· 6 years ago · Oct 12, 2019, 03:22 PM
1#######################################################################################################################################
2=======================================================================================================================================
3Hostname www.michiganmasons.org ISP Winn Telecom
4Continent North America Flag
5US
6Country United States Country Code US
7Region Michigan Local time 12 Oct 2019 08:38 EDT
8City Alma Postal Code 48801
9IP Address 67.209.250.173 Latitude 43.381
10 Longitude -84.664
11======================================================================================================================================
12#######################################################################################################################################
13> www.michiganmasons.org
14Server: 38.132.106.139
15Address: 38.132.106.139#53
16
17Non-authoritative answer:
18www.michiganmasons.org canonical name = michiganmasons.org.
19Name: michiganmasons.org
20Address: 67.209.250.173
21>
22#######################################################################################################################################
23Domain Name: MICHIGANMASONS.ORG
24Registry Domain ID: D101914037-LROR
25Registrar WHOIS Server: whois.wildwestdomains.com
26Registrar URL: http://whois.wildwestdomains.com
27Updated Date: 2018-11-01T18:44:05Z
28Creation Date: 2003-10-31T17:18:50Z
29Registry Expiry Date: 2020-10-31T17:18:50Z
30Registrar Registration Expiration Date:
31Registrar: Wild West Domains, LLC
32Registrar IANA ID: 440
33Registrar Abuse Contact Email: abuse@wildwest.com
34Registrar Abuse Contact Phone: +1.4806242505
35Reseller:
36Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
37Domain Status: clientRenewProhibited https://icann.org/epp#clientRenewProhibited
38Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
39Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
40Registrant Organization: Grand Lodge of Michigan
41Registrant State/Province: Michigan
42Registrant Country: US
43Name Server: NS11.DOMAINCONTROL.COM
44Name Server: NS12.DOMAINCONTROL.COM
45DNSSEC: unsigned
46#######################################################################################################################################
47[+] Target : www.michiganmasons.org
48
49[+] IP Address : 67.209.250.173
50
51[+] Headers :
52
53[+] Transfer-Encoding : chunked
54[+] Content-Type : text/html;charset=UTF-8
55[+] Content-Language : en-US
56[+] Server : Microsoft-IIS/8.5
57[+] Strict-Transport-Security : max-age=1200
58[+] Generator : Mura CMS 7.0
59[+] X-Powered-By : ASP.NET
60[+] Date : Sat, 12 Oct 2019 12:45:22 GMT
61
62[+] SSL Certificate Information :
63
64[+] organizationalUnitName : Domain Control Validated
65[+] commonName : www.grandlodgemi.org
66[+] countryName : US
67[+] stateOrProvinceName : Arizona
68[+] localityName : Scottsdale
69[+] organizationName : Starfield Technologies, Inc.
70[+] organizationalUnitName : http://certs.starfieldtech.com/repository/
71[+] commonName : Starfield Secure Certificate Authority - G2
72[+] Version : 3
73[+] Serial Number : 58D1A1A94EF95DD4
74[+] Not Before : Dec 20 10:28:44 2018 GMT
75[+] Not After : Feb 18 20:52:40 2021 GMT
76[+] OCSP : ('http://ocsp.starfieldtech.com/',)
77[+] subject Alt Name : (('DNS', 'www.grandlodgemi.org'), ('DNS', 'grandlodgemi.org'), ('DNS', 'www.sharethesecret.org'), ('DNS', 'michiganchildid.org'), ('DNS', 'mds.grandlodgemi.org'), ('DNS', 'qr.grandlodgemi.org'), ('DNS', 'data.michiganmasons.org'), ('DNS', 'sharethesecret.org'), ('DNS', 'contacts.michiganmasons.org'), ('DNS', 'search.grandlodgemi.org'), ('DNS', 'www.michiganchildid.org'), ('DNS', 'www.michiganmasons.org'), ('DNS', 'michiganmasons.org'))
78[+] CA Issuers : ('http://certificates.starfieldtech.com/repository/sfig2.crt',)
79[+] CRL Distribution Points : ('http://crl.starfieldtech.com/sfig2s1-140.crl',)
80
81[+] Whois Lookup :
82
83[+] NIR : None
84[+] ASN Registry : arin
85[+] ASN : 17143
86[+] ASN CIDR : 67.209.248.0/21
87[+] ASN Country Code : US
88[+] ASN Date : 2008-10-20
89[+] ASN Description : WINNTELECOM - Winn Telecom, US
90[+] cidr : 67.209.240.0/20
91[+] name : WINN-TELECOM-INET-200810
92[+] handle : NET-67-209-240-0-1
93[+] range : 67.209.240.0 - 67.209.255.255
94[+] description : Winn Telecom
95[+] country : US
96[+] state : MI
97[+] city : Mount Pleasant
98[+] address : 402 N. Mission St.
99Suite 1
100[+] postal_code : 48858
101[+] emails : ['abuse@winntel.com', 'ipnoc@winntel.com']
102[+] created : 2008-10-20
103[+] updated : 2012-03-02
104
105[+] Crawling Target...
106
107[+] Looking for robots.txt........[ Found ]
108[+] Extracting robots Links.......[ 6 ]
109[+] Looking for sitemap.xml.......[ Not Found ]
110[+] Extracting CSS Links..........[ 5 ]
111[+] Extracting Javascript Links...[ 6 ]
112[+] Extracting Internal Links.....[ 0 ]
113[+] Extracting External Links.....[ 6 ]
114[+] Extracting Images.............[ 8 ]
115
116[+] Total Links Extracted : 31
117
118[+] Dumping Links in /opt/FinalRecon/dumps/www.michiganmasons.org.dump
119[+] Completed!
120#######################################################################################################################################
121[+] Starting At 2019-10-12 08:45:17.702239
122[+] Collecting Information On: https://www.michiganmasons.org/
123[#] Status: 200
124--------------------------------------------------
125[#] Web Server Detected: Microsoft-IIS/8.5
126[#] X-Powered-By: ASP.NET
127[!] X-Frame-Options Headers not detect! target might be vulnerable Click Jacking
128- Transfer-Encoding: chunked
129- Content-Type: text/html;charset=UTF-8
130- Content-Language: en-US
131- Server: Microsoft-IIS/8.5
132- Set-Cookie: CFID=3534456; Expires=Sun, 13-Oct-2019 12:45:43 GMT; Path=/; HttpOnly, CFTOKEN=800ed84c79cf8421-80083606-5056-BE23-CB61DA213BEAD4CA; Expires=Sun, 13-Oct-2019 12:45:43 GMT; Path=/; HttpOnly, MXP_TRACKINGID=80083618%2D5056%2DBE23%2DCBA47FB344A5D0EB; Expires=Mon, 04-Oct-2049 12:45:43 GMT; Path=/; HttpOnly, mobileFormat=false; Expires=Mon, 04-Oct-2049 12:45:43 GMT; Path=/; HttpOnly
133- Strict-Transport-Security: max-age=1200
134- Generator: Mura CMS 7.0
135- X-Powered-By: ASP.NET
136- Date: Sat, 12 Oct 2019 12:45:43 GMT
137--------------------------------------------------
138[#] Finding Location..!
139[#] as: AS17143 Winn Telecom
140[#] city: Alma
141[#] country: United States
142[#] countryCode: US
143[#] isp: Winn Telecom
144[#] lat: 43.3809
145[#] lon: -84.6635
146[#] org: Winn Telecom
147[#] query: 67.209.250.173
148[#] region: MI
149[#] regionName: Michigan
150[#] status: success
151[#] timezone: America/Detroit
152[#] zip: 48801
153--------------------------------------------------
154[x] Didn't Detect WAF Presence on: https://www.michiganmasons.org/
155--------------------------------------------------
156[#] Starting Reverse DNS
157[-] Failed ! Fail
158--------------------------------------------------
159[!] Scanning Open Port
160[#] 80/tcp open http
161[#] 443/tcp open https
162--------------------------------------------------
163[+] Collecting Information Disclosure!
164[#] Detecting sitemap.xml file
165[-] sitemap.xml file not Found!?
166[#] Detecting robots.txt file
167[!] robots.txt File Found: https://www.michiganmasons.org//robots.txt
168[#] Detecting GNU Mailman
169[-] GNU Mailman App Not Detected!?
170--------------------------------------------------
171[+] Crawling Url Parameter On: https://www.michiganmasons.org/
172--------------------------------------------------
173[#] Searching Html Form !
174[-] No Html Form Found!?
175--------------------------------------------------
176[!] Found 2 dom parameter
177[#] https://www.michiganmasons.org//#myModal
178[#] https://www.michiganmasons.org//#
179--------------------------------------------------
180[-] No internal Dynamic Parameter Found!?
181--------------------------------------------------
182[!] 2 External Dynamic Parameter Discovered
183[#] http://visitor.r20.constantcontact.com/manage/optin?v=001ZaS58ajNOw3eQGQVjbQcXALJWFk-PywwtMdGCoVJE_VVmOpEhhScSRD7WdvuqMbPUU8iPXXytZKzh_mYFRy64A%3D%3D
184[#] http://visitor.r20.constantcontact.com/manage/optin?v=001ZaS58ajNOw3eQGQVjbQcXALJWFk-PywwtMdGCoVJE_VVmOpEhhScSRD7WdvuqMbPUU8iPXXytZKzh_mYFRy64A%3D%3D
185--------------------------------------------------
186[!] 59 Internal links Discovered
187[+] https://www.michiganmasons.org/muraGLMI/includes/themes/MuraBootstrap/images/favicon/apple-touch-icon-144x144.png
188[+] https://www.michiganmasons.org/muraGLMI/includes/themes/MuraBootstrap/images/favicon/apple-touch-icon-152x152.png
189[+] https://www.michiganmasons.org/muraGLMI/includes/themes/MuraBootstrap/images/favicon/favicon-32x32.png
190[+] https://www.michiganmasons.org/muraGLMI/includes/themes/MuraBootstrap/images/favicon/favicon-16x16.png
191[+] https://www.michiganmasons.org///MichiganMasons/includes/themes/MuraBootstrap/assets/bootstrap/css/bootstrap.min.css
192[+] https://www.michiganmasons.org///MichiganMasons/includes/themes/MuraBootstrap/assets/font-awesome/css/font-awesome.css
193[+] https://www.michiganmasons.org///MichiganMasons/css/mura.6.0.min.css
194[+] https://www.michiganmasons.org///muraGLMI/includes/themes/MuraBootstrap/css/css/theme.css
195[+] https://www.michiganmasons.org///MichiganMasons/includes/themes/MuraBootstrap/images/ico/favicon.ico
196[+] https://www.michiganmasons.org///MichiganMasons/includes/themes/MuraBootstrap/images/ico/ico/apple-touch-icon-144-precomposed.png
197[+] https://www.michiganmasons.org///MichiganMasons/includes/themes/MuraBootstrap/images/ico/ico/apple-touch-icon-114-precomposed.png
198[+] https://www.michiganmasons.org///MichiganMasons/includes/themes/MuraBootstrap/images/ico/ico/apple-touch-icon-72-precomposed.png
199[+] https://www.michiganmasons.org///MichiganMasons/includes/themes/MuraBootstrap/images/ico/ico/apple-touch-icon-57-precomposed.png
200[+] https://www.michiganmasons.org///
201[+] https://www.michiganmasons.org///
202[+] https://www.michiganmasons.org///what-we-do/
203[+] https://www.michiganmasons.org///what-we-do/community-outreach/
204[+] https://www.michiganmasons.org///what-we-do/beacon-project/
205[+] https://www.michiganmasons.org///what-we-do/books-for-bikes/
206[+] https://www.michiganmasons.org///what-we-do/calendar-of-events/
207[+] https://www.michiganmasons.org///what-we-do/michigan-child-id-program/
208[+] https://www.michiganmasons.org///what-we-do/scholarship-and-grants/
209[+] https://www.michiganmasons.org///what-we-do/student-assistance/
210[+] https://www.michiganmasons.org///what-we-do/video-links/
211[+] https://www.michiganmasons.org///about/
212[+] https://www.michiganmasons.org///about/photo-gallery/
213[+] https://www.michiganmasons.org///about/basics-of-freemasonry/
214[+] https://www.michiganmasons.org///about/history-of-freemasonry/
215[+] https://www.michiganmasons.org///about/masonic-symbols/
216[+] https://www.michiganmasons.org///about/masons-live-better/
217[+] https://www.michiganmasons.org///about/philosophy-and-beliefs/
218[+] https://www.michiganmasons.org///about/share-the-secret/
219[+] https://www.michiganmasons.org///about/who-are-masons/
220[+] https://www.michiganmasons.org///faq/
221[+] https://www.michiganmasons.org///faq/michigan-masons/
222[+] https://www.michiganmasons.org///faq/masonic-pathways/
223[+] https://www.michiganmasons.org///faq/personal-growth/
224[+] https://www.michiganmasons.org///faq/leadership/
225[+] https://www.michiganmasons.org///faq/questions-about-freemasonry/
226[+] https://www.michiganmasons.org///faq/s-a-y-detroit/
227[+] https://www.michiganmasons.org///join/
228[+] https://www.michiganmasons.org///join/joining-a-masonic-lodge/
229[+] https://www.michiganmasons.org///join/request-more-info/
230[+] https://www.michiganmasons.org///locations/
231[+] https://www.michiganmasons.org///locations/lodges-in-michigan/
232[+] https://www.michiganmasons.org///locations/lodge-directions/
233[+] https://www.michiganmasons.org///contact/
234[+] https://www.michiganmasons.org///default/css/bxslider/jquery.bxslider.css
235[+] https://www.michiganmasons.org///faq/michigan-masons/
236[+] https://www.michiganmasons.org///faq/leadership/
237[+] https://www.michiganmasons.org///videos/
238[+] https://www.michiganmasons.org///videos/
239[+] https://www.michiganmasons.org//mailto:webmaster@grandlodgemi.org
240[+] https://www.michiganmasons.org///join/
241[+] https://www.michiganmasons.org///join/joining-a-masonic-lodge/
242[+] https://www.michiganmasons.org///join/
243[+] https://www.michiganmasons.org///join/joining-a-lodge/
244[+] https://www.michiganmasons.org///privacy/
245[+] https://www.michiganmasons.org///site-map/
246--------------------------------------------------
247[!] 7 External links Discovered
248[#] http://www.youtube.com/michiganmasons
249[#] https://www.facebook.com/MichiganMasons
250[#] http://www.twitter.com/GLofMichigan
251[#] https://www.facebook.com/MichiganMasons
252[#] https://twitter.com/GLofMichigan
253[#] https://www.youtube.com/user/michiganmasons
254[#] https://www.facebook.com/MichiganMasons
255--------------------------------------------------
256[#] Mapping Subdomain..
257[!] Found 5 Subdomain
258- michiganmasons.org
259- contacts.michiganmasons.org
260- data.michiganmasons.org
261- mail.michiganmasons.org
262- webmail.michiganmasons.org
263--------------------------------------------------
264[!] Done At 2019-10-12 08:45:40.757703
265#######################################################################################################################################
266[i] Scanning Site: https://www.michiganmasons.org
267
268
269
270B A S I C I N F O
271====================
272
273
274[+] Site Title: Michigan Masons Home Page - MichiganMasons
275[+] IP address: 67.209.250.173
276[+] Web Server: Microsoft-IIS/8.5
277[+] CMS: Could Not Detect
278[+] Cloudflare: Not Detected
279[+] Robots File: Found
280
281-------------[ contents ]----------------
282User-agent: *
283Crawl-Delay: 5
284Allow: /requirements/fullcalendar
285Allow: /requirements/prettify
286Disallow: /admin/
287Disallow: /tasks/
288Disallow: /requirements/
289Disallow: /config/
290
291-----------[end of contents]-------------
292
293
294
295W H O I S L O O K U P
296========================
297
298 Domain Name: MICHIGANMASONS.ORG
299Registry Domain ID: D101914037-LROR
300Registrar WHOIS Server: whois.wildwestdomains.com
301Registrar URL: http://whois.wildwestdomains.com
302Updated Date: 2018-11-01T18:44:05Z
303Creation Date: 2003-10-31T17:18:50Z
304Registry Expiry Date: 2020-10-31T17:18:50Z
305Registrar Registration Expiration Date:
306Registrar: Wild West Domains, LLC
307Registrar IANA ID: 440
308Registrar Abuse Contact Email: abuse@wildwest.com
309Registrar Abuse Contact Phone: +1.4806242505
310Reseller:
311Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
312Domain Status: clientRenewProhibited https://icann.org/epp#clientRenewProhibited
313Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
314Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
315Registrant Organization: Grand Lodge of Michigan
316Registrant State/Province: Michigan
317Registrant Country: US
318Name Server: NS11.DOMAINCONTROL.COM
319Name Server: NS12.DOMAINCONTROL.COM
320DNSSEC: unsigned
321URL of the ICANN Whois Inaccuracy Complaint Form https://www.icann.org/wicf/)
322>>> Last update of WHOIS database: 2019-10-12T12:44:11Z <<<
323
324For more information on Whois status codes, please visit https://icann.org/epp
325
326
327
328
329
330G E O I P L O O K U P
331=========================
332
333[i] IP Address: 67.209.250.173
334[i] Country: United States
335[i] State: Michigan
336[i] City: Rosebush
337[i] Latitude: 43.6843
338[i] Longitude: -84.7833
339
340
341
342
343H T T P H E A D E R S
344=======================
345
346
347[i] HTTP/1.1 200 OK
348[i] Content-Type: text/html;charset=UTF-8
349[i] Content-Language: en-US
350[i] Server: Microsoft-IIS/8.5
351[i] Set-Cookie: CFID=3534455; Expires=Sun, 13-Oct-2019 12:45:38 GMT; Path=/; HttpOnly
352[i] Set-Cookie: CFTOKEN=d0dfddc4483a67fa-80076B3B-5056-BE23-CB3EC8C0ACAFC7FD; Expires=Sun, 13-Oct-2019 12:45:38 GMT; Path=/; HttpOnly
353[i] Set-Cookie: MXP_TRACKINGID=80076B4E%2D5056%2DBE23%2DCB3735B359AED745; Expires=Mon, 04-Oct-2049 12:45:38 GMT; Path=/; HttpOnly
354[i] Set-Cookie: mobileFormat=false; Expires=Mon, 04-Oct-2049 12:45:38 GMT; Path=/; HttpOnly
355[i] Strict-Transport-Security: max-age=1200
356[i] Generator: Mura CMS 7.0
357[i] X-Powered-By: ASP.NET
358[i] Date: Sat, 12 Oct 2019 12:45:38 GMT
359[i] Connection: close
360
361
362
363
364D N S L O O K U P
365===================
366
367michiganmasons.org. 3599 IN A 67.209.250.173
368michiganmasons.org. 3599 IN NS ns11.domaincontrol.com.
369michiganmasons.org. 3599 IN NS ns12.domaincontrol.com.
370michiganmasons.org. 3599 IN SOA ns11.domaincontrol.com. dns.jomax.net. 2019040200 28800 7200 604800 3600
371michiganmasons.org. 1799 IN MX 10 mx1.cmsinter.net.
372michiganmasons.org. 1799 IN MX 20 d22800a.ess.barracudanetworks.com.
373michiganmasons.org. 1799 IN TXT "v=spf1 mx ip4:67.209.250.165/32 ip4:67.209.250.166/32 ip4:207.241.128.23/32 -all"
374
375
376
377
378S U B N E T C A L C U L A T I O N
379====================================
380
381Address = 67.209.250.173
382Network = 67.209.250.173 / 32
383Netmask = 255.255.255.255
384Broadcast = not needed on Point-to-Point links
385Wildcard Mask = 0.0.0.0
386Hosts Bits = 0
387Max. Hosts = 1 (2^0 - 0)
388Host Range = { 67.209.250.173 - 67.209.250.173 }
389
390
391
392N M A P P O R T S C A N
393============================
394
395Starting Nmap 7.70 ( https://nmap.org ) at 2019-10-12 12:45 UTC
396Nmap scan report for michiganmasons.org (67.209.250.173)
397Host is up (0.036s latency).
398rDNS record for 67.209.250.173: a67-209-250-173.cust.mi.winntel.net
399
400PORT STATE SERVICE
40121/tcp filtered ftp
40222/tcp filtered ssh
40323/tcp filtered telnet
40480/tcp open http
405110/tcp filtered pop3
406143/tcp filtered imap
407443/tcp open https
4083389/tcp filtered ms-wbt-server
409
410Nmap done: 1 IP address (1 host up) scanned in 1.41 seconds
411
412
413
414S U B - D O M A I N F I N D E R
415==================================
416
417
418[i] Total Subdomains Found : 4
419
420[+] Subdomain: data.michiganmasons.org
421[-] IP: 67.209.250.181
422
423[+] Subdomain: mail.michiganmasons.org
424[-] IP: 67.209.250.204
425
426[+] Subdomain: webmail.michiganmasons.org
427[-] IP: 67.209.250.204
428
429[+] Subdomain: contacts.michiganmasons.org
430[-] IP: 67.209.250.173
431#######################################################################################################################################
432Enter Address Website = www.michiganmasons.org
433
434
435
436Reversing IP With HackTarget 'www.michiganmasons.org'
437--------------------------------------------------------
438
439[+] a67-209-250-173.cust.mi.winntel.net
440[+] beacon-project.com
441[+] beacon-project.org
442[+] contacts.michiganmasons.org
443[+] grandlodgemi.org
444[+] masonslivebetter.com
445[+] masonslivebetter.org
446[+] mds.grandlodgemi.org
447[+] michiganmasons.org
448[+] qr.grandlodgemi.org
449[+] search.grandlodgemi.org
450[+] wearethemasons.info
451
452
453
454Reverse IP With YouGetSignal 'www.michiganmasons.org'
455--------------------------------------------------------
456
457[*] IP: 67.209.250.173
458[*] Domain: michiganmasons.org
459[*] Total Domains: 4
460
461[+] grandlodgemi.org
462[+] michiganmasons.org
463[+] www.musculardevelopment.com
464[+] www.ranjanchalksculpture.net
465
466
467
468Geo IP Lookup 'www.michiganmasons.org'
469-----------------------------------------
470
471[+] IP Address: 67.209.250.173
472[+] Country: United States
473[+] State: Michigan
474[+] City: Rosebush
475[+] Latitude: 43.6843
476[+] Longitude: -84.7833
477
478
479
480
481
482DNS Lookup 'www.michiganmasons.org'
483--------------------------------------
484
485[+] michiganmasons.org. 3568 IN A 67.209.250.173
486[+] michiganmasons.org. 3568 IN NS ns11.domaincontrol.com.
487[+] michiganmasons.org. 3568 IN NS ns12.domaincontrol.com.
488[+] michiganmasons.org. 3568 IN SOA ns11.domaincontrol.com. dns.jomax.net. 2019040200 28800 7200 604800 3600
489[+] michiganmasons.org. 1768 IN MX 10 mx1.cmsinter.net.
490[+] michiganmasons.org. 1768 IN MX 20 d22800a.ess.barracudanetworks.com.
491[+] michiganmasons.org. 1768 IN TXT "v=spf1 mx ip4:67.209.250.165/32 ip4:67.209.250.166/32 ip4:207.241.128.23/32 -all"
492
493
494
495Show HTTP Header 'www.michiganmasons.org'
496--------------------------------------------
497
498[+] HTTP/1.1 301 Moved Permanently
499[+] Cache-Control: no-cache
500[+] Pragma: no-cache
501[+] Transfer-Encoding: chunked
502[+] Content-Type: text/html;charset=UTF-8
503[+] Location: https://www.michiganmasons.org
504[+] Server: Microsoft-IIS/8.5
505[+] Set-Cookie: CFID=3534460; Expires=Sun, 13-Oct-2019 12:46:12 GMT; Path=/; HttpOnly
506[+] Set-Cookie: CFTOKEN=9117a21535b09130-800C8FF1-5056-BE23-CBE8CD762F4CF101; Expires=Sun, 13-Oct-2019 12:46:12 GMT; Path=/; HttpOnly
507[+] Set-Cookie: MXP_TRACKINGID=800C9002%2D5056%2DBE23%2DCB475B621ABF31E2; Expires=Mon, 04-Oct-2049 12:46:12 GMT; Path=/; HttpOnly
508[+] Set-Cookie: mobileFormat=false; Expires=Mon, 04-Oct-2049 12:46:12 GMT; Path=/; HttpOnly
509[+] Strict-Transport-Security: max-age=1200
510[+] Generator: Mura CMS 7.0
511[+] X-Powered-By: ASP.NET
512[+] Date: Sat, 12 Oct 2019 12:46:12 GMT
513[+]
514
515
516
517Port Scan 'www.michiganmasons.org'
518-------------------------------------
519
520Starting Nmap 7.70 ( https://nmap.org ) at 2019-10-12 12:45 UTC
521Nmap scan report for www.michiganmasons.org (67.209.250.173)
522Host is up (0.031s latency).
523rDNS record for 67.209.250.173: a67-209-250-173.cust.mi.winntel.net
524
525PORT STATE SERVICE
52621/tcp filtered ftp
52722/tcp filtered ssh
52823/tcp filtered telnet
52980/tcp open http
530110/tcp filtered pop3
531143/tcp filtered imap
532443/tcp open https
5333389/tcp filtered ms-wbt-server
534
535Nmap done: 1 IP address (1 host up) scanned in 1.30 seconds
536
537
538
539
540Cms Scan 'www.michiganmasons.org'
541------------------------------------
542
543[+] Cms : Mura CMS
544[+] Web Servers : IIS
545[+] Programming Languages : CFML
546
547
548
549
550
551Robot.txt 'www.michiganmasons.org'
552-------------------------------------
553
554User-agent: *
555Crawl-Delay: 5
556Allow: /requirements/fullcalendar
557Allow: /requirements/prettify
558Disallow: /admin/
559Disallow: /tasks/
560Disallow: /requirements/
561Disallow: /config/
562
563
564
565
566Traceroute 'www.michiganmasons.org'
567--------------------------------------
568
569Start: 2019-10-12T12:45:52+0000
570HOST: web01 Loss% Snt Last Avg Best Wrst StDev
571 1.|-- 45.79.12.201 0.0% 3 0.6 0.7 0.6 0.9 0.2
572 2.|-- 45.79.12.0 0.0% 3 0.5 0.6 0.5 0.8 0.2
573 3.|-- 45.79.12.9 0.0% 3 0.7 17.4 0.7 39.6 20.0
574 4.|-- dls-b22-link.telia.net 0.0% 3 1.0 1.0 0.9 1.0 0.0
575 5.|-- kanc-b1-link.telia.net 0.0% 3 12.8 12.9 12.2 13.8 0.8
576 6.|-- chi-b21-link.telia.net 0.0% 3 24.4 24.5 24.4 24.6 0.1
577 7.|-- hurricane-ic-350465-chi-b21.c.telia.net 0.0% 3 25.9 24.5 23.7 25.9 1.3
578 8.|-- 216.66.76.146 0.0% 3 31.6 31.6 31.5 31.6 0.1
579 9.|-- 216.111.200.58 0.0% 3 33.1 33.3 33.0 33.9 0.5
580 10.|-- ??? 100.0 3 0.0 0.0 0.0 0.0 0.0
581
582
583
584Page Admin Finder 'www.michiganmasons.org'
585---------------------------------------------
586
587
588
589Avilable Links :
590
591Find Page >> http://www.michiganmasons.org/admin/
592
593Find Page >> http://www.michiganmasons.org/admin/index.cfm
594
595#######################################################################################################################################
596[*] Load target domain: www.michiganmasons.org
597 - starting scanning @ 2019-10-12 08:51:19
598
599[+] Running & Checking source to be used
600---------------------------------------------
601
602 ⍥ Shodan [ ✕ ]
603 ⍥ Webarchive [ ✔ ]
604 ⍥ Dnsdumpster [ ✔ ]
605 ⍥ Certspotter [ ✔ ]
606 ⍥ Certsh [ ✔ ]
607 ⍥ Bufferover [ ✔ ]
608 ⍥ Threatminer [ ✔ ]
609 ⍥ Censys [ ✕ ]
610 ⍥ Securitytrails [ ✕ ]
611 ⍥ Binaryedge [ ✕ ]
612 ⍥ Hackertarget [ ✔ ]
613 ⍥ Threatcrowd [ ✔ ]
614 ⍥ Riddler [ ✔ ]
615 ⍥ Entrust [ ✔ ]
616 ⍥ Virustotal [ ✕ ]
617jq: error (at <stdin>:16): Cannot iterate over null (null)
618jq: error (at <stdin>:0): Cannot iterate over null (null)
619 ⍥ Findsubdomain [ ✔ ]
620
621[+] Get & Count subdomain total From source
622---------------------------------------------
623
624 ⍥ Hackertarget: Total Subdomain (1)
625 ⍥ Findsubdomain: Total Subdomain (0)
626 ⍥ Certspotter: Total Subdomain (13)
627 ⍥ Threatminer: Total Subdomain (0)
628 ⍥ Certsh: Total Subdomain (0)
629 ⍥ BufferOver: Total Subdomain (0)
630 ⍥ Entrust: Total Subdomain (1)
631 ⍥ Threatcrowd: Total Subdomain (0)
632 ⍥ Dnsdumpster: Total Subdomain (5)
633 ⍥ Riddler: Total Subdomain (0)
634 ⍥ Webarchive: Total Subdomain (2)
635
636[+] Parsing & Sorting list Domain
637---------------------------------------------
638
639 ⍥ Total [1]
640
641 - www.michiganmasons.org
642
643 ⍥ Total [1]
644
645[+] Probe subdomain for working on http/https
646---------------------------------------------
647
648 - http://www.michiganmasons.org
649 - https://www.michiganmasons.org
650
651 ⍥ Total [2]
652
653
654[+] Check Live Host: Ping Sweep - ICMP PING
655---------------------------------------------
656
657 ⍥ [DEAD] www.michiganmasons.org
658
659[+] Check Resolving: Subdomains & Domains
660---------------------------------------------
661
662 ⍥ Resolving domains to: 67.209.250.173
663
664[+] Subdomain TakeOver - Check Possible Vulns
665---------------------------------------------
666
667 ⍥ [FAILS] En: Unknown http://www.michiganmasons.org
668 ⍥ [FAILS] En: Unknown https://www.michiganmasons.org
669
670[+] Checks status code on port 80 and 443
671---------------------------------------------
672
673 ⍥ [301] http://www.michiganmasons.org
674 ⍥ [200] https://www.michiganmasons.org
675
676[+] Web Screenshots: from domain list
677---------------------------------------------
678
679[+] 2 URLs to be screenshot
680
681[+] 2 actual URLs screenshot
682[+] 0 error(s)
683
684[+] Sud⍥my has been sucessfully completed
685---------------------------------------------
686
687 ⍥ Location output:
688 - output/10-12-2019/www.michiganmasons.org
689 - output/10-12-2019/www.michiganmasons.org/report
690 - output/10-12-2019/www.michiganmasons.org/screenshots
691
692#######################################################################################################################################
693[INFO] ------TARGET info------
694[*] TARGET: https://www.michiganmasons.org/
695[*] TARGET IP: 67.209.250.173
696[INFO] NO load balancer detected for www.michiganmasons.org...
697[*] DNS servers: michiganmasons.org.
698[*] TARGET server: Microsoft-IIS/8.5
699[*] CC: US
700[*] Country: United States
701[*] RegionCode: MI
702[*] RegionName: Michigan
703[*] City: Alma
704[*] ASN: AS17143
705[*] BGP_PREFIX: 67.209.240.0/20
706[*] ISP: WINNTELECOM - Winn Telecom, US
707[INFO] SSL/HTTPS certificate detected
708[*] Issuer: issuer=C = US, ST = Arizona, L = Scottsdale, O = "Starfield Technologies, Inc.", OU = http://certs.starfieldtech.com/repository/, CN = Starfield Secure Certificate Authority - G2
709[*] Subject: subject=OU = Domain Control Validated, CN = www.grandlodgemi.org
710[INFO] DNS enumeration:
711[*] ftp.michiganmasons.org michiganmasons.org. 67.209.250.173
712[*] mail.michiganmasons.org 67.209.250.204
713[*] webmail.michiganmasons.org 67.209.250.204
714[INFO] Possible abuse mails are:
715[*] abuse@michiganmasons.org
716[*] abuse@www.michiganmasons.org
717[INFO] NO PAC (Proxy Auto Configuration) file FOUND
718[ALERT] robots.txt file FOUND in http://www.michiganmasons.org/robots.txt
719[INFO] Checking for HTTP status codes recursively from http://www.michiganmasons.org/robots.txt
720[INFO] Status code Folders
721[*] 200 http://www.michiganmasons.org/admin/
722[*] 200 http://www.michiganmasons.org/tasks/
723[INFO] Starting FUZZing in http://www.michiganmasons.org/FUzZzZzZzZz...
724[INFO] Status code Folders
725[ALERT] Look in the source code. It may contain passwords
726[INFO] Links found from https://www.michiganmasons.org/ http://67.209.250.173/:
727[*] https://twitter.com/GLofMichigan
728[*] https://www.facebook.com/MichiganMasons
729[*] https://www.google.com/calendar/embed?showTitle=0&showPrint=0&showTabs=0&showCalendars=0&mode=AGENDA&height=250&wkst=1&bgcolor=#FFFFFF&src=michiganmasons@gmail.com&color=#865A5A&ctz=America/New_York
730[*] https://www.michiganmasons.org/
731[*] https://www.michiganmasons.org/about/
732[*] https://www.michiganmasons.org/about/basics-of-freemasonry/
733[*] https://www.michiganmasons.org/about/history-of-freemasonry/
734[*] https://www.michiganmasons.org/about/masonic-symbols/
735[*] https://www.michiganmasons.org/about/masons-live-better/
736[*] https://www.michiganmasons.org/about/philosophy-and-beliefs/
737[*] https://www.michiganmasons.org/about/photo-gallery/
738[*] https://www.michiganmasons.org/about/share-the-secret/
739[*] https://www.michiganmasons.org/about/who-are-masons/
740[*] https://www.michiganmasons.org/contact/
741[*] https://www.michiganmasons.org/faq/
742[*] https://www.michiganmasons.org/faq/leadership/
743[*] https://www.michiganmasons.org/faq/masonic-pathways/
744[*] https://www.michiganmasons.org/faq/michigan-masons/
745[*] https://www.michiganmasons.org/faq/personal-growth/
746[*] https://www.michiganmasons.org/faq/questions-about-freemasonry/
747[*] https://www.michiganmasons.org/faq/s-a-y-detroit/
748[*] https://www.michiganmasons.org/join/
749[*] https://www.michiganmasons.org/join/joining-a-lodge/
750[*] https://www.michiganmasons.org/join/joining-a-masonic-lodge/
751[*] https://www.michiganmasons.org/join/request-more-info/
752[*] https://www.michiganmasons.org/locations/
753[*] https://www.michiganmasons.org/locations/lodge-directions/
754[*] https://www.michiganmasons.org/locations/lodges-in-michigan/
755[*] https://www.michiganmasons.org/#myModal
756[*] https://www.michiganmasons.org/privacy/
757[*] https://www.michiganmasons.org/site-map/
758[*] https://www.michiganmasons.org/what-we-do/
759[*] https://www.michiganmasons.org/what-we-do/beacon-project/
760[*] https://www.michiganmasons.org/what-we-do/books-for-bikes/
761[*] https://www.michiganmasons.org/what-we-do/calendar-of-events/
762[*] https://www.michiganmasons.org/what-we-do/community-outreach/
763[*] https://www.michiganmasons.org/what-we-do/michigan-child-id-program/
764[*] https://www.michiganmasons.org/what-we-do/scholarship-and-grants/
765[*] https://www.michiganmasons.org/what-we-do/student-assistance/
766[*] https://www.michiganmasons.org/what-we-do/video-links/
767[*] https://www.youtube.com/user/michiganmasons
768[*] http://visitor.r20.constantcontact.com/manage/optin?v=001ZaS58ajNOw3eQGQVjbQcXALJWFk-PywwtMdGCoVJE_VVmOpEhhScSRD7WdvuqMbPUU8iPXXytZKzh_mYFRy64A==
769[INFO] GOOGLE has 11,100 results (0.25 seconds) about http://www.michiganmasons.org/
770[INFO] Shodan detected the following opened ports on 67.209.250.173:
771[*] 0
772[*] 443
773[*] 80
774[INFO] ------VirusTotal SECTION------
775[INFO] VirusTotal passive DNS only stores address records. The following domains resolved to the given IP address:
776[INFO] Latest URLs hosted in this IP address detected by at least one URL scanner or malicious URL dataset:
777[INFO] Latest files that are not detected by any antivirus solution and were downloaded by VirusTotal from the IP address provided:
778[INFO] ------Alexa Rank SECTION------
779[INFO] Percent of Visitors Rank in Country:
780[INFO] Percent of Search Traffic:
781[INFO] Percent of Unique Visits:
782[INFO] Total Sites Linking In:
783[*] Total Sites
784[INFO] Useful links related to www.michiganmasons.org - 67.209.250.173:
785[*] https://www.virustotal.com/pt/ip-address/67.209.250.173/information/
786[*] https://www.hybrid-analysis.com/search?host=67.209.250.173
787[*] https://www.shodan.io/host/67.209.250.173
788[*] https://www.senderbase.org/lookup/?search_string=67.209.250.173
789[*] https://www.alienvault.com/open-threat-exchange/ip/67.209.250.173
790[*] http://pastebin.com/search?q=67.209.250.173
791[*] http://urlquery.net/search.php?q=67.209.250.173
792[*] http://www.alexa.com/siteinfo/www.michiganmasons.org
793[*] http://www.google.com/safebrowsing/diagnostic?site=www.michiganmasons.org
794[*] https://censys.io/ipv4/67.209.250.173
795[*] https://www.abuseipdb.com/check/67.209.250.173
796[*] https://urlscan.io/search/#67.209.250.173
797[*] https://github.com/search?q=67.209.250.173&type=Code
798[INFO] Useful links related to AS17143 - 67.209.240.0/20:
799[*] http://www.google.com/safebrowsing/diagnostic?site=AS:17143
800[*] https://www.senderbase.org/lookup/?search_string=67.209.240.0/20
801[*] http://bgp.he.net/AS17143
802[*] https://stat.ripe.net/AS17143
803[INFO] Date: 12/10/19 | Time: 08:52:14
804[INFO] Total time: 0 minute(s) and 52 second(s)
805#######################################################################################################################################
806Trying "michiganmasons.org"
807;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 61245
808;; flags: qr rd ra; QUERY: 1, ANSWER: 7, AUTHORITY: 2, ADDITIONAL: 4
809
810;; QUESTION SECTION:
811;michiganmasons.org. IN ANY
812
813;; ANSWER SECTION:
814michiganmasons.org. 1800 IN TXT "v=spf1 mx ip4:67.209.250.165/32 ip4:67.209.250.166/32 ip4:207.241.128.23/32 -all"
815michiganmasons.org. 1800 IN MX 10 mx1.cmsinter.net.
816michiganmasons.org. 1800 IN MX 20 d22800a.ess.barracudanetworks.com.
817michiganmasons.org. 3600 IN SOA ns11.domaincontrol.com. dns.jomax.net. 2019040200 28800 7200 604800 3600
818michiganmasons.org. 3600 IN A 67.209.250.173
819michiganmasons.org. 3600 IN NS ns12.domaincontrol.com.
820michiganmasons.org. 3600 IN NS ns11.domaincontrol.com.
821
822;; AUTHORITY SECTION:
823michiganmasons.org. 3600 IN NS ns12.domaincontrol.com.
824michiganmasons.org. 3600 IN NS ns11.domaincontrol.com.
825
826;; ADDITIONAL SECTION:
827ns11.domaincontrol.com. 8384 IN A 97.74.105.6
828ns11.domaincontrol.com. 7552 IN AAAA 2603:5:2190::6
829ns12.domaincontrol.com. 8384 IN A 173.201.73.6
830ns12.domaincontrol.com. 39527 IN AAAA 2603:5:2290::6
831
832Received 440 bytes from 2001:18c0:121:6900:724f:b8ff:fefd:5b6a#53 in 81 ms
833#######################################################################################################################################
834
835; <<>> DiG 9.11.5-P4-5.1+b1-Debian <<>> +trace michiganmasons.org
836;; global options: +cmd
837. 86122 IN NS g.root-servers.net.
838. 86122 IN NS b.root-servers.net.
839. 86122 IN NS c.root-servers.net.
840. 86122 IN NS d.root-servers.net.
841. 86122 IN NS f.root-servers.net.
842. 86122 IN NS i.root-servers.net.
843. 86122 IN NS m.root-servers.net.
844. 86122 IN NS l.root-servers.net.
845. 86122 IN NS k.root-servers.net.
846. 86122 IN NS j.root-servers.net.
847. 86122 IN NS a.root-servers.net.
848. 86122 IN NS h.root-servers.net.
849. 86122 IN NS e.root-servers.net.
850. 86122 IN RRSIG NS 8 0 518400 20191025050000 20191012040000 22545 . gWH4QXRDAA/uXyfoerYe5dJ0yqiuSE95/+sVlUjhrB0Lh7l9zeOpCHon 04RKagHpE2zSeMEAnp3Rix8V+oLH3R8CzbOGCr+wQ04UMvKrxkIPGlZD MDJ0m1NDVWjiobKbcaPulTDQZdB+0anG/WQv+PBs7Gn9M3Hzk+cS6gnj oV2J4cwEK56OrrW7ticJByBtz00Rhz+hN+964FNZdg8Mdmz1QgCOu9MO 8rsR7JLHFv//9az0K5ntLv7SPKV2rN5hWqwAeiR66/4nPPEB1BuLC4OB dviHoX/gGJdyefy+toOTGG23coYbxk5ovi8St4jOwAQD1J7ppFWEbDEf yF14vg==
851;; Received 525 bytes from 38.132.106.139#53(38.132.106.139) in 49 ms
852
853org. 172800 IN NS b0.org.afilias-nst.org.
854org. 172800 IN NS b2.org.afilias-nst.org.
855org. 172800 IN NS d0.org.afilias-nst.org.
856org. 172800 IN NS a0.org.afilias-nst.info.
857org. 172800 IN NS c0.org.afilias-nst.info.
858org. 172800 IN NS a2.org.afilias-nst.info.
859org. 86400 IN DS 9795 7 1 364DFAB3DAF254CAB477B5675B10766DDAA24982
860org. 86400 IN DS 9795 7 2 3922B31B6F3A4EA92B19EB7B52120F031FD8E05FF0B03BAFCF9F891B FE7FF8E5
861org. 86400 IN RRSIG DS 8 1 86400 20191025050000 20191012040000 22545 . SSi7C1mZS4ucsPWnu+fVWj+3sKuolaTQR60FOUJ1buhWXlkZ95BdLWIQ VXOg8Nqo9ZKT8ktXcWrBjCWOwpN1iRMFKgd08XP6+RVqkXmRou6J9Jvo tBj9cDwVE/9Q0zrsqa89MDgM8MHSsBYD4bCsNRhUj1CVdgfUC7lKoWUW sbpfAYqrMgbwiQ/gKu5hALnZsUXgU5DQ8AGM/PZbMB0H3CborhdEpt/D 3L3rlb4e5CWwuJfjcZOcXufI5S8nQDjHfmo62Q8UVt7mM+v5KvMITxia EefafnCUWm7Qk6LE50rPhomEBSLo9/ZjtJ10AMdF1jH1jqbdr9EPismV 3Nrw0g==
862;; Received 848 bytes from 192.112.36.4#53(g.root-servers.net) in 51 ms
863
864michiganmasons.org. 86400 IN NS ns12.domaincontrol.com.
865michiganmasons.org. 86400 IN NS ns11.domaincontrol.com.
866h9p7u7tr2u91d0v0ljs9l1gidnp90u3h.org. 86400 IN NSEC3 1 1 1 D399EAAB H9PARR669T6U8O1GSG9E1LMITK4DEM0T NS SOA RRSIG DNSKEY NSEC3PARAM
867h9p7u7tr2u91d0v0ljs9l1gidnp90u3h.org. 86400 IN RRSIG NSEC3 7 2 86400 20191102130047 20191012120047 36752 org. AptuzDYURj7zhlKGH31L1TzS5SW5nAd1A/7GRWuRfTGSI4ckhWPFdZL3 6duit1qpE6i40SiL8uyURjNdwi64DziG2t4CxhpfS4wrzmZ0qarslcxv zhdpYO8MrkAnzSvGecBZaRifpoMC8epLPpNQKPsYeU/BSoIeRyyz1dqS eJE=
868qiuvaqji8f10qqv89nf0996ev08bf2qj.org. 86400 IN NSEC3 1 1 1 D399EAAB QJ05E3RSUSBHS2GC5GBAVSO1KE5817DG A RRSIG
869qiuvaqji8f10qqv89nf0996ev08bf2qj.org. 86400 IN RRSIG NSEC3 7 2 86400 20191030152851 20191009142851 36752 org. AtlRoDYgFIjauVjq5TZJCpPhNEXD9jv3/ba6jTRZ0sK3+urj6a4PuTm6 OLYruZDeLEyf3yORD+HGS5Nwmy6lYXtTep3njUM+E94gP90K3CMnL3Ck VccUIrQRiz7zXRhPXwNufBPAQypK1+ZKBptnejXeOtG57xLifsdje2Ez 5l8=
870;; Received 595 bytes from 2001:500:b::1#53(c0.org.afilias-nst.info) in 174 ms
871
872michiganmasons.org. 3600 IN A 67.209.250.173
873michiganmasons.org. 3600 IN NS ns11.domaincontrol.com.
874michiganmasons.org. 3600 IN NS ns12.domaincontrol.com.
875;; Received 118 bytes from 97.74.105.6#53(ns11.domaincontrol.com) in 35 ms
876#######################################################################################################################################
877[*] Performing General Enumeration of Domain: michiganmasons.org
878[-] DNSSEC is not configured for michiganmasons.org
879[*] SOA ns11.domaincontrol.com 97.74.105.6
880[*] NS ns12.domaincontrol.com 173.201.73.6
881[*] NS ns12.domaincontrol.com 2603:5:2290::6
882[*] NS ns11.domaincontrol.com 97.74.105.6
883[*] NS ns11.domaincontrol.com 2603:5:2190::6
884[*] MX mx1.cmsinter.net 207.241.128.7
885[*] MX d22800a.ess.barracudanetworks.com 209.222.82.126
886[*] MX d22800a.ess.barracudanetworks.com 209.222.82.132
887[*] MX d22800a.ess.barracudanetworks.com 209.222.82.138
888[*] MX d22800a.ess.barracudanetworks.com 209.222.82.147
889[*] MX d22800a.ess.barracudanetworks.com 209.222.82.156
890[*] MX d22800a.ess.barracudanetworks.com 209.222.82.150
891[*] MX d22800a.ess.barracudanetworks.com 209.222.82.141
892[*] MX d22800a.ess.barracudanetworks.com 209.222.82.153
893[*] MX d22800a.ess.barracudanetworks.com 209.222.82.162
894[*] MX d22800a.ess.barracudanetworks.com 209.222.82.165
895[*] MX d22800a.ess.barracudanetworks.com 209.222.82.159
896[*] MX d22800a.ess.barracudanetworks.com 209.222.82.144
897[*] MX d22800a.ess.barracudanetworks.com 209.222.82.129
898[*] MX d22800a.ess.barracudanetworks.com 209.222.82.135
899[*] A michiganmasons.org 67.209.250.173
900[*] TXT michiganmasons.org v=spf1 mx ip4:67.209.250.165/32 ip4:67.209.250.166/32 ip4:207.241.128.23/32 -all
901[*] Enumerating SRV Records
902[-] No SRV Records Found for michiganmasons.org
903[+] 0 Records Found
904#######################################################################################################################################
905[*] Processing domain michiganmasons.org
906[*] Using system resolvers ['38.132.106.139', '194.187.251.67', '185.93.180.131', '2001:18c0:121:6900:724f:b8ff:fefd:5b6a', '192.168.0.1']
907[+] Getting nameservers
908173.201.73.6 - ns12.domaincontrol.com
90997.74.105.6 - ns11.domaincontrol.com
910[-] Zone transfer failed
911
912[+] TXT records found
913"v=spf1 mx ip4:67.209.250.165/32 ip4:67.209.250.166/32 ip4:207.241.128.23/32 -all"
914
915[+] MX records found, added to target list
91610 mx1.cmsinter.net.
91720 d22800a.ess.barracudanetworks.com.
918
919[*] Scanning michiganmasons.org for A records
92067.209.250.173 - michiganmasons.org
92167.209.250.166 - autodiscover.michiganmasons.org
92267.209.250.173 - contacts.michiganmasons.org
92367.209.250.181 - data.michiganmasons.org
92467.209.250.173 - ftp.michiganmasons.org
92567.209.250.204 - imap.michiganmasons.org
92667.209.250.204 - mail.michiganmasons.org
92767.209.250.204 - pop3.michiganmasons.org
92867.209.250.204 - smtp.michiganmasons.org
92967.209.250.204 - webmail.michiganmasons.org
93067.209.250.173 - www.michiganmasons.org
931#######################################################################################################################################
932Parsero scan report for www.michiganmasons.org
933http://www.michiganmasons.org/requirements/ 403 Forbidden
934http://www.michiganmasons.org/admin/ 302 Found
935http://www.michiganmasons.org/tasks/ 200 OK
936http://www.michiganmasons.org/config/ 403 Forbidden
937##########################################################################################################################################
938
939
940 AVAILABLE PLUGINS
941 -----------------
942
943 EarlyDataPlugin
944 SessionRenegotiationPlugin
945 CertificateInfoPlugin
946 OpenSslCipherSuitesPlugin
947 HeartbleedPlugin
948 RobotPlugin
949 HttpHeadersPlugin
950 SessionResumptionPlugin
951 OpenSslCcsInjectionPlugin
952 CompressionPlugin
953 FallbackScsvPlugin
954
955
956
957 CHECKING HOST(S) AVAILABILITY
958 -----------------------------
959
960 67.209.250.173:443 => 67.209.250.173
961
962
963
964
965 SCAN RESULTS FOR 67.209.250.173:443 - 67.209.250.173
966 ----------------------------------------------------
967
968 * SSLV2 Cipher Suites:
969 Server rejected all cipher suites.
970
971 * Downgrade Attacks:
972 TLS_FALLBACK_SCSV: VULNERABLE - Signaling cipher suite not supported
973
974 * Deflate Compression:
975 OK - Compression disabled
976
977 * TLSV1_3 Cipher Suites:
978 Server rejected all cipher suites.
979
980 * Session Renegotiation:
981 Client-initiated Renegotiation: OK - Rejected
982 Secure Renegotiation: OK - Supported
983
984 * TLS 1.2 Session Resumption Support:
985 With Session IDs: OK - Supported (5 successful, 0 failed, 0 errors, 5 total attempts).
986 With TLS Tickets: NOT SUPPORTED - TLS ticket not assigned.
987
988 * TLSV1_2 Cipher Suites:
989 Forward Secrecy OK - Supported
990 RC4 INSECURE - Supported
991
992 Preferred:
993 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 256 bits HTTP 404 Not Found
994 Accepted:
995 TLS_RSA_WITH_RC4_128_SHA 128 bits HTTP 404 Not Found
996 TLS_RSA_WITH_RC4_128_MD5 128 bits HTTP 404 Not Found
997 TLS_RSA_WITH_AES_256_GCM_SHA384 256 bits HTTP 404 Not Found
998 TLS_RSA_WITH_AES_256_CBC_SHA256 256 bits HTTP 404 Not Found
999 TLS_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 404 Not Found
1000 TLS_RSA_WITH_AES_128_GCM_SHA256 128 bits HTTP 404 Not Found
1001 TLS_RSA_WITH_AES_128_CBC_SHA256 128 bits HTTP 404 Not Found
1002 TLS_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 404 Not Found
1003 TLS_RSA_WITH_3DES_EDE_CBC_SHA 112 bits HTTP 404 Not Found
1004 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 256 bits HTTP 404 Not Found
1005 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 404 Not Found
1006 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 128 bits HTTP 404 Not Found
1007 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 404 Not Found
1008 TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 256 bits HTTP 404 Not Found
1009 TLS_DHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 404 Not Found
1010 TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 128 bits HTTP 404 Not Found
1011 TLS_DHE_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 404 Not Found
1012
1013 * TLSV1_1 Cipher Suites:
1014 Forward Secrecy OK - Supported
1015 RC4 INSECURE - Supported
1016
1017 Preferred:
1018 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 404 Not Found
1019 Accepted:
1020 TLS_RSA_WITH_RC4_128_SHA 128 bits HTTP 404 Not Found
1021 TLS_RSA_WITH_RC4_128_MD5 128 bits HTTP 404 Not Found
1022 TLS_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 404 Not Found
1023 TLS_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 404 Not Found
1024 TLS_RSA_WITH_3DES_EDE_CBC_SHA 112 bits HTTP 404 Not Found
1025 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 404 Not Found
1026 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 404 Not Found
1027 TLS_DHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 404 Not Found
1028 TLS_DHE_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 404 Not Found
1029
1030 * OpenSSL Heartbleed:
1031 OK - Not vulnerable to Heartbleed
1032
1033 * Certificate Information:
1034 Content
1035 SHA1 Fingerprint: e0a9130d7691f74514ed63463fae05f737094e32
1036 Common Name: www.grandlodgemi.org
1037 Issuer: Starfield Secure Certificate Authority - G2
1038 Serial Number: 6400074294016695764
1039 Not Before: 2018-12-20 10:28:44
1040 Not After: 2021-02-18 20:52:40
1041 Signature Algorithm: sha256
1042 Public Key Algorithm: RSA
1043 Key Size: 2048
1044 Exponent: 65537 (0x10001)
1045 DNS Subject Alternative Names: ['www.grandlodgemi.org', 'grandlodgemi.org', 'www.sharethesecret.org', 'michiganchildid.org', 'mds.grandlodgemi.org', 'qr.grandlodgemi.org', 'data.michiganmasons.org', 'sharethesecret.org', 'contacts.michiganmasons.org', 'search.grandlodgemi.org', 'www.michiganchildid.org', 'www.michiganmasons.org', 'michiganmasons.org']
1046
1047 Trust
1048 Hostname Validation: FAILED - Certificate does NOT match 67.209.250.173
1049 Android CA Store (9.0.0_r9): OK - Certificate is trusted
1050 Apple CA Store (iOS 12, macOS 10.14, watchOS 5, and tvOS 12):OK - Certificate is trusted
1051 Java CA Store (jdk-12.0.1): OK - Certificate is trusted
1052 Mozilla CA Store (2019-03-14): OK - Certificate is trusted
1053 Windows CA Store (2019-05-27): OK - Certificate is trusted
1054 Symantec 2018 Deprecation: WARNING: Certificate distrusted by Google and Mozilla on September 2018
1055 Received Chain: www.grandlodgemi.org --> Starfield Secure Certificate Authority - G2 --> Starfield Root Certificate Authority - G2
1056 Verified Chain: www.grandlodgemi.org --> Starfield Secure Certificate Authority - G2 --> Starfield Root Certificate Authority - G2
1057 Received Chain Contains Anchor: OK - Anchor certificate not sent
1058 Received Chain Order: OK - Order is valid
1059 Verified Chain contains SHA1: OK - No SHA1-signed certificate in the verified certificate chain
1060
1061 Extensions
1062 OCSP Must-Staple: NOT SUPPORTED - Extension not found
1063 Certificate Transparency: OK - 3 SCTs included
1064
1065 OCSP Stapling
1066 OCSP Response Status: successful
1067 Validation w/ Mozilla Store: OK - Response is trusted
1068 Responder Id: C = US, ST = Arizona, L = Scottsdale, O = "Starfield Technologies, LLC", CN = Starfield Validation Authority - G2
1069 Cert Status: good
1070 Cert Serial Number: 58D1A1A94EF95DD4
1071 This Update: Oct 11 12:38:19 2019 GMT
1072 Next Update: Oct 13 00:38:19 2019 GMT
1073
1074 * TLSV1 Cipher Suites:
1075 Forward Secrecy OK - Supported
1076 RC4 INSECURE - Supported
1077
1078 Preferred:
1079 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA 256 bits Error sending HTTP GET
1080 Accepted:
1081 TLS_RSA_WITH_RC4_128_SHA 128 bits HTTP 404 Not Found
1082 TLS_RSA_WITH_RC4_128_MD5 128 bits HTTP 404 Not Found
1083 TLS_RSA_WITH_AES_256_CBC_SHA 256 bits Error sending HTTP GET
1084 TLS_RSA_WITH_AES_128_CBC_SHA 128 bits Error sending HTTP GET
1085 TLS_RSA_WITH_3DES_EDE_CBC_SHA 112 bits Error sending HTTP GET
1086 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA 256 bits Error sending HTTP GET
1087 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA 128 bits Error sending HTTP GET
1088 TLS_DHE_RSA_WITH_AES_256_CBC_SHA 256 bits Error sending HTTP GET
1089 TLS_DHE_RSA_WITH_AES_128_CBC_SHA 128 bits Error sending HTTP GET
1090
1091 * OpenSSL CCS Injection:
1092 OK - Not vulnerable to OpenSSL CCS injection
1093
1094 * SSLV3 Cipher Suites:
1095 Forward Secrecy INSECURE - Not Supported
1096 RC4 INSECURE - Supported
1097
1098 Preferred:
1099 TLS_RSA_WITH_3DES_EDE_CBC_SHA 112 bits Error sending HTTP GET
1100 Accepted:
1101 TLS_RSA_WITH_RC4_128_SHA 128 bits HTTP 404 Not Found
1102 TLS_RSA_WITH_RC4_128_MD5 128 bits HTTP 404 Not Found
1103 TLS_RSA_WITH_3DES_EDE_CBC_SHA 112 bits Error sending HTTP GET
1104
1105 * ROBOT Attack:
1106 OK - Not vulnerable
1107
1108
1109 SCAN COMPLETED IN 18.98 S
1110 -------------------------
1111#######################################################################################################################################
1112
1113
1114Domains still to check: 1
1115 Checking if the hostname michiganmasons.org. given is in fact a domain...
1116
1117Analyzing domain: michiganmasons.org.
1118 Checking NameServers using system default resolver...
1119 IP: 173.201.73.6 (United States)
1120 HostName: ns12.domaincontrol.com Type: NS
1121 HostName: ns12.domaincontrol.com Type: PTR
1122 IP: 97.74.105.6 (United States)
1123 HostName: ns11.domaincontrol.com Type: NS
1124 HostName: ns11.domaincontrol.com Type: PTR
1125
1126 Checking MailServers using system default resolver...
1127 IP: 207.241.128.7 (United States)
1128 HostName: mx1.cmsinter.net Type: MX
1129 HostName: mx1.cmsinter.net Type: PTR
1130 IP: 209.222.82.135 (United States)
1131 HostName: d22800a.ess.barracudanetworks.com Type: MX
1132 HostName: mail.ess.barracuda.com Type: PTR
1133 IP: 209.222.82.126 (United States)
1134 HostName: d22800a.ess.barracudanetworks.com Type: MX
1135 HostName: mail.ess.barracuda.com Type: PTR
1136 IP: 209.222.82.138 (United States)
1137 HostName: d22800a.ess.barracudanetworks.com Type: MX
1138 HostName: mail.ess.barracuda.com Type: PTR
1139 IP: 209.222.82.159 (United States)
1140 HostName: d22800a.ess.barracudanetworks.com Type: MX
1141 HostName: mail.ess.barracuda.com Type: PTR
1142 IP: 209.222.82.132 (United States)
1143 HostName: d22800a.ess.barracudanetworks.com Type: MX
1144 HostName: mail.ess.barracuda.com Type: PTR
1145 IP: 209.222.82.150 (United States)
1146 HostName: d22800a.ess.barracudanetworks.com Type: MX
1147 HostName: mail.ess.barracuda.com Type: PTR
1148 IP: 209.222.82.141 (United States)
1149 HostName: d22800a.ess.barracudanetworks.com Type: MX
1150 HostName: mail.ess.barracuda.com Type: PTR
1151 IP: 209.222.82.147 (United States)
1152 HostName: d22800a.ess.barracudanetworks.com Type: MX
1153 HostName: mail.ess.barracuda.com Type: PTR
1154 IP: 209.222.82.165 (United States)
1155 HostName: d22800a.ess.barracudanetworks.com Type: MX
1156 HostName: mail.ess.barracuda.com Type: PTR
1157 IP: 209.222.82.162 (United States)
1158 HostName: d22800a.ess.barracudanetworks.com Type: MX
1159 HostName: mail.ess.barracuda.com Type: PTR
1160 IP: 209.222.82.144 (United States)
1161 HostName: d22800a.ess.barracudanetworks.com Type: MX
1162 HostName: mail.ess.barracuda.com Type: PTR
1163 IP: 209.222.82.129 (United States)
1164 HostName: d22800a.ess.barracudanetworks.com Type: MX
1165 HostName: mail.ess.barracuda.com Type: PTR
1166 IP: 209.222.82.156 (United States)
1167 HostName: d22800a.ess.barracudanetworks.com Type: MX
1168 HostName: mail.ess.barracuda.com Type: PTR
1169 IP: 209.222.82.153 (United States)
1170 HostName: d22800a.ess.barracudanetworks.com Type: MX
1171 HostName: mail.ess.barracuda.com Type: PTR
1172
1173 Checking the zone transfer for each NS... (if this takes more than 10 seconds, just hit CTRL-C and it will continue. Bug in the libs)
1174 No zone transfer found on nameserver 173.201.73.6
1175 No zone transfer found on nameserver 97.74.105.6
1176
1177 Checking SPF record...
1178 WARNING! SPF record allows an entire network to send mails. Probably an ISP network. We are not going to check the entire network by now: 67.209.250.165/32, but only the network IP
1179 New IP found: 67.209.250.165
1180 WARNING! SPF record allows an entire network to send mails. Probably an ISP network. We are not going to check the entire network by now: 67.209.250.166/32, but only the network IP
1181 New IP found: 67.209.250.166
1182 WARNING! SPF record allows an entire network to send mails. Probably an ISP network. We are not going to check the entire network by now: 207.241.128.23/32, but only the network IP
1183 New IP found: 207.241.128.23
1184
1185 Checking 192 most common hostnames using system default resolver...
1186 IP: 67.209.250.173 (United States)
1187 HostName: www.michiganmasons.org. Type: A
1188 IP: 67.209.250.173 (United States)
1189 HostName: www.michiganmasons.org. Type: A
1190 HostName: ftp.michiganmasons.org. Type: A
1191 HostName: a67-209-250-173.cust.mi.winntel.net Type: PTR
1192 IP: 67.209.250.204 (United States)
1193 HostName: mail.michiganmasons.org. Type: A
1194 IP: 67.209.250.204 (United States)
1195 HostName: mail.michiganmasons.org. Type: A
1196 HostName: webmail.michiganmasons.org. Type: A
1197 HostName: web-2-204.winntel.com Type: PTR
1198 IP: 67.209.250.204 (United States)
1199 HostName: mail.michiganmasons.org. Type: A
1200 HostName: webmail.michiganmasons.org. Type: A
1201 HostName: web-2-204.winntel.com Type: PTR
1202 HostName: smtp.michiganmasons.org. Type: A
1203 IP: 67.209.250.204 (United States)
1204 HostName: mail.michiganmasons.org. Type: A
1205 HostName: webmail.michiganmasons.org. Type: A
1206 HostName: web-2-204.winntel.com Type: PTR
1207 HostName: smtp.michiganmasons.org. Type: A
1208 HostName: imap.michiganmasons.org. Type: A
1209 IP: 67.209.250.204 (United States)
1210 HostName: mail.michiganmasons.org. Type: A
1211 HostName: webmail.michiganmasons.org. Type: A
1212 HostName: web-2-204.winntel.com Type: PTR
1213 HostName: smtp.michiganmasons.org. Type: A
1214 HostName: imap.michiganmasons.org. Type: A
1215 HostName: pop3.michiganmasons.org. Type: A
1216
1217 Checking with nmap the reverse DNS hostnames of every <ip>/24 netblock using system default resolver...
1218 Checking netblock 209.222.82.0
1219 Checking netblock 67.209.250.0
1220 Checking netblock 207.241.128.0
1221 Checking netblock 173.201.73.0
1222 Checking netblock 97.74.105.0
1223
1224 Searching for michiganmasons.org. emails in Google
1225 robertconley@michiganmasons.org
1226 robertconley@michiganmasons.org.
