CVE-2009-2502
- EPSS 51.58%
- Published 14.10.2009 10:30:01
- Last modified 09.04.2025 00:30:58
Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3...
CVE-2009-2503
- EPSS 43.91%
- Published 14.10.2009 10:30:01
- Last modified 09.04.2025 00:30:58
GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold a...
CVE-2009-2504
- EPSS 48.8%
- Published 14.10.2009 10:30:01
- Last modified 09.04.2025 00:30:58
Multiple integer overflows in unspecified APIs in GDI+ in Microsoft .NET Framework 1.1 SP1, .NET Framework 2.0 SP1 and SP2, Windows XP SP2 and SP3, Windows Server 2003 SP2, Vista Gold and SP1, Server 2008 Gold, Office XP SP3, Office 2003 SP3, 2007 Mi...
CVE-2009-2528
- EPSS 41.2%
- Published 14.10.2009 10:30:01
- Last modified 09.04.2025 00:30:58
GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "Memory Corruption Vu...
CVE-2009-2529
- EPSS 24.55%
- Published 14.10.2009 10:30:01
- Last modified 09.04.2025 00:30:58
Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not properly handle argument validation for unspecified variables, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "HTML Component Handling Vulnera...
CVE-2009-2530
- EPSS 40.12%
- Published 14.10.2009 10:30:01
- Last modified 09.04.2025 00:30:58
Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corru...
CVE-2009-2531
- EPSS 40.12%
- Published 14.10.2009 10:30:01
- Last modified 09.04.2025 00:30:58
Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corru...
CVE-2009-3126
- EPSS 50.94%
- Published 14.10.2009 10:30:01
- Last modified 09.04.2025 00:30:58
Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP...
CVE-2009-1547
- EPSS 29.72%
- Published 14.10.2009 10:30:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted data stream header that triggers memory corruption, aka "Data Stream Header Corruption Vulnerability."
- EPSS 13.77%
- Published 18.09.2009 22:30:00
- Last modified 09.04.2025 00:30:58
Microsoft Internet Explorer 6 through 6.0.2900.2180, and 7.0.6000.16711, allows remote attackers to cause a denial of service (CPU consumption) via an automatically submitted form containing a KEYGEN element, a related issue to CVE-2009-1828.