Vulnerabilities > Resource Management Errors

DATE CVE VULNERABILITY TITLE RISK
2008-08-29 CVE-2008-3283 Resource Management Errors vulnerability in multiple products
Multiple memory leaks in Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fedora Directory Server 1.1.1 and earlier allow remote attackers to cause a denial of service (memory consumption) via vectors involving (1) the authentication / bind phase and (2) anonymous LDAP search requests.
network
low complexity
fedora redhat CWE-399
7.8
2008-08-29 CVE-2008-2930 Resource Management Errors vulnerability in multiple products
Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fedora Directory Server 1.1.1 allow remote attackers to cause a denial of service (CPU consumption and search outage) via crafted LDAP search requests with patterns, related to a single-threaded regular-expression subsystem.
7.1
2008-08-14 CVE-2008-3443 Resource Management Errors vulnerability in Ruby-Lang Ruby
The regular expression engine (regex.c) in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows remote attackers to cause a denial of service (infinite loop and crash) via multiple long requests to a Ruby socket, related to memory allocation failure, and as demonstrated against Webrick.
network
low complexity
ruby-lang CWE-399
5.0
2008-08-13 CVE-2008-2258 Resource Management Errors vulnerability in Microsoft Internet Explorer 5.01/6/7
Microsoft Internet Explorer 5.01, 6, and 7 accesses uninitialized memory in certain conditions, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via vectors related to a document object "appended in a specific order" with "particular functions ...
network
microsoft CWE-399
critical
9.3
2008-08-13 CVE-2008-2257 Resource Management Errors vulnerability in Microsoft Internet Explorer 5.01/6/7
Microsoft Internet Explorer 5.01, 6, and 7 accesses uninitialized memory in certain conditions, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via vectors related to a document object "appended in a specific order," aka "HTML Objects Memory Corruption Vulnerability" or "XHTML Rendering Memory Corruption Vulnerability," a different vulnerability than CVE-2008-2258.
network
microsoft CWE-399
critical
9.3
2008-08-13 CVE-2008-2255 Resource Management Errors vulnerability in Microsoft Internet Explorer 5.01/6/7
Microsoft Internet Explorer 5.01, 6, and 7 accesses uninitialized memory, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors, a different vulnerability than CVE-2008-2254, aka "HTML Object Memory Corruption Vulnerability."
network
microsoft CWE-399
critical
9.3
2008-08-13 CVE-2008-2254 Resource Management Errors vulnerability in Microsoft Internet Explorer 6/7
Microsoft Internet Explorer 6 and 7 accesses uninitialized memory, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors, aka "HTML Object Memory Corruption Vulnerability."
network
microsoft CWE-399
critical
9.3
2008-08-13 CVE-2008-3656 Resource Management Errors vulnerability in Ruby-Lang Ruby
Algorithmic complexity vulnerability in the WEBrick::HTTPUtils.split_header_value function in WEBrick::HTTP::DefaultFileHandler in WEBrick in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted HTTP request that is processed by a backtracking regular expression.
network
low complexity
ruby-lang CWE-399
7.8
2008-08-13 CVE-2008-1455 Resource Management Errors vulnerability in Microsoft products
A "memory calculation error" in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, 2003 SP2, and 2007 through SP1; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 through SP1; and Office 2004 for Mac allows remote attackers to execute arbitrary code via a PowerPoint file with crafted list values that trigger memory corruption, aka "Parsing Overflow Vulnerability."
network
microsoft CWE-399
6.8
2008-08-13 CVE-2008-0121 Resource Management Errors vulnerability in Microsoft Office Powerpoint Viewer 2003
A "memory calculation error" in Microsoft PowerPoint Viewer 2003 allows remote attackers to execute arbitrary code via a PowerPoint file with an invalid picture index that triggers memory corruption, aka "Memory Calculation Vulnerability."
network
microsoft CWE-399
critical
9.3