1227
1228 Checking 22 active hosts using nmap... (nmap -sn -n -v -PP -PM -PS80,25 -PA -PY -PU53,40125 -PE --reason <ip> -oA <output_directory>/nmap/<ip>.sn)
1229 Host 209.222.82.144 is up (echo-reply ttl 43)
1230 Host 209.222.82.147 is up (echo-reply ttl 43)
1231 Host 209.222.82.141 is up (echo-reply ttl 43)
1232 Host 209.222.82.162 is up (echo-reply ttl 43)
1233 Host 67.209.250.173 is up (reset ttl 64)
1234 Host 207.241.128.23 is up (reset ttl 64)
1235 Host 209.222.82.129 is up (reset ttl 64)
1236 Host 209.222.82.126 is up (echo-reply ttl 43)
1237 Host 209.222.82.165 is up (echo-reply ttl 43)
1238 Host 209.222.82.159 is up (echo-reply ttl 43)
1239 Host 173.201.73.6 is up (echo-reply ttl 52)
1240 Host 209.222.82.153 is up (reset ttl 64)
1241 Host 209.222.82.150 is up (echo-reply ttl 43)
1242 Host 209.222.82.156 is up (echo-reply ttl 43)
1243 Host 67.209.250.204 is up (reset ttl 64)
1244 Host 209.222.82.138 is up (reset ttl 64)
1245 Host 209.222.82.135 is up (echo-reply ttl 43)
1246 Host 67.209.250.165 is up (reset ttl 64)
1247 Host 67.209.250.166 is up (reset ttl 64)
1248 Host 209.222.82.132 is up (reset ttl 64)
1249 Host 97.74.105.6 is up (echo-reply ttl 52)
1250 Host 207.241.128.7 is up (reset ttl 64)
1251
1252 Checking ports on every active host using nmap... (nmap -O --reason --webxml --traceroute -sS -sV -sC -Pn -n -v -F <ip> -oA <output_directory>/nmap/<ip>)
1253 Scanning ip 209.222.82.144 (mail.ess.barracuda.com (PTR)):
1254 587/tcp open smtp syn-ack ttl 42
1255 | fingerprint-strings:
1256 | GenericLines:
1257 | 220 mail.ess.barracuda.com ESMTP (mx141.us-east-2b.ess.aws)
1258 | Syntax error, command unrecognized
1259 Scanning ip 209.222.82.147 (mail.ess.barracuda.com (PTR)):
1260 587/tcp open smtp syn-ack ttl 42
1261 | fingerprint-strings:
1262 | GenericLines:
1263 | 220 mail.ess.barracuda.com ESMTP (mx168.us-east-2b.ess.aws)
1264 | Syntax error, command unrecognized
1265 Scanning ip 209.222.82.141 (mail.ess.barracuda.com (PTR)):
1266 587/tcp open smtp syn-ack ttl 42
1267 | fingerprint-strings:
1268 | GenericLines:
1269 | 220 mail.ess.barracuda.com ESMTP (mx127.us-east-2b.ess.aws)
1270 | Syntax error, command unrecognized
1271 Scanning ip 209.222.82.162 (mail.ess.barracuda.com (PTR)):
1272 587/tcp open smtp syn-ack ttl 42
1273 | fingerprint-strings:
1274 | GenericLines:
1275 | 220 mail.ess.barracuda.com ESMTP (mx227.us-east-2a.ess.aws)
1276 | Syntax error, command unrecognized
1277 Scanning ip 67.209.250.173 (a67-209-250-173.cust.mi.winntel.net (PTR)):
1278 80/tcp open http syn-ack ttl 116 Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
1279 |_http-server-header: Microsoft-HTTPAPI/2.0
1280 443/tcp open ssl/http syn-ack ttl 116 Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
1281 |_http-server-header: Microsoft-HTTPAPI/2.0
1282 |_http-title: Not Found
1283 | ssl-cert: Subject: commonName=www.grandlodgemi.org
1284 | Subject Alternative Name: DNS:www.grandlodgemi.org, DNS:grandlodgemi.org, DNS:www.sharethesecret.org, DNS:michiganchildid.org, DNS:mds.grandlodgemi.org, DNS:qr.grandlodgemi.org, DNS:data.michiganmasons.org, DNS:sharethesecret.org, DNS:contacts.michiganmasons.org, DNS:search.grandlodgemi.org, DNS:www.michiganchildid.org, DNS:www.michiganmasons.org, DNS:michiganmasons.org
1285 | Issuer: commonName=Starfield Secure Certificate Authority - G2/organizationName=Starfield Technologies, Inc./stateOrProvinceName=Arizona/countryName=US
1286 | Public Key type: rsa
1287 | Public Key bits: 2048
1288 | Signature Algorithm: sha256WithRSAEncryption
1289 | Not valid before: 2018-12-20T10:28:44
1290 | Not valid after: 2021-02-18T20:52:40
1291 | MD5: 3bc6 ecca bde0 0f36 8cd7 1e6a 0ce4 bcc9
1292 |_SHA-1: e0a9 130d 7691 f745 14ed 6346 3fae 05f7 3709 4e32
1293 Device type: general purpose|WAP
1294 Running (JUST GUESSING): Linux 2.6.X|2.4.X (90%), Microsoft Windows 2012 (85%)
1295 OS Info: Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
1296 Scanning ip 207.241.128.23 ():
1297 80/tcp open http syn-ack ttl 116 Microsoft IIS httpd 7.5
1298 |_http-favicon: Unknown favicon MD5: 7EB5B3865441954A3B905A0088D08B58
1299 | http-methods:
1300 |_ Supported Methods: GET HEAD POST OPTIONS
1301 |_http-server-header: Microsoft-IIS/7.5
1302 | http-title: IMail Web Client - Login
1303 |_Requested resource was /Login.aspx?ReturnUrl=%2f
1304 |_http-trane-info: Problem with XML parsing of /evox/about
1305 110/tcp open pop3 syn-ack ttl 116 IMail pop3d 12.5.7.59 622689-12
1306 |_pop3-capabilities: TOP UIDL RESP-CODES LOGIN-DELAY(120) PIPELINING USER SASL(LOGIN PLAIN CRAM-MD5) EXPIRE(30 USER) IMPLEMENTATION(Ipswitch_IMail_12)
1307 | ssl-cert: Subject: commonName=*.cmsinter.net
1308 | Subject Alternative Name: DNS:*.cmsinter.net, DNS:cmsinter.net
1309 | Issuer: commonName=Go Daddy Secure Certificate Authority - G2/organizationName=GoDaddy.com, Inc./stateOrProvinceName=Arizona/countryName=US
1310 | Public Key type: rsa
1311 | Public Key bits: 2048
1312 | Signature Algorithm: sha256WithRSAEncryption
1313 | Not valid before: 2017-05-16T18:32:00
1314 | Not valid after: 2020-05-16T18:32:00
1315 | MD5: 0c15 b448 afda 5173 802e b22a 025b 13ac
1316 |_SHA-1: b50e 3c15 8fc5 74ce d2a4 8985 f08a 4f44 ba95 748e
1317 |_ssl-date: TLS randomness does not represent time
1318 143/tcp open imap? syn-ack ttl 116
1319 | fingerprint-strings:
1320 | DNSStatusRequestTCP, DNSVersionBindReqTCP, Kerberos, NULL, RPCCheck, SMBProgNeg, SSLSessionReq, TLSSessionReq, TerminalServerCookie, X11Probe:
1321 | * OK IMAP4 Server mail1.cmsinter.net (IMail 12.5.7.59)
1322 | FourOhFourRequest:
1323 | * OK IMAP4 Server mail1.cmsinter.net (IMail 12.5.7.59)
1324 | Invalid Syntax
1325 | Null Command
1326 | GenericLines:
1327 | * OK IMAP4 Server mail1.cmsinter.net (IMail 12.5.7.59)
1328 | Null Command
1329 | Null Command
1330 | GetRequest:
1331 | * OK IMAP4 Server mail1.cmsinter.net (IMail 12.5.7.59)
1332 | Unknown Command
1333 | Null Command
1334 | HTTPOptions, RTSPRequest:
1335 | * OK IMAP4 Server mail1.cmsinter.net (IMail 12.5.7.59)
1336 | OPTIONS BAD / Unknown Command
1337 | Null Command
1338 | Help:
1339 | * OK IMAP4 Server mail1.cmsinter.net (IMail 12.5.7.59)
1340 |_ HELP BAD Null Command
1341 |_imap-capabilities: IMAP4 AUTH=CRAM-MD5 CAPABILITY IDLEA0001 AUTH=LOGIN OK STARTTLS completed AUTH=PLAIN IMAP4rev1
1342 | ssl-cert: Subject: commonName=*.cmsinter.net
1343 | Subject Alternative Name: DNS:*.cmsinter.net, DNS:cmsinter.net
1344 | Issuer: commonName=Go Daddy Secure Certificate Authority - G2/organizationName=GoDaddy.com, Inc./stateOrProvinceName=Arizona/countryName=US
1345 | Public Key type: rsa
1346 | Public Key bits: 2048
1347 | Signature Algorithm: sha256WithRSAEncryption
1348 | Not valid before: 2017-05-16T18:32:00
1349 | Not valid after: 2020-05-16T18:32:00
1350 | MD5: 0c15 b448 afda 5173 802e b22a 025b 13ac
1351 |_SHA-1: b50e 3c15 8fc5 74ce d2a4 8985 f08a 4f44 ba95 748e
1352 |_ssl-date: TLS randomness does not represent time
1353 443/tcp open ssl/https? syn-ack ttl 116
1354 |_ssl-date: 2019-10-12T13:19:34+00:00; 0s from scanner time.
1355 | sslv2:
1356 | SSLv2 supported
1357 | ciphers:
1358 | SSL2_RC4_128_WITH_MD5
1359 |_ SSL2_DES_192_EDE3_CBC_WITH_MD5
1360 465/tcp open ssl/smtps? syn-ack ttl 116
1361 | fingerprint-strings:
1362 | GenericLines, GetRequest, NULL:
1363 | 220 mail.cmsinter.net
1364 | Hello:
1365 | 220 mail.cmsinter.net
1366 | 250-mail1.cmsinter.net says hello
1367 | 250-SIZE 52428800
1368 | 250-8BITMIME
1369 | 250-DSN
1370 | 250-ETRN
1371 | 250-AUTH LOGIN CRAM-MD5
1372 | 250-AUTH LOGIN
1373 | AUTH=LOGIN
1374 | Help:
1375 | 220 mail.cmsinter.net
1376 |_ DATA EHLO HELO MAIL NOOP QUIT RCPT RSET VRFY
1377 |_smtp-commands: Couldn't establish connection on port 465
1378 587/tcp open submission? syn-ack ttl 116
1379 | fingerprint-strings:
1380 | GenericLines, GetRequest, HTTPOptions, Help, NULL:
1381 | 220 mail.cmsinter.net
1382 | Hello:
1383 | 220 mail.cmsinter.net
1384 | 250-mail1.cmsinter.net says hello
1385 | 250-SIZE 52428800
1386 | 250-8BITMIME
1387 | 250-DSN
1388 | 250-ETRN
1389 | 250-AUTH LOGIN CRAM-MD5
1390 | 250-AUTH LOGIN
1391 | 250-AUTH=LOGIN
1392 |_ STARTTLS
1393 |_smtp-commands: Couldn't establish connection on port 587
1394 993/tcp open ssl/imaps? syn-ack ttl 116
1395 | fingerprint-strings:
1396 | DNSStatusRequestTCP, DNSVersionBindReqTCP, Kerberos, NULL, RPCCheck, SMBProgNeg, SSLSessionReq, TLSSessionReq, TerminalServerCookie, X11Probe:
1397 | * OK IMAP4 Server mail1.cmsinter.net (IMail 12.5.7.59)
1398 | FourOhFourRequest:
1399 | * OK IMAP4 Server mail1.cmsinter.net (IMail 12.5.7.59)
1400 | Invalid Syntax
1401 | Null Command
1402 | GenericLines:
1403 | * OK IMAP4 Server mail1.cmsinter.net (IMail 12.5.7.59)
1404 | Null Command
1405 | Null Command
1406 | GetRequest:
1407 | * OK IMAP4 Server mail1.cmsinter.net (IMail 12.5.7.59)
1408 | Unknown Command
1409 | Null Command
1410 | HTTPOptions, RTSPRequest:
1411 | * OK IMAP4 Server mail1.cmsinter.net (IMail 12.5.7.59)
1412 | OPTIONS BAD / Unknown Command
1413 | Null Command
1414 | Help:
1415 | * OK IMAP4 Server mail1.cmsinter.net (IMail 12.5.7.59)
1416 |_ HELP BAD Null Command
1417 |_imap-capabilities: IMAP4 AUTH=CRAM-MD5 CAPABILITY IDLEA0001 AUTH=LOGIN OK completed AUTH=PLAIN IMAP4rev1
1418 | ssl-cert: Subject: commonName=*.cmsinter.net
1419 | Subject Alternative Name: DNS:*.cmsinter.net, DNS:cmsinter.net
1420 | Issuer: commonName=Go Daddy Secure Certificate Authority - G2/organizationName=GoDaddy.com, Inc./stateOrProvinceName=Arizona/countryName=US
1421 | Public Key type: rsa
1422 | Public Key bits: 2048
1423 | Signature Algorithm: sha256WithRSAEncryption
1424 | Not valid before: 2017-05-16T18:32:00
1425 | Not valid after: 2020-05-16T18:32:00
1426 | MD5: 0c15 b448 afda 5173 802e b22a 025b 13ac
1427 |_SHA-1: b50e 3c15 8fc5 74ce d2a4 8985 f08a 4f44 ba95 748e
1428 |_ssl-date: TLS randomness does not represent time
1429 995/tcp open ssl/pop3 syn-ack ttl 116 IMail pop3d 12.5.7.59 622694-13
1430 |_pop3-capabilities: TOP UIDL RESP-CODES LOGIN-DELAY(120) PIPELINING USER SASL(LOGIN PLAIN CRAM-MD5) EXPIRE(30 USER) IMPLEMENTATION(Ipswitch_IMail_12)
1431 | ssl-cert: Subject: commonName=*.cmsinter.net
1432 | Subject Alternative Name: DNS:*.cmsinter.net, DNS:cmsinter.net
1433 | Issuer: commonName=Go Daddy Secure Certificate Authority - G2/organizationName=GoDaddy.com, Inc./stateOrProvinceName=Arizona/countryName=US
1434 | Public Key type: rsa
1435 | Public Key bits: 2048
1436 | Signature Algorithm: sha256WithRSAEncryption
1437 | Not valid before: 2017-05-16T18:32:00
1438 | Not valid after: 2020-05-16T18:32:00
1439 | MD5: 0c15 b448 afda 5173 802e b22a 025b 13ac
1440 |_SHA-1: b50e 3c15 8fc5 74ce d2a4 8985 f08a 4f44 ba95 748e
1441 |_ssl-date: TLS randomness does not represent time
1442 OS Info: Service Info: Host: mail1.cmsinter.net; OS: Windows; CPE: cpe:/o:microsoft:windows
1443 Scanning ip 209.222.82.129 (mail.ess.barracuda.com (PTR)):
1444 587/tcp open smtp syn-ack ttl 42
1445 | fingerprint-strings:
1446 | GenericLines:
1447 | 220 mail.ess.barracuda.com ESMTP (mx124.us-east-2a.ess.aws)
1448 | Syntax error, command unrecognized
1449 Scanning ip 209.222.82.126 (mail.ess.barracuda.com (PTR)):
1450 587/tcp open smtp syn-ack ttl 42
1451 | fingerprint-strings:
1452 | GenericLines:
1453 | 220 mail.ess.barracuda.com ESMTP (mx101.us-east-2a.ess.aws)
1454 | Syntax error, command unrecognized
1455 Scanning ip 209.222.82.165 (mail.ess.barracuda.com (PTR)):
1456 587/tcp open smtp syn-ack ttl 42
1457 | fingerprint-strings:
1458 | GenericLines, GetRequest:
1459 | 220 mail.ess.barracuda.com ESMTP (mx229.us-east-2b.ess.aws)
1460 | Syntax error, command unrecognized
1461 Scanning ip 209.222.82.159 (mail.ess.barracuda.com (PTR)):
1462 587/tcp open smtp syn-ack ttl 42
1463 | fingerprint-strings:
1464 | GenericLines:
1465 | 220 mail.ess.barracuda.com ESMTP (mx203.us-east-2b.ess.aws)
1466 | Syntax error, command unrecognized
1467 Scanning ip 173.201.73.6 (ns12.domaincontrol.com (PTR)):
1468 53/tcp open tcpwrapped syn-ack ttl 56
1469 Scanning ip 209.222.82.153 (mail.ess.barracuda.com (PTR)):
1470 587/tcp open smtp syn-ack ttl 42
1471 | fingerprint-strings:
1472 | GenericLines:
1473 | 220 mail.ess.barracuda.com ESMTP (mx182.us-east-2b.ess.aws)
1474 | Syntax error, command unrecognized
1475 Scanning ip 209.222.82.150 (mail.ess.barracuda.com (PTR)):
1476 587/tcp open smtp syn-ack ttl 42
1477 | fingerprint-strings:
1478 | GenericLines:
1479 | 220 mail.ess.barracuda.com ESMTP (mx180.us-east-2a.ess.aws)
1480 | Syntax error, command unrecognized
1481 Scanning ip 209.222.82.156 (mail.ess.barracuda.com (PTR)):
1482 Scanning ip 67.209.250.204 (pop3.michiganmasons.org.):
1483 21/tcp open ftp syn-ack ttl 55 ProFTPD
1484 | ssl-cert: Subject: commonName=webcontrol.winntel.com
1485 | Subject Alternative Name: DNS:webcontrol.winntel.com
1486 | Issuer: commonName=Let's Encrypt Authority X3/organizationName=Let's Encrypt/countryName=US
1487 | Public Key type: rsa
1488 | Public Key bits: 2048
1489 | Signature Algorithm: sha256WithRSAEncryption
1490 | Not valid before: 2019-09-29T17:47:32
1491 | Not valid after: 2019-12-28T17:47:32
1492 | MD5: 460c 586e df42 c7c0 b68a 773a 9f3c c4d9
1493 |_SHA-1: 1f8e f5d2 f802 7026 e54d c6e6 f34c ff42 bdc8 191e
1494 |_ssl-date: TLS randomness does not represent time
1495 | tls-nextprotoneg:
1496 |_ ftp
1497 53/tcp open domain syn-ack ttl 55 (unknown banner: none)
1498 | dns-nsid:
1499 |_ bind.version: none
1500 | fingerprint-strings:
1501 | DNSVersionBindReqTCP:
1502 | version
1503 | bind
1504 |_ none
1505 80/tcp open http syn-ack ttl 55 nginx
1506 |_http-favicon: Parallels Plesk
1507 | http-methods:
1508 |_ Supported Methods: GET HEAD POST OPTIONS
1509 |_http-title: Web Server's Default Page
1510 110/tcp open pop3 syn-ack ttl 55 Courier pop3d
1511 |_pop3-capabilities: PIPELINING SASL(LOGIN CRAM-MD5 CRAM-SHA1 CRAM-SHA256 PLAIN) STLS USER UIDL IMPLEMENTATION(Courier Mail Server) APOP TOP LOGIN-DELAY(10)
1512 | ssl-cert: Subject: commonName=virt-mail.winntel.com
1513 | Subject Alternative Name: DNS:virt-mail.winntel.com
1514 | Issuer: commonName=Let's Encrypt Authority X3/organizationName=Let's Encrypt/countryName=US
1515 | Public Key type: rsa
1516 | Public Key bits: 2048
1517 | Signature Algorithm: sha256WithRSAEncryption
1518 | Not valid before: 2019-09-29T17:47:05
1519 | Not valid after: 2019-12-28T17:47:05
1520 | MD5: 70ac d8a3 7eac 21b7 857a 1aaa f8c5 fa1c
1521 |_SHA-1: a014 ad57 1e12 88cc e297 b23a c5da 5157 1d4f d75e
1522 |_ssl-date: TLS randomness does not represent time
1523 143/tcp open imap syn-ack ttl 55 Courier Imapd (released 2017)
1524 |_imap-capabilities: ACL2=UNION THREAD=REFERENCES THREAD=ORDEREDSUBJECT SORT AUTH=PLAIN AUTH=CRAM-MD5 ACL NAMESPACE AUTH=CRAM-SHA1 UIDPLUS CHILDREN CAPABILITY STARTTLSA0001 QUOTA OK IMAP4rev1 IDLE completed AUTH=CRAM-SHA256
1525 | ssl-cert: Subject: commonName=virt-mail.winntel.com
1526 | Subject Alternative Name: DNS:virt-mail.winntel.com
1527 | Issuer: commonName=Let's Encrypt Authority X3/organizationName=Let's Encrypt/countryName=US
1528 | Public Key type: rsa
1529 | Public Key bits: 2048
1530 | Signature Algorithm: sha256WithRSAEncryption
1531 | Not valid before: 2019-09-29T17:47:05
1532 | Not valid after: 2019-12-28T17:47:05
1533 | MD5: 70ac d8a3 7eac 21b7 857a 1aaa f8c5 fa1c
1534 |_SHA-1: a014 ad57 1e12 88cc e297 b23a c5da 5157 1d4f d75e
1535 |_ssl-date: TLS randomness does not represent time
1536 443/tcp open ssl/http syn-ack ttl 55 nginx
1537 |_http-favicon: Parallels Plesk
1538 | http-methods:
1539 |_ Supported Methods: GET HEAD POST OPTIONS
1540 |_http-title: Web Server's Default Page
1541 | ssl-cert: Subject: commonName=Plesk/organizationName=Plesk/countryName=CH
1542 | Issuer: commonName=Plesk/organizationName=Plesk/countryName=CH
1543 | Public Key type: rsa
1544 | Public Key bits: 2048
1545 | Signature Algorithm: sha256WithRSAEncryption
1546 | Not valid before: 2018-07-02T04:48:34
1547 | Not valid after: 2019-07-02T04:48:34
1548 | MD5: 751b ad5b 6ae1 adb1 de68 4f90 9702 1819
1549 |_SHA-1: 4831 321f 030c 5b2f 9d68 4ce6 7676 c7d0 c395 2fae
1550 |_ssl-date: TLS randomness does not represent time
1551 | tls-alpn:
1552 | h2
1553 |_ http/1.1
1554 | tls-nextprotoneg:
1555 | h2
1556 |_ http/1.1
1557 465/tcp open ssl/smtp syn-ack ttl 55 Postfix smtpd
1558 |_smtp-commands: WebServ-110.WinnTel.Net, PIPELINING, SIZE 102400000, ETRN, AUTH DIGEST-MD5 CRAM-MD5 PLAIN LOGIN, ENHANCEDSTATUSCODES, 8BITMIME, DSN,
1559 | ssl-cert: Subject: commonName=virt-mail.winntel.com
1560 | Subject Alternative Name: DNS:virt-mail.winntel.com
1561 | Issuer: commonName=Let's Encrypt Authority X3/organizationName=Let's Encrypt/countryName=US
1562 | Public Key type: rsa
1563 | Public Key bits: 2048
1564 | Signature Algorithm: sha256WithRSAEncryption
1565 | Not valid before: 2019-09-29T17:47:05
1566 | Not valid after: 2019-12-28T17:47:05
1567 | MD5: 70ac d8a3 7eac 21b7 857a 1aaa f8c5 fa1c
1568 |_SHA-1: a014 ad57 1e12 88cc e297 b23a c5da 5157 1d4f d75e
1569 |_ssl-date: TLS randomness does not represent time
1570 587/tcp open smtp syn-ack ttl 55 Postfix smtpd
1571 |_smtp-commands: WebServ-110.WinnTel.Net, PIPELINING, SIZE 102400000, ETRN, STARTTLS, ENHANCEDSTATUSCODES, 8BITMIME, DSN,
1572 | ssl-cert: Subject: commonName=virt-mail.winntel.com
1573 | Subject Alternative Name: DNS:virt-mail.winntel.com
1574 | Issuer: commonName=Let's Encrypt Authority X3/organizationName=Let's Encrypt/countryName=US
1575 | Public Key type: rsa
1576 | Public Key bits: 2048
1577 | Signature Algorithm: sha256WithRSAEncryption
1578 | Not valid before: 2019-09-29T17:47:05
1579 | Not valid after: 2019-12-28T17:47:05
1580 | MD5: 70ac d8a3 7eac 21b7 857a 1aaa f8c5 fa1c
1581 |_SHA-1: a014 ad57 1e12 88cc e297 b23a c5da 5157 1d4f d75e
1582 |_ssl-date: TLS randomness does not represent time
1583 993/tcp open ssl/imap syn-ack ttl 55 Courier Imapd (released 2017)
1584 |_imap-capabilities: IMAP4rev1 THREAD=REFERENCES THREAD=ORDEREDSUBJECT SORT AUTH=PLAIN AUTH=CRAM-MD5 ACL NAMESPACE AUTH=CRAM-SHA1 ACL2=UNIONA0001 UIDPLUS CHILDREN QUOTA OK CAPABILITY IDLE completed AUTH=CRAM-SHA256
1585 | ssl-cert: Subject: commonName=virt-mail.winntel.com
1586 | Subject Alternative Name: DNS:virt-mail.winntel.com
1587 | Issuer: commonName=Let's Encrypt Authority X3/organizationName=Let's Encrypt/countryName=US
1588 | Public Key type: rsa
1589 | Public Key bits: 2048
1590 | Signature Algorithm: sha256WithRSAEncryption
1591 | Not valid before: 2019-09-29T17:47:05
1592 | Not valid after: 2019-12-28T17:47:05
1593 | MD5: 70ac d8a3 7eac 21b7 857a 1aaa f8c5 fa1c
1594 |_SHA-1: a014 ad57 1e12 88cc e297 b23a c5da 5157 1d4f d75e
1595 |_ssl-date: TLS randomness does not represent time
1596 995/tcp open ssl/pop3 syn-ack ttl 55 Courier pop3d
1597 |_pop3-capabilities: PIPELINING UIDL APOP SASL(LOGIN PLAIN) IMPLEMENTATION(Courier Mail Server) LOGIN-DELAY(10) TOP USER
1598 | ssl-cert: Subject: commonName=virt-mail.winntel.com
1599 | Subject Alternative Name: DNS:virt-mail.winntel.com
1600 | Issuer: commonName=Let's Encrypt Authority X3/organizationName=Let's Encrypt/countryName=US
1601 | Public Key type: rsa
1602 | Public Key bits: 2048
1603 | Signature Algorithm: sha256WithRSAEncryption
1604 | Not valid before: 2019-09-29T17:47:05
1605 | Not valid after: 2019-12-28T17:47:05
1606 | MD5: 70ac d8a3 7eac 21b7 857a 1aaa f8c5 fa1c
1607 |_SHA-1: a014 ad57 1e12 88cc e297 b23a c5da 5157 1d4f d75e
1608 |_ssl-date: TLS randomness does not represent time
1609 8443/tcp open ssl/http syn-ack ttl 55 sw-cp-server httpd (Plesk Onyx 17.8.11)
1610 |_http-favicon: Parallels Plesk
1611 | http-methods:
1612 |_ Supported Methods: GET HEAD POST
1613 | http-robots.txt: 1 disallowed entry
1614 |_/
1615 |_http-server-header: sw-cp-server
1616 |_http-title: Plesk Onyx 17.8.11
1617 | ssl-cert: Subject: commonName=webcontrol.winntel.com
1618 | Subject Alternative Name: DNS:webcontrol.winntel.com
1619 | Issuer: commonName=Let's Encrypt Authority X3/organizationName=Let's Encrypt/countryName=US
1620 | Public Key type: rsa
1621 | Public Key bits: 2048
1622 | Signature Algorithm: sha256WithRSAEncryption
1623 | Not valid before: 2019-09-29T17:47:32
1624 | Not valid after: 2019-12-28T17:47:32
1625 | MD5: 460c 586e df42 c7c0 b68a 773a 9f3c c4d9
1626 |_SHA-1: 1f8e f5d2 f802 7026 e54d c6e6 f34c ff42 bdc8 191e
1627 |_ssl-date: TLS randomness does not represent time
1628 | tls-alpn:
1629 |_ http/1.1
1630 | tls-nextprotoneg:
1631 |_ http/1.1
1632 OS Info: Service Info: Hosts: localhost.localdomain, WebServ-110.WinnTel.Net
1633 Scanning ip 209.222.82.138 (mail.ess.barracuda.com (PTR)):
1634 587/tcp open smtp syn-ack ttl 42
1635 | fingerprint-strings:
1636 | GenericLines, GetRequest:
1637 | 220 mail.ess.barracuda.com ESMTP (mx106.us-east-2b.ess.aws)
1638 | Syntax error, command unrecognized
1639 Scanning ip 209.222.82.135 (mail.ess.barracuda.com (PTR)):
1640 587/tcp open smtp syn-ack ttl 42
1641 | fingerprint-strings:
1642 | GenericLines:
1643 | 220 mail.ess.barracuda.com ESMTP (mx164.us-east-2a.ess.aws)
1644 | Syntax error, command unrecognized
1645 Scanning ip 67.209.250.165 ():
1646 Scanning ip 67.209.250.166 ():
1647 80/tcp open http syn-ack ttl 116 Microsoft IIS httpd 7.5
1648 |_http-server-header: Microsoft-IIS/7.5
1649 443/tcp open ssl/https? syn-ack ttl 116
1650 |_ssl-date: 2019-10-12T13:30:57+00:00; 0s from scanner time.
1651 | sslv2:
1652 | SSLv2 supported
1653 | ciphers:
1654 | SSL2_RC4_128_WITH_MD5
1655 |_ SSL2_DES_192_EDE3_CBC_WITH_MD5
1656 Device type: general purpose|WAP
1657 Running (JUST GUESSING): Linux 2.6.X|2.4.X (90%), Microsoft Windows 2008|7|Vista (86%)
1658 OS Info: Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
1659 Scanning ip 209.222.82.132 (mail.ess.barracuda.com (PTR)):
1660 587/tcp open smtp syn-ack ttl 42
1661 | fingerprint-strings:
1662 | GenericLines, GetRequest:
1663 | 220 mail.ess.barracuda.com ESMTP (mx140.us-east-2a.ess.aws)
1664 | Syntax error, command unrecognized
1665 Scanning ip 97.74.105.6 (ns11.domaincontrol.com (PTR)):
1666 53/tcp open tcpwrapped syn-ack ttl 52
1667 Scanning ip 207.241.128.7 (mx1.cmsinter.net (PTR)):
1668 80/tcp open http syn-ack ttl 52 nginx
1669 |_http-favicon: Unknown favicon MD5: EEB82041F5921BC49ED723997A5BF35F
1670 | http-methods:
1671 |_ Supported Methods: GET HEAD
1672 | http-robots.txt: 1 disallowed entry
1673 |_/
1674 |_http-title: Site doesn't have a title (text/html).
1675 443/tcp open ssl/http syn-ack ttl 52 nginx
1676 |_http-favicon: Unknown favicon MD5: EEB82041F5921BC49ED723997A5BF35F
1677 | http-methods:
1678 |_ Supported Methods: GET HEAD
1679 | http-robots.txt: 1 disallowed entry
1680 |_/
1681 |_http-server-header: BarracudaHTTP 4.0
1682 |_http-title: Site doesn't have a title (text/html).
1683 | ssl-cert: Subject: commonName=*.cmsinter.net
1684 | Subject Alternative Name: DNS:*.cmsinter.net, DNS:cmsinter.net
1685 | Issuer: commonName=Go Daddy Secure Certificate Authority - G2/organizationName=GoDaddy.com, Inc./stateOrProvinceName=Arizona/countryName=US
1686 | Public Key type: rsa
1687 | Public Key bits: 2048
1688 | Signature Algorithm: sha256WithRSAEncryption
1689 | Not valid before: 2017-05-16T18:32:00
1690 | Not valid after: 2020-05-16T18:32:00
1691 | MD5: 0c15 b448 afda 5173 802e b22a 025b 13ac
1692 |_SHA-1: b50e 3c15 8fc5 74ce d2a4 8985 f08a 4f44 ba95 748e
1693 |_ssl-date: TLS randomness does not represent time
1694 WebCrawling domain's web servers... up to 50 max links.
1695
1696 + URL to crawl: http://www.michiganmasons.org.
1697 + Date: 2019-10-12
1698
1699 + Crawling URL: http://www.michiganmasons.org.:
1700 + Links:
1701 + Crawling http://www.michiganmasons.org. (400 Bad Request)
1702 + Searching for directories...
1703 + Searching open folders...
1704
1705
1706 + URL to crawl: http://ftp.michiganmasons.org.
1707 + Date: 2019-10-12
1708
1709 + Crawling URL: http://ftp.michiganmasons.org.:
1710 + Links:
1711 + Crawling http://ftp.michiganmasons.org. (400 Bad Request)
1712 + Searching for directories...
1713 + Searching open folders...
1714
1715
1716 + URL to crawl: https://www.michiganmasons.org.
1717 + Date: 2019-10-12
1718
1719 + Crawling URL: https://www.michiganmasons.org.:
1720 + Links:
1721 + Crawling https://www.michiganmasons.org.
1722 + Searching for directories...
1723 + Searching open folders...
1724
1725
1726 + URL to crawl: https://ftp.michiganmasons.org.
1727 + Date: 2019-10-12
1728
1729 + Crawling URL: https://ftp.michiganmasons.org.:
1730 + Links:
1731 + Crawling https://ftp.michiganmasons.org.
1732 + Searching for directories...
1733 + Searching open folders...
1734
1735
1736 + URL to crawl: http://mail.michiganmasons.org.
1737 + Date: 2019-10-12
1738
1739 + Crawling URL: http://mail.michiganmasons.org.:
1740 + Links:
1741 + Crawling http://mail.michiganmasons.org.
1742 + Searching for directories...
1743 - Found: http://mail.michiganmasons.org./css/
1744 - Found: http://mail.michiganmasons.org./img/
1745 + Searching open folders...
1746 - http://mail.michiganmasons.org./css/ (403 Forbidden)
1747 - http://mail.michiganmasons.org./img/ (403 Forbidden)
1748
1749
1750 + URL to crawl: http://pop3.michiganmasons.org.
1751 + Date: 2019-10-12
1752
1753 + Crawling URL: http://pop3.michiganmasons.org.:
1754 + Links:
1755 + Crawling http://pop3.michiganmasons.org.
1756 + Searching for directories...
1757 - Found: http://pop3.michiganmasons.org./css/
1758 - Found: http://pop3.michiganmasons.org./img/
1759 + Searching open folders...
1760 - http://pop3.michiganmasons.org./css/ (403 Forbidden)
1761 - http://pop3.michiganmasons.org./img/ (403 Forbidden)
1762
1763
1764 + URL to crawl: http://imap.michiganmasons.org.
1765 + Date: 2019-10-12
1766
1767 + Crawling URL: http://imap.michiganmasons.org.:
1768 + Links:
1769 + Crawling http://imap.michiganmasons.org.
1770 + Searching for directories...
1771 - Found: http://imap.michiganmasons.org./css/
1772 - Found: http://imap.michiganmasons.org./img/
1773 + Searching open folders...
1774 - http://imap.michiganmasons.org./css/ (403 Forbidden)
1775 - http://imap.michiganmasons.org./img/ (403 Forbidden)
1776
1777
1778 + URL to crawl: http://webmail.michiganmasons.org.
1779 + Date: 2019-10-12
1780
1781 + Crawling URL: http://webmail.michiganmasons.org.:
1782 + Links:
1783 + Crawling http://webmail.michiganmasons.org.
1784 + Crawling http://webmail.michiganmasons.org./js/prototype.js?v=596ca0a81b7fe741719c6df2f8b52a22 (File! Not crawling it.)
1785 + Crawling http://webmail.michiganmasons.org./js/horde.js?v=596ca0a81b7fe741719c6df2f8b52a22 (File! Not crawling it.)
1786 + Crawling http://webmail.michiganmasons.org./js/login.js?v=596ca0a81b7fe741719c6df2f8b52a22 (File! Not crawling it.)
1787 + Crawling http://webmail.michiganmasons.org./imp/js/login.js?v=00b6fb7403c5dd3e1dece8deb4772850 (File! Not crawling it.)
1788 + Crawling http://webmail.michiganmasons.org./js/accesskeys.js?v=596ca0a81b7fe741719c6df2f8b52a22 (File! Not crawling it.)
1789 + Searching for directories...
1790 - Found: http://webmail.michiganmasons.org./themes/
1791 - Found: http://webmail.michiganmasons.org./themes/default/
1792 - Found: http://webmail.michiganmasons.org./themes/default/graphics/
1793 - Found: http://webmail.michiganmasons.org./js/
1794 - Found: http://webmail.michiganmasons.org./imp/
1795 - Found: http://webmail.michiganmasons.org./imp/js/
1796 + Searching open folders...
1797 - http://webmail.michiganmasons.org./themes/ (403 Forbidden)
1798 - http://webmail.michiganmasons.org./themes/default/ (403 Forbidden)
1799 - http://webmail.michiganmasons.org./themes/default/graphics/ (403 Forbidden)
1800 - http://webmail.michiganmasons.org./js/ (403 Forbidden)
1801 - http://webmail.michiganmasons.org./imp/ (No Open Folder)
1802 - http://webmail.michiganmasons.org./imp/js/ (403 Forbidden)
1803
1804
1805 + URL to crawl: http://smtp.michiganmasons.org.
1806 + Date: 2019-10-12
1807
1808 + Crawling URL: http://smtp.michiganmasons.org.:
1809 + Links:
1810 + Crawling http://smtp.michiganmasons.org.
1811 + Searching for directories...
1812 - Found: http://smtp.michiganmasons.org./css/
1813 - Found: http://smtp.michiganmasons.org./img/
1814 + Searching open folders...
1815 - http://smtp.michiganmasons.org./css/ (403 Forbidden)
1816 - http://smtp.michiganmasons.org./img/ (403 Forbidden)
1817
1818
1819 + URL to crawl: https://mail.michiganmasons.org.
1820 + Date: 2019-10-12
1821
1822 + Crawling URL: https://mail.michiganmasons.org.:
1823 + Links:
1824 + Crawling https://mail.michiganmasons.org. ([SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:727))
1825 + Searching for directories...
1826 + Searching open folders...
1827
1828
1829 + URL to crawl: https://pop3.michiganmasons.org.
1830 + Date: 2019-10-12
1831
1832 + Crawling URL: https://pop3.michiganmasons.org.:
1833 + Links:
1834 + Crawling https://pop3.michiganmasons.org. ([SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:727))
1835 + Searching for directories...
1836 + Searching open folders...
1837
1838
1839 + URL to crawl: https://imap.michiganmasons.org.
1840 + Date: 2019-10-12
1841
1842 + Crawling URL: https://imap.michiganmasons.org.:
1843 + Links:
1844 + Crawling https://imap.michiganmasons.org. ([SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:727))
1845 + Searching for directories...
1846 + Searching open folders...
1847
1848
1849 + URL to crawl: https://webmail.michiganmasons.org.
1850 + Date: 2019-10-12
1851
1852 + Crawling URL: https://webmail.michiganmasons.org.:
1853 + Links:
1854 + Crawling https://webmail.michiganmasons.org. ([SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:727))
1855 + Searching for directories...
1856 + Searching open folders...
1857
1858
1859 + URL to crawl: https://smtp.michiganmasons.org.
1860 + Date: 2019-10-12
1861
1862 + Crawling URL: https://smtp.michiganmasons.org.:
1863 + Links:
1864 + Crawling https://smtp.michiganmasons.org. ([SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:727))
1865 + Searching for directories...
1866 + Searching open folders...
1867
1868
1869 + URL to crawl: https://mail.michiganmasons.org.:8443
1870 + Date: 2019-10-12
1871
1872 + Crawling URL: https://mail.michiganmasons.org.:8443:
1873 + Links:
1874 + Crawling https://mail.michiganmasons.org.:8443
1875 + Searching for directories...
1876 + Searching open folders...
1877
1878
1879 + URL to crawl: https://pop3.michiganmasons.org.:8443
1880 + Date: 2019-10-12
1881
1882 + Crawling URL: https://pop3.michiganmasons.org.:8443:
1883 + Links:
1884 + Crawling https://pop3.michiganmasons.org.:8443
1885 + Searching for directories...
1886 + Searching open folders...
1887
1888
1889 + URL to crawl: https://imap.michiganmasons.org.:8443
1890 + Date: 2019-10-12
1891
1892 + Crawling URL: https://imap.michiganmasons.org.:8443:
1893 + Links:
1894 + Crawling https://imap.michiganmasons.org.:8443
1895 + Searching for directories...
1896 + Searching open folders...
1897
1898
1899 + URL to crawl: https://webmail.michiganmasons.org.:8443
1900 + Date: 2019-10-12
1901
1902 + Crawling URL: https://webmail.michiganmasons.org.:8443:
1903 + Links:
1904 + Crawling https://webmail.michiganmasons.org.:8443
1905 + Searching for directories...
1906 + Searching open folders...
1907
1908
1909 + URL to crawl: https://smtp.michiganmasons.org.:8443
1910 + Date: 2019-10-12
1911
1912 + Crawling URL: https://smtp.michiganmasons.org.:8443:
1913 + Links:
1914 + Crawling https://smtp.michiganmasons.org.:8443
1915 + Searching for directories...
1916 + Searching open folders...
1917
1918
1919 + URL to crawl: http://mx1.cmsinter.net
1920 + Date: 2019-10-12
1921
1922 + Crawling URL: http://mx1.cmsinter.net:
1923 + Links:
1924 + Crawling http://mx1.cmsinter.net (REDIRECTING TO: /cgi-mod/index.cgi)
1925 + Searching for directories...
1926 + Searching open folders...
1927
1928
1929 + URL to crawl: https://mx1.cmsinter.net
1930 + Date: 2019-10-12
1931
1932 + Crawling URL: https://mx1.cmsinter.net:
1933 + Links:
1934 + Crawling https://mx1.cmsinter.net (REDIRECTING TO: /cgi-mod/index.cgi)
1935 + Searching for directories...
1936 + Searching open folders...
1937
1938--Finished--
1939Summary information for domain michiganmasons.org.
1940-----------------------------------------
1941 Domain Specific Information:
1942 Email: robertconley@michiganmasons.org
1943 Email: robertconley@michiganmasons.org.
1944
1945 Domain Ips Information:
1946 IP: 209.222.82.144
1947 HostName: d22800a.ess.barracudanetworks.com Type: MX
1948 HostName: mail.ess.barracuda.com Type: PTR
1949 Country: United States
1950 Is Active: True (echo-reply ttl 43)
1951 Port: 587/tcp open smtp syn-ack ttl 42
1952 Script Info: | fingerprint-strings:
1953 Script Info: | GenericLines:
1954 Script Info: | 220 mail.ess.barracuda.com ESMTP (mx141.us-east-2b.ess.aws)
1955 Script Info: | Syntax error, command unrecognized
1956 IP: 209.222.82.147
1957 HostName: d22800a.ess.barracudanetworks.com Type: MX
1958 HostName: mail.ess.barracuda.com Type: PTR
1959 Country: United States
1960 Is Active: True (echo-reply ttl 43)
1961 Port: 587/tcp open smtp syn-ack ttl 42
1962 Script Info: | fingerprint-strings:
1963 Script Info: | GenericLines:
1964 Script Info: | 220 mail.ess.barracuda.com ESMTP (mx168.us-east-2b.ess.aws)
1965 Script Info: | Syntax error, command unrecognized
1966 IP: 209.222.82.141
1967 HostName: d22800a.ess.barracudanetworks.com Type: MX
1968 HostName: mail.ess.barracuda.com Type: PTR
1969 Country: United States
1970 Is Active: True (echo-reply ttl 43)
1971 Port: 587/tcp open smtp syn-ack ttl 42
1972 Script Info: | fingerprint-strings:
1973 Script Info: | GenericLines:
1974 Script Info: | 220 mail.ess.barracuda.com ESMTP (mx127.us-east-2b.ess.aws)
1975 Script Info: | Syntax error, command unrecognized
1976 IP: 209.222.82.162
1977 HostName: d22800a.ess.barracudanetworks.com Type: MX
1978 HostName: mail.ess.barracuda.com Type: PTR
1979 Country: United States
1980 Is Active: True (echo-reply ttl 43)
1981 Port: 587/tcp open smtp syn-ack ttl 42
1982 Script Info: | fingerprint-strings:
1983 Script Info: | GenericLines:
1984 Script Info: | 220 mail.ess.barracuda.com ESMTP (mx227.us-east-2a.ess.aws)
1985 Script Info: | Syntax error, command unrecognized
1986 IP: 67.209.250.173
1987 HostName: www.michiganmasons.org. Type: A
1988 HostName: ftp.michiganmasons.org. Type: A
1989 HostName: a67-209-250-173.cust.mi.winntel.net Type: PTR
1990 Country: United States
1991 Is Active: True (reset ttl 64)
1992 Port: 80/tcp open http syn-ack ttl 116 Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
1993 Script Info: |_http-server-header: Microsoft-HTTPAPI/2.0
1994 Port: 443/tcp open ssl/http syn-ack ttl 116 Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
1995 Script Info: |_http-server-header: Microsoft-HTTPAPI/2.0
1996 Script Info: |_http-title: Not Found
1997 Script Info: | ssl-cert: Subject: commonName=www.grandlodgemi.org
1998 Script Info: | Subject Alternative Name: DNS:www.grandlodgemi.org, DNS:grandlodgemi.org, DNS:www.sharethesecret.org, DNS:michiganchildid.org, DNS:mds.grandlodgemi.org, DNS:qr.grandlodgemi.org, DNS:data.michiganmasons.org, DNS:sharethesecret.org, DNS:contacts.michiganmasons.org, DNS:search.grandlodgemi.org, DNS:www.michiganchildid.org, DNS:www.michiganmasons.org, DNS:michiganmasons.org
1999 Script Info: | Issuer: commonName=Starfield Secure Certificate Authority - G2/organizationName=Starfield Technologies, Inc./stateOrProvinceName=Arizona/countryName=US
2000 Script Info: | Public Key type: rsa
2001 Script Info: | Public Key bits: 2048
2002 Script Info: | Signature Algorithm: sha256WithRSAEncryption
2003 Script Info: | Not valid before: 2018-12-20T10:28:44
2004 Script Info: | Not valid after: 2021-02-18T20:52:40
2005 Script Info: | MD5: 3bc6 ecca bde0 0f36 8cd7 1e6a 0ce4 bcc9
2006 Script Info: |_SHA-1: e0a9 130d 7691 f745 14ed 6346 3fae 05f7 3709 4e32
2007 Script Info: Device type: general purpose|WAP
2008 Script Info: Running (JUST GUESSING): Linux 2.6.X|2.4.X (90%), Microsoft Windows 2012 (85%)
2009 Os Info: OS: Windows; CPE: cpe:/o:microsoft:windows
2010 IP: 207.241.128.23
2011 Type: SPF
2012 Is Active: True (reset ttl 64)
2013 Port: 80/tcp open http syn-ack ttl 116 Microsoft IIS httpd 7.5
2014 Script Info: |_http-favicon: Unknown favicon MD5: 7EB5B3865441954A3B905A0088D08B58
2015 Script Info: | http-methods:
2016 Script Info: |_ Supported Methods: GET HEAD POST OPTIONS
2017 Script Info: |_http-server-header: Microsoft-IIS/7.5
2018 Script Info: | http-title: IMail Web Client - Login
2019 Script Info: |_Requested resource was /Login.aspx?ReturnUrl=%2f
2020 Script Info: |_http-trane-info: Problem with XML parsing of /evox/about
2021 Port: 110/tcp open pop3 syn-ack ttl 116 IMail pop3d 12.5.7.59 622689-12
2022 Script Info: |_pop3-capabilities: TOP UIDL RESP-CODES LOGIN-DELAY(120) PIPELINING USER SASL(LOGIN PLAIN CRAM-MD5) EXPIRE(30 USER) IMPLEMENTATION(Ipswitch_IMail_12)
2023 Script Info: | ssl-cert: Subject: commonName=*.cmsinter.net
2024 Script Info: | Subject Alternative Name: DNS:*.cmsinter.net, DNS:cmsinter.net
2025 Script Info: | Issuer: commonName=Go Daddy Secure Certificate Authority - G2/organizationName=GoDaddy.com, Inc./stateOrProvinceName=Arizona/countryName=US
2026 Script Info: | Public Key type: rsa
2027 Script Info: | Public Key bits: 2048
2028 Script Info: | Signature Algorithm: sha256WithRSAEncryption
2029 Script Info: | Not valid before: 2017-05-16T18:32:00
2030 Script Info: | Not valid after: 2020-05-16T18:32:00
2031 Script Info: | MD5: 0c15 b448 afda 5173 802e b22a 025b 13ac
2032 Script Info: |_SHA-1: b50e 3c15 8fc5 74ce d2a4 8985 f08a 4f44 ba95 748e
2033 Script Info: |_ssl-date: TLS randomness does not represent time
2034 Port: 143/tcp open imap? syn-ack ttl 116
2035 Script Info: | fingerprint-strings:
2036 Script Info: | DNSStatusRequestTCP, DNSVersionBindReqTCP, Kerberos, NULL, RPCCheck, SMBProgNeg, SSLSessionReq, TLSSessionReq, TerminalServerCookie, X11Probe:
2037 Script Info: | * OK IMAP4 Server mail1.cmsinter.net (IMail 12.5.7.59)
2038 Script Info: | FourOhFourRequest:
2039 Script Info: | * OK IMAP4 Server mail1.cmsinter.net (IMail 12.5.7.59)
2040 Script Info: | Invalid Syntax
2041 Script Info: | Null Command
2042 Script Info: | GenericLines:
2043 Script Info: | * OK IMAP4 Server mail1.cmsinter.net (IMail 12.5.7.59)
2044 Script Info: | Null Command
2045 Script Info: | Null Command
2046 Script Info: | GetRequest:
2047 Script Info: | * OK IMAP4 Server mail1.cmsinter.net (IMail 12.5.7.59)
2048 Script Info: | Unknown Command
2049 Script Info: | Null Command
2050 Script Info: | HTTPOptions, RTSPRequest:
2051 Script Info: | * OK IMAP4 Server mail1.cmsinter.net (IMail 12.5.7.59)
2052 Script Info: | OPTIONS BAD / Unknown Command
2053 Script Info: | Null Command
2054 Script Info: | Help:
2055 Script Info: | * OK IMAP4 Server mail1.cmsinter.net (IMail 12.5.7.59)
2056 Script Info: |_ HELP BAD Null Command
2057 Script Info: |_imap-capabilities: IMAP4 AUTH=CRAM-MD5 CAPABILITY IDLEA0001 AUTH=LOGIN OK STARTTLS completed AUTH=PLAIN IMAP4rev1
2058 Script Info: | ssl-cert: Subject: commonName=*.cmsinter.net
2059 Script Info: | Subject Alternative Name: DNS:*.cmsinter.net, DNS:cmsinter.net
2060 Script Info: | Issuer: commonName=Go Daddy Secure Certificate Authority - G2/organizationName=GoDaddy.com, Inc./stateOrProvinceName=Arizona/countryName=US
2061 Script Info: | Public Key type: rsa
2062 Script Info: | Public Key bits: 2048
2063 Script Info: | Signature Algorithm: sha256WithRSAEncryption
2064 Script Info: | Not valid before: 2017-05-16T18:32:00
2065 Script Info: | Not valid after: 2020-05-16T18:32:00
2066 Script Info: | MD5: 0c15 b448 afda 5173 802e b22a 025b 13ac
2067 Script Info: |_SHA-1: b50e 3c15 8fc5 74ce d2a4 8985 f08a 4f44 ba95 748e
2068 Script Info: |_ssl-date: TLS randomness does not represent time
2069 Port: 443/tcp open ssl/https? syn-ack ttl 116
2070 Script Info: |_ssl-date: 2019-10-12T13:19:34+00:00; 0s from scanner time.
2071 Script Info: | sslv2:
2072 Script Info: | SSLv2 supported
2073 Script Info: | ciphers:
2074 Script Info: | SSL2_RC4_128_WITH_MD5
2075 Script Info: |_ SSL2_DES_192_EDE3_CBC_WITH_MD5
2076 Port: 465/tcp open ssl/smtps? syn-ack ttl 116
2077 Script Info: | fingerprint-strings:
2078 Script Info: | GenericLines, GetRequest, NULL:
2079 Script Info: | 220 mail.cmsinter.net
2080 Script Info: | Hello:
2081 Script Info: | 220 mail.cmsinter.net
2082 Script Info: | 250-mail1.cmsinter.net says hello
2083 Script Info: | 250-SIZE 52428800
2084 Script Info: | 250-8BITMIME
2085 Script Info: | 250-DSN
2086 Script Info: | 250-ETRN
2087 Script Info: | 250-AUTH LOGIN CRAM-MD5
2088 Script Info: | 250-AUTH LOGIN
2089 Script Info: | AUTH=LOGIN
2090 Script Info: | Help:
2091 Script Info: | 220 mail.cmsinter.net
2092 Script Info: |_ DATA EHLO HELO MAIL NOOP QUIT RCPT RSET VRFY
2093 Script Info: |_smtp-commands: Couldn't establish connection on port 465
2094 Port: 587/tcp open submission? syn-ack ttl 116
2095 Script Info: | fingerprint-strings:
2096 Script Info: | GenericLines, GetRequest, HTTPOptions, Help, NULL:
2097 Script Info: | 220 mail.cmsinter.net
2098 Script Info: | Hello:
2099 Script Info: | 220 mail.cmsinter.net
2100 Script Info: | 250-mail1.cmsinter.net says hello
2101 Script Info: | 250-SIZE 52428800
2102 Script Info: | 250-8BITMIME
2103 Script Info: | 250-DSN
2104 Script Info: | 250-ETRN
2105 Script Info: | 250-AUTH LOGIN CRAM-MD5
2106 Script Info: | 250-AUTH LOGIN
2107 Script Info: | 250-AUTH=LOGIN
2108 Script Info: |_ STARTTLS
2109 Script Info: |_smtp-commands: Couldn't establish connection on port 587
2110 Port: 993/tcp open ssl/imaps? syn-ack ttl 116
2111 Script Info: | fingerprint-strings:
2112 Script Info: | DNSStatusRequestTCP, DNSVersionBindReqTCP, Kerberos, NULL, RPCCheck, SMBProgNeg, SSLSessionReq, TLSSessionReq, TerminalServerCookie, X11Probe:
2113 Script Info: | * OK IMAP4 Server mail1.cmsinter.net (IMail 12.5.7.59)
2114 Script Info: | FourOhFourRequest:
2115 Script Info: | * OK IMAP4 Server mail1.cmsinter.net (IMail 12.5.7.59)
2116 Script Info: | Invalid Syntax
2117 Script Info: | Null Command
2118 Script Info: | GenericLines:
2119 Script Info: | * OK IMAP4 Server mail1.cmsinter.net (IMail 12.5.7.59)
2120 Script Info: | Null Command
2121 Script Info: | Null Command
2122 Script Info: | GetRequest:
2123 Script Info: | * OK IMAP4 Server mail1.cmsinter.net (IMail 12.5.7.59)
2124 Script Info: | Unknown Command
2125 Script Info: | Null Command
2126 Script Info: | HTTPOptions, RTSPRequest:
2127 Script Info: | * OK IMAP4 Server mail1.cmsinter.net (IMail 12.5.7.59)
2128 Script Info: | OPTIONS BAD / Unknown Command
2129 Script Info: | Null Command
2130 Script Info: | Help:
2131 Script Info: | * OK IMAP4 Server mail1.cmsinter.net (IMail 12.5.7.59)
2132 Script Info: |_ HELP BAD Null Command
2133 Script Info: |_imap-capabilities: IMAP4 AUTH=CRAM-MD5 CAPABILITY IDLEA0001 AUTH=LOGIN OK completed AUTH=PLAIN IMAP4rev1
2134 Script Info: | ssl-cert: Subject: commonName=*.cmsinter.net
2135 Script Info: | Subject Alternative Name: DNS:*.cmsinter.net, DNS:cmsinter.net
2136 Script Info: | Issuer: commonName=Go Daddy Secure Certificate Authority - G2/organizationName=GoDaddy.com, Inc./stateOrProvinceName=Arizona/countryName=US
2137 Script Info: | Public Key type: rsa
2138 Script Info: | Public Key bits: 2048
2139 Script Info: | Signature Algorithm: sha256WithRSAEncryption
2140 Script Info: | Not valid before: 2017-05-16T18:32:00
2141 Script Info: | Not valid after: 2020-05-16T18:32:00
2142 Script Info: | MD5: 0c15 b448 afda 5173 802e b22a 025b 13ac
2143 Script Info: |_SHA-1: b50e 3c15 8fc5 74ce d2a4 8985 f08a 4f44 ba95 748e
2144 Script Info: |_ssl-date: TLS randomness does not represent time
2145 Port: 995/tcp open ssl/pop3 syn-ack ttl 116 IMail pop3d 12.5.7.59 622694-13
2146 Script Info: |_pop3-capabilities: TOP UIDL RESP-CODES LOGIN-DELAY(120) PIPELINING USER SASL(LOGIN PLAIN CRAM-MD5) EXPIRE(30 USER) IMPLEMENTATION(Ipswitch_IMail_12)
2147 Script Info: | ssl-cert: Subject: commonName=*.cmsinter.net
2148 Script Info: | Subject Alternative Name: DNS:*.cmsinter.net, DNS:cmsinter.net
2149 Script Info: | Issuer: commonName=Go Daddy Secure Certificate Authority - G2/organizationName=GoDaddy.com, Inc./stateOrProvinceName=Arizona/countryName=US
2150 Script Info: | Public Key type: rsa
2151 Script Info: | Public Key bits: 2048
2152 Script Info: | Signature Algorithm: sha256WithRSAEncryption
2153 Script Info: | Not valid before: 2017-05-16T18:32:00
2154 Script Info: | Not valid after: 2020-05-16T18:32:00
2155 Script Info: | MD5: 0c15 b448 afda 5173 802e b22a 025b 13ac
2156 Script Info: |_SHA-1: b50e 3c15 8fc5 74ce d2a4 8985 f08a 4f44 ba95 748e
2157 Script Info: |_ssl-date: TLS randomness does not represent time
2158 Os Info: Host: mail1.cmsinter.net; OS: Windows; CPE: cpe:/o:microsoft:windows
2159 IP: 209.222.82.129
2160 HostName: d22800a.ess.barracudanetworks.com Type: MX
2161 HostName: mail.ess.barracuda.com Type: PTR
2162 Country: United States
2163 Is Active: True (reset ttl 64)
2164 Port: 587/tcp open smtp syn-ack ttl 42
2165 Script Info: | fingerprint-strings:
2166 Script Info: | GenericLines:
2167 Script Info: | 220 mail.ess.barracuda.com ESMTP (mx124.us-east-2a.ess.aws)
2168 Script Info: | Syntax error, command unrecognized
2169 IP: 209.222.82.126
2170 HostName: d22800a.ess.barracudanetworks.com Type: MX
2171 HostName: mail.ess.barracuda.com Type: PTR
2172 Country: United States
2173 Is Active: True (echo-reply ttl 43)
2174 Port: 587/tcp open smtp syn-ack ttl 42
2175 Script Info: | fingerprint-strings:
2176 Script Info: | GenericLines:
2177 Script Info: | 220 mail.ess.barracuda.com ESMTP (mx101.us-east-2a.ess.aws)
2178 Script Info: | Syntax error, command unrecognized
2179 IP: 209.222.82.165
2180 HostName: d22800a.ess.barracudanetworks.com Type: MX
2181 HostName: mail.ess.barracuda.com Type: PTR
2182 Country: United States
2183 Is Active: True (echo-reply ttl 43)
2184 Port: 587/tcp open smtp syn-ack ttl 42
2185 Script Info: | fingerprint-strings:
2186 Script Info: | GenericLines, GetRequest:
2187 Script Info: | 220 mail.ess.barracuda.com ESMTP (mx229.us-east-2b.ess.aws)
2188 Script Info: | Syntax error, command unrecognized
2189 IP: 209.222.82.159
2190 HostName: d22800a.ess.barracudanetworks.com Type: MX
2191 HostName: mail.ess.barracuda.com Type: PTR
2192 Country: United States
2193 Is Active: True (echo-reply ttl 43)
2194 Port: 587/tcp open smtp syn-ack ttl 42
2195 Script Info: | fingerprint-strings:
2196 Script Info: | GenericLines:
2197 Script Info: | 220 mail.ess.barracuda.com ESMTP (mx203.us-east-2b.ess.aws)
2198 Script Info: | Syntax error, command unrecognized
2199 IP: 173.201.73.6
2200 HostName: ns12.domaincontrol.com Type: NS
2201 HostName: ns12.domaincontrol.com Type: PTR
2202 Country: United States
2203 Is Active: True (echo-reply ttl 52)
2204 Port: 53/tcp open tcpwrapped syn-ack ttl 56
2205 IP: 209.222.82.153
2206 HostName: d22800a.ess.barracudanetworks.com Type: MX
2207 HostName: mail.ess.barracuda.com Type: PTR
2208 Country: United States
2209 Is Active: True (reset ttl 64)
2210 Port: 587/tcp open smtp syn-ack ttl 42
2211 Script Info: | fingerprint-strings:
2212 Script Info: | GenericLines:
2213 Script Info: | 220 mail.ess.barracuda.com ESMTP (mx182.us-east-2b.ess.aws)
2214 Script Info: | Syntax error, command unrecognized
2215 IP: 209.222.82.150
2216 HostName: d22800a.ess.barracudanetworks.com Type: MX
2217 HostName: mail.ess.barracuda.com Type: PTR
2218 Country: United States
2219 Is Active: True (echo-reply ttl 43)
2220 Port: 587/tcp open smtp syn-ack ttl 42
2221 Script Info: | fingerprint-strings:
2222 Script Info: | GenericLines:
2223 Script Info: | 220 mail.ess.barracuda.com ESMTP (mx180.us-east-2a.ess.aws)
2224 Script Info: | Syntax error, command unrecognized
2225 IP: 209.222.82.156
2226 HostName: d22800a.ess.barracudanetworks.com Type: MX
2227 HostName: mail.ess.barracuda.com Type: PTR
2228 Country: United States
2229 Is Active: True (echo-reply ttl 43)
2230 IP: 67.209.250.204
2231 HostName: mail.michiganmasons.org. Type: A
2232 HostName: webmail.michiganmasons.org. Type: A
2233 HostName: web-2-204.winntel.com Type: PTR
2234 HostName: smtp.michiganmasons.org. Type: A
2235 HostName: imap.michiganmasons.org. Type: A
2236 HostName: pop3.michiganmasons.org. Type: A
2237 Country: United States
2238 Is Active: True (reset ttl 64)
2239 Port: 21/tcp open ftp syn-ack ttl 55 ProFTPD
2240 Script Info: | ssl-cert: Subject: commonName=webcontrol.winntel.com
2241 Script Info: | Subject Alternative Name: DNS:webcontrol.winntel.com
2242 Script Info: | Issuer: commonName=Let's Encrypt Authority X3/organizationName=Let's Encrypt/countryName=US
2243 Script Info: | Public Key type: rsa
2244 Script Info: | Public Key bits: 2048
2245 Script Info: | Signature Algorithm: sha256WithRSAEncryption
2246 Script Info: | Not valid before: 2019-09-29T17:47:32
2247 Script Info: | Not valid after: 2019-12-28T17:47:32
2248 Script Info: | MD5: 460c 586e df42 c7c0 b68a 773a 9f3c c4d9
2249 Script Info: |_SHA-1: 1f8e f5d2 f802 7026 e54d c6e6 f34c ff42 bdc8 191e
2250 Script Info: |_ssl-date: TLS randomness does not represent time
2251 Script Info: | tls-nextprotoneg:
2252 Script Info: |_ ftp
2253 Port: 53/tcp open domain syn-ack ttl 55 (unknown banner: none)
2254 Script Info: | dns-nsid:
2255 Script Info: |_ bind.version: none
2256 Script Info: | fingerprint-strings:
2257 Script Info: | DNSVersionBindReqTCP:
2258 Script Info: | version
2259 Script Info: | bind
2260 Script Info: |_ none
2261 Port: 80/tcp open http syn-ack ttl 55 nginx
2262 Script Info: |_http-favicon: Parallels Plesk
2263 Script Info: | http-methods:
2264 Script Info: |_ Supported Methods: GET HEAD POST OPTIONS
2265 Script Info: |_http-title: Web Server's Default Page
2266 Port: 110/tcp open pop3 syn-ack ttl 55 Courier pop3d
2267 Script Info: |_pop3-capabilities: PIPELINING SASL(LOGIN CRAM-MD5 CRAM-SHA1 CRAM-SHA256 PLAIN) STLS USER UIDL IMPLEMENTATION(Courier Mail Server) APOP TOP LOGIN-DELAY(10)
2268 Script Info: | ssl-cert: Subject: commonName=virt-mail.winntel.com
2269 Script Info: | Subject Alternative Name: DNS:virt-mail.winntel.com
2270 Script Info: | Issuer: commonName=Let's Encrypt Authority X3/organizationName=Let's Encrypt/countryName=US
2271 Script Info: | Public Key type: rsa
2272 Script Info: | Public Key bits: 2048
2273 Script Info: | Signature Algorithm: sha256WithRSAEncryption
2274 Script Info: | Not valid before: 2019-09-29T17:47:05
2275 Script Info: | Not valid after: 2019-12-28T17:47:05
2276 Script Info: | MD5: 70ac d8a3 7eac 21b7 857a 1aaa f8c5 fa1c
2277 Script Info: |_SHA-1: a014 ad57 1e12 88cc e297 b23a c5da 5157 1d4f d75e
2278 Script Info: |_ssl-date: TLS randomness does not represent time
2279 Port: 143/tcp open imap syn-ack ttl 55 Courier Imapd (released 2017)
2280 Script Info: |_imap-capabilities: ACL2=UNION THREAD=REFERENCES THREAD=ORDEREDSUBJECT SORT AUTH=PLAIN AUTH=CRAM-MD5 ACL NAMESPACE AUTH=CRAM-SHA1 UIDPLUS CHILDREN CAPABILITY STARTTLSA0001 QUOTA OK IMAP4rev1 IDLE completed AUTH=CRAM-SHA256
2281 Script Info: | ssl-cert: Subject: commonName=virt-mail.winntel.com
2282 Script Info: | Subject Alternative Name: DNS:virt-mail.winntel.com
2283 Script Info: | Issuer: commonName=Let's Encrypt Authority X3/organizationName=Let's Encrypt/countryName=US
2284 Script Info: | Public Key type: rsa
2285 Script Info: | Public Key bits: 2048
2286 Script Info: | Signature Algorithm: sha256WithRSAEncryption
2287 Script Info: | Not valid before: 2019-09-29T17:47:05
2288 Script Info: | Not valid after: 2019-12-28T17:47:05
2289 Script Info: | MD5: 70ac d8a3 7eac 21b7 857a 1aaa f8c5 fa1c
2290 Script Info: |_SHA-1: a014 ad57 1e12 88cc e297 b23a c5da 5157 1d4f d75e
2291 Script Info: |_ssl-date: TLS randomness does not represent time
2292 Port: 443/tcp open ssl/http syn-ack ttl 55 nginx
2293 Script Info: |_http-favicon: Parallels Plesk
2294 Script Info: | http-methods:
2295 Script Info: |_ Supported Methods: GET HEAD POST OPTIONS
2296 Script Info: |_http-title: Web Server's Default Page
2297 Script Info: | ssl-cert: Subject: commonName=Plesk/organizationName=Plesk/countryName=CH
2298 Script Info: | Issuer: commonName=Plesk/organizationName=Plesk/countryName=CH
2299 Script Info: | Public Key type: rsa
2300 Script Info: | Public Key bits: 2048
2301 Script Info: | Signature Algorithm: sha256WithRSAEncryption
2302 Script Info: | Not valid before: 2018-07-02T04:48:34
2303 Script Info: | Not valid after: 2019-07-02T04:48:34
2304 Script Info: | MD5: 751b ad5b 6ae1 adb1 de68 4f90 9702 1819
2305 Script Info: |_SHA-1: 4831 321f 030c 5b2f 9d68 4ce6 7676 c7d0 c395 2fae
2306 Script Info: |_ssl-date: TLS randomness does not represent time
2307 Script Info: | tls-alpn:
2308 Script Info: | h2
2309 Script Info: |_ http/1.1
2310 Script Info: | tls-nextprotoneg:
2311 Script Info: | h2
2312 Script Info: |_ http/1.1
2313 Port: 465/tcp open ssl/smtp syn-ack ttl 55 Postfix smtpd
2314 Script Info: |_smtp-commands: WebServ-110.WinnTel.Net, PIPELINING, SIZE 102400000, ETRN, AUTH DIGEST-MD5 CRAM-MD5 PLAIN LOGIN, ENHANCEDSTATUSCODES, 8BITMIME, DSN,
2315 Script Info: | ssl-cert: Subject: commonName=virt-mail.winntel.com
2316 Script Info: | Subject Alternative Name: DNS:virt-mail.winntel.com
2317 Script Info: | Issuer: commonName=Let's Encrypt Authority X3/organizationName=Let's Encrypt/countryName=US
2318 Script Info: | Public Key type: rsa
2319 Script Info: | Public Key bits: 2048
2320 Script Info: | Signature Algorithm: sha256WithRSAEncryption
2321 Script Info: | Not valid before: 2019-09-29T17:47:05
2322 Script Info: | Not valid after: 2019-12-28T17:47:05
2323 Script Info: | MD5: 70ac d8a3 7eac 21b7 857a 1aaa f8c5 fa1c
2324 Script Info: |_SHA-1: a014 ad57 1e12 88cc e297 b23a c5da 5157 1d4f d75e
2325 Script Info: |_ssl-date: TLS randomness does not represent time
2326 Port: 587/tcp open smtp syn-ack ttl 55 Postfix smtpd
2327 Script Info: |_smtp-commands: WebServ-110.WinnTel.Net, PIPELINING, SIZE 102400000, ETRN, STARTTLS, ENHANCEDSTATUSCODES, 8BITMIME, DSN,
2328 Script Info: | ssl-cert: Subject: commonName=virt-mail.winntel.com
2329 Script Info: | Subject Alternative Name: DNS:virt-mail.winntel.com
2330 Script Info: | Issuer: commonName=Let's Encrypt Authority X3/organizationName=Let's Encrypt/countryName=US
2331 Script Info: | Public Key type: rsa
2332 Script Info: | Public Key bits: 2048
2333 Script Info: | Signature Algorithm: sha256WithRSAEncryption
2334 Script Info: | Not valid before: 2019-09-29T17:47:05
2335 Script Info: | Not valid after: 2019-12-28T17:47:05
2336 Script Info: | MD5: 70ac d8a3 7eac 21b7 857a 1aaa f8c5 fa1c
2337 Script Info: |_SHA-1: a014 ad57 1e12 88cc e297 b23a c5da 5157 1d4f d75e
2338 Script Info: |_ssl-date: TLS randomness does not represent time
2339 Port: 993/tcp open ssl/imap syn-ack ttl 55 Courier Imapd (released 2017)
2340 Script Info: |_imap-capabilities: IMAP4rev1 THREAD=REFERENCES THREAD=ORDEREDSUBJECT SORT AUTH=PLAIN AUTH=CRAM-MD5 ACL NAMESPACE AUTH=CRAM-SHA1 ACL2=UNIONA0001 UIDPLUS CHILDREN QUOTA OK CAPABILITY IDLE completed AUTH=CRAM-SHA256
2341 Script Info: | ssl-cert: Subject: commonName=virt-mail.winntel.com
2342 Script Info: | Subject Alternative Name: DNS:virt-mail.winntel.com
2343 Script Info: | Issuer: commonName=Let's Encrypt Authority X3/organizationName=Let's Encrypt/countryName=US
2344 Script Info: | Public Key type: rsa
2345 Script Info: | Public Key bits: 2048
2346 Script Info: | Signature Algorithm: sha256WithRSAEncryption
2347 Script Info: | Not valid before: 2019-09-29T17:47:05
2348 Script Info: | Not valid after: 2019-12-28T17:47:05
2349 Script Info: | MD5: 70ac d8a3 7eac 21b7 857a 1aaa f8c5 fa1c
2350 Script Info: |_SHA-1: a014 ad57 1e12 88cc e297 b23a c5da 5157 1d4f d75e
2351 Script Info: |_ssl-date: TLS randomness does not represent time
2352 Port: 995/tcp open ssl/pop3 syn-ack ttl 55 Courier pop3d
2353 Script Info: |_pop3-capabilities: PIPELINING UIDL APOP SASL(LOGIN PLAIN) IMPLEMENTATION(Courier Mail Server) LOGIN-DELAY(10) TOP USER
