CVE-2009-1511
- EPSS 10.07%
- Veröffentlicht 01.05.2009 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
GDI+ in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (infinite loop) via a PNG file that contains a certain large btChunkLen value.
CVE-2009-0078
- EPSS 1.63%
- Veröffentlicht 15.04.2009 08:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Windows Management Instrumentation (WMI) provider in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly implement isolation among a set of distinct processes that (1) all run under the...
CVE-2009-0079
- EPSS 0.65%
- Veröffentlicht 15.04.2009 08:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The RPCSS service in Microsoft Windows XP SP2 and SP3 and Server 2003 SP1 and SP2 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account,...
- EPSS 52.49%
- Veröffentlicht 15.04.2009 08:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer underflow in Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote HTTP servers to execute arbitrary code via crafted parameter values in ...
CVE-2009-0087
- EPSS 60.58%
- Veröffentlicht 15.04.2009 08:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in the Word 6 text converter in WordPad in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and the Word 6 text converter in Microsoft Office Word 2000 SP3 and 2002 SP3; allows remote attackers to exe...
CVE-2009-0088
- EPSS 67.01%
- Veröffentlicht 15.04.2009 08:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The WordPerfect 6.x Converter (WPFT632.CNV, 1998.1.27.0) in Microsoft Office Word 2000 SP3 and Microsoft Office Converter Pack does not properly validate the length of an unspecified string, which allows remote attackers to execute arbitrary code via...
CVE-2009-0089
- EPSS 12.82%
- Veröffentlicht 15.04.2009 08:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Vista Gold allows remote web servers to impersonate arbitrary https web sites by using DNS spoofing to "forward a connection" to a differe...
CVE-2009-0235
- EPSS 74.69%
- Veröffentlicht 15.04.2009 08:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Stack-based buffer overflow in the Word 97 text converter in WordPad in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted Word 97 file that triggers memory corrupti...
CVE-2009-0550
- EPSS 38.59%
- Veröffentlicht 15.04.2009 08:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008; and WinINet in Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on...
CVE-2009-0083
- EPSS 1.16%
- Veröffentlicht 10.03.2009 20:30:06
- Zuletzt bearbeitet 09.04.2025 00:30:58
The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 does not properly handle invalid pointers, which allows local users to gain privileges via an application that triggers use of a crafted pointer, aka "Windows Kernel Invali...