Vulnerabilities > Resource Management Errors

DATE CVE VULNERABILITY TITLE RISK
2009-01-20 CVE-2009-0177 Resource Management Errors vulnerability in VMWare products
vmwarebase.dll, as used in the vmware-authd service (aka vmware-authd.exe), in VMware Workstation 6.5.1 build 126130, 6.5.1 and earlier; VMware Player 2.5.1 build 126130, 2.5.1 and earlier; VMware ACE 2.5.1 and earlier; VMware Server 2.0.x before 2.0.1 build 156745; and VMware Fusion before 2.0.2 build 147997 allows remote attackers to cause a denial of service (daemon crash) via a long (1) USER or (2) PASS command.
network
low complexity
vmware CWE-399
5.0
2009-01-08 CVE-2009-0071 Resource Management Errors vulnerability in Mozilla Firefox
Mozilla Firefox 3.0.5 and earlier 3.0.x versions, when designMode is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a certain (a) replaceChild or (b) removeChild call, followed by a (1) queryCommandValue, (2) queryCommandState, or (3) queryCommandIndeterm call.
network
high complexity
mozilla CWE-399
2.6
2009-01-07 CVE-2009-0069 Resource Management Errors vulnerability in SUN Opensolaris and Solaris
Unspecified vulnerability in the nfs4rename_persistent_fh function in the NFS 4 (aka NFSv4) client in the kernel in Sun Solaris 10 and OpenSolaris before snv_102 allows local users to cause a denial of service (recursive mutex_enter and panic) via unspecified vectors.
local
low complexity
sun CWE-399
4.9
2009-01-02 CVE-2008-5822 Resource Management Errors vulnerability in Mozilla Libxul
Memory leak in Libxul, as used in Mozilla Firefox 3.0.5 and other products, allows remote attackers to cause a denial of service (memory consumption and browser hang) via a long CLASS attribute in an HR element in an HTML document.
network
low complexity
mozilla CWE-399
5.0
2009-01-02 CVE-2008-5821 Resource Management Errors vulnerability in Apple Safari 3.2
Memory leak in WebKit.dll in WebKit, as used by Apple Safari 3.2 on Windows Vista SP1, allows remote attackers to cause a denial of service (memory consumption and browser crash) via a long ALINK attribute in a BODY element in an HTML document.
network
low complexity
apple microsoft CWE-399
5.0
2008-12-29 CVE-2008-5747 Resource Management Errors vulnerability in F-Prot Antivirus 4.6.8
F-Prot 4.6.8 for GNU/Linux allows remote attackers to bypass anti-virus protection via a crafted ELF program with a "corrupted" header that still allows the program to be executed.
network
low complexity
f-prot CWE-399
5.0
2008-12-26 CVE-2008-5731 Resource Management Errors vulnerability in PGP Desktop 9.0.6/9.9.0
The PGPwded device driver (aka PGPwded.sys) in PGP Corporation PGP Desktop 9.0.6 build 6060 and 9.9.0 build 397 allows local users to cause a denial of service (system crash) and possibly gain privileges via a certain METHOD_BUFFERED IOCTL request that overwrites portions of memory, related to a "Driver Collapse." NOTE: some of these details are obtained from third party information.
local
low complexity
pgp CWE-399
4.9
2008-12-24 CVE-2008-2382 Resource Management Errors vulnerability in multiple products
The protocol_client_msg function in vnc.c in the VNC server in (1) Qemu 0.9.1 and earlier and (2) KVM kvm-79 and earlier allows remote attackers to cause a denial of service (infinite loop) via a certain message.
network
low complexity
qemu kvm-qumranet CWE-399
5.0
2008-12-23 CVE-2008-2435 Resource Management Errors vulnerability in Trend Micro Housecall 6.51.0.1028/6.6.0.1278
Use-after-free vulnerability in the Trend Micro HouseCall ActiveX control 6.51.0.1028 and 6.6.0.1278 in Housecall_ActiveX.dll allows remote attackers to execute arbitrary code via a crafted notifyOnLoadNative callback function.
network
trend-micro CWE-399
critical
9.3
2008-12-22 CVE-2008-5698 Resource Management Errors vulnerability in KDE Konqueror
HTMLTokenizer::scriptHandler in Konqueror in KDE 3.5.9 and 3.5.10 allows remote attackers to cause a denial of service (application crash) via an invalid document.load call that triggers use of a deleted object.
network
kde CWE-399
4.3