- EPSS 7.7%
- Published 23.12.2002 05:00:00
- Last modified 03.04.2025 01:03:51
Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to execute arbitrary code by including a Java applet that invokes COM (Component Object Model) objects in a web site or an HTML mail.
CVE-2002-1183
- EPSS 11.91%
- Published 11.12.2002 05:00:00
- Last modified 03.04.2025 01:03:51
Microsoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital certificates, allowing remote attackers to execute code, aka "New Variant of Certificate Validation Flaw Could Enable Identity Spoofing" (CAN-2002-0862).
CVE-2002-0694
- EPSS 31.91%
- Published 10.10.2002 04:00:00
- Last modified 03.04.2025 01:03:51
The HTML Help facility in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP uses the Local Computer Security Zone when opening .chm files from the Temporary Internet File...
CVE-2002-0693
- EPSS 71.91%
- Published 10.10.2002 04:00:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute code via (1) a long ...
- EPSS 9.93%
- Published 04.10.2002 04:00:00
- Last modified 03.04.2025 01:03:51
Unknown vulnerability in the Certificate Enrollment ActiveX Control in Microsoft Windows 98, Windows 98 Second Edition, Windows Millennium, Windows NT 4.0, Windows 2000, and Windows XP allow remote attackers to delete digital certificates on a user's...
CVE-2002-0862
- EPSS 12.51%
- Published 04.10.2002 04:00:00
- Last modified 03.04.2025 01:03:51
The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express f...
CVE-2002-0070
- EPSS 38.35%
- Published 15.03.2002 05:00:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in Windows Shell (used as the Windows Desktop) allows local and possibly remote attackers to execute arbitrary code via a custom URL handler that has not been removed for an application that has been improperly uninstalled.
CVE-2002-0053
- EPSS 52.63%
- Published 08.03.2002 05:00:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in SNMP agent service in Windows 95/98/98SE, Windows NT 4.0, Windows 2000, and Windows XP allows remote attackers to cause a denial of service or execute arbitrary code via a malformed management request. NOTE: this candidate may be ...
- EPSS 52.8%
- Published 20.12.2001 05:00:00
- Last modified 03.04.2025 01:03:51
Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to cause a denial of service via (1) a spoofed SSDP advertisement that causes the client to connect to a service on another machine that generates a large amount o...
CVE-2001-0876
- EPSS 78.7%
- Published 20.12.2001 05:00:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to execute arbitrary code via a NOTIFY directive with a long Location URL.