Vulnerabilities > Resource Management Errors

DATE CVE VULNERABILITY TITLE RISK
2009-02-17 CVE-2008-4285 Resource Management Errors vulnerability in IBM Websphere Application Server
Unspecified vulnerability in the Performance Monitoring Infrastructure (PMI) feature in the Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.19, when a component statistic is enabled, allows attackers to cause a denial of service (daemon crash) via vectors related to "a gradual degradation in performance."
network
low complexity
ibm CWE-399
5.0
2009-02-14 CVE-2008-6141 Resource Management Errors vulnerability in Avaya IP Soft Phone 6.0/6.01.85
Unspecified vulnerability in Avaya IP Softphone 6.0 SP4 and 6.01.85 allows remote attackers to cause a denial of service (crash) via a large amount of H.323 data.
network
low complexity
avaya CWE-399
5.0
2009-02-13 CVE-2009-0140 Resource Management Errors vulnerability in Apple mac OS X and mac OS X Server
Unspecified vulnerability in the SMB component in Apple Mac OS X 10.4.11 and 10.5.6 allows remote SMB servers to cause a denial of service (memory exhaustion and system shutdown) via a crafted file system name.
network
apple CWE-399
critical
9.3
2009-02-13 CVE-2009-0020 Resource Management Errors vulnerability in Apple mac OS X and mac OS X Server
Unspecified vulnerability in CarbonCore in Apple Mac OS X 10.4.11 and 10.5.6 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted resource fork that triggers memory corruption.
network
low complexity
apple CWE-399
7.8
2009-02-10 CVE-2009-0098 Resource Management Errors vulnerability in Microsoft Exchange Server 2000/2003/2007
Microsoft Exchange 2000 Server SP3, Exchange Server 2003 SP2, and Exchange Server 2007 SP1 do not properly interpret Transport Neutral Encapsulation (TNEF) properties, which allows remote attackers to execute arbitrary code via a crafted TNEF message, aka "Memory Corruption Vulnerability."
network
microsoft CWE-399
critical
9.3
2009-02-10 CVE-2009-0097 Resource Management Errors vulnerability in Microsoft Visio 2002/2003/2007
Microsoft Office Visio 2002 SP2 and 2003 SP3 does not properly validate memory allocation for Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Memory Corruption Vulnerability."
network
microsoft CWE-399
critical
9.3
2009-02-10 CVE-2009-0096 Resource Management Errors vulnerability in Microsoft Visio 2002/2003/2007
Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 does not properly perform memory copy operations for object data, which allows remote attackers to execute arbitrary code via a crafted Visio document, aka "Memory Corruption Vulnerability."
network
microsoft CWE-399
critical
9.3
2009-02-10 CVE-2009-0095 Resource Management Errors vulnerability in Microsoft Visio 2002/2003/2007
Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 does not properly validate object data in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Memory Validation Vulnerability."
network
microsoft CWE-399
critical
9.3
2009-02-10 CVE-2009-0075 Resource Management Errors vulnerability in Microsoft Internet Explorer 7
Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to CFunctionPointer and the appending of document objects, aka "Uninitialized Memory Corruption Vulnerability."
network
microsoft CWE-399
critical
9.3
2009-02-10 CVE-2008-6107 Resource Management Errors vulnerability in Linux Kernel
The (1) sys32_mremap function in arch/sparc64/kernel/sys_sparc32.c, the (2) sparc_mmap_check function in arch/sparc/kernel/sys_sparc.c, and the (3) sparc64_mmap_check function in arch/sparc64/kernel/sys_sparc.c, in the Linux kernel before 2.6.25.4, omit some virtual-address range (aka span) checks when the mremap MREMAP_FIXED bit is not set, which allows local users to cause a denial of service (panic) via unspecified mremap calls, a related issue to CVE-2008-2137.
local
low complexity
linux CWE-399
4.9