Vulnerabilities > Resource Management Errors

DATE CVE VULNERABILITY TITLE RISK
2009-06-09 CVE-2009-1196 Resource Management Errors vulnerability in Apple Cups 1.1.17/1.1.22
The directory-services functionality in the scheduler in CUPS 1.1.17 and 1.1.22 allows remote attackers to cause a denial of service (cupsd daemon outage or crash) via manipulations of the timing of CUPS browse packets, related to a "pointer use-after-delete flaw."
network
low complexity
apple CWE-399
5.0
2009-06-08 CVE-2009-1958 Resource Management Errors vulnerability in Strongswan
charon/sa/tasks/child_create.c in the charon daemon in strongSWAN before 4.3.1 switches the NULL checks for TSi and TSr payloads, which allows remote attackers to cause a denial of service via an IKE_AUTH request without a (1) TSi or (2) TSr traffic selector.
network
low complexity
strongswan CWE-399
5.0
2009-06-08 CVE-2009-1957 Resource Management Errors vulnerability in Strongswan
charon/sa/ike_sa.c in the charon daemon in strongSWAN before 4.3.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an invalid IKE_SA_INIT request that triggers "an incomplete state," followed by a CREATE_CHILD_SA request.
network
low complexity
strongswan CWE-399
5.0
2009-06-02 CVE-2009-0956 Resource Management Errors vulnerability in Apple Quicktime
Apple QuickTime before 7.6.2 does not properly initialize memory before use in handling movie files, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a movie containing a user data atom of size zero.
network
apple CWE-399
critical
9.3
2009-06-02 CVE-2009-0188 Resource Management Errors vulnerability in Apple Quicktime
Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie composed of a Sorenson 3 video file.
network
apple CWE-399
critical
9.3
2009-05-29 CVE-2009-1828 Resource Management Errors vulnerability in Mozilla Firefox 3.0.10
Mozilla Firefox 3.0.10 allows remote attackers to cause a denial of service (infinite loop, application hang, and memory consumption) via a KEYGEN element in conjunction with (1) a META element specifying automatic page refresh or (2) a JavaScript onLoad event handler for a BODY element.
network
low complexity
mozilla CWE-399
5.0
2009-05-29 CVE-2009-1827 Resource Management Errors vulnerability in Mozilla Firefox 3.0.4
The SVG component in Mozilla Firefox 3.0.4 allows remote attackers to cause a denial of service (application hang) via a large value in the r (aka Radius) attribute of a circle element, related to an "unclamped loop."
network
low complexity
mozilla CWE-399
5.0
2009-05-22 CVE-2009-1758 Resource Management Errors vulnerability in XEN
The hypervisor_callback function in Xen, possibly before 3.4.0, as applied to the Linux kernel 2.6.30-rc4, 2.6.18, and probably other versions allows guest user applications to cause a denial of service (kernel oops) of the guest OS by triggering a segmentation fault in "certain address ranges."
network
low complexity
linux xen CWE-399
5.0
2009-05-14 CVE-2009-1632 Resource Management Errors vulnerability in Ipsec-Tools
Multiple memory leaks in Ipsec-tools before 0.7.2 allow remote attackers to cause a denial of service (memory consumption) via vectors involving (1) signature verification during user authentication with X.509 certificates, related to the eay_check_x509sign function in src/racoon/crypto_openssl.c; and (2) the NAT-Traversal (aka NAT-T) keepalive implementation, related to src/racoon/nattraversal.c.
network
low complexity
ipsec-tools CWE-399
5.0
2009-05-04 CVE-2009-1514 Resource Management Errors vulnerability in Google Chrome 1.0.154.53
Google Chrome 1.0.154.53 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a throw statement with a long exception value.
network
low complexity
google CWE-399
5.0