Vulnerabilities > Resource Management Errors

DATE CVE VULNERABILITY TITLE RISK
2009-08-28 CVE-2009-3000 Resource Management Errors vulnerability in SUN Opensolaris and Solaris
The sockfs module in the kernel in Sun Solaris 10 and OpenSolaris snv_41 through snv_122, when Network Cache Accelerator (NCA) logging is enabled, allows remote attackers to cause a denial of service (panic) via unspecified web-server traffic that triggers a NULL pointer dereference in the nl7c_http_log function, related to "improper http response handling."
network
sun CWE-399
7.1
2009-08-27 CVE-2009-2972 Resource Management Errors vulnerability in SUN Solaris 8/9
in.lpd in the print service in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors that trigger a "fork()/exec() bomb."
network
low complexity
sun CWE-399
7.8
2009-08-26 CVE-2008-7094 Resource Management Errors vulnerability in Unica Affinium Campaign 7.2.1.0.55
Campaign/CampaignListener in the listener server in Unica Affinium Campaign 7.2.1.0.55 allows remote attackers to cause a denial of service (server crash) via a crafted length field that triggers (1) connection exhaustion or (2) memory allocation failure.
network
low complexity
unica CWE-399
5.0
2009-08-25 CVE-2009-2966 Resource Management Errors vulnerability in Kaspersky Anti-Virus and Kaspersky Internet Security
avp.exe in Kaspersky Internet Security 9.0.0.459 and Anti-Virus 9.0.0.463 allows remote attackers to cause a denial of service (CPU consumption and network connectivity loss) via an HTTP URL request that contains a large number of dot "." characters.
network
kaspersky CWE-399
4.3
2009-08-24 CVE-2008-7061 Resource Management Errors vulnerability in Google Chrome 0.2.149.29
The tooltip manager (chrome/views/tooltip_manager.cc) in Google Chrome 0.2.149.29 Build 1798 and possibly other versions before 0.2.149.30 allows remote attackers to cause a denial of service (CPU consumption or crash) via a tag with a long title attribute, which is not properly handled when displaying a tooltip, a different vulnerability than CVE-2008-6994.
network
google CWE-399
4.3
2009-08-24 CVE-2008-7053 Resource Management Errors vulnerability in Logmein Ractrl.Dll
LogMeIn Remote Access Utility ActiveX control (RACtrl.dll) allows remote attackers to cause a denial of service (crash) by setting the fgcolor and bgcolor properties to certain long values that trigger memory corruption.
network
logmein CWE-399
critical
9.3
2009-08-24 CVE-2009-2953 Resource Management Errors vulnerability in Mozilla Firefox
Mozilla Firefox 3.0.6 through 3.0.13, and 3.5.x, allows remote attackers to cause a denial of service (CPU consumption) via JavaScript code with a long string value for the hash property (aka location.hash), a related issue to CVE-2008-5715.
network
low complexity
mozilla CWE-399
5.0
2009-08-21 CVE-2009-2473 Resource Management Errors vulnerability in Webdav Neon 0.28.6
neon before 0.28.6, when expat is used, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
network
webdav CWE-399
4.3
2009-08-21 CVE-2009-2694 Resource Management Errors vulnerability in multiple products
The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) before 2.5.9 and Adium 1.3.5 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) by sending multiple crafted SLP (aka MSNSLP) messages to trigger an overwrite of an arbitrary memory location.
network
low complexity
adium pidgin CWE-399
critical
10.0
2009-08-19 CVE-2009-2858 Resource Management Errors vulnerability in IBM DB2 8.1
Memory leak in the Security component in IBM DB2 8.1 before FP18 on Unix platforms allows attackers to cause a denial of service (memory consumption) via unspecified vectors, related to private memory within the DB2 memory structure.
network
low complexity
ibm CWE-399
5.0