2354 Script Info: | ssl-cert: Subject: commonName=virt-mail.winntel.com
2355 Script Info: | Subject Alternative Name: DNS:virt-mail.winntel.com
2356 Script Info: | Issuer: commonName=Let's Encrypt Authority X3/organizationName=Let's Encrypt/countryName=US
2357 Script Info: | Public Key type: rsa
2358 Script Info: | Public Key bits: 2048
2359 Script Info: | Signature Algorithm: sha256WithRSAEncryption
2360 Script Info: | Not valid before: 2019-09-29T17:47:05
2361 Script Info: | Not valid after: 2019-12-28T17:47:05
2362 Script Info: | MD5: 70ac d8a3 7eac 21b7 857a 1aaa f8c5 fa1c
2363 Script Info: |_SHA-1: a014 ad57 1e12 88cc e297 b23a c5da 5157 1d4f d75e
2364 Script Info: |_ssl-date: TLS randomness does not represent time
2365 Port: 8443/tcp open ssl/http syn-ack ttl 55 sw-cp-server httpd (Plesk Onyx 17.8.11)
2366 Script Info: |_http-favicon: Parallels Plesk
2367 Script Info: | http-methods:
2368 Script Info: |_ Supported Methods: GET HEAD POST
2369 Script Info: | http-robots.txt: 1 disallowed entry
2370 Script Info: |_/
2371 Script Info: |_http-server-header: sw-cp-server
2372 Script Info: |_http-title: Plesk Onyx 17.8.11
2373 Script Info: | ssl-cert: Subject: commonName=webcontrol.winntel.com
2374 Script Info: | Subject Alternative Name: DNS:webcontrol.winntel.com
2375 Script Info: | Issuer: commonName=Let's Encrypt Authority X3/organizationName=Let's Encrypt/countryName=US
2376 Script Info: | Public Key type: rsa
2377 Script Info: | Public Key bits: 2048
2378 Script Info: | Signature Algorithm: sha256WithRSAEncryption
2379 Script Info: | Not valid before: 2019-09-29T17:47:32
2380 Script Info: | Not valid after: 2019-12-28T17:47:32
2381 Script Info: | MD5: 460c 586e df42 c7c0 b68a 773a 9f3c c4d9
2382 Script Info: |_SHA-1: 1f8e f5d2 f802 7026 e54d c6e6 f34c ff42 bdc8 191e
2383 Script Info: |_ssl-date: TLS randomness does not represent time
2384 Script Info: | tls-alpn:
2385 Script Info: |_ http/1.1
2386 Script Info: | tls-nextprotoneg:
2387 Script Info: |_ http/1.1
2388 Os Info: Hosts: localhost.localdomain, WebServ-110.WinnTel.Net
2389 IP: 209.222.82.138
2390 HostName: d22800a.ess.barracudanetworks.com Type: MX
2391 HostName: mail.ess.barracuda.com Type: PTR
2392 Country: United States
2393 Is Active: True (reset ttl 64)
2394 Port: 587/tcp open smtp syn-ack ttl 42
2395 Script Info: | fingerprint-strings:
2396 Script Info: | GenericLines, GetRequest:
2397 Script Info: | 220 mail.ess.barracuda.com ESMTP (mx106.us-east-2b.ess.aws)
2398 Script Info: | Syntax error, command unrecognized
2399 IP: 209.222.82.135
2400 HostName: d22800a.ess.barracudanetworks.com Type: MX
2401 HostName: mail.ess.barracuda.com Type: PTR
2402 Country: United States
2403 Is Active: True (echo-reply ttl 43)
2404 Port: 587/tcp open smtp syn-ack ttl 42
2405 Script Info: | fingerprint-strings:
2406 Script Info: | GenericLines:
2407 Script Info: | 220 mail.ess.barracuda.com ESMTP (mx164.us-east-2a.ess.aws)
2408 Script Info: | Syntax error, command unrecognized
2409 IP: 67.209.250.165
2410 Type: SPF
2411 Is Active: True (reset ttl 64)
2412 IP: 67.209.250.166
2413 Type: SPF
2414 Is Active: True (reset ttl 64)
2415 Port: 80/tcp open http syn-ack ttl 116 Microsoft IIS httpd 7.5
2416 Script Info: |_http-server-header: Microsoft-IIS/7.5
2417 Port: 443/tcp open ssl/https? syn-ack ttl 116
2418 Script Info: |_ssl-date: 2019-10-12T13:30:57+00:00; 0s from scanner time.
2419 Script Info: | sslv2:
2420 Script Info: | SSLv2 supported
2421 Script Info: | ciphers:
2422 Script Info: | SSL2_RC4_128_WITH_MD5
2423 Script Info: |_ SSL2_DES_192_EDE3_CBC_WITH_MD5
2424 Script Info: Device type: general purpose|WAP
2425 Script Info: Running (JUST GUESSING): Linux 2.6.X|2.4.X (90%), Microsoft Windows 2008|7|Vista (86%)
2426 Os Info: OS: Windows; CPE: cpe:/o:microsoft:windows
2427 IP: 209.222.82.132
2428 HostName: d22800a.ess.barracudanetworks.com Type: MX
2429 HostName: mail.ess.barracuda.com Type: PTR
2430 Country: United States
2431 Is Active: True (reset ttl 64)
2432 Port: 587/tcp open smtp syn-ack ttl 42
2433 Script Info: | fingerprint-strings:
2434 Script Info: | GenericLines, GetRequest:
2435 Script Info: | 220 mail.ess.barracuda.com ESMTP (mx140.us-east-2a.ess.aws)
2436 Script Info: | Syntax error, command unrecognized
2437 IP: 97.74.105.6
2438 HostName: ns11.domaincontrol.com Type: NS
2439 HostName: ns11.domaincontrol.com Type: PTR
2440 Country: United States
2441 Is Active: True (echo-reply ttl 52)
2442 Port: 53/tcp open tcpwrapped syn-ack ttl 52
2443 IP: 207.241.128.7
2444 HostName: mx1.cmsinter.net Type: MX
2445 HostName: mx1.cmsinter.net Type: PTR
2446 Country: United States
2447 Is Active: True (reset ttl 64)
2448 Port: 80/tcp open http syn-ack ttl 52 nginx
2449 Script Info: |_http-favicon: Unknown favicon MD5: EEB82041F5921BC49ED723997A5BF35F
2450 Script Info: | http-methods:
2451 Script Info: |_ Supported Methods: GET HEAD
2452 Script Info: | http-robots.txt: 1 disallowed entry
2453 Script Info: |_/
2454 Script Info: |_http-title: Site doesn't have a title (text/html).
2455 Port: 443/tcp open ssl/http syn-ack ttl 52 nginx
2456 Script Info: |_http-favicon: Unknown favicon MD5: EEB82041F5921BC49ED723997A5BF35F
2457 Script Info: | http-methods:
2458 Script Info: |_ Supported Methods: GET HEAD
2459 Script Info: | http-robots.txt: 1 disallowed entry
2460 Script Info: |_/
2461 Script Info: |_http-server-header: BarracudaHTTP 4.0
2462 Script Info: |_http-title: Site doesn't have a title (text/html).
2463 Script Info: | ssl-cert: Subject: commonName=*.cmsinter.net
2464 Script Info: | Subject Alternative Name: DNS:*.cmsinter.net, DNS:cmsinter.net
2465 Script Info: | Issuer: commonName=Go Daddy Secure Certificate Authority - G2/organizationName=GoDaddy.com, Inc./stateOrProvinceName=Arizona/countryName=US
2466 Script Info: | Public Key type: rsa
2467 Script Info: | Public Key bits: 2048
2468 Script Info: | Signature Algorithm: sha256WithRSAEncryption
2469 Script Info: | Not valid before: 2017-05-16T18:32:00
2470 Script Info: | Not valid after: 2020-05-16T18:32:00
2471 Script Info: | MD5: 0c15 b448 afda 5173 802e b22a 025b 13ac
2472 Script Info: |_SHA-1: b50e 3c15 8fc5 74ce d2a4 8985 f08a 4f44 ba95 748e
2473 Script Info: |_ssl-date: TLS randomness does not represent time
2474#######################################################################################################################################
2475dnsenum VERSION:1.2.4
2476
2477----- www.michiganmasons.org -----
2478
2479
2480Host's addresses:
2481__________________
2482
2483michiganmasons.org. 1626 IN A 67.209.250.173
2484
2485
2486Name Servers:
2487______________
2488
2489ns12.domaincontrol.com. 85838 IN A 173.201.73.6
2490ns11.domaincontrol.com. 85838 IN A 97.74.105.6
2491
2492
2493Mail (MX) Servers:
2494___________________
2495
2496mx1.cmsinter.net. 3148 IN A 207.241.128.7
2497d22800a.ess.barracudanetworks.com. 19 IN A 209.222.82.135
2498d22800a.ess.barracudanetworks.com. 19 IN A 209.222.82.126
2499d22800a.ess.barracudanetworks.com. 19 IN A 209.222.82.138
2500d22800a.ess.barracudanetworks.com. 19 IN A 209.222.82.159
2501d22800a.ess.barracudanetworks.com. 19 IN A 209.222.82.132
2502d22800a.ess.barracudanetworks.com. 19 IN A 209.222.82.150
2503d22800a.ess.barracudanetworks.com. 19 IN A 209.222.82.141
2504d22800a.ess.barracudanetworks.com. 19 IN A 209.222.82.147
2505d22800a.ess.barracudanetworks.com. 19 IN A 209.222.82.165
2506d22800a.ess.barracudanetworks.com. 19 IN A 209.222.82.162
2507d22800a.ess.barracudanetworks.com. 19 IN A 209.222.82.144
2508d22800a.ess.barracudanetworks.com. 19 IN A 209.222.82.129
2509d22800a.ess.barracudanetworks.com. 19 IN A 209.222.82.156
2510d22800a.ess.barracudanetworks.com. 19 IN A 209.222.82.153
2511
2512
2513Trying Zone Transfers and getting Bind Versions:
2514_________________________________________________
2515
2516
2517Trying Zone Transfer for www.michiganmasons.org on ns12.domaincontrol.com ...
2518
2519Trying Zone Transfer for www.michiganmasons.org on ns11.domaincontrol.com ...
2520
2521brute force file not specified, bay.
2522#######################################################################################################################################
2523[*] Processing domain www.michiganmasons.org
2524[*] Using system resolvers ['38.132.106.139', '194.187.251.67', '185.93.180.131', '2001:18c0:121:6900:724f:b8ff:fefd:5b6a', '192.168.0.1']
2525[+] Getting nameservers
252697.74.105.6 - ns11.domaincontrol.com
2527173.201.73.6 - ns12.domaincontrol.com
2528[-] Zone transfer failed
2529
2530[+] TXT records found
2531"v=spf1 mx ip4:67.209.250.165/32 ip4:67.209.250.166/32 ip4:207.241.128.23/32 -all"
2532
2533[+] MX records found, added to target list
253410 mx1.cmsinter.net.
253520 d22800a.ess.barracudanetworks.com.
2536
2537[*] Scanning www.michiganmasons.org for A records
253867.209.250.173 - www.michiganmasons.org
2539#######################################################################################################################################
2540[*] Found SPF record:
2541[*] v=spf1 mx ip4:67.209.250.165/32 ip4:67.209.250.166/32 ip4:207.241.128.23/32 -all
2542[*] SPF record contains an All item: -all
2543[*] No DMARC record found. Looking for organizational record
2544[+] No organizational DMARC record
2545[+] Spoofing possible for www.michiganmasons.org!
2546#######################################################################################################################################
254710-12](09:15)x•
2548Starting Nmap 7.80 ( https://nmap.org ) at 2019-10-12 09:15 EDT
2549Nmap scan report for www.michiganmasons.org (67.209.250.173)
2550Host is up (0.077s latency).
2551rDNS record for 67.209.250.173: a67-209-250-173.cust.mi.winntel.net
2552Not shown: 994 filtered ports, 4 closed ports
2553Some closed ports may be reported as filtered due to --defeat-rst-ratelimit
2554PORT STATE SERVICE
255580/tcp open http
2556443/tcp open https
2557
2558Nmap done: 1 IP address (1 host up) scanned in 7.21 seconds
2559#######################################################################################################################################
2560Starting Nmap 7.80 ( https://nmap.org ) at 2019-10-12 09:15 EDT
2561Nmap scan report for www.michiganmasons.org (67.209.250.173)
2562Host is up (0.076s latency).
2563rDNS record for 67.209.250.173: a67-209-250-173.cust.mi.winntel.net
2564Not shown: 2 filtered ports
2565PORT STATE SERVICE
256653/udp open|filtered domain
256767/udp open|filtered dhcps
256868/udp open|filtered dhcpc
256969/udp open|filtered tftp
257088/udp open|filtered kerberos-sec
2571123/udp open|filtered ntp
2572139/udp open|filtered netbios-ssn
2573161/udp open|filtered snmp
2574162/udp open|filtered snmptrap
2575389/udp open|filtered ldap
2576500/udp open|filtered isakmp
2577520/udp open|filtered route
25782049/udp open|filtered nfs
2579
2580Nmap done: 1 IP address (1 host up) scanned in 2.49 seconds
2581#######################################################################################################################################
2582HTTP/1.1 301 Moved Permanently
2583Cache-Control: no-cache
2584Pragma: no-cache
2585Transfer-Encoding: chunked
2586Content-Type: text/html;charset=UTF-8
2587Content-Language: en-US
2588Location: https://www.michiganmasons.org/
2589Server: Microsoft-IIS/8.5
2590Set-Cookie: CFID=3534699; Expires=Sun, 13-Oct-2019 13:15:55 GMT; Path=/; HttpOnly
2591Set-Cookie: CFTOKEN=a3b1a3827dd7f382-811CB3E6-5056-BE23-CB24A2EB37FF945E; Expires=Sun, 13-Oct-2019 13:15:55 GMT; Path=/; HttpOnly
2592Set-Cookie: MXP_TRACKINGID=811CB3F6%2D5056%2DBE23%2DCB7E42A5221A30B7; Expires=Mon, 04-Oct-2049 13:15:55 GMT; Path=/; HttpOnly
2593Set-Cookie: mobileFormat=false; Expires=Mon, 04-Oct-2049 13:15:55 GMT; Path=/; HttpOnly
2594Strict-Transport-Security: max-age=1200
2595Generator: Mura CMS 7.0
2596X-Powered-By: ASP.NET
2597Date: Sat, 12 Oct 2019 13:15:55 GMT
2598
2599Allow: OPTIONS, TRACE, GET, HEAD, POST
2600#######################################################################################################################################
2601//connect.facebook.net/en_US/all.js#xfbml=1&appId=130246740447368
2602/default/css/bxslider/jquery.bxslider.css
2603/default/jquery/jquery.min.js
2604/default/js/bxslider/jquery.bxslider.min.js
2605/faq/leadership/
2606/faq/michigan-masons/
2607http://html5shim.googlecode.com/svn/trunk/html5.js
2608https://twitter.com/GLofMichigan
2609https://www.facebook.com/MichiganMasons
2610https://www.youtube.com/user/michiganmasons
2611/join/
2612/MichiganMasons
2613/MichiganMasons/includes/themes/MuraBootstrap
2614/MichiganMasons/includes/themes/MuraBootstrap/assets/bootstrap/js/bootstrap.min.js
2615/MichiganMasons/includes/themes/MuraBootstrap/images/Embossed-Logo-v01A-transparent.png
2616/MichiganMasons/includes/themes/MuraBootstrap/js/theme/theme.js
2617/MichiganMasons/jquery/jquery.js
2618/privacy/
2619/requirements
2620/site-map/
2621text/javascript
2622/videos/
2623#######################################################################################################################################
2624http://www.michiganmasons.org [301 Moved Permanently] ColdFusion, Content-Language[en-US], Cookies[CFID,CFTOKEN,MXP_TRACKINGID,mobileFormat], Country[UNITED STATES][US], HTTPServer[Microsoft-IIS/8.5], HttpOnly[CFID,CFTOKEN,MXP_TRACKINGID,mobileFormat], IP[67.209.250.173], Microsoft-IIS[8.5], RedirectLocation[https://www.michiganmasons.org/], Strict-Transport-Security[max-age=1200], UncommonHeaders[generator], X-Powered-By[ASP.NET]
2625https://www.michiganmasons.org/ [200 OK] ColdFusion, Content-Language[en-US], Cookies[CFID,CFTOKEN,MXP_TRACKINGID,mobileFormat], Country[UNITED STATES][US], Email[webmaster@grandlodgemi.org], Frame, Google-Analytics[Universal][UA-5778311-1], HTML5, HTTPServer[Microsoft-IIS/8.5], HttpOnly[CFID,CFTOKEN,MXP_TRACKINGID,mobileFormat], IP[67.209.250.173], JQuery, MetaGenerator[Mura CMS 7.0], Microsoft-IIS[8.5], Mura-CMS[7.0], Script[text/javascript], Strict-Transport-Security[max-age=1200], Title[Michigan Masons Home Page - MichiganMasons], UncommonHeaders[generator], X-Powered-By[ASP.NET], X-UA-Compatible[IE=edge]
2626#######################################################################################################################################
2627
2628wig - WebApp Information Gatherer
2629
2630
2631Scanning https://www.michiganmasons.org...
2632__________________________ SITE INFO __________________________
2633IP Title
263467.209.250.173 Michigan Masons Home Page - Michiga
2635
2636___________________________ VERSION ___________________________
2637Name Versions Type
2638ASP.NET 4.0.30319 Platform
2639IIS 8.5 Platform
2640JSP Platform
2641Microsoft Windows Server 2012 R2 OS
2642
2643_________________________ INTERESTING _________________________
2644URL Note Type
2645/robots.txt robots.txt index Interesting
2646
2647_______________________________________________________________
2648Time: 40.6 sec Urls: 625 Fingerprints: 40401
2649#######################################################################################################################################
2650Starting Nmap 7.80 ( https://nmap.org ) at 2019-10-12 09:16 EDT
2651NSE: Loaded 163 scripts for scanning.
2652NSE: Script Pre-scanning.
2653Initiating NSE at 09:16
2654Completed NSE at 09:16, 0.00s elapsed
2655Initiating NSE at 09:16
2656Completed NSE at 09:16, 0.00s elapsed
2657Initiating Parallel DNS resolution of 1 host. at 09:16
2658Completed Parallel DNS resolution of 1 host. at 09:16, 0.02s elapsed
2659Initiating SYN Stealth Scan at 09:16
2660Scanning www.michiganmasons.org (67.209.250.173) [1 port]
2661Discovered open port 80/tcp on 67.209.250.173
2662Completed SYN Stealth Scan at 09:16, 0.13s elapsed (1 total ports)
2663Initiating Service scan at 09:16
2664Scanning 1 service on www.michiganmasons.org (67.209.250.173)
2665Completed Service scan at 09:16, 6.14s elapsed (1 service on 1 host)
2666Initiating OS detection (try #1) against www.michiganmasons.org (67.209.250.173)
2667Retrying OS detection (try #2) against www.michiganmasons.org (67.209.250.173)
2668Initiating Traceroute at 09:16
2669Completed Traceroute at 09:16, 0.09s elapsed
2670Initiating Parallel DNS resolution of 11 hosts. at 09:16
2671Completed Parallel DNS resolution of 11 hosts. at 09:16, 0.13s elapsed
2672NSE: Script scanning 67.209.250.173.
2673Initiating NSE at 09:16
2674NSE Timing: About 34.51% done; ETC: 09:18 (0:00:59 remaining)
2675NSE Timing: About 61.54% done; ETC: 09:18 (0:00:44 remaining)
2676NSE Timing: About 84.14% done; ETC: 09:19 (0:00:30 remaining)
2677NSE Timing: About 83.90% done; ETC: 09:20 (0:00:36 remaining)
2678NSE Timing: About 84.30% done; ETC: 09:21 (0:00:42 remaining)
2679NSE Timing: About 84.75% done; ETC: 09:22 (0:00:49 remaining)
2680NSE Timing: About 85.23% done; ETC: 09:23 (0:00:56 remaining)
2681NSE Timing: About 85.05% done; ETC: 09:24 (0:01:07 remaining)
2682NSE: [http-wordpress-enum 67.209.250.173:80] got no answers from pipelined queries
2683NSE Timing: About 87.04% done; ETC: 09:25 (0:01:07 remaining)
2684NSE Timing: About 88.37% done; ETC: 09:26 (0:01:08 remaining)
2685NSE Timing: About 90.03% done; ETC: 09:27 (0:01:05 remaining)
2686NSE Timing: About 91.36% done; ETC: 09:28 (0:01:02 remaining)
2687NSE Timing: About 92.38% done; ETC: 09:29 (0:00:59 remaining)
2688NSE Timing: About 94.04% done; ETC: 09:30 (0:00:49 remaining)
2689NSE Timing: About 95.03% done; ETC: 09:31 (0:00:43 remaining)
2690NSE Timing: About 96.36% done; ETC: 09:31 (0:00:33 remaining)
2691Completed NSE at 09:37, 1222.37s elapsed
2692Initiating NSE at 09:37
2693Completed NSE at 09:37, 8.08s elapsed
2694Nmap scan report for www.michiganmasons.org (67.209.250.173)
2695Host is up (0.068s latency).
2696rDNS record for 67.209.250.173: a67-209-250-173.cust.mi.winntel.net
2697
2698PORT STATE SERVICE VERSION
269980/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
2700|_http-aspnet-debug: ERROR: Script execution failed (use -d to debug)
2701| http-brute:
2702|_ Path "/" does not require authentication
2703|_http-chrono: Request times for /; avg: 22375.36ms; min: 22254.55ms; max: 22595.01ms
2704|_http-csrf: Couldn't find any CSRF vulnerabilities.
2705|_http-devframework: Couldn't determine the underlying framework or CMS. Try increasing 'httpspider.maxpagecount' value to spider more pages.
2706|_http-dombased-xss: Couldn't find any DOM based XSS.
2707|_http-errors: ERROR: Script execution failed (use -d to debug)
2708|_http-feed: Couldn't find any feeds.
2709|_http-fetch: Please enter the complete path of the directory to save data in.
2710|_http-jsonp-detection: Couldn't find any JSONP endpoints.
2711|_http-mobileversion-checker: No mobile version detected.
2712|_http-security-headers:
2713| http-server-header:
2714| Microsoft-HTTPAPI/2.0
2715|_ Microsoft-IIS/8.5
2716| http-sitemap-generator:
2717| Directory structure:
2718| Longest directory structure:
2719| Depth: 0
2720| Dir: /
2721| Total files found (by extension):
2722|_
2723|_http-stored-xss: Couldn't find any stored XSS vulnerabilities.
2724|_http-traceroute: ERROR: Script execution failed (use -d to debug)
2725| http-vhosts:
2726|_127 names had status ERROR
2727|_http-vuln-cve2014-3704: ERROR: Script execution failed (use -d to debug)
2728|_http-wordpress-users: [Error] Wordpress installation was not found. We couldn't find wp-login.php
2729|_http-xssed: No previously reported XSS vuln.
2730| vulscan: VulDB - https://vuldb.com:
2731| [141625] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 DirectX memory corruption
2732| [141624] Microsoft Windows 7 SP1/Server 2008 R2 SP1 Graphics Component information disclosure
2733| [139966] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Kernel information disclosure
2734| [139923] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Graphics Component information disclosure
2735| [139905] Microsoft Windows Server 2008 SP2 DHCP Server memory corruption
2736| [137573] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
2737| [137567] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
2738| [137566] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
2739| [137565] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
2740| [137564] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
2741| [136343] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
2742| [136342] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
2743| [136341] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
2744| [136316] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
2745| [136315] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
2746| [136313] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
2747| [136311] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
2748| [136309] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
2749| [136302] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
2750| [136298] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
2751| [136297] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Win32k memory corruption
2752| [131683] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Win32k memory corruption
2753| [131642] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Active Directory privilege escalation
2754| [127822] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2012 Kernel information disclosure
2755| [125103] Microsoft Windows Server 2008 SP2 Graphics Component information disclosure
2756| [123853] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Kernel Memory information disclosure
2757| [122858] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 LNK memory corruption
2758| [122833] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI+ memory corruption
2759| [121109] Microsoft Wireless Display Adapter V2 2.0.8350/2.0.8365/2.0.8372 privilege escalation
2760| [120449] Microsoft Forefront Unified Access Gateway 2000 InitParams.aspx Parameter Server-Side Request Forgery
2761| [119469] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Kernel privilege escalation
2762| [116015] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1 memory corruption
2763| [114563] Microsoft Office 2007 SP3/2010 SP2/2013/2013 RT SP1 memory corruption
2764| [114528] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI privilege escalation
2765| [114524] Microsoft ASP.NET Core 2.0 denial of service
2766| [114523] Microsoft ASP.NET Core 2.0 Kestrel Web Application privilege escalation
2767| [113257] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2012 Kernel information disclosure
2768| [113256] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2012 Kernel information disclosure
2769| [113255] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2012 Kernel information disclosure
2770| [113247] Microsoft Windows 7 SP1/Server 2008 R2 SP1 EOT Font Engine information disclosure
2771| [113246] Microsoft Windows 7 SP1/Server 2008 R2 SP1 EOT Font Engine information disclosure
2772| [113245] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2012 EOT Font Engine information disclosure
2773| [113244] Microsoft Windows 7 SP1/Server 2008 R2 SP1 EOT Font Engine information disclosure
2774| [113235] Microsoft Outlook 2007 SP3/2010 SP2/2013 SP1/2016 privilege escalation
2775| [113234] Microsoft Office 2007 SP2/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
2776| [113216] Microsoft Outlook 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
2777| [112285] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
2778| [112284] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
2779| [112283] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
2780| [112282] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
2781| [111578] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
2782| [111577] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
2783| [111576] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
2784| [111575] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
2785| [111574] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
2786| [111573] Microsoft Office 2007/2010/2013/2016 Equation Editor memory corruption
2787| [111572] Microsoft Office 2007/2010/2013/2016 Equation Editor memory corruption
2788| [111570] Microsoft Office 2007/2010/2013/2016 Equation Editor memory corruption
2789| [111568] Microsoft Excel 2007/2010/2013/2016 memory corruption
2790| [111566] Microsoft Word 2007/2010/2013/2016 memory corruption
2791| [111565] Microsoft Word 2007/2010/2013 Email Message memory corruption
2792| [111563] Microsoft Outlook 2007/2010/2013/2016 Email Message privilege escalation
2793| [111347] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Color Management Icm32.dll information disclosure
2794| [109388] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2016 memory corruption
2795| [109387] Microsoft ASP.NET Core 2.0 privilege escalation
2796| [109386] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
2797| [109385] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 Security Feature Macro privilege escalation
2798| [109381] Microsoft Office/Word 2007 SP3/2010 SP2 memory corruption
2799| [107703] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
2800| [106530] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
2801| [106528] Microsoft PowerPoint 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
2802| [106515] Microsoft Publisher 2007 SP3/2010 SP2 memory corruption
2803| [106497] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Uniscribe memory corruption
2804| [106476] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
2805| [106475] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
2806| [105051] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Font Library privilege escalation
2807| [105032] Microsoft Internet Explorer 9/10 on Server 2008/Server 2012 memory corruption
2808| [102513] Microsoft Windows Server 2003 SP2/XP SP3 OLE olecnv32.dll privilege escalation
2809| [102512] Microsoft Windows Server 2003 SP2/XP SP3 rpc privilege escalation
2810| [102511] Microsoft Windows Server 2003 SP2/XP SP3 RDP EsteemAudit privilege escalation
2811| [102447] Microsoft PowerPoint/SharePoint Server 2007 SP3 privilege escalation
2812| [102444] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 privilege escalation
2813| [102442] Microsoft Outlook 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 Bypass privilege escalation
2814| [102441] Microsoft Outlook 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
2815| [102401] Microsoft Windows 7 SP1/Server 2008 R2 SP1 GDI USP10!NextCharInLiga Uniscribe Font information disclosure
2816| [101491] Microsoft Windows up to XP SP3/Server 2003 SP2 Remote Desktop Protocol gpkcsp.dll memory corruption
2817| [101017] Microsoft Office 2007 SP3/2010 SP2/2016 memory corruption
2818| [101012] Microsoft Office 2007 SP3/2010 SP2/2011/2013 SP1/2016 memory corruption
2819| [101011] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 ActiveX Object Memory memory corruption
2820| [100854] Microsoft Windows Server 2003 SP2 RRAS ERRATICGOPHER memory corruption
2821| [99904] Microsoft Windows Server 2003 SP2/XP SP3 SmartCard Authentication RDP Packet EsteemAudit privilege escalation
2822| [99698] Microsoft OneNote 2007 SP3/2010 SP2 DLL Loader privilege escalation
2823| [99684] Microsoft Excel 2007 SP3/2010 SP2 Memory information disclosure
2824| [99654] Microsoft Outlook 2007 SP3/2010 SP2/2011/2013 SP1/2016 Email Message privilege escalation
2825| [99653] Microsoft Outlook 2007 SP3/2010 SP2/2011/2013 SP1/2016 Email Message privilege escalation
2826| [99533] Microsoft Office 2007/2010/2013/2016 RTF Document Necurs Dridex memory corruption
2827| [98561] Microsoft IIS 6.0 on Windows Server 2003 WebDAV ScStoragePathFromUrl Long Header memory corruption
2828| [98092] Microsoft SharePoint Server 2007 SP3 memory corruption
2829| [98088] Microsoft SharePoint Server 2007 SP3 memory corruption
2830| [98087] Microsoft Office 2007 SP3/2010 SP2 memory corruption
2831| [98086] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
2832| [98085] Microsoft Excel 2007 SP3 memory corruption
2833| [98084] Microsoft Word 2007 SP3/2010 SP2/2011 memory corruption
2834| [98083] Microsoft Word 2007 SP3/2010 SP2/2011 memory corruption
2835| [98078] Microsoft Word/Excel 2007 SP3 memory corruption
2836| [98072] Microsoft Office 2007 SP3/2010 SP2/Word Viewer Graphics Component privilege escalation
2837| [98071] Microsoft Office 2007 SP3/2010 SP2/Word Viewer GDI+ information disclosure
2838| [98070] Microsoft Office 2007 SP3/2010 SP2/Word Viewer GDI+ information disclosure
2839| [94450] Microsoft Office 2007 SP3/2010 SP2/2011 memory corruption
2840| [94449] Microsoft Office 2007 SP3/2010 SP2/2011/2013 SP1 information disclosure
2841| [94448] Microsoft Office 2007 SP3/2010 SP2/2011/2013 SP1 information disclosure
2842| [94445] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1 information disclosure
2843| [94441] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 privilege escalation
2844| [94440] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
2845| [94439] Microsoft Office 2007 SP3/2011 privilege escalation
2846| [94438] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 privilege escalation
2847| [93542] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1 memory corruption
2848| [93541] Microsoft Office 2007 SP3 denial of service
2849| [93539] Microsoft Office 2007/2010 SP2/2011 memory corruption
2850| [93538] Microsoft Office 2007/2010 SP2/2011/2013 SP1 memory corruption
2851| [93537] Microsoft Office 2007/2010 SP2/2011 memory corruption
2852| [93396] Microsoft Office 2007/2010/2011 memory corruption
2853| [93395] Microsoft Office 2007/2010/2011 memory corruption
2854| [93394] Microsoft Office 2007/2010 memory corruption
2855| [92596] Microsoft Windows 7 SP1/Server 2008 R2/Server 2008 SP2/Vista SP2 Internet Messaging API File information disclosure
2856| [91554] Microsoft Exchange 2007/2010/2013/2016 Email information disclosure
2857| [91553] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
2858| [91552] Microsoft Office 2007/2010/2013/2013 RT/2016 spoofing
2859| [91551] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
2860| [91549] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
2861| [91548] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
2862| [91546] Microsoft Office 2007/2010/2013/2013 RT memory corruption
2863| [91545] Microsoft Office 2007/2010 memory corruption
2864| [91544] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
2865| [91542] Microsoft Office 2007/2010/2013/2013 RT/2016 information disclosure
2866| [90707] Microsoft OneNote 2007/2010/2013/2013 RT/2016 information disclosure
2867| [90706] Microsoft Office 2007/2010/2013/2013 RT Graphics memory corruption
2868| [90705] Microsoft Office 2007/2010/2011 memory corruption
2869| [90703] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
2870| [89039] Microsoft Office 2007 SP3/2010 SP2/2011/2013 RT SP1/2013 SP1 memory corruption
2871| [89034] Microsoft Windows Server 2008/Vista SP2 JScript/VBScript memory corruption
2872| [87960] Microsoft Windows Server 2008 R2/Server 2012/Server 2012 R2 Active Directory denial of service
2873| [87955] Microsoft Exchange 2007/2010/2013/2016 Oracle Outside In Libraries privilege escalation
2874| [87954] Microsoft Exchange 2007/2010/2013/2016 Oracle Outside In Libraries privilege escalation
2875| [87953] Microsoft Exchange 2007/2010/2013/2016 Oracle Outside In Libraries privilege escalation
2876| [87939] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 OLE DLL memory corruption
2877| [87938] Microsoft Office 2007 SP3/2010 SP2/2011 information disclosure
2878| [87937] Microsoft Office 2007 SP3/2010 SP2/2011 memory corruption
2879| [87935] Microsoft Windows Server 2008 R2 SP1/Server 2008 SP2/Vista SP2 VBScript/JScript memory corruption
2880| [87934] Microsoft Windows Server 2008 R2 SP1/Server 2008 SP2/Vista SP2 VBScript/JScript memory corruption
2881| [87933] Microsoft Windows Server 2008 R2 SP1/Server 2008 SP2/Vista SP2 VBScript/JScript memory corruption
2882| [87147] Microsoft Office 2007/2010 memory corruption
2883| [87145] Microsoft Windows Server 2008/Vista SP2 JScript/VBScript memory corruption
2884| [87144] Microsoft Windows Server 2008/Vista SP2 JScript/VBScript memory corruption
2885| [82228] Microsoft Excel 2007 SP3/2010 SP2 Office Document memory corruption
2886| [82225] Microsoft Word 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1 Office Document memory corruption
2887| [82224] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 Office Document memory corruption
2888| [81273] Microsoft Office 2007/2010/2013/2016 memory corruption
2889| [81272] Microsoft Office 2007/2010/2013 memory corruption
2890| [81265] Microsoft Windows Server 2008/Vista SP2 Library Loader memory corruption
2891| [80872] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
2892| [80871] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
2893| [80869] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
2894| [79506] Microsoft Windows 7/Server 2008/Server 2008 R2/Vista Library Loader memory corruption
2895| [79505] Microsoft Office 2007 memory corruption
2896| [79504] Microsoft Office 2007/2010/2013/2016 memory corruption
2897| [79503] Microsoft Office 2007/2010/2013 memory corruption
2898| [79502] Microsoft Office 2007/2010/2011 memory corruption
2899| [79501] Microsoft Office 2007/2010 memory corruption
2900| [79499] Microsoft Windows 7/Server 2008 R2 Uniscribe memory corruption
2901| [79493] Microsoft Windows Server 2008/Vista Graphics memory corruption
2902| [79190] Microsoft Word 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 Office Document memory corruption
2903| [79189] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 Office Document memory corruption
2904| [79187] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2016 Sandbox privilege escalation
2905| [79167] Microsoft Windows 7/Server 2008/Server 2008 R2/Vista Journal memory corruption
2906| [78372] Microsoft Visio 2007 SP3/2010 SP2 UML Data memory corruption
2907| [78371] Microsoft SharePoint Server 2007 SP3/2010 SP2 InfoPath Forms Services XXE information disclosure
2908| [77646] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1 EPS Image memory corruption
2909| [77629] Microsoft Excel 2007 SP3/2010 SP2/2011/2016 Office Document memory corruption
2910| [77627] Microsoft Excel 2007 SP3/2010 SP2 Office Document memory corruption
2911| [77626] Microsoft Excel 2007 SP3/2010 SP2/2011/2016 Office Document memory corruption
2912| [77617] Microsoft Office 2007 SP3/2010 SP2 OpenType Font memory corruption
2913| [77252] Microsoft Office 2007 SP3/2010 SP2 Office Graphics Library Font memory corruption
2914| [77038] Microsoft Windows Server 2008 SP2 UDDI Services cross site scripting
2915| [76497] Microsoft PowerPoint 2007 SP3/2010 SP2/2013 SP1 Office Document memory corruption
2916| [76491] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1 Office Document memory corruption
2917| [76467] Microsoft Word 2007 SP3/2010 SP2/2011/2013 RT SP1/2013 SP1 Office Document memory corruption
2918| [76466] Microsoft Word 2007 SP3/2010 SP2/2011/2013 RT SP1/2013 SP1 Office Document memory corruption
2919| [76464] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1 Office Document memory corruption
2920| [76463] Microsoft Excel 2007 SP3/2010 SP2/2011/2013 RT SP1/2013 SP1 Office Document memory corruption
2921| [76449] Microsoft Windows 8/8.1/Server 2008/Server 2012/Server 2012 R2 Hyper-V memory corruption
2922| [76440] Microsoft SQL Server 2008/2008 R2/2012/2014 Virtual Function Uninitialized Memory memory corruption
2923| [76439] Microsoft SQL Server 2008/2008 R2/2012/2014 Uninitialized Memory memory corruption
2924| [76438] Microsoft SQL Server 2008/2008 R2/2012/2014 Pointer Casting privilege escalation
2925| [75783] Microsoft Windows Server 2008/Server 2012 Active Directory Federation Services cross site scripting
2926| [75338] Microsoft SharePoint 2007/2010/2013 Content privilege escalation
2927| [75337] Microsoft Office 2007 SP3/2010 SP2/2011/2013 RT SP1/2013 SP1 memory corruption
2928| [75336] Microsoft Office 2007 SP3/2010 SP2/2011/2013 RT SP1/2013 SP1 memory corruption
2929| [74845] Microsoft Office 2007/2010/2013 Document Use-After-Free memory corruption
2930| [74844] Microsoft Office 2007/2010 Document Use-After-Free memory corruption
2931| [74837] Microsoft Office 2007/2010/2011/2013 RTF Document Use-After-Free privilege escalation
2932| [73979] Microsoft Exchange Server 2003 CU7/2003 SP1 Meeting privilege escalation
2933| [73978] Microsoft Exchange Server 2003 CU7/2003 SP1 cross site scripting
2934| [73977] Microsoft Exchange Server 2003 CU7/2003 SP1 cross site scripting
2935| [73976] Microsoft Exchange Server 2003 CU7/2003 SP1 cross site scripting
2936| [73975] Microsoft Exchange Server 2003 CU7/2003 SP1 cross site scripting
2937| [73964] Microsoft SharePoint 2007/2010/2013 cross site scripting
2938| [69158] Microsoft Office 2007/2010/2013 Use-After-Free memory corruption
2939| [69157] Microsoft Office 2007/2010/2013 OneTableDocumentStream memory corruption
2940| [68416] Microsoft Exchange 2007/2010/2013 Outlook Web Access Token spoofing
2941| [68409] Microsoft Office 2007/2010/2013 Use-After-Free memory corruption
2942| [68408] Microsoft Excel 2007/2010/2013 memory corruption
2943| [68407] Microsoft Excel 2007/2010 memory corruption
2944| [68405] Microsoft Word 2007/2010 Index Use-After-Free memory corruption
2945| [68195] Microsoft Windows 7/Server 2003/Server 2008/Vista Input Method Editor Sandbox privilege escalation
2946| [68189] Microsoft Windows Server 2003 SP2 TCP/IP Stack Stack-Based memory corruption
2947| [68188] Microsoft Word 2007 File memory corruption
2948| [68187] Microsoft Word 2007 File memory corruption
2949| [68186] Microsoft Word 2007 File memory corruption
2950| [67829] Microsoft Office 2007/2010/2011 Object memory corruption
2951| [67825] Microsoft .NET Framework 2.0/3.5/3.5.1 ASLR privilege escalation
2952| [71337] Microsoft Office 2000/2004/XP memory corruption
2953| [67355] Microsoft OneNote 2007 File Processing privilege escalation
2954| [67354] Microsoft SQL Server 2008 R2 SP2/2008 SP3/2012 SP1/2014 SQL Master Data Services cross site scripting
2955| [67353] Microsoft SQL Server 2008 R2 SP2/2008 SP3/2012 SP1/2014 T-SQL Query Stack-Based memory corruption
2956| [67018] Microsoft Windows Server 2008/Server 2012/Server 2012 R2 Service Bus AMQP Message denial of service
2957| [13545] Microsoft Word 2007 Embedded Font memory corruption
2958| [13397] Microsoft Windows 2000/Server 2003/XP DHCP Response DHCP ACK spoofing
2959| [13462] Microsoft Visual Studio 2002/2003/2005/2010 Debug Interface msdia.dll PDB File memory corruption
2960| [13229] Microsoft Office 2007/2010/2013 Common Control Library MSCOMCTL.OCX privilege escalation
2961| [13227] Microsoft Office 2007/2010/2013 Chinese Grammar Checker Library privilege escalation
2962| [13226] Microsoft SharePoint Server 2007/2010/2013 Page memory corruption
2963| [13225] Microsoft SharePoint Server 2007/2010/2013 cross site scripting
2964| [13224] Microsoft SharePoint Server 2007/2010/2013 Page memory corruption
2965| [12859] Microsoft Word 2003 Office Document Stack-Based memory corruption
2966| [12852] Microsoft Publisher 2003/2007 Publisher File pubconv.dll memory corruption
2967| [12845] Microsoft Word 2003 Office File Stack-Based memory corruption
2968| [12844] Microsoft Word 2007/2010 Office File memory corruption
2969| [12843] Microsoft Office 2007/2010/2011/2013 XML Parser Nested Entities Memory Consumption denial of service
2970| [12687] Microsoft Word/Office/Outlook 2003/2007/2010/2013 RTF Document memory corruption
2971| [12530] Microsoft Windows Server 2003/Server 2008/Server 2012/Vista/XP Security Account Manager Lockout privilege escalation
2972| [12266] Microsoft .NET Framework 2.0 SP2/3.5.1 ASLR Bypass privilege escalation
2973| [12070] Apple Pages 2.0/2.0.1/2.0.2/5.0/5.0.1 on Mac Microsoft Word Document memory corruption
2974| [11950] Microsoft Office Compability Pack/Word 2007 SP3 File memory corruption
2975| [11949] Microsoft Word Viewer/Office Compatibility Pack/Word 2003 SP3/2007 SP3 File memory corruption
2976| [11494] Microsoft .NET Framework 2.0 SP2/3.5.1/4/4.5/4.5.1 MAC Authentication privilege escalation
2977| [11448] Microsoft Office 2007/2010 Address Space Layout Randomization privilege escalation
2978| [11148] Microsoft Office 2003/2007 WordPerfect Document epsimp32.flt memory corruption
2979| [11146] Microsoft Office 2003/2007 epsimp32.flt memory corruption
2980| [11230] Microsoft Word 2003 DOC Document Embedded Image denial of service
2981| [11081] Microsoft Windows Server 2008/Vista TIFF Image memory corruption
2982| [10648] Microsoft Word 2007 Word File memory corruption
2983| [10647] Microsoft Word 2003 Word File memory corruption
2984| [10643] Microsoft SharePoint Server 2007/2010/2013 Input Sanitizer memory corruption
2985| [10642] Microsoft SharePoint Server 2007/2010 Content Display in Frames privilege escalation
2986| [10247] Microsoft SharePoint Server 2007/2010/2013 Online Cloud cross site scripting
2987| [10245] Microsoft Office 2003/2007/2010 Word File memory corruption
2988| [10244] Microsoft Office 2003 SP3 Word File memory corruption
2989| [10243] Microsoft Office 2003/2007 Word File memory corruption
2990| [10242] Microsoft Office 2007 Word File memory corruption
2991| [10241] Microsoft Office 2007 Word File memory corruption
2992| [10240] Microsoft Office 2003/2007/2010 Word File memory corruption
2993| [10239] Microsoft Office 2003/2007 Word File memory corruption
2994| [10238] Microsoft Excel 2003/2007 XML External Entity Data information disclosure
2995| [10237] Microsoft Excel 2003/2007/2010 XML External Entity Data information disclosure
2996| [10236] Microsoft Word/Office 2003/2007 XML External Entity Data information disclosure
2997| [10234] Microsoft Word/Sharepoint 2003 SP3/2007 SP3/2010 SP1 Office File memory corruption
2998| [10232] Microsoft Word/Sharepoint 2003 SP3/2007 SP3/2010 SP1 Office File memory corruption
2999| [10231] Microsoft Word/Sharepoint 2003 SP3/2007 SP3/2010 SP1 Office File memory corruption
3000| [10230] Microsoft Word/Sharepoint 2003 SP3/2007 SP3/2010 SP1 Office File memory corruption
3001| [10229] Microsoft Access 2007/2010/2013 Access File ACCDB File memory corruption
3002| [10228] Microsoft Access 2007/2010/2013 Access File ACCDB File memory corruption
3003| [10227] Microsoft Access 2007/2010/2013 Access File ACCDB File memory corruption
3004| [10192] Microsoft Windows 7/2000/Server 2003 SP2/Vista/XP SP3 Windows Theme File privilege escalation
3005| [10191] Microsoft Windows Server 2003/XP OLE Object privilege escalation
3006| [10190] Microsoft Windows 7/8/Server 2008/Vista Active Directory denial of service
3007| [10189] Microsoft Outlook 2007/2010 S/MIME privilege escalation
3008| [9941] Microsoft Windows Server 2003/XP Unicode Scripts Processor USP10.DLL Uniscribe Font memory corruption
3009| [9929] Microsoft Windows Server 2008/Server 2012 Active Directory Federation Services Unspecified Account information disclosure
3010| [9715] Microsoft PowerPoint 2007 DirectShow Runtime quartz.dll GetMaxSampleSize denial of service
3011| [9397] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 Array privilege escalation
3012| [9394] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 on 64-bit Array memory corruption
3013| [9393] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 Permission privilege escalation
3014| [8738] Microsoft Visio 2003 SP3/2007 SP3/2010 SP1 XML Parser File information disclosure
3015| [8737] Microsoft Word 2003 SP3 Shape Data Parser File memory corruption
3016| [8736] Microsoft Publisher 2003 SP3 PUB File memory corruption
3017| [8735] Microsoft Publisher 2003 SP3/2007 SP3/2010 SP1 PUB File memory corruption
3018| [8734] Microsoft Publisher 2003 SP3 PUB File memory corruption
3019| [8733] Microsoft Publisher 2003 SP3 PUB File memory corruption
3020| [8732] Microsoft Publisher 2003 SP3 PUB File memory corruption
3021| [8731] Microsoft Publisher 2003 SP3 PUB File memory corruption
3022| [8730] Microsoft Publisher 2003 SP3 PUB File memory corruption
3023| [8729] Microsoft Publisher 2003 SP3 PUB File memory corruption
3024| [8728] Microsoft Publisher 2003 SP3 PUB File memory corruption
3025| [8727] Microsoft Publisher 2003 SP3 PUB File memory corruption
3026| [8726] Microsoft Publisher 2003 PUB File Eingabe memory corruption
3027| [8723] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 XML File spoofing
3028| [7643] Microsoft Windows Server 2008 R2/Server 2012 NFS Server NULL Pointer Dereference denial of service
3029| [7642] Microsoft Exchange 2007/2010 Outlook Web Access vspdx.dll) privilege escalation
3030| [7641] Microsoft Windows Server 2003/Server 2008/Vista/XP DirectShow Quartz.dll memory corruption
3031| [8589] Microsoft System Center Operations Manager 2007 R2/2007 SP1 ViewTypeManager.aspx cross site scripting
3032| [7252] Microsoft System Center Operations Manager 2007 ExecuteTask.aspx cross site scripting
3033| [7251] Microsoft System Center Operations Manager 2007 cross site scripting
3034| [7248] Microsoft Windows 7/Server 2008 R2 Print Spooler privilege escalation
3035| [7121] Microsoft Exchange 2007/2010 RSS Feed denial of service
3036| [7118] Microsoft Windows Server 2008 R2/Server 2012 IP-HTTPS unknown vulnerability
3037| [62914] Microsoft Office 2003 SP3/2007 SP3/2008/2010 SP1/2011 Spreadsheet Use-After-Free memory corruption
3038| [7058] Microsoft Windows 7/Server 2008 R2 DHCPv6 Message denial of service
3039| [6935] Microsoft Office Excel 2003/2007/2010 Input Sanitizer File Stack-based memory corruption
3040| [6934] Microsoft Office Excel 2003/2007/2010 Input Sanitizer memory corruption
3041| [6933] Microsoft Office Excel 2003/2007/2010 SerAuxErrBar File memory corruption
3042| [6929] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 Web Proxy Setting Auto-Discovery memory corruption
3043| [6927] Microsoft .NET Framework 2.0 SP2/3.5.1 Trusted Code Function information disclosure
3044| [6918] Microsoft Excel 2007 SP2 Input Sanitizer File memory corruption
3045| [6830] Microsoft Word 2007/2010 File memory corruption
3046| [6819] Microsoft Excel 2007 File memory corruption
3047| [6627] Microsoft Windows 7/Server 2008 R2 Kerberos denial of service
3048| [6626] Microsoft SharePoint/Lync/Infopath 2007/2010 HTML Sanitization cross site scripting
3049| [6621] Microsoft Word 2007 PAPX memory corruption
3050| [62239] Microsoft Systems Management Server 2003 Configuration Manager Reflected cross site scripting
3051| [5945] Microsoft Office 2007/2010 Computer Graphics Metafile memory corruption
3052| [5939] Microsoft Windows 7/Server 2003/Server 2008 R2/Vista/XP Print Spooler Service memory corruption
3053| [5938] Microsoft Windows 7/Server 2003/Server 2008 R2/Vista/XP Remote Administration Protocol netapi32.dll RAP Request denial of service
3054| [5933] Microsoft SQL Server 2000/2005/2008/2008 R2 Common Controls TabStrip ActiveX MSCOMCTL.OCX memory corruption
3055| [5932] Microsoft Office 2003/2007/2010 Common Controls TabStrip ActiveX MSCOMCTL.OCX memory corruption
3056| [5654] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP information disclosure
3057| [5653] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP win32k.sys memory corruption
3058| [5652] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP win32k.sys memory corruption
3059| [5650] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP memory corruption
3060| [5649] Microsoft Office 2003/2007/2010 libraries memory corruption
3061| [5645] Microsoft SharePoint 2007/2010/3.0 Reflected cross site scripting
3062| [5643] Microsoft SharePoint 2007/2010 information disclosure
3063| [5642] Microsoft SharePoint 2007 cross site request forgery
3064| [5553] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP OpenType Font atmfd.dll denial of service
3065| [5524] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP memory corruption
3066| [5518] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 memory corruption
3067| [5362] Microsoft Office 2003/2007 GDI+ memory corruption
3068| [5291] Microsoft Visual Studio 2008 Incremental Linker link.exe ConvertRgImgSymToRgImgSymEx memory corruption
3069| [5268] Microsoft Office 2008 on Mac RTF Pfragment File memory corruption
3070| [5080] Microsoft SQL Server 2005/2008/2008R2 CREATE DATABASE sql injection
3071| [5050] Microsoft Office 2007 WPS Converter Heap-based memory corruption
3072| [5049] Microsoft SQL Server 2000/2005/2008 MSCOMCTL.OCX privilege escalation
3073| [5048] Microsoft Office 2003/2007/2010 MSCOMCTL.OCX privilege escalation
3074| [5046] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Windows Authenticode Signature Verification WinVerifyTrust Signature privilege escalation
3075| [4803] Microsoft Windows Server 2003/Server 2008 DNS Server Domain Resource Record Query Parser denial of service
3076| [4802] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Remote Desktop Protocol denial of service
3077| [4798] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Remote Desktop Service memory corruption
3078| [60205] Microsoft .NET Framework 2.0 SP2/3.5.1 Heap-based memory corruption
3079| [4642] Microsoft .NET Framework 2.0 SP2/3.5.1/4 XAML Browser Application memory corruption
3080| [60065] Microsoft Windows 2000 mod_sql unknown vulnerability
3081| [4535] Microsoft Windows Server 2003/XP Object Packager packager.exe privilege escalation
3082| [4534] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Line21 DirectShow Filter Quartz.dll/Qdvd.dll Media File memory corruption
3083| [4533] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Multimedia Library winmm.dll MIDI File memory corruption
3084| [4507] Microsoft .NET Framework 2.0 SP2/3.5 SP1/3.5.1/4.0 Forms Authentication privilege escalation
3085| [59666] Microsoft Publisher 2003/2007 "Publisher memory corruption
3086| [4482] Microsoft Word 2007/2010/2011 Document Parser memory corruption
3087| [4480] Microsoft Excel 2003 memory corruption
3088| [4478] Microsoft Windows Server 2003/XP OLE Objects Memory Management memory corruption
3089| [4477] Microsoft PowerPoint 2007 SP2/2008 OfficeArt Use-After-Free memory corruption
3090| [4474] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Active Directory Query memory corruption
3091| [4473] Microsoft PowerPoint 2007 SP2/2010 DLL-Loader memory corruption
3092| [4471] Microsoft Office 2003/2007 Publisher Out-of-Bounds memory corruption
3093| [4470] Microsoft Office 2003 SP3 memory corruption
3094| [4453] Microsoft Excel 2003 Record Parser memory corruption
3095| [4446] Microsoft Office 2007/2008 OfficeArt Record Parser memory corruption
3096| [4445] Microsoft Office 2007/2010/2011 Word Document Parser memory corruption
3097| [4438] Microsoft Windows 7/Server 2008/Vista TCP/IP Reference Counter denial of service
3098| [5358] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP TrueType Font Handling memory corruption
3099| [59005] Microsoft Host Integration Server 2004 denial of service
3100| [58492] Microsoft SharePoint Server 2007 Spreadsheet memory corruption
3101| [58491] Microsoft Office 2004/2007/2008/2010/2011 Spreadsheet memory corruption
3102| [58490] Microsoft Office Compatibility Pack 2007 Spreadsheet memory corruption
3103| [58489] Microsoft Office 2004/2007/2008/2010/2011 Spreadsheet memory corruption
3104| [58488] Microsoft Office 2007/2010 memory corruption
3105| [4412] Microsoft Office 2003/2007 Library Loader unknown vulnerability
3106| [4411] Microsoft Excel 2003 memory corruption
3107| [4409] Microsoft Windows Server 2003/Server 2008 WINS unknown vulnerability
3108| [58240] Microsoft Visio 2003/2007 memory corruption
3109| [58237] Microsoft Visio 2003/2007/2010 memory corruption
3110| [4396] Microsoft Windows 7/Server 2008/Vista TCP/IP Stack denial of service
3111| [4393] Microsoft Windows Server 2008 DNS Service memory corruption
3112| [4391] Microsoft .NET Framework 2.0 SP2/3.5.1/4 Socket Restriction privilege escalation
3113| [4390] Microsoft Windows Server 2008 Remote Desktop Web Access cross site scripting
3114| [4388] Microsoft Windows 7/Server 2008/Vista File Metadata Parser denial of service
3115| [57691] Microsoft SQL Server 2008 Web Service information disclosure
3116| [57690] Microsoft Excel 2002/2003 Spreadsheet memory corruption
3117| [57689] Microsoft Excel 2002 Spreadsheet memory corruption
3118| [57688] Microsoft Excel 2002 Spreadsheet memory corruption
3119| [57687] Microsoft Excel 2002/2003/2007 Spreadsheet memory corruption
3120| [57686] Microsoft Excel 2002 Spreadsheet memory corruption
3121| [57685] Microsoft Excel 2002/2003/2007 Array Access memory corruption
3122| [57684] Microsoft Excel 2002/2003/2007/2010 Spreadsheet memory corruption
3123| [4369] Microsoft Excel 2002/2003/2007 memory corruption
3124| [4367] Microsoft Windows Server 2008 Hyper-V VMBus denial of service
3125| [4362] Microsoft Windows 7/Server 2008/Vista denial of service
3126| [57420] Microsoft PowerPoint 2002/2003 memory corruption
3127| [4349] Microsoft Office 2004/2007/2008 Presentation File Parser memory corruption
3128| [4348] Microsoft PowerPoint 2002/2003/2007 memory corruption
3129| [57077] Microsoft Excel 2002 Uninitialized Memory memory corruption
3130| [57078] Microsoft Office 2003/2007/Xp docx unknown vulnerability
3131| [57079] Microsoft PowerPoint 2002/2003/2007/2010 memory corruption
3132| [57076] Microsoft Excel 2002/2003 memory corruption
3133| [57075] Microsoft Excel 2002/2003 memory corruption
3134| [57074] Microsoft Excel 2002 memory corruption
3135| [57073] Microsoft Excel 2002/2003/2007/2010 memory corruption
3136| [4334] Microsoft .NET Framework 2.0 SP2/3.5 SP1/3.5.1/4.0 JIT Compiler memory corruption
3137| [4332] Microsoft PowerPoint 2007/2010 memory corruption
3138| [4301] Microsoft Windows Server 2003 SMB Browser Heap-based denial of service
3139| [56475] Microsoft Office 2004/2008 memory corruption
3140| [56414] Microsoft Visio 2002/2003/2007 ELEMENTS.DLL memory corruption
3141| [56413] Microsoft Visio 2002/2003/2007 Exception ORMELEMS.DLL memory corruption
3142| [4298] Microsoft Windows 7/Server 2008 JScript/VBScript Engine information disclosure
3143| [4297] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP OpenType Compact Font Format Driver privilege escalation
3144| [4296] Microsoft Windows Server 2003/XP LSASS Authentication Request unknown vulnerability
3145| [4295] Microsoft Windows 7/Server 2008 Kerberos weak authentication
3146| [4294] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Driver win32k.sys unknown vulnerability
3147| [4293] Microsoft Windows Server 2003/XP Kerberos CRC32 Checksum privilege escalation
3148| [4292] Microsoft Windows Server 2003/XP CSRSS Logoff privilege escalation
3149| [4289] Microsoft Excel 2007 Shape Data Parser memory corruption
3150| [4286] Microsoft PowerPoint 2002 SP3/2003 SP3/2004/2007 SP2/2008 OfficeArt Container Parser memory corruption
3151| [4279] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP MHTML cross site scripting
3152| [56176] Microsoft Windows 7/Server 2003/XP fxscover.exe CDrawPoly::Serialize memory corruption
3153| [55772] Microsoft Publisher 2002 pubconv.dll memory corruption
3154| [55771] Microsoft Publisher 2002/2003/2010 memory corruption
3155| [55765] Microsoft Office 2003/Xp Integer memory corruption
3156| [55764] Microsoft Office 2003/Xp memory corruption
3157| [55750] Microsoft Publisher 2002/2003 pubconv.dll memory corruption
3158| [55749] Microsoft Publisher 2002/2003/2007/2010 pubconv.dll memory corruption
3159| [55748] Microsoft Publisher 2002/2003/2007 pubconv.dll memory corruption
3160| [4230] Microsoft Exchange 2007 on 64-bit RPC store.exe MAPI Request denial of service
3161| [4229] Microsoft SharePoint 2007 Document Conversion Launcher Service Eingabeung\xC3\xBCltigkeit
3162| [4228] Microsoft Windows Server 2008 Hyper-V VMBus denial of service
3163| [4224] Microsoft Windows 7/Server 2008/Vista Consent User Interface privilege escalation
3164| [4231] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Driver win32k.sys GreEnableEUDC denial of service
3165| [55420] Microsoft Office 2007/2010 memory corruption
3166| [55419] Microsoft Office 2004/2008/2011/Xp memory corruption
3167| [55412] Microsoft PowerPoint Viewer 2007 memory corruption
3168| [55411] Microsoft PowerPoint 2002/2003 memory corruption
3169| [4204] Microsoft Windows Server 2008 Color Control Panel Eingabeung\xC3\xBCltigkeit
3170| [54995] Microsoft Office 2004/2008 memory corruption
3171| [54994] Microsoft Office 2004/2008 Out-of-Bounds memory corruption
3172| [54993] Microsoft Office Compatibility Pack 2007 memory corruption
3173| [54992] Microsoft Excel 2002 memory corruption
3174| [54991] Microsoft Office 2004 Future memory corruption
3175| [54990] Microsoft Office 2004 memory corruption
3176| [54989] Microsoft Office 2004/2008 memory corruption
3177| [54988] Microsoft Excel 2002 memory corruption
3178| [54987] Microsoft Excel 2002 memory corruption
3179| [54986] Microsoft Excel 2002/2003 memory corruption
3180| [54985] Microsoft Office Compatibility Pack 2003/2004/2007/2008 memory corruption
3181| [54984] Microsoft Office 2004/2008 memory corruption
3182| [54983] Microsoft Excel 2002 Integer memory corruption
3183| [54980] Microsoft Word 2002/2003 memory corruption
3184| [54979] Microsoft Word 2002 memory corruption
3185| [54978] Microsoft Word 2002 memory corruption
3186| [54977] Microsoft Word 2002 Heap-based memory corruption
3187| [54976] Microsoft Word 2002 memory corruption
3188| [54975] Microsoft Word 2002 memory corruption
3189| [54974] Microsoft Word 2002 memory corruption
3190| [54973] Microsoft Word 2002 memory corruption
3191| [54972] Microsoft Word 2002 memory corruption
3192| [54971] Microsoft Word 2002 memory corruption
3193| [4197] Microsoft SharePoint 2007/3.0 cross site scripting
3194| [4196] Microsoft Word 2002/2003/2007/2010 Stack-based memory corruption
3195| [4194] Microsoft Windows 7/Server 2008/Vista SChannel Client Certificate Request denial of service
3196| [54774] Microsoft Word 2003 word_crash_11.8326.8324_poc.doc denial of service
3197| [54757] Microsoft SharePoint Server 2007 HTML Sanitization SafeHTML cross site scripting
3198| [4186] Microsoft Outlook 2002/2003/2007 Content Parser Heap-based memory corruption
3199| [54584] Microsoft Visual C++ 2005 AtlTraceTool8.exe unknown vulnerability
3200| [54554] Microsoft Groove 2007 mso.dll memory corruption
3201| [4187] Microsoft Windows 7/Server 2008/Vista TCP/IP Stack Ipv4SetEchoRequestCreate denial of service
3202| [54322] Microsoft Word 2002/2003 memory corruption
3203| [54321] Microsoft Office Compatibility Pack 2007 memory corruption
3204| [54320] Microsoft Office Compatibility Pack 2007 memory corruption
3205| [54319] Microsoft Office Compatibility Pack 2007 memory corruption
3206| [54318] Microsoft .NET Framework 2.0 SP1/2.0 SP2/3.5/3.5 SP1/3.5.1 Interfaces memory corruption
3207| [4165] Microsoft Windows 7/Server 2008/Vista TCP/IP Stack denial of service
3208| [4162] Microsoft Windows 7/Server 2008/Vista Kernel memory corruption
3209| [4159] Microsoft Excel 2002/2003 SXDB PivotTable Cache Data Record memory corruption
3210| [4149] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Shell Shortcut Parser memory corruption
3211| [54083] Microsoft Access 2003 ActiveX Control ACCWIZ.dll memory corruption
3212| [4146] Microsoft Outlook 2002/2003/2007 SMB Attachment PR_ATTACH_METHOD memory corruption
3213| [4145] Microsoft Access 2003/2007 ActiveX ACCWIZ.dll memory corruption
3214| [54617] Microsoft Outlook Web Access up to 2007 cross site request forgery
3215| [4151] Microsoft Windows Server 2008/Vista NtUserCheckAccessForIntegrityLevel memory corruption
3216| [53591] Microsoft Windows Server 2003 GetServerName cross site scripting
3217| [53505] Microsoft Excel 2002/2007 memory corruption
3218| [53501] Microsoft Excel 2002 memory corruption
3219| [53500] Microsoft Excel 2002 memory corruption
3220| [53499] Microsoft Excel 2002 memory corruption
3221| [53495] Microsoft Excel 2002/2003/2007 memory corruption
3222| [53494] Microsoft Excel 2002 Stack-based memory corruption
3223| [53504] Microsoft Excel 2002 memory corruption
3224| [53503] Microsoft Excel 2002 Stack-Based memory corruption
3225| [53502] Microsoft Excel 2002 Heap-based memory corruption
3226| [53498] Microsoft Excel 2002 Stack-based memory corruption
3227| [53497] Microsoft Excel 2002 memory corruption
3228| [53496] Microsoft Excel 2002 memory corruption
3229| [53493] Microsoft Excel 2002/2003/2007 memory corruption
3230| [4133] Microsoft Office 2003/2007/Xp COM Object Instantiator memory corruption
3231| [53366] Microsoft ASP.NET 2.0 cross site scripting
3232| [53385] Microsoft Exchange Server 2007 Outlook Web Access cross site scripting
3233| [53164] Microsoft Office 2003/2007/Xp ActiveX Control VBE6.DLL memory corruption
3234| [53054] Microsoft VISIO 2002/2003/2007 VISIODWG.DLL memory corruption
3235| [4125] Microsoft SharePoint 2007/3.0 help.aspx cross site scripting
3236| [52777] Microsoft Publisher 2002/2003/2007 memory corruption
3237| [52773] Microsoft Visio 2002/2003/2007 memory corruption
3238| [52772] Microsoft Visio 2002/2003/2007 memory corruption
3239| [4107] Microsoft Windows 7/Server 2008 Kernel denial of service
3240| [4103] Microsoft Windows Server 2003 Media Services Stack-based memory corruption
3241| [52543] Microsoft Virtual PC 2007 unknown vulnerability
3242| [52148] Microsoft Office 2004/2007/2008 Uninitialized Memory memory corruption
3243| [52147] Microsoft Office 2004/2007/2008 Spreadsheet Uninitialized Memory memory corruption
3244| [52146] Microsoft Office 2004/2007/2008 Spreadsheet Heap-based memory corruption
3245| [52145] Microsoft Office 2004/2007/2008 Spreadsheet Heap-based memory corruption
