CVE-2008-3464
- EPSS 1.43%
- Published 15.10.2008 00:12:15
- Last modified 09.04.2025 00:30:58
afd.sys in the Ancillary Function Driver (AFD) component in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP1 and SP2 does not properly validate input sent from user mode to the kernel, which allows local users to gain privileges via a cra...
CVE-2008-3008
- EPSS 81.1%
- Published 11.09.2008 01:11:47
- Last modified 09.04.2025 00:30:58
Stack-based buffer overflow in the WMEncProfileManager ActiveX control in wmex.dll in Microsoft Windows Media Encoder 9 Series allows remote attackers to execute arbitrary code via a long first argument to the GetDetailsString method, aka "Windows Me...
- EPSS 58.67%
- Published 13.08.2008 12:42:00
- Last modified 09.04.2025 00:30:58
Array index vulnerability in the Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote authenticated users to execute arbitrary code via a crafted event subscription req...
- EPSS 54.93%
- Published 13.08.2008 12:42:00
- Last modified 09.04.2025 00:30:58
The Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate per-user subscriptions, which allows remote authenticated users to execute arbitrary code via a cr...
CVE-2008-2245
- EPSS 83.12%
- Published 13.08.2008 00:41:00
- Last modified 09.04.2025 00:30:58
Heap-based buffer overflow in the InternalOpenColorProfile function in mscms.dll in Microsoft Windows Image Color Management System (MSCMS) in the Image Color Management (ICM) component on Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2...
CVE-2008-1445
- EPSS 57.92%
- Published 12.06.2008 02:32:00
- Last modified 09.04.2025 00:30:58
Active Directory on Microsoft Windows 2000 Server SP4, XP Professional SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to cause a denial of service (system hang or reboot) via a crafted LDAP request.
CVE-2008-1451
- EPSS 4.91%
- Published 12.06.2008 02:32:00
- Last modified 09.04.2025 00:30:58
The WINS service on Microsoft Windows 2000 SP4, and Server 2003 SP1 and SP2, does not properly validate data structures in WINS network packets, which allows local users to gain privileges via a crafted packet, aka "Memory Overwrite Vulnerability."
CVE-2008-0083
- EPSS 50.84%
- Published 08.04.2008 23:05:00
- Last modified 09.04.2025 00:30:58
The (1) VBScript (VBScript.dll) and (2) JScript (JScript.dll) scripting engines 5.1 and 5.6, as used in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2, do not properly decode script, which allows remote attackers to execute arbitrary...
CVE-2008-1083
- EPSS 68.7%
- Published 08.04.2008 23:05:00
- Last modified 09.04.2025 00:30:58
Heap-based buffer overflow in the CreateDIBPatternBrushPt function in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to execute arbitrary code via an EMF or WMF image file with a mal...
CVE-2008-1084
- EPSS 9%
- Published 08.04.2008 23:05:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, through Vista SP1, and Server 2008 allows local users to execute arbitrary code via unknown vectors related to improper input validation. NOTE: i...