Vulnerabilities > Resource Management Errors

DATE CVE VULNERABILITY TITLE RISK
2007-12-19 CVE-2007-4710 Resource Management Errors vulnerability in Apple mac OS X 10.4.11
Unspecified vulnerability in ColorSync in Apple Mac OS X 10.4.11 allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via an image with a crafted ColorSync profile, which triggers memory corruption.
network
apple CWE-399
critical
9.3
2007-12-18 CVE-2007-6356 Resource Management Errors vulnerability in Aertherwide Exiftags
exiftags before 1.01 allows attackers to cause a denial of service (infinite loop) via recursive IFD references in the EXIF data in a JPEG image.
network
low complexity
aertherwide CWE-399
5.0
2007-12-18 CVE-2007-6417 Resource Management Errors vulnerability in Linux Kernel
The shmem_getpage function (mm/shmem.c) in Linux kernel 2.6.11 through 2.6.23 does not properly clear allocated memory in some rare circumstances related to tmpfs, which might allow local users to read sensitive kernel data or cause a denial of service (crash).
local
low complexity
linux CWE-399
7.2
2007-12-12 CVE-2007-3902 Resource Management Errors vulnerability in Microsoft IE and Internet Explorer
Use-after-free vulnerability in the CRecalcProperty function in mshtml.dll in Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code by calling the setExpression method and then modifying the outerHTML property of an HTML element, one variant of "Uninitialized Memory Corruption Vulnerability."
network
microsoft CWE-399
critical
9.3
2007-12-07 CVE-2007-6279 Resource Management Errors vulnerability in Flac Libflac
Multiple double free vulnerabilities in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allow user-assisted remote attackers to execute arbitrary code via malformed (1) Seektable values or (2) Seektable Data Offsets in a .FLAC file.
network
flac CWE-399
critical
9.3
2007-12-06 CVE-2007-5971 Resource Management Errors vulnerability in MIT Kerberos 5
Double free vulnerability in the gss_krb5int_make_seal_token_v3 function in lib/gssapi/krb5/k5sealv3.c in MIT Kerberos 5 (krb5) has unknown impact and attack vectors.
local
apple mit CWE-399
6.9
2007-12-06 CVE-2007-5901 Resource Management Errors vulnerability in MIT Kerberos 5
Use-after-free vulnerability in the gss_indicate_mechs function in lib/gssapi/mechglue/g_initialize.c in MIT Kerberos 5 (krb5) has unknown impact and attack vectors.
local
apple mit CWE-399
6.9
2007-11-30 CVE-2007-5494 Resource Management Errors vulnerability in Redhat Enterprise Linux 4.0/5.0
Memory leak in the Red Hat Content Accelerator kernel patch in Red Hat Enterprise Linux (RHEL) 4 and 5 allows local users to cause a denial of service (memory consumption) via a large number of open requests involving O_ATOMICLOOKUP.
local
low complexity
redhat CWE-399
4.9
2007-11-29 CVE-2007-4346 Resource Management Errors vulnerability in Symantec Backupexec System Recovery 11.0.6235/11.0.7170
The Job Engine (bengine.exe) service in Symantec Backup Exec for Windows Servers (BEWS) 11d build 11.0.7170 and 11.0.6.6235 allows remote attackers to cause a denial of service (NULL dereference and service crash) via a crafted packet to port 5633/tcp.
network
low complexity
symantec CWE-399
5.0
2007-11-21 CVE-2007-5612 Resource Management Errors vulnerability in IBM Director
CIM Server in IBM Director 5.20.1 and earlier allows remote attackers to cause a denial of service (CPU consumption, connection slot exhaustion, and daemon crash) via a large number of idle connections.
network
low complexity
ibm CWE-399
7.8