Vulnerabilities > Resource Management Errors

DATE CVE VULNERABILITY TITLE RISK
2010-06-01 CVE-2010-2117 Resource Management Errors vulnerability in Mozilla Firefox
Mozilla Firefox 3.0.19, 3.5.x, and 3.6.x allows remote attackers to cause a denial of service (resource consumption) via JavaScript code containing an infinite loop that creates IFRAME elements for invalid (1) news:// or (2) nntp:// URIs.
network
mozilla CWE-399
4.3
2010-05-27 CVE-2010-2093 Resource Management Errors vulnerability in PHP
Use-after-free vulnerability in the request shutdown functionality in PHP 5.2 before 5.2.13 and 5.3 before 5.3.2 allows context-dependent attackers to cause a denial of service (crash) via a stream context structure that is freed before destruction occurs.
network
low complexity
php CWE-399
5.0
2010-05-26 CVE-2009-4875 Resource Management Errors vulnerability in Frederico Caldeira Knabben Fckeditor.Java 2.4
FCKeditor.Java 2.4 allows remote attackers to cause a denial of service (infinite loop) via a malformed request parameter that contains "ctrl" characters.
network
low complexity
frederico-caldeira-knabben CWE-399
5.0
2010-05-21 CVE-2010-0538 Resource Management Errors vulnerability in Apple Java
Apple Java for Mac OS X 10.5 before Update 7 and Java for Mac OS X 10.6 before Update 2 do not properly handle mediaLibImage objects, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds memory access and application crash) via a crafted applet, related to the com.sun.medialib.mlib package.
network
apple CWE-399
6.8
2010-05-20 CVE-2010-1993 Resource Management Errors vulnerability in Opera Browser 9.52
Opera 9.52 does not properly handle an IFRAME element with a mailto: URL in its SRC attribute, which allows remote attackers to cause a denial of service (resource consumption) via an HTML document with many IFRAME elements.
network
low complexity
opera CWE-399
5.0
2010-05-20 CVE-2010-1992 Resource Management Errors vulnerability in Google Chrome 1.0.154.48
Google Chrome 1.0.154.48 executes a mail application in situations where an IFRAME element has a mailto: URL in its SRC attribute, which allows remote attackers to cause a denial of service (excessive application launches) via an HTML document with many IFRAME elements.
network
low complexity
google CWE-399
5.0
2010-05-20 CVE-2010-1991 Resource Management Errors vulnerability in Microsoft IE and Internet Explorer
Microsoft Internet Explorer 6.0.2900.2180, 7, and 8.0.7600.16385 executes a mail application in situations where an IFRAME element has a mailto: URL in its SRC attribute, which allows remote attackers to cause a denial of service (excessive application launches) via an HTML document with many IFRAME elements.
network
low complexity
microsoft CWE-399
5.0
2010-05-20 CVE-2010-1990 Resource Management Errors vulnerability in Mozilla Firefox and Seamonkey
Mozilla Firefox 3.6.x, 3.5.x, 3.0.19, and earlier, and SeaMonkey, executes a mail application in situations where an IFRAME element has a mailto: URL in its SRC attribute, which allows remote attackers to cause a denial of service (excessive application launches) via an HTML document with many IFRAME elements.
network
low complexity
mozilla CWE-399
5.0
2010-05-20 CVE-2010-1989 Resource Management Errors vulnerability in Opera Browser 9.52
Opera 9.52 executes a mail application in situations where an IMG element has a SRC attribute that is a redirect to a mailto: URL, which allows remote attackers to cause a denial of service (excessive application launches) via an HTML document with many images, a related issue to CVE-2010-0181.
network
low complexity
opera CWE-399
5.0
2010-05-20 CVE-2010-1987 Resource Management Errors vulnerability in Mozilla Firefox 3.6.3
Mozilla Firefox 3.6.3 on Windows XP SP3 allows remote attackers to cause a denial of service (memory consumption, out-of-bounds read, and application crash) via JavaScript code that appends long strings to the content of a P element, and performs certain other string concatenation and substring operations, related to the DoubleWideCharMappedString class in USP10.dll and the gfxWindowsFontGroup::GetUnderlineOffset function in xul.dll, a different vulnerability than CVE-2009-1571.
network
low complexity
mozilla microsoft CWE-399
5.0