3246| [52144] Microsoft Office 2004/2007/2008 Spreadsheet memory corruption
3247| [52143] Microsoft Office 2004/2007/2008 Spreadsheet memory corruption
3248| [4090] Microsoft Excel 2002/2003/2007 memory corruption
3249| [52036] Microsoft Windows 2000 MsgBox memory corruption
3250| [51995] Microsoft SharePoint Server up to 2006 cross site scripting
3251| [51810] Microsoft Office 2004/Xp MSO.DLL memory corruption
3252| [51802] Microsoft PowerPoint 2003 Stack-based memory corruption
3253| [51801] Microsoft PowerPoint 2003 Stack-based memory corruption
3254| [51800] Microsoft PowerPoint 2002/2003 Use-After-Free memory corruption
3255| [51799] Microsoft PowerPoint 2002/2003 memory corruption
3256| [51798] Microsoft PowerPoint 2002/2003 Heap-based memory corruption
3257| [4082] Microsoft PowerPoint 2002 SP3 memory corruption
3258| [54550] Microsoft PowerPoint 2007 rpawinet.dll memory corruption
3259| [54556] Microsoft Visio 2003 mfc71enu.dll unknown vulnerability
3260| [51497] Microsoft Windows Live Messenger 2009 ActiveX Control msnmsgr.exe denial of service
3261| [51133] Microsoft Windows 2000 SP4/Server 2003 SP2/SP3/XP SP2 memory corruption
3262| [51074] Microsoft Office 2002/2003 Integer memory corruption
3263| [4069] Microsoft Project 2003/2007 Project Memory Validator memory corruption
3264| [50794] Microsoft Office 2004/2008 Spreadsheet memory corruption
3265| [50793] Microsoft Office 2004/2008 Spreadsheet memory corruption
3266| [50792] Microsoft Office 2004/2008 Spreadsheet memory corruption
3267| [50791] Microsoft Office 2004/2008 Spreadsheet memory corruption
3268| [50790] Microsoft Office 2004/2008 Spreadsheet Heap-based memory corruption
3269| [50788] Microsoft Office 2004/2008 Spreadsheet memory corruption
3270| [50787] Microsoft Office 2004/2008 Spreadsheet memory corruption
3271| [50786] Microsoft Windows 2000 llssrv.exe memory corruption
3272| [50789] Microsoft Office 2004/2008 Spreadsheet memory corruption
3273| [4056] Microsoft Word 2002/2003 File Information Block Parser Stack-based memory corruption
3274| [50660] Microsoft SharePoint Server 2007 unknown vulnerability
3275| [50443] Microsoft PowerPoint 2007 Integer memory corruption
3276| [50432] Microsoft .NET Framework 2.0/2.0 SP1/2.0 SP2/3.5/3.5 SP1 memory corruption
3277| [49866] Microsoft Windows Server 2003 memory corruption
3278| [4031] Microsoft Windows Server 2008/Vista SMB Processor EducatedScholar memory corruption
3279| [4030] Microsoft Windows Server 2008/Vista Wireless LAN AutoConfig Service Heap-based memory corruption
3280| [4029] Microsoft Windows 2000/XP TCP/IP Window Size denial of service
3281| [49745] Microsoft Windows Server 2003 denial of service
3282| [49395] Microsoft Office 2000/2003/XP Office Web Components Heap-based memory corruption
3283| [49394] Microsoft Windows Server 2003 memory corruption
3284| [49389] Microsoft Office 2000/2003/XP Office Web Components memory corruption
3285| [49390] Microsoft Office 2000/2003/XP Office Web Components memory corruption
3286| [49198] Microsoft Visual Studio 2005 information disclosure
3287| [49047] Microsoft Virtual Server 2005 privilege escalation
3288| [49046] Microsoft Windows Server 2003 quartz.dll memory corruption
3289| [49045] Microsoft Windows Server 2003 quartz.dll memory corruption
3290| [49044] Microsoft ISA Server 2006 privilege escalation
3291| [3999] Microsoft Office 2007 Pointer memory corruption
3292| [4000] Microsoft Office 2003/Sp3/Xp Web Components memory corruption
3293| [48894] Microsoft Windows Server 2003 msvidctl.dll memory corruption
3294| [48572] Microsoft PowerPoint 2002 FL21WIN.DLL memory corruption
3295| [48517] Microsoft Windows 2000 Memory Leak memory corruption
3296| [48516] Microsoft Windows Server 2008 unknown vulnerability
3297| [48512] Microsoft Windows Server 2008 unknown vulnerability
3298| [48515] Microsoft Office Word Viewer 2003 memory corruption
3299| [48514] Microsoft Office Word Viewer 2003 Stack-based memory corruption
3300| [48554] Microsoft Excel 2000/2003/2007 memory corruption
3301| [48157] Microsoft PowerPoint 2002 Sound memory corruption
3302| [48156] Microsoft PowerPoint 2000 Stack-based memory corruption
3303| [48154] Microsoft PowerPoint 2002 Sound PP7X32.DLL memory corruption
3304| [48152] Microsoft PowerPoint 2002 PP4X32.DLL memory corruption
3305| [48150] Microsoft PowerPoint 2002 Sound memory corruption
3306| [48147] Microsoft PowerPoint 2002 Sound memory corruption
3307| [48146] Microsoft PowerPoint 2002 Integer memory corruption
3308| [48155] Microsoft PowerPoint 2002 Notes Container Heap-based memory corruption
3309| [48153] Microsoft PowerPoint 2002 Sound memory corruption
3310| [48151] Microsoft PowerPoint 2002 Stack-based memory corruption
3311| [48149] Microsoft PowerPoint 2002 memory corruption
3312| [48148] Microsoft PowerPoint 2002 Sound memory corruption
3313| [3974] Microsoft PowerPoint 2000/2002/2003 Sound Data Stack-based memory corruption
3314| [3973] Microsoft PowerPoint 2000/2002/2003 Notes Container Stack-based memory corruption
3315| [3972] Microsoft PowerPoint 2000/2002/2003 BuildList memory corruption
3316| [3971] Microsoft PowerPoint 2000/2002/2003 Object Stack-based memory corruption
3317| [3970] Microsoft PowerPoint 2000/2002/2003 Paragraph Stack-based memory corruption
3318| [3969] Microsoft PowerPoint 2000/2002/2003 Atom Stack-based memory corruption
3319| [47719] Microsoft Windows 2000 Stack-based memory corruption
3320| [47720] Microsoft Internet Security And Acceleration Server 2006 Forms Authentication cookieauth.dll cross site scripting
3321| [47716] Microsoft Office Converter Pack 2003 WPFT632.CNV memory corruption
3322| [47715] Microsoft Windows 2000 Wordpad memory corruption
3323| [47718] Microsoft Excel 2000/2002/2003/2007 Spreadsheet memory corruption
3324| [3960] Microsoft Windows 2000/Server 2003/XP DirectShow MJPEG memory corruption
3325| [3952] Microsoft ISA Server 2004/2006 denial of service
3326| [3946] Microsoft PowerPoint 2000/2002/2003/2004 memory corruption
3327| [47091] Microsoft Windows Server 2008 unknown vulnerability
3328| [47090] Microsoft Windows Server 2008 unknown vulnerability
3329| [3939] Microsoft Windows 2000 DNS spoofing
3330| [3938] Microsoft Windows 2000 SSL weak authentication
3331| [3937] Microsoft Windows 2000 memory corruption
3332| [3932] Microsoft Excel 2000/2002/2003/2004/2007 Object Reference memory corruption
3333| [46620] Microsoft Windows Live Messenger 2009 msnmsgr.exe denial of service
3334| [46455] Microsoft Exchange Server 2007 denial of service
3335| [46454] Microsoft Exchange Server 2007 memory corruption
3336| [46453] Microsoft Visio 2002/2003/2007 memory corruption
3337| [46452] Microsoft Visio 2002/2003/2007 memory corruption
3338| [46451] Microsoft Visio 2002/2003/2007 memory corruption
3339| [46327] Microsoft Word 2007 information disclosure
3340| [45758] Microsoft Money 2006 ActiveX Control prtstb06.dll denial of service
3341| [45381] Microsoft Windows Server 2008/Vista SP1 Explorer memory corruption
3342| [45380] Microsoft Windows Server 2008/Vista SP1 Search memory corruption
3343| [45379] Microsoft Office SharePoint Server 2007 denial of service
3344| [3896] Microsoft SQL Server up to 2005 sp_replwritetovarbin memory corruption
3345| [3892] Microsoft Excel 2000/2002/2003 Formula memory corruption
3346| [3891] Microsoft Excel 2000/2002/2003 memory corruption
3347| [3890] Microsoft Excel 2000/2002/2003 NAME Index memory corruption
3348| [3889] Microsoft Word 2000/2002/2003/2007 Table Property Stack-based memory corruption
3349| [3888] Microsoft Word 2000/2002/2003/2007 RTF Stylesheet memory corruption
3350| [3887] Microsoft Word 2000/2002/2003/2007 memory corruption
3351| [3886] Microsoft Word 2000/2002/2003/2007 ControlWord Heap-based memory corruption
3352| [3885] Microsoft Word 2000/2002/2003/2007 memory corruption
3353| [3884] Microsoft Word 2000/2002/2003/2007 memory corruption
3354| [3883] Microsoft Word 2000/2002/2003/2007 RTF Heap-based memory corruption
3355| [3882] Microsoft Word 2000/2002/2003/2007 LFO memory corruption
3356| [3880] Microsoft Visual Basic up to 2003 ActiveX Control Mschrt20.ocx memory corruption
3357| [3879] Microsoft Visual Basic up to 2003 ActiveX Control mscomct2.ocx memory corruption
3358| [3878] Microsoft Visual Basic up to 2003 ActiveX Control mshflxgd.ocx memory corruption
3359| [3877] Microsoft Visual Basic up to 2003 ActiveX Control msflxgrd.ocx memory corruption
3360| [3876] Microsoft Visual Basic up to 2003 ActiveX Control msdatgrd.ocx memory corruption
3361| [45197] Microsoft Windows 2000 nskey.dll memory corruption
3362| [45063] Microsoft Windows Server 2003 Active Directory unknown vulnerability
3363| [45040] Microsoft .NET Framework 2.0.50727 Code Access Security unknown vulnerability
3364| [44855] DjVu Activex Control For Microsoft Office 2000 3.0 ActiveX Control DjVu_ActiveX_MSOffice.dll memory corruption
3365| [44665] Microsoft Peachtree Accounting 2004 ActiveX Control PAWWeb11.ocx unknown vulnerability
3366| [44589] Microsoft Exchange Server 2003 Outlook Web Access unknown vulnerability
3367| [3845] Microsoft Windows 2000 SP4 Active Directory memory corruption
3368| [44533] Microsoft Windows 2000 mqsvc.exe memory corruption
3369| [3844] Microsoft Excel 2003 REPT memory corruption
3370| [3843] Microsoft Excel up to 2007 BIFF File Heap-based memory corruption
3371| [3842] Microsoft Excel 2003 VBA Performance Cache Stack-based memory corruption
3372| [44405] Microsoft Digital Image 2006 ActiveX Control PipPPush.DLL unknown vulnerability
3373| [44047] Microsoft SQL Server 2000 ActiveX Control SQLVDIRLib.SQLVDirControl memory corruption
3374| [43981] Microsoft Organization Chart 2.00 orgchart.exe memory corruption
3375| [43957] Microsoft Office 2003/2007/Xp gdiplus.dll memory corruption
3376| [43956] Microsoft Office 2003/2007/Xp gdiplus.dll memory corruption
3377| [43955] Microsoft Office 2003/2007/Xp gdiplus.dll memory corruption
3378| [43952] Microsoft Office 2003/2007/Xp URI memory corruption
3379| [43676] Microsoft Windows 2000/Server 2003/Vista/XP memory corruption
3380| [43675] Microsoft Windows 2000/Server 2003/Vista/XP of memory corruption
3381| [43662] Microsoft PowerPoint Viewer 2000 SP3/2002 SP3/2003 SP2/2007 SP1 memory corruption
3382| [43661] Microsoft PowerPoint Viewer 2003 memory corruption
3383| [43660] Microsoft PowerPoint Viewer 2003 Integer memory corruption
3384| [43657] Microsoft Office 2000/2003/Xp memory corruption
3385| [43654] Microsoft SharePoint Server 2007 memory corruption
3386| [43653] Microsoft Office 2000/2002/2004/2008 memory corruption
3387| [43652] Microsoft Office 2000/2002/2003/2004/2008 memory corruption
3388| [3797] Microsoft Windows Server 2008/Vista IPsec Policy Designfehler
3389| [3796] Microsoft Office 2000 WPG memory corruption
3390| [3795] Microsoft Office 2000/2003/Xp BMP Image BMPIMP32.FLT memory corruption
3391| [3794] Microsoft Office 2000/2003/Xp PICT bits_per_pixel memory corruption
3392| [3793] Microsoft Office 2000/2003/Xp PICT memory corruption
3393| [3792] Microsoft Office 2000 EPS File memory corruption
3394| [3783] Microsoft Word 2002 memory corruption
3395| [43103] Microsoft Exchange Srv 2007 Sp1 Outlook Web Access cross site scripting
3396| [43102] Microsoft Windows 2000 SP4/Server 2003 SP2/Server 2008 DNS Cache privilege escalation
3397| [3778] Microsoft Exchange 2003/2007 Outlook Web Access cross site scripting
3398| [3777] Microsoft Windows Server 2008/Vista SP1 Explorer memory corruption
3399| [43087] Microsoft Office Snapshot Viewer ActiveX up to Office 2003 Snapshot Viewer ActiveX Control snapview.ocx memory corruption
3400| [43096] Microsoft Publisher 2003/2007 Crypto API unknown vulnerability
3401| [42816] Microsoft Word 2000/2003 memory corruption
3402| [42732] Microsoft Windows Server 2003/Vista/XP denial of service
3403| [42731] Microsoft Windows Server 2003 denial of service
3404| [3732] Microsoft Windows 2000/Server 2003 WINS memory corruption
3405| [3701] Microsoft Word 2003 CSS Heap-based memory corruption
3406| [3700] Microsoft Word 2003 RTF Document Heap-based memory corruption
3407| [42065] Microsoft SharePoint Server 2.0 Rich Text Editor cross site scripting
3408| [41881] Microsoft Office 2003/2007/2007 Sp1/Xp memory corruption
3409| [41880] Microsoft Project 2000/2002/2003 memory corruption
3410| [41879] Microsoft Windows 2000/Server 2003/Vista Stack-based memory corruption
3411| [41878] Microsoft Windows 2000/Server 2003/Vista spoofing
3412| [41877] Microsoft Windows Server 2003 vbscript.dll memory corruption
3413| [3671] Microsoft Visio 2002/2003/2003 Sp3/2007/2007 Sp1 memory corruption
3414| [3670] Microsoft Visio 2002/2003/2003 Sp3/2007/2007 Sp1 Object memory corruption
3415| [41455] Microsoft Office 2000/2003/2004/Xp memory corruption
3416| [41454] Microsoft Excel 2000/2002/2003/2007 memory corruption
3417| [41453] Microsoft Excel 2000/2002/2003 memory corruption
3418| [41452] Microsoft Excel 2000/2002/2003/2007 memory corruption
3419| [41451] Microsoft Excel 2000/2002/2003 memory corruption
3420| [41450] Microsoft Excel 2000 memory corruption
3421| [41449] Microsoft Excel 2000/2002/2003 memory corruption
3422| [41448] Microsoft Office 2000/Xp Office Web Components memory corruption
3423| [3648] Microsoft Excel 2003 memory corruption
3424| [3647] Microsoft Outlook up to 2007 mailto URI memory corruption
3425| [41003] Microsoft Office 2000/2003/2004/Xp memory corruption
3426| [41002] Microsoft Office 2000/2003/Xp memory corruption
3427| [41001] Microsoft Works 2005/8.0 wkcvqd01.dll memory corruption
3428| [41000] Microsoft Works 2005/8.0 memory corruption
3429| [40998] Microsoft Publisher 2000/2002/2003 memory corruption
3430| [40994] Microsoft Works 2005/8.0 wkcvqd01.dll memory corruption
3431| [40987] Microsoft Windows 2000 denial of service
3432| [40736] Microsoft ActiveX 2.0 ActiveX Control privilege escalation
3433| [3552] Microsoft Excel 2000/2002/2003 File memory corruption
3434| [40242] Microsoft Publisher 2000/2002/2003/2007 Crash denial of service
3435| [40020] Microsoft Office 2007 ZIP Container unknown vulnerability
3436| [39769] Microsoft Windows 2000 cryptgenrandom weak encryption
3437| [39749] Microsoft Windows 2000 msjet40.dll memory corruption
3438| [39655] Microsoft Windows Server 2003 spoofing
3439| [39324] Microsoft Windows Mobile 2005 SMS unknown vulnerability
3440| [3373] Microsoft Word 2000/2002 memory corruption
3441| [38999] Microsoft Windows Server 2003 explorer.exe denial of service
3442| [38899] Microsoft ISA Server 2004 information disclosure
3443| [38728] Microsoft SQL Server 2005 Enterprise Manager sqldmo.dll memory corruption
3444| [38326] Microsoft Windows 2000 attemptwrite memory corruption
3445| [3241] Microsoft Excel 2000/2003/2004/XP SP3 rtWnDesk memory corruption
3446| [3223] Microsoft Windows Server 2003/XP URI privilege escalation
3447| [3212] Microsoft DirectX February 2006 RLE Compression Targa Files Heap-based memory corruption
3448| [37739] Microsoft Excel 2000/2002/2003/2004/2007 memory corruption
3449| [37738] Microsoft Office 2002/2003 memory corruption
3450| [3176] Microsoft Excel 2000/2002/2003/2007 File Attribute memory corruption
3451| [3175] Microsoft Excel 2000/2002/2003/2007 Active Worksheet memory corruption
3452| [3174] Microsoft Excel 2000/2002/2003/2007 Version Information memory corruption
3453| [3172] Microsoft Office Publisher 2007 Pointer memory corruption
3454| [37566] Microsoft Excel 2003 unknown vulnerability
3455| [37526] Microsoft Windows 2000/Server 2003 denial of service
3456| [37248] Microsoft Visio 2002 Packaging memory corruption
3457| [37251] Microsoft Windows 2000 memory corruption
3458| [3119] Microsoft Visio 2002 Object memory corruption
3459| [3118] Microsoft Visio 2002 Data memory corruption
3460| [37093] Microsoft Windows Server 2003 Error Message unknown vulnerability
3461| [37010] Microsoft Office 2000 ActiveX Control ouactrl.ocx memory corruption
3462| [36628] Microsoft Word 2000/2002/2003/2004 winword.exe memory corruption
3463| [36616] Microsoft Works 2004/2005/2006 memory corruption
3464| [36621] Microsoft Exchange Server 2000 Integer denial of service
3465| [36620] Microsoft Exchange Server 2000 Outlook Web Access cross site scripting
3466| [36619] Microsoft Exchange Server 2000/2003/2007 MIME Email memory corruption
3467| [36618] Microsoft Exchange Server 2000 NULL Pointer Dereference denial of service
3468| [36617] Microsoft Excel 2000/2002/2003/2004 memory corruption
3469| [36623] Microsoft BizTalk Server 2004 ActiveX Control capicom.dll memory corruption
3470| [3067] Microsoft Office 2000/2003/2004/2007/Xp Drawing Object memory corruption
3471| [3065] Microsoft Excel 2000/2002/2003/2007 Filter Stack-based memory corruption
3472| [3064] Microsoft Excel 2000/2002/2003/2004/2007 set Font memory corruption
3473| [3063] Microsoft Excel 2000/2002/2003/2007 BIFF Record Stack-based memory corruption
3474| [3012] Microsoft Windows 2000/Server 2003 DNS Service Stack-based memory corruption
3475| [36039] Microsoft Content Management Server 2001 memory corruption
3476| [36052] Microsoft Windows 2000 Heap-based memory corruption
3477| [36051] Microsoft Word 2007 file798-1.doc memory corruption
3478| [36050] Microsoft Word 2007 file789-1.doc memory corruption
3479| [36040] Microsoft Content Management Server 2001 cross site scripting
3480| [3004] Microsoft Windows up to 2003/XP URL Parser memory corruption
3481| [36041] Microsoft .NET Framework 2.0.50727.42 cross site scripting
3482| [36002] Microsoft Windows 2000/XP denial of service
3483| [2990] Microsoft Windows 2000/Vista/XP Animated Cursor Stack-based memory corruption
3484| [36515] Microsoft Windows 2000/Server 2003/XP memory corruption
3485| [35846] Microsoft Windows 2000/Server 2003 Default Configuration information disclosure
3486| [35373] Microsoft Excel 2003 denial of service
3487| [35372] Microsoft Office 2003 denial of service
3488| [35206] Microsoft Windows Server 2003/XP Crash denial of service
3489| [35161] Microsoft ISA Server 2004 unknown vulnerability
3490| [35236] Microsoft Publisher 2007 memory corruption
3491| [2939] Microsoft Word 2000 memory corruption
3492| [34994] Microsoft Windows 2000 OLE Dialog memory corruption
3493| [34993] Microsoft Office 2000/2003/Xp memory corruption
3494| [35001] Microsoft Office 2000/2003/2004/Xp memory corruption
3495| [35000] Microsoft Word 2000/2002/2003 memory corruption
3496| [2933] Microsoft Windows 2000 SP4/Server 2003 SP1/XP SP2 OLE Dialog Stack-based memory corruption
3497| [2894] Microsoft Office 2000/2003/2004/Xp Undefined String Format String
3498| [2884] Microsoft Word 2000/2002/2003 memory corruption
3499| [34321] Microsoft Office 2000/2003/2004/Xp Spreadsheet Heap-based memory corruption
3500| [34320] Microsoft Office 2000/2003/2004/Xp memory corruption
3501| [34319] Microsoft Office 2000/2003/2004/Xp memory corruption
3502| [34318] Microsoft Office 2000/2003/2004/Xp memory corruption
3503| [34322] Microsoft Office 2000/2003/Xp memory corruption
3504| [2811] Microsoft Windows 2000/Server 2003/XP VML Vector Markup Language Integer memory corruption
3505| [2810] Microsoft Outlook 2000/2002/2003 Office Saved Search OSS File memory corruption
3506| [2809] Microsoft Outlook 2000/2002/2003 Header denial of service
3507| [2808] Microsoft Outlook 2000/2002/2003 Meeting VEVENT memory corruption
3508| [2807] Microsoft Excel 2000/2002/2003 XLS File memory corruption
3509| [34126] Microsoft Office 2003 memory corruption
3510| [34122] Microsoft Office Web Components 2000 memory corruption
3511| [2789] Microsoft Windows 2000/XP RPC Request NetrWkstaUserEnum denial of service
3512| [2765] Microsoft Project Server 2003 pdsrequest.asp weak authentication
3513| [33851] Microsoft Word 2000/2002/2003 12122006-djtest.doc memory corruption
3514| [2739] Microsoft Windows 2000 Remote Installation Service Fehlende Authentifizierung
3515| [2738] Microsoft Windows 2000/Server 2003/XP SNMP memory corruption
3516| [2737] Microsoft Windows Server 2003/XP Manifest denial of service
3517| [33766] Microsoft Word 2000/2002/2003 memory corruption
3518| [2718] Microsoft Word 2000/2002/2003 DOC Document memory corruption
3519| [2717] Microsoft Windows 2000 Print Spooler Memory Consumption denial of service
3520| [2689] Microsoft Windows up to 2000 SP4 Active Directory denial of service
3521| [2688] Microsoft Windows 2000/Server 2003/XP Client Service for Netware denial of service
3522| [2687] Microsoft Windows 2000/Server 2003/XP Agent ActiveX ACF File Heap-based memory corruption
3523| [2686] Microsoft Windows 2000/Server 2003/XP Client Service for Netware memory corruption
3524| [2684] Microsoft Windows 2000/XP Workstation Service Stack-based memory corruption
3525| [2659] Microsoft Windows 2000/XP GDI Crash memory corruption
3526| [2655] Microsoft Windows 2000/Server 2003/XP XML Core Services memory corruption
3527| [33067] Microsoft Visual Studio .net 2005 ActiveX Control wmiscriptutils.dll memory corruption
3528| [2610] Microsoft PowerPoint 2003 PPT Document NULL Pointer Dereference denial of service
3529| [32693] Microsoft Word 2004 memory corruption
3530| [32686] Microsoft Office 2000/2001/2003/2004 Integer memory corruption
3531| [32690] Microsoft Office 2000/2003/2004/Xp memory corruption
3532| [32676] Microsoft Office 2000/2001/2003/2004 memory corruption
3533| [32675] Microsoft Office 2000/2003/2004/Xp memory corruption
3534| [32694] Microsoft Windows 2000 memory corruption
3535| [32689] Microsoft Excel 2000/2002/2003/2004/XP memory corruption
3536| [32688] Microsoft Excel 2000/2002/2003/2004/XP memory corruption
3537| [32687] Microsoft Word 2000/2002 memory corruption
3538| [32685] Microsoft Office 2000/2001/2003/2004 memory corruption
3539| [2601] Microsoft Windows Server 2003/XP IPv6 Stack denial of service
3540| [2600] Microsoft Windows Server 2003/XP IPv6 Stack TCP denial of service
3541| [2599] Microsoft Windows Server 2003/XP IPv6 Stack ICMP denial of service
3542| [2598] Microsoft Windows Server 2003/XP Object Packager privilege escalation
3543| [2597] Microsoft Office 2003/Xp Smart-Tag Parser memory corruption
3544| [2596] Microsoft Office 2000/2003/2004/Xp Value Read memory corruption
3545| [2595] Microsoft Office 2000/2001/2003/2004 Diagram Value memory corruption
3546| [2594] Microsoft Office 2000/2001/2003/2004 Document memory corruption
3547| [2593] Microsoft ASP.NET 2.0 cross site scripting
3548| [141652] Microsoft Windows up to Server 2019 Common Log File System Driver information disclosure
3549| [141639] Microsoft SharePoint Foundation 2013 SP1 cross site request forgery
3550| [141637] Microsoft Windows up to Server 2019 AppX Deployment Server privilege escalation
3551| [141636] Microsoft ASP.NET Core 2.1/2.2/3.0 Project Template privilege escalation
3552| [141635] Microsoft .NET Core 2.1/2.2 denial of service
3553| [141633] Microsoft Excel up to 2019 memory corruption
3554| [141631] Microsoft Windows up to Server 2019 SMB Client Driver information disclosure
3555| [141630] Microsoft Windows up to Server 2019 denial of service
3556| [141629] Microsoft Windows up to Server 2019 Update Delivery Optimization privilege escalation
3557| [141627] Microsoft Windows up to Server 2019 GDI information disclosure
3558| [141626] Microsoft Windows up to Server 2019 Win32k memory corruption
3559| [141621] Microsoft Windows up to Server 2019 Kernel information disclosure
3560| [141620] Microsoft Windows up to Server 2019 Active Directory Federation Services cross site scripting
3561| [141619] Microsoft Windows up to Server 2019 ALPC privilege escalation
3562| [141618] Microsoft Windows up to Server 2019 hdAudio.sys privilege escalation
3563| [141617] Microsoft Windows up to Server 2019 Store Installer privilege escalation
3564| [141616] Microsoft Windows up to Server 2019 ALPC privilege escalation
3565| [141615] Microsoft Windows up to Server 2019 Winlogon privilege escalation
3566| [141614] Microsoft Windows up to Server 2019 Compatibility Appraiser privilege escalation
3567| [141611] Microsoft Office up to 2019 Security Feature privilege escalation
3568| [141610] Microsoft Excel up to 2019 information disclosure
3569| [141609] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
3570| [141608] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site request forgery
3571| [141607] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016/2019 privilege escalation
3572| [141606] Microsoft Windows up to Server 2019 Win32k memory corruption
3573| [141605] Microsoft Windows up to Server 2019 Hyper-V information disclosure
3574| [141604] Microsoft Windows up to Server 2019 AppX Deployment Server privilege escalation
3575| [141603] Microsoft Windows up to Server 2019 GDI information disclosure
3576| [141602] Microsoft Windows up to Server 2019 DirectWrite information disclosure
3577| [141601] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3578| [141600] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3579| [141599] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3580| [141598] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3581| [141597] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3582| [141596] Microsoft Windows up to Server 2019 DirectWrite information disclosure
3583| [141595] Microsoft Windows up to Server 2019 DirectWrite information disclosure
3584| [141594] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3585| [141593] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3586| [141592] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3587| [141591] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3588| [141590] Microsoft Windows up to Server 2019 Text Service Framework command injection
3589| [141589] Microsoft Exchange Server 2016 CU12/2016 CU13/2019 CU1/2019 CU2 denial of service
3590| [141583] Microsoft Lync Server 2013 Conference directory traversal
3591| [141581] Microsoft Windows up to Server 2016 Hyper-V denial of service
3592| [141580] Microsoft Windows up to Server 2019 Transaction Manager information disclosure
3593| [141579] Microsoft Windows up to Server 2016 DirectX information disclosure
3594| [141577] Microsoft Windows up to Server 2019 Common Log File System Driver privilege escalation
3595| [141575] Microsoft Windows up to Server 2019 lnk File privilege escalation
3596| [141564] Microsoft SharePoint Enterprise Server 2010 SP1/2013 SP1/2016/2019 Markup Application Package privilege escalation
3597| [141561] Microsoft Windows up to Server 2019 Remote Desktop privilege escalation
3598| [141560] Microsoft Windows up to Server 2019 Remote Desktop privilege escalation
3599| [139972] Microsoft Windows up to Server 2019 HTTP2 HTTP.sys denial of service
3600| [139971] Microsoft Windows up to Server 2019 HTTP2 HTTP.sys denial of service
3601| [139970] Microsoft Windows up to Server 2019 HTTP2 HTTP.sys denial of service
3602| [139969] Microsoft Windows up to Server 2019 HTTP2 HTTP.sys denial of service
3603| [139968] Microsoft Windows up to Server 2019 HTTP2 HTTP.sys denial of service
3604| [139965] Microsoft Windows up to Server 2019 Kernel information disclosure
3605| [139963] Microsoft Windows up to Server 2019 Remote Desktop Protocol information disclosure
3606| [139962] Microsoft Windows up to Server 2019 Remote Desktop Protocol denial of service
3607| [139960] Microsoft Windows up to Server 2019 DHCP Server denial of service
3608| [139958] Microsoft Windows up to Server 2019 DHCP Server denial of service
3609| [139957] Microsoft SharePoint Server 2013 SP1/2016/2019 cross site scripting
3610| [139956] Microsoft SharePoint 2010 SP2/2013 SP1/2016/2019 Session Object information disclosure
3611| [139955] Microsoft Windows up to Server 2019 SyncController.dll privilege escalation
3612| [139949] Microsoft Windows up to Server 2019 XmlLite Runtime XmlLite.dll denial of service
3613| [139946] Microsoft Windows up to Server 2019 Core Shell COM Server Registrar COM Call privilege escalation
3614| [139942] Microsoft Windows up to Server 2019 rpcss.dll memory corruption
3615| [139941] Microsoft Windows up to Server 2019 DirectX memory corruption
3616| [139937] Microsoft Windows up to Server 2019 Azure Active Directory information disclosure
3617| [139936] Microsoft Windows up to Server 2019 SymCrypt information disclosure
3618| [139935] Microsoft Windows 10 1809/10 1903/Server 1903/Server 2019 NTFS privilege escalation
3619| [139934] Microsoft Windows 7 SP1/Server 2018 R2 SP1/Server 2018 SP2 Win32k memory corruption
3620| [139933] Microsoft Windows up to Server 2019 p2pimsvc privilege escalation
3621| [139932] Microsoft Windows up to Server 2019 Kernel memory corruption
3622| [139931] Microsoft Windows up to Server 2019 File Signature Security Feature CAB File privilege escalation
3623| [139930] Microsoft Windows up to Server 2019 ALPC privilege escalation
3624| [139928] Microsoft Windows up to Server 2019 Kernel memory corruption
3625| [139927] Microsoft Windows up to Server 2019 Graphics Component information disclosure
3626| [139926] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3627| [139925] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3628| [139924] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3629| [139922] Microsoft Windows up to Server 2019 Graphics Component information disclosure
3630| [139921] Microsoft Windows up to Server 2019 Graphics Component information disclosure
3631| [139920] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3632| [139919] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3633| [139918] Microsoft Windows up to Server 2019 Graphics Component information disclosure
3634| [139917] Microsoft Windows up to Server 2019 Graphics Component information disclosure
3635| [139916] Microsoft Windows up to Server 2019 XML Core Services MSXML Parser privilege escalation
3636| [139914] Microsoft Windows up to Server 2019 Hyper-V Network Switch denial of service
3637| [139913] Microsoft Windows up to Server 2019 Hyper-V Network Switch denial of service
3638| [139912] Microsoft Windows 10 1809/10 1903/Server 1903/Server 2019 Hyper-V Network Switch denial of service
3639| [139911] Microsoft Windows up to Server 2019 denial of service
3640| [139910] Microsoft Windows up to Server 2019 Hyper-V Network Switch denial of service
3641| [139909] Microsoft Windows up to Server 2019 Hyper-V Network Switch denial of service
3642| [139908] Microsoft Windows up to Server 2019 Bluetooth weak encryption
3643| [139907] Microsoft Windows up to Server 2019 Remote Desktop Service privilege escalation
3644| [139906] Microsoft Windows up to Server 2019 Remote Desktop Service privilege escalation
3645| [139902] Microsoft Word up to 2019 memory corruption
3646| [139901] Microsoft Outlook up to 2019 memory corruption
3647| [139895] Microsoft Windows up to Server 2019 lnk File privilege escalation
3648| [139894] Microsoft Windows up to Server 2019 VBScript Engine memory corruption
3649| [139893] Microsoft Windows up to Server 2019 Remote Desktop Service privilege escalation
3650| [139892] Microsoft Windows up to Server 2019 Remote Desktop Service privilege escalation
3651| [139891] Microsoft Windows up to Server 2019 Font Library memory corruption
3652| [139890] Microsoft Windows up to Server 2019 Font Library memory corruption
3653| [139889] Microsoft Windows up to Server 2019 Font Library memory corruption
3654| [139888] Microsoft Windows up to Server 2019 Font Library memory corruption
3655| [139887] Microsoft Windows up to Server 2019 Font Library memory corruption
3656| [139886] Microsoft Windows up to Server 2019 Font Library memory corruption
3657| [139880] Microsoft Windows up to Server 2019 Hyper-V memory corruption
3658| [139879] Microsoft Windows up to Server 2019 DHCP Client memory corruption
3659| [139878] Microsoft Windows up to Server 2019 Hyper-V Network Switch memory corruption
3660| [139877] Microsoft Outlook up to 2019 memory corruption
3661| [139876] Microsoft Windows up to Server 2019 Remote Desktop Service privilege escalation
3662| [139875] Microsoft Windows up to Server 2019 Remote Desktop Service privilege escalation
3663| [137590] Microsoft ASP.NET Core 2.1/2.2 Open Redirect
3664| [137589] Microsoft Exchange Server 2013 CU23/2016 CU12/2016 CU13/2019 CU1/2019 CU2 cross site scripting
3665| [137588] Microsoft Exchange Server 2010 SP3/2013 CU23/2016 CU12/2016 CU13 Web Services privilege escalation
3666| [137587] Microsoft SharePoint Server 2013 SP1/2016/2019 cross site scripting
3667| [137586] Microsoft Windows up to Server 2019 AppX Deployment Service privilege escalation
3668| [137585] Microsoft Windows up to Server 2019 AppX Deployment Service privilege escalation
3669| [137584] Microsoft Windows up to Server 2019 DirectWrite memory corruption
3670| [137583] Microsoft Windows up to Server 2019 DirectWrite memory corruption
3671| [137581] Microsoft Windows up to Server 2019 DirectWrite memory corruption
3672| [137580] Microsoft Windows up to Server 2019 DirectWrite memory corruption
3673| [137579] Microsoft Windows up to Server 2019 DirectWrite memory corruption
3674| [137578] Microsoft Windows up to Server 2019 DirectWrite memory corruption
3675| [137577] Microsoft Windows up to Server 2019 DirectWrite memory corruption
3676| [137576] Microsoft Windows up to Server 2019 DirectWrite memory corruption
3677| [137575] Microsoft Windows up to Server 2019 DirectWrite memory corruption
3678| [137574] Microsoft Windows up to Server 2019 DirectWrite memory corruption
3679| [137568] Microsoft Windows up to Server 2019 Remote Desktop Protocol information disclosure
3680| [137563] Microsoft Windows up to Server 2019 DirectWrite information disclosure
3681| [137562] Microsoft Windows up to Server 2019 Win32k information disclosure
3682| [137561] Microsoft Windows up to Server 2019 GDI information disclosure
3683| [137560] Microsoft Windows up to Server 2019 GDI information disclosure
3684| [137559] Microsoft Windows up to Server 2019 DirectWrite information disclosure
3685| [137555] Microsoft Windows up to Server 2019 Audio Service privilege escalation
3686| [137554] Microsoft Windows up to Server 2019 Audio Service privilege escalation
3687| [137553] Microsoft Windows up to Server 2019 Audio Service privilege escalation
3688| [137549] Microsoft Windows up to Server 2016 DLL privilege escalation
3689| [137544] Microsoft Windows up to Server 2019 Kernel information disclosure
3690| [137543] Microsoft Windows up to Server 2019 Kernel information disclosure
3691| [137542] Microsoft SQL Server 2014 SP2/2016 SP1/2017 privilege escalation
3692| [137541] Microsoft Windows up to Server 2019 memory corruption
3693| [137540] Microsoft Windows up to Server 2019 Error Reporting privilege escalation
3694| [137539] Microsoft Windows up to Server 2016 DirectX memory corruption
3695| [137538] Microsoft Windows Server 1803/Server 1903/Server 2016/Server 2019 ADFS Security Feature privilege escalation
3696| [137537] Microsoft Windows up to Server 2019 Hyper-V denial of service
3697| [137535] Microsoft Windows up to Server 2019 Remote Desktop Service privilege escalation
3698| [137533] Microsoft Windows up to Server 2019 SymCrypt denial of service
3699| [137527] Microsoft Windows up to Server 2019 GDI+ memory corruption
3700| [137512] Microsoft Windows up to Server 2019 DHCP memory corruption
3701| [136414] Microsoft Azure DevOps Server 2019 cross site request forgery
3702| [136349] Microsoft Windows up to Server 2019 Event Viewer eventvwr.msc XML External Entity
3703| [136348] Microsoft Windows up to Server 2019 Task Scheduler privilege escalation
3704| [136347] Microsoft Windows up to Server 2019 AppXSVC privilege escalation
3705| [136345] Microsoft Windows up to Server 2019 Windows Shell privilege escalation
3706| [136344] Microsoft Windows up to Server 2019 GDI information disclosure
3707| [136340] Microsoft Windows up to Server 2019 GDI information disclosure
3708| [136337] Microsoft Windows up to Server 2019 Comctl32.dll memory corruption
3709| [136336] Microsoft Windows up to Server 2019 Kernel privilege escalation
3710| [136335] Microsoft Windows up to Server 2019 NTLM Downgrade weak authentication
3711| [136334] Microsoft Windows up to Server 2019 Kernel information disclosure
3712| [136333] Microsoft SharePoint Server 2010 SP2/2013 SP1/2016/2019 cross site scripting
3713| [136330] Microsoft SharePoint Server 2010 SP2/2013 SP1/2016/2019 cross site scripting
3714| [136329] Microsoft SharePoint Server 2016/2019 cross site scripting
3715| [136328] Microsoft SharePoint Server 2010 SP2/2013 SP1/2016/2019 cross site scripting
3716| [136327] Microsoft Lync Server 2010/2013 denial of service
3717| [136326] Microsoft Windows up to Server 2019 Audio Service privilege escalation
3718| [136325] Microsoft Windows up to Server 2019 Audio Service privilege escalation
3719| [136324] Microsoft Windows up to Server 2019 Audio Service privilege escalation
3720| [136323] Microsoft Windows up to Server 2019 denial of service
3721| [136321] Microsoft Windows 10 1809/10 1903/Server 1903/Server 2019 Audio Service privilege escalation
3722| [136320] Microsoft Windows up to Server 2019 Audio Service privilege escalation
3723| [136319] Microsoft Windows up to Server 2019 Security Credentials information disclosure
3724| [136318] Microsoft Windows up to Server 2019 DirectX privilege escalation
3725| [136317] Microsoft Windows up to Server 2019 Win32k memory corruption
3726| [136314] Microsoft Windows up to Server 2019 Win32k memory corruption
3727| [136312] Microsoft Windows up to Server 2019 GDI information disclosure
3728| [136310] Microsoft Windows up to Server 2019 GDI information disclosure
3729| [136308] Microsoft Windows up to Server 2019 Audio Service privilege escalation
3730| [136306] Microsoft Windows up to Server 2019 Storage Service privilege escalation
3731| [136305] Microsoft Windows up to Server 2019 User Profile Service privilege escalation
3732| [136304] Microsoft Windows up to Server 2019 Common Log File System Driver privilege escalation
3733| [136303] Microsoft Windows up to Server 2019 Storage Service privilege escalation
3734| [136301] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3735| [136299] Microsoft Windows up to Server 2019 Local Security Authority Subsystem Service Reboot denial of service
3736| [136296] Microsoft Windows up to Server 2019 Common Log File System Driver memory corruption
3737| [136295] Microsoft Windows up to Server 2019 ALPC privilege escalation
3738| [136293] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3739| [136292] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3740| [136291] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3741| [136290] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3742| [136289] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3743| [136288] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3744| [136287] Microsoft Windows up to Server 2019 Hyper-V denial of service
3745| [136286] Microsoft Windows up to Server 2019 Hyper-V denial of service
3746| [136285] Microsoft Windows up to Server 2019 Hyper-V denial of service
3747| [136284] Microsoft Windows up to Server 2019 Kernel memory corruption
3748| [136276] Microsoft Windows up to Server 2019 Hyper-V memory corruption
3749| [136275] Microsoft Windows 10/10 1607/10 1703/10 1709/Server 2016 Hyper-V memory corruption
3750| [136274] Microsoft Windows up to Server 2019 ActiveX memory corruption
3751| [136273] Microsoft Windows up to Server 2019 Hyper-V memory corruption
3752| [134750] Microsoft ASP.NET Core 2.1/2.2 denial of service
3753| [134745] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
3754| [134744] Microsoft Windows up to Server 2019 GDI information disclosure
3755| [134743] Microsoft SharePoint Server 2013 SP1/2016 cross site scripting
3756| [134742] Microsoft SharePoint Enterprise Server 2016/2019 cross site scripting
3757| [134741] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
3758| [134740] Microsoft SharePoint Enterprise Server 2013 SP1/2016 privilege escalation
3759| [134739] Microsoft SharePoint Foundation 2010 SP2/2013 SP2 cross site scripting
3760| [134738] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
3761| [134737] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
3762| [134736] Microsoft Office 2010 SP2 Access Connectivity Engine memory corruption
3763| [134735] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
3764| [134734] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
3765| [134733] Microsoft Windows up to Server 2019 Unified Write Filter privilege escalation
3766| [134731] Microsoft Windows up to Server 2019 Symlink privilege escalation
3767| [134729] Microsoft Windows up to Server 2019 Storage Service privilege escalation
3768| [134725] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3769| [134724] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3770| [134723] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3771| [134722] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3772| [134721] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3773| [134720] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3774| [134719] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3775| [134718] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3776| [134717] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3777| [134716] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3778| [134715] Microsoft Windows up to Server 2019 Win32k memory corruption
3779| [134714] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3780| [134713] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3781| [134712] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3782| [134710] Microsoft Windows up to Server 2019 GDI information disclosure
3783| [134709] Microsoft Windows up to Server 2019 Kernel privilege escalation
3784| [134706] Microsoft Windows up to Server 2019 Error Reporting privilege escalation
3785| [134701] Microsoft Windows up to Server 2019 Windows Defender Application Control privilege escalation
3786| [134700] Microsoft Windows up to Server 2019 Diagnostic Hub privilege escalation
3787| [134699] Microsoft Windows up to Server 2019 NDIS ndis.sys memory corruption
3788| [134698] Microsoft Windows up to Server 2019 OLE memory corruption
3789| [134684] Microsoft Windows up to Server 2019 DHCP Server memory corruption
3790| [134678] Microsoft Windows up to Server 2019 GDI+ memory corruption
3791| [133236] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3792| [133234] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3793| [133232] Microsoft Azure DevOps Server 2019 cross site scripting
3794| [133229] Microsoft Azure DevOps Server 2019 cross site scripting
3795| [133224] Microsoft Exchange Server 2013 CU22/2016 CU11/2016 CU12/2019/2019 CU1 Outlook Web Access privilege escalation
3796| [133223] Microsoft Azure DevOps Server 2019 Content Security Policy privilege escalation
3797| [133222] Microsoft Windows up to Server 2019 Remote Registry Service memory corruption
3798| [133221] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3799| [133220] Microsoft Windows up to Server 2019 GDI Memory information disclosure
3800| [133219] Microsoft Windows up to Server 2019 Win32k Memory information disclosure
3801| [133218] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3802| [133217] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3803| [133216] Microsoft Windows up to Server 2019 Kernel Memory information disclosure
3804| [133215] Microsoft Windows up to Server 2019 VBScript Engine memory corruption
3805| [133214] Microsoft Windows up to Server 2019 AppX Deployment Service privilege escalation
3806| [133213] Microsoft Windows up to Server 2019 Kernel Memory information disclosure
3807| [133212] Microsoft Windows up to Server 2019 Terminal Services Memory information disclosure
3808| [133211] Microsoft Windows up to Server 2019 Task Scheduler information disclosure
3809| [133209] Microsoft Windows up to Server 2019 LUAFV Driver luafv.sys privilege escalation
3810| [133206] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016/2019 cross site scripting
3811| [133205] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site scripting
3812| [133204] Microsoft Office/Excel up to 2019 memory corruption
3813| [133203] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
3814| [133202] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
3815| [133201] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
3816| [133200] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
3817| [133199] Microsoft Office 2010 SP2 Access Connectivity Engine memory corruption
3818| [133198] Microsoft Exchange Server up to 2019 CU1 Outlook Web Access cross site scripting
3819| [133197] Microsoft ASP.NET Core 2.2 Request denial of service
3820| [133196] Microsoft Windows up to Server 2019 Win32k information disclosure
3821| [133195] Microsoft Windows up to Server 2019 LUAFV Driver luafv.sys privilege escalation
3822| [133194] Microsoft Windows up to Server 2019 GDI Memory information disclosure
3823| [133193] Microsoft Windows up to Server 2019 LUAFV Driver luafv.sys privilege escalation
3824| [133192] Microsoft Windows up to Server 2019 OLE Automation privilege escalation
3825| [133189] Microsoft Windows up to Server 2019 CSRSS memory corruption
3826| [133188] Microsoft Windows up to Server 2019 LUAFV Driver luafv.sys privilege escalation
3827| [133187] Microsoft Windows up to Server 2019 LUAFV Driver luafv.sys privilege escalation
3828| [133186] Microsoft Windows up to Server 2019 TCP/IP Stack Fragmented IP Packet information disclosure
3829| [133185] Microsoft Windows up to Server 2019 Win32k memory corruption
3830| [133183] Microsoft Windows up to Server 2019 Win32k memory corruption
3831| [133182] Microsoft Windows up to Server 2019 Win32k memory corruption
3832| [133181] Microsoft Office/Excel/PowerPoint up to 2019 URL Document Code Execution
3833| [133180] Microsoft Windows up to Server 2019 MS XML Code Execution
3834| [133179] Microsoft Windows up to Server 2019 MS XML Code Execution
3835| [133177] Microsoft Windows up to Server 2019 Device Guard luafv.sys privilege escalation
3836| [133174] Microsoft Windows up to Server 2019 GDI+ privilege escalation
3837| [133173] Microsoft Windows up to Server 2019 IOleCvt Interface privilege escalation
3838| [133166] Microsoft Windows up to Server 2019 MS XML Code Execution
3839| [133165] Microsoft Windows up to Server 2019 MS XML Code Execution
3840| [133164] Microsoft Windows up to Server 2019 MS XML Code Execution
3841| [133163] Microsoft Windows up to Server 2019 MS XML Code Execution
3842| [133162] Microsoft Windows up to Server 2019 MS XML Code Execution
3843| [131687] Microsoft Team Foundation Server 2017 Update 3.1/2018 Update 3.2/2018 Updated 1.2 cross site scripting
3844| [131685] Microsoft Windows up to Server 2019 SMB information disclosure
3845| [131684] Microsoft Visual Studio 2017 Version 15.9 C++ Redistributable Installer privilege escalation
3846| [131681] Microsoft Windows up to Server 2019 Win32k memory corruption
3847| [131679] Microsoft Windows up to Server 2019 Kernel information disclosure
3848| [131675] Microsoft SharePoint 2013 SP1/2016 cross site scripting
3849| [131674] Microsoft Windows up to Server 2019 Win32k information disclosure
3850| [131673] Microsoft Windows up to Server 2019 Kernel information disclosure
3851| [131672] Microsoft Windows up to Server 2019 GDI information disclosure
3852| [131671] Microsoft Windows up to Server 2019 VBScript Engine memory corruption
3853| [131668] Microsoft Windows up to Server 2019 AppX Deployment Server privilege escalation
3854| [131667] Microsoft Windows up to Server 2019 Comctl32.dll memory corruption
3855| [131663] Microsoft Windows up to Server 2019 Print Spooler information disclosure
3856| [131658] Microsoft Windows up to Server 2019 information disclosure
3857| [131657] Microsoft Windows up to Server 2019 denial of service
3858| [131656] Microsoft Office 2010 SP2 Connectivity Engine memory corruption
3859| [131653] Microsoft Windows up to Server 2019 SMB information disclosure
3860| [131652] Microsoft Windows up to Server 2019 SMB information disclosure
3861| [131651] Microsoft Windows up to Server 2019 Kernel information disclosure
3862| [131650] Microsoft Windows 10 1803/10 1809/Server 1803/Server 2019 Hyper-V denial of service
3863| [131649] Microsoft Windows up to Server 2019 Kernel memory corruption
3864| [131648] Microsoft Windows up to Server 2019 Hyper-V denial of service
3865| [131644] Microsoft Windows up to Server 2019 Hyper-V denial of service
3866| [131638] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3867| [131632] Microsoft Windows 10 1803/10 1809/Server 1803/Server 2019 DHCP Client memory corruption
3868| [131631] Microsoft Windows 10 1803/10 1809/Server 1803/Server 2019 DHCP Client memory corruption
3869| [131630] Microsoft Windows 10 1803/10 1809/Server 1803/Server 2019 DHCP Client memory corruption
3870| [131629] Microsoft Windows up to Server 2019 Deployment Services TFTP Server memory corruption
3871| [131628] Microsoft Windows up to Server 2019 ActiveX memory corruption
3872| [131619] Microsoft Windows up to Server 2019 MS XML privilege escalation
3873| [131334] Microsoft Team Foundation Server 2018 Update 3.2 cross site scripting
3874| [131333] Microsoft Team Foundation Server 2018 Update 3.2 cross site scripting
3875| [131328] Microsoft Windows up to Server 2016 Kernel information disclosure
3876| [130832] Microsoft 2013 SP1 spoofing
3877| [130828] Microsoft Exchange Server 2010 SP3/2013 CU22/2016 CU12/2019 CU1 EWS privilege escalation
3878| [130826] Microsoft Office 2010 SP2 Connectivity Engine memory corruption
3879| [130825] Microsoft Office up to 2019 Connectivity Engine memory corruption
3880| [130824] Microsoft Office up to 2019 Connectivity Engine memory corruption
3881| [130823] Microsoft Office up to 2019 Connectivity Engine privilege escalation
3882| [130822] Microsoft Office up to 2019 Connectivity Engine privilege escalation
3883| [130821] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
3884| [130820] Microsoft Windows up to Server 2012 R2 GDI information disclosure
3885| [130818] Microsoft Windows up to Server 2019 GDI information disclosure
3886| [130817] Microsoft Windows up to Server 2019 Storage Service privilege escalation
3887| [130814] Microsoft Windows up to Server 2019 privilege escalation
3888| [130809] Microsoft Windows up to Server 2019 Defender Firewall Security privilege escalation
3889| [130808] Microsoft Windows up to Server 2019 information disclosure
3890| [130807] Microsoft Windows up to Server 2019 Hyper-V information disclosure
3891| [130806] Microsoft Windows up to Server 2019 SMB privilege escalation
3892| [130805] Microsoft Windows up to Server 2019 Device Guard privilege escalation
3893| [130804] Microsoft Windows up to Server 2019 Device Guard privilege escalation
3894| [130803] Microsoft Windows up to Server 2019 SMB privilege escalation
3895| [130802] Microsoft Windows up to Server 2019 Win32k information disclosure
3896| [130801] Microsoft Windows up to Server 2019 Device Guard privilege escalation
3897| [130800] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3898| [130799] Microsoft Windows up to Server 2016 Win32k memory corruption
3899| [130798] Microsoft Windows up to Server 2019 GDI information disclosure
3900| [130797] Microsoft Windows up to Server 2019 GDI information disclosure
3901| [130796] Microsoft Windows up to Server 2019 GDI information disclosure
3902| [130793] Microsoft Windows up to Server 2019 GDI information disclosure
3903| [130792] Microsoft Windows up to Server 2019 HID information disclosure
3904| [130791] Microsoft Windows up to Server 2019 HID information disclosure
3905| [130790] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3906| [130789] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3907| [130788] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3908| [130787] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3909| [130786] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3910| [130784] Microsoft Windows up to Server 2019 GDI+ memory corruption
3911| [130782] Microsoft Windows up to Server 2019 DHCP Server memory corruption
3912| [130781] Microsoft Windows up to Server 2019 GDI+ memory corruption
3913| [129847] Microsoft Team Foundation Server 2017 Update 3.1/2018 Update 1.2/2018 Update 3.2 information disclosure
3914| [129846] Microsoft Team Foundation Server 2018 Update 3.2 cross site scripting
3915| [129845] Microsoft Skype for Business 2015 CU 8 Request cross site scripting
3916| [128765] Microsoft Visual Studio 2017 Version 15.9 C++ Construct privilege escalation
3917| [128764] Microsoft Exchange Server 2010 SP3/2013 CU21/2016 CU10/2016 CU11/2019 PowerShell API information disclosure
3918| [128761] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
3919| [128760] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
3920| [128759] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
3921| [128758] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
3922| [128757] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
3923| [128756] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
3924| [128755] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
3925| [128754] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
3926| [128753] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
3927| [128752] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
3928| [128751] Microsoft Windows up to Server 2019 Data Sharing Service privilege escalation
3929| [128750] Microsoft Windows up to Server 2019 Runtime privilege escalation
3930| [128749] Microsoft Windows up to Server 2019 Kernel information disclosure
3931| [128747] Microsoft ASP.NET Core 2.1 Web Request denial of service
3932| [128746] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site scripting
3933| [128745] Microsoft Office up to 2019 Word Macro information disclosure
3934| [128742] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site scripting
3935| [128741] Microsoft SharePoint Enterprise Server 2016 cross site scripting
3936| [128740] Microsoft SharePoint Enterprise Server 2013 SP1 cross site scripting
3937| [128739] Microsoft Windows up to Server 2019 Kernel information disclosure
3938| [128738] Microsoft Windows up to Server 2019 Subsystem for Linux information disclosure
3939| [128737] Microsoft Windows up to Server 2019 COM Desktop Broker privilege escalation
3940| [128736] Microsoft Windows up to Server 2019 Kernel information disclosure
3941| [128735] Microsoft ASP.NET Core 2.1/2.2 Web Request denial of service
3942| [128733] Microsoft Windows up to Server 2019 Authentication Request privilege escalation
3943| [128729] Microsoft Visual Studio 2010 SP1/2012 Update 5 vscontent File information disclosure
3944| [128728] Microsoft Windows up to Server 2019 Kernel information disclosure
3945| [128727] Microsoft Windows up to Server 2019 Data Sharing Service privilege escalation
3946| [128726] Microsoft Windows up to Server 2019 Data Sharing Service privilege escalation
3947| [128725] Microsoft Windows up to Server 2019 Data Sharing Service privilege escalation
3948| [128718] Microsoft Windows up to Server 2019 Hyper-V memory corruption
3949| [128717] Microsoft Windows 10 1803/10 1809/Server 1803/Server 2019 Hyper-V memory corruption
3950| [127925] Microsoft SharePoint Enterprise Server 2016 Web Request cross site scripting
3951| [127882] Microsoft Dynamics NAV 2016/2017 Web Request cross site scripting
3952| [127881] Microsoft Windows 10 1809/Server 2019 Object denial of service
3953| [127880] Microsoft Windows up to Server 2019 Win32k Object memory corruption
3954| [127828] Microsoft Windows up to Server 2019 Win32k memory corruption
3955| [127827] Microsoft Windows 10 1809/Server 2019 DirectX information disclosure
3956| [127826] Microsoft Windows 10 1803/10 1809/Server 1803/Server 2019 Win32k ASLR privilege escalation
3957| [127825] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016 privilege escalation
3958| [127824] Microsoft Excel up to 2019 Out-of-Bounds memory corruption
3959| [127823] Microsoft Windows up to Server 2012 R2 Kernel information disclosure
3960| [127821] Microsoft Windows up to Server 2019 Connected User Experiences and Telemetry Service denial of service
3961| [127820] Microsoft Windows up to Server 2019 Kernel memory corruption
3962| [127819] Microsoft Exchange Server 2016 CU10/2016 CU11 Profile Data privilege escalation
3963| [127817] Microsoft Excel up to 2019 information disclosure
3964| [127816] Microsoft Windows up to Server 2019 GDI information disclosure
3965| [127815] Microsoft Windows up to Server 2019 GDI information disclosure
3966| [127814] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016 Search cross site request forgery
3967| [127812] Microsoft Windows up to Server 2019 Remote Procedure Call information disclosure
3968| [127806] Microsoft Outlook up to 2019 memory corruption
3969| [127805] Microsoft Excel up to 2019 memory corruption
3970| [127804] Microsoft Excel up to 2019 memory corruption
3971| [127803] Microsoft Windows up to Server 2019 Text-To-Speech memory corruption
3972| [127801] Microsoft Windows up to Server 2019 DNS Server privilege escalation
3973| [126938] Microsoft Team Foundation Server 2018 Update 1.1/2018 Update 3 Code Execution
3974| [126755] Microsoft .NET Core 2.1 privilege escalation
3975| [126754] Microsoft Skype for Business/Lync Server 2013 SP1/2016 Emoji denial of service
3976| [126750] Microsoft Windows up to Server 2019 ALPC privilege escalation
3977| [126749] Microsoft Exchange Server 2010/2013/2016/2019 privilege escalation
3978| [126747] Microsoft SharePoint Enterprise Server 2013 SP1 Folder information disclosure
3979| [126746] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
3980| [126745] Microsoft Project 2010 SP2/2013 SP1/2016 memory corruption
3981| [126744] Microsoft Office up to 2019 Word memory corruption
3982| [126743] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site scripting
3983| [126742] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site scripting
3984| [126739] Microsoft Windows up to Server 2012 R2 Win32k information disclosure
3985| [126737] Microsoft Windows up to Server 2012 R2 DirectX information disclosure
3986| [126736] Microsoft Windows up to Server 2019 Win32k memory corruption
3987| [126735] Microsoft Windows up to Server 2019 DirectX privilege escalation
3988| [126733] Microsoft Windows 10 1803/10 1809/Server 1803/Server 2019 DirectX memory corruption
3989| [126730] Microsoft Windows up to Server 2019 Active Directory Federation Services cross site scripting
3990| [126728] Microsoft Office/SharePoint 2010 SP2 Word memory corruption
3991| [126727] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
3992| [126726] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
3993| [126725] Microsoft Windows up to Server 2019 DirectX memory corruption
3994| [126722] Microsoft Windows up to Server 2019 PowerShell privilege escalation
3995| [126718] Microsoft Windows up to Server 2016 Search memory corruption
3996| [126717] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016/2019 memory corruption
3997| [126716] Microsoft Office up to 2019 Excel memory corruption
3998| [126714] Microsoft Windows up to Server 2019 PowerShell unknown vulnerability
3999| [126713] Microsoft Windows up to Server 2019 VBScript Engine memory corruption
4000| [126712] Microsoft Windows up to Server 2016 Graphics Component memory corruption
4001| [126711] Microsoft Windows up to Server 2019 Deployment Services TFTP Server memory corruption
4002| [125123] Microsoft Windows up to Server 2019 Codecs Library information disclosure
4003| [125122] Microsoft Windows up to Server 2016 TCP/IP information disclosure
4004| [125121] Microsoft Windows up to Server 2019 DirectX memory corruption
4005| [125120] Microsoft Windows up to Server 2019 Windows Media Player information disclosure
4006| [125119] Microsoft Windows up to Server 2019 Windows Media Player information disclosure
4007| [125116] Microsoft Exchange Server 2013 CU21/2016 CU10 privilege escalation
4008| [125115] Microsoft Windows up to Server 2019 Theme API privilege escalation
4009| [125114] Microsoft Windows up to Server 2019 Windows Shell privilege escalation
4010| [125113] Microsoft Windows up to Server 2019 Kernel memory corruption
4011| [125111] Microsoft Windows up to Server 2019 Device Guard Code Integrity Policy privilege escalation
4012| [125110] Microsoft Windows up to Server 2019 DNS Global Blocklist privilege escalation
4013| [125109] Microsoft Windows up to Server 2019 NTFS privilege escalation
4014| [125108] Microsoft Windows up to Server 2019 Filter Manager memory corruption
4015| [125107] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
4016| [125106] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
4017| [125105] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
4018| [125104] Microsoft SharePoint Enterprise Server 2016 cross site scripting
4019| [125102] Microsoft Office/Word 2010 SP2/2013 RT SP1/2013 SP1/2016/2019 Protected View memory corruption
4020| [125100] Microsoft Office/PowerPoint 2010 SP2/2013 RT SP1/2013 SP1/2016/2019 Protected View memory corruption
4021| [125099] Microsoft Office/Excel up to 2019 Protected View memory corruption
4022| [125098] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
4023| [125097] Microsoft Windows up to Server 2019 DirectX Graphics memory corruption
4024| [125096] Microsoft Windows up to Server 2019 Win32k memory corruption
4025| [125095] Microsoft Exchange Server 2013 CU21/2016 CU10 Outlook Web Access cross site scripting
4026| [125093] Microsoft Windows up to Server 2019 Hyper-V memory corruption
