Vulnerabilities > Resource Management Errors

DATE CVE VULNERABILITY TITLE RISK
2009-06-02 CVE-2009-0188 Resource Management Errors vulnerability in Apple Quicktime
Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie composed of a Sorenson 3 video file.
network
apple CWE-399
critical
9.3
2009-05-29 CVE-2009-1828 Resource Management Errors vulnerability in Mozilla Firefox 3.0.10
Mozilla Firefox 3.0.10 allows remote attackers to cause a denial of service (infinite loop, application hang, and memory consumption) via a KEYGEN element in conjunction with (1) a META element specifying automatic page refresh or (2) a JavaScript onLoad event handler for a BODY element.
network
low complexity
mozilla CWE-399
5.0
2009-05-29 CVE-2009-1827 Resource Management Errors vulnerability in Mozilla Firefox 3.0.4
The SVG component in Mozilla Firefox 3.0.4 allows remote attackers to cause a denial of service (application hang) via a large value in the r (aka Radius) attribute of a circle element, related to an "unclamped loop."
network
low complexity
mozilla CWE-399
5.0
2009-05-22 CVE-2009-1758 Resource Management Errors vulnerability in XEN
The hypervisor_callback function in Xen, possibly before 3.4.0, as applied to the Linux kernel 2.6.30-rc4, 2.6.18, and probably other versions allows guest user applications to cause a denial of service (kernel oops) of the guest OS by triggering a segmentation fault in "certain address ranges."
network
low complexity
linux xen CWE-399
5.0
2009-05-14 CVE-2009-1632 Resource Management Errors vulnerability in Ipsec-Tools
Multiple memory leaks in Ipsec-tools before 0.7.2 allow remote attackers to cause a denial of service (memory consumption) via vectors involving (1) signature verification during user authentication with X.509 certificates, related to the eay_check_x509sign function in src/racoon/crypto_openssl.c; and (2) the NAT-Traversal (aka NAT-T) keepalive implementation, related to src/racoon/nattraversal.c.
network
low complexity
ipsec-tools CWE-399
5.0
2009-05-04 CVE-2009-1514 Resource Management Errors vulnerability in Google Chrome 1.0.154.53
Google Chrome 1.0.154.53 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a throw statement with a long exception value.
network
low complexity
google CWE-399
5.0
2009-05-01 CVE-2009-1511 Resource Management Errors vulnerability in Microsoft Windows XP
GDI+ in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (infinite loop) via a PNG file that contains a certain large btChunkLen value.
network
low complexity
microsoft CWE-399
7.8
2009-04-30 CVE-2009-1492 Resource Management Errors vulnerability in Adobe Acrobat and Acrobat Reader
The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that contains an annotation, and has an OpenAction entry with JavaScript code that calls this method with crafted integer arguments.
network
adobe CWE-399
critical
9.3
2009-04-27 CVE-2009-1190 Resource Management Errors vulnerability in SUN JDK
Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Development Kit (JDK) before 1.6, when used with spring.jar in SpringSource Spring Framework 1.1.0 through 2.5.6 and 3.0.0.M1 through 3.0.0.M2 and dm Server 1.0.0 through 1.0.2, allows remote attackers to cause a denial of service (CPU consumption) via serializable data with a long regex string containing multiple optional groups, a related issue to CVE-2004-2540.
network
low complexity
sun springsource CWE-399
5.0
2009-04-27 CVE-2009-1435 Resource Management Errors vulnerability in Trendmicro Officescan 8.0
NTRtScan.exe in Trend Micro OfficeScan Client 8.0 SP1 and 8.0 SP1 Patch 1 allows local users to cause a denial of service (application crash) via directories with long pathnames.
local
low complexity
trendmicro CWE-399
2.1