Vulnerabilities > Resource Management Errors

DATE CVE VULNERABILITY TITLE RISK
2010-04-22 CVE-2010-1320 Resource Management Errors vulnerability in MIT Kerberos 5
Double free vulnerability in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x before 1.8.2 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a request associated with (1) renewal or (2) validation.
network
low complexity
mit CWE-399
4.0
2010-04-16 CVE-2010-1460 Resource Management Errors vulnerability in IBM Advanced Management Module
The IBM BladeCenter with Advanced Management Module (AMM) firmware before bpet50g does not properly perform interrupt sharing for USB and iSCSI, which allows remote attackers to cause a denial of service (management module reboot) via TCP packets with malformed application data.
network
low complexity
ibm CWE-399
5.0
2010-04-14 CVE-2010-0477 Resource Management Errors vulnerability in Microsoft Windows 7 and Windows Server 2008
The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly handle (1) SMBv1 and (2) SMBv2 response packets, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted packet that causes the client to read the entirety of the response, and then improperly interact with the Winsock Kernel (WSK), aka "SMB Client Message Size Vulnerability."
network
low complexity
microsoft CWE-399
critical
10.0
2010-04-14 CVE-2010-0236 Resource Management Errors vulnerability in Microsoft products
The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold does not properly allocate memory for the destination key associated with a symbolic-link registry key, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Allocation Vulnerability."
local
low complexity
microsoft CWE-399
7.2
2010-04-06 CVE-2010-1083 Resource Management Errors vulnerability in Linux Kernel
The processcompl_compat function in drivers/usb/core/devio.c in Linux kernel 2.6.x through 2.6.32, and possibly other versions, does not clear the transfer buffer before returning to userspace when a USB command fails, which might make it easier for physically proximate attackers to obtain sensitive information (kernel memory).
local
linux CWE-399
4.7
2010-04-05 CVE-2010-0177 Resource Management Errors vulnerability in Mozilla Firefox and Seamonkey
Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, frees the contents of the window.navigator.plugins array while a reference to an array element is still active, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors, related to a "dangling pointer vulnerability."
network
mozilla CWE-399
critical
9.3
2010-04-05 CVE-2010-0176 Resource Management Errors vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4; and SeaMonkey before 2.0.4 do not properly manage reference counts for option elements in a XUL tree optgroup, which might allow remote attackers to execute arbitrary code via unspecified vectors that trigger access to deleted elements, related to a "dangling pointer vulnerability."
network
mozilla CWE-399
critical
9.3
2010-04-05 CVE-2010-0175 Resource Management Errors vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
Use-after-free vulnerability in the nsTreeSelection implementation in Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.9, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors that trigger a call to the handler for the select event for XUL tree items.
network
mozilla CWE-399
critical
9.3
2010-04-01 CVE-2010-1232 Resource Management Errors vulnerability in Google Chrome
Google Chrome before 4.1.249.1036 allows remote attackers to cause a denial of service (memory error) or possibly have unspecified other impact via a malformed SVG document.
network
low complexity
google CWE-399
5.0
2010-04-01 CVE-2010-1229 Resource Management Errors vulnerability in Google Chrome
The sandbox infrastructure in Google Chrome before 4.1.249.1036 does not properly use pointers, which has unspecified impact and attack vectors.
network
low complexity
google CWE-399
critical
10.0