4027| [125092] Microsoft Windows up to Server 2019 Hyper-V memory corruption
4028| [125091] Microsoft Windows up to Server 2019 MS XML privilege escalation
4029| [124371] Microsoft Exchange Server up to 2010 SP3 Outlook Web Access /owa/auth/logon.aspx Parameter Server-Side Request Forgery
4030| [124217] Microsoft Windows Server 2012/Server 2016 Active Directory Federation Services /adfs/ls Server-Side Request Forgery
4031| [123995] Microsoft Lync 2011 on Mac Security Feature Messages Download privilege escalation
4032| [123881] Microsoft Windows up to Server 2016 Sandbox privilege escalation
4033| [123874] Microsoft Windows up to Server 2016 Kernel information disclosure
4034| [123872] Microsoft Windows 8.1/10/RT 8.1/Server 2012/Server 2012 R2 SMB information disclosure
4035| [123868] Microsoft Windows up to Server 2016 Hyper-V denial of service
4036| [123864] Microsoft Windows up to Server 2016 Hyper-V information disclosure
4037| [123862] Microsoft SharePoint Enterprise Server 2010 SP2/2013 RT SP1/2013 SP1/2016 cross site scripting
4038| [123861] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R information disclosure
4039| [123860] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
4040| [123859] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016 cross site scripting
4041| [123851] Microsoft Windows up to Server 2016 ALPC privilege escalation
4042| [123849] Microsoft Windows up to Server 2016 SMB denial of service
4043| [123846] Microsoft Office 2016 on Win/Mac memory corruption
4044| [123844] Microsoft Word 2013 RT SP1/2013 SP1/2016 PDF File memory corruption
4045| [123843] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
4046| [123842] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
4047| [123830] Microsoft Windows up to Server 2016 Hyper-V memory corruption
4048| [123828] Microsoft Windows up to Server 2016 Win32k Graphics privilege escalation
4049| [123827] Microsoft Windows up to Server 2016 Image memory corruption
4050| [123825] Microsoft Windows up to Server 2016 MSXML Parser privilege escalation
4051| [123823] Microsoft Windows up to Server 2016 Hyper-V privilege escalation
4052| [122887] Microsoft Office 2016 on Mac AutoUpdate memory corruption
4053| [122886] Microsoft Windows up to Server 2016 DirectX Graphics memory corruption
4054| [122885] Microsoft Windows up to Server 2016 DirectX Graphics memory corruption
4055| [122884] Microsoft Windows up to Server 2016 Win32k memory corruption
4056| [122883] Microsoft Windows up to Server 2016 DirectX Graphics memory corruption
4057| [122875] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R information disclosure
4058| [122874] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
4059| [122873] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R information disclosure
4060| [122871] Microsoft PowerPoint 2010 SP2 memory corruption
4061| [122870] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
4062| [122861] Microsoft Windows up to Server 2016 Microsoft COM for Windows privilege escalation
4063| [122850] Microsoft Visual Studio 2015 Update 3/2017/2017 Version 15.8 Diagnostic Hub privilege escalation
4064| [122849] Microsoft Windows up to Server 2016 Diagnostic Hub privilege escalation
4065| [122848] Microsoft Windows Security Feature 2FA weak authentication
4066| [122834] Microsoft Windows up to Server 2016 LNK memory corruption
4067| [122825] Microsoft Windows up to Server 2016 Graphics memory corruption
4068| [122823] Microsoft SQL Server 2016 SP1/2016 SP2/2017 memory corruption
4069| [121208] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R Attachment privilege escalation
4070| [121118] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
4071| [121116] Microsoft Windows up to Server 2016 Sandbox privilege escalation
4072| [121114] Microsoft Access 2013 SP1/2016/2016 C2R memory corruption
4073| [121111] Microsoft Windows up to Server 2016 Kernel memory corruption
4074| [121110] Microsoft Windows up to Server 2016 Wordpad privilege escalation
4075| [121107] Microsoft Windows up to Server 2016 DNSAPI DNSAPI.dll denial of service
4076| [121106] Microsoft SharePoint Enterprise Server 2013 SP1/2016 privilege escalation
4077| [121105] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
4078| [121098] Microsoft Office 2016/2016 C2R memory corruption
4079| [121092] Microsoft Windows up to Server 2016 FTP Server denial of service
4080| [121090] Microsoft Visual Studio up to 2017 Version 15.8 Preview privilege escalation
4081| [119479] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
4082| [119477] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016 information disclosure
4083| [119476] Microsoft Publisher 2010 SP2 OLE Object PUB File privilege escalation
4084| [119475] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016 Attachment privilege escalation
4085| [119474] Microsoft Windows up to Server 2016 GDI information disclosure
4086| [119470] Microsoft Windows up to Server 2016 HTTP HTTP.sys denial of service
4087| [119468] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
4088| [119467] Microsoft Windows up to Server 2016 Hypervisor privilege escalation
4089| [119465] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
4090| [119464] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
4091| [119463] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
4092| [119461] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
4093| [119460] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
4094| [119459] Microsoft Windows up to Server 2016 memory corruption
4095| [119457] Microsoft Windows up to Server 2016 Desktop Bridge privilege escalation
4096| [119456] Microsoft Windows up to Server 2016 Kernel information disclosure
4097| [119455] Microsoft Windows up to Server 2016 denial of service
4098| [119454] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
4099| [119452] Microsoft Windows up to Server 2016 HIDParser memory corruption
4100| [119448] Microsoft Windows up to Server 2016 Code Integrity Module denial of service
4101| [119447] Microsoft Windows up to Server 2016 NTFS privilege escalation
4102| [119441] Microsoft Windows up to Server 2016 Media Foundation memory corruption
4103| [119437] Microsoft Windows up to Server 2016 HTTP Protocol Stack Http.sys memory corruption
4104| [119436] Microsoft Windows up to Server 2016 memory corruption
4105| [119431] Microsoft Windows up to Server 2016 DNSAPI DNSAPI.dll DNS Response privilege escalation
4106| [118120] Microsoft Office 2016 on Mac XML Data Code Execution
4107| [117561] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1 Web Request cross site scripting
4108| [117560] Microsoft Exchange Server up to 2016 CU9 Code Execution memory corruption
4109| [117559] Microsoft Exchange Server 2016 CU8/2016 CU9 Outlook Web Access Web Request cross site scripting
4110| [117558] Microsoft Windows up to Server 2016 Code Execution memory corruption
4111| [117507] Microsoft Infopath 2013 SP1 memory corruption
4112| [117505] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R information disclosure
4113| [117504] Microsoft Office 2010 SP2 information disclosure
4114| [117503] Microsoft Exchange Server 2013 CU19/2013 CU20/2016 CU8/2016 CU9 Outlook Web Access cross site scripting
4115| [117502] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016 cross site scripting
4116| [117501] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
4117| [117500] Microsoft Exchange Server 2016 CU8/2016 CU9 Outlook Web Access cross site scripting
4118| [117499] Microsoft Exchange Server up to 2016 CU9 information disclosure
4119| [117498] Microsoft Office 2016 C2R Security Feature privilege escalation
4120| [117497] Microsoft SharePoint Enterprise Server 2010/2013 SP1/2016 cross site scripting
4121| [117480] Microsoft Windows up to Server 2016 COM Serialized privilege escalation
4122| [117473] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
4123| [117472] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
4124| [117471] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
4125| [117470] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
4126| [117469] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
4127| [117468] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
4128| [117444] Microsoft Windows up to Server 2016 Hyper-V vSMB memory corruption
4129| [117443] Microsoft Windows up to Server 2016 Hyper-V memory corruption
4130| [117442] Microsoft Windows up to Server 2016 VBScript Engine memory corruption
4131| [116132] Microsoft Office 2016 Memory information disclosure
4132| [116051] Microsoft SharePoint Enterprise Server 2016 cross site scripting
4133| [116050] Microsoft SharePoint Enterprise Server 2010 SP2/2013/2016 cross site scripting
4134| [116049] Microsoft SharePoint Enterprise Server 2013/2016 privilege escalation
4135| [116048] Microsoft Windows up to Server 2016 DirectX Graphics Kernel Subsystem memory corruption
4136| [116047] Microsoft Windows up to Server 2016 OpenType Font Driver atmfd.dll memory corruption
4137| [116046] Microsoft SharePoint Enterprise Server 2013/2016 Share cross site scripting
4138| [116045] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
4139| [116039] Microsoft Windows up to Server 2016 Remote Desktop Protocol denial of service
4140| [116031] Microsoft Windows up to Server 2016 Kernel ASLR information disclosure
4141| [116030] Microsoft Windows up to Server 2016 SNMP Service denial of service
4142| [116026] Microsoft Windows up to Server 2016 Kernel information disclosure
4143| [116024] Microsoft Windows up to Server 2016 HTTP.sys denial of service
4144| [116023] Microsoft Office up to 2016 C2R information disclosure
4145| [116022] Microsoft Excel 2010 SP2 memory corruption
4146| [116020] Microsoft Windows 10 1607/10 1703/10 1709/Server 1709/Server 2016 Active Directory privilege escalation
4147| [116019] Microsoft Windows up to Server 2016 Kernel information disclosure
4148| [116018] Microsoft Office 2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
4149| [116017] Microsoft Excel up to 2016 C2R memory corruption
4150| [116016] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 Graphics memory corruption
4151| [116014] Microsoft Office 2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
4152| [116013] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1 memory corruption
4153| [116008] Microsoft Windows up to Server 2016 Graphics memory corruption
4154| [116007] Microsoft Windows up to Server 2016 Graphics memory corruption
4155| [116006] Microsoft Windows up to Server 2016 Graphics memory corruption
4156| [116005] Microsoft Windows up to Server 2016 Graphics memory corruption
4157| [116004] Microsoft Windows up to Server 2016 Graphics memory corruption
4158| [116003] Microsoft Windows up to Server 2016 VBScript Engine memory corruption
4159| [115994] Microsoft Windows up to Server 2016 Malware Protection Engine memory corruption
4160| [115804] Microsoft Windows up to Server 2016 Malware Protection Engine privilege escalation
4161| [114579] Microsoft Exchange Server up to 2017 CU8 Outlook Web Access information disclosure
4162| [114574] Microsoft SharePoint Enterprise Server 2016 privilege escalation
4163| [114573] Microsoft SharePoint Enterprise Server 2016 cross site scripting
4164| [114571] Microsoft Exchange Server 2016 CU7/2016 CU8 Outlook Web Access information disclosure
4165| [114570] Microsoft Exchange Server 2010 SP3/2013 CU18/2013 CU19/2016 CU7/2016 CU8 Outlook Web Access Fake privilege escalation
4166| [114565] Microsoft Windows 10 1607/10 1703/10 1709/Server 1709/Server 2016 Kernel information disclosure
4167| [114564] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
4168| [114562] Microsoft SharePoint Enterprise Server 2016 cross site scripting
4169| [114560] Microsoft SharePoint Enterprise Server 2016 cross site scripting
4170| [114559] Microsoft SharePoint Enterprise Server 2016 cross site scripting
4171| [114558] Microsoft SharePoint Enterprise Server 2016 cross site scripting
4172| [114557] Microsoft SharePoint Enterprise Server 2016 cross site scripting
4173| [114556] Microsoft SharePoint Enterprise Server 2016 cross site scripting
4174| [114555] Microsoft SharePoint Enterprise Server 2016 cross site scripting
4175| [114554] Microsoft SharePoint Enterprise Server 2016 cross site scripting
4176| [114553] Microsoft SharePoint Enterprise Server 2016 cross site scripting
4177| [114552] Microsoft SharePoint Enterprise Server 2016 cross site scripting
4178| [114551] Microsoft Excel up to 2016 C2R Security Feature privilege escalation
4179| [114549] Microsoft Access 2010 SP2/2013 SP1/2016 memory corruption
4180| [114548] Microsoft Windows up to Server 2016 CNG Security Feature cng.sys privilege escalation
4181| [114547] Microsoft Windows up to Server 2016 Kernel information disclosure
4182| [114546] Microsoft Windows up to Server 2016 Kernel information disclosure
4183| [114545] Microsoft Windows up to Server 2016 Kernel information disclosure
4184| [114544] Microsoft Windows up to Server 2016 Kernel information disclosure
4185| [114543] Microsoft Windows up to Server 2016 Kernel information disclosure
4186| [114542] Microsoft Windows up to Server 2016 Kernel information disclosure
4187| [114541] Microsoft Windows up to Server 2016 Kernel information disclosure
4188| [114540] Microsoft Windows up to Server 2016 Kernel information disclosure
4189| [114536] Microsoft Windows up to Server 2016 CredSSP privilege escalation
4190| [114535] Microsoft Windows up to Server 2016 Hyper-V denial of service
4191| [114531] Microsoft Windows up to Server 2016 Windows Installer privilege escalation
4192| [114530] Microsoft Windows up to Server 2016 GDI privilege escalation
4193| [114529] Microsoft Windows up to Server 2016 GDI privilege escalation
4194| [114527] Microsoft Windows up to Server 2016 Kernel information disclosure
4195| [114526] Microsoft Windows up to Server 2016 Kernel information disclosure
4196| [114525] Microsoft Windows up to Server 2016 Kernel information disclosure
4197| [114522] Microsoft Windows 10 1607/10 1703/Server 2016 Desktop Bridge privilege escalation
4198| [114521] Microsoft Windows up to Server 2016 Video Control privilege escalation
4199| [114520] Microsoft Windows 10/Server 1709/Server 2016 Desktop Bridge privilege escalation
4200| [114518] Microsoft Windows up to Server 2016 Remote Assistance information disclosure
4201| [114517] Microsoft Windows 10/Server 1709/Server 2016 Desktop Bridge VFS privilege escalation
4202| [114516] Microsoft Windows up to Server 2016 Windows Shell privilege escalation
4203| [113835] Microsoft Identity Manager 2016 SP1 cross site scripting
4204| [113264] Microsoft Windows 8.1/RT 8.1/Server 2012 R2 SMBv2/SMBv3 denial of service
4205| [113260] Microsoft Windows up to Server 2016 Kernel memory corruption
4206| [113259] Microsoft Windows 10/Server 1709/Server 2016 NTFS privilege escalation
4207| [113254] Microsoft Windows up to Server 2016 Kernel information disclosure
4208| [113253] Microsoft Windows 10/Server 1709/Server 2016 Kernel memory corruption
4209| [113252] Microsoft Windows up to Server 2016 Kernel memory corruption
4210| [113250] Microsoft Windows 10/Server 1709/Server 2016 Kernel memory corruption
4211| [113249] Microsoft Windows up to Server 2016 Kernel memory corruption
4212| [113248] Microsoft Windows up to Server 2016 Kernel information disclosure
4213| [113243] Microsoft Windows 10/Server 2016 MultiPoint Management privilege escalation
4214| [113242] Microsoft Windows up to Server 2016 Common Log File System Driver memory corruption
4215| [113241] Microsoft Windows up to Server 2016 Common Log File System Driver memory corruption
4216| [113240] Microsoft Windows 10/Server 1709/Server 2016 AppContainer privilege escalation
4217| [113237] Microsoft SharePoint Enterprise Server 2016 cross site scripting
4218| [113236] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
4219| [113233] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 Uninitialized Memory information disclosure
4220| [113232] Microsoft Excel 2016 memory corruption
4221| [113230] Microsoft Windows up to Server 2016 Scripting Engine information disclosure
4222| [113229] Microsoft Windows up to Server 2016 StructuredQuery memory corruption
4223| [111580] Microsoft Office 2016 on Mac Email Attachment spoofing
4224| [111571] Microsoft SharePoint Enterprise Server 2013/2016 Access cross site scripting
4225| [111567] Microsoft Office 2010/2013/2016 memory corruption
4226| [111564] Microsoft Word 2016 memory corruption
4227| [111562] Microsoft SharePoint Server 2010/2013/2016 Web Request cross site scripting
4228| [111561] Microsoft SharePoint Server 2010/2013/2016 Web Request cross site scripting
4229| [128730] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
4230| [111358] Microsoft Windows up to Server 2016 IPsec denial of service
4231| [110553] Microsoft Office 2016 C2R information disclosure
4232| [110552] Microsoft SharePoint Enterprise Server 2016 Web Request privilege escalation
4233| [110551] Microsoft Excel 2016 C2R memory corruption
4234| [110550] Microsoft PowerPoint 2013 RT SP1/2013 SP1/2016 information disclosure
4235| [110549] Microsoft Exchange Server 2016 CU6/2016 CU7 Outlook Web Access privilege escalation
4236| [110547] Microsoft Windows up to Server 2016 its:// Protocol information disclosure
4237| [110531] Microsoft Windows 10/Server 2016 Device Guard privilege escalation
4238| [110522] Microsoft Windows up to Server 2016 RRAS privilege escalation
4239| [110350] Microsoft Windows up to Server 2016 Malware Protection Engine memory corruption
4240| [110318] Microsoft Windows up to Server 2016 Malware Protection Engine memory corruption
4241| [109391] Microsoft SharePoint Enterprise Server 2016 Project Server cross site request forgery
4242| [109389] Microsoft Excel 2016 Click-to-Run memory corruption
4243| [109360] Microsoft Windows up to Server 2016 Windows Search denial of service
4244| [107759] Microsoft Windows up to Server 2016 SMB denial of service
4245| [107757] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
4246| [107756] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
4247| [107753] Microsoft Windows 10/Server 2016 SMB privilege escalation
4248| [107744] Microsoft Windows up to Server 2016 DNSAPI DNSAPI.dll DNS Response privilege escalation
4249| [107741] Microsoft Outlook 2016 Secure Connection Mail information disclosure
4250| [107740] Microsoft Windows up to Server 2016 Graphics memory corruption
4251| [107739] Microsoft Windows up to Server 2016 Graphics memory corruption
4252| [107738] Microsoft Windows up to Server 2016 Search information disclosure
4253| [107734] Microsoft Windows 10/Server 2016 SMB privilege escalation
4254| [107732] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016 Bypass privilege escalation
4255| [107730] Microsoft Windows up to Server 2016 Search Remote memory corruption
4256| [107729] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
4257| [107728] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
4258| [107727] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
4259| [107724] Microsoft Windows up to Server 2016 Text Services Framework memory corruption
4260| [107723] Microsoft Windows up to Server 2016 SMB information disclosure
4261| [107698] Microsoft Office 2016 memory corruption
4262| [107593] InFocus Mondopad 2.2.08 Excel Spreadsheet Microsoft Office Document Credentials information disclosure
4263| [106544] Microsoft Exchange Server 2016 Outlook Web Access cross site scripting
4264| [106531] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
4265| [106529] Microsoft PowerPoint 2016 memory corruption
4266| [106523] Microsoft Windows up to Server 2016 PDF Library memory corruption
4267| [106518] Microsoft Edge on Win10/Server 2016 memory corruption
4268| [106516] Microsoft Windows up to Server 2016 PDF Library memory corruption
4269| [106498] Microsoft Windows up to Server 2016 Shell privilege escalation
4270| [106496] Microsoft Windows up to Server 2016 Uniscribe information disclosure
4271| [106495] Microsoft Windows up to Server 2012 R2 Uniscribe memory corruption
4272| [106492] Microsoft Windows Server 2012/Server 2012 R2/Server 2016 DHCP Service memory corruption
4273| [106489] Microsoft Windows up to Server 2016 Graphics Win32k win32k!fsc_CalcGrayRow memory corruption
4274| [106474] Microsoft Office 2016 memory corruption
4275| [106473] Microsoft SharePoint Server 2013 SP1 cross site scripting
4276| [106472] Microsoft Windows up to Server 2016 Bluetooth Driver Object BlueBorne spoofing
4277| [106470] Microsoft Excel 2011 on Mac memory corruption
4278| [106455] Microsoft Exchange Server 2013/2016 information disclosure
4279| [106454] Microsoft Windows up to Server 2016 Windows NetBT Session Services race condition memory corruption
4280| [105048] Microsoft Edge on Win10/Server 2016 Scripting Engine memory corruption
4281| [105047] Microsoft Edge on Win10/Server 2016 Scripting Engine EntryCall memory corruption
4282| [105046] Microsoft Edge on Win10/Server 2016 Javascript Engine memory corruption
4283| [105040] Microsoft Edge on Win10/Server 2016 Scripting Engine memory corruption
4284| [105038] Microsoft Edge on Win10/Server 2016 Javascript Engine Out-of-Bounds memory corruption
4285| [105037] Microsoft Edge on Win10/Server 2016 Javascript Engine PreVisitCatch memory corruption
4286| [105035] Microsoft SharePoint Server 2010 SP2 cross site scripting
4287| [105033] Microsoft Edge 38.14393.1066.0 on Win10/Server 2016 Use-After-Free information disclosure
4288| [105029] Microsoft Edge on Win10/Server 2016 Javascript Engine ProcessLinkFailedAsmJsModule memory corruption
4289| [105027] Microsoft Edge on Win10/Server 2016 _SelectValueInternal information disclosure
4290| [105024] Microsoft Edge on Win10/Server 2016 Javascript Engine memory corruption
4291| [105023] Microsoft Edge on Win10/Server 2016 Javascript Engine memory corruption
4292| [105017] Microsoft Windows up to Server 2016 Error Reporting information disclosure
4293| [105013] Microsoft Windows 10 1607/10 1703/Server 2016 Hyper-V denial of service
4294| [105011] Microsoft Windows up to Server 2016 Windows Search memory corruption
4295| [105010] Microsoft Windows up to Server 2016 Win32k memory corruption
4296| [105009] Microsoft Windows up to Server 2016 Input Method Editor memory corruption
4297| [105008] Microsoft SQL Server 2012/2014/2016 Analysis Services information disclosure
4298| [104990] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
4299| [104989] Microsoft Windows up to Server 2016 NetBIOS denial of service
4300| [104584] Microsoft Outlook up to 2016 C2R Document File privilege escalation
4301| [104583] Microsoft Outlook up to 2016 C2R Email memory corruption
4302| [104582] Microsoft Outlook up to 2016 C2R Object memory corruption
4303| [103468] Microsoft Exchange Server 2010 SP3/2013 CU16/2013 SP3/2016 CU5 Open Redirect
4304| [103446] Microsoft Windows up to Server 2016 Search Object privilege escalation
4305| [103445] Microsoft Windows up to Server 2016 Wordpad privilege escalation
4306| [103444] Microsoft Windows up to Server 2016 Explorer denial of service
4307| [103442] Microsoft Windows 10/Server 2016 HoloLens WiFi Packet privilege escalation
4308| [103441] Microsoft Windows up to Server 2016 Object HTTP.sys information disclosure
4309| [103431] Microsoft Windows up to Server 2016 PowerShell PSObject Object privilege escalation
4310| [103429] Microsoft Windows up to Server 2016 Kerberos weak authentication
4311| [103426] Microsoft Exchange Server 2010 SP3/2013 CU16/2013 SP3/2016 CU5 OWA Request cross site scripting
4312| [103425] Microsoft Exchange Server 2010 SP3/2013 CU16/2013 SP3/2016 CU5 OWA Request cross site scripting
4313| [103420] Microsoft Windows up to Server 2016 Kerberos Bypass privilege escalation
4314| [103417] Microsoft Windows up to Server 2016 Windows Shell privilege escalation
4315| [102544] Microsoft Edge on Win10/Server 2016 Fetch API information disclosure
4316| [102543] Microsoft Edge on Win10/Server 2016 Javascript XML DOM Object information disclosure
4317| [102463] Microsoft Project Server 2013 SP1 cross site scripting
4318| [102460] Microsoft Outlook 2016 on Mac HTML spoofing
4319| [102448] Microsoft SharePoint Enterprise Server 2016 Reflected cross site scripting
4320| [102446] Microsoft Office up to 2016 privilege escalation
4321| [102445] Microsoft Office 2010 SP2/2011/2013 RT SP1/2013 SP1/2016 privilege escalation
4322| [102443] Microsoft Office up to 2016 privilege escalation
4323| [102412] Microsoft Windows up to Server 2016 PDF information disclosure
4324| [102397] Microsoft Outlook 2010 SP1/2013 SP1/2016 DLL Loader privilege escalation
4325| [102396] Microsoft Office 2013 SP1/2016 DLL Loader privilege escalation
4326| [102386] Microsoft Windows up to Server 2012 R2 Uniscribe privilege escalation
4327| [102385] Microsoft Windows up to Server 2016 Font Library privilege escalation
4328| [102376] Microsoft Windows up to Server 2016 CAB File privilege escalation
4329| [102375] Microsoft Windows up to Server 2016 PDF Parser privilege escalation
4330| [102374] Microsoft Windows up to Server 2016 PDF Parser privilege escalation
4331| [102373] Microsoft Windows up to Server 2016 Uniscribe Font USP10!MergeLigRecords memory corruption
4332| [101817] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
4333| [101816] Microsoft Windows up to Server 2016 Malware Protection Engine setCaller memory corruption
4334| [101815] Microsoft Windows up to Server 2016 Malware Protection Engine Use-After-Free memory corruption
4335| [101814] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
4336| [101813] Microsoft Windows up to Server 2016 Malware Protection Engine memory corruption
4337| [101812] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
4338| [101811] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
4339| [101810] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
4340| [101028] Microsoft Windows 10/Server 2016 Hyper-V vSMB privilege escalation
4341| [101020] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
4342| [101019] Microsoft Skype for Business 2016 memory corruption
4343| [101018] Microsoft SharePoint 2010 SP2/2013 SP1/2016 memory corruption
4344| [101016] Microsoft PowerPoint 2011 on Mac memory corruption
4345| [101015] Microsoft PowerPoint 2011 on Mac memory corruption
4346| [101014] Microsoft Office 2010 SP2/2016 memory corruption
4347| [101013] Microsoft Office 2010 SP2/2016 memory corruption
4348| [101002] Microsoft Windows up to Server 2016 SMBv1 Server memory corruption
4349| [101001] Microsoft Windows up to Server 2016 SMBv1 Server memory corruption
4350| [101000] Microsoft Windows up to Server 2016 SMBv1 Server memory corruption
4351| [100999] Microsoft Windows up to Server 2016 SMBv1 Server memory corruption
4352| [100918] Microsoft Windows 8/8.1/10/Server 2012/Server 2016 Malware Protection Service Type Confusion privilege escalation
4353| [99697] Microsoft SharePoint Server 2010 SP1/2010 SP2 Excel Services cross site scripting
4354| [99683] Microsoft Windows 10 1607/10 1703/Server 2012 R2/Server 2016 Active Directory Lockout privilege escalation
4355| [99682] Microsoft Outlook 2011 on Mac HTML Tag Validator spoofing
4356| [99681] Microsoft Windows up to Server 2016 OLE Integrity-Level Check privilege escalation
4357| [99667] Microsoft Windows 10/Server 2016 Active Directory Service Unresponsive denial of service
4358| [98272] Microsoft Windows up to 10/Server 2016 Local Session privilege escalation
4359| [98096] Microsoft Exchange 2013 SP1 privilege escalation
4360| [98095] Microsoft Lync for Mac 2011 Certificate Validation weak authentication
4361| [98094] Microsoft SharePoint Server 2013 SP1 cross site scripting
4362| [98093] Microsoft SharePoint Server/Office Web Apps 2010 SP2 memory corruption
4363| [98091] Microsoft SharePoint Server/Office Web Apps 2010 SP2 memory corruption
4364| [98090] Microsoft SharePoint Server 2010 SP2/2013 SP1 information disclosure
4365| [98089] Microsoft Office Web Apps 2013 SP1 memory corruption
4366| [98082] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 denial of service
4367| [98081] Microsoft Excel up to 2016 information disclosure
4368| [98080] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
4369| [98079] Microsoft Word 2016 memory corruption
4370| [98076] Microsoft Lync/Skype for Business 2010/2013/2016 Graphics Component privilege escalation
4371| [98075] Microsoft Lync/Skype for Business 2010/2013/2016 GDI+ information disclosure
4372| [98074] Microsoft Lync/Skype for Business 2010/2013/2016 GDI+ information disclosure
4373| [98073] Microsoft Office 2010 SP2/Word Viewer Graphics Component information disclosure
4374| [98069] Microsoft Windows up to Server 2012 R2 Color Management memory corruption
4375| [98056] Microsoft Windows up to Server 2016 DNS Query information disclosure
4376| [98054] Microsoft Windows up to Server 2016 SMBv2/SMBv3 NULL Pointer Dereference memory corruption
4377| [98017] Microsoft Windows up to Server 2016 PDF memory corruption
4378| [98015] Microsoft Windows 10/Server 2016 Hyper-V denial of service
4379| [98013] Microsoft Windows 10/Server 2016 Hyper-V vSMB memory corruption
4380| [98007] Microsoft Windows 10/Server 2016 Hyper-V Network Switch denial of service
4381| [98006] Microsoft Windows 10/Server 2016 Hyper-V vSMB memory corruption
4382| [96521] Microsoft Windows 8.1/10/Server 2012/Server 2016 SMB Response mrxsmb20.sys denial of service
4383| [95781] Microsoft PowerPoint 2016 Java Embedded Object privilege escalation
4384| [95125] Microsoft Word/SharePoint Enterprise Server 2016 Document privilege escalation
4385| [94451] Microsoft Office 2011 memory corruption
4386| [94447] Microsoft Office 2010 SP2 memory corruption
4387| [94446] Microsoft Office 2016 memory corruption
4388| [94444] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 OLE DLL Loader memory corruption
4389| [94443] Microsoft Office up to 2016 information disclosure
4390| [94442] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 privilege escalation
4391| [93964] Microsoft Windows 7 Excel Starter 2010 XXE information disclosure
4392| [93543] Microsoft SQL Server 2016 FILESTREAM Path privilege escalation
4393| [93540] Microsoft Excel 2010 SP2/2011/2016 memory corruption
4394| [93416] Microsoft SQL Server 2014 SP2/2016/up to 2012 SP3 Server Agent atxcore.dll privilege escalation
4395| [93415] Microsoft SQL Server 2016 MDS API cross site scripting
4396| [93414] Microsoft SQL Server up to 2012 SP3 RDBMS Engine privilege escalation
4397| [93413] Microsoft SQL Server 2016/up to 2014 SP2 RDBMS Engine privilege escalation
4398| [93412] Microsoft SQL Server 2016 RDBMS Engine privilege escalation
4399| [93393] Microsoft Office up to 2016 memory corruption
4400| [93392] Microsoft Office up to 2016 memory corruption
4401| [93391] Microsoft Office up to 2016 memory corruption
4402| [93389] Microsoft Windows up to Server 2016 Media Foundation memory corruption
4403| [93388] Microsoft Windows up to Server 2016 Animation Manager Stylesheets memory corruption
4404| [92587] Microsoft Windows 8.1/10/RT 8.1/Server 2012/Server 2012 R2 Transaction Manager privilege escalation
4405| [92584] Microsoft Office up to 2016 memory corruption
4406| [91571] Microsoft Windows 8.1/10/RT 8.1/Server 2012/Server 2012 R2 PDF Library information disclosure
4407| [91570] Microsoft Windows 8.1/10/RT 8.1/Server 2012/Server 2012 R2 PDF Library information disclosure
4408| [91556] Microsoft Exchange 2016 Meeting Invation cross site scripting
4409| [91555] Microsoft Exchange 2013/2016 Link spoofing
4410| [91550] Microsoft Office 2016 memory corruption
4411| [91547] Microsoft Office 2010 memory corruption
4412| [91543] Microsoft Office up to 2016 memory corruption
4413| [91541] Microsoft Office 2013/2016 APP-V ASLR privilege escalation
4414| [90711] Microsoft Windows 8.1/10/RT 8.1/Server 2012/Server 2012 R2 PDF privilege escalation
4415| [90710] Microsoft Windows 8.1/RT 8.1/Server 2012/Server 2012 R2 Netlogon privilege escalation
4416| [90704] Microsoft Office 2013/2013 RT/2016 memory corruption
4417| [89043] Microsoft Office up to 2016 memory corruption
4418| [89041] Microsoft Office up to 2016 memory corruption
4419| [89040] Microsoft Office 2010 SP2/2011/2013 RT SP1/2013 SP1/2016 memory corruption
4420| [89038] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 Security Feature privilege escalation
4421| [89037] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
4422| [87961] Microsoft Windows up to Server 2012 R2 Search denial of service
4423| [87959] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 PDF information disclosure
4424| [87958] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 PDF memory corruption
4425| [87957] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 PDF information disclosure
4426| [87956] Microsoft Exchange 2013/2016 Oracle Outside In Libraries information disclosure
4427| [87944] Microsoft Windows Server 2012/Server 2012 R2 Virtual PCI Memory information disclosure
4428| [87940] Microsoft Windows Server 2012/Server 2012 R2 DNS Server Use-After-Free memory corruption
4429| [87936] Microsoft Office up to 2016 memory corruption
4430| [87166] Microsoft Windows up to Server 2012 R2 DirectX Graphics Kernel Subsystem privilege escalation
4431| [87156] Microsoft Windows 8.1/10/RT 8.1/Server 2012 R2 Shell memory corruption
4432| [87149] Microsoft Office up to 2016 memory corruption
4433| [87148] Microsoft Office 2010 Graphics memory corruption
4434| [87146] Microsoft Office 2011/2013/2013 RT/2016 memory corruption
4435| [82229] Microsoft Excel 2010 SP2 Office Document memory corruption
4436| [82223] Microsoft Windows 8.1/10/Server 2012 R2 Hyper-V Memory information disclosure
4437| [82222] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 Memory information disclosure
4438| [82221] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 Hyper-V privilege escalation
4439| [81274] Microsoft Office up to 2016 memory corruption
4440| [81270] Microsoft Windows 8.1/10/RT 8.1/Server 2012/Server 2012 R2 PDF Library memory corruption
4441| [81269] Microsoft Windows up to Server 2012 R2 Media Parser memory corruption
4442| [81268] Microsoft Windows up to Server 2012 R2 Media Parser memory corruption
4443| [80886] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
4444| [80885] Microsoft Windows 7 SP1/8.1/10/Server 2012/Server 2012 R2 RDP memory corruption
4445| [80878] Microsoft Windows Server 2012 R2 Active Directory Federation Service denial of service
4446| [80874] Microsoft Windows 7 SP1/8.1/10/Server 2012/Server 2012 R2 RDP privilege escalation
4447| [80870] Microsoft Office up to 2016 memory corruption
4448| [80868] Microsoft Office up to 2016 memory corruption
4449| [80867] Microsoft Office up to 2016 memory corruption
4450| [80865] Microsoft Windows 8.1/RT 8.1/Server 2012/Server 2012 R2 DLL Loader memory corruption
4451| [80860] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 Reader memory corruption
4452| [80859] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 PDF Library memory corruption
4453| [80231] Microsoft Excel up to 2016 Office Document memory corruption
4454| [80229] Microsoft Exchange Server 2013 CU 10/2013 CU 11/2013 SP1/2016 Outlook Web Access cross site scripting
4455| [80228] Microsoft Exchange Server 2016 Outlook Web Access cross site scripting
4456| [80227] Microsoft Exchange Server 2013 CU 10/2013 SP1/2016 Outlook Web Access cross site scripting
4457| [80226] Microsoft Exchange Server 2016 Outlook Web Access cross site scripting
4458| [80218] Microsoft Office up to 2016 ASLR privilege escalation
4459| [80217] Microsoft SharePoint Foundation 2013 SP1 Access Control Policy cross site scripting
4460| [80216] Microsoft Office up to 2016 Office Document memory corruption
4461| [80206] Microsoft SharePoint Foundation 2013 SP1 Access Control Policy cross site scripting
4462| [128763] Microsoft Exchange Server 2016 CU10/2016 CU11/2019 memory corruption
4463| [79508] Microsoft Windows up to Server 2012 R2 Library Loader memory corruption
4464| [79500] Microsoft Office 2010/2011/2016 memory corruption
4465| [79183] Microsoft Windows up to Server 2012 R2 IPsec denial of service
4466| [79173] Microsoft Windows up to Server 2012 R2 Graphics information disclosure
4467| [79117] Microsoft Outlook 2011/2016 on Mac HTML spoofing
4468| [78375] Microsoft SharePoint Server/SharePoint Foundation 2013 SP1 cross site scripting
4469| [77645] Microsoft Exchange Server 2013 CU8/2013 CU9 Outlook Web Access cross site scripting
4470| [77644] Microsoft Exchange Server 2013 CU8/2013 CU9 Outlook Web Access cross site scripting
4471| [77638] Microsoft Lync Server 2013 cross site scripting
4472| [77628] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
4473| [77612] Microsoft Exchange Server 2013 CU8/2013 CU9 Outlook Web Access Stack-Based information disclosure
4474| [77050] Microsoft Office up to 2016 memory corruption
4475| [77037] Microsoft Windows Server 2012/Server 2012 R2 System Center Operations Manager cross site scripting
4476| [76461] Microsoft Windows up to Server 2012 R2 Domain-Controller Communication Credentials information disclosure
4477| [76460] Microsoft Windows 7 SP1/8/Server 2012 RDP Server Service memory corruption
4478| [76448] Microsoft Windows 8.1/Server 2012 R2 Hyper-V memory corruption
4479| [75793] Microsoft Exchange Server 2013 CU8 cross site scripting
4480| [75792] Microsoft Exchange Server 2013 SP1 CU8 cross site request forgery
4481| [75791] Microsoft Office 2013 SP1 Office Document Uninitialized Memory memory corruption
4482| [75787] Microsoft Exchange Server 2013 SP1 CU8 Same Origin Policy privilege escalation
4483| [75786] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1 Office Document memory corruption
4484| [66976] Microsoft Access 2010 VBA Datatype denial of service
4485| [74848] Microsoft SharePoint Foundation/SharePoint Server 2013 SP1 cross site scripting
4486| [74842] Microsoft Windows 8.1/Server 2012 R2 Hyper-V denial of service
4487| [74836] Microsoft Project Server 2010 SP2/2013 SP1 cross site scripting
4488| [74835] Microsoft Office 2011 on Mac Use-After-Free cross site scripting
4489| [74834] Microsoft Windows Server 2012 R2 Active Directory Federation Services 3.0 privilege escalation
4490| [74833] Microsoft Windows 7 SP1/8/8.1/Server 2012/Server 2012 R2 HTTP Request HTTP.sys privilege escalation
4491| [74393] Microsoft SharePoint Server 2013 Foundation cross site scripting
4492| [73967] Microsoft Office up to 2013 SP1 Office File memory corruption
4493| [73966] Microsoft Office up to 2013 SP1 RTF File memory corruption
4494| [73965] Microsoft Office up to 2013 SP1 Use-After-Free memory corruption
4495| [73961] Microsoft Windows 7 SP1/8/8.1/Server 2012/Server 2012 R2 Remote Desktop Protocol Object Management denial of service
4496| [69162] Microsoft System Center Virtual Machine Manager 2012 privilege escalation
4497| [69160] Microsoft Windows up to Server 2012 Process privilege escalation
4498| [69156] Microsoft Office 2010 Object memory corruption
4499| [68593] Microsoft Windows up to Server 2012 Network Location Awareness Service privilege escalation
4500| [68417] Microsoft Exchange 2013 Outlook Web Access Token spoofing
4501| [68191] Microsoft SharePoint 2010 cross site scripting
4502| [67828] Microsoft ASP.NET MVC 2/3/4/5/5.1 System.Web.Mvc.dll cross site scripting
4503| [67518] Microsoft Lync 2013 denial of service
4504| [67517] Microsoft Lync 2013 Script Reflected cross site scripting
4505| [67516] Microsoft Lync 2010/2013 denial of service
4506| [67362] Microsoft Windows up to Server 2012 R2 Remote Procedure Call privilege escalation
4507| [67360] Microsoft SharePoint 2013 App Permission Management cross site scripting
4508| [13549] Microsoft Windows 7/8/8.1/Server 2012 Remote Desktop Protocol weak encryption
4509| [13547] Microsoft Lync 2010/2013 Meeting cross site scripting
4510| [13228] Microsoft Office 2013 Document privilege escalation
4511| [68577] Microsoft ASP.NET 2014.3.1209 Telerik UI RadAsyncUpload directory traversal
4512| [12267] Microsoft Forefront Security for Exchange Server 2010 Mail memory corruption
4513| [12263] Microsoft Windows up to Server 2012 Direct2D 2D Geometric Figure memory corruption
4514| [12238] Microsoft Windows 8/RT/Server 2012 IPv6 denial of service
4515| [12185] Microsoft .NET Framework 2/4 HMAC weak authentication
4516| [12183] Microsoft .NET Framework 2/4 DTD denial of service
4517| [11673] Microsoft Windows Live Movie Maker 2011 WAV File denial of service
4518| [11468] Microsoft Exchange 2010/2013 cross site scripting
4519| [11466] Microsoft Office 2013 File Response information disclosure
4520| [11457] Microsoft SharePoint Server/Office Web Apps 2010 SP1/2010 SP2/2013 W3WP Service Account privilege escalation
4521| [11150] Microsoft Windows 8/Server 2012 Hyper-V Data Structure Value Crash privilege escalation
4522| [11004] Microsoft Windows Server 2012 R2 RDP Restricted Admin Mode weak authentication
4523| [10250] Microsoft SharePoint Server up to 2013 W3WP Process denial of service
4524| [10249] Microsoft SharePoint 2010/2003/2007/2.0/3.0 Workflow memory corruption
4525| [10248] Microsoft SharePoint Server up to 2013 cross site scripting
4526| [9943] Microsoft Windows Server 2012 NAT Driver ICMP Packet denial of service
4527| [8739] Microsoft Windows Essentials up to 2012 Windows Writer Eingabe information disclosure
4528| [8725] Microsoft Lync 2010/2013 Use-After-Free memory corruption
4529| [8722] Microsoft Windows 8/RT/Server 2012 HTTP.sys denial of service
4530| [8206] Microsoft SharePoint Server 2010 SP1 HTML Sanitization Component cross site scripting
4531| [8203] Microsoft Windows up to 2012 AD LDAP Query denial of service
4532| [8200] Microsoft SharePoint Server 2013 ACL information disclosure
4533| [7971] Microsoft Office for Mac 2011 up to 14.3.1 on Mac HTML5 Mail Message Parser File information disclosure
4534| [7969] Microsoft OneNote 2010 SP1 ONE File information disclosure
4535| [7968] Microsoft SharePoint Server 2010 SP1 Input Validator Eingabe Crash denial of service
4536| [7967] Microsoft SharePoint Server 2010 SP1 User Account Eingabe Crash information disclosure
4537| [7966] Microsoft SharePoint Server 2010 SP1 Eingabe Crash cross site scripting
4538| [7965] Microsoft SharePoint Server 2010 SP1 User Account Callback URL privilege escalation
4539| [7964] Microsoft Visio 2010 Tree Object Type File memory corruption
4540| [7343] Microsoft Lync 2012 HTTP Format String
4541| [7258] Microsoft Windows up to 8/Server 2012 SSL/TLS race condition
4542| [7230] Microsoft Excel 2010 SP1 on 32-bit XLS File Formatting Information Crash denial of service
4543| [6831] Microsoft Office Picture Manager 2010 File memory corruption
4544| [62720] EMC NetWorker Module for Microsoft Applications up to 2.2.0 memory corruption
4545| [6624] Microsoft SQL Server up to 2012 Report Manager cross site scripting
4546| [62238] Microsoft Visual Studio Team Foundation Server 2010 cross site scripting
4547| [5946] Microsoft Visio/Visio Viewer up to 2010 SP1 File memory corruption
4548| [5644] Microsoft SharePoint 2010 scriptesx.ashx cross site scripting
4549| [5641] Microsoft SharePoint 2010 cross site scripting
4550| [60943] Microsoft Dynamics AX 2012 Enterprise Portal cross site scripting
4551| [12311] Microsoft Lync 2010 Search race condition
4552| [60570] Microsoft Forefront Unified Access Gateway 2010 information disclosure
4553| [60569] Microsoft Forefront Unified Access Gateway 2010 spoofing
4554| [60208] Microsoft Visio Viewer 2010 memory corruption
4555| [60207] Microsoft Visio Viewer 2010 memory corruption
4556| [60206] Microsoft Visio Viewer 2010 memory corruption
4557| [4640] Microsoft SharePoint 2010 inplview.aspx cross site scripting
4558| [4636] Microsoft SharePoint 2010 wizardlist.aspx cross site scripting
4559| [4635] Microsoft SharePoint 2010 themeweb.aspx cross site scripting
4560| [59008] Microsoft Forefront Unified Access Gateway 2010 Crash denial of service
4561| [58995] Microsoft Forefront Unified Access Gateway 2010 memory corruption
4562| [58994] Microsoft Forefront Unified Access Gateway 2010 Reflected cross site scripting
4563| [58993] Microsoft Forefront Unified Access Gateway 2010 Reflected cross site scripting
4564| [4424] Microsoft Host Integration Server up to 2010 denial of service
4565| [4420] Microsoft Forefront Unified Access Gateway 2010 memory corruption
4566| [58487] Microsoft SharePoint Foundation 2010 cross site scripting
4567| [58486] Microsoft SharePoint Foundation 2010 Reflected cross site scripting
4568| [58485] Microsoft SharePoint Foundation 2010 EditForm.aspx cross site scripting
4569| [4414] Microsoft SharePoint 2010 cross site scripting
4570| [4413] Microsoft SharePoint 2010/2007/3.0 XML/XLS unknown vulnerability
4571| [91971] Microsoft Skype 2.2.x/5.2.x/5.3.x denial of service
4572| [57693] Microsoft Forefront Threat Management Gateway 2010 NSPLookupServiceNext memory corruption
4573| [56028] Microsoft Data Access Components 2.8 memory corruption
4574| [55777] Microsoft Windows Movie Maker 2.6 memory corruption
4575| [55424] Microsoft Forefront Unified Access Gateway 2010 Signurl.asp cross site scripting
4576| [55415] Microsoft Forefront Unified Access Gateway 2010 cross site scripting
4577| [55414] Microsoft Forefront Unified Access Gateway 2010 cross site scripting
4578| [55413] Microsoft Forefront Unified Access Gateway 2010 spoofing
4579| [54341] Microsoft Windows Movie Maker 2.1 memory corruption
4580| [54549] Microsoft PowerPoint 2010 pptimpconv.dll memory corruption
4581| [4009] Microsoft NET Framework 2.x/3.x denial of service
4582| [45681] Microsoft Internet Explorer 8 Beta 2 privilege escalation
4583| [45449] Microsoft Internet Explorer 8 Beta 2 XSS Filter cross site scripting
4584| [45448] Microsoft Internet Explorer 8 Beta 2 XSS Filter cross site scripting
4585| [45446] Microsoft Internet Explorer 8 Beta 2 XSS Filter cross site scripting
4586| [2927] Microsoft Data Access Components 2.x ADODB.Connection ActiveX Control memory corruption
4587| [32692] Microsoft XML Core Services up to 2.6 memory corruption
4588| [32691] Microsoft XML Core Services up to 2.6 memory corruption
4589|
4590| MITRE CVE - https://cve.mitre.org:
4591| [CVE-2013-3661] The EPATHOBJ::bFlatten function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not check whether linked-list traversal is continually accessing the same list member, which allows local users to cause a denial of service (infinite traversal) via vectors that trigger a crafted PATHRECORD chain.
4592| [CVE-2013-3660] The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 does not properly initialize a pointer for the next object in a certain list, which allows local users to obtain write access to the PATHRECORD chain, and consequently gain privileges, by triggering excessive consumption of paged memory and then making many FlattenPath function calls, aka "Win32k Read AV Vulnerability."
4593| [CVE-2013-3174] DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 allows remote attackers to execute arbitrary code via a crafted GIF file, aka "DirectShow Arbitrary Memory Overwrite Vulnerability."
4594| [CVE-2013-3173] Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Win32k Buffer Overwrite Vulnerability."
4595| [CVE-2013-3172] Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to cause a denial of service (system hang) via a crafted application that leverages improper handling of objects in memory, aka "Win32k Buffer Overflow Vulnerability."
4596| [CVE-2013-3171] The serialization functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly check the permissions of delegate objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a partial-trust relationship, aka "Delegate Serialization Vulnerability."
4597| [CVE-2013-3167] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Information Disclosure Vulnerability."
4598| [CVE-2013-3154] The signature-update functionality in Windows Defender on Microsoft Windows 7 and Windows Server 2008 R2 relies on an incorrect pathname, which allows local users to gain privileges via a Trojan horse application in the %SYSTEMDRIVE% top-level directory, aka "Microsoft Windows 7 Defender Improper Pathname Vulnerability."
4599| [CVE-2013-3138] Integer overflow in the TCP/IP kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (system hang) via crafted TCP packets, aka "TCP/IP Integer Overflow Vulnerability."
4600| [CVE-2013-3136] The kernel in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, and Windows 8 on 32-bit platforms does not properly handle unspecified page-fault system calls, which allows local users to obtain sensitive information from kernel memory via a crafted application, aka "Kernel Information Disclosure Vulnerability."
4601| [CVE-2013-3134] The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 on 64-bit platforms does not properly allocate arrays of structures, which allows remote attackers to execute arbitrary code via a crafted .NET Framework application that changes array data, aka "Array Allocation Vulnerability."
4602| [CVE-2013-3133] Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "Anonymous Method Injection Vulnerability."
4603| [CVE-2013-3132] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "Delegate Reflection Bypass Vulnerability."
4604| [CVE-2013-3131] Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5, and Silverlight 5 before 5.1.20513.0, does not properly prevent changes to data in multidimensional arrays of structures, which allows remote attackers to execute arbitrary code via (1) a crafted .NET Framework application or (2) a crafted Silverlight application, aka "Array Access Violation Vulnerability."
4605| [CVE-2013-1345] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Vulnerability."
4606| [CVE-2013-1340] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Dereference Vulnerability."
4607| [CVE-2013-1339] The Print Spooler in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly manage memory during deletion of printer connections, which allows remote authenticated users to execute arbitrary code via a crafted request, aka "Print Spooler Vulnerability."
4608| [CVE-2013-1336] The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check signatures, which allows remote attackers to make undetected changes to signed XML documents via unspecified vectors that preserve signature validity, aka "XML Digital Signature Spoofing Vulnerability."
4609| [CVE-2013-1335] Microsoft Word 2003 SP3 and Word Viewer allow remote attackers to execute arbitrary code via crafted shape data in a Word document, aka "Word Shape Corruption Vulnerability."
4610| [CVE-2013-1334] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Window Handle Vulnerability."
4611| [CVE-2013-1332] dxgkrnl.sys (aka the DirectX graphics kernel subsystem) in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "DirectX Graphics Kernel Subsystem Double Fetch Vulnerability."
4612| [CVE-2013-1331] Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Office document, leading to improper memory allocation, aka "Office Buffer Overflow Vulnerability."
4613| [CVE-2013-1329] Integer signedness error in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers a buffer underflow, aka "Publisher Buffer Underflow Vulnerability."
4614| [CVE-2013-1328] Microsoft Publisher 2003 SP3, 2007 SP3, and 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers incorrect pointer handling, aka "Publisher Pointer Handling Vulnerability."
4615| [CVE-2013-1327] Integer signedness error in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers an improper memory allocation, aka "Publisher Signed Integer Vulnerability."
4616| [CVE-2013-1323] Microsoft Publisher 2003 SP3 does not properly handle NULL values for unspecified data items, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Incorrect NULL Value Handling Vulnerability."
4617| [CVE-2013-1322] Microsoft Publisher 2003 SP3 does not properly check table range data, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Invalid Range Check Vulnerability."
4618| [CVE-2013-1321] Microsoft Publisher 2003 SP3 does not properly check the data type of an unspecified return value, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Return Value Validation Vulnerability."
4619| [CVE-2013-1320] Buffer overflow in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Buffer Overflow Vulnerability."
4620| [CVE-2013-1319] Microsoft Publisher 2003 SP3 does not properly check the return value of an unspecified method, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Return Value Handling Vulnerability."
4621| [CVE-2013-1318] Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers access to an invalid pointer, aka "Publisher Corrupt Interface Pointer Vulnerability."
4622| [CVE-2013-1317] Integer overflow in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers an improper allocation-size calculation, aka "Publisher Integer Overflow Vulnerability."
4623| [CVE-2013-1316] Microsoft Publisher 2003 SP3 does not properly validate the size of an unspecified array, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Negative Value Allocation Vulnerability."
4624| [CVE-2013-1302] Microsoft Communicator 2007 R2, Lync 2010, Lync 2010 Attendee, and Lync Server 2013 do not properly handle objects in memory, which allows remote attackers to execute arbitrary code via an invitation that triggers access to a deleted object, aka "Lync RCE Vulnerability."
4625| [CVE-2013-1301] Microsoft Visio 2003 SP3 2007 SP3, and 2010 SP1 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, aka "XML External Entities Resolution Vulnerability."
4626| [CVE-2013-1300] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Memory Allocation Vulnerability."
4627| [CVE-2013-1295] The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "CSRSS Memory Corruption Vulnerability."
4628| [CVE-2013-1294] Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Kernel Race Condition Vulnerability."
4629| [CVE-2013-1293] The NTFS kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via a crafted application that leverages improper handling of objects in memory, aka "NTFS NULL Pointer Dereference Vulnerability."
4630| [CVE-2013-1292] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Win32k Race Condition Vulnerability."
4631| [CVE-2013-1291] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 Gold and SP1, and Windows 8 allows local users to cause a denial of service (reboot) via a crafted OpenType font, aka "OpenType Font Parsing Vulnerability" or "Win32k Font Parsing Vulnerability."
4632| [CVE-2013-1287] The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Windows USB Descriptor Vulnerability," a different vulnerability than CVE-2013-1285 and CVE-2013-1286.
4633| [CVE-2013-1286] The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Windows USB Descriptor Vulnerability," a different vulnerability than CVE-2013-1285 and CVE-2013-1287.
4634| [CVE-2013-1285] The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Windows USB Descriptor Vulnerability," a different vulnerability than CVE-2013-1286 and CVE-2013-1287.
4635| [CVE-2013-1283] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Win32k Race Condition Vulnerability."
4636| [CVE-2013-1281] The NFS server in Microsoft Windows Server 2008 R2 and R2 SP1 and Server 2012 allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via an attempted renaming of a file or folder located on a read-only share, aka "NULL Dereference Vulnerability."
4637| [CVE-2013-1280] The kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Reference Count Vulnerability."
4638| [CVE-2013-1279] Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages incorrect handling of objects in memory, aka "Kernel Race Condition Vulnerability," a different vulnerability than CVE-2013-1278.
4639| [CVE-2013-1278] Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages incorrect handling of objects in memory, aka "Kernel Race Condition Vulnerability," a different vulnerability than CVE-2013-1279.
4640| [CVE-2013-1277] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
4641| [CVE-2013-1276] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
4642| [CVE-2013-1275] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
4643| [CVE-2013-1274] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
4644| [CVE-2013-1273] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
4645| [CVE-2013-1272] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
4646| [CVE-2013-1271] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
4647| [CVE-2013-1270] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
4648| [CVE-2013-1269] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
4649| [CVE-2013-1268] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
4650| [CVE-2013-1267] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
4651| [CVE-2013-1266] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
4652| [CVE-2013-1265] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
4653| [CVE-2013-1264] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
4654| [CVE-2013-1263] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
4655| [CVE-2013-1262] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
4656| [CVE-2013-1261] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
4657| [CVE-2013-1260] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
4658| [CVE-2013-1259] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
4659| [CVE-2013-1258] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
4660| [CVE-2013-1257] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
4661| [CVE-2013-1256] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
4662| [CVE-2013-1255] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
4663| [CVE-2013-1254] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
4664| [CVE-2013-1253] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
4665| [CVE-2013-1252] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
4666| [CVE-2013-1251] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
4667| [CVE-2013-1250] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
4668| [CVE-2013-1249] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
4669| [CVE-2013-1248] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
4670| [CVE-2013-0095] Outlook in Microsoft Office for Mac 2008 before 12.3.6 and Office for Mac 2011 before 14.3.2 allows remote attackers to trigger access to a remote URL and consequently confirm the rendering of an HTML e-mail message by including unspecified HTML5 elements and leveraging the installation of a WebKit browser on the victim's machine, aka "Unintended Content Loading Vulnerability."
4671| [CVE-2013-0077] Quartz.dll in DirectShow in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows remote attackers to execute arbitrary code via crafted media content in (1) a media file, (2) a media stream, or (3) a Microsoft Office document, aka "Media Decompression Vulnerability."
4672| [CVE-2013-0076] The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Reference Count Vulnerability."
4673| [CVE-2013-0075] The TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (reboot) via a crafted packet that terminates a TCP connection, aka "TCP FIN WAIT Vulnerability."
4674| [CVE-2013-0073] The Windows Forms (aka WinForms) component in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly restrict the privileges of a callback function during object creation, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "WinForms Callback Elevation Vulnerability."
4675| [CVE-2013-0013] The SSL provider component in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle encrypted packets, which allows man-in-the-middle attackers to conduct SSLv2 downgrade attacks against (1) SSLv3 sessions or (2) TLS sessions by intercepting handshakes and injecting content, aka "Microsoft SSL Version 3 and TLS Protocol Security Feature Bypass Vulnerability."
4676| [CVE-2013-0011] The Print Spooler in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted print job, aka "Windows Print Spooler Components Vulnerability."
4677| [CVE-2013-0010] Cross-site scripting (XSS) vulnerability in Microsoft System Center Operations Manager 2007 SP1 and R2 allows remote attackers to inject arbitrary web script or HTML via crafted input, aka "System Center Operations Manager Web Console XSS Vulnerability," a different vulnerability than CVE-2013-0009.
4678| [CVE-2013-0009] Cross-site scripting (XSS) vulnerability in Microsoft System Center Operations Manager 2007 SP1 and R2 allows remote attackers to inject arbitrary web script or HTML via crafted input, aka "System Center Operations Manager Web Console XSS Vulnerability," a different vulnerability than CVE-2013-0010.
4679| [CVE-2013-0008] win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle window broadcast messages, which allows local users to gain privileges via a crafted application, aka "Win32k Improper Message Handling Vulnerability."
4680| [CVE-2013-0004] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate the permissions of objects in memory, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "Double Construction Vulnerability."
4681| [CVE-2013-0003] Buffer overflow in a System.DirectoryServices.Protocols (S.DS.P) namespace method in Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a missing array-size check during a memory copy operation, aka "S.DS.P Buffer Ov
4682#######################################################################################################################################
4683Starting Nmap 7.80 ( https://nmap.org ) at 2019-10-12 08:55 EDT
4684Nmap scan report for a67-209-250-173.cust.mi.winntel.net (67.209.250.173)
4685Host is up (0.066s latency).
