CVE-2007-1206
- EPSS 2.12%
- Veröffentlicht 10.04.2007 21:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0; 2000 SP4; XP SP2; Server 2003, 2003 SP1, and 2003 SP2; and Windows Vista before June 2006; uses insecure permissions (PAGE_READWRITE) for a physical memory view, which a...
CVE-2006-5586
- EPSS 1.3%
- Veröffentlicht 04.04.2007 16:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Graphics Rendering Engine in Microsoft Windows 2000 SP4 and XP SP2 allows local users to gain privileges via "invalid application window sizes" in layered application windows, aka the "GDI Invalid Window Size Elevation of Privilege Vulnerability....
CVE-2007-1211
- EPSS 75.74%
- Veröffentlicht 04.04.2007 16:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified kernel GDI functions in Microsoft Windows 2000 SP4; XP SP2; and Server 2003 Gold, SP1, and SP2 allows user-assisted remote attackers to cause a denial of service (possibly persistent restart) via a crafted Windows Metafile (WMF) image tha...
CVE-2007-1212
- EPSS 2.14%
- Veröffentlicht 04.04.2007 16:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4; XP SP2; Server 2003 Gold, SP1, and SP2; and Vista allows local users to gain privileges via a crafted Enhanced Metafile (EMF) image format file.
CVE-2007-1213
- EPSS 1.61%
- Veröffentlicht 04.04.2007 16:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The TrueType Fonts rasterizer in Microsoft Windows 2000 SP4 allows local users to gain privileges via crafted TrueType fonts, which result in an uninitialized function pointer.
CVE-2007-1215
- EPSS 2.74%
- Veröffentlicht 04.04.2007 16:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4; XP SP2; Server 2003 Gold, SP1, and SP2; and Vista allows local users to gain privileges via certain "color-related parameters" in crafted images.
CVE-2007-0038
- EPSS 88.34%
- Veröffentlicht 30.03.2007 20:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a large length value in the second (or later) a...
CVE-2007-1765
- EPSS 59.33%
- Veröffentlicht 30.03.2007 00:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malformed ANI file, which results in memory corruption when processing curs...
CVE-2007-1692
- EPSS 32.54%
- Veröffentlicht 26.03.2007 23:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The default configuration of Microsoft Windows uses the Web Proxy Autodiscovery Protocol (WPAD) without static WPAD entries, which might allow remote attackers to intercept web traffic by registering a proxy server using WINS or DNS, then responding ...
CVE-2007-0843
- EPSS 0.39%
- Veröffentlicht 23.02.2007 02:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The ReadDirectoryChangesW API function on Microsoft Windows 2000, XP, Server 2003, and Vista does not check permissions for child objects, which allows local users to bypass permissions by opening a directory with LIST (READ) access and using ReadDir...