- EPSS 79.75%
- Veröffentlicht 11.08.2010 18:47:50
- Zuletzt bearbeitet 11.04.2025 00:51:21
The SMB Server in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate fields in an SMB request, which allows remote attackers to execute...
CVE-2010-2553
- EPSS 68.44%
- Veröffentlicht 11.08.2010 18:47:50
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Cinepak codec in Microsoft Windows XP SP2 and SP3, Windows Vista SP1 and SP2, and Windows 7 does not properly decompress media files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Cinepak Codec Decompression Vul...
CVE-2010-1882
- EPSS 64.56%
- Veröffentlicht 11.08.2010 18:47:49
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple buffer overflows in the MPEG Layer-3 Audio Codec for Microsoft DirectShow in l3codecx.ax in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allow remote attackers to execute arbitrary code via an MPEG Layer-3 audio stream in (1) a craft...
CVE-2010-1887
- EPSS 0.4%
- Veröffentlicht 11.08.2010 18:47:49
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly validate an unspecified system-call argument, ...
CVE-2010-1888
- EPSS 0.77%
- Veröffentlicht 11.08.2010 18:47:49
- Zuletzt bearbeitet 11.04.2025 00:51:21
Race condition in the kernel in Microsoft Windows XP SP3 allows local users to gain privileges via vectors involving thread creation, aka "Windows Kernel Data Initialization Vulnerability."
CVE-2010-2568
- EPSS 92.38%
- Veröffentlicht 22.07.2010 05:43:49
- Zuletzt bearbeitet 11.04.2025 00:51:21
Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code via a crafted (1) .LNK or (2) .PIF shortcut file, which is not prope...
CVE-2010-2265
- EPSS 24.81%
- Veröffentlicht 15.06.2010 14:04:24
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in the GetServerName function in sysinfo/commonFunc.js in Microsoft Windows Help and Support Center for Windows XP and Windows Server 2003 allows remote attackers to inject arbitrary web script or HTML via the...
CVE-2010-1885
- EPSS 91.2%
- Veröffentlicht 15.06.2010 14:04:23
- Zuletzt bearbeitet 11.04.2025 00:51:21
The MPC::HexToNum function in helpctr.exe in Microsoft Windows Help and Support Center in Windows XP and Windows Server 2003 does not properly handle malformed escape sequences, which allows remote attackers to bypass the trusted documents whitelist ...
CVE-2010-0484
- EPSS 2.1%
- Veröffentlicht 08.06.2010 22:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 "do not properly validate changes in certain kernel objects," which allows local users to ex...
CVE-2010-0485
- EPSS 1.06%
- Veröffentlicht 08.06.2010 22:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 Gold and SP2, Windows 7, and Server 2008 R2 "do not properly validate all callback parameters when creating a...