Vulnerabilities > Resource Management Errors

DATE CVE VULNERABILITY TITLE RISK
2016-10-05 CVE-2016-7907 Resource Management Errors vulnerability in Qemu
The imx_fec_do_tx function in hw/net/imx_fec.c in QEMU (aka Quick Emulator) does not properly limit the buffer descriptor count when transmitting packets, which allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via vectors involving a buffer descriptor with a length of 0 and crafted values in bd.flags.
local
low complexity
qemu CWE-399
4.4
2016-10-03 CVE-2016-7046 Resource Management Errors vulnerability in Redhat Jboss Enterprise Application Platform 7.0
Red Hat JBoss Enterprise Application Platform (EAP) 7, when operating as a reverse-proxy with default buffer sizes, allows remote attackers to cause a denial of service (CPU and disk consumption) via a long URL.
network
high complexity
redhat CWE-399
5.9
2016-09-27 CVE-2016-7498 Resource Management Errors vulnerability in Openstack Compute (Nova) 13.0.0
OpenStack Compute (nova) 13.0.0 does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service (disk consumption) by deleting instances while in the resize state.
network
low complexity
openstack CWE-399
6.5
2016-09-26 CVE-2016-6308 Resource Management Errors vulnerability in Openssl 1.1.0
statem/statem_dtls.c in the DTLS implementation in OpenSSL 1.1.0 before 1.1.0a allocates memory before checking for an excessive length, which might allow remote attackers to cause a denial of service (memory consumption) via crafted DTLS messages.
network
high complexity
openssl CWE-399
5.9
2016-09-26 CVE-2016-6518 Resource Management Errors vulnerability in Huawei products
Memory leak in Huawei S9300, S5300, S5700, S6700, S7700, S9700, and S12700 devices allows remote attackers to cause a denial of service (memory consumption and restart) via a large number of malformed packets.
network
low complexity
huawei CWE-399
7.5
2016-09-25 CVE-2016-4772 Resource Management Errors vulnerability in Apple products
The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remote attackers to cause a denial of service (unintended lock) via unspecified vectors.
network
low complexity
apple CWE-399
7.5
2016-09-24 CVE-2016-6409 Resource Management Errors vulnerability in Cisco IOS 15.6(1)T
The Data in Motion (DMo) component in Cisco IOS 15.6(1)T and IOS XE, when the IOx feature set is enabled, allows remote attackers to cause a denial of service (out-of-bounds access) via crafted traffic, aka Bug ID CSCuy54015.
network
low complexity
cisco CWE-399
7.5
2016-09-21 CVE-2016-7166 Resource Management Errors vulnerability in multiple products
libarchive before 3.2.0 does not limit the number of recursive decompressions, which allows remote attackers to cause a denial of service (memory consumption and application crash) via a crafted gzip file.
local
low complexity
redhat libarchive oracle CWE-399
5.5
2016-09-21 CVE-2016-5427 Resource Management Errors vulnerability in Powerdns Authoritative
PowerDNS (aka pdns) Authoritative Server before 3.4.10 does not properly handle a .
network
low complexity
powerdns CWE-399
7.5
2016-09-21 CVE-2016-5426 Resource Management Errors vulnerability in Powerdns Authoritative
PowerDNS (aka pdns) Authoritative Server before 3.4.10 allows remote attackers to cause a denial of service (backend CPU consumption) via a long qname.
network
low complexity
powerdns CWE-399
7.5