Microsoft

Windows Server 2008

3466 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 80.78%
  • Veröffentlicht 14.10.2009 10:30:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 do not properly validate fields in SMBv2 packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted packet to the Server se...

  • EPSS 41.2%
  • Veröffentlicht 14.10.2009 10:30:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "Memory Corruption Vu...

  • EPSS 24.55%
  • Veröffentlicht 14.10.2009 10:30:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not properly handle argument validation for unspecified variables, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "HTML Component Handling Vulnera...

  • EPSS 40.12%
  • Veröffentlicht 14.10.2009 10:30:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corru...

  • EPSS 40.12%
  • Veröffentlicht 14.10.2009 10:30:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corru...

  • EPSS 61.78%
  • Veröffentlicht 14.10.2009 10:30:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC do not properly process the command value in an SMB Multi-Protocol Negotiate Request packet, which allows remote attackers to execute arbitrary code via a ...

  • EPSS 50.94%
  • Veröffentlicht 14.10.2009 10:30:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP...

  • EPSS 44.66%
  • Veröffentlicht 14.10.2009 10:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, and 2.0 SP1 does not properly validate .NET verifiable code, which allows remote attackers to obtain unintended access to stack memory, and execute arbitrary code, via (1) a crafted XAML browser application ...

  • EPSS 44.52%
  • Veröffentlicht 14.10.2009 10:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Microsoft .NET Framework 2.0, 2.0 SP1, and 3.5 does not properly enforce a certain type-equality constraint in .NET verifiable code, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a craf...

  • EPSS 31.95%
  • Veröffentlicht 14.10.2009 10:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Compression Manager (ACM), does not properly process Advanced Systems Format (ASF) files, which allows remote attackers to execute ar...