CVE-2012-0005
- EPSS 4.91%
- Published 10.01.2012 21:55:03
- Last modified 11.04.2025 00:51:21
The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2, when a Chinese, Japanese, or Korean system locale is used, can access uninitialized memory d...
CVE-2012-0009
- EPSS 58.79%
- Published 10.01.2012 21:55:03
- Last modified 11.04.2025 00:51:21
Untrusted search path vulnerability in the Windows Object Packager configuration in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a Trojan horse executable file in the current working directory, as dem...
CVE-2011-5046
- EPSS 76.98%
- Published 30.12.2011 19:55:01
- Last modified 11.04.2025 00:51:21
The Graphics Device Interface (GDI) in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly valida...
CVE-2011-3414
- EPSS 76.67%
- Published 30.12.2011 01:55:01
- Last modified 11.04.2025 00:51:21
The CaseInsensitiveHashProvider.getHashCode function in the HashTable implementation in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 computes hash values for form parameters without restricting the abili...
CVE-2011-3415
- EPSS 44.11%
- Published 30.12.2011 01:55:01
- Last modified 11.04.2025 00:51:21
Open redirect vulnerability in the Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a ...
CVE-2011-3416
- EPSS 83.53%
- Published 30.12.2011 01:55:01
- Last modified 11.04.2025 00:51:21
The Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 allows remote authenticated users to obtain access to arbitrary user accounts via a crafted username, aka "ASP.Net Forms A...
CVE-2011-3417
- EPSS 64.98%
- Published 30.12.2011 01:55:01
- Last modified 11.04.2025 00:51:21
The Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0, when sliding expiry is enabled, does not properly handle cached content, which allows remote attackers to obtain access t...
CVE-2011-2018
- EPSS 0.31%
- Published 14.12.2011 00:55:01
- Last modified 11.04.2025 00:51:21
The kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, and Windows 7 Gold and SP1 does not properly initialize objects, which allows local users to gain privileges via a crafted applicatio...
CVE-2011-3397
- EPSS 45.37%
- Published 14.12.2011 00:55:01
- Last modified 11.04.2025 00:51:21
The Microsoft Time component in DATIME.DLL in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted web site that leverages an unspecified "binary behavior" in Internet Explorer, aka "Mic...
CVE-2011-3400
- EPSS 84.37%
- Published 14.12.2011 00:55:01
- Last modified 11.04.2025 00:51:21
Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 do not properly handle OLE objects in memory, which allows remote attackers to execute arbitrary code via a crafted object in a file, aka "OLE Property Vulnerability."