CVE-2009-3675
- EPSS 38.94%
- Veröffentlicht 09.12.2009 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
LSASS.exe in the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote authenticated users to cause a denial of service (CPU consumption) via a malformed ISAKMP request ove...
- EPSS 66.7%
- Veröffentlicht 09.12.2009 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Internet Authentication Service (IAS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly verify the credentials in an MS-CHAP v2 Protected Extensible Authentication Protocol ...
CVE-2009-1127
- EPSS 1.2%
- Veröffentlicht 11.11.2009 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not correctly validate an argument to an unspecified system call, which allows local users to gain pr...
CVE-2009-1928
- EPSS 47.86%
- Veröffentlicht 11.11.2009 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Stack consumption vulnerability in the LDAP service in Active Directory on Microsoft Windows 2000 SP4, Server 2003 SP2, and Server 2008 Gold and SP2; Active Directory Application Mode (ADAM) on Windows XP SP2 and SP3 and Server 2003 SP2; and Active D...
CVE-2009-2513
- EPSS 0.44%
- Veröffentlicht 11.11.2009 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Graphics Device Interface (GDI) in win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not properly validate user-mode input, which allows local user...
CVE-2009-2514
- EPSS 80.21%
- Veröffentlicht 11.11.2009 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not correctly parse font code during construction of a directory-entry table, which allows remote attackers to execute arbitrary code via a crafted Embed...
CVE-2009-2497
- EPSS 39.63%
- Veröffentlicht 14.10.2009 10:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0, 2.0 SP1, 2.0 SP2, 3.5, and 3.5 SP1, and Silverlight 2, does not properly handle interfaces, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser appl...
CVE-2009-2500
- EPSS 56.77%
- Veröffentlicht 14.10.2009 10:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP...
CVE-2009-2501
- EPSS 51.68%
- Veröffentlicht 14.10.2009 10:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
Heap-based buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 G...
CVE-2009-2502
- EPSS 51.58%
- Veröffentlicht 14.10.2009 10:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3...