CVE-2009-0081
- EPSS 66.51%
- Published 10.03.2009 20:30:00
- Last modified 09.04.2025 00:30:58
The graphics device interface (GDI) implementation in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate input received from user mode, which allows remote...
CVE-2009-0243
- EPSS 1.28%
- Published 21.01.2009 20:30:00
- Last modified 09.04.2025 00:30:58
Microsoft Windows does not properly enforce the Autorun and NoDriveTypeAutoRun registry values, which allows physically proximate attackers to execute arbitrary code by (1) inserting CD-ROM media, (2) inserting DVD media, (3) connecting a USB device,...
CVE-1999-1593
- EPSS 3.6%
- Published 15.01.2009 01:30:00
- Last modified 09.04.2025 00:30:58
Windows Internet Naming Service (WINS) allows remote attackers to cause a denial of service (connectivity loss) or steal credentials via a 1Ch registration that causes WINS to change the domain controller to point to a malicious server. NOTE: this p...
- EPSS 73.95%
- Published 14.01.2009 22:30:00
- Last modified 09.04.2025 00:30:58
Buffer overflow in SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside the SMB packets" in an NT Tra...
- EPSS 66.73%
- Published 14.01.2009 22:30:00
- Last modified 09.04.2025 00:30:58
SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside the SMB packets...
CVE-2008-2249
- EPSS 68.72%
- Published 10.12.2008 14:00:00
- Last modified 09.04.2025 00:30:58
Integer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via a malformed header in a crafted WMF file, which triggers a buffe...
CVE-2008-3465
- EPSS 45.75%
- Published 10.12.2008 14:00:00
- Last modified 09.04.2025 00:30:58
Heap-based buffer overflow in an API in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows context-dependent attackers to cause a denial of service or execute arbitrary code via a WM...
CVE-2008-5232
- EPSS 26.14%
- Published 26.11.2008 01:30:00
- Last modified 09.04.2025 00:30:58
Buffer overflow in the CallHTMLHelp method in the Microsoft Windows Media Services ActiveX control in nskey.dll 4.1.00.3917 in Windows Media Services on Microsoft Windows NT and 2000, and Avaya Media and Message Application servers, allows remote att...
- EPSS 37.94%
- Published 17.11.2008 23:30:00
- Last modified 09.04.2025 00:30:58
The LDAP server in Active Directory in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 responds differently to a failed bind attempt depending on whether the user account exists and is permitted to login, which allows remote attackers to enume...
CVE-2008-4037
- EPSS 73.93%
- Published 12.11.2008 23:30:02
- Last modified 09.04.2025 00:30:58
Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote SMB servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user, as ...