- EPSS 94.04%
- Published 23.10.2008 22:00:01
- Last modified 09.04.2025 00:30:58
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during p...
CVE-2008-4609
- EPSS 0.48%
- Published 20.10.2008 17:59:26
- Last modified 09.04.2025 00:30:58
The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vect...
CVE-2008-4036
- EPSS 1.13%
- Published 15.10.2008 00:12:16
- Last modified 09.04.2025 00:30:58
Integer overflow in Memory Manager in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows local users to gain privileges via a crafted application that triggers an erroneous decrement of a variable, r...
- EPSS 70.09%
- Published 15.10.2008 00:12:16
- Last modified 09.04.2025 00:30:58
Buffer underflow in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via a Server Message Block (SMB) request that contains a filename with a cr...
CVE-2008-2250
- EPSS 1.4%
- Published 15.10.2008 00:12:15
- Last modified 09.04.2025 00:30:58
The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate window properties sent from a parent window to a child window during creation of a new window, which all...
CVE-2008-2251
- EPSS 0.78%
- Published 15.10.2008 00:12:15
- Last modified 09.04.2025 00:30:58
Double free vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows local users to gain privileges via a crafted application that makes system calls within multipl...
CVE-2008-2252
- EPSS 1.05%
- Published 15.10.2008 00:12:15
- Last modified 09.04.2025 00:30:58
The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate parameters sent from user mode to the kernel, which allows local users to gain privileges via a crafted ...
CVE-2008-3464
- EPSS 1.43%
- Published 15.10.2008 00:12:15
- Last modified 09.04.2025 00:30:58
afd.sys in the Ancillary Function Driver (AFD) component in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP1 and SP2 does not properly validate input sent from user mode to the kernel, which allows local users to gain privileges via a cra...
CVE-2008-4327
- EPSS 27.28%
- Published 30.09.2008 16:13:54
- Last modified 09.04.2025 00:30:58
gdiplus.dll in GDI+ in Microsoft Windows XP SP3 does not properly handle crafted .ico files, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a certain crash.ico file on a web site, and allow...
CVE-2008-4323
- EPSS 11.25%
- Published 29.09.2008 20:09:59
- Last modified 09.04.2025 00:30:58
Windows Explorer in Microsoft Windows XP SP3 allows user-assisted attackers to cause a denial of service (application crash) via a crafted .ZIP file.