Vulnerabilities > Resource Management Errors

DATE CVE VULNERABILITY TITLE RISK
2008-07-16 CVE-2008-3196 Resource Management Errors vulnerability in Yacc
skeleton.c in yacc does not properly handle reduction of a rule with an empty right hand side, which allows context-dependent attackers to cause an out-of-bounds stack access when the yacc stack pointer points to the end of the stack.
network
low complexity
yacc CWE-399
7.8
2008-07-14 CVE-2008-2317 Resource Management Errors vulnerability in Apple Safari
WebCore in Apple Safari does not properly perform garbage collection of JavaScript document elements, which allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption and application crash) via a reference to the ownerNode property of a copied CSSStyleSheet object of a STYLE element, as originally demonstrated on Apple iPhone before 2.0 and iPod touch before 2.0, a different vulnerability than CVE-2008-1590.
network
apple CWE-399
critical
9.3
2008-07-14 CVE-2008-1590 Resource Management Errors vulnerability in Webkit Javascriptcore
JavaScriptCore in WebKit on Apple iPhone before 2.0 and iPod touch before 2.0 does not properly perform runtime garbage collection, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors that trigger memory corruption, a different vulnerability than CVE-2008-2317.
network
webkit CWE-399
6.8
2008-07-11 CVE-2008-3157 Resource Management Errors vulnerability in Nortel SIP Multimedia PC Client 4.0
Nortel SIP Multimedia PC Client 4.x MCS5100 and MCS5200 does not limit the number of concurrent sessions, which allows attackers to cause a denial of service (resource consumption) via a large number of sessions.
network
low complexity
nortel CWE-399
5.0
2008-07-10 CVE-2008-3134 Resource Management Errors vulnerability in Graphicsmagick
Multiple unspecified vulnerabilities in GraphicsMagick before 1.2.4 allow remote attackers to cause a denial of service (crash, infinite loop, or memory consumption) via (a) unspecified vectors in the (1) AVI, (2) AVS, (3) DCM, (4) EPT, (5) FITS, (6) MTV, (7) PALM, (8) RLA, and (9) TGA decoder readers; and (b) the GetImageCharacteristics function in magick/image.c, as reachable from a crafted (10) PNG, (11) JPEG, (12) BMP, or (13) TIFF file.
network
low complexity
graphicsmagick CWE-399
5.0
2008-07-09 CVE-2008-2244 Resource Management Errors vulnerability in Microsoft Office Word 2002
Microsoft Office Word 2002 SP3 allows remote attackers to execute arbitrary code via a .doc file that contains malformed data, as exploited in the wild in July 2008, and as demonstrated by attachement.doc.
network
microsoft CWE-399
critical
9.3
2008-07-07 CVE-2008-2811 Resource Management Errors vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
The block reflow implementation in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image whose display requires more pixels than nscoord_MAX, related to nsBlockFrame::DrainOverflowLines.
network
low complexity
mozilla CWE-399
critical
10.0
2008-07-07 CVE-2008-2799 Resource Management Errors vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via unknown vectors related to the JavaScript engine.
network
low complexity
mozilla CWE-399
critical
10.0
2008-07-07 CVE-2008-2798 Resource Management Errors vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via unknown vectors related to the layout engine.
network
low complexity
mozilla CWE-399
critical
10.0
2008-07-07 CVE-2008-3052 Resource Management Errors vulnerability in Typo3 SQL Frontend Extension
Unspecified vulnerability in the SQL Frontend (mh_omsqlio) extension 1.0.11 and earlier for TYPO3 allows remote attackers to cause a denial of service via unknown vectors.
network
low complexity
typo3 CWE-399
7.5