4686Not shown: 994 filtered ports, 4 closed ports
4687Some closed ports may be reported as filtered due to --defeat-rst-ratelimit
4688PORT STATE SERVICE
468980/tcp open http
4690443/tcp open https
4691
4692Nmap done: 1 IP address (1 host up) scanned in 7.40 seconds
4693#######################################################################################################################################
4694Starting Nmap 7.80 ( https://nmap.org ) at 2019-10-12 08:55 EDT
4695Nmap scan report for a67-209-250-173.cust.mi.winntel.net (67.209.250.173)
4696Host is up (0.066s latency).
4697Not shown: 2 filtered ports
4698PORT STATE SERVICE
469953/udp open|filtered domain
470067/udp open|filtered dhcps
470168/udp open|filtered dhcpc
470269/udp open|filtered tftp
470388/udp open|filtered kerberos-sec
4704123/udp open|filtered ntp
4705139/udp open|filtered netbios-ssn
4706161/udp open|filtered snmp
4707162/udp open|filtered snmptrap
4708389/udp open|filtered ldap
4709500/udp open|filtered isakmp
4710520/udp open|filtered route
47112049/udp open|filtered nfs
4712
4713Nmap done: 1 IP address (1 host up) scanned in 2.54 seconds
4714#######################################################################################################################################
4715HTTP/1.1 404 Not Found
4716Content-Length: 315
4717Content-Type: text/html; charset=us-ascii
4718Server: Microsoft-HTTPAPI/2.0
4719Date: Sat, 12 Oct 2019 12:55:48 GMT
4720Connection: close
4721#######################################################################################################################################
4722
4723wig - WebApp Information Gatherer
4724
4725
4726Scanning http://67.209.250.173...
4727____________________________________________ SITE INFO _____________________________________________
4728IP Title
472967.209.250.173
4730
4731_____________________________________________ VERSION ______________________________________________
4732Name Versions Type
4733microsoft-httpapi 2.0 Platform
4734Microsoft Windows 7 OS
4735Microsoft Windows Server 2003 SP2 | 2003 SP3 | 2008 | 2008 R2 | 2012 | 2012 R2 OS
4736
4737____________________________________________________________________________________________________
4738Time: 14.2 sec Urls: 599 Fingerprints: 40401
4739#######################################################################################################################################
4740Starting Nmap 7.80 ( https://nmap.org ) at 2019-10-12 08:55 EDT
4741NSE: Loaded 163 scripts for scanning.
4742NSE: Script Pre-scanning.
4743Initiating NSE at 08:55
4744Completed NSE at 08:55, 0.00s elapsed
4745Initiating NSE at 08:55
4746Completed NSE at 08:55, 0.00s elapsed
4747Initiating Parallel DNS resolution of 1 host. at 08:55
4748Completed Parallel DNS resolution of 1 host. at 08:55, 0.02s elapsed
4749Initiating SYN Stealth Scan at 08:55
4750Scanning a67-209-250-173.cust.mi.winntel.net (67.209.250.173) [1 port]
4751Discovered open port 80/tcp on 67.209.250.173
4752Completed SYN Stealth Scan at 08:55, 0.09s elapsed (1 total ports)
4753Initiating Service scan at 08:55
4754Scanning 1 service on a67-209-250-173.cust.mi.winntel.net (67.209.250.173)
4755Completed Service scan at 08:55, 6.11s elapsed (1 service on 1 host)
4756Initiating OS detection (try #1) against a67-209-250-173.cust.mi.winntel.net (67.209.250.173)
4757Retrying OS detection (try #2) against a67-209-250-173.cust.mi.winntel.net (67.209.250.173)
4758Initiating Traceroute at 08:56
4759Completed Traceroute at 08:56, 0.09s elapsed
4760Initiating Parallel DNS resolution of 11 hosts. at 08:56
4761Completed Parallel DNS resolution of 11 hosts. at 08:56, 0.20s elapsed
4762NSE: Script scanning 67.209.250.173.
4763Initiating NSE at 08:56
4764NSE Timing: About 36.49% done; ETC: 08:57 (0:00:54 remaining)
4765NSE Timing: About 68.88% done; ETC: 08:57 (0:00:36 remaining)
4766NSE Timing: About 85.12% done; ETC: 08:59 (0:00:30 remaining)
4767NSE Timing: About 85.86% done; ETC: 08:59 (0:00:34 remaining)
4768NSE Timing: About 85.96% done; ETC: 09:00 (0:00:39 remaining)
4769NSE Timing: About 85.76% done; ETC: 09:01 (0:00:46 remaining)
4770NSE Timing: About 85.57% done; ETC: 09:02 (0:00:55 remaining)
4771NSE Timing: About 85.38% done; ETC: 09:03 (0:01:06 remaining)
4772NSE: [http-wordpress-enum 67.209.250.173:80] got no answers from pipelined queries
4773NSE Timing: About 87.04% done; ETC: 09:04 (0:01:07 remaining)
4774NSE Timing: About 88.08% done; ETC: 09:05 (0:01:10 remaining)
4775NSE Timing: About 89.40% done; ETC: 09:07 (0:01:10 remaining)
4776NSE Timing: About 91.39% done; ETC: 09:08 (0:01:03 remaining)
4777NSE Timing: About 92.72% done; ETC: 09:09 (0:00:57 remaining)
4778NSE Timing: About 94.04% done; ETC: 09:09 (0:00:50 remaining)
4779NSE Timing: About 95.03% done; ETC: 09:10 (0:00:44 remaining)
4780NSE Timing: About 96.36% done; ETC: 09:11 (0:00:33 remaining)
4781NSE Timing: About 96.69% done; ETC: 09:11 (0:00:31 remaining)
4782Completed NSE at 09:15, 1190.99s elapsed
4783Initiating NSE at 09:15
4784Completed NSE at 09:15, 8.16s elapsed
4785Nmap scan report for a67-209-250-173.cust.mi.winntel.net (67.209.250.173)
4786Host is up (0.055s latency).
4787
4788PORT STATE SERVICE VERSION
478980/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
4790|_http-aspnet-debug: ERROR: Script execution failed (use -d to debug)
4791| http-brute:
4792|_ Path "/" does not require authentication
4793|_http-chrono: Request times for /; avg: 22315.23ms; min: 22228.62ms; max: 22402.86ms
4794|_http-csrf: Couldn't find any CSRF vulnerabilities.
4795|_http-devframework: Couldn't determine the underlying framework or CMS. Try increasing 'httpspider.maxpagecount' value to spider more pages.
4796|_http-dombased-xss: Couldn't find any DOM based XSS.
4797|_http-errors: ERROR: Script execution failed (use -d to debug)
4798|_http-feed: Couldn't find any feeds.
4799|_http-fetch: Please enter the complete path of the directory to save data in.
4800|_http-jsonp-detection: Couldn't find any JSONP endpoints.
4801|_http-mobileversion-checker: No mobile version detected.
4802|_http-security-headers:
4803|_http-server-header: Microsoft-HTTPAPI/2.0
4804| http-sitemap-generator:
4805| Directory structure:
4806| Longest directory structure:
4807| Depth: 0
4808| Dir: /
4809| Total files found (by extension):
4810|_
4811|_http-stored-xss: Couldn't find any stored XSS vulnerabilities.
4812|_http-traceroute: ERROR: Script execution failed (use -d to debug)
4813| http-vhosts:
4814| 126 names had status ERROR
4815|_alpha.cust.mi.winntel.net : 404
4816|_http-vuln-cve2014-3704: ERROR: Script execution failed (use -d to debug)
4817|_http-wordpress-users: [Error] Wordpress installation was not found. We couldn't find wp-login.php
4818|_http-xssed: No previously reported XSS vuln.
4819| vulscan: VulDB - https://vuldb.com:
4820| [141625] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 DirectX memory corruption
4821| [141624] Microsoft Windows 7 SP1/Server 2008 R2 SP1 Graphics Component information disclosure
4822| [139966] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Kernel information disclosure
4823| [139923] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Graphics Component information disclosure
4824| [139905] Microsoft Windows Server 2008 SP2 DHCP Server memory corruption
4825| [137573] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
4826| [137567] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
4827| [137566] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
4828| [137565] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
4829| [137564] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
4830| [136343] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
4831| [136342] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
4832| [136341] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
4833| [136316] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
4834| [136315] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
4835| [136313] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
4836| [136311] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
4837| [136309] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
4838| [136302] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
4839| [136298] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
4840| [136297] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Win32k memory corruption
4841| [131683] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Win32k memory corruption
4842| [131642] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Active Directory privilege escalation
4843| [127822] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2012 Kernel information disclosure
4844| [125103] Microsoft Windows Server 2008 SP2 Graphics Component information disclosure
4845| [123853] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Kernel Memory information disclosure
4846| [122858] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 LNK memory corruption
4847| [122833] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI+ memory corruption
4848| [121109] Microsoft Wireless Display Adapter V2 2.0.8350/2.0.8365/2.0.8372 privilege escalation
4849| [120449] Microsoft Forefront Unified Access Gateway 2000 InitParams.aspx Parameter Server-Side Request Forgery
4850| [119469] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Kernel privilege escalation
4851| [116015] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1 memory corruption
4852| [114563] Microsoft Office 2007 SP3/2010 SP2/2013/2013 RT SP1 memory corruption
4853| [114528] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI privilege escalation
4854| [114524] Microsoft ASP.NET Core 2.0 denial of service
4855| [114523] Microsoft ASP.NET Core 2.0 Kestrel Web Application privilege escalation
4856| [113257] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2012 Kernel information disclosure
4857| [113256] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2012 Kernel information disclosure
4858| [113255] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2012 Kernel information disclosure
4859| [113247] Microsoft Windows 7 SP1/Server 2008 R2 SP1 EOT Font Engine information disclosure
4860| [113246] Microsoft Windows 7 SP1/Server 2008 R2 SP1 EOT Font Engine information disclosure
4861| [113245] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2012 EOT Font Engine information disclosure
4862| [113244] Microsoft Windows 7 SP1/Server 2008 R2 SP1 EOT Font Engine information disclosure
4863| [113235] Microsoft Outlook 2007 SP3/2010 SP2/2013 SP1/2016 privilege escalation
4864| [113234] Microsoft Office 2007 SP2/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
4865| [113216] Microsoft Outlook 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
4866| [112285] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
4867| [112284] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
4868| [112283] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
4869| [112282] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
4870| [111578] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
4871| [111577] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
4872| [111576] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
4873| [111575] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
4874| [111574] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
4875| [111573] Microsoft Office 2007/2010/2013/2016 Equation Editor memory corruption
4876| [111572] Microsoft Office 2007/2010/2013/2016 Equation Editor memory corruption
4877| [111570] Microsoft Office 2007/2010/2013/2016 Equation Editor memory corruption
4878| [111568] Microsoft Excel 2007/2010/2013/2016 memory corruption
4879| [111566] Microsoft Word 2007/2010/2013/2016 memory corruption
4880| [111565] Microsoft Word 2007/2010/2013 Email Message memory corruption
4881| [111563] Microsoft Outlook 2007/2010/2013/2016 Email Message privilege escalation
4882| [111347] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Color Management Icm32.dll information disclosure
4883| [109388] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2016 memory corruption
4884| [109387] Microsoft ASP.NET Core 2.0 privilege escalation
4885| [109386] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
4886| [109385] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 Security Feature Macro privilege escalation
4887| [109381] Microsoft Office/Word 2007 SP3/2010 SP2 memory corruption
4888| [107703] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
4889| [106530] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
4890| [106528] Microsoft PowerPoint 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
4891| [106515] Microsoft Publisher 2007 SP3/2010 SP2 memory corruption
4892| [106497] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Uniscribe memory corruption
4893| [106476] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
4894| [106475] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
4895| [105051] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Font Library privilege escalation
4896| [105032] Microsoft Internet Explorer 9/10 on Server 2008/Server 2012 memory corruption
4897| [102513] Microsoft Windows Server 2003 SP2/XP SP3 OLE olecnv32.dll privilege escalation
4898| [102512] Microsoft Windows Server 2003 SP2/XP SP3 rpc privilege escalation
4899| [102511] Microsoft Windows Server 2003 SP2/XP SP3 RDP EsteemAudit privilege escalation
4900| [102447] Microsoft PowerPoint/SharePoint Server 2007 SP3 privilege escalation
4901| [102444] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 privilege escalation
4902| [102442] Microsoft Outlook 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 Bypass privilege escalation
4903| [102441] Microsoft Outlook 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
4904| [102401] Microsoft Windows 7 SP1/Server 2008 R2 SP1 GDI USP10!NextCharInLiga Uniscribe Font information disclosure
4905| [101491] Microsoft Windows up to XP SP3/Server 2003 SP2 Remote Desktop Protocol gpkcsp.dll memory corruption
4906| [101017] Microsoft Office 2007 SP3/2010 SP2/2016 memory corruption
4907| [101012] Microsoft Office 2007 SP3/2010 SP2/2011/2013 SP1/2016 memory corruption
4908| [101011] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 ActiveX Object Memory memory corruption
4909| [100854] Microsoft Windows Server 2003 SP2 RRAS ERRATICGOPHER memory corruption
4910| [99904] Microsoft Windows Server 2003 SP2/XP SP3 SmartCard Authentication RDP Packet EsteemAudit privilege escalation
4911| [99698] Microsoft OneNote 2007 SP3/2010 SP2 DLL Loader privilege escalation
4912| [99684] Microsoft Excel 2007 SP3/2010 SP2 Memory information disclosure
4913| [99654] Microsoft Outlook 2007 SP3/2010 SP2/2011/2013 SP1/2016 Email Message privilege escalation
4914| [99653] Microsoft Outlook 2007 SP3/2010 SP2/2011/2013 SP1/2016 Email Message privilege escalation
4915| [99533] Microsoft Office 2007/2010/2013/2016 RTF Document Necurs Dridex memory corruption
4916| [98561] Microsoft IIS 6.0 on Windows Server 2003 WebDAV ScStoragePathFromUrl Long Header memory corruption
4917| [98092] Microsoft SharePoint Server 2007 SP3 memory corruption
4918| [98088] Microsoft SharePoint Server 2007 SP3 memory corruption
4919| [98087] Microsoft Office 2007 SP3/2010 SP2 memory corruption
4920| [98086] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
4921| [98085] Microsoft Excel 2007 SP3 memory corruption
4922| [98084] Microsoft Word 2007 SP3/2010 SP2/2011 memory corruption
4923| [98083] Microsoft Word 2007 SP3/2010 SP2/2011 memory corruption
4924| [98078] Microsoft Word/Excel 2007 SP3 memory corruption
4925| [98072] Microsoft Office 2007 SP3/2010 SP2/Word Viewer Graphics Component privilege escalation
4926| [98071] Microsoft Office 2007 SP3/2010 SP2/Word Viewer GDI+ information disclosure
4927| [98070] Microsoft Office 2007 SP3/2010 SP2/Word Viewer GDI+ information disclosure
4928| [94450] Microsoft Office 2007 SP3/2010 SP2/2011 memory corruption
4929| [94449] Microsoft Office 2007 SP3/2010 SP2/2011/2013 SP1 information disclosure
4930| [94448] Microsoft Office 2007 SP3/2010 SP2/2011/2013 SP1 information disclosure
4931| [94445] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1 information disclosure
4932| [94441] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 privilege escalation
4933| [94440] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
4934| [94439] Microsoft Office 2007 SP3/2011 privilege escalation
4935| [94438] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 privilege escalation
4936| [93542] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1 memory corruption
4937| [93541] Microsoft Office 2007 SP3 denial of service
4938| [93539] Microsoft Office 2007/2010 SP2/2011 memory corruption
4939| [93538] Microsoft Office 2007/2010 SP2/2011/2013 SP1 memory corruption
4940| [93537] Microsoft Office 2007/2010 SP2/2011 memory corruption
4941| [93396] Microsoft Office 2007/2010/2011 memory corruption
4942| [93395] Microsoft Office 2007/2010/2011 memory corruption
4943| [93394] Microsoft Office 2007/2010 memory corruption
4944| [92596] Microsoft Windows 7 SP1/Server 2008 R2/Server 2008 SP2/Vista SP2 Internet Messaging API File information disclosure
4945| [91554] Microsoft Exchange 2007/2010/2013/2016 Email information disclosure
4946| [91553] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
4947| [91552] Microsoft Office 2007/2010/2013/2013 RT/2016 spoofing
4948| [91551] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
4949| [91549] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
4950| [91548] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
4951| [91546] Microsoft Office 2007/2010/2013/2013 RT memory corruption
4952| [91545] Microsoft Office 2007/2010 memory corruption
4953| [91544] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
4954| [91542] Microsoft Office 2007/2010/2013/2013 RT/2016 information disclosure
4955| [90707] Microsoft OneNote 2007/2010/2013/2013 RT/2016 information disclosure
4956| [90706] Microsoft Office 2007/2010/2013/2013 RT Graphics memory corruption
4957| [90705] Microsoft Office 2007/2010/2011 memory corruption
4958| [90703] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
4959| [89039] Microsoft Office 2007 SP3/2010 SP2/2011/2013 RT SP1/2013 SP1 memory corruption
4960| [89034] Microsoft Windows Server 2008/Vista SP2 JScript/VBScript memory corruption
4961| [87960] Microsoft Windows Server 2008 R2/Server 2012/Server 2012 R2 Active Directory denial of service
4962| [87955] Microsoft Exchange 2007/2010/2013/2016 Oracle Outside In Libraries privilege escalation
4963| [87954] Microsoft Exchange 2007/2010/2013/2016 Oracle Outside In Libraries privilege escalation
4964| [87953] Microsoft Exchange 2007/2010/2013/2016 Oracle Outside In Libraries privilege escalation
4965| [87939] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 OLE DLL memory corruption
4966| [87938] Microsoft Office 2007 SP3/2010 SP2/2011 information disclosure
4967| [87937] Microsoft Office 2007 SP3/2010 SP2/2011 memory corruption
4968| [87935] Microsoft Windows Server 2008 R2 SP1/Server 2008 SP2/Vista SP2 VBScript/JScript memory corruption
4969| [87934] Microsoft Windows Server 2008 R2 SP1/Server 2008 SP2/Vista SP2 VBScript/JScript memory corruption
4970| [87933] Microsoft Windows Server 2008 R2 SP1/Server 2008 SP2/Vista SP2 VBScript/JScript memory corruption
4971| [87147] Microsoft Office 2007/2010 memory corruption
4972| [87145] Microsoft Windows Server 2008/Vista SP2 JScript/VBScript memory corruption
4973| [87144] Microsoft Windows Server 2008/Vista SP2 JScript/VBScript memory corruption
4974| [82228] Microsoft Excel 2007 SP3/2010 SP2 Office Document memory corruption
4975| [82225] Microsoft Word 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1 Office Document memory corruption
4976| [82224] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 Office Document memory corruption
4977| [81273] Microsoft Office 2007/2010/2013/2016 memory corruption
4978| [81272] Microsoft Office 2007/2010/2013 memory corruption
4979| [81265] Microsoft Windows Server 2008/Vista SP2 Library Loader memory corruption
4980| [80872] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
4981| [80871] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
4982| [80869] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
4983| [79506] Microsoft Windows 7/Server 2008/Server 2008 R2/Vista Library Loader memory corruption
4984| [79505] Microsoft Office 2007 memory corruption
4985| [79504] Microsoft Office 2007/2010/2013/2016 memory corruption
4986| [79503] Microsoft Office 2007/2010/2013 memory corruption
4987| [79502] Microsoft Office 2007/2010/2011 memory corruption
4988| [79501] Microsoft Office 2007/2010 memory corruption
4989| [79499] Microsoft Windows 7/Server 2008 R2 Uniscribe memory corruption
4990| [79493] Microsoft Windows Server 2008/Vista Graphics memory corruption
4991| [79190] Microsoft Word 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 Office Document memory corruption
4992| [79189] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 Office Document memory corruption
4993| [79187] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2016 Sandbox privilege escalation
4994| [79167] Microsoft Windows 7/Server 2008/Server 2008 R2/Vista Journal memory corruption
4995| [78372] Microsoft Visio 2007 SP3/2010 SP2 UML Data memory corruption
4996| [78371] Microsoft SharePoint Server 2007 SP3/2010 SP2 InfoPath Forms Services XXE information disclosure
4997| [77646] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1 EPS Image memory corruption
4998| [77629] Microsoft Excel 2007 SP3/2010 SP2/2011/2016 Office Document memory corruption
4999| [77627] Microsoft Excel 2007 SP3/2010 SP2 Office Document memory corruption
5000| [77626] Microsoft Excel 2007 SP3/2010 SP2/2011/2016 Office Document memory corruption
5001| [77617] Microsoft Office 2007 SP3/2010 SP2 OpenType Font memory corruption
5002| [77252] Microsoft Office 2007 SP3/2010 SP2 Office Graphics Library Font memory corruption
5003| [77038] Microsoft Windows Server 2008 SP2 UDDI Services cross site scripting
5004| [76497] Microsoft PowerPoint 2007 SP3/2010 SP2/2013 SP1 Office Document memory corruption
5005| [76491] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1 Office Document memory corruption
5006| [76467] Microsoft Word 2007 SP3/2010 SP2/2011/2013 RT SP1/2013 SP1 Office Document memory corruption
5007| [76466] Microsoft Word 2007 SP3/2010 SP2/2011/2013 RT SP1/2013 SP1 Office Document memory corruption
5008| [76464] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1 Office Document memory corruption
5009| [76463] Microsoft Excel 2007 SP3/2010 SP2/2011/2013 RT SP1/2013 SP1 Office Document memory corruption
5010| [76449] Microsoft Windows 8/8.1/Server 2008/Server 2012/Server 2012 R2 Hyper-V memory corruption
5011| [76440] Microsoft SQL Server 2008/2008 R2/2012/2014 Virtual Function Uninitialized Memory memory corruption
5012| [76439] Microsoft SQL Server 2008/2008 R2/2012/2014 Uninitialized Memory memory corruption
5013| [76438] Microsoft SQL Server 2008/2008 R2/2012/2014 Pointer Casting privilege escalation
5014| [75783] Microsoft Windows Server 2008/Server 2012 Active Directory Federation Services cross site scripting
5015| [75338] Microsoft SharePoint 2007/2010/2013 Content privilege escalation
5016| [75337] Microsoft Office 2007 SP3/2010 SP2/2011/2013 RT SP1/2013 SP1 memory corruption
5017| [75336] Microsoft Office 2007 SP3/2010 SP2/2011/2013 RT SP1/2013 SP1 memory corruption
5018| [74845] Microsoft Office 2007/2010/2013 Document Use-After-Free memory corruption
5019| [74844] Microsoft Office 2007/2010 Document Use-After-Free memory corruption
5020| [74837] Microsoft Office 2007/2010/2011/2013 RTF Document Use-After-Free privilege escalation
5021| [73979] Microsoft Exchange Server 2003 CU7/2003 SP1 Meeting privilege escalation
5022| [73978] Microsoft Exchange Server 2003 CU7/2003 SP1 cross site scripting
5023| [73977] Microsoft Exchange Server 2003 CU7/2003 SP1 cross site scripting
5024| [73976] Microsoft Exchange Server 2003 CU7/2003 SP1 cross site scripting
5025| [73975] Microsoft Exchange Server 2003 CU7/2003 SP1 cross site scripting
5026| [73964] Microsoft SharePoint 2007/2010/2013 cross site scripting
5027| [69158] Microsoft Office 2007/2010/2013 Use-After-Free memory corruption
5028| [69157] Microsoft Office 2007/2010/2013 OneTableDocumentStream memory corruption
5029| [68416] Microsoft Exchange 2007/2010/2013 Outlook Web Access Token spoofing
5030| [68409] Microsoft Office 2007/2010/2013 Use-After-Free memory corruption
5031| [68408] Microsoft Excel 2007/2010/2013 memory corruption
5032| [68407] Microsoft Excel 2007/2010 memory corruption
5033| [68405] Microsoft Word 2007/2010 Index Use-After-Free memory corruption
5034| [68195] Microsoft Windows 7/Server 2003/Server 2008/Vista Input Method Editor Sandbox privilege escalation
5035| [68189] Microsoft Windows Server 2003 SP2 TCP/IP Stack Stack-Based memory corruption
5036| [68188] Microsoft Word 2007 File memory corruption
5037| [68187] Microsoft Word 2007 File memory corruption
5038| [68186] Microsoft Word 2007 File memory corruption
5039| [67829] Microsoft Office 2007/2010/2011 Object memory corruption
5040| [67825] Microsoft .NET Framework 2.0/3.5/3.5.1 ASLR privilege escalation
5041| [71337] Microsoft Office 2000/2004/XP memory corruption
5042| [67355] Microsoft OneNote 2007 File Processing privilege escalation
5043| [67354] Microsoft SQL Server 2008 R2 SP2/2008 SP3/2012 SP1/2014 SQL Master Data Services cross site scripting
5044| [67353] Microsoft SQL Server 2008 R2 SP2/2008 SP3/2012 SP1/2014 T-SQL Query Stack-Based memory corruption
5045| [67018] Microsoft Windows Server 2008/Server 2012/Server 2012 R2 Service Bus AMQP Message denial of service
5046| [13545] Microsoft Word 2007 Embedded Font memory corruption
5047| [13397] Microsoft Windows 2000/Server 2003/XP DHCP Response DHCP ACK spoofing
5048| [13462] Microsoft Visual Studio 2002/2003/2005/2010 Debug Interface msdia.dll PDB File memory corruption
5049| [13229] Microsoft Office 2007/2010/2013 Common Control Library MSCOMCTL.OCX privilege escalation
5050| [13227] Microsoft Office 2007/2010/2013 Chinese Grammar Checker Library privilege escalation
5051| [13226] Microsoft SharePoint Server 2007/2010/2013 Page memory corruption
5052| [13225] Microsoft SharePoint Server 2007/2010/2013 cross site scripting
5053| [13224] Microsoft SharePoint Server 2007/2010/2013 Page memory corruption
5054| [12859] Microsoft Word 2003 Office Document Stack-Based memory corruption
5055| [12852] Microsoft Publisher 2003/2007 Publisher File pubconv.dll memory corruption
5056| [12845] Microsoft Word 2003 Office File Stack-Based memory corruption
5057| [12844] Microsoft Word 2007/2010 Office File memory corruption
5058| [12843] Microsoft Office 2007/2010/2011/2013 XML Parser Nested Entities Memory Consumption denial of service
5059| [12687] Microsoft Word/Office/Outlook 2003/2007/2010/2013 RTF Document memory corruption
5060| [12530] Microsoft Windows Server 2003/Server 2008/Server 2012/Vista/XP Security Account Manager Lockout privilege escalation
5061| [12266] Microsoft .NET Framework 2.0 SP2/3.5.1 ASLR Bypass privilege escalation
5062| [12070] Apple Pages 2.0/2.0.1/2.0.2/5.0/5.0.1 on Mac Microsoft Word Document memory corruption
5063| [11950] Microsoft Office Compability Pack/Word 2007 SP3 File memory corruption
5064| [11949] Microsoft Word Viewer/Office Compatibility Pack/Word 2003 SP3/2007 SP3 File memory corruption
5065| [11494] Microsoft .NET Framework 2.0 SP2/3.5.1/4/4.5/4.5.1 MAC Authentication privilege escalation
5066| [11448] Microsoft Office 2007/2010 Address Space Layout Randomization privilege escalation
5067| [11148] Microsoft Office 2003/2007 WordPerfect Document epsimp32.flt memory corruption
5068| [11146] Microsoft Office 2003/2007 epsimp32.flt memory corruption
5069| [11230] Microsoft Word 2003 DOC Document Embedded Image denial of service
5070| [11081] Microsoft Windows Server 2008/Vista TIFF Image memory corruption
5071| [10648] Microsoft Word 2007 Word File memory corruption
5072| [10647] Microsoft Word 2003 Word File memory corruption
5073| [10643] Microsoft SharePoint Server 2007/2010/2013 Input Sanitizer memory corruption
5074| [10642] Microsoft SharePoint Server 2007/2010 Content Display in Frames privilege escalation
5075| [10247] Microsoft SharePoint Server 2007/2010/2013 Online Cloud cross site scripting
5076| [10245] Microsoft Office 2003/2007/2010 Word File memory corruption
5077| [10244] Microsoft Office 2003 SP3 Word File memory corruption
5078| [10243] Microsoft Office 2003/2007 Word File memory corruption
5079| [10242] Microsoft Office 2007 Word File memory corruption
5080| [10241] Microsoft Office 2007 Word File memory corruption
5081| [10240] Microsoft Office 2003/2007/2010 Word File memory corruption
5082| [10239] Microsoft Office 2003/2007 Word File memory corruption
5083| [10238] Microsoft Excel 2003/2007 XML External Entity Data information disclosure
5084| [10237] Microsoft Excel 2003/2007/2010 XML External Entity Data information disclosure
5085| [10236] Microsoft Word/Office 2003/2007 XML External Entity Data information disclosure
5086| [10234] Microsoft Word/Sharepoint 2003 SP3/2007 SP3/2010 SP1 Office File memory corruption
5087| [10232] Microsoft Word/Sharepoint 2003 SP3/2007 SP3/2010 SP1 Office File memory corruption
5088| [10231] Microsoft Word/Sharepoint 2003 SP3/2007 SP3/2010 SP1 Office File memory corruption
5089| [10230] Microsoft Word/Sharepoint 2003 SP3/2007 SP3/2010 SP1 Office File memory corruption
5090| [10229] Microsoft Access 2007/2010/2013 Access File ACCDB File memory corruption
5091| [10228] Microsoft Access 2007/2010/2013 Access File ACCDB File memory corruption
5092| [10227] Microsoft Access 2007/2010/2013 Access File ACCDB File memory corruption
5093| [10192] Microsoft Windows 7/2000/Server 2003 SP2/Vista/XP SP3 Windows Theme File privilege escalation
5094| [10191] Microsoft Windows Server 2003/XP OLE Object privilege escalation
5095| [10190] Microsoft Windows 7/8/Server 2008/Vista Active Directory denial of service
5096| [10189] Microsoft Outlook 2007/2010 S/MIME privilege escalation
5097| [9941] Microsoft Windows Server 2003/XP Unicode Scripts Processor USP10.DLL Uniscribe Font memory corruption
5098| [9929] Microsoft Windows Server 2008/Server 2012 Active Directory Federation Services Unspecified Account information disclosure
5099| [9715] Microsoft PowerPoint 2007 DirectShow Runtime quartz.dll GetMaxSampleSize denial of service
5100| [9397] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 Array privilege escalation
5101| [9394] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 on 64-bit Array memory corruption
5102| [9393] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 Permission privilege escalation
5103| [8738] Microsoft Visio 2003 SP3/2007 SP3/2010 SP1 XML Parser File information disclosure
5104| [8737] Microsoft Word 2003 SP3 Shape Data Parser File memory corruption
5105| [8736] Microsoft Publisher 2003 SP3 PUB File memory corruption
5106| [8735] Microsoft Publisher 2003 SP3/2007 SP3/2010 SP1 PUB File memory corruption
5107| [8734] Microsoft Publisher 2003 SP3 PUB File memory corruption
5108| [8733] Microsoft Publisher 2003 SP3 PUB File memory corruption
5109| [8732] Microsoft Publisher 2003 SP3 PUB File memory corruption
5110| [8731] Microsoft Publisher 2003 SP3 PUB File memory corruption
5111| [8730] Microsoft Publisher 2003 SP3 PUB File memory corruption
5112| [8729] Microsoft Publisher 2003 SP3 PUB File memory corruption
5113| [8728] Microsoft Publisher 2003 SP3 PUB File memory corruption
5114| [8727] Microsoft Publisher 2003 SP3 PUB File memory corruption
5115| [8726] Microsoft Publisher 2003 PUB File Eingabe memory corruption
5116| [8723] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 XML File spoofing
5117| [7643] Microsoft Windows Server 2008 R2/Server 2012 NFS Server NULL Pointer Dereference denial of service
5118| [7642] Microsoft Exchange 2007/2010 Outlook Web Access vspdx.dll) privilege escalation
5119| [7641] Microsoft Windows Server 2003/Server 2008/Vista/XP DirectShow Quartz.dll memory corruption
5120| [8589] Microsoft System Center Operations Manager 2007 R2/2007 SP1 ViewTypeManager.aspx cross site scripting
5121| [7252] Microsoft System Center Operations Manager 2007 ExecuteTask.aspx cross site scripting
5122| [7251] Microsoft System Center Operations Manager 2007 cross site scripting
5123| [7248] Microsoft Windows 7/Server 2008 R2 Print Spooler privilege escalation
5124| [7121] Microsoft Exchange 2007/2010 RSS Feed denial of service
5125| [7118] Microsoft Windows Server 2008 R2/Server 2012 IP-HTTPS unknown vulnerability
5126| [62914] Microsoft Office 2003 SP3/2007 SP3/2008/2010 SP1/2011 Spreadsheet Use-After-Free memory corruption
5127| [7058] Microsoft Windows 7/Server 2008 R2 DHCPv6 Message denial of service
5128| [6935] Microsoft Office Excel 2003/2007/2010 Input Sanitizer File Stack-based memory corruption
5129| [6934] Microsoft Office Excel 2003/2007/2010 Input Sanitizer memory corruption
5130| [6933] Microsoft Office Excel 2003/2007/2010 SerAuxErrBar File memory corruption
5131| [6929] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 Web Proxy Setting Auto-Discovery memory corruption
5132| [6927] Microsoft .NET Framework 2.0 SP2/3.5.1 Trusted Code Function information disclosure
5133| [6918] Microsoft Excel 2007 SP2 Input Sanitizer File memory corruption
5134| [6830] Microsoft Word 2007/2010 File memory corruption
5135| [6819] Microsoft Excel 2007 File memory corruption
5136| [6627] Microsoft Windows 7/Server 2008 R2 Kerberos denial of service
5137| [6626] Microsoft SharePoint/Lync/Infopath 2007/2010 HTML Sanitization cross site scripting
5138| [6621] Microsoft Word 2007 PAPX memory corruption
5139| [62239] Microsoft Systems Management Server 2003 Configuration Manager Reflected cross site scripting
5140| [5945] Microsoft Office 2007/2010 Computer Graphics Metafile memory corruption
5141| [5939] Microsoft Windows 7/Server 2003/Server 2008 R2/Vista/XP Print Spooler Service memory corruption
5142| [5938] Microsoft Windows 7/Server 2003/Server 2008 R2/Vista/XP Remote Administration Protocol netapi32.dll RAP Request denial of service
5143| [5933] Microsoft SQL Server 2000/2005/2008/2008 R2 Common Controls TabStrip ActiveX MSCOMCTL.OCX memory corruption
5144| [5932] Microsoft Office 2003/2007/2010 Common Controls TabStrip ActiveX MSCOMCTL.OCX memory corruption
5145| [5654] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP information disclosure
5146| [5653] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP win32k.sys memory corruption
5147| [5652] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP win32k.sys memory corruption
5148| [5650] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP memory corruption
5149| [5649] Microsoft Office 2003/2007/2010 libraries memory corruption
5150| [5645] Microsoft SharePoint 2007/2010/3.0 Reflected cross site scripting
5151| [5643] Microsoft SharePoint 2007/2010 information disclosure
5152| [5642] Microsoft SharePoint 2007 cross site request forgery
5153| [5553] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP OpenType Font atmfd.dll denial of service
5154| [5524] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP memory corruption
5155| [5518] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 memory corruption
5156| [5362] Microsoft Office 2003/2007 GDI+ memory corruption
5157| [5291] Microsoft Visual Studio 2008 Incremental Linker link.exe ConvertRgImgSymToRgImgSymEx memory corruption
5158| [5268] Microsoft Office 2008 on Mac RTF Pfragment File memory corruption
5159| [5080] Microsoft SQL Server 2005/2008/2008R2 CREATE DATABASE sql injection
5160| [5050] Microsoft Office 2007 WPS Converter Heap-based memory corruption
5161| [5049] Microsoft SQL Server 2000/2005/2008 MSCOMCTL.OCX privilege escalation
5162| [5048] Microsoft Office 2003/2007/2010 MSCOMCTL.OCX privilege escalation
5163| [5046] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Windows Authenticode Signature Verification WinVerifyTrust Signature privilege escalation
5164| [4803] Microsoft Windows Server 2003/Server 2008 DNS Server Domain Resource Record Query Parser denial of service
5165| [4802] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Remote Desktop Protocol denial of service
5166| [4798] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Remote Desktop Service memory corruption
5167| [60205] Microsoft .NET Framework 2.0 SP2/3.5.1 Heap-based memory corruption
5168| [4642] Microsoft .NET Framework 2.0 SP2/3.5.1/4 XAML Browser Application memory corruption
5169| [60065] Microsoft Windows 2000 mod_sql unknown vulnerability
5170| [4535] Microsoft Windows Server 2003/XP Object Packager packager.exe privilege escalation
5171| [4534] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Line21 DirectShow Filter Quartz.dll/Qdvd.dll Media File memory corruption
5172| [4533] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Multimedia Library winmm.dll MIDI File memory corruption
5173| [4507] Microsoft .NET Framework 2.0 SP2/3.5 SP1/3.5.1/4.0 Forms Authentication privilege escalation
5174| [59666] Microsoft Publisher 2003/2007 "Publisher memory corruption
5175| [4482] Microsoft Word 2007/2010/2011 Document Parser memory corruption
5176| [4480] Microsoft Excel 2003 memory corruption
5177| [4478] Microsoft Windows Server 2003/XP OLE Objects Memory Management memory corruption
5178| [4477] Microsoft PowerPoint 2007 SP2/2008 OfficeArt Use-After-Free memory corruption
5179| [4474] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Active Directory Query memory corruption
5180| [4473] Microsoft PowerPoint 2007 SP2/2010 DLL-Loader memory corruption
5181| [4471] Microsoft Office 2003/2007 Publisher Out-of-Bounds memory corruption
5182| [4470] Microsoft Office 2003 SP3 memory corruption
5183| [4453] Microsoft Excel 2003 Record Parser memory corruption
5184| [4446] Microsoft Office 2007/2008 OfficeArt Record Parser memory corruption
5185| [4445] Microsoft Office 2007/2010/2011 Word Document Parser memory corruption
5186| [4438] Microsoft Windows 7/Server 2008/Vista TCP/IP Reference Counter denial of service
5187| [5358] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP TrueType Font Handling memory corruption
5188| [59005] Microsoft Host Integration Server 2004 denial of service
5189| [58492] Microsoft SharePoint Server 2007 Spreadsheet memory corruption
5190| [58491] Microsoft Office 2004/2007/2008/2010/2011 Spreadsheet memory corruption
5191| [58490] Microsoft Office Compatibility Pack 2007 Spreadsheet memory corruption
5192| [58489] Microsoft Office 2004/2007/2008/2010/2011 Spreadsheet memory corruption
5193| [58488] Microsoft Office 2007/2010 memory corruption
5194| [4412] Microsoft Office 2003/2007 Library Loader unknown vulnerability
5195| [4411] Microsoft Excel 2003 memory corruption
5196| [4409] Microsoft Windows Server 2003/Server 2008 WINS unknown vulnerability
5197| [58240] Microsoft Visio 2003/2007 memory corruption
5198| [58237] Microsoft Visio 2003/2007/2010 memory corruption
5199| [4396] Microsoft Windows 7/Server 2008/Vista TCP/IP Stack denial of service
5200| [4393] Microsoft Windows Server 2008 DNS Service memory corruption
5201| [4391] Microsoft .NET Framework 2.0 SP2/3.5.1/4 Socket Restriction privilege escalation
5202| [4390] Microsoft Windows Server 2008 Remote Desktop Web Access cross site scripting
5203| [4388] Microsoft Windows 7/Server 2008/Vista File Metadata Parser denial of service
5204| [57691] Microsoft SQL Server 2008 Web Service information disclosure
5205| [57690] Microsoft Excel 2002/2003 Spreadsheet memory corruption
5206| [57689] Microsoft Excel 2002 Spreadsheet memory corruption
5207| [57688] Microsoft Excel 2002 Spreadsheet memory corruption
5208| [57687] Microsoft Excel 2002/2003/2007 Spreadsheet memory corruption
5209| [57686] Microsoft Excel 2002 Spreadsheet memory corruption
5210| [57685] Microsoft Excel 2002/2003/2007 Array Access memory corruption
5211| [57684] Microsoft Excel 2002/2003/2007/2010 Spreadsheet memory corruption
5212| [4369] Microsoft Excel 2002/2003/2007 memory corruption
5213| [4367] Microsoft Windows Server 2008 Hyper-V VMBus denial of service
5214| [4362] Microsoft Windows 7/Server 2008/Vista denial of service
5215| [57420] Microsoft PowerPoint 2002/2003 memory corruption
5216| [4349] Microsoft Office 2004/2007/2008 Presentation File Parser memory corruption
5217| [4348] Microsoft PowerPoint 2002/2003/2007 memory corruption
5218| [57077] Microsoft Excel 2002 Uninitialized Memory memory corruption
5219| [57078] Microsoft Office 2003/2007/Xp docx unknown vulnerability
5220| [57079] Microsoft PowerPoint 2002/2003/2007/2010 memory corruption
5221| [57076] Microsoft Excel 2002/2003 memory corruption
5222| [57075] Microsoft Excel 2002/2003 memory corruption
5223| [57074] Microsoft Excel 2002 memory corruption
5224| [57073] Microsoft Excel 2002/2003/2007/2010 memory corruption
5225| [4334] Microsoft .NET Framework 2.0 SP2/3.5 SP1/3.5.1/4.0 JIT Compiler memory corruption
5226| [4332] Microsoft PowerPoint 2007/2010 memory corruption
5227| [4301] Microsoft Windows Server 2003 SMB Browser Heap-based denial of service
5228| [56475] Microsoft Office 2004/2008 memory corruption
5229| [56414] Microsoft Visio 2002/2003/2007 ELEMENTS.DLL memory corruption
5230| [56413] Microsoft Visio 2002/2003/2007 Exception ORMELEMS.DLL memory corruption
5231| [4298] Microsoft Windows 7/Server 2008 JScript/VBScript Engine information disclosure
5232| [4297] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP OpenType Compact Font Format Driver privilege escalation
5233| [4296] Microsoft Windows Server 2003/XP LSASS Authentication Request unknown vulnerability
5234| [4295] Microsoft Windows 7/Server 2008 Kerberos weak authentication
5235| [4294] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Driver win32k.sys unknown vulnerability
5236| [4293] Microsoft Windows Server 2003/XP Kerberos CRC32 Checksum privilege escalation
5237| [4292] Microsoft Windows Server 2003/XP CSRSS Logoff privilege escalation
5238| [4289] Microsoft Excel 2007 Shape Data Parser memory corruption
5239| [4286] Microsoft PowerPoint 2002 SP3/2003 SP3/2004/2007 SP2/2008 OfficeArt Container Parser memory corruption
5240| [4279] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP MHTML cross site scripting
5241| [56176] Microsoft Windows 7/Server 2003/XP fxscover.exe CDrawPoly::Serialize memory corruption
5242| [55772] Microsoft Publisher 2002 pubconv.dll memory corruption
5243| [55771] Microsoft Publisher 2002/2003/2010 memory corruption
5244| [55765] Microsoft Office 2003/Xp Integer memory corruption
5245| [55764] Microsoft Office 2003/Xp memory corruption
5246| [55750] Microsoft Publisher 2002/2003 pubconv.dll memory corruption
5247| [55749] Microsoft Publisher 2002/2003/2007/2010 pubconv.dll memory corruption
5248| [55748] Microsoft Publisher 2002/2003/2007 pubconv.dll memory corruption
5249| [4230] Microsoft Exchange 2007 on 64-bit RPC store.exe MAPI Request denial of service
5250| [4229] Microsoft SharePoint 2007 Document Conversion Launcher Service Eingabeung\xC3\xBCltigkeit
5251| [4228] Microsoft Windows Server 2008 Hyper-V VMBus denial of service
5252| [4224] Microsoft Windows 7/Server 2008/Vista Consent User Interface privilege escalation
5253| [4231] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Driver win32k.sys GreEnableEUDC denial of service
5254| [55420] Microsoft Office 2007/2010 memory corruption
5255| [55419] Microsoft Office 2004/2008/2011/Xp memory corruption
5256| [55412] Microsoft PowerPoint Viewer 2007 memory corruption
5257| [55411] Microsoft PowerPoint 2002/2003 memory corruption
5258| [4204] Microsoft Windows Server 2008 Color Control Panel Eingabeung\xC3\xBCltigkeit
5259| [54995] Microsoft Office 2004/2008 memory corruption
5260| [54994] Microsoft Office 2004/2008 Out-of-Bounds memory corruption
5261| [54993] Microsoft Office Compatibility Pack 2007 memory corruption
5262| [54992] Microsoft Excel 2002 memory corruption
5263| [54991] Microsoft Office 2004 Future memory corruption
5264| [54990] Microsoft Office 2004 memory corruption
5265| [54989] Microsoft Office 2004/2008 memory corruption
5266| [54988] Microsoft Excel 2002 memory corruption
5267| [54987] Microsoft Excel 2002 memory corruption
5268| [54986] Microsoft Excel 2002/2003 memory corruption
5269| [54985] Microsoft Office Compatibility Pack 2003/2004/2007/2008 memory corruption
5270| [54984] Microsoft Office 2004/2008 memory corruption
5271| [54983] Microsoft Excel 2002 Integer memory corruption
5272| [54980] Microsoft Word 2002/2003 memory corruption
5273| [54979] Microsoft Word 2002 memory corruption
5274| [54978] Microsoft Word 2002 memory corruption
5275| [54977] Microsoft Word 2002 Heap-based memory corruption
5276| [54976] Microsoft Word 2002 memory corruption
5277| [54975] Microsoft Word 2002 memory corruption
5278| [54974] Microsoft Word 2002 memory corruption
5279| [54973] Microsoft Word 2002 memory corruption
5280| [54972] Microsoft Word 2002 memory corruption
5281| [54971] Microsoft Word 2002 memory corruption
5282| [4197] Microsoft SharePoint 2007/3.0 cross site scripting
5283| [4196] Microsoft Word 2002/2003/2007/2010 Stack-based memory corruption
5284| [4194] Microsoft Windows 7/Server 2008/Vista SChannel Client Certificate Request denial of service
5285| [54774] Microsoft Word 2003 word_crash_11.8326.8324_poc.doc denial of service
5286| [54757] Microsoft SharePoint Server 2007 HTML Sanitization SafeHTML cross site scripting
5287| [4186] Microsoft Outlook 2002/2003/2007 Content Parser Heap-based memory corruption
5288| [54584] Microsoft Visual C++ 2005 AtlTraceTool8.exe unknown vulnerability
5289| [54554] Microsoft Groove 2007 mso.dll memory corruption
5290| [4187] Microsoft Windows 7/Server 2008/Vista TCP/IP Stack Ipv4SetEchoRequestCreate denial of service
5291| [54322] Microsoft Word 2002/2003 memory corruption
5292| [54321] Microsoft Office Compatibility Pack 2007 memory corruption
5293| [54320] Microsoft Office Compatibility Pack 2007 memory corruption
5294| [54319] Microsoft Office Compatibility Pack 2007 memory corruption
5295| [54318] Microsoft .NET Framework 2.0 SP1/2.0 SP2/3.5/3.5 SP1/3.5.1 Interfaces memory corruption
5296| [4165] Microsoft Windows 7/Server 2008/Vista TCP/IP Stack denial of service
5297| [4162] Microsoft Windows 7/Server 2008/Vista Kernel memory corruption
5298| [4159] Microsoft Excel 2002/2003 SXDB PivotTable Cache Data Record memory corruption
5299| [4149] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Shell Shortcut Parser memory corruption
5300| [54083] Microsoft Access 2003 ActiveX Control ACCWIZ.dll memory corruption
5301| [4146] Microsoft Outlook 2002/2003/2007 SMB Attachment PR_ATTACH_METHOD memory corruption
5302| [4145] Microsoft Access 2003/2007 ActiveX ACCWIZ.dll memory corruption
5303| [54617] Microsoft Outlook Web Access up to 2007 cross site request forgery
5304| [4151] Microsoft Windows Server 2008/Vista NtUserCheckAccessForIntegrityLevel memory corruption
5305| [53591] Microsoft Windows Server 2003 GetServerName cross site scripting
5306| [53505] Microsoft Excel 2002/2007 memory corruption
5307| [53501] Microsoft Excel 2002 memory corruption
5308| [53500] Microsoft Excel 2002 memory corruption
5309| [53499] Microsoft Excel 2002 memory corruption
5310| [53495] Microsoft Excel 2002/2003/2007 memory corruption
5311| [53494] Microsoft Excel 2002 Stack-based memory corruption
5312| [53504] Microsoft Excel 2002 memory corruption
5313| [53503] Microsoft Excel 2002 Stack-Based memory corruption
5314| [53502] Microsoft Excel 2002 Heap-based memory corruption
5315| [53498] Microsoft Excel 2002 Stack-based memory corruption
5316| [53497] Microsoft Excel 2002 memory corruption
5317| [53496] Microsoft Excel 2002 memory corruption
5318| [53493] Microsoft Excel 2002/2003/2007 memory corruption
5319| [4133] Microsoft Office 2003/2007/Xp COM Object Instantiator memory corruption
5320| [53366] Microsoft ASP.NET 2.0 cross site scripting
5321| [53385] Microsoft Exchange Server 2007 Outlook Web Access cross site scripting
5322| [53164] Microsoft Office 2003/2007/Xp ActiveX Control VBE6.DLL memory corruption
5323| [53054] Microsoft VISIO 2002/2003/2007 VISIODWG.DLL memory corruption
5324| [4125] Microsoft SharePoint 2007/3.0 help.aspx cross site scripting
5325| [52777] Microsoft Publisher 2002/2003/2007 memory corruption
5326| [52773] Microsoft Visio 2002/2003/2007 memory corruption
5327| [52772] Microsoft Visio 2002/2003/2007 memory corruption
5328| [4107] Microsoft Windows 7/Server 2008 Kernel denial of service
5329| [4103] Microsoft Windows Server 2003 Media Services Stack-based memory corruption
5330| [52543] Microsoft Virtual PC 2007 unknown vulnerability
5331| [52148] Microsoft Office 2004/2007/2008 Uninitialized Memory memory corruption
5332| [52147] Microsoft Office 2004/2007/2008 Spreadsheet Uninitialized Memory memory corruption
5333| [52146] Microsoft Office 2004/2007/2008 Spreadsheet Heap-based memory corruption
5334| [52145] Microsoft Office 2004/2007/2008 Spreadsheet Heap-based memory corruption
5335| [52144] Microsoft Office 2004/2007/2008 Spreadsheet memory corruption
5336| [52143] Microsoft Office 2004/2007/2008 Spreadsheet memory corruption
5337| [4090] Microsoft Excel 2002/2003/2007 memory corruption
5338| [52036] Microsoft Windows 2000 MsgBox memory corruption
5339| [51995] Microsoft SharePoint Server up to 2006 cross site scripting
5340| [51810] Microsoft Office 2004/Xp MSO.DLL memory corruption
5341| [51802] Microsoft PowerPoint 2003 Stack-based memory corruption
5342| [51801] Microsoft PowerPoint 2003 Stack-based memory corruption
5343| [51800] Microsoft PowerPoint 2002/2003 Use-After-Free memory corruption
5344| [51799] Microsoft PowerPoint 2002/2003 memory corruption
5345| [51798] Microsoft PowerPoint 2002/2003 Heap-based memory corruption
5346| [4082] Microsoft PowerPoint 2002 SP3 memory corruption
5347| [54550] Microsoft PowerPoint 2007 rpawinet.dll memory corruption
5348| [54556] Microsoft Visio 2003 mfc71enu.dll unknown vulnerability
5349| [51497] Microsoft Windows Live Messenger 2009 ActiveX Control msnmsgr.exe denial of service
5350| [51133] Microsoft Windows 2000 SP4/Server 2003 SP2/SP3/XP SP2 memory corruption
5351| [51074] Microsoft Office 2002/2003 Integer memory corruption
5352| [4069] Microsoft Project 2003/2007 Project Memory Validator memory corruption
5353| [50794] Microsoft Office 2004/2008 Spreadsheet memory corruption
5354| [50793] Microsoft Office 2004/2008 Spreadsheet memory corruption
5355| [50792] Microsoft Office 2004/2008 Spreadsheet memory corruption
5356| [50791] Microsoft Office 2004/2008 Spreadsheet memory corruption
5357| [50790] Microsoft Office 2004/2008 Spreadsheet Heap-based memory corruption
5358| [50788] Microsoft Office 2004/2008 Spreadsheet memory corruption
5359| [50787] Microsoft Office 2004/2008 Spreadsheet memory corruption
5360| [50786] Microsoft Windows 2000 llssrv.exe memory corruption
5361| [50789] Microsoft Office 2004/2008 Spreadsheet memory corruption
5362| [4056] Microsoft Word 2002/2003 File Information Block Parser Stack-based memory corruption
5363| [50660] Microsoft SharePoint Server 2007 unknown vulnerability
5364| [50443] Microsoft PowerPoint 2007 Integer memory corruption
5365| [50432] Microsoft .NET Framework 2.0/2.0 SP1/2.0 SP2/3.5/3.5 SP1 memory corruption
5366| [49866] Microsoft Windows Server 2003 memory corruption
5367| [4031] Microsoft Windows Server 2008/Vista SMB Processor EducatedScholar memory corruption
5368| [4030] Microsoft Windows Server 2008/Vista Wireless LAN AutoConfig Service Heap-based memory corruption
5369| [4029] Microsoft Windows 2000/XP TCP/IP Window Size denial of service
5370| [49745] Microsoft Windows Server 2003 denial of service
5371| [49395] Microsoft Office 2000/2003/XP Office Web Components Heap-based memory corruption
5372| [49394] Microsoft Windows Server 2003 memory corruption
5373| [49389] Microsoft Office 2000/2003/XP Office Web Components memory corruption
5374| [49390] Microsoft Office 2000/2003/XP Office Web Components memory corruption
5375| [49198] Microsoft Visual Studio 2005 information disclosure
5376| [49047] Microsoft Virtual Server 2005 privilege escalation
5377| [49046] Microsoft Windows Server 2003 quartz.dll memory corruption
5378| [49045] Microsoft Windows Server 2003 quartz.dll memory corruption
5379| [49044] Microsoft ISA Server 2006 privilege escalation
5380| [3999] Microsoft Office 2007 Pointer memory corruption
5381| [4000] Microsoft Office 2003/Sp3/Xp Web Components memory corruption
5382| [48894] Microsoft Windows Server 2003 msvidctl.dll memory corruption
5383| [48572] Microsoft PowerPoint 2002 FL21WIN.DLL memory corruption
5384| [48517] Microsoft Windows 2000 Memory Leak memory corruption
5385| [48516] Microsoft Windows Server 2008 unknown vulnerability
5386| [48512] Microsoft Windows Server 2008 unknown vulnerability
5387| [48515] Microsoft Office Word Viewer 2003 memory corruption
5388| [48514] Microsoft Office Word Viewer 2003 Stack-based memory corruption
5389| [48554] Microsoft Excel 2000/2003/2007 memory corruption
5390| [48157] Microsoft PowerPoint 2002 Sound memory corruption
5391| [48156] Microsoft PowerPoint 2000 Stack-based memory corruption
5392| [48154] Microsoft PowerPoint 2002 Sound PP7X32.DLL memory corruption
5393| [48152] Microsoft PowerPoint 2002 PP4X32.DLL memory corruption
5394| [48150] Microsoft PowerPoint 2002 Sound memory corruption
5395| [48147] Microsoft PowerPoint 2002 Sound memory corruption
5396| [48146] Microsoft PowerPoint 2002 Integer memory corruption
5397| [48155] Microsoft PowerPoint 2002 Notes Container Heap-based memory corruption
5398| [48153] Microsoft PowerPoint 2002 Sound memory corruption
5399| [48151] Microsoft PowerPoint 2002 Stack-based memory corruption
5400| [48149] Microsoft PowerPoint 2002 memory corruption
5401| [48148] Microsoft PowerPoint 2002 Sound memory corruption
5402| [3974] Microsoft PowerPoint 2000/2002/2003 Sound Data Stack-based memory corruption
5403| [3973] Microsoft PowerPoint 2000/2002/2003 Notes Container Stack-based memory corruption
5404| [3972] Microsoft PowerPoint 2000/2002/2003 BuildList memory corruption
5405| [3971] Microsoft PowerPoint 2000/2002/2003 Object Stack-based memory corruption
5406| [3970] Microsoft PowerPoint 2000/2002/2003 Paragraph Stack-based memory corruption
5407| [3969] Microsoft PowerPoint 2000/2002/2003 Atom Stack-based memory corruption
5408| [47719] Microsoft Windows 2000 Stack-based memory corruption
5409| [47720] Microsoft Internet Security And Acceleration Server 2006 Forms Authentication cookieauth.dll cross site scripting
5410| [47716] Microsoft Office Converter Pack 2003 WPFT632.CNV memory corruption
5411| [47715] Microsoft Windows 2000 Wordpad memory corruption
5412| [47718] Microsoft Excel 2000/2002/2003/2007 Spreadsheet memory corruption
5413| [3960] Microsoft Windows 2000/Server 2003/XP DirectShow MJPEG memory corruption
5414| [3952] Microsoft ISA Server 2004/2006 denial of service
5415| [3946] Microsoft PowerPoint 2000/2002/2003/2004 memory corruption
5416| [47091] Microsoft Windows Server 2008 unknown vulnerability
5417| [47090] Microsoft Windows Server 2008 unknown vulnerability
5418| [3939] Microsoft Windows 2000 DNS spoofing
5419| [3938] Microsoft Windows 2000 SSL weak authentication
5420| [3937] Microsoft Windows 2000 memory corruption
5421| [3932] Microsoft Excel 2000/2002/2003/2004/2007 Object Reference memory corruption
5422| [46620] Microsoft Windows Live Messenger 2009 msnmsgr.exe denial of service
5423| [46455] Microsoft Exchange Server 2007 denial of service
5424| [46454] Microsoft Exchange Server 2007 memory corruption
5425| [46453] Microsoft Visio 2002/2003/2007 memory corruption
5426| [46452] Microsoft Visio 2002/2003/2007 memory corruption
5427| [46451] Microsoft Visio 2002/2003/2007 memory corruption
5428| [46327] Microsoft Word 2007 information disclosure
5429| [45758] Microsoft Money 2006 ActiveX Control prtstb06.dll denial of service
5430| [45381] Microsoft Windows Server 2008/Vista SP1 Explorer memory corruption
5431| [45380] Microsoft Windows Server 2008/Vista SP1 Search memory corruption
5432| [45379] Microsoft Office SharePoint Server 2007 denial of service
5433| [3896] Microsoft SQL Server up to 2005 sp_replwritetovarbin memory corruption
5434| [3892] Microsoft Excel 2000/2002/2003 Formula memory corruption
5435| [3891] Microsoft Excel 2000/2002/2003 memory corruption
5436| [3890] Microsoft Excel 2000/2002/2003 NAME Index memory corruption
5437| [3889] Microsoft Word 2000/2002/2003/2007 Table Property Stack-based memory corruption
5438| [3888] Microsoft Word 2000/2002/2003/2007 RTF Stylesheet memory corruption
5439| [3887] Microsoft Word 2000/2002/2003/2007 memory corruption
5440| [3886] Microsoft Word 2000/2002/2003/2007 ControlWord Heap-based memory corruption
5441| [3885] Microsoft Word 2000/2002/2003/2007 memory corruption
5442| [3884] Microsoft Word 2000/2002/2003/2007 memory corruption
5443| [3883] Microsoft Word 2000/2002/2003/2007 RTF Heap-based memory corruption
5444| [3882] Microsoft Word 2000/2002/2003/2007 LFO memory corruption
5445| [3880] Microsoft Visual Basic up to 2003 ActiveX Control Mschrt20.ocx memory corruption
5446| [3879] Microsoft Visual Basic up to 2003 ActiveX Control mscomct2.ocx memory corruption
5447| [3878] Microsoft Visual Basic up to 2003 ActiveX Control mshflxgd.ocx memory corruption
5448| [3877] Microsoft Visual Basic up to 2003 ActiveX Control msflxgrd.ocx memory corruption
5449| [3876] Microsoft Visual Basic up to 2003 ActiveX Control msdatgrd.ocx memory corruption
5450| [45197] Microsoft Windows 2000 nskey.dll memory corruption
5451| [45063] Microsoft Windows Server 2003 Active Directory unknown vulnerability
5452| [45040] Microsoft .NET Framework 2.0.50727 Code Access Security unknown vulnerability
5453| [44855] DjVu Activex Control For Microsoft Office 2000 3.0 ActiveX Control DjVu_ActiveX_MSOffice.dll memory corruption
5454| [44665] Microsoft Peachtree Accounting 2004 ActiveX Control PAWWeb11.ocx unknown vulnerability
5455| [44589] Microsoft Exchange Server 2003 Outlook Web Access unknown vulnerability
5456| [3845] Microsoft Windows 2000 SP4 Active Directory memory corruption
5457| [44533] Microsoft Windows 2000 mqsvc.exe memory corruption
5458| [3844] Microsoft Excel 2003 REPT memory corruption
5459| [3843] Microsoft Excel up to 2007 BIFF File Heap-based memory corruption
5460| [3842] Microsoft Excel 2003 VBA Performance Cache Stack-based memory corruption
5461| [44405] Microsoft Digital Image 2006 ActiveX Control PipPPush.DLL unknown vulnerability
5462| [44047] Microsoft SQL Server 2000 ActiveX Control SQLVDIRLib.SQLVDirControl memory corruption
5463| [43981] Microsoft Organization Chart 2.00 orgchart.exe memory corruption
5464| [43957] Microsoft Office 2003/2007/Xp gdiplus.dll memory corruption
5465| [43956] Microsoft Office 2003/2007/Xp gdiplus.dll memory corruption
5466| [43955] Microsoft Office 2003/2007/Xp gdiplus.dll memory corruption
5467| [43952] Microsoft Office 2003/2007/Xp URI memory corruption
5468| [43676] Microsoft Windows 2000/Server 2003/Vista/XP memory corruption
5469| [43675] Microsoft Windows 2000/Server 2003/Vista/XP of memory corruption
5470| [43662] Microsoft PowerPoint Viewer 2000 SP3/2002 SP3/2003 SP2/2007 SP1 memory corruption
5471| [43661] Microsoft PowerPoint Viewer 2003 memory corruption
5472| [43660] Microsoft PowerPoint Viewer 2003 Integer memory corruption
5473| [43657] Microsoft Office 2000/2003/Xp memory corruption
5474| [43654] Microsoft SharePoint Server 2007 memory corruption
5475| [43653] Microsoft Office 2000/2002/2004/2008 memory corruption
5476| [43652] Microsoft Office 2000/2002/2003/2004/2008 memory corruption
5477| [3797] Microsoft Windows Server 2008/Vista IPsec Policy Designfehler
5478| [3796] Microsoft Office 2000 WPG memory corruption
5479| [3795] Microsoft Office 2000/2003/Xp BMP Image BMPIMP32.FLT memory corruption
5480| [3794] Microsoft Office 2000/2003/Xp PICT bits_per_pixel memory corruption
5481| [3793] Microsoft Office 2000/2003/Xp PICT memory corruption
5482| [3792] Microsoft Office 2000 EPS File memory corruption
5483| [3783] Microsoft Word 2002 memory corruption
5484| [43103] Microsoft Exchange Srv 2007 Sp1 Outlook Web Access cross site scripting
5485| [43102] Microsoft Windows 2000 SP4/Server 2003 SP2/Server 2008 DNS Cache privilege escalation
5486| [3778] Microsoft Exchange 2003/2007 Outlook Web Access cross site scripting
5487| [3777] Microsoft Windows Server 2008/Vista SP1 Explorer memory corruption
5488| [43087] Microsoft Office Snapshot Viewer ActiveX up to Office 2003 Snapshot Viewer ActiveX Control snapview.ocx memory corruption
5489| [43096] Microsoft Publisher 2003/2007 Crypto API unknown vulnerability
5490| [42816] Microsoft Word 2000/2003 memory corruption
5491| [42732] Microsoft Windows Server 2003/Vista/XP denial of service
5492| [42731] Microsoft Windows Server 2003 denial of service
5493| [3732] Microsoft Windows 2000/Server 2003 WINS memory corruption
5494| [3701] Microsoft Word 2003 CSS Heap-based memory corruption
5495| [3700] Microsoft Word 2003 RTF Document Heap-based memory corruption
5496| [42065] Microsoft SharePoint Server 2.0 Rich Text Editor cross site scripting
5497| [41881] Microsoft Office 2003/2007/2007 Sp1/Xp memory corruption
5498| [41880] Microsoft Project 2000/2002/2003 memory corruption
5499| [41879] Microsoft Windows 2000/Server 2003/Vista Stack-based memory corruption
5500| [41878] Microsoft Windows 2000/Server 2003/Vista spoofing
5501| [41877] Microsoft Windows Server 2003 vbscript.dll memory corruption
5502| [3671] Microsoft Visio 2002/2003/2003 Sp3/2007/2007 Sp1 memory corruption
5503| [3670] Microsoft Visio 2002/2003/2003 Sp3/2007/2007 Sp1 Object memory corruption
5504| [41455] Microsoft Office 2000/2003/2004/Xp memory corruption
5505| [41454] Microsoft Excel 2000/2002/2003/2007 memory corruption
5506| [41453] Microsoft Excel 2000/2002/2003 memory corruption
5507| [41452] Microsoft Excel 2000/2002/2003/2007 memory corruption
5508| [41451] Microsoft Excel 2000/2002/2003 memory corruption
5509| [41450] Microsoft Excel 2000 memory corruption
5510| [41449] Microsoft Excel 2000/2002/2003 memory corruption
5511| [41448] Microsoft Office 2000/Xp Office Web Components memory corruption
5512| [3648] Microsoft Excel 2003 memory corruption
5513| [3647] Microsoft Outlook up to 2007 mailto URI memory corruption
5514| [41003] Microsoft Office 2000/2003/2004/Xp memory corruption
5515| [41002] Microsoft Office 2000/2003/Xp memory corruption
5516| [41001] Microsoft Works 2005/8.0 wkcvqd01.dll memory corruption
5517| [41000] Microsoft Works 2005/8.0 memory corruption
5518| [40998] Microsoft Publisher 2000/2002/2003 memory corruption
5519| [40994] Microsoft Works 2005/8.0 wkcvqd01.dll memory corruption
5520| [40987] Microsoft Windows 2000 denial of service
5521| [40736] Microsoft ActiveX 2.0 ActiveX Control privilege escalation
5522| [3552] Microsoft Excel 2000/2002/2003 File memory corruption
5523| [40242] Microsoft Publisher 2000/2002/2003/2007 Crash denial of service
5524| [40020] Microsoft Office 2007 ZIP Container unknown vulnerability
5525| [39769] Microsoft Windows 2000 cryptgenrandom weak encryption
5526| [39749] Microsoft Windows 2000 msjet40.dll memory corruption
5527| [39655] Microsoft Windows Server 2003 spoofing
5528| [39324] Microsoft Windows Mobile 2005 SMS unknown vulnerability
5529| [3373] Microsoft Word 2000/2002 memory corruption
5530| [38999] Microsoft Windows Server 2003 explorer.exe denial of service
5531| [38899] Microsoft ISA Server 2004 information disclosure
5532| [38728] Microsoft SQL Server 2005 Enterprise Manager sqldmo.dll memory corruption
5533| [38326] Microsoft Windows 2000 attemptwrite memory corruption
5534| [3241] Microsoft Excel 2000/2003/2004/XP SP3 rtWnDesk memory corruption
5535| [3223] Microsoft Windows Server 2003/XP URI privilege escalation
5536| [3212] Microsoft DirectX February 2006 RLE Compression Targa Files Heap-based memory corruption
5537| [37739] Microsoft Excel 2000/2002/2003/2004/2007 memory corruption
5538| [37738] Microsoft Office 2002/2003 memory corruption
5539| [3176] Microsoft Excel 2000/2002/2003/2007 File Attribute memory corruption
5540| [3175] Microsoft Excel 2000/2002/2003/2007 Active Worksheet memory corruption
5541| [3174] Microsoft Excel 2000/2002/2003/2007 Version Information memory corruption
5542| [3172] Microsoft Office Publisher 2007 Pointer memory corruption
5543| [37566] Microsoft Excel 2003 unknown vulnerability
5544| [37526] Microsoft Windows 2000/Server 2003 denial of service
5545| [37248] Microsoft Visio 2002 Packaging memory corruption
5546| [37251] Microsoft Windows 2000 memory corruption
5547| [3119] Microsoft Visio 2002 Object memory corruption
5548| [3118] Microsoft Visio 2002 Data memory corruption
5549| [37093] Microsoft Windows Server 2003 Error Message unknown vulnerability
5550| [37010] Microsoft Office 2000 ActiveX Control ouactrl.ocx memory corruption
5551| [36628] Microsoft Word 2000/2002/2003/2004 winword.exe memory corruption
5552| [36616] Microsoft Works 2004/2005/2006 memory corruption
5553| [36621] Microsoft Exchange Server 2000 Integer denial of service
5554| [36620] Microsoft Exchange Server 2000 Outlook Web Access cross site scripting
5555| [36619] Microsoft Exchange Server 2000/2003/2007 MIME Email memory corruption
5556| [36618] Microsoft Exchange Server 2000 NULL Pointer Dereference denial of service
5557| [36617] Microsoft Excel 2000/2002/2003/2004 memory corruption
5558| [36623] Microsoft BizTalk Server 2004 ActiveX Control capicom.dll memory corruption
5559| [3067] Microsoft Office 2000/2003/2004/2007/Xp Drawing Object memory corruption
5560| [3065] Microsoft Excel 2000/2002/2003/2007 Filter Stack-based memory corruption
5561| [3064] Microsoft Excel 2000/2002/2003/2004/2007 set Font memory corruption
5562| [3063] Microsoft Excel 2000/2002/2003/2007 BIFF Record Stack-based memory corruption
5563| [3012] Microsoft Windows 2000/Server 2003 DNS Service Stack-based memory corruption
5564| [36039] Microsoft Content Management Server 2001 memory corruption
5565| [36052] Microsoft Windows 2000 Heap-based memory corruption
5566| [36051] Microsoft Word 2007 file798-1.doc memory corruption
5567| [36050] Microsoft Word 2007 file789-1.doc memory corruption
5568| [36040] Microsoft Content Management Server 2001 cross site scripting
5569| [3004] Microsoft Windows up to 2003/XP URL Parser memory corruption
5570| [36041] Microsoft .NET Framework 2.0.50727.42 cross site scripting
5571| [36002] Microsoft Windows 2000/XP denial of service
5572| [2990] Microsoft Windows 2000/Vista/XP Animated Cursor Stack-based memory corruption
5573| [36515] Microsoft Windows 2000/Server 2003/XP memory corruption
5574| [35846] Microsoft Windows 2000/Server 2003 Default Configuration information disclosure
5575| [35373] Microsoft Excel 2003 denial of service
5576| [35372] Microsoft Office 2003 denial of service
5577| [35206] Microsoft Windows Server 2003/XP Crash denial of service
5578| [35161] Microsoft ISA Server 2004 unknown vulnerability
5579| [35236] Microsoft Publisher 2007 memory corruption
5580| [2939] Microsoft Word 2000 memory corruption
5581| [34994] Microsoft Windows 2000 OLE Dialog memory corruption
