CVE-2008-1087
- EPSS 53.65%
- Veröffentlicht 08.04.2008 23:05:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Stack-based buffer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to execute arbitrary code via an EMF image file with crafted filename parameters, aka "GDI Stack Overflo...
CVE-2008-0088
- EPSS 65.98%
- Veröffentlicht 12.02.2008 21:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in Active Directory on Microsoft Windows 2000 and Windows Server 2003, and Active Directory Application Mode (ADAM) on XP and Server 2003, allows remote attackers to cause a denial of service (hang and restart) via a crafted...
CVE-2007-0066
- EPSS 27.15%
- Veröffentlicht 08.01.2008 20:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The kernel in Microsoft Windows 2000 SP4, XP SP2, and Server 2003, when ICMP Router Discovery Protocol (RDP) is enabled, allows remote attackers to cause a denial of service via fragmented router advertisement ICMP packets that trigger an out-of-boun...
CVE-2007-5352
- EPSS 3.19%
- Veröffentlicht 08.01.2008 20:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows local users to gain privileges via a crafted local procedure call (LPC) request.
CVE-2007-6043
- EPSS 17.76%
- Veröffentlicht 20.11.2007 19:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The CryptGenRandom function in Microsoft Windows 2000 generates predictable values, which makes it easier for context-dependent attackers to reduce the effectiveness of cryptographic mechanisms, as demonstrated by attacks on (1) forward security and ...
CVE-2007-6026
- EPSS 80.55%
- Veröffentlicht 20.11.2007 00:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Stack-based buffer overflow in Microsoft msjet40.dll 4.0.8618.0 (aka Microsoft Jet Engine), as used by Access 2003 in Microsoft Office 2003 SP3, allows user-assisted attackers to execute arbitrary code via a crafted MDB file database file containing ...
CVE-2007-3898
- EPSS 83.87%
- Veröffentlicht 14.11.2007 01:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS servers, which allows remote attackers to spoof DNS replies, poison the DNS cache, and facilitate further attac...
CVE-2007-2228
- EPSS 76.67%
- Veröffentlicht 09.10.2007 22:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
rpcrt4.dll (aka the RPC runtime library) in Microsoft Windows XP SP2, XP Professional x64 Edition, Server 2003 SP1 and SP2, Server 2003 x64 Edition and x64 Edition SP2, and Vista and Vista x64 Edition allows remote attackers to cause a denial of serv...
CVE-2007-3040
- EPSS 65.69%
- Veröffentlicht 12.09.2007 01:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Stack-based buffer overflow in agentdpv.dll 2.0.0.3425 in Microsoft Agent on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a crafted URL to the Agent (Agent.Control) ActiveX control, which triggers an overflow within the Agen...
CVE-2007-3034
- EPSS 81.88%
- Veröffentlicht 14.08.2007 21:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer overflow in the AttemptWrite function in Graphics Rendering Engine (GDI) on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted metafile (image) with a large record length va...