Vulnerabilities > Resource Management Errors

DATE CVE VULNERABILITY TITLE RISK
2006-03-19 CVE-2006-1275 Resource Management Errors vulnerability in GGZ Gaming Zone GGZ Gaming Zone 0.0.12
GGZ Gaming Zone 0.0.12 allows remote attackers to cause a denial of service (client disconnect) via inputs that produce malformed XML, including (1) trailing ' (apostrophe) character on the ID attribute in a PLAYER XML tag, (2) joining with a long ID attribute or non-trailing ' characters, which causes a <none> name to be assigned, and then disconnecting, or (3) a long CDATA message attribute, which prevents closing tags from being added to the string.
network
low complexity
ggz-gaming-zone CWE-399
5.0
2006-03-07 CVE-2006-0047 Resource Management Errors vulnerability in Freeciv
packets.c in Freeciv 2.0 before 2.0.8 allows remote attackers to cause a denial of service (server crash) via crafted packets with negative compressed size values.
network
low complexity
freeciv CWE-399
5.0
2006-03-07 CVE-2006-0883 Resource Management Errors vulnerability in multiple products
OpenSSH on FreeBSD 5.3 and 5.4, when used with OpenPAM, does not properly handle when a forked child process terminates during PAM authentication, which allows remote attackers to cause a denial of service (client connection refusal) by connecting multiple times to the SSH server, waiting for the password prompt, then disconnecting.
network
low complexity
openbsd freebsd CWE-399
5.0
2006-03-02 CVE-2006-0967 Resource Management Errors vulnerability in NCP Network Communications Secure Client 8.11Build146
NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to cause a denial of service (memory usage and cpu utilization) via a flood of arbitrary UDP datagrams to ports 0 to 65000.
local
low complexity
ncp-network-communications CWE-399
2.1
2006-03-02 CVE-2006-0966 Resource Management Errors vulnerability in NCP Network Communications Secure Client 8.11Build146
NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to cause a denial of service (CPU consumption) via a large number of arguments to ncprwsnt.exe, possibly due to a buffer overflow.
local
low complexity
ncp-network-communications CWE-399
2.1
2006-02-28 CVE-2006-0911 Resource Management Errors vulnerability in Ipswitch Whatsup Professional2006
NmService.exe in Ipswitch WhatsUp Professional 2006 allows remote attackers to cause a denial of service (CPU consumption) via crafted requests to Login.asp, possibly involving the (1) "In]" and (2) "b;tnLogIn" parameters, or (3) malformed btnLogIn parameters, possibly involving missing "[" (open bracket) or "[" (closing bracket) characters, as demonstrated by "&btnLogIn=[Log&In]=&" or "&b;tnLogIn=[Log&In]=&" in the URL.
network
low complexity
ipswitch CWE-399
5.0
2006-02-09 CVE-2006-0622 Resource Management Errors vulnerability in QNX Rtos 6.3.0
QNX Neutrino RTOS 6.3.0 allows local users to cause a denial of service (hang) by supplying a "break *0xb032d59f" command to gdb.
local
low complexity
qnx CWE-399
4.9
2006-02-07 CVE-2006-0454 Resource Management Errors vulnerability in Linux Kernel
Linux kernel before 2.6.15.3 down to 2.6.12, while constructing an ICMP response in icmp_send, does not properly handle when the ip_options_echo function in icmp.c fails, which allows remote attackers to cause a denial of service (crash) via vectors such as (1) record-route and (2) timestamp IP options with the needaddr bit set and a truncated value.
network
low complexity
linux CWE-399
5.0
2006-01-22 CVE-2006-0354 Resource Management Errors vulnerability in Cisco products
Cisco IOS before 12.3-7-JA2 on Aironet Wireless Access Points (WAP) allows remote authenticated users to cause a denial of service (termination of packet passing or termination of client connections) by sending the management interface a large number of spoofed ARP packets, which creates a large ARP table that exhausts memory, aka Bug ID CSCsc16644.
low complexity
cisco CWE-399
5.5
2006-01-21 CVE-2006-0342 Resource Management Errors vulnerability in Rockliffe Mailsite 7.0.3.1
RockLiffe MailSite HTTP Mail management agent (httpma) 7.0.3.1 allows remote attackers to cause a denial of service (CPU consumption and crash) via a malformed query string containing special characters such as "|".
network
low complexity
rockliffe CWE-399
7.8