Vulnerabilities > Resource Management Errors

DATE CVE VULNERABILITY TITLE RISK
2008-08-13 CVE-2008-2254 Resource Management Errors vulnerability in Microsoft Internet Explorer 6/7
Microsoft Internet Explorer 6 and 7 accesses uninitialized memory, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors, aka "HTML Object Memory Corruption Vulnerability."
network
microsoft CWE-399
critical
9.3
2008-08-13 CVE-2008-3656 Resource Management Errors vulnerability in Ruby-Lang Ruby
Algorithmic complexity vulnerability in the WEBrick::HTTPUtils.split_header_value function in WEBrick::HTTP::DefaultFileHandler in WEBrick in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted HTTP request that is processed by a backtracking regular expression.
network
low complexity
ruby-lang CWE-399
7.8
2008-08-13 CVE-2008-1455 Resource Management Errors vulnerability in Microsoft products
A "memory calculation error" in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, 2003 SP2, and 2007 through SP1; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 through SP1; and Office 2004 for Mac allows remote attackers to execute arbitrary code via a PowerPoint file with crafted list values that trigger memory corruption, aka "Parsing Overflow Vulnerability."
network
microsoft CWE-399
6.8
2008-08-13 CVE-2008-0121 Resource Management Errors vulnerability in Microsoft Office Powerpoint Viewer 2003
A "memory calculation error" in Microsoft PowerPoint Viewer 2003 allows remote attackers to execute arbitrary code via a PowerPoint file with an invalid picture index that triggers memory corruption, aka "Memory Calculation Vulnerability."
network
microsoft CWE-399
critical
9.3
2008-08-13 CVE-2008-0120 Resource Management Errors vulnerability in Microsoft Office Powerpoint Viewer 2003
Integer overflow in Microsoft PowerPoint Viewer 2003 allows remote attackers to execute arbitrary code via a PowerPoint file with a malformed picture index that triggers memory corruption, related to handling of CString objects, aka "Memory Allocation Vulnerability."
network
microsoft CWE-399
critical
9.3
2008-08-12 CVE-2008-3460 Resource Management Errors vulnerability in Microsoft Office, Office Converter Pack and Works
WPGIMP32.FLT in Microsoft Office 2000 SP3, XP SP3, and 2003 SP2; Office Converter Pack; and Works 8 does not properly parse the length of a WordPerfect Graphics (WPG) file, which allows remote attackers to execute arbitrary code via a crafted WPG file, aka the "WPG Image File Heap Corruption Vulnerability."
network
microsoft CWE-399
critical
9.3
2008-08-12 CVE-2008-3021 Resource Management Errors vulnerability in Microsoft Office, Office Converter Pack and Works
Microsoft Office 2000 SP3, XP SP3, and 2003 SP2; Office Converter Pack; and Works 8 do not properly parse the length of a PICT file, which allows remote attackers to execute arbitrary code via a crafted PICT file with an invalid bits_per_pixel field, aka the "PICT Filter Parsing Vulnerability," a different vulnerability than CVE-2008-3018.
network
microsoft CWE-399
critical
9.3
2008-08-12 CVE-2008-3020 Resource Management Errors vulnerability in Microsoft Office, Office Converter Pack and Works
Microsoft Office 2000 SP3 and XP SP3; Office Converter Pack; and Works 8 do not properly parse the length of a BMP file, which allows remote attackers to execute arbitrary code via a crafted BMP file, aka the "Malformed BMP Filter Vulnerability."
network
microsoft CWE-399
critical
9.3
2008-08-12 CVE-2008-3019 Resource Management Errors vulnerability in Microsoft Office, Office Converter Pack and Works
Microsoft Office 2000 SP3, XP SP3, and 2003 SP2; Office Converter Pack; and Works 8 do not properly parse the length of an Encapsulated PostScript (EPS) file, which allows remote attackers to execute arbitrary code via a crafted EPS file, aka the "Malformed EPS Filter Vulnerability."
network
microsoft CWE-399
critical
9.3
2008-08-12 CVE-2008-3006 Resource Management Errors vulnerability in Microsoft products
Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1; Office Excel Viewer 2003 Gold and SP3; Office Excel Viewer; Office Compatibility Pack 2007 Gold and SP1; Office SharePoint Server 2007 Gold and SP1; and Office 2004 and 2008 for Mac do not properly parse Country record values when loading Excel files, which allows remote attackers to execute arbitrary code via a crafted Excel file, aka the "Excel Record Parsing Vulnerability." This vulnerability has multiple attack vectors and CIA impact.
network
microsoft CWE-399
critical
9.3