Microsoft

Windows 2000

517 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 41.04%
  • Published 14.04.2010 16:00:01
  • Last modified 11.04.2025 00:51:21

The Authenticode Signature verification functionality in cabview.dll in Cabinet File Viewer Shell Extension 5.1, 6.0, and 6.1 in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Se...

  • EPSS 40.22%
  • Published 14.04.2010 16:00:00
  • Last modified 11.04.2025 00:51:21

The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2003 SP2, does not properly parse MX records, which allows remote DNS servers to cause a denial of service (serv...

  • EPSS 59.4%
  • Published 14.04.2010 16:00:00
  • Last modified 11.04.2025 00:51:21

The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2000 SP3, does not properly allocate memory for SMTP command replies, which allows remote attackers to read frag...

  • EPSS 66.17%
  • Published 31.03.2010 19:30:00
  • Last modified 11.04.2025 00:51:21

Microsoft Internet Explorer 6, 6 SP1, and 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corrupti...

  • EPSS 15.55%
  • Published 31.03.2010 19:30:00
  • Last modified 11.04.2025 00:51:21

Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 does not properly handle unspecified "encoding strings," which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site, aka "Post Encoding ...

  • EPSS 35.42%
  • Published 31.03.2010 19:30:00
  • Last modified 11.04.2025 00:51:21

Race condition in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted HTML document that triggers memory corruption, aka "Race Condition Memory Corruption Vulnerability."

  • EPSS 62.43%
  • Published 31.03.2010 19:30:00
  • Last modified 11.04.2025 00:51:21

Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, and 6 SP1 allows remote attackers to execute arbitrary code by changing unspecified properties of an HTML object that has an onreadystatechange event handler, aka "HTML Object M...

  • EPSS 50.18%
  • Published 31.03.2010 19:30:00
  • Last modified 11.04.2025 00:51:21

Cross-domain vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 allows user-assisted remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted HTML document in a situation where the cl...

  • EPSS 87.69%
  • Published 31.03.2010 19:30:00
  • Last modified 11.04.2025 00:51:21

The Tabular Data Control (TDC) ActiveX control in Microsoft Internet Explorer 5.01 SP4, 6 on Windows XP SP2 and SP3, and 6 SP1 allows remote attackers to execute arbitrary code via a long URL (DataURL parameter) that triggers memory corruption in the...

  • EPSS 90.86%
  • Published 10.03.2010 22:30:01
  • Last modified 11.04.2025 00:51:21

Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an ...