Vulnerabilities > Resource Management Errors

DATE CVE VULNERABILITY TITLE RISK
2014-02-24 CVE-2013-6655 Resource Management Errors vulnerability in Google Chrome
Use-after-free vulnerability in Blink, as used in Google Chrome before 33.0.1750.117, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to improper handling of overflowchanged DOM events during interaction between JavaScript and layout.
network
low complexity
google CWE-399
7.5
2014-02-24 CVE-2013-6653 Resource Management Errors vulnerability in Google Chrome
Use-after-free vulnerability in the web contents implementation in Google Chrome before 33.0.1750.117 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving attempted conflicting access to the color chooser.
network
low complexity
google CWE-399
7.5
2014-02-18 CVE-2014-0625 Resource Management Errors vulnerability in multiple products
The SSLSocket implementation in the (1) JSAFE and (2) JSSE APIs in EMC RSA BSAFE SSL-J 5.x before 5.1.3 and 6.x before 6.0.2 allows remote attackers to cause a denial of service (memory consumption) by triggering application-data processing during the TLS handshake, a time at which the data is internally buffered.
network
low complexity
emc dell CWE-399
5.0
2014-02-14 CVE-2014-1950 Resource Management Errors vulnerability in XEN
Use-after-free vulnerability in the xc_cpupool_getinfo function in Xen 4.1.x through 4.3.x, when using a multithreaded toolstack, does not properly handle a failure by the xc_cpumap_alloc function, which allows local users with access to management functions to cause a denial of service (heap corruption) and possibly gain privileges via unspecified vectors.
local
low complexity
xen CWE-399
4.6
2014-02-08 CVE-2014-1916 Resource Management Errors vulnerability in Light Speed Gaming Mumble and Mumblekit
The (1) opus_packet_get_nb_frames and (2) opus_packet_get_samples_per_frame functions in the client in MumbleKit before commit fd190328a9b24d37382b269a5674b0c0c7a7e36d and Mumble for iOS 1.1 through 1.2.2 do not properly check the return value of the copyDataBlock method, which allow remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted length prefix value in an Opus voice packet.
network
low complexity
light-speed-gaming CWE-399
5.0
2014-02-07 CVE-2014-1699 Resource Management Errors vulnerability in Siemens Simatic Wincc Open Architecture
Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote attackers to cause a denial of service (monitoring-service outage) via malformed HTTP requests to port 4999.
network
low complexity
siemens CWE-399
5.0
2014-02-06 CVE-2013-6479 Resource Management Errors vulnerability in Pidgin
util.c in libpurple in Pidgin before 2.10.8 does not properly allocate memory for HTTP responses that are inconsistent with the Content-Length header, which allows remote HTTP servers to cause a denial of service (application crash) via a crafted response.
network
low complexity
pidgin CWE-399
5.0
2014-01-31 CVE-2014-0757 Resource Management Errors vulnerability in 3S-Software Codesys Runtime Toolkit
Smart Software Solutions (3S) CoDeSys Runtime Toolkit before 2.4.7.44 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors.
network
low complexity
3s-software CWE-399
5.0
2014-01-28 CVE-2013-6649 Resource Management Errors vulnerability in Google Chrome
Use-after-free vulnerability in the RenderSVGImage::paint function in core/rendering/svg/RenderSVGImage.cpp in Blink, as used in Google Chrome before 32.0.1700.102, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a zero-size SVG image.
network
low complexity
google debian opensuse CWE-399
7.5
2014-01-26 CVE-2013-7298 Resource Management Errors vulnerability in Tntnet Cxxtools 2.2
query_params.cpp in cxxtools before 2.2.1 allows remote attackers to cause a denial of service (infinite recursion and crash) via an HTTP query that contains %% (double percent) characters.
network
low complexity
tntnet CWE-399
5.0