Vulnerabilities > Resource Management Errors

DATE CVE VULNERABILITY TITLE RISK
2013-09-18 CVE-2013-3893 Resource Management Errors vulnerability in Microsoft Internet Explorer
Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript strings, as demonstrated by use of an ms-help: URL that triggers loading of hxds.dll.
network
microsoft CWE-399
critical
9.3
2013-09-18 CVE-2013-1738 Resource Management Errors vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
Use-after-free vulnerability in the JS_GetGlobalForScopeChain function in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code by leveraging incorrect garbage collection in situations involving default compartments and frame-chain restoration.
network
mozilla CWE-399
critical
9.3
2013-09-18 CVE-2013-1724 Resource Management Errors vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
Use-after-free vulnerability in the mozilla::dom::HTMLFormElement::IsDefaultSubmitElement function in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving a destroyed SELECT element.
network
mozilla CWE-399
critical
9.3
2013-09-18 CVE-2013-1722 Resource Management Errors vulnerability in Mozilla products
Use-after-free vulnerability in the nsAnimationManager::BuildAnimations function in the Animation Manager in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving stylesheet cloning.
network
mozilla CWE-399
critical
9.3
2013-09-17 CVE-2012-4067 Resource Management Errors vulnerability in Eucalyptus
Walrus in Eucalyptus before 3.2.2 allows remote attackers to cause a denial of service (memory, thread, and CPU consumption) via a crafted XML message containing a DTD, as demonstrated by a bucket-logging request.
4.3
2013-09-16 CVE-2013-5719 Resource Management Errors vulnerability in Wireshark
epan/dissectors/packet-assa_r3.c in the ASSA R3 dissector in Wireshark 1.8.x before 1.8.10 and 1.10.x before 1.10.2 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.
network
wireshark CWE-399
4.3
2013-09-11 CVE-2013-3870 Resource Management Errors vulnerability in Microsoft Outlook 2007/2010
Double free vulnerability in Microsoft Outlook 2007 SP3 and 2010 SP1 and SP2 allows remote attackers to execute arbitrary code by including many nested S/MIME certificates in an e-mail message, aka "Message Certificate Vulnerability."
network
microsoft CWE-399
critical
9.3
2013-09-11 CVE-2013-3862 Resource Management Errors vulnerability in Microsoft Windows 7 and Windows Server 2008
Double free vulnerability in Microsoft Windows 7 and Server 2008 R2 SP1 allows local users to gain privileges via a crafted service description that is not properly handled by services.exe in the Service Control Manager (SCM), aka "Service Control Manager Double Free Vulnerability."
6.9
2013-08-30 CVE-2013-3467 Resource Management Errors vulnerability in Cisco products
Memory leak in the CLI component on Cisco Unified Computing System (UCS) 6100 Fabric Interconnect devices, in certain situations that lack a SPAN session, allows local users to cause a denial of service (memory consumption and device reset) via a (1) "show monitor session all" or (2) "show monitor session" command, aka Bug ID CSCug20103.
local
low complexity
cisco CWE-399
4.6
2013-08-28 CVE-2013-2176 Resource Management Errors vulnerability in Redhat Enterprise Virtualization 3.0/3.2
Unquoted Windows search path vulnerability in the Red Hat Enterprise Virtualization Application Provisioning Tool (RHEV-APT) in the rhev-guest-tools-iso package 3.2 allows local users to gain privileges via a Trojan horse application.
local
low complexity
redhat CWE-399
7.2