Vulnerabilities > Resource Management Errors

DATE CVE VULNERABILITY TITLE RISK
2010-04-01 CVE-2010-0770 Resource Management Errors vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 allows remote authenticated users to cause a denial of service (ORB ListenerThread hang) by aborting an SSL handshake.
network
low complexity
ibm CWE-399
4.0
2010-03-31 CVE-2010-0491 Resource Management Errors vulnerability in Microsoft products
Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, and 6 SP1 allows remote attackers to execute arbitrary code by changing unspecified properties of an HTML object that has an onreadystatechange event handler, aka "HTML Object Memory Corruption Vulnerability."
network
microsoft CWE-399
critical
9.3
2010-03-31 CVE-2010-0531 Resource Management Errors vulnerability in Apple Itunes
Apple iTunes before 9.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted MP4 podcast file.
4.3
2010-03-31 CVE-2010-1188 Resource Management Errors vulnerability in Linux Kernel
Use-after-free vulnerability in net/ipv4/tcp_input.c in the Linux kernel 2.6 before 2.6.20, when IPV6_RECVPKTINFO is set on a listening socket, allows remote attackers to cause a denial of service (kernel panic) via a SYN packet while the socket is in a listening (TCP_LISTEN) state, which is not properly handled and causes the skb structure to be freed.
network
linux CWE-399
7.1
2010-03-30 CVE-2010-0503 Resource Management Errors vulnerability in Apple mac OS X Server
Use-after-free vulnerability in iChat Server in Apple Mac OS X Server 10.5.8 allows remote authenticated users to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
network
low complexity
apple CWE-399
6.5
2010-03-25 CVE-2010-1119 Resource Management Errors vulnerability in Apple products
Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Safari before 4.1 on Mac OS X 10.4, and Safari on Apple iPhone OS allows remote attackers to execute arbitrary code or cause a denial of service (application crash), or read the SMS database or other data, via vectors related to "attribute manipulation," as demonstrated by Vincenzo Iozzo and Ralf Philipp Weinmann during a Pwn2Own competition at CanSecWest 2010.
network
low complexity
apple microsoft CWE-399
critical
10.0
2010-03-25 CVE-2010-0583 Resource Management Errors vulnerability in Cisco IOS 12.1Xu/12.1Yd/12.2B
Memory leak in the H.323 implementation in Cisco IOS 12.1 through 12.4, and 15.0M before 15.0(1)M1, allows remote attackers to cause a denial of service (memory consumption and device reload) via malformed H.323 packets, aka Bug ID CSCtb93855.
network
low complexity
cisco CWE-399
7.8
2010-03-25 CVE-2010-0577 Resource Management Errors vulnerability in Cisco IOS
Cisco IOS 12.2 through 12.4, when certain PMTUD, SNAT, or window-size configurations are used, allows remote attackers to cause a denial of service (infinite loop, and device reload or hang) via a TCP segment with crafted options, aka Bug ID CSCsz75186.
network
cisco CWE-399
7.1
2010-03-25 CVE-2010-0164 Resource Management Errors vulnerability in Mozilla Firefox 3.6
Use-after-free vulnerability in the imgContainer::InternalAddFrameHelper function in src/imgContainer.cpp in libpr0n in Mozilla Firefox 3.6 before 3.6.2 allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a multipart/x-mixed-replace animation in which the frames have different bits-per-pixel (bpp) values.
network
mozilla CWE-399
critical
9.3
2010-03-23 CVE-2010-0161 Resource Management Errors vulnerability in Mozilla Seamonkey and Thunderbird
The nsAuthSSPI::Unwrap function in extensions/auth/nsAuthSSPI.cpp in Mozilla Thunderbird before 2.0.0.24 and SeaMonkey before 1.1.19 on Windows Vista, Windows Server 2008 R2, and Windows 7 allows remote SMTP, IMAP, and POP servers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via crafted data in a session that uses SSPI.
4.3