CVE-2010-0027
- EPSS 50.11%
- Veröffentlicht 22.01.2010 22:00:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
The URL validation functionality in Microsoft Internet Explorer 5.01, 6, 6 SP1, 7 and 8, and the ShellExecute API function in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, does not properly process input parameters, which allows remote attac...
CVE-2010-0232
- EPSS 76.74%
- Veröffentlicht 21.01.2010 19:30:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2, when access to 16-bit applications is enabl...
CVE-2010-0018
- EPSS 68.95%
- Veröffentlicht 13.01.2010 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer overflow in the Embedded OpenType (EOT) Font Engine (t2embed.dll) in Microsoft Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows re...
CVE-2009-3671
- EPSS 56.49%
- Veröffentlicht 09.12.2009 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Unini...
CVE-2009-3673
- EPSS 55.4%
- Veröffentlicht 09.12.2009 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Microsoft Internet Explorer 7 and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka ...
CVE-2009-3674
- EPSS 59.22%
- Veröffentlicht 09.12.2009 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Unini...
CVE-2009-3676
- EPSS 56.03%
- Veröffentlicht 13.11.2009 15:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The SMB client in the kernel in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle attackers to cause a denial of service (infinite loop and system hang) via a (1) SMBv1 or (2) SMBv2 response packet that co...
CVE-2009-2497
- EPSS 39.63%
- Veröffentlicht 14.10.2009 10:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0, 2.0 SP1, 2.0 SP2, 3.5, and 3.5 SP1, and Silverlight 2, does not properly handle interfaces, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser appl...
CVE-2009-2510
- EPSS 17.11%
- Veröffentlicht 14.10.2009 10:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
The CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, as used by Internet Explorer and other applications, does ...
CVE-2009-2511
- EPSS 14.51%
- Veröffentlicht 14.10.2009 10:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer overflow in the CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows man-in-the-middle attackers to s...