5582| [34993] Microsoft Office 2000/2003/Xp memory corruption
5583| [35001] Microsoft Office 2000/2003/2004/Xp memory corruption
5584| [35000] Microsoft Word 2000/2002/2003 memory corruption
5585| [2933] Microsoft Windows 2000 SP4/Server 2003 SP1/XP SP2 OLE Dialog Stack-based memory corruption
5586| [2894] Microsoft Office 2000/2003/2004/Xp Undefined String Format String
5587| [2884] Microsoft Word 2000/2002/2003 memory corruption
5588| [34321] Microsoft Office 2000/2003/2004/Xp Spreadsheet Heap-based memory corruption
5589| [34320] Microsoft Office 2000/2003/2004/Xp memory corruption
5590| [34319] Microsoft Office 2000/2003/2004/Xp memory corruption
5591| [34318] Microsoft Office 2000/2003/2004/Xp memory corruption
5592| [34322] Microsoft Office 2000/2003/Xp memory corruption
5593| [2811] Microsoft Windows 2000/Server 2003/XP VML Vector Markup Language Integer memory corruption
5594| [2810] Microsoft Outlook 2000/2002/2003 Office Saved Search OSS File memory corruption
5595| [2809] Microsoft Outlook 2000/2002/2003 Header denial of service
5596| [2808] Microsoft Outlook 2000/2002/2003 Meeting VEVENT memory corruption
5597| [2807] Microsoft Excel 2000/2002/2003 XLS File memory corruption
5598| [34126] Microsoft Office 2003 memory corruption
5599| [34122] Microsoft Office Web Components 2000 memory corruption
5600| [2789] Microsoft Windows 2000/XP RPC Request NetrWkstaUserEnum denial of service
5601| [2765] Microsoft Project Server 2003 pdsrequest.asp weak authentication
5602| [33851] Microsoft Word 2000/2002/2003 12122006-djtest.doc memory corruption
5603| [2739] Microsoft Windows 2000 Remote Installation Service Fehlende Authentifizierung
5604| [2738] Microsoft Windows 2000/Server 2003/XP SNMP memory corruption
5605| [2737] Microsoft Windows Server 2003/XP Manifest denial of service
5606| [33766] Microsoft Word 2000/2002/2003 memory corruption
5607| [2718] Microsoft Word 2000/2002/2003 DOC Document memory corruption
5608| [2717] Microsoft Windows 2000 Print Spooler Memory Consumption denial of service
5609| [2689] Microsoft Windows up to 2000 SP4 Active Directory denial of service
5610| [2688] Microsoft Windows 2000/Server 2003/XP Client Service for Netware denial of service
5611| [2687] Microsoft Windows 2000/Server 2003/XP Agent ActiveX ACF File Heap-based memory corruption
5612| [2686] Microsoft Windows 2000/Server 2003/XP Client Service for Netware memory corruption
5613| [2684] Microsoft Windows 2000/XP Workstation Service Stack-based memory corruption
5614| [2659] Microsoft Windows 2000/XP GDI Crash memory corruption
5615| [2655] Microsoft Windows 2000/Server 2003/XP XML Core Services memory corruption
5616| [33067] Microsoft Visual Studio .net 2005 ActiveX Control wmiscriptutils.dll memory corruption
5617| [2610] Microsoft PowerPoint 2003 PPT Document NULL Pointer Dereference denial of service
5618| [32693] Microsoft Word 2004 memory corruption
5619| [32686] Microsoft Office 2000/2001/2003/2004 Integer memory corruption
5620| [32690] Microsoft Office 2000/2003/2004/Xp memory corruption
5621| [32676] Microsoft Office 2000/2001/2003/2004 memory corruption
5622| [32675] Microsoft Office 2000/2003/2004/Xp memory corruption
5623| [32694] Microsoft Windows 2000 memory corruption
5624| [32689] Microsoft Excel 2000/2002/2003/2004/XP memory corruption
5625| [32688] Microsoft Excel 2000/2002/2003/2004/XP memory corruption
5626| [32687] Microsoft Word 2000/2002 memory corruption
5627| [32685] Microsoft Office 2000/2001/2003/2004 memory corruption
5628| [2601] Microsoft Windows Server 2003/XP IPv6 Stack denial of service
5629| [2600] Microsoft Windows Server 2003/XP IPv6 Stack TCP denial of service
5630| [2599] Microsoft Windows Server 2003/XP IPv6 Stack ICMP denial of service
5631| [2598] Microsoft Windows Server 2003/XP Object Packager privilege escalation
5632| [2597] Microsoft Office 2003/Xp Smart-Tag Parser memory corruption
5633| [2596] Microsoft Office 2000/2003/2004/Xp Value Read memory corruption
5634| [2595] Microsoft Office 2000/2001/2003/2004 Diagram Value memory corruption
5635| [2594] Microsoft Office 2000/2001/2003/2004 Document memory corruption
5636| [2593] Microsoft ASP.NET 2.0 cross site scripting
5637| [141652] Microsoft Windows up to Server 2019 Common Log File System Driver information disclosure
5638| [141639] Microsoft SharePoint Foundation 2013 SP1 cross site request forgery
5639| [141637] Microsoft Windows up to Server 2019 AppX Deployment Server privilege escalation
5640| [141636] Microsoft ASP.NET Core 2.1/2.2/3.0 Project Template privilege escalation
5641| [141635] Microsoft .NET Core 2.1/2.2 denial of service
5642| [141633] Microsoft Excel up to 2019 memory corruption
5643| [141631] Microsoft Windows up to Server 2019 SMB Client Driver information disclosure
5644| [141630] Microsoft Windows up to Server 2019 denial of service
5645| [141629] Microsoft Windows up to Server 2019 Update Delivery Optimization privilege escalation
5646| [141627] Microsoft Windows up to Server 2019 GDI information disclosure
5647| [141626] Microsoft Windows up to Server 2019 Win32k memory corruption
5648| [141621] Microsoft Windows up to Server 2019 Kernel information disclosure
5649| [141620] Microsoft Windows up to Server 2019 Active Directory Federation Services cross site scripting
5650| [141619] Microsoft Windows up to Server 2019 ALPC privilege escalation
5651| [141618] Microsoft Windows up to Server 2019 hdAudio.sys privilege escalation
5652| [141617] Microsoft Windows up to Server 2019 Store Installer privilege escalation
5653| [141616] Microsoft Windows up to Server 2019 ALPC privilege escalation
5654| [141615] Microsoft Windows up to Server 2019 Winlogon privilege escalation
5655| [141614] Microsoft Windows up to Server 2019 Compatibility Appraiser privilege escalation
5656| [141611] Microsoft Office up to 2019 Security Feature privilege escalation
5657| [141610] Microsoft Excel up to 2019 information disclosure
5658| [141609] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
5659| [141608] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site request forgery
5660| [141607] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016/2019 privilege escalation
5661| [141606] Microsoft Windows up to Server 2019 Win32k memory corruption
5662| [141605] Microsoft Windows up to Server 2019 Hyper-V information disclosure
5663| [141604] Microsoft Windows up to Server 2019 AppX Deployment Server privilege escalation
5664| [141603] Microsoft Windows up to Server 2019 GDI information disclosure
5665| [141602] Microsoft Windows up to Server 2019 DirectWrite information disclosure
5666| [141601] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5667| [141600] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5668| [141599] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5669| [141598] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5670| [141597] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5671| [141596] Microsoft Windows up to Server 2019 DirectWrite information disclosure
5672| [141595] Microsoft Windows up to Server 2019 DirectWrite information disclosure
5673| [141594] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5674| [141593] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5675| [141592] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5676| [141591] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5677| [141590] Microsoft Windows up to Server 2019 Text Service Framework command injection
5678| [141589] Microsoft Exchange Server 2016 CU12/2016 CU13/2019 CU1/2019 CU2 denial of service
5679| [141583] Microsoft Lync Server 2013 Conference directory traversal
5680| [141581] Microsoft Windows up to Server 2016 Hyper-V denial of service
5681| [141580] Microsoft Windows up to Server 2019 Transaction Manager information disclosure
5682| [141579] Microsoft Windows up to Server 2016 DirectX information disclosure
5683| [141577] Microsoft Windows up to Server 2019 Common Log File System Driver privilege escalation
5684| [141575] Microsoft Windows up to Server 2019 lnk File privilege escalation
5685| [141564] Microsoft SharePoint Enterprise Server 2010 SP1/2013 SP1/2016/2019 Markup Application Package privilege escalation
5686| [141561] Microsoft Windows up to Server 2019 Remote Desktop privilege escalation
5687| [141560] Microsoft Windows up to Server 2019 Remote Desktop privilege escalation
5688| [139972] Microsoft Windows up to Server 2019 HTTP2 HTTP.sys denial of service
5689| [139971] Microsoft Windows up to Server 2019 HTTP2 HTTP.sys denial of service
5690| [139970] Microsoft Windows up to Server 2019 HTTP2 HTTP.sys denial of service
5691| [139969] Microsoft Windows up to Server 2019 HTTP2 HTTP.sys denial of service
5692| [139968] Microsoft Windows up to Server 2019 HTTP2 HTTP.sys denial of service
5693| [139965] Microsoft Windows up to Server 2019 Kernel information disclosure
5694| [139963] Microsoft Windows up to Server 2019 Remote Desktop Protocol information disclosure
5695| [139962] Microsoft Windows up to Server 2019 Remote Desktop Protocol denial of service
5696| [139960] Microsoft Windows up to Server 2019 DHCP Server denial of service
5697| [139958] Microsoft Windows up to Server 2019 DHCP Server denial of service
5698| [139957] Microsoft SharePoint Server 2013 SP1/2016/2019 cross site scripting
5699| [139956] Microsoft SharePoint 2010 SP2/2013 SP1/2016/2019 Session Object information disclosure
5700| [139955] Microsoft Windows up to Server 2019 SyncController.dll privilege escalation
5701| [139949] Microsoft Windows up to Server 2019 XmlLite Runtime XmlLite.dll denial of service
5702| [139946] Microsoft Windows up to Server 2019 Core Shell COM Server Registrar COM Call privilege escalation
5703| [139942] Microsoft Windows up to Server 2019 rpcss.dll memory corruption
5704| [139941] Microsoft Windows up to Server 2019 DirectX memory corruption
5705| [139937] Microsoft Windows up to Server 2019 Azure Active Directory information disclosure
5706| [139936] Microsoft Windows up to Server 2019 SymCrypt information disclosure
5707| [139935] Microsoft Windows 10 1809/10 1903/Server 1903/Server 2019 NTFS privilege escalation
5708| [139934] Microsoft Windows 7 SP1/Server 2018 R2 SP1/Server 2018 SP2 Win32k memory corruption
5709| [139933] Microsoft Windows up to Server 2019 p2pimsvc privilege escalation
5710| [139932] Microsoft Windows up to Server 2019 Kernel memory corruption
5711| [139931] Microsoft Windows up to Server 2019 File Signature Security Feature CAB File privilege escalation
5712| [139930] Microsoft Windows up to Server 2019 ALPC privilege escalation
5713| [139928] Microsoft Windows up to Server 2019 Kernel memory corruption
5714| [139927] Microsoft Windows up to Server 2019 Graphics Component information disclosure
5715| [139926] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5716| [139925] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5717| [139924] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5718| [139922] Microsoft Windows up to Server 2019 Graphics Component information disclosure
5719| [139921] Microsoft Windows up to Server 2019 Graphics Component information disclosure
5720| [139920] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5721| [139919] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5722| [139918] Microsoft Windows up to Server 2019 Graphics Component information disclosure
5723| [139917] Microsoft Windows up to Server 2019 Graphics Component information disclosure
5724| [139916] Microsoft Windows up to Server 2019 XML Core Services MSXML Parser privilege escalation
5725| [139914] Microsoft Windows up to Server 2019 Hyper-V Network Switch denial of service
5726| [139913] Microsoft Windows up to Server 2019 Hyper-V Network Switch denial of service
5727| [139912] Microsoft Windows 10 1809/10 1903/Server 1903/Server 2019 Hyper-V Network Switch denial of service
5728| [139911] Microsoft Windows up to Server 2019 denial of service
5729| [139910] Microsoft Windows up to Server 2019 Hyper-V Network Switch denial of service
5730| [139909] Microsoft Windows up to Server 2019 Hyper-V Network Switch denial of service
5731| [139908] Microsoft Windows up to Server 2019 Bluetooth weak encryption
5732| [139907] Microsoft Windows up to Server 2019 Remote Desktop Service privilege escalation
5733| [139906] Microsoft Windows up to Server 2019 Remote Desktop Service privilege escalation
5734| [139902] Microsoft Word up to 2019 memory corruption
5735| [139901] Microsoft Outlook up to 2019 memory corruption
5736| [139895] Microsoft Windows up to Server 2019 lnk File privilege escalation
5737| [139894] Microsoft Windows up to Server 2019 VBScript Engine memory corruption
5738| [139893] Microsoft Windows up to Server 2019 Remote Desktop Service privilege escalation
5739| [139892] Microsoft Windows up to Server 2019 Remote Desktop Service privilege escalation
5740| [139891] Microsoft Windows up to Server 2019 Font Library memory corruption
5741| [139890] Microsoft Windows up to Server 2019 Font Library memory corruption
5742| [139889] Microsoft Windows up to Server 2019 Font Library memory corruption
5743| [139888] Microsoft Windows up to Server 2019 Font Library memory corruption
5744| [139887] Microsoft Windows up to Server 2019 Font Library memory corruption
5745| [139886] Microsoft Windows up to Server 2019 Font Library memory corruption
5746| [139880] Microsoft Windows up to Server 2019 Hyper-V memory corruption
5747| [139879] Microsoft Windows up to Server 2019 DHCP Client memory corruption
5748| [139878] Microsoft Windows up to Server 2019 Hyper-V Network Switch memory corruption
5749| [139877] Microsoft Outlook up to 2019 memory corruption
5750| [139876] Microsoft Windows up to Server 2019 Remote Desktop Service privilege escalation
5751| [139875] Microsoft Windows up to Server 2019 Remote Desktop Service privilege escalation
5752| [137590] Microsoft ASP.NET Core 2.1/2.2 Open Redirect
5753| [137589] Microsoft Exchange Server 2013 CU23/2016 CU12/2016 CU13/2019 CU1/2019 CU2 cross site scripting
5754| [137588] Microsoft Exchange Server 2010 SP3/2013 CU23/2016 CU12/2016 CU13 Web Services privilege escalation
5755| [137587] Microsoft SharePoint Server 2013 SP1/2016/2019 cross site scripting
5756| [137586] Microsoft Windows up to Server 2019 AppX Deployment Service privilege escalation
5757| [137585] Microsoft Windows up to Server 2019 AppX Deployment Service privilege escalation
5758| [137584] Microsoft Windows up to Server 2019 DirectWrite memory corruption
5759| [137583] Microsoft Windows up to Server 2019 DirectWrite memory corruption
5760| [137581] Microsoft Windows up to Server 2019 DirectWrite memory corruption
5761| [137580] Microsoft Windows up to Server 2019 DirectWrite memory corruption
5762| [137579] Microsoft Windows up to Server 2019 DirectWrite memory corruption
5763| [137578] Microsoft Windows up to Server 2019 DirectWrite memory corruption
5764| [137577] Microsoft Windows up to Server 2019 DirectWrite memory corruption
5765| [137576] Microsoft Windows up to Server 2019 DirectWrite memory corruption
5766| [137575] Microsoft Windows up to Server 2019 DirectWrite memory corruption
5767| [137574] Microsoft Windows up to Server 2019 DirectWrite memory corruption
5768| [137568] Microsoft Windows up to Server 2019 Remote Desktop Protocol information disclosure
5769| [137563] Microsoft Windows up to Server 2019 DirectWrite information disclosure
5770| [137562] Microsoft Windows up to Server 2019 Win32k information disclosure
5771| [137561] Microsoft Windows up to Server 2019 GDI information disclosure
5772| [137560] Microsoft Windows up to Server 2019 GDI information disclosure
5773| [137559] Microsoft Windows up to Server 2019 DirectWrite information disclosure
5774| [137555] Microsoft Windows up to Server 2019 Audio Service privilege escalation
5775| [137554] Microsoft Windows up to Server 2019 Audio Service privilege escalation
5776| [137553] Microsoft Windows up to Server 2019 Audio Service privilege escalation
5777| [137549] Microsoft Windows up to Server 2016 DLL privilege escalation
5778| [137544] Microsoft Windows up to Server 2019 Kernel information disclosure
5779| [137543] Microsoft Windows up to Server 2019 Kernel information disclosure
5780| [137542] Microsoft SQL Server 2014 SP2/2016 SP1/2017 privilege escalation
5781| [137541] Microsoft Windows up to Server 2019 memory corruption
5782| [137540] Microsoft Windows up to Server 2019 Error Reporting privilege escalation
5783| [137539] Microsoft Windows up to Server 2016 DirectX memory corruption
5784| [137538] Microsoft Windows Server 1803/Server 1903/Server 2016/Server 2019 ADFS Security Feature privilege escalation
5785| [137537] Microsoft Windows up to Server 2019 Hyper-V denial of service
5786| [137535] Microsoft Windows up to Server 2019 Remote Desktop Service privilege escalation
5787| [137533] Microsoft Windows up to Server 2019 SymCrypt denial of service
5788| [137527] Microsoft Windows up to Server 2019 GDI+ memory corruption
5789| [137512] Microsoft Windows up to Server 2019 DHCP memory corruption
5790| [136414] Microsoft Azure DevOps Server 2019 cross site request forgery
5791| [136349] Microsoft Windows up to Server 2019 Event Viewer eventvwr.msc XML External Entity
5792| [136348] Microsoft Windows up to Server 2019 Task Scheduler privilege escalation
5793| [136347] Microsoft Windows up to Server 2019 AppXSVC privilege escalation
5794| [136345] Microsoft Windows up to Server 2019 Windows Shell privilege escalation
5795| [136344] Microsoft Windows up to Server 2019 GDI information disclosure
5796| [136340] Microsoft Windows up to Server 2019 GDI information disclosure
5797| [136337] Microsoft Windows up to Server 2019 Comctl32.dll memory corruption
5798| [136336] Microsoft Windows up to Server 2019 Kernel privilege escalation
5799| [136335] Microsoft Windows up to Server 2019 NTLM Downgrade weak authentication
5800| [136334] Microsoft Windows up to Server 2019 Kernel information disclosure
5801| [136333] Microsoft SharePoint Server 2010 SP2/2013 SP1/2016/2019 cross site scripting
5802| [136330] Microsoft SharePoint Server 2010 SP2/2013 SP1/2016/2019 cross site scripting
5803| [136329] Microsoft SharePoint Server 2016/2019 cross site scripting
5804| [136328] Microsoft SharePoint Server 2010 SP2/2013 SP1/2016/2019 cross site scripting
5805| [136327] Microsoft Lync Server 2010/2013 denial of service
5806| [136326] Microsoft Windows up to Server 2019 Audio Service privilege escalation
5807| [136325] Microsoft Windows up to Server 2019 Audio Service privilege escalation
5808| [136324] Microsoft Windows up to Server 2019 Audio Service privilege escalation
5809| [136323] Microsoft Windows up to Server 2019 denial of service
5810| [136321] Microsoft Windows 10 1809/10 1903/Server 1903/Server 2019 Audio Service privilege escalation
5811| [136320] Microsoft Windows up to Server 2019 Audio Service privilege escalation
5812| [136319] Microsoft Windows up to Server 2019 Security Credentials information disclosure
5813| [136318] Microsoft Windows up to Server 2019 DirectX privilege escalation
5814| [136317] Microsoft Windows up to Server 2019 Win32k memory corruption
5815| [136314] Microsoft Windows up to Server 2019 Win32k memory corruption
5816| [136312] Microsoft Windows up to Server 2019 GDI information disclosure
5817| [136310] Microsoft Windows up to Server 2019 GDI information disclosure
5818| [136308] Microsoft Windows up to Server 2019 Audio Service privilege escalation
5819| [136306] Microsoft Windows up to Server 2019 Storage Service privilege escalation
5820| [136305] Microsoft Windows up to Server 2019 User Profile Service privilege escalation
5821| [136304] Microsoft Windows up to Server 2019 Common Log File System Driver privilege escalation
5822| [136303] Microsoft Windows up to Server 2019 Storage Service privilege escalation
5823| [136301] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5824| [136299] Microsoft Windows up to Server 2019 Local Security Authority Subsystem Service Reboot denial of service
5825| [136296] Microsoft Windows up to Server 2019 Common Log File System Driver memory corruption
5826| [136295] Microsoft Windows up to Server 2019 ALPC privilege escalation
5827| [136293] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5828| [136292] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5829| [136291] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5830| [136290] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5831| [136289] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5832| [136288] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5833| [136287] Microsoft Windows up to Server 2019 Hyper-V denial of service
5834| [136286] Microsoft Windows up to Server 2019 Hyper-V denial of service
5835| [136285] Microsoft Windows up to Server 2019 Hyper-V denial of service
5836| [136284] Microsoft Windows up to Server 2019 Kernel memory corruption
5837| [136276] Microsoft Windows up to Server 2019 Hyper-V memory corruption
5838| [136275] Microsoft Windows 10/10 1607/10 1703/10 1709/Server 2016 Hyper-V memory corruption
5839| [136274] Microsoft Windows up to Server 2019 ActiveX memory corruption
5840| [136273] Microsoft Windows up to Server 2019 Hyper-V memory corruption
5841| [134750] Microsoft ASP.NET Core 2.1/2.2 denial of service
5842| [134745] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
5843| [134744] Microsoft Windows up to Server 2019 GDI information disclosure
5844| [134743] Microsoft SharePoint Server 2013 SP1/2016 cross site scripting
5845| [134742] Microsoft SharePoint Enterprise Server 2016/2019 cross site scripting
5846| [134741] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
5847| [134740] Microsoft SharePoint Enterprise Server 2013 SP1/2016 privilege escalation
5848| [134739] Microsoft SharePoint Foundation 2010 SP2/2013 SP2 cross site scripting
5849| [134738] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
5850| [134737] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
5851| [134736] Microsoft Office 2010 SP2 Access Connectivity Engine memory corruption
5852| [134735] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
5853| [134734] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
5854| [134733] Microsoft Windows up to Server 2019 Unified Write Filter privilege escalation
5855| [134731] Microsoft Windows up to Server 2019 Symlink privilege escalation
5856| [134729] Microsoft Windows up to Server 2019 Storage Service privilege escalation
5857| [134725] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5858| [134724] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5859| [134723] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5860| [134722] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5861| [134721] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5862| [134720] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5863| [134719] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5864| [134718] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5865| [134717] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5866| [134716] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5867| [134715] Microsoft Windows up to Server 2019 Win32k memory corruption
5868| [134714] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5869| [134713] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5870| [134712] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5871| [134710] Microsoft Windows up to Server 2019 GDI information disclosure
5872| [134709] Microsoft Windows up to Server 2019 Kernel privilege escalation
5873| [134706] Microsoft Windows up to Server 2019 Error Reporting privilege escalation
5874| [134701] Microsoft Windows up to Server 2019 Windows Defender Application Control privilege escalation
5875| [134700] Microsoft Windows up to Server 2019 Diagnostic Hub privilege escalation
5876| [134699] Microsoft Windows up to Server 2019 NDIS ndis.sys memory corruption
5877| [134698] Microsoft Windows up to Server 2019 OLE memory corruption
5878| [134684] Microsoft Windows up to Server 2019 DHCP Server memory corruption
5879| [134678] Microsoft Windows up to Server 2019 GDI+ memory corruption
5880| [133236] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5881| [133234] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5882| [133232] Microsoft Azure DevOps Server 2019 cross site scripting
5883| [133229] Microsoft Azure DevOps Server 2019 cross site scripting
5884| [133224] Microsoft Exchange Server 2013 CU22/2016 CU11/2016 CU12/2019/2019 CU1 Outlook Web Access privilege escalation
5885| [133223] Microsoft Azure DevOps Server 2019 Content Security Policy privilege escalation
5886| [133222] Microsoft Windows up to Server 2019 Remote Registry Service memory corruption
5887| [133221] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5888| [133220] Microsoft Windows up to Server 2019 GDI Memory information disclosure
5889| [133219] Microsoft Windows up to Server 2019 Win32k Memory information disclosure
5890| [133218] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5891| [133217] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5892| [133216] Microsoft Windows up to Server 2019 Kernel Memory information disclosure
5893| [133215] Microsoft Windows up to Server 2019 VBScript Engine memory corruption
5894| [133214] Microsoft Windows up to Server 2019 AppX Deployment Service privilege escalation
5895| [133213] Microsoft Windows up to Server 2019 Kernel Memory information disclosure
5896| [133212] Microsoft Windows up to Server 2019 Terminal Services Memory information disclosure
5897| [133211] Microsoft Windows up to Server 2019 Task Scheduler information disclosure
5898| [133209] Microsoft Windows up to Server 2019 LUAFV Driver luafv.sys privilege escalation
5899| [133206] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016/2019 cross site scripting
5900| [133205] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site scripting
5901| [133204] Microsoft Office/Excel up to 2019 memory corruption
5902| [133203] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
5903| [133202] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
5904| [133201] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
5905| [133200] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
5906| [133199] Microsoft Office 2010 SP2 Access Connectivity Engine memory corruption
5907| [133198] Microsoft Exchange Server up to 2019 CU1 Outlook Web Access cross site scripting
5908| [133197] Microsoft ASP.NET Core 2.2 Request denial of service
5909| [133196] Microsoft Windows up to Server 2019 Win32k information disclosure
5910| [133195] Microsoft Windows up to Server 2019 LUAFV Driver luafv.sys privilege escalation
5911| [133194] Microsoft Windows up to Server 2019 GDI Memory information disclosure
5912| [133193] Microsoft Windows up to Server 2019 LUAFV Driver luafv.sys privilege escalation
5913| [133192] Microsoft Windows up to Server 2019 OLE Automation privilege escalation
5914| [133189] Microsoft Windows up to Server 2019 CSRSS memory corruption
5915| [133188] Microsoft Windows up to Server 2019 LUAFV Driver luafv.sys privilege escalation
5916| [133187] Microsoft Windows up to Server 2019 LUAFV Driver luafv.sys privilege escalation
5917| [133186] Microsoft Windows up to Server 2019 TCP/IP Stack Fragmented IP Packet information disclosure
5918| [133185] Microsoft Windows up to Server 2019 Win32k memory corruption
5919| [133183] Microsoft Windows up to Server 2019 Win32k memory corruption
5920| [133182] Microsoft Windows up to Server 2019 Win32k memory corruption
5921| [133181] Microsoft Office/Excel/PowerPoint up to 2019 URL Document Code Execution
5922| [133180] Microsoft Windows up to Server 2019 MS XML Code Execution
5923| [133179] Microsoft Windows up to Server 2019 MS XML Code Execution
5924| [133177] Microsoft Windows up to Server 2019 Device Guard luafv.sys privilege escalation
5925| [133174] Microsoft Windows up to Server 2019 GDI+ privilege escalation
5926| [133173] Microsoft Windows up to Server 2019 IOleCvt Interface privilege escalation
5927| [133166] Microsoft Windows up to Server 2019 MS XML Code Execution
5928| [133165] Microsoft Windows up to Server 2019 MS XML Code Execution
5929| [133164] Microsoft Windows up to Server 2019 MS XML Code Execution
5930| [133163] Microsoft Windows up to Server 2019 MS XML Code Execution
5931| [133162] Microsoft Windows up to Server 2019 MS XML Code Execution
5932| [131687] Microsoft Team Foundation Server 2017 Update 3.1/2018 Update 3.2/2018 Updated 1.2 cross site scripting
5933| [131685] Microsoft Windows up to Server 2019 SMB information disclosure
5934| [131684] Microsoft Visual Studio 2017 Version 15.9 C++ Redistributable Installer privilege escalation
5935| [131681] Microsoft Windows up to Server 2019 Win32k memory corruption
5936| [131679] Microsoft Windows up to Server 2019 Kernel information disclosure
5937| [131675] Microsoft SharePoint 2013 SP1/2016 cross site scripting
5938| [131674] Microsoft Windows up to Server 2019 Win32k information disclosure
5939| [131673] Microsoft Windows up to Server 2019 Kernel information disclosure
5940| [131672] Microsoft Windows up to Server 2019 GDI information disclosure
5941| [131671] Microsoft Windows up to Server 2019 VBScript Engine memory corruption
5942| [131668] Microsoft Windows up to Server 2019 AppX Deployment Server privilege escalation
5943| [131667] Microsoft Windows up to Server 2019 Comctl32.dll memory corruption
5944| [131663] Microsoft Windows up to Server 2019 Print Spooler information disclosure
5945| [131658] Microsoft Windows up to Server 2019 information disclosure
5946| [131657] Microsoft Windows up to Server 2019 denial of service
5947| [131656] Microsoft Office 2010 SP2 Connectivity Engine memory corruption
5948| [131653] Microsoft Windows up to Server 2019 SMB information disclosure
5949| [131652] Microsoft Windows up to Server 2019 SMB information disclosure
5950| [131651] Microsoft Windows up to Server 2019 Kernel information disclosure
5951| [131650] Microsoft Windows 10 1803/10 1809/Server 1803/Server 2019 Hyper-V denial of service
5952| [131649] Microsoft Windows up to Server 2019 Kernel memory corruption
5953| [131648] Microsoft Windows up to Server 2019 Hyper-V denial of service
5954| [131644] Microsoft Windows up to Server 2019 Hyper-V denial of service
5955| [131638] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5956| [131632] Microsoft Windows 10 1803/10 1809/Server 1803/Server 2019 DHCP Client memory corruption
5957| [131631] Microsoft Windows 10 1803/10 1809/Server 1803/Server 2019 DHCP Client memory corruption
5958| [131630] Microsoft Windows 10 1803/10 1809/Server 1803/Server 2019 DHCP Client memory corruption
5959| [131629] Microsoft Windows up to Server 2019 Deployment Services TFTP Server memory corruption
5960| [131628] Microsoft Windows up to Server 2019 ActiveX memory corruption
5961| [131619] Microsoft Windows up to Server 2019 MS XML privilege escalation
5962| [131334] Microsoft Team Foundation Server 2018 Update 3.2 cross site scripting
5963| [131333] Microsoft Team Foundation Server 2018 Update 3.2 cross site scripting
5964| [131328] Microsoft Windows up to Server 2016 Kernel information disclosure
5965| [130832] Microsoft 2013 SP1 spoofing
5966| [130828] Microsoft Exchange Server 2010 SP3/2013 CU22/2016 CU12/2019 CU1 EWS privilege escalation
5967| [130826] Microsoft Office 2010 SP2 Connectivity Engine memory corruption
5968| [130825] Microsoft Office up to 2019 Connectivity Engine memory corruption
5969| [130824] Microsoft Office up to 2019 Connectivity Engine memory corruption
5970| [130823] Microsoft Office up to 2019 Connectivity Engine privilege escalation
5971| [130822] Microsoft Office up to 2019 Connectivity Engine privilege escalation
5972| [130821] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
5973| [130820] Microsoft Windows up to Server 2012 R2 GDI information disclosure
5974| [130818] Microsoft Windows up to Server 2019 GDI information disclosure
5975| [130817] Microsoft Windows up to Server 2019 Storage Service privilege escalation
5976| [130814] Microsoft Windows up to Server 2019 privilege escalation
5977| [130809] Microsoft Windows up to Server 2019 Defender Firewall Security privilege escalation
5978| [130808] Microsoft Windows up to Server 2019 information disclosure
5979| [130807] Microsoft Windows up to Server 2019 Hyper-V information disclosure
5980| [130806] Microsoft Windows up to Server 2019 SMB privilege escalation
5981| [130805] Microsoft Windows up to Server 2019 Device Guard privilege escalation
5982| [130804] Microsoft Windows up to Server 2019 Device Guard privilege escalation
5983| [130803] Microsoft Windows up to Server 2019 SMB privilege escalation
5984| [130802] Microsoft Windows up to Server 2019 Win32k information disclosure
5985| [130801] Microsoft Windows up to Server 2019 Device Guard privilege escalation
5986| [130800] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5987| [130799] Microsoft Windows up to Server 2016 Win32k memory corruption
5988| [130798] Microsoft Windows up to Server 2019 GDI information disclosure
5989| [130797] Microsoft Windows up to Server 2019 GDI information disclosure
5990| [130796] Microsoft Windows up to Server 2019 GDI information disclosure
5991| [130793] Microsoft Windows up to Server 2019 GDI information disclosure
5992| [130792] Microsoft Windows up to Server 2019 HID information disclosure
5993| [130791] Microsoft Windows up to Server 2019 HID information disclosure
5994| [130790] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5995| [130789] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5996| [130788] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5997| [130787] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5998| [130786] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
5999| [130784] Microsoft Windows up to Server 2019 GDI+ memory corruption
6000| [130782] Microsoft Windows up to Server 2019 DHCP Server memory corruption
6001| [130781] Microsoft Windows up to Server 2019 GDI+ memory corruption
6002| [129847] Microsoft Team Foundation Server 2017 Update 3.1/2018 Update 1.2/2018 Update 3.2 information disclosure
6003| [129846] Microsoft Team Foundation Server 2018 Update 3.2 cross site scripting
6004| [129845] Microsoft Skype for Business 2015 CU 8 Request cross site scripting
6005| [128765] Microsoft Visual Studio 2017 Version 15.9 C++ Construct privilege escalation
6006| [128764] Microsoft Exchange Server 2010 SP3/2013 CU21/2016 CU10/2016 CU11/2019 PowerShell API information disclosure
6007| [128761] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
6008| [128760] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
6009| [128759] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
6010| [128758] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
6011| [128757] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
6012| [128756] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
6013| [128755] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
6014| [128754] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
6015| [128753] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
6016| [128752] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
6017| [128751] Microsoft Windows up to Server 2019 Data Sharing Service privilege escalation
6018| [128750] Microsoft Windows up to Server 2019 Runtime privilege escalation
6019| [128749] Microsoft Windows up to Server 2019 Kernel information disclosure
6020| [128747] Microsoft ASP.NET Core 2.1 Web Request denial of service
6021| [128746] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site scripting
6022| [128745] Microsoft Office up to 2019 Word Macro information disclosure
6023| [128742] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site scripting
6024| [128741] Microsoft SharePoint Enterprise Server 2016 cross site scripting
6025| [128740] Microsoft SharePoint Enterprise Server 2013 SP1 cross site scripting
6026| [128739] Microsoft Windows up to Server 2019 Kernel information disclosure
6027| [128738] Microsoft Windows up to Server 2019 Subsystem for Linux information disclosure
6028| [128737] Microsoft Windows up to Server 2019 COM Desktop Broker privilege escalation
6029| [128736] Microsoft Windows up to Server 2019 Kernel information disclosure
6030| [128735] Microsoft ASP.NET Core 2.1/2.2 Web Request denial of service
6031| [128733] Microsoft Windows up to Server 2019 Authentication Request privilege escalation
6032| [128729] Microsoft Visual Studio 2010 SP1/2012 Update 5 vscontent File information disclosure
6033| [128728] Microsoft Windows up to Server 2019 Kernel information disclosure
6034| [128727] Microsoft Windows up to Server 2019 Data Sharing Service privilege escalation
6035| [128726] Microsoft Windows up to Server 2019 Data Sharing Service privilege escalation
6036| [128725] Microsoft Windows up to Server 2019 Data Sharing Service privilege escalation
6037| [128718] Microsoft Windows up to Server 2019 Hyper-V memory corruption
6038| [128717] Microsoft Windows 10 1803/10 1809/Server 1803/Server 2019 Hyper-V memory corruption
6039| [127925] Microsoft SharePoint Enterprise Server 2016 Web Request cross site scripting
6040| [127882] Microsoft Dynamics NAV 2016/2017 Web Request cross site scripting
6041| [127881] Microsoft Windows 10 1809/Server 2019 Object denial of service
6042| [127880] Microsoft Windows up to Server 2019 Win32k Object memory corruption
6043| [127828] Microsoft Windows up to Server 2019 Win32k memory corruption
6044| [127827] Microsoft Windows 10 1809/Server 2019 DirectX information disclosure
6045| [127826] Microsoft Windows 10 1803/10 1809/Server 1803/Server 2019 Win32k ASLR privilege escalation
6046| [127825] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016 privilege escalation
6047| [127824] Microsoft Excel up to 2019 Out-of-Bounds memory corruption
6048| [127823] Microsoft Windows up to Server 2012 R2 Kernel information disclosure
6049| [127821] Microsoft Windows up to Server 2019 Connected User Experiences and Telemetry Service denial of service
6050| [127820] Microsoft Windows up to Server 2019 Kernel memory corruption
6051| [127819] Microsoft Exchange Server 2016 CU10/2016 CU11 Profile Data privilege escalation
6052| [127817] Microsoft Excel up to 2019 information disclosure
6053| [127816] Microsoft Windows up to Server 2019 GDI information disclosure
6054| [127815] Microsoft Windows up to Server 2019 GDI information disclosure
6055| [127814] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016 Search cross site request forgery
6056| [127812] Microsoft Windows up to Server 2019 Remote Procedure Call information disclosure
6057| [127806] Microsoft Outlook up to 2019 memory corruption
6058| [127805] Microsoft Excel up to 2019 memory corruption
6059| [127804] Microsoft Excel up to 2019 memory corruption
6060| [127803] Microsoft Windows up to Server 2019 Text-To-Speech memory corruption
6061| [127801] Microsoft Windows up to Server 2019 DNS Server privilege escalation
6062| [126938] Microsoft Team Foundation Server 2018 Update 1.1/2018 Update 3 Code Execution
6063| [126755] Microsoft .NET Core 2.1 privilege escalation
6064| [126754] Microsoft Skype for Business/Lync Server 2013 SP1/2016 Emoji denial of service
6065| [126750] Microsoft Windows up to Server 2019 ALPC privilege escalation
6066| [126749] Microsoft Exchange Server 2010/2013/2016/2019 privilege escalation
6067| [126747] Microsoft SharePoint Enterprise Server 2013 SP1 Folder information disclosure
6068| [126746] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
6069| [126745] Microsoft Project 2010 SP2/2013 SP1/2016 memory corruption
6070| [126744] Microsoft Office up to 2019 Word memory corruption
6071| [126743] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site scripting
6072| [126742] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site scripting
6073| [126739] Microsoft Windows up to Server 2012 R2 Win32k information disclosure
6074| [126737] Microsoft Windows up to Server 2012 R2 DirectX information disclosure
6075| [126736] Microsoft Windows up to Server 2019 Win32k memory corruption
6076| [126735] Microsoft Windows up to Server 2019 DirectX privilege escalation
6077| [126733] Microsoft Windows 10 1803/10 1809/Server 1803/Server 2019 DirectX memory corruption
6078| [126730] Microsoft Windows up to Server 2019 Active Directory Federation Services cross site scripting
6079| [126728] Microsoft Office/SharePoint 2010 SP2 Word memory corruption
6080| [126727] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
6081| [126726] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
6082| [126725] Microsoft Windows up to Server 2019 DirectX memory corruption
6083| [126722] Microsoft Windows up to Server 2019 PowerShell privilege escalation
6084| [126718] Microsoft Windows up to Server 2016 Search memory corruption
6085| [126717] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016/2019 memory corruption
6086| [126716] Microsoft Office up to 2019 Excel memory corruption
6087| [126714] Microsoft Windows up to Server 2019 PowerShell unknown vulnerability
6088| [126713] Microsoft Windows up to Server 2019 VBScript Engine memory corruption
6089| [126712] Microsoft Windows up to Server 2016 Graphics Component memory corruption
6090| [126711] Microsoft Windows up to Server 2019 Deployment Services TFTP Server memory corruption
6091| [125123] Microsoft Windows up to Server 2019 Codecs Library information disclosure
6092| [125122] Microsoft Windows up to Server 2016 TCP/IP information disclosure
6093| [125121] Microsoft Windows up to Server 2019 DirectX memory corruption
6094| [125120] Microsoft Windows up to Server 2019 Windows Media Player information disclosure
6095| [125119] Microsoft Windows up to Server 2019 Windows Media Player information disclosure
6096| [125116] Microsoft Exchange Server 2013 CU21/2016 CU10 privilege escalation
6097| [125115] Microsoft Windows up to Server 2019 Theme API privilege escalation
6098| [125114] Microsoft Windows up to Server 2019 Windows Shell privilege escalation
6099| [125113] Microsoft Windows up to Server 2019 Kernel memory corruption
6100| [125111] Microsoft Windows up to Server 2019 Device Guard Code Integrity Policy privilege escalation
6101| [125110] Microsoft Windows up to Server 2019 DNS Global Blocklist privilege escalation
6102| [125109] Microsoft Windows up to Server 2019 NTFS privilege escalation
6103| [125108] Microsoft Windows up to Server 2019 Filter Manager memory corruption
6104| [125107] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
6105| [125106] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
6106| [125105] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
6107| [125104] Microsoft SharePoint Enterprise Server 2016 cross site scripting
6108| [125102] Microsoft Office/Word 2010 SP2/2013 RT SP1/2013 SP1/2016/2019 Protected View memory corruption
6109| [125100] Microsoft Office/PowerPoint 2010 SP2/2013 RT SP1/2013 SP1/2016/2019 Protected View memory corruption
6110| [125099] Microsoft Office/Excel up to 2019 Protected View memory corruption
6111| [125098] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
6112| [125097] Microsoft Windows up to Server 2019 DirectX Graphics memory corruption
6113| [125096] Microsoft Windows up to Server 2019 Win32k memory corruption
6114| [125095] Microsoft Exchange Server 2013 CU21/2016 CU10 Outlook Web Access cross site scripting
6115| [125093] Microsoft Windows up to Server 2019 Hyper-V memory corruption
6116| [125092] Microsoft Windows up to Server 2019 Hyper-V memory corruption
6117| [125091] Microsoft Windows up to Server 2019 MS XML privilege escalation
6118| [124371] Microsoft Exchange Server up to 2010 SP3 Outlook Web Access /owa/auth/logon.aspx Parameter Server-Side Request Forgery
6119| [124217] Microsoft Windows Server 2012/Server 2016 Active Directory Federation Services /adfs/ls Server-Side Request Forgery
6120| [123995] Microsoft Lync 2011 on Mac Security Feature Messages Download privilege escalation
6121| [123881] Microsoft Windows up to Server 2016 Sandbox privilege escalation
6122| [123874] Microsoft Windows up to Server 2016 Kernel information disclosure
6123| [123872] Microsoft Windows 8.1/10/RT 8.1/Server 2012/Server 2012 R2 SMB information disclosure
6124| [123868] Microsoft Windows up to Server 2016 Hyper-V denial of service
6125| [123864] Microsoft Windows up to Server 2016 Hyper-V information disclosure
6126| [123862] Microsoft SharePoint Enterprise Server 2010 SP2/2013 RT SP1/2013 SP1/2016 cross site scripting
6127| [123861] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R information disclosure
6128| [123860] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
6129| [123859] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016 cross site scripting
6130| [123851] Microsoft Windows up to Server 2016 ALPC privilege escalation
6131| [123849] Microsoft Windows up to Server 2016 SMB denial of service
6132| [123846] Microsoft Office 2016 on Win/Mac memory corruption
6133| [123844] Microsoft Word 2013 RT SP1/2013 SP1/2016 PDF File memory corruption
6134| [123843] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
6135| [123842] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
6136| [123830] Microsoft Windows up to Server 2016 Hyper-V memory corruption
6137| [123828] Microsoft Windows up to Server 2016 Win32k Graphics privilege escalation
6138| [123827] Microsoft Windows up to Server 2016 Image memory corruption
6139| [123825] Microsoft Windows up to Server 2016 MSXML Parser privilege escalation
6140| [123823] Microsoft Windows up to Server 2016 Hyper-V privilege escalation
6141| [122887] Microsoft Office 2016 on Mac AutoUpdate memory corruption
6142| [122886] Microsoft Windows up to Server 2016 DirectX Graphics memory corruption
6143| [122885] Microsoft Windows up to Server 2016 DirectX Graphics memory corruption
6144| [122884] Microsoft Windows up to Server 2016 Win32k memory corruption
6145| [122883] Microsoft Windows up to Server 2016 DirectX Graphics memory corruption
6146| [122875] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R information disclosure
6147| [122874] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
6148| [122873] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R information disclosure
6149| [122871] Microsoft PowerPoint 2010 SP2 memory corruption
6150| [122870] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
6151| [122861] Microsoft Windows up to Server 2016 Microsoft COM for Windows privilege escalation
6152| [122850] Microsoft Visual Studio 2015 Update 3/2017/2017 Version 15.8 Diagnostic Hub privilege escalation
6153| [122849] Microsoft Windows up to Server 2016 Diagnostic Hub privilege escalation
6154| [122848] Microsoft Windows Security Feature 2FA weak authentication
6155| [122834] Microsoft Windows up to Server 2016 LNK memory corruption
6156| [122825] Microsoft Windows up to Server 2016 Graphics memory corruption
6157| [122823] Microsoft SQL Server 2016 SP1/2016 SP2/2017 memory corruption
6158| [121208] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R Attachment privilege escalation
6159| [121118] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
6160| [121116] Microsoft Windows up to Server 2016 Sandbox privilege escalation
6161| [121114] Microsoft Access 2013 SP1/2016/2016 C2R memory corruption
6162| [121111] Microsoft Windows up to Server 2016 Kernel memory corruption
6163| [121110] Microsoft Windows up to Server 2016 Wordpad privilege escalation
6164| [121107] Microsoft Windows up to Server 2016 DNSAPI DNSAPI.dll denial of service
6165| [121106] Microsoft SharePoint Enterprise Server 2013 SP1/2016 privilege escalation
6166| [121105] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
6167| [121098] Microsoft Office 2016/2016 C2R memory corruption
6168| [121092] Microsoft Windows up to Server 2016 FTP Server denial of service
6169| [121090] Microsoft Visual Studio up to 2017 Version 15.8 Preview privilege escalation
6170| [119479] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
6171| [119477] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016 information disclosure
6172| [119476] Microsoft Publisher 2010 SP2 OLE Object PUB File privilege escalation
6173| [119475] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016 Attachment privilege escalation
6174| [119474] Microsoft Windows up to Server 2016 GDI information disclosure
6175| [119470] Microsoft Windows up to Server 2016 HTTP HTTP.sys denial of service
6176| [119468] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
6177| [119467] Microsoft Windows up to Server 2016 Hypervisor privilege escalation
6178| [119465] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
6179| [119464] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
6180| [119463] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
6181| [119461] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
6182| [119460] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
6183| [119459] Microsoft Windows up to Server 2016 memory corruption
6184| [119457] Microsoft Windows up to Server 2016 Desktop Bridge privilege escalation
6185| [119456] Microsoft Windows up to Server 2016 Kernel information disclosure
6186| [119455] Microsoft Windows up to Server 2016 denial of service
6187| [119454] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
6188| [119452] Microsoft Windows up to Server 2016 HIDParser memory corruption
6189| [119448] Microsoft Windows up to Server 2016 Code Integrity Module denial of service
6190| [119447] Microsoft Windows up to Server 2016 NTFS privilege escalation
6191| [119441] Microsoft Windows up to Server 2016 Media Foundation memory corruption
6192| [119437] Microsoft Windows up to Server 2016 HTTP Protocol Stack Http.sys memory corruption
6193| [119436] Microsoft Windows up to Server 2016 memory corruption
6194| [119431] Microsoft Windows up to Server 2016 DNSAPI DNSAPI.dll DNS Response privilege escalation
6195| [118120] Microsoft Office 2016 on Mac XML Data Code Execution
6196| [117561] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1 Web Request cross site scripting
6197| [117560] Microsoft Exchange Server up to 2016 CU9 Code Execution memory corruption
6198| [117559] Microsoft Exchange Server 2016 CU8/2016 CU9 Outlook Web Access Web Request cross site scripting
6199| [117558] Microsoft Windows up to Server 2016 Code Execution memory corruption
6200| [117507] Microsoft Infopath 2013 SP1 memory corruption
6201| [117505] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R information disclosure
6202| [117504] Microsoft Office 2010 SP2 information disclosure
6203| [117503] Microsoft Exchange Server 2013 CU19/2013 CU20/2016 CU8/2016 CU9 Outlook Web Access cross site scripting
6204| [117502] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016 cross site scripting
6205| [117501] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
6206| [117500] Microsoft Exchange Server 2016 CU8/2016 CU9 Outlook Web Access cross site scripting
6207| [117499] Microsoft Exchange Server up to 2016 CU9 information disclosure
6208| [117498] Microsoft Office 2016 C2R Security Feature privilege escalation
6209| [117497] Microsoft SharePoint Enterprise Server 2010/2013 SP1/2016 cross site scripting
6210| [117480] Microsoft Windows up to Server 2016 COM Serialized privilege escalation
6211| [117473] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
6212| [117472] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
6213| [117471] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
6214| [117470] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
6215| [117469] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
6216| [117468] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
6217| [117444] Microsoft Windows up to Server 2016 Hyper-V vSMB memory corruption
6218| [117443] Microsoft Windows up to Server 2016 Hyper-V memory corruption
6219| [117442] Microsoft Windows up to Server 2016 VBScript Engine memory corruption
6220| [116132] Microsoft Office 2016 Memory information disclosure
6221| [116051] Microsoft SharePoint Enterprise Server 2016 cross site scripting
6222| [116050] Microsoft SharePoint Enterprise Server 2010 SP2/2013/2016 cross site scripting
6223| [116049] Microsoft SharePoint Enterprise Server 2013/2016 privilege escalation
6224| [116048] Microsoft Windows up to Server 2016 DirectX Graphics Kernel Subsystem memory corruption
6225| [116047] Microsoft Windows up to Server 2016 OpenType Font Driver atmfd.dll memory corruption
6226| [116046] Microsoft SharePoint Enterprise Server 2013/2016 Share cross site scripting
6227| [116045] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
6228| [116039] Microsoft Windows up to Server 2016 Remote Desktop Protocol denial of service
6229| [116031] Microsoft Windows up to Server 2016 Kernel ASLR information disclosure
6230| [116030] Microsoft Windows up to Server 2016 SNMP Service denial of service
6231| [116026] Microsoft Windows up to Server 2016 Kernel information disclosure
6232| [116024] Microsoft Windows up to Server 2016 HTTP.sys denial of service
6233| [116023] Microsoft Office up to 2016 C2R information disclosure
6234| [116022] Microsoft Excel 2010 SP2 memory corruption
6235| [116020] Microsoft Windows 10 1607/10 1703/10 1709/Server 1709/Server 2016 Active Directory privilege escalation
6236| [116019] Microsoft Windows up to Server 2016 Kernel information disclosure
6237| [116018] Microsoft Office 2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
6238| [116017] Microsoft Excel up to 2016 C2R memory corruption
6239| [116016] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 Graphics memory corruption
6240| [116014] Microsoft Office 2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
6241| [116013] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1 memory corruption
6242| [116008] Microsoft Windows up to Server 2016 Graphics memory corruption
6243| [116007] Microsoft Windows up to Server 2016 Graphics memory corruption
6244| [116006] Microsoft Windows up to Server 2016 Graphics memory corruption
6245| [116005] Microsoft Windows up to Server 2016 Graphics memory corruption
6246| [116004] Microsoft Windows up to Server 2016 Graphics memory corruption
6247| [116003] Microsoft Windows up to Server 2016 VBScript Engine memory corruption
6248| [115994] Microsoft Windows up to Server 2016 Malware Protection Engine memory corruption
6249| [115804] Microsoft Windows up to Server 2016 Malware Protection Engine privilege escalation
6250| [114579] Microsoft Exchange Server up to 2017 CU8 Outlook Web Access information disclosure
6251| [114574] Microsoft SharePoint Enterprise Server 2016 privilege escalation
6252| [114573] Microsoft SharePoint Enterprise Server 2016 cross site scripting
6253| [114571] Microsoft Exchange Server 2016 CU7/2016 CU8 Outlook Web Access information disclosure
6254| [114570] Microsoft Exchange Server 2010 SP3/2013 CU18/2013 CU19/2016 CU7/2016 CU8 Outlook Web Access Fake privilege escalation
6255| [114565] Microsoft Windows 10 1607/10 1703/10 1709/Server 1709/Server 2016 Kernel information disclosure
6256| [114564] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
6257| [114562] Microsoft SharePoint Enterprise Server 2016 cross site scripting
6258| [114560] Microsoft SharePoint Enterprise Server 2016 cross site scripting
6259| [114559] Microsoft SharePoint Enterprise Server 2016 cross site scripting
6260| [114558] Microsoft SharePoint Enterprise Server 2016 cross site scripting
6261| [114557] Microsoft SharePoint Enterprise Server 2016 cross site scripting
6262| [114556] Microsoft SharePoint Enterprise Server 2016 cross site scripting
6263| [114555] Microsoft SharePoint Enterprise Server 2016 cross site scripting
6264| [114554] Microsoft SharePoint Enterprise Server 2016 cross site scripting
6265| [114553] Microsoft SharePoint Enterprise Server 2016 cross site scripting
6266| [114552] Microsoft SharePoint Enterprise Server 2016 cross site scripting
6267| [114551] Microsoft Excel up to 2016 C2R Security Feature privilege escalation
6268| [114549] Microsoft Access 2010 SP2/2013 SP1/2016 memory corruption
6269| [114548] Microsoft Windows up to Server 2016 CNG Security Feature cng.sys privilege escalation
6270| [114547] Microsoft Windows up to Server 2016 Kernel information disclosure
6271| [114546] Microsoft Windows up to Server 2016 Kernel information disclosure
6272| [114545] Microsoft Windows up to Server 2016 Kernel information disclosure
6273| [114544] Microsoft Windows up to Server 2016 Kernel information disclosure
6274| [114543] Microsoft Windows up to Server 2016 Kernel information disclosure
6275| [114542] Microsoft Windows up to Server 2016 Kernel information disclosure
6276| [114541] Microsoft Windows up to Server 2016 Kernel information disclosure
6277| [114540] Microsoft Windows up to Server 2016 Kernel information disclosure
6278| [114536] Microsoft Windows up to Server 2016 CredSSP privilege escalation
6279| [114535] Microsoft Windows up to Server 2016 Hyper-V denial of service
6280| [114531] Microsoft Windows up to Server 2016 Windows Installer privilege escalation
6281| [114530] Microsoft Windows up to Server 2016 GDI privilege escalation
6282| [114529] Microsoft Windows up to Server 2016 GDI privilege escalation
6283| [114527] Microsoft Windows up to Server 2016 Kernel information disclosure
6284| [114526] Microsoft Windows up to Server 2016 Kernel information disclosure
6285| [114525] Microsoft Windows up to Server 2016 Kernel information disclosure
6286| [114522] Microsoft Windows 10 1607/10 1703/Server 2016 Desktop Bridge privilege escalation
6287| [114521] Microsoft Windows up to Server 2016 Video Control privilege escalation
6288| [114520] Microsoft Windows 10/Server 1709/Server 2016 Desktop Bridge privilege escalation
6289| [114518] Microsoft Windows up to Server 2016 Remote Assistance information disclosure
6290| [114517] Microsoft Windows 10/Server 1709/Server 2016 Desktop Bridge VFS privilege escalation
6291| [114516] Microsoft Windows up to Server 2016 Windows Shell privilege escalation
6292| [113835] Microsoft Identity Manager 2016 SP1 cross site scripting
6293| [113264] Microsoft Windows 8.1/RT 8.1/Server 2012 R2 SMBv2/SMBv3 denial of service
6294| [113260] Microsoft Windows up to Server 2016 Kernel memory corruption
6295| [113259] Microsoft Windows 10/Server 1709/Server 2016 NTFS privilege escalation
6296| [113254] Microsoft Windows up to Server 2016 Kernel information disclosure
6297| [113253] Microsoft Windows 10/Server 1709/Server 2016 Kernel memory corruption
6298| [113252] Microsoft Windows up to Server 2016 Kernel memory corruption
6299| [113250] Microsoft Windows 10/Server 1709/Server 2016 Kernel memory corruption
6300| [113249] Microsoft Windows up to Server 2016 Kernel memory corruption
6301| [113248] Microsoft Windows up to Server 2016 Kernel information disclosure
6302| [113243] Microsoft Windows 10/Server 2016 MultiPoint Management privilege escalation
6303| [113242] Microsoft Windows up to Server 2016 Common Log File System Driver memory corruption
6304| [113241] Microsoft Windows up to Server 2016 Common Log File System Driver memory corruption
6305| [113240] Microsoft Windows 10/Server 1709/Server 2016 AppContainer privilege escalation
6306| [113237] Microsoft SharePoint Enterprise Server 2016 cross site scripting
6307| [113236] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
6308| [113233] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 Uninitialized Memory information disclosure
6309| [113232] Microsoft Excel 2016 memory corruption
6310| [113230] Microsoft Windows up to Server 2016 Scripting Engine information disclosure
6311| [113229] Microsoft Windows up to Server 2016 StructuredQuery memory corruption
6312| [111580] Microsoft Office 2016 on Mac Email Attachment spoofing
6313| [111571] Microsoft SharePoint Enterprise Server 2013/2016 Access cross site scripting
6314| [111567] Microsoft Office 2010/2013/2016 memory corruption
6315| [111564] Microsoft Word 2016 memory corruption
6316| [111562] Microsoft SharePoint Server 2010/2013/2016 Web Request cross site scripting
6317| [111561] Microsoft SharePoint Server 2010/2013/2016 Web Request cross site scripting
6318| [128730] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
6319| [111358] Microsoft Windows up to Server 2016 IPsec denial of service
6320| [110553] Microsoft Office 2016 C2R information disclosure
6321| [110552] Microsoft SharePoint Enterprise Server 2016 Web Request privilege escalation
6322| [110551] Microsoft Excel 2016 C2R memory corruption
6323| [110550] Microsoft PowerPoint 2013 RT SP1/2013 SP1/2016 information disclosure
6324| [110549] Microsoft Exchange Server 2016 CU6/2016 CU7 Outlook Web Access privilege escalation
6325| [110547] Microsoft Windows up to Server 2016 its:// Protocol information disclosure
6326| [110531] Microsoft Windows 10/Server 2016 Device Guard privilege escalation
6327| [110522] Microsoft Windows up to Server 2016 RRAS privilege escalation
6328| [110350] Microsoft Windows up to Server 2016 Malware Protection Engine memory corruption
6329| [110318] Microsoft Windows up to Server 2016 Malware Protection Engine memory corruption
6330| [109391] Microsoft SharePoint Enterprise Server 2016 Project Server cross site request forgery
6331| [109389] Microsoft Excel 2016 Click-to-Run memory corruption
6332| [109360] Microsoft Windows up to Server 2016 Windows Search denial of service
6333| [107759] Microsoft Windows up to Server 2016 SMB denial of service
6334| [107757] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
6335| [107756] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
6336| [107753] Microsoft Windows 10/Server 2016 SMB privilege escalation
6337| [107744] Microsoft Windows up to Server 2016 DNSAPI DNSAPI.dll DNS Response privilege escalation
6338| [107741] Microsoft Outlook 2016 Secure Connection Mail information disclosure
6339| [107740] Microsoft Windows up to Server 2016 Graphics memory corruption
6340| [107739] Microsoft Windows up to Server 2016 Graphics memory corruption
6341| [107738] Microsoft Windows up to Server 2016 Search information disclosure
6342| [107734] Microsoft Windows 10/Server 2016 SMB privilege escalation
6343| [107732] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016 Bypass privilege escalation
6344| [107730] Microsoft Windows up to Server 2016 Search Remote memory corruption
6345| [107729] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
6346| [107728] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
6347| [107727] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
6348| [107724] Microsoft Windows up to Server 2016 Text Services Framework memory corruption
6349| [107723] Microsoft Windows up to Server 2016 SMB information disclosure
6350| [107698] Microsoft Office 2016 memory corruption
6351| [107593] InFocus Mondopad 2.2.08 Excel Spreadsheet Microsoft Office Document Credentials information disclosure
6352| [106544] Microsoft Exchange Server 2016 Outlook Web Access cross site scripting
6353| [106531] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
6354| [106529] Microsoft PowerPoint 2016 memory corruption
6355| [106523] Microsoft Windows up to Server 2016 PDF Library memory corruption
6356| [106518] Microsoft Edge on Win10/Server 2016 memory corruption
6357| [106516] Microsoft Windows up to Server 2016 PDF Library memory corruption
6358| [106498] Microsoft Windows up to Server 2016 Shell privilege escalation
6359| [106496] Microsoft Windows up to Server 2016 Uniscribe information disclosure
6360| [106495] Microsoft Windows up to Server 2012 R2 Uniscribe memory corruption
6361| [106492] Microsoft Windows Server 2012/Server 2012 R2/Server 2016 DHCP Service memory corruption
6362| [106489] Microsoft Windows up to Server 2016 Graphics Win32k win32k!fsc_CalcGrayRow memory corruption
6363| [106474] Microsoft Office 2016 memory corruption
6364| [106473] Microsoft SharePoint Server 2013 SP1 cross site scripting
6365| [106472] Microsoft Windows up to Server 2016 Bluetooth Driver Object BlueBorne spoofing
6366| [106470] Microsoft Excel 2011 on Mac memory corruption
6367| [106455] Microsoft Exchange Server 2013/2016 information disclosure
6368| [106454] Microsoft Windows up to Server 2016 Windows NetBT Session Services race condition memory corruption
6369| [105048] Microsoft Edge on Win10/Server 2016 Scripting Engine memory corruption
6370| [105047] Microsoft Edge on Win10/Server 2016 Scripting Engine EntryCall memory corruption
6371| [105046] Microsoft Edge on Win10/Server 2016 Javascript Engine memory corruption
6372| [105040] Microsoft Edge on Win10/Server 2016 Scripting Engine memory corruption
6373| [105038] Microsoft Edge on Win10/Server 2016 Javascript Engine Out-of-Bounds memory corruption
6374| [105037] Microsoft Edge on Win10/Server 2016 Javascript Engine PreVisitCatch memory corruption
6375| [105035] Microsoft SharePoint Server 2010 SP2 cross site scripting
6376| [105033] Microsoft Edge 38.14393.1066.0 on Win10/Server 2016 Use-After-Free information disclosure
6377| [105029] Microsoft Edge on Win10/Server 2016 Javascript Engine ProcessLinkFailedAsmJsModule memory corruption
6378| [105027] Microsoft Edge on Win10/Server 2016 _SelectValueInternal information disclosure
6379| [105024] Microsoft Edge on Win10/Server 2016 Javascript Engine memory corruption
6380| [105023] Microsoft Edge on Win10/Server 2016 Javascript Engine memory corruption
6381| [105017] Microsoft Windows up to Server 2016 Error Reporting information disclosure
6382| [105013] Microsoft Windows 10 1607/10 1703/Server 2016 Hyper-V denial of service
6383| [105011] Microsoft Windows up to Server 2016 Windows Search memory corruption
6384| [105010] Microsoft Windows up to Server 2016 Win32k memory corruption
6385| [105009] Microsoft Windows up to Server 2016 Input Method Editor memory corruption
6386| [105008] Microsoft SQL Server 2012/2014/2016 Analysis Services information disclosure
6387| [104990] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
6388| [104989] Microsoft Windows up to Server 2016 NetBIOS denial of service
6389| [104584] Microsoft Outlook up to 2016 C2R Document File privilege escalation
6390| [104583] Microsoft Outlook up to 2016 C2R Email memory corruption
6391| [104582] Microsoft Outlook up to 2016 C2R Object memory corruption
6392| [103468] Microsoft Exchange Server 2010 SP3/2013 CU16/2013 SP3/2016 CU5 Open Redirect
6393| [103446] Microsoft Windows up to Server 2016 Search Object privilege escalation
6394| [103445] Microsoft Windows up to Server 2016 Wordpad privilege escalation
6395| [103444] Microsoft Windows up to Server 2016 Explorer denial of service
6396| [103442] Microsoft Windows 10/Server 2016 HoloLens WiFi Packet privilege escalation
6397| [103441] Microsoft Windows up to Server 2016 Object HTTP.sys information disclosure
6398| [103431] Microsoft Windows up to Server 2016 PowerShell PSObject Object privilege escalation
6399| [103429] Microsoft Windows up to Server 2016 Kerberos weak authentication
6400| [103426] Microsoft Exchange Server 2010 SP3/2013 CU16/2013 SP3/2016 CU5 OWA Request cross site scripting
6401| [103425] Microsoft Exchange Server 2010 SP3/2013 CU16/2013 SP3/2016 CU5 OWA Request cross site scripting
6402| [103420] Microsoft Windows up to Server 2016 Kerberos Bypass privilege escalation
