Vulnerabilities > Resource Management Errors

DATE CVE VULNERABILITY TITLE RISK
2009-07-22 CVE-2009-2462 Resource Management Errors vulnerability in Mozilla Firefox and Thunderbird
The browser engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) the frame chain and synchronous events, (2) a SetMayHaveFrame assertion and nsCSSFrameConstructor::CreateFloatingLetterFrame, (3) nsCSSFrameConstructor::ConstructFrame, (4) the child list and initial reflow, (5) GetLastSpecialSibling, (6) nsFrameManager::GetPrimaryFrameFor and MathML, (7) nsFrame::GetBoxAscent, (8) nsCSSFrameConstructor::AdjustParentFrame, (9) nsDOMOfflineResourceList, and (10) nsContentUtils::ComparePosition.
network
low complexity
mozilla CWE-399
critical
10.0
2009-07-20 CVE-2009-2542 Resource Management Errors vulnerability in Netscape Navigator 6/8
Netscape 6 and 8 allows remote attackers to cause a denial of service (memory consumption) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.
network
netscape CWE-399
4.3
2009-07-20 CVE-2009-2541 Resource Management Errors vulnerability in Sony Playstation 3
The web browser on the Sony PLAYSTATION 3 (PS3) allows remote attackers to cause a denial of service (memory consumption and console hang) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.
network
low complexity
sony CWE-399
7.8
2009-07-20 CVE-2009-2538 Resource Management Errors vulnerability in Nokia N810 Internet Tablet, N82 and Symbian
The Nokia N95 running Symbian OS 9.2, N82, and N810 Internet Tablet allow remote attackers to cause a denial of service (memory consumption) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.
network
nokia CWE-399
7.1
2009-07-20 CVE-2009-2537 Resource Management Errors vulnerability in KDE Konqueror
KDE Konqueror allows remote attackers to cause a denial of service (memory consumption) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.
network
kde CWE-399
4.3
2009-07-20 CVE-2009-2536 Resource Management Errors vulnerability in Microsoft Internet Explorer
Microsoft Internet Explorer 5 through 8 allows remote attackers to cause a denial of service (memory consumption and application crash) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.
network
microsoft CWE-399
4.3
2009-07-16 CVE-2009-2487 Resource Management Errors vulnerability in SUN Opensolaris and Solaris
Use-after-free vulnerability in the frpr_icmp function in the ipfilter (aka IP Filter) subsystem in Sun Solaris 10, and OpenSolaris snv_45 through snv_110, allows remote attackers to cause a denial of service (panic) via unspecified vectors.
network
low complexity
sun CWE-399
7.8
2009-07-09 CVE-2009-2419 Resource Management Errors vulnerability in Apple Safari 4.0/4.0.1
Use-after-free vulnerability in the servePendingRequests function in WebCore in WebKit in Apple Safari 4.0 and 4.0.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted HTML document that references a zero-length .js file and the JavaScript reload function.
network
apple CWE-399
4.3
2009-07-02 CVE-2009-2300 Resource Management Errors vulnerability in Phion Airlock web Application Firewall 4.110.41
The management interface in the phion airlock Web Application Firewall (WAF) 4.1-10.41 does not properly handle CGI requests that specify large width and height parameters for an image, which allows remote attackers to execute arbitrary commands or cause a denial of service (resource consumption) via a crafted request.
network
low complexity
phion CWE-399
critical
10.0
2009-07-01 CVE-2009-1889 Resource Management Errors vulnerability in Pidgin
The OSCAR protocol implementation in Pidgin before 2.5.8 misinterprets the ICQWebMessage message type as the ICQSMS message type, which allows remote attackers to cause a denial of service (application crash) via a crafted ICQ web message that triggers allocation of a large amount of memory.
network
low complexity
pidgin CWE-399
5.0