (1) font-face or (2) use element in an SVG document.
network
apple microsoft CWE-399
critical
9.3