Vulnerabilities > Resource Management Errors

DATE CVE VULNERABILITY TITLE RISK
2008-01-08 CVE-2008-0095 Resource Management Errors vulnerability in Asterisk products
The SIP channel driver in Asterisk Open Source 1.4.x before 1.4.17, Business Edition before C.1.0-beta8, AsteriskNOW before beta7, Appliance Developer Kit before Asterisk 1.4 revision 95946, and Appliance s800i 1.0.x before 1.0.3.4 allows remote attackers to cause a denial of service (daemon crash) via a BYE message with an Also (Also transfer) header, which triggers a NULL pointer dereference.
network
low complexity
asterisk CWE-399
5.0
2007-12-24 CVE-2007-6523 Resource Management Errors vulnerability in Opera Browser
Algorithmic complexity vulnerability in Opera 9.50 beta and 9.x before 9.25 allows remote attackers to cause a denial of service (CPU consumption) via a crafted bitmap (BMP) file that triggers a large number of calculations and checks.
network
low complexity
opera CWE-399
7.8
2007-12-20 CVE-2007-6349 Resource Management Errors vulnerability in Perforce P4Web 2006.1/2006.2
P4Webs.exe in Perforce P4Web 2006.2 and earlier, when running on Windows, allows remote attackers to cause a denial of service (CPU consumption) via an HTTP request with an empty body and a Content-Length greater than 0.
network
low complexity
perforce CWE-399
7.8
2007-12-19 CVE-2007-6451 Resource Management Errors vulnerability in Wireshark
Unspecified vulnerability in the CIP dissector in Wireshark (formerly Ethereal) 0.9.14 to 0.99.6 allows remote attackers to cause a denial of service (crash) via unknown vectors that trigger allocation of large amounts of memory.
network
wireshark CWE-399
4.3
2007-12-19 CVE-2007-5861 Resource Management Errors vulnerability in Apple mac OS X 10.4.11
Unspecified vulnerability in Spotlight in Apple Mac OS X 10.4.11 allows user-assisted attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted .XLS file that triggers memory corruption in the Microsoft Office Spotlight Importer.
network
apple CWE-399
6.8
2007-12-19 CVE-2007-5859 Resource Management Errors vulnerability in Apple Safari
Unspecified vulnerability in Safari RSS in Apple Mac OS X 10.4.11 allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted feed: URL that triggers memory corruption.
network
apple CWE-399
critical
9.3
2007-12-19 CVE-2007-4710 Resource Management Errors vulnerability in Apple mac OS X 10.4.11
Unspecified vulnerability in ColorSync in Apple Mac OS X 10.4.11 allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via an image with a crafted ColorSync profile, which triggers memory corruption.
network
apple CWE-399
critical
9.3
2007-12-18 CVE-2007-6356 Resource Management Errors vulnerability in Aertherwide Exiftags
exiftags before 1.01 allows attackers to cause a denial of service (infinite loop) via recursive IFD references in the EXIF data in a JPEG image.
network
low complexity
aertherwide CWE-399
5.0
2007-12-18 CVE-2007-6417 Resource Management Errors vulnerability in Linux Kernel
The shmem_getpage function (mm/shmem.c) in Linux kernel 2.6.11 through 2.6.23 does not properly clear allocated memory in some rare circumstances related to tmpfs, which might allow local users to read sensitive kernel data or cause a denial of service (crash).
local
low complexity
linux CWE-399
7.2
2007-12-12 CVE-2007-3902 Resource Management Errors vulnerability in Microsoft IE and Internet Explorer
Use-after-free vulnerability in the CRecalcProperty function in mshtml.dll in Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code by calling the setExpression method and then modifying the outerHTML property of an HTML element, one variant of "Uninitialized Memory Corruption Vulnerability."
network
microsoft CWE-399
critical
9.3