Vulnerabilities > Resource Management Errors

DATE CVE VULNERABILITY TITLE RISK
2010-01-13 CVE-2009-3955 Resource Management Errors vulnerability in Adobe Acrobat and Acrobat Reader
Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted JPC_MS_RGN marker in the Jp2c stream of a JpxDecode encoded data stream, which triggers an integer sign extension that bypasses a sanity check, leading to memory corruption.
network
low complexity
adobe apple microsoft CWE-399
critical
10.0
2010-01-09 CVE-2010-0277 Resource Management Errors vulnerability in multiple products
slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.6, including 2.6.4, and Adium 1.3.8 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a malformed MSNSLP INVITE request in an SLP message, a different issue than CVE-2010-0013.
network
low complexity
adium pidgin CWE-399
5.0
2010-01-07 CVE-2010-0220 Resource Management Errors vulnerability in Mozilla Firefox
The nsObserverList::FillObserverArray function in xpcom/ds/nsObserverList.cpp in Mozilla Firefox before 3.5.7 allows remote attackers to cause a denial of service (application crash) via a crafted web site that triggers memory consumption and an accompanying Low Memory alert dialog, and also triggers attempted removal of an observer from an empty observers array.
network
low complexity
mozilla CWE-399
5.0
2009-12-30 CVE-2009-4479 Resource Management Errors vulnerability in Mailsite 8.0.4
LDAP3A.exe in MailSite 8.0.4 allows remote attackers to cause a denial of service (heap memory corruption and daemon crash) via unspecified vectors, as demonstrated by a certain module in VulnDisco Pack Professional 7.13 through 8.11.
network
low complexity
mailsite CWE-399
7.8
2009-12-29 CVE-2009-4448 Resource Management Errors vulnerability in Mybboard Mybb 1.4.10
inc/functions_time.php in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, allows remote attackers to cause a denial of service (CPU consumption) via a crafted request with a large year value, which triggers a long loop, as reachable through member.php and possibly other vectors.
network
low complexity
mybboard CWE-399
5.0
2009-12-17 CVE-2009-3980 Resource Management Errors vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
network
mozilla CWE-399
critical
9.3
2009-12-17 CVE-2009-3388 Resource Management Errors vulnerability in Mozilla Firefox and Seamonkey
liboggplay in Mozilla Firefox 3.5.x before 3.5.6 and SeaMonkey before 2.0.1 might allow context-dependent attackers to cause a denial of service (application crash) or execute arbitrary code via unspecified vectors, related to "memory safety issues."
network
mozilla CWE-399
critical
9.3
2009-12-10 CVE-2009-3798 Resource Management Errors vulnerability in Adobe AIR and Flash Player
Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors that trigger memory corruption.
network
adobe CWE-399
critical
9.3
2009-12-10 CVE-2009-3797 Resource Management Errors vulnerability in Adobe AIR and Flash Player
Adobe Flash Player 10.x before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors that trigger memory corruption.
network
adobe CWE-399
critical
9.3
2009-12-09 CVE-2009-3675 Resource Management Errors vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
LSASS.exe in the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote authenticated users to cause a denial of service (CPU consumption) via a malformed ISAKMP request over IPsec, aka "Local Security Authority Subsystem Service Resource Exhaustion Vulnerability."
network
low complexity
microsoft CWE-399
6.8