Vulnerabilities > Resource Management Errors

DATE CVE VULNERABILITY TITLE RISK
2014-08-12 CVE-2014-0316 Resource Management Errors vulnerability in Microsoft products
Memory leak in the Local RPC (LRPC) server implementation in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to cause a denial of service (memory consumption) and bypass the ASLR protection mechanism via a crafted client that sends messages with an invalid data view, aka "LRPC ASLR Bypass Vulnerability."
network
low complexity
microsoft CWE-399
7.5
2014-07-01 CVE-2014-1354 Resource Management Errors vulnerability in Apple Iphone OS
CoreGraphics in Apple iOS before 7.1.2 does not properly restrict allocation of stack memory for processing of XBM images, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted image data.
network
apple CWE-399
6.8
2014-06-14 CVE-2014-2176 Resource Management Errors vulnerability in Cisco products
Cisco IOS XR 4.1.2 through 5.1.1 on ASR 9000 devices, when a Trident-based line card is used, allows remote attackers to cause a denial of service (NP chip and line card reload) via malformed IPv6 packets, aka Bug ID CSCun71928.
network
cisco CWE-399
7.1
2014-06-11 CVE-2014-1811 Resource Management Errors vulnerability in Microsoft products
The TCP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to cause a denial of service (non-paged pool memory consumption and system hang) via malformed data in the Options field of a TCP header, aka "TCP Denial of Service Vulnerability."
network
low complexity
microsoft CWE-399
5.0
2014-06-09 CVE-2013-4599 Resource Management Errors vulnerability in Misery Project Misery
The Misery module 6.x-2.x before 6.x-2.5 and 7.x-2.x before 7.x-2.2 for Drupal, when the "delay misery" configuration is set to a high value, allows remote attackers to cause a denial of service (process consumption) via multiple requests.
4.3
2014-06-09 CVE-2013-2564 Resource Management Errors vulnerability in Mambo-Foundation Mambo CMS 4.6.5
Mambo CMS 4.6.5 allows remote attackers to cause a denial of service (memory and bandwidth consumption) by uploading a crafted file.
network
low complexity
mambo-foundation CWE-399
5.0
2014-05-26 CVE-2014-3276 Resource Management Errors vulnerability in Cisco Identity Services Engine Software
Cisco Identity Services Engine (ISE) 1.2(.1 patch 2) and earlier does not properly handle deadlock conditions during reception of crafted RADIUS accounting packets from multiple NAS devices, which allows remote authenticated users to cause a denial of service (RADIUS outage) by sourcing these packets from two origins, aka Bug ID CSCuo56780.
network
low complexity
cisco CWE-399
4.0
2014-05-22 CVE-2014-1770 Resource Management Errors vulnerability in Microsoft Internet Explorer
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript code that interacts improperly with a CollectGarbage function call on a CMarkup object allocated by the CMarkup::CreateInitialMarkup function.
network
microsoft CWE-399
critical
9.3
2014-05-22 CVE-2014-0949 Resource Management Errors vulnerability in IBM Websphere Portal
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 allows remote attackers to cause a denial of service (resource consumption and daemon crash) via a crafted web request.
network
low complexity
ibm CWE-399
5.0
2014-05-19 CVE-2013-6413 Resource Management Errors vulnerability in Unrealircd 3.2.10/3.2.10.1
Use-after-free vulnerability in UnrealIRCd 3.2.10 before 3.2.10.2 allows remote attackers to cause a denial of service (crash) via unspecified vectors.
network
low complexity
unrealircd CWE-399
5.0