Vulnerabilities > Resource Management Errors

DATE CVE VULNERABILITY TITLE RISK
2008-03-24 CVE-2008-1471 Resource Management Errors vulnerability in Panda products
The cpoint.sys driver in Panda Internet Security 2008 and Antivirus+ Firewall 2008 allows local users to cause a denial of service (system crash or kernel panic), overwrite memory, or execute arbitrary code via a crafted IOCTL request that triggers an out-of-bounds write of kernel memory.
local
low complexity
microsoft panda CWE-399
7.2
2008-03-20 CVE-2008-1402 Resource Management Errors vulnerability in Mg-Soft NET Inspector
MG-SOFT Net Inspector 6.5.0.828 and earlier for Windows allows remote attackers to cause a (1) denial of service (exception and crash) via a UDP packet to the SNMP Trap Service (MgWTrap3.exe) or (2) denial of service (device freeze or memory consumption) via a malformed request to the Net Inspector Server (niengine).
7.1
2008-03-20 CVE-2008-1364 Resource Management Errors vulnerability in VMWare products
Unspecified vulnerability in the DHCP service in VMware Workstation 5.5.x before 5.5.6, VMware Player 1.0.x before 1.0.6, VMware ACE 1.0.x before 1.0.5, VMware Server 1.0.x before 1.0.5, and VMware Fusion 1.1.x before 1.1.1 allows attackers to cause a denial of service.
network
low complexity
vmware CWE-399
7.8
2008-03-20 CVE-2008-1340 Resource Management Errors vulnerability in VMWare products
Virtual Machine Communication Interface (VMCI) in VMware Workstation 6.0.x before 6.0.3, VMware Player 2.0.x before 2.0.3, and VMware ACE 2.0.x before 2.0.1 allows attackers to cause a denial of service (host OS crash) via crafted VMCI calls that trigger "memory exhaustion and memory corruption."
network
vmware CWE-399
7.1
2008-03-12 CVE-2008-1309 Resource Management Errors vulnerability in Realnetworks Realplayer 10.0/10.5/11
The RealAudioObjects.RealAudio ActiveX control in rmoc3260.dll in RealNetworks RealPlayer Enterprise, RealPlayer 10, RealPlayer 10.5 before build 6.0.12.1675, and RealPlayer 11 before 11.0.3 build 6.0.14.806 does not properly manage memory for the (1) Console or (2) Controls property, which allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via a series of assignments of long string values, which triggers an overwrite of freed heap memory.
network
realnetworks CWE-399
critical
9.3
2008-03-05 CVE-2008-1097 Resource Management Errors vulnerability in Imagemagick Graphicsmagick and Imagemagick
Heap-based buffer overflow in the ReadPCXImage function in the PCX coder in coders/pcx.c in (1) ImageMagick 6.2.4-5 and 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted .pcx file that triggers incorrect memory allocation for the scanline array, leading to memory corruption.
6.8
2008-03-04 CVE-2008-1141 Resource Management Errors vulnerability in Deslock
Memory leak in DLMFENC.sys 1.0.0.26 in DESlock+ 3.2.6 and earlier allows local users to cause a denial of service (kernel memory consumption) via a series of DLMFENC_IOCTL requests to \\.\DLKPFSD_Device that allocate "link list structures."
local
low complexity
deslock CWE-399
4.9
2008-02-28 CVE-2008-1071 Resource Management Errors vulnerability in Wireshark
The SNMP dissector in Wireshark (formerly Ethereal) 0.99.6 through 0.99.7 allows remote attackers to cause a denial of service (crash) via a malformed packet.
network
wireshark CWE-399
4.3
2008-02-28 CVE-2008-0308 Resource Management Errors vulnerability in Symantec products
Symantec Decomposer, as used in certain Symantec antivirus products including Symantec Scan Engine 5.1.2 and other versions before 5.1.6.31, allows remote attackers to cause a denial of service (memory consumption) via a malformed RAR file to the Internet Content Adaptation Protocol (ICAP) port (1344/tcp).
network
symantec CWE-399
7.1
2008-02-26 CVE-2008-0984 Resource Management Errors vulnerability in multiple products
The MP4 demuxer (mp4.c) for VLC media player 0.8.6d and earlier, as used in Miro Player 1.1 and earlier, allows remote attackers to overwrite arbitrary memory and execute arbitrary code via a malformed MP4 file.
network
miro videolan CWE-399
critical
9.3