Vulnerabilities > Resource Management Errors

DATE CVE VULNERABILITY TITLE RISK
2008-10-15 CVE-2008-4558 Resource Management Errors vulnerability in Videolan VLC Media Player 0.9.2
Array index error in VLC media player 0.9.2 allows remote attackers to overwrite arbitrary memory and execute arbitrary code via an XSPF playlist file with a negative identifier tag, which passes a signed comparison.
network
videolan CWE-399
6.8
2008-10-14 CVE-2008-4551 Resource Management Errors vulnerability in Strongswan
strongSwan 4.2.6 and earlier allows remote attackers to cause a denial of service (daemon crash) via an IKE_SA_INIT message with a large number of NULL values in a Key Exchange payload, which triggers a NULL pointer dereference for the return value of the mpz_export function in the GNU Multiprecision Library (GMP).
network
low complexity
strongswan CWE-399
5.0
2008-10-14 CVE-2008-4546 Resource Management Errors vulnerability in Adobe Flash Player
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows remote web servers to cause a denial of service (NULL pointer dereference and browser crash) by returning a different response when an HTTP request is sent a second time, as demonstrated by two responses that provide SWF files with different SWF version numbers.
network
adobe CWE-399
4.3
2008-10-13 CVE-2008-4543 Resource Management Errors vulnerability in Cisco Unity
Cisco Unity 4.x before 4.2(1)ES161, 5.x before 5.0(1)ES53, and 7.x before 7.0(2)ES8, when using anonymous authentication (aka native Unity authentication), allows remote attackers to cause a denial of service (session exhaustion) via a large number of connections.
network
cisco CWE-399
7.1
2008-10-10 CVE-2008-3641 Resource Management Errors vulnerability in Apple Cups
The Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via crafted pen width and pen color opcodes that overwrite arbitrary memory.
network
low complexity
apple CWE-399
critical
10.0
2008-10-09 CVE-2008-4510 Resource Management Errors vulnerability in Microsoft Windows Vista
Microsoft Windows Vista Home and Ultimate Edition SP1 and earlier allows local users to cause a denial of service (page fault and system crash) via multiple attempts to access a virtual address in a PAGE_NOACCESS memory page.
local
low complexity
microsoft CWE-399
4.9
2008-10-03 CVE-2008-4409 Resource Management Errors vulnerability in Xmlsoft Libxml2 2.7.0/2.7.1
libxml2 2.7.0 and 2.7.1 does not properly handle "predefined entities definitions" in entities, which allows context-dependent attackers to cause a denial of service (memory consumption and application crash), as demonstrated by use of xmllint on a certain XML document, a different vulnerability than CVE-2003-1564 and CVE-2008-3281.
network
low complexity
xmlsoft CWE-399
5.0
2008-10-03 CVE-2008-4403 Resource Management Errors vulnerability in Trend Micro Officescan 8.0
The CGI modules in the server in Trend Micro OfficeScan 8.0 SP1 before build 2439 and 8.0 SP1 Patch 1 before build 3087 allow remote attackers to cause a denial of service (NULL pointer dereference and child process crash) via crafted HTTP headers, related to the "error handling mechanism."
network
low complexity
trend-micro CWE-399
5.0
2008-10-02 CVE-2008-4382 Resource Management Errors vulnerability in KDE Konqueror 3.5.9
Konqueror in KDE 3.5.9 allows remote attackers to cause a denial of service (application crash) via Javascript that calls the alert function with a URL-encoded string of a large number of invalid characters.
network
low complexity
kde CWE-399
5.0
2008-10-02 CVE-2008-4381 Resource Management Errors vulnerability in Microsoft Internet Explorer 5/6/7
Microsoft Internet Explorer 7 allows remote attackers to cause a denial of service (application crash) via Javascript that calls the alert function with a URL-encoded string of a large number of invalid characters.
network
low complexity
microsoft CWE-399
5.0