6403| [103417] Microsoft Windows up to Server 2016 Windows Shell privilege escalation
6404| [102544] Microsoft Edge on Win10/Server 2016 Fetch API information disclosure
6405| [102543] Microsoft Edge on Win10/Server 2016 Javascript XML DOM Object information disclosure
6406| [102463] Microsoft Project Server 2013 SP1 cross site scripting
6407| [102460] Microsoft Outlook 2016 on Mac HTML spoofing
6408| [102448] Microsoft SharePoint Enterprise Server 2016 Reflected cross site scripting
6409| [102446] Microsoft Office up to 2016 privilege escalation
6410| [102445] Microsoft Office 2010 SP2/2011/2013 RT SP1/2013 SP1/2016 privilege escalation
6411| [102443] Microsoft Office up to 2016 privilege escalation
6412| [102412] Microsoft Windows up to Server 2016 PDF information disclosure
6413| [102397] Microsoft Outlook 2010 SP1/2013 SP1/2016 DLL Loader privilege escalation
6414| [102396] Microsoft Office 2013 SP1/2016 DLL Loader privilege escalation
6415| [102386] Microsoft Windows up to Server 2012 R2 Uniscribe privilege escalation
6416| [102385] Microsoft Windows up to Server 2016 Font Library privilege escalation
6417| [102376] Microsoft Windows up to Server 2016 CAB File privilege escalation
6418| [102375] Microsoft Windows up to Server 2016 PDF Parser privilege escalation
6419| [102374] Microsoft Windows up to Server 2016 PDF Parser privilege escalation
6420| [102373] Microsoft Windows up to Server 2016 Uniscribe Font USP10!MergeLigRecords memory corruption
6421| [101817] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
6422| [101816] Microsoft Windows up to Server 2016 Malware Protection Engine setCaller memory corruption
6423| [101815] Microsoft Windows up to Server 2016 Malware Protection Engine Use-After-Free memory corruption
6424| [101814] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
6425| [101813] Microsoft Windows up to Server 2016 Malware Protection Engine memory corruption
6426| [101812] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
6427| [101811] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
6428| [101810] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
6429| [101028] Microsoft Windows 10/Server 2016 Hyper-V vSMB privilege escalation
6430| [101020] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
6431| [101019] Microsoft Skype for Business 2016 memory corruption
6432| [101018] Microsoft SharePoint 2010 SP2/2013 SP1/2016 memory corruption
6433| [101016] Microsoft PowerPoint 2011 on Mac memory corruption
6434| [101015] Microsoft PowerPoint 2011 on Mac memory corruption
6435| [101014] Microsoft Office 2010 SP2/2016 memory corruption
6436| [101013] Microsoft Office 2010 SP2/2016 memory corruption
6437| [101002] Microsoft Windows up to Server 2016 SMBv1 Server memory corruption
6438| [101001] Microsoft Windows up to Server 2016 SMBv1 Server memory corruption
6439| [101000] Microsoft Windows up to Server 2016 SMBv1 Server memory corruption
6440| [100999] Microsoft Windows up to Server 2016 SMBv1 Server memory corruption
6441| [100918] Microsoft Windows 8/8.1/10/Server 2012/Server 2016 Malware Protection Service Type Confusion privilege escalation
6442| [99697] Microsoft SharePoint Server 2010 SP1/2010 SP2 Excel Services cross site scripting
6443| [99683] Microsoft Windows 10 1607/10 1703/Server 2012 R2/Server 2016 Active Directory Lockout privilege escalation
6444| [99682] Microsoft Outlook 2011 on Mac HTML Tag Validator spoofing
6445| [99681] Microsoft Windows up to Server 2016 OLE Integrity-Level Check privilege escalation
6446| [99667] Microsoft Windows 10/Server 2016 Active Directory Service Unresponsive denial of service
6447| [98272] Microsoft Windows up to 10/Server 2016 Local Session privilege escalation
6448| [98096] Microsoft Exchange 2013 SP1 privilege escalation
6449| [98095] Microsoft Lync for Mac 2011 Certificate Validation weak authentication
6450| [98094] Microsoft SharePoint Server 2013 SP1 cross site scripting
6451| [98093] Microsoft SharePoint Server/Office Web Apps 2010 SP2 memory corruption
6452| [98091] Microsoft SharePoint Server/Office Web Apps 2010 SP2 memory corruption
6453| [98090] Microsoft SharePoint Server 2010 SP2/2013 SP1 information disclosure
6454| [98089] Microsoft Office Web Apps 2013 SP1 memory corruption
6455| [98082] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 denial of service
6456| [98081] Microsoft Excel up to 2016 information disclosure
6457| [98080] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
6458| [98079] Microsoft Word 2016 memory corruption
6459| [98076] Microsoft Lync/Skype for Business 2010/2013/2016 Graphics Component privilege escalation
6460| [98075] Microsoft Lync/Skype for Business 2010/2013/2016 GDI+ information disclosure
6461| [98074] Microsoft Lync/Skype for Business 2010/2013/2016 GDI+ information disclosure
6462| [98073] Microsoft Office 2010 SP2/Word Viewer Graphics Component information disclosure
6463| [98069] Microsoft Windows up to Server 2012 R2 Color Management memory corruption
6464| [98056] Microsoft Windows up to Server 2016 DNS Query information disclosure
6465| [98054] Microsoft Windows up to Server 2016 SMBv2/SMBv3 NULL Pointer Dereference memory corruption
6466| [98017] Microsoft Windows up to Server 2016 PDF memory corruption
6467| [98015] Microsoft Windows 10/Server 2016 Hyper-V denial of service
6468| [98013] Microsoft Windows 10/Server 2016 Hyper-V vSMB memory corruption
6469| [98007] Microsoft Windows 10/Server 2016 Hyper-V Network Switch denial of service
6470| [98006] Microsoft Windows 10/Server 2016 Hyper-V vSMB memory corruption
6471| [96521] Microsoft Windows 8.1/10/Server 2012/Server 2016 SMB Response mrxsmb20.sys denial of service
6472| [95781] Microsoft PowerPoint 2016 Java Embedded Object privilege escalation
6473| [95125] Microsoft Word/SharePoint Enterprise Server 2016 Document privilege escalation
6474| [94451] Microsoft Office 2011 memory corruption
6475| [94447] Microsoft Office 2010 SP2 memory corruption
6476| [94446] Microsoft Office 2016 memory corruption
6477| [94444] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 OLE DLL Loader memory corruption
6478| [94443] Microsoft Office up to 2016 information disclosure
6479| [94442] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 privilege escalation
6480| [93964] Microsoft Windows 7 Excel Starter 2010 XXE information disclosure
6481| [93543] Microsoft SQL Server 2016 FILESTREAM Path privilege escalation
6482| [93540] Microsoft Excel 2010 SP2/2011/2016 memory corruption
6483| [93416] Microsoft SQL Server 2014 SP2/2016/up to 2012 SP3 Server Agent atxcore.dll privilege escalation
6484| [93415] Microsoft SQL Server 2016 MDS API cross site scripting
6485| [93414] Microsoft SQL Server up to 2012 SP3 RDBMS Engine privilege escalation
6486| [93413] Microsoft SQL Server 2016/up to 2014 SP2 RDBMS Engine privilege escalation
6487| [93412] Microsoft SQL Server 2016 RDBMS Engine privilege escalation
6488| [93393] Microsoft Office up to 2016 memory corruption
6489| [93392] Microsoft Office up to 2016 memory corruption
6490| [93391] Microsoft Office up to 2016 memory corruption
6491| [93389] Microsoft Windows up to Server 2016 Media Foundation memory corruption
6492| [93388] Microsoft Windows up to Server 2016 Animation Manager Stylesheets memory corruption
6493| [92587] Microsoft Windows 8.1/10/RT 8.1/Server 2012/Server 2012 R2 Transaction Manager privilege escalation
6494| [92584] Microsoft Office up to 2016 memory corruption
6495| [91571] Microsoft Windows 8.1/10/RT 8.1/Server 2012/Server 2012 R2 PDF Library information disclosure
6496| [91570] Microsoft Windows 8.1/10/RT 8.1/Server 2012/Server 2012 R2 PDF Library information disclosure
6497| [91556] Microsoft Exchange 2016 Meeting Invation cross site scripting
6498| [91555] Microsoft Exchange 2013/2016 Link spoofing
6499| [91550] Microsoft Office 2016 memory corruption
6500| [91547] Microsoft Office 2010 memory corruption
6501| [91543] Microsoft Office up to 2016 memory corruption
6502| [91541] Microsoft Office 2013/2016 APP-V ASLR privilege escalation
6503| [90711] Microsoft Windows 8.1/10/RT 8.1/Server 2012/Server 2012 R2 PDF privilege escalation
6504| [90710] Microsoft Windows 8.1/RT 8.1/Server 2012/Server 2012 R2 Netlogon privilege escalation
6505| [90704] Microsoft Office 2013/2013 RT/2016 memory corruption
6506| [89043] Microsoft Office up to 2016 memory corruption
6507| [89041] Microsoft Office up to 2016 memory corruption
6508| [89040] Microsoft Office 2010 SP2/2011/2013 RT SP1/2013 SP1/2016 memory corruption
6509| [89038] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 Security Feature privilege escalation
6510| [89037] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
6511| [87961] Microsoft Windows up to Server 2012 R2 Search denial of service
6512| [87959] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 PDF information disclosure
6513| [87958] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 PDF memory corruption
6514| [87957] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 PDF information disclosure
6515| [87956] Microsoft Exchange 2013/2016 Oracle Outside In Libraries information disclosure
6516| [87944] Microsoft Windows Server 2012/Server 2012 R2 Virtual PCI Memory information disclosure
6517| [87940] Microsoft Windows Server 2012/Server 2012 R2 DNS Server Use-After-Free memory corruption
6518| [87936] Microsoft Office up to 2016 memory corruption
6519| [87166] Microsoft Windows up to Server 2012 R2 DirectX Graphics Kernel Subsystem privilege escalation
6520| [87156] Microsoft Windows 8.1/10/RT 8.1/Server 2012 R2 Shell memory corruption
6521| [87149] Microsoft Office up to 2016 memory corruption
6522| [87148] Microsoft Office 2010 Graphics memory corruption
6523| [87146] Microsoft Office 2011/2013/2013 RT/2016 memory corruption
6524| [82229] Microsoft Excel 2010 SP2 Office Document memory corruption
6525| [82223] Microsoft Windows 8.1/10/Server 2012 R2 Hyper-V Memory information disclosure
6526| [82222] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 Memory information disclosure
6527| [82221] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 Hyper-V privilege escalation
6528| [81274] Microsoft Office up to 2016 memory corruption
6529| [81270] Microsoft Windows 8.1/10/RT 8.1/Server 2012/Server 2012 R2 PDF Library memory corruption
6530| [81269] Microsoft Windows up to Server 2012 R2 Media Parser memory corruption
6531| [81268] Microsoft Windows up to Server 2012 R2 Media Parser memory corruption
6532| [80886] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
6533| [80885] Microsoft Windows 7 SP1/8.1/10/Server 2012/Server 2012 R2 RDP memory corruption
6534| [80878] Microsoft Windows Server 2012 R2 Active Directory Federation Service denial of service
6535| [80874] Microsoft Windows 7 SP1/8.1/10/Server 2012/Server 2012 R2 RDP privilege escalation
6536| [80870] Microsoft Office up to 2016 memory corruption
6537| [80868] Microsoft Office up to 2016 memory corruption
6538| [80867] Microsoft Office up to 2016 memory corruption
6539| [80865] Microsoft Windows 8.1/RT 8.1/Server 2012/Server 2012 R2 DLL Loader memory corruption
6540| [80860] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 Reader memory corruption
6541| [80859] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 PDF Library memory corruption
6542| [80231] Microsoft Excel up to 2016 Office Document memory corruption
6543| [80229] Microsoft Exchange Server 2013 CU 10/2013 CU 11/2013 SP1/2016 Outlook Web Access cross site scripting
6544| [80228] Microsoft Exchange Server 2016 Outlook Web Access cross site scripting
6545| [80227] Microsoft Exchange Server 2013 CU 10/2013 SP1/2016 Outlook Web Access cross site scripting
6546| [80226] Microsoft Exchange Server 2016 Outlook Web Access cross site scripting
6547| [80218] Microsoft Office up to 2016 ASLR privilege escalation
6548| [80217] Microsoft SharePoint Foundation 2013 SP1 Access Control Policy cross site scripting
6549| [80216] Microsoft Office up to 2016 Office Document memory corruption
6550| [80206] Microsoft SharePoint Foundation 2013 SP1 Access Control Policy cross site scripting
6551| [128763] Microsoft Exchange Server 2016 CU10/2016 CU11/2019 memory corruption
6552| [79508] Microsoft Windows up to Server 2012 R2 Library Loader memory corruption
6553| [79500] Microsoft Office 2010/2011/2016 memory corruption
6554| [79183] Microsoft Windows up to Server 2012 R2 IPsec denial of service
6555| [79173] Microsoft Windows up to Server 2012 R2 Graphics information disclosure
6556| [79117] Microsoft Outlook 2011/2016 on Mac HTML spoofing
6557| [78375] Microsoft SharePoint Server/SharePoint Foundation 2013 SP1 cross site scripting
6558| [77645] Microsoft Exchange Server 2013 CU8/2013 CU9 Outlook Web Access cross site scripting
6559| [77644] Microsoft Exchange Server 2013 CU8/2013 CU9 Outlook Web Access cross site scripting
6560| [77638] Microsoft Lync Server 2013 cross site scripting
6561| [77628] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
6562| [77612] Microsoft Exchange Server 2013 CU8/2013 CU9 Outlook Web Access Stack-Based information disclosure
6563| [77050] Microsoft Office up to 2016 memory corruption
6564| [77037] Microsoft Windows Server 2012/Server 2012 R2 System Center Operations Manager cross site scripting
6565| [76461] Microsoft Windows up to Server 2012 R2 Domain-Controller Communication Credentials information disclosure
6566| [76460] Microsoft Windows 7 SP1/8/Server 2012 RDP Server Service memory corruption
6567| [76448] Microsoft Windows 8.1/Server 2012 R2 Hyper-V memory corruption
6568| [75793] Microsoft Exchange Server 2013 CU8 cross site scripting
6569| [75792] Microsoft Exchange Server 2013 SP1 CU8 cross site request forgery
6570| [75791] Microsoft Office 2013 SP1 Office Document Uninitialized Memory memory corruption
6571| [75787] Microsoft Exchange Server 2013 SP1 CU8 Same Origin Policy privilege escalation
6572| [75786] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1 Office Document memory corruption
6573| [66976] Microsoft Access 2010 VBA Datatype denial of service
6574| [74848] Microsoft SharePoint Foundation/SharePoint Server 2013 SP1 cross site scripting
6575| [74842] Microsoft Windows 8.1/Server 2012 R2 Hyper-V denial of service
6576| [74836] Microsoft Project Server 2010 SP2/2013 SP1 cross site scripting
6577| [74835] Microsoft Office 2011 on Mac Use-After-Free cross site scripting
6578| [74834] Microsoft Windows Server 2012 R2 Active Directory Federation Services 3.0 privilege escalation
6579| [74833] Microsoft Windows 7 SP1/8/8.1/Server 2012/Server 2012 R2 HTTP Request HTTP.sys privilege escalation
6580| [74393] Microsoft SharePoint Server 2013 Foundation cross site scripting
6581| [73967] Microsoft Office up to 2013 SP1 Office File memory corruption
6582| [73966] Microsoft Office up to 2013 SP1 RTF File memory corruption
6583| [73965] Microsoft Office up to 2013 SP1 Use-After-Free memory corruption
6584| [73961] Microsoft Windows 7 SP1/8/8.1/Server 2012/Server 2012 R2 Remote Desktop Protocol Object Management denial of service
6585| [69162] Microsoft System Center Virtual Machine Manager 2012 privilege escalation
6586| [69160] Microsoft Windows up to Server 2012 Process privilege escalation
6587| [69156] Microsoft Office 2010 Object memory corruption
6588| [68593] Microsoft Windows up to Server 2012 Network Location Awareness Service privilege escalation
6589| [68417] Microsoft Exchange 2013 Outlook Web Access Token spoofing
6590| [68191] Microsoft SharePoint 2010 cross site scripting
6591| [67828] Microsoft ASP.NET MVC 2/3/4/5/5.1 System.Web.Mvc.dll cross site scripting
6592| [67518] Microsoft Lync 2013 denial of service
6593| [67517] Microsoft Lync 2013 Script Reflected cross site scripting
6594| [67516] Microsoft Lync 2010/2013 denial of service
6595| [67362] Microsoft Windows up to Server 2012 R2 Remote Procedure Call privilege escalation
6596| [67360] Microsoft SharePoint 2013 App Permission Management cross site scripting
6597| [13549] Microsoft Windows 7/8/8.1/Server 2012 Remote Desktop Protocol weak encryption
6598| [13547] Microsoft Lync 2010/2013 Meeting cross site scripting
6599| [13228] Microsoft Office 2013 Document privilege escalation
6600| [68577] Microsoft ASP.NET 2014.3.1209 Telerik UI RadAsyncUpload directory traversal
6601| [12267] Microsoft Forefront Security for Exchange Server 2010 Mail memory corruption
6602| [12263] Microsoft Windows up to Server 2012 Direct2D 2D Geometric Figure memory corruption
6603| [12238] Microsoft Windows 8/RT/Server 2012 IPv6 denial of service
6604| [12185] Microsoft .NET Framework 2/4 HMAC weak authentication
6605| [12183] Microsoft .NET Framework 2/4 DTD denial of service
6606| [11673] Microsoft Windows Live Movie Maker 2011 WAV File denial of service
6607| [11468] Microsoft Exchange 2010/2013 cross site scripting
6608| [11466] Microsoft Office 2013 File Response information disclosure
6609| [11457] Microsoft SharePoint Server/Office Web Apps 2010 SP1/2010 SP2/2013 W3WP Service Account privilege escalation
6610| [11150] Microsoft Windows 8/Server 2012 Hyper-V Data Structure Value Crash privilege escalation
6611| [11004] Microsoft Windows Server 2012 R2 RDP Restricted Admin Mode weak authentication
6612| [10250] Microsoft SharePoint Server up to 2013 W3WP Process denial of service
6613| [10249] Microsoft SharePoint 2010/2003/2007/2.0/3.0 Workflow memory corruption
6614| [10248] Microsoft SharePoint Server up to 2013 cross site scripting
6615| [9943] Microsoft Windows Server 2012 NAT Driver ICMP Packet denial of service
6616| [8739] Microsoft Windows Essentials up to 2012 Windows Writer Eingabe information disclosure
6617| [8725] Microsoft Lync 2010/2013 Use-After-Free memory corruption
6618| [8722] Microsoft Windows 8/RT/Server 2012 HTTP.sys denial of service
6619| [8206] Microsoft SharePoint Server 2010 SP1 HTML Sanitization Component cross site scripting
6620| [8203] Microsoft Windows up to 2012 AD LDAP Query denial of service
6621| [8200] Microsoft SharePoint Server 2013 ACL information disclosure
6622| [7971] Microsoft Office for Mac 2011 up to 14.3.1 on Mac HTML5 Mail Message Parser File information disclosure
6623| [7969] Microsoft OneNote 2010 SP1 ONE File information disclosure
6624| [7968] Microsoft SharePoint Server 2010 SP1 Input Validator Eingabe Crash denial of service
6625| [7967] Microsoft SharePoint Server 2010 SP1 User Account Eingabe Crash information disclosure
6626| [7966] Microsoft SharePoint Server 2010 SP1 Eingabe Crash cross site scripting
6627| [7965] Microsoft SharePoint Server 2010 SP1 User Account Callback URL privilege escalation
6628| [7964] Microsoft Visio 2010 Tree Object Type File memory corruption
6629| [7343] Microsoft Lync 2012 HTTP Format String
6630| [7258] Microsoft Windows up to 8/Server 2012 SSL/TLS race condition
6631| [7230] Microsoft Excel 2010 SP1 on 32-bit XLS File Formatting Information Crash denial of service
6632| [6831] Microsoft Office Picture Manager 2010 File memory corruption
6633| [62720] EMC NetWorker Module for Microsoft Applications up to 2.2.0 memory corruption
6634| [6624] Microsoft SQL Server up to 2012 Report Manager cross site scripting
6635| [62238] Microsoft Visual Studio Team Foundation Server 2010 cross site scripting
6636| [5946] Microsoft Visio/Visio Viewer up to 2010 SP1 File memory corruption
6637| [5644] Microsoft SharePoint 2010 scriptesx.ashx cross site scripting
6638| [5641] Microsoft SharePoint 2010 cross site scripting
6639| [60943] Microsoft Dynamics AX 2012 Enterprise Portal cross site scripting
6640| [12311] Microsoft Lync 2010 Search race condition
6641| [60570] Microsoft Forefront Unified Access Gateway 2010 information disclosure
6642| [60569] Microsoft Forefront Unified Access Gateway 2010 spoofing
6643| [60208] Microsoft Visio Viewer 2010 memory corruption
6644| [60207] Microsoft Visio Viewer 2010 memory corruption
6645| [60206] Microsoft Visio Viewer 2010 memory corruption
6646| [4640] Microsoft SharePoint 2010 inplview.aspx cross site scripting
6647| [4636] Microsoft SharePoint 2010 wizardlist.aspx cross site scripting
6648| [4635] Microsoft SharePoint 2010 themeweb.aspx cross site scripting
6649| [59008] Microsoft Forefront Unified Access Gateway 2010 Crash denial of service
6650| [58995] Microsoft Forefront Unified Access Gateway 2010 memory corruption
6651| [58994] Microsoft Forefront Unified Access Gateway 2010 Reflected cross site scripting
6652| [58993] Microsoft Forefront Unified Access Gateway 2010 Reflected cross site scripting
6653| [4424] Microsoft Host Integration Server up to 2010 denial of service
6654| [4420] Microsoft Forefront Unified Access Gateway 2010 memory corruption
6655| [58487] Microsoft SharePoint Foundation 2010 cross site scripting
6656| [58486] Microsoft SharePoint Foundation 2010 Reflected cross site scripting
6657| [58485] Microsoft SharePoint Foundation 2010 EditForm.aspx cross site scripting
6658| [4414] Microsoft SharePoint 2010 cross site scripting
6659| [4413] Microsoft SharePoint 2010/2007/3.0 XML/XLS unknown vulnerability
6660| [91971] Microsoft Skype 2.2.x/5.2.x/5.3.x denial of service
6661| [57693] Microsoft Forefront Threat Management Gateway 2010 NSPLookupServiceNext memory corruption
6662| [56028] Microsoft Data Access Components 2.8 memory corruption
6663| [55777] Microsoft Windows Movie Maker 2.6 memory corruption
6664| [55424] Microsoft Forefront Unified Access Gateway 2010 Signurl.asp cross site scripting
6665| [55415] Microsoft Forefront Unified Access Gateway 2010 cross site scripting
6666| [55414] Microsoft Forefront Unified Access Gateway 2010 cross site scripting
6667| [55413] Microsoft Forefront Unified Access Gateway 2010 spoofing
6668| [54341] Microsoft Windows Movie Maker 2.1 memory corruption
6669| [54549] Microsoft PowerPoint 2010 pptimpconv.dll memory corruption
6670| [4009] Microsoft NET Framework 2.x/3.x denial of service
6671| [45681] Microsoft Internet Explorer 8 Beta 2 privilege escalation
6672| [45449] Microsoft Internet Explorer 8 Beta 2 XSS Filter cross site scripting
6673| [45448] Microsoft Internet Explorer 8 Beta 2 XSS Filter cross site scripting
6674| [45446] Microsoft Internet Explorer 8 Beta 2 XSS Filter cross site scripting
6675| [2927] Microsoft Data Access Components 2.x ADODB.Connection ActiveX Control memory corruption
6676| [32692] Microsoft XML Core Services up to 2.6 memory corruption
6677| [32691] Microsoft XML Core Services up to 2.6 memory corruption
6678|
6679| MITRE CVE - https://cve.mitre.org:
6680| [CVE-2013-3661] The EPATHOBJ::bFlatten function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not check whether linked-list traversal is continually accessing the same list member, which allows local users to cause a denial of service (infinite traversal) via vectors that trigger a crafted PATHRECORD chain.
6681| [CVE-2013-3660] The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 does not properly initialize a pointer for the next object in a certain list, which allows local users to obtain write access to the PATHRECORD chain, and consequently gain privileges, by triggering excessive consumption of paged memory and then making many FlattenPath function calls, aka "Win32k Read AV Vulnerability."
6682| [CVE-2013-3174] DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 allows remote attackers to execute arbitrary code via a crafted GIF file, aka "DirectShow Arbitrary Memory Overwrite Vulnerability."
6683| [CVE-2013-3173] Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Win32k Buffer Overwrite Vulnerability."
6684| [CVE-2013-3172] Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to cause a denial of service (system hang) via a crafted application that leverages improper handling of objects in memory, aka "Win32k Buffer Overflow Vulnerability."
6685| [CVE-2013-3171] The serialization functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly check the permissions of delegate objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a partial-trust relationship, aka "Delegate Serialization Vulnerability."
6686| [CVE-2013-3167] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Information Disclosure Vulnerability."
6687| [CVE-2013-3154] The signature-update functionality in Windows Defender on Microsoft Windows 7 and Windows Server 2008 R2 relies on an incorrect pathname, which allows local users to gain privileges via a Trojan horse application in the %SYSTEMDRIVE% top-level directory, aka "Microsoft Windows 7 Defender Improper Pathname Vulnerability."
6688| [CVE-2013-3138] Integer overflow in the TCP/IP kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (system hang) via crafted TCP packets, aka "TCP/IP Integer Overflow Vulnerability."
6689| [CVE-2013-3136] The kernel in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, and Windows 8 on 32-bit platforms does not properly handle unspecified page-fault system calls, which allows local users to obtain sensitive information from kernel memory via a crafted application, aka "Kernel Information Disclosure Vulnerability."
6690| [CVE-2013-3134] The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 on 64-bit platforms does not properly allocate arrays of structures, which allows remote attackers to execute arbitrary code via a crafted .NET Framework application that changes array data, aka "Array Allocation Vulnerability."
6691| [CVE-2013-3133] Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "Anonymous Method Injection Vulnerability."
6692| [CVE-2013-3132] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "Delegate Reflection Bypass Vulnerability."
6693| [CVE-2013-3131] Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5, and Silverlight 5 before 5.1.20513.0, does not properly prevent changes to data in multidimensional arrays of structures, which allows remote attackers to execute arbitrary code via (1) a crafted .NET Framework application or (2) a crafted Silverlight application, aka "Array Access Violation Vulnerability."
6694| [CVE-2013-1345] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Vulnerability."
6695| [CVE-2013-1340] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Dereference Vulnerability."
6696| [CVE-2013-1339] The Print Spooler in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly manage memory during deletion of printer connections, which allows remote authenticated users to execute arbitrary code via a crafted request, aka "Print Spooler Vulnerability."
6697| [CVE-2013-1336] The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check signatures, which allows remote attackers to make undetected changes to signed XML documents via unspecified vectors that preserve signature validity, aka "XML Digital Signature Spoofing Vulnerability."
6698| [CVE-2013-1335] Microsoft Word 2003 SP3 and Word Viewer allow remote attackers to execute arbitrary code via crafted shape data in a Word document, aka "Word Shape Corruption Vulnerability."
6699| [CVE-2013-1334] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Window Handle Vulnerability."
6700| [CVE-2013-1332] dxgkrnl.sys (aka the DirectX graphics kernel subsystem) in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "DirectX Graphics Kernel Subsystem Double Fetch Vulnerability."
6701| [CVE-2013-1331] Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Office document, leading to improper memory allocation, aka "Office Buffer Overflow Vulnerability."
6702| [CVE-2013-1329] Integer signedness error in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers a buffer underflow, aka "Publisher Buffer Underflow Vulnerability."
6703| [CVE-2013-1328] Microsoft Publisher 2003 SP3, 2007 SP3, and 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers incorrect pointer handling, aka "Publisher Pointer Handling Vulnerability."
6704| [CVE-2013-1327] Integer signedness error in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers an improper memory allocation, aka "Publisher Signed Integer Vulnerability."
6705| [CVE-2013-1323] Microsoft Publisher 2003 SP3 does not properly handle NULL values for unspecified data items, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Incorrect NULL Value Handling Vulnerability."
6706| [CVE-2013-1322] Microsoft Publisher 2003 SP3 does not properly check table range data, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Invalid Range Check Vulnerability."
6707| [CVE-2013-1321] Microsoft Publisher 2003 SP3 does not properly check the data type of an unspecified return value, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Return Value Validation Vulnerability."
6708| [CVE-2013-1320] Buffer overflow in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Buffer Overflow Vulnerability."
6709| [CVE-2013-1319] Microsoft Publisher 2003 SP3 does not properly check the return value of an unspecified method, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Return Value Handling Vulnerability."
6710| [CVE-2013-1318] Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers access to an invalid pointer, aka "Publisher Corrupt Interface Pointer Vulnerability."
6711| [CVE-2013-1317] Integer overflow in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers an improper allocation-size calculation, aka "Publisher Integer Overflow Vulnerability."
6712| [CVE-2013-1316] Microsoft Publisher 2003 SP3 does not properly validate the size of an unspecified array, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Negative Value Allocation Vulnerability."
6713| [CVE-2013-1302] Microsoft Communicator 2007 R2, Lync 2010, Lync 2010 Attendee, and Lync Server 2013 do not properly handle objects in memory, which allows remote attackers to execute arbitrary code via an invitation that triggers access to a deleted object, aka "Lync RCE Vulnerability."
6714| [CVE-2013-1301] Microsoft Visio 2003 SP3 2007 SP3, and 2010 SP1 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, aka "XML External Entities Resolution Vulnerability."
6715| [CVE-2013-1300] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Memory Allocation Vulnerability."
6716| [CVE-2013-1295] The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "CSRSS Memory Corruption Vulnerability."
6717| [CVE-2013-1294] Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Kernel Race Condition Vulnerability."
6718| [CVE-2013-1293] The NTFS kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via a crafted application that leverages improper handling of objects in memory, aka "NTFS NULL Pointer Dereference Vulnerability."
6719| [CVE-2013-1292] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Win32k Race Condition Vulnerability."
6720| [CVE-2013-1291] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 Gold and SP1, and Windows 8 allows local users to cause a denial of service (reboot) via a crafted OpenType font, aka "OpenType Font Parsing Vulnerability" or "Win32k Font Parsing Vulnerability."
6721| [CVE-2013-1287] The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Windows USB Descriptor Vulnerability," a different vulnerability than CVE-2013-1285 and CVE-2013-1286.
6722| [CVE-2013-1286] The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Windows USB Descriptor Vulnerability," a different vulnerability than CVE-2013-1285 and CVE-2013-1287.
6723| [CVE-2013-1285] The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Windows USB Descriptor Vulnerability," a different vulnerability than CVE-2013-1286 and CVE-2013-1287.
6724| [CVE-2013-1283] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Win32k Race Condition Vulnerability."
6725| [CVE-2013-1281] The NFS server in Microsoft Windows Server 2008 R2 and R2 SP1 and Server 2012 allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via an attempted renaming of a file or folder located on a read-only share, aka "NULL Dereference Vulnerability."
6726| [CVE-2013-1280] The kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Reference Count Vulnerability."
6727| [CVE-2013-1279] Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages incorrect handling of objects in memory, aka "Kernel Race Condition Vulnerability," a different vulnerability than CVE-2013-1278.
6728| [CVE-2013-1278] Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages incorrect handling of objects in memory, aka "Kernel Race Condition Vulnerability," a different vulnerability than CVE-2013-1279.
6729| [CVE-2013-1277] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
6730| [CVE-2013-1276] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
6731| [CVE-2013-1275] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
6732| [CVE-2013-1274] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
6733| [CVE-2013-1273] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
6734| [CVE-2013-1272] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
6735| [CVE-2013-1271] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
6736| [CVE-2013-1270] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
6737| [CVE-2013-1269] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
6738| [CVE-2013-1268] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
6739| [CVE-2013-1267] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
6740| [CVE-2013-1266] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
6741| [CVE-2013-1265] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
6742| [CVE-2013-1264] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
6743| [CVE-2013-1263] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
6744| [CVE-2013-1262] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
6745| [CVE-2013-1261] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
6746| [CVE-2013-1260] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
6747| [CVE-2013-1259] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
6748| [CVE-2013-1258] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
6749| [CVE-2013-1257] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
6750| [CVE-2013-1256] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
6751| [CVE-2013-1255] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
6752| [CVE-2013-1254] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
6753| [CVE-2013-1253] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
6754| [CVE-2013-1252] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
6755| [CVE-2013-1251] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
6756| [CVE-2013-1250] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
6757| [CVE-2013-1249] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
6758| [CVE-2013-1248] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
6759| [CVE-2013-0095] Outlook in Microsoft Office for Mac 2008 before 12.3.6 and Office for Mac 2011 before 14.3.2 allows remote attackers to trigger access to a remote URL and consequently confirm the rendering of an HTML e-mail message by including unspecified HTML5 elements and leveraging the installation of a WebKit browser on the victim's machine, aka "Unintended Content Loading Vulnerability."
6760| [CVE-2013-0077] Quartz.dll in DirectShow in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows remote attackers to execute arbitrary code via crafted media content in (1) a media file, (2) a media stream, or (3) a Microsoft Office document, aka "Media Decompression Vulnerability."
6761| [CVE-2013-0076] The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Reference Count Vulnerability."
6762| [CVE-2013-0075] The TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (reboot) via a crafted packet that terminates a TCP connection, aka "TCP FIN WAIT Vulnerability."
6763| [CVE-2013-0073] The Windows Forms (aka WinForms) component in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly restrict the privileges of a callback function during object creation, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "WinForms Callback Elevation Vulnerability."
6764| [CVE-2013-0013] The SSL provider component in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle encrypted packets, which allows man-in-the-middle attackers to conduct SSLv2 downgrade attacks against (1) SSLv3 sessions or (2) TLS sessions by intercepting handshakes and injecting content, aka "Microsoft SSL Version 3 and TLS Protocol Security Feature Bypass Vulnerability."
6765| [CVE-2013-0011] The Print Spooler in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted print job, aka "Windows Print Spooler Components Vulnerability."
6766| [CVE-2013-0010] Cross-site scripting (XSS) vulnerability in Microsoft System Center Operations Manager 2007 SP1 and R2 allows remote attackers to inject arbitrary web script or HTML via crafted input, aka "System Center Operations Manager Web Console XSS Vulnerability," a different vulnerability than CVE-2013-0009.
6767| [CVE-2013-0009] Cross-site scripting (XSS) vulnerability in Microsoft System Center Operations Manager 2007 SP1 and R2 allows remote attackers to inject arbitrary web script or HTML via crafted input, aka "System Center Operations Manager Web Console XSS Vulnerability," a different vulnerability than CVE-2013-0010.
6768| [CVE-2013-0008] win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle window broadcast messages, which allows local users to gain privileges via a crafted application, aka "Win32k Improper Message Handling Vulnerability."
6769| [CVE-2013-0004] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate the permissions of objects in memory, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "Double Construction Vulnerability."
6770| [CVE-2013-0003] Buffer overflow in a System.DirectoryServices.Protocols (S.DS.P) namespace method in Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a missing array-size check during a memory copy operation, aka "S.DS.P Buffer Overflow Vulnerability."
6771| [CVE-2013-0002] Buffer overflow in the Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages improper counting of objects during a memory copy operation, aka "WinForms Buffer Overflow Vulnerability."
6772| [CVE-2013-0001] The Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 4, and 4.5 does not properly initialize memory arrays, which allows remote attackers to obtain sensitive information via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a pointer to an unmanaged memory location, aka "System Drawing Information Disclosure Vulnerability."
6773| [CVE-2012-5672] Microsoft Excel Viewer (aka Xlview.exe) and Excel in Microsoft Office 2007 (aka Office 12) allow remote attackers to cause a denial of service (read access violation and application crash) via a crafted spreadsheet file, as demonstrated by a .xls file with battery voltage data.
6774| [CVE-2012-4791] Microsoft Exchange Server 2007 SP3 and 2010 SP1 and SP2 allows remote authenticated users to cause a denial of service (Information Store service hang) by subscribing to a crafted RSS feed, aka "RSS Feed May Cause Exchange DoS Vulnerability."
6775| [CVE-2012-4786] The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allow remote attackers to execute arbitrary code via a crafted TrueType Font (TTF) file, aka "TrueType Font Parsing Vulnerability."
6776| [CVE-2012-4776] The Web Proxy Auto-Discovery (WPAD) functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not validate configuration data that is returned during acquisition of proxy settings, which allows remote attackers to execute arbitrary JavaScript code by providing crafted data during execution of (1) an XAML browser application (aka XBAP) or (2) a .NET Framework application, aka "Web Proxy Auto-Discovery Vulnerability."
6777| [CVE-2012-4774] Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allow remote attackers to execute arbitrary code via a crafted (1) file name or (2) subfolder name that triggers use of unallocated memory as the destination of a copy operation, aka "Windows Filename Parsing Vulnerability."
6778| [CVE-2012-2897] The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT, as used by Google Chrome before 22.0.1229.79 and other programs, do not properly handle objects in memory, which allows remote attackers to execute arbitrary code via a crafted TrueType font file, aka "Windows Font Parsing Vulnerability" or "TrueType Font Parsing Vulnerability."
6779| [CVE-2012-2556] The OpenType Font (OTF) driver in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to execute arbitrary code via a crafted OpenType font file, aka "OpenType Font Parsing Vulnerability."
6780| [CVE-2012-2553] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application, aka "Win32k Use After Free Vulnerability."
6781| [CVE-2012-2552] Cross-site scripting (XSS) vulnerability in the SQL Server Report Manager in Microsoft SQL Server 2000 Reporting Services SP2 and SQL Server 2005 SP4, 2008 SP2 and SP3, 2008 R2 SP1, and 2012 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "Reflected XSS Vulnerability."
6782| [CVE-2012-2551] The server in Kerberos in Microsoft Windows Server 2008 R2 and R2 SP1, and Windows 7 Gold and SP1, allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via a crafted session request, aka "Kerberos NULL Dereference Vulnerability."
6783| [CVE-2012-2543] Stack-based buffer overflow in Microsoft Excel 2007 SP2 and SP3 and 2010 SP1
6784| [CVE-2012-2539] Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1
6785| [CVE-2012-2536] Cross-site scripting (XSS) vulnerability in Microsoft Systems Management Server 2003 SP3 and System Center Configuration Manager 2007 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Reflected XSS Vulnerability."
6786| [CVE-2012-2530] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application, aka "Win32k Use After Free Vulnerability."
6787| [CVE-2012-2529] Integer overflow in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Windows Kernel Integer Overflow Vulnerability."
6788| [CVE-2012-2528] Use-after-free vulnerability in Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1
6789| [CVE-2012-2527] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application, aka "Win32k Use After Free Vulnerability."
6790| [CVE-2012-2524] Microsoft Office 2007 SP2 and SP3 and 2010 SP1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Computer Graphics Metafile (CGM) file, aka "CGM File Format Memory Corruption Vulnerability."
6791| [CVE-2012-2520] Cross-site scripting (XSS) vulnerability in Microsoft InfoPath 2007 SP2 and SP3 and 2010 SP1, Communicator 2007 R2, Lync 2010 and 2010 Attendee, SharePoint Server 2007 SP2 and SP3 and 2010 SP1, Groove Server 2010 SP1, Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010 SP1, and Office Web Apps 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted string, aka "HTML Sanitization Vulnerability."
6792| [CVE-2012-2519] Untrusted search path vulnerability in Entity Framework in ADO.NET in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, and 4 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .NET application, aka ".NET Framework Insecure Library Loading Vulnerability."
6793| [CVE-2012-1896] Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly consider trust levels during construction of output data, which allows remote attackers to obtain sensitive information via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka "Code Access Security Info Disclosure Vulnerability."
6794| [CVE-2012-1895] The reflection implementation in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4 does not properly enforce object permissions, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka "Reflection Bypass Vulnerability."
6795| [CVE-2012-1893] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate callback parameters during creation of a hook procedure, which allows local users to gain privileges via a crafted application, aka "Win32k Incorrect Type Handling Vulnerability."
6796| [CVE-2012-1890] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle keyboard-layout files, which allows local users to gain privileges via a crafted application, aka "Keyboard Layout Vulnerability."
6797| [CVE-2012-1887] Use-after-free vulnerability in Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 SP1, and Office 2008 and 2011 for Mac, allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel SST Invalid Length Use After Free Vulnerability."
6798| [CVE-2012-1886] Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 SP1
6799| [CVE-2012-1885] Heap-based buffer overflow in Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 SP1
6800| [CVE-2012-1870] The CBC mode in the TLS protocol, as used in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and other products, allows remote web servers to obtain plaintext data by triggering multiple requests to a third-party HTTPS server and sniffing the network during the resulting HTTPS session, aka "TLS Protocol Vulnerability."
6801| [CVE-2012-1867] Integer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted TrueType font file that triggers incorrect memory allocation, aka "Font Resource Refcount Integer Overflow Vulnerability."
6802| [CVE-2012-1866] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle user-mode input passed to kernel mode for driver objects, which allows local users to gain privileges via a crafted application, aka "Clipboard Format Atom Name Handling Vulnerability."
6803| [CVE-2012-1865] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle user-mode input passed to kernel mode for driver objects, which allows local users to gain privileges via a crafted application, aka "String Atom Class Name Handling Vulnerability," a different vulnerability than CVE-2012-1864.
6804| [CVE-2012-1864] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle user-mode input passed to kernel mode for driver objects, which allows local users to gain privileges via a crafted application, aka "String Atom Class Name Handling Vulnerability," a different vulnerability than CVE-2012-1865.
6805| [CVE-2012-1863] Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2007 SP2 and SP3 Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "SharePoint Reflected List Parameter Vulnerability."
6806| [CVE-2012-1862] Open redirect vulnerability in Microsoft Office SharePoint Server 2007 SP2 and SP3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka "SharePoint URL Redirection Vulnerability."
6807| [CVE-2012-1860] Microsoft Office SharePoint Server 2007 SP2 and SP3, SharePoint Server 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 do not properly check permissions for search scopes, which allows remote authenticated users to obtain sensitive information or cause a denial of service (data modification) by changing a parameter in a search-scope URL, aka "SharePoint Search Scope Vulnerability."
6808| [CVE-2012-1858] The toStaticHTML API (aka the SafeHTML component) in Microsoft Internet Explorer 8 and 9, Communicator 2007 R2, and Lync 2010 and 2010 Attendee does not properly handle event attributes and script, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted HTML document, aka "HTML Sanitization Vulnerability."
6809| [CVE-2012-1856] The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Server 2000 SP4, SQL Server 2005 SP4, SQL Server 2008 SP2, SP3, R2, R2 SP1, and R2 SP2, Commerce Server 2002 SP4, Commerce Server 2007 SP2, Commerce Server 2009 Gold and R2, Host Integration Server 2004 SP1, Visual FoxPro 8.0 SP1, Visual FoxPro 9.0 SP2, and Visual Basic 6.0 Runtime allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption, aka "MSCOMCTL.OCX RCE Vulnerability."
6810| [CVE-2012-1855] Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly handle function pointers, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka ".NET Framework Memory Access Vulnerability."
6811| [CVE-2012-1854] Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1
6812| [CVE-2012-1851] Format string vulnerability in the Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted response, aka "Print Spooler Service Format String Vulnerability."
6813| [CVE-2012-1850] The Remote Administration Protocol (RAP) implementation in the LanmanWorkstation service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle RAP responses, which allows remote attackers to cause a denial of service (service hang) via crafted RAP packets, aka "Remote Administration Protocol Denial of Service Vulnerability."
6814| [CVE-2012-1848] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly handle user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Scrollbar Calculation Vulnerability."
6815| [CVE-2012-1847] Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1
6816| [CVE-2012-1537] Heap-based buffer overflow in DirectPlay in DirectX 9.0 through 11.1 in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 allows remote attackers to execute arbitrary code via a crafted Office document, aka "DirectPlay Heap Overflow Vulnerability."
6817| [CVE-2012-1528] Integer overflow in Windows Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 allows local users to gain privileges via a crafted briefcase, aka "Windows Briefcase Integer Overflow Vulnerability."
6818| [CVE-2012-1527] Integer underflow in Windows Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 allows local users to gain privileges via a crafted briefcase, aka "Windows Briefcase Integer Underflow Vulnerability."
6819| [CVE-2012-1459] The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, nProtect Anti-Virus 2011-01-17.01, Panda Antivirus 10.0.2.7, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field corresponding to that entire entry, plus part of the header of the next entry. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
6820| [CVE-2012-1457] The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field that exceeds the total TAR file size. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
6821| [CVE-2012-1453] The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Trend Micro AntiVirus 9.120.0.1004, McAfee Gateway (formerly Webwasher) 2010.1C, Emsisoft Anti-Malware 5.1.0.1, CA eTrust Vet Antivirus 36.1.8511, Antiy Labs AVL SDK 2.0.3.7, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Rising Antivirus 22.83.00.03, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via a CAB file with a modified coffFiles field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.
6822| [CVE-2012-1443] The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Command Antivirus 5.2.11.5, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Emsisoft Anti-Malware 5.1.0.1, PC Tools AntiVirus 7.0.3.5, F-Prot Antivirus 4.6.2.117, VirusBuster 13.6.151.0, Fortinet Antivirus 4.2.254.0, Antiy Labs AVL SDK 2.0.3.7, K7 AntiVirus 9.77.3565, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Jiangmin Antivirus 13.0.900, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Sophos Anti-Virus 4.61.0, NOD32 Antivirus 5795, Avira AntiVir 7.11.1.163, Norman Antivirus 6.06.12, McAfee Anti-Virus Scanning Engine 5.400.0.1158, Panda Antivirus 10.0.2.7, McAfee Gateway (formerly Webwasher) 2010.1C, Trend Micro AntiVirus 9.120.0.1004, Comodo Antivirus 7424, Bitdefender 7.2, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, nProtect Anti-Virus 2011-01-17.01, AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, avast! Antivirus 4.8.1351.0 and 5.0.677.0, and VBA32 3.12.14.2 allows user-assisted remote attackers to bypass malware detection via a RAR file with an initial MZ character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different RAR parser implementations.
6823| [CVE-2012-1420] The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Panda Antivirus 10.0.2.7, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial \7fELF character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
6824| [CVE-2012-1194] The resolver in the DNS Server service in Microsoft Windows Server 2008 before R2 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack.
6825| [CVE-2012-0185] Heap-based buffer overflow in Microsoft Excel 2007 SP2 and SP3 and 2010 Gold and SP1, Excel Viewer, and Office Compatibility Pack SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet that triggers incorrect handling of memory during opening, aka "Excel MergeCells Record Heap Overflow Vulnerability."
6826| [CVE-2012-0184] Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1
6827| [CVE-2012-0183] Microsoft Word 2003 SP3 and 2007 SP2 and SP3, Office 2008 and 2011 for Mac, and Office Compatibility Pack SP2 and SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, aka "RTF Mismatch Vulnerability."
6828| [CVE-2012-0182] Microsoft Word 2007 SP2 and SP3 does not properly handle memory during the parsing of Word documents, which allows remote attackers to execute arbitrary code via a crafted document, aka "Word PAPX Section Corruption Vulnerability."
6829| [CVE-2012-0181] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly manage Keyboard Layout files, which allows local users to gain privileges via a crafted application, aka "Keyboard Layout File Vulnerability."
6830| [CVE-2012-0180] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly handle user-mode input passed to kernel mode for (1) windows and (2) messages, which allows local users to gain privileges via a crafted application, aka "Windows and Messages Vulnerability."
6831| [CVE-2012-0179] Double free vulnerability in tcpip.sys in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that binds an IPv6 address to a local interface, aka "TCP/IP Double Free Vulnerability."
6832| [CVE-2012-0178] Race condition in partmgr.sys in Windows Partition Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that makes multiple simultaneous Plug and Play (PnP) Configuration Manager function calls, aka "Plug and Play (PnP) Configuration Manager Vulnerability."
6833| [CVE-2012-0177] Heap-based buffer overflow in the Office Works File Converter in Microsoft Office 2007 SP2, Works 9, and Works 6-9 File Converter allows remote attackers to execute arbitrary code via a crafted Works (aka .wps) file, aka "Office WPS Converter Heap Overflow Vulnerability."
6834| [CVE-2012-0175] The Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted name for a (1) file or (2) directory, aka "Command Injection Vulnerability."
6835| [CVE-2012-0174] Windows Firewall in tcpip.sys in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly enforce firewall rules for outbound broadcast packets, which allows remote attackers to obtain potentially sensitive information by observing broadcast traffic on a local network, aka "Windows Firewall Bypass Vulnerability."
6836| [CVE-2012-0173] The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process packets in memory, which allows remote attackers to execute arbitrary code by sending crafted RDP packets triggering access to an object that (1) was not properly initialized or (2) is deleted, aka "Remote Desktop Protocol Vulnerability," a different vulnerability than CVE-2012-0002.
6837| [CVE-2012-0167] Heap-based buffer overflow in the Office GDI+ library in Microsoft Office 2003 SP3 and 2007 SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted EMF image in an Office document, aka "GDI+ Heap Overflow Vulnerability."
6838| [CVE-2012-0165] GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2 and Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1 does not properly validate record types in EMF images, which allows remote attackers to execute arbitrary code via a crafted image, aka "GDI+ Record Type Vulnerability."
6839| [CVE-2012-0163] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate function parameters, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka ".NET Framework Parameter Validation Vulnerability."
6840| [CVE-2012-0161] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly handle an unspecified exception during use of partially trusted assemblies to serialize input data, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka ".NET Framework Serialization Vulnerability."
6841| [CVE-2012-0160] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly serialize input data, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka ".NET Framework Serialization Vulnerability."
6842| [CVE-2012-0159] Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview
6843| [CVE-2012-0158] The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1
6844| [CVE-2012-0157] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle window messaging, which allows local users to gain privileges via a crafted application that calls the PostMessage function, aka "PostMessage Function Vulnerability."
6845| [CVE-2012-0156] DirectWrite in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly render Unicode characters, which allows remote attackers to cause a denial of service (application hang) via a (1) instant message or (2) web site, aka "DirectWrite Application Denial of Service Vulnerability."
6846| [CVE-2012-0154] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers keyboard layout errors, aka "Keyboard Layout Use After Free Vulnerability."
6847| [CVE-2012-0152] The Remote Desktop Protocol (RDP) service in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (application hang) via a series of crafted packets, aka "Terminal Server Denial of Service Vulnerability."
6848| [CVE-2012-0151] The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to execute arbitrary code via a modified file with additional content, aka "WinVerifyTrust Signature Validation Vulnerability."
6849| [CVE-2012-0150] Buffer overflow in msvcrt.dll in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted media file, aka "Msvcrt.dll Buffer Overflow Vulnerability."
6850| [CVE-2012-0149] afd.sys in the Ancillary Function Driver in Microsoft Windows Server 2003 SP2 does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."
6851| [CVE-2012-0148] afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 on 64-bit platforms does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "AfdPoll Elevation of Privilege Vulnerability."
6852| [CVE-2012-0143] Microsoft Excel 2003 SP3 and Office 2008 for Mac do not properly handle memory during the opening of files, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Memory Corruption Using Various Modified Bytes Vulnerability."
6853| [CVE-2012-0142] Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1
6854| [CVE-2012-0141] Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1
6855| [CVE-2012-0015] Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly calculate the length of an unspecified buffer, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka ".NET Framework Heap Corruption Vulnerability."
6856| [CVE-2012-0014] Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.1.10111, does not properly restrict access to memory associated with unmanaged objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4) a crafted Silverlight application, aka ".NET Framework Unmanaged Objects Vulnerability."
6857| [CVE-2012-0013] Incomplete blacklist vulnerability in the Windows Packager configuration in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted ClickOnce application in a Microsoft Office document, related to .application files, aka "Assembly Execution Vulnerability."
6858| [CVE-2012-0009] Untrusted search path vulnerability in the Windows Object Packager configuration in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a Trojan horse executable file in the current working directory, as demonstrated by a directory that contains a file with an embedded packaged object, aka "Object Packager Insecure Executable Launching Vulnerability."
6859| [CVE-2012-0008] Untrusted search path vulnerability in Microsoft Visual Studio 2008 SP1, 2010, and 2010 SP1 allows local users to gain privileges via a Trojan horse add-in in an unspecified directory, aka "Visual Studio Add-In Vulnerability."
6860| [CVE-2012-0006] The DNS server in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 does not properly handle objects in memory during record lookup, which allows remote attackers to cause a denial of service (daemon restart) via a crafted query, aka "DNS Denial of Service Vulnerability."
6861| [CVE-2012-0005] The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2, when a Chinese, Japanese, or Korean system locale is used, can access uninitialized memory during the processing of Unicode characters, which allows local users to gain privileges via a crafted application, aka "CSRSS Elevation of Privilege Vulnerability."
6862| [CVE-2012-0004] Unspecified vulnerability in DirectShow in DirectX in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted media file, related to Quartz.dll, Qdvd.dll, closed captioning, and the Line21 DirectShow filter, aka "DirectShow Remote Code Execution Vulnerability."
6863| [CVE-2012-0003] Unspecified vulnerability in winmm.dll in Windows Multimedia Library in Windows Media Player (WMP) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows remote attackers to execute arbitrary code via a crafted MIDI file, aka "MIDI Remote Code Execution Vulnerability."
6864| [CVE-2012-0002] The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process packets in memory, which allows remote attackers to execute arbitrary code by sending crafted RDP packets triggering access to an object that (1) was not properly initialized or (2) is deleted, aka "Remote Desktop Protocol Vulnerability."
6865| [CVE-2012-0001] The kernel in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly load structured exception handling tables, which allows context-dependent attackers to bypass the SafeSEH security feature by leveraging a Visual C++ .NET 2003 application, aka "Windows Kernel SafeSEH Bypass Vulnerability."
6866| [CVE-2011-5046] The Graphics Device Interface (GDI) in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted data, as demonstrated by a large height attribute of an IFRAME element rendered by Safari, aka "GDI Access Violation Vulnerability."
6867| [CVE-2011-4434] Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 do not properly enforce AppLocker rules, which allows local users to bypass intended access restrictions via a (1) macro or (2) scripting feature in an application, as demonstrated by Microsoft Office applications and the SANDBOX_INERT and LOAD_IGNORE_CODE_AUTHZ_LEVEL flags.
6868| [CVE-2011-3417] The Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0, when sliding expiry is enabled, does not properly handle cached content, which allows remote attackers to obtain access to arbitrary user accounts via a crafted URL, aka "ASP.NET Forms Authentication Ticket Caching Vulnerability."
6869| [CVE-2011-3416] The Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 allows remote authenticated users to obtain access to arbitrary user accounts via a crafted username, aka "ASP.Net Forms Authentication Bypass Vulnerability."
6870| [CVE-2011-3415] Open redirect vulnerability in the Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted return URL, aka "Insecure Redirect in .NET Form Authentication Vulnerability."
6871| [CVE-2011-3414] The CaseInsensitiveHashProvider.getHashCode function in the HashTable implementation in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters, aka "Collisions in HashTable May Cause DoS Vulnerability."
6872| [CVE-2011-3413] Microsoft PowerPoint 2007 SP2
6873| [CVE-2011-3412] Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, allows remote attackers to execute arbitrary code via a crafted Publisher file that leverages incorrect memory handling, aka "Publisher Memory Corruption Vulnerability."
6874| [CVE-2011-3411] Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that leverages incorrect handling of values in memory, aka "Publisher Invalid Pointer Vulnerability."
6875| [CVE-2011-3410] Array index error in Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, allows remote attackers to execute arbitrary code via a crafted Publisher file that leverages incorrect handling of values in memory, aka "Publisher Out-of-bounds Array Index Vulnerability."
6876| [CVE-2011-3408] Csrsrv.dll in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly check permissions for sending inter-process device-event messages from low-integrity processes to high-integrity processes, which allows local users to gain privileges via a crafted application, aka "CSRSS Local Privilege Elevation Vulnerability."
6877| [CVE-2011-3406] Buffer overflow in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote authenticated users to execute arbitrary code via a crafted query that leverages incorrect memory initialization, aka "Active Directory Buffer Overflow Vulnerability."
6878| [CVE-2011-3403] Microsoft Excel 2003 SP3 and Office 2004 for Mac do not properly handle objects in memory, which allows remote attackers to execute arbitrary code via a crafted Excel spreadsheet, aka "Record Memory Corruption Vulnerability."
6879| [CVE-2011-3402] Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via crafted font data in a Word document or web page, as exploited in the wild in November 2011 by Duqu, aka "TrueType Font Parsing Vulnerability."
6880| [CVE-2011-3400] Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 do not properly handle OLE objects in memory, which allows remote attackers to execute arbitrary code via a crafted object in a file, aka "OLE Property Vulnerability."
6881| [CVE-2011-3397] The Microsoft Time component in DATIME.DLL in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted web site that leverages an unspecified "binary behavior" in Internet Explorer, aka "Microsoft Time Remote Code Execution Vulnerability."
6882| [CVE-2011-3396] Untrusted search path vulnerability in Microsoft PowerPoint 2007 SP2 and 2010 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "PowerPoint Insecure Library Loading Vulnerability."
6883| [CVE-2011-2019] Untrusted search path vulnerability in Microsoft Internet Explorer 9 on Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains an HTML file, aka "Internet Explorer Insecure Library Loading Vulnerability."
6884| [CVE-2011-2018] The kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, and Windows 7 Gold and SP1 does not properly initialize objects, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Exception Handler Vulnerability."
6885| [CVE-2011-2016] Untrusted search path vulnerability in Windows Mail and Windows Meeting Space in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .eml or .wcinv file, aka "Windows Mail Insecure Library Loading Vulnerability."
6886| [CVE-2011-2014] The LDAP over SSL (aka LDAPS) implementation in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not examine Certificate Revocation Lists (CRLs), which allows remote authenticated users to bypass intended certificate restrictions and access Active Directory resources by leveraging a revoked X.509 certificate for a domain account, aka "LDAPS Authentication Bypass Vulnerability."
6887| [CVE-2011-2013] Integer overflow in the TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code by sending a sequence of crafted UDP packets to a closed port, aka "Reference Counter Overflow Vulnerability."
6888| [CVE-2011-2011] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, aka "Win32k Use After Free Vulnerability."
6889| [CVE-2011-2008] Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service outage) via crafted TCP or UDP traffic, aka "Access of Unallocated Memory DoS Vulnerability."
6890| [CVE-2011-2007] Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service outage) via crafted TCP or UDP traffic, aka "Endless Loop DoS in snabase.exe Vulnerability."
6891| [CVE-2011-2005] afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."
6892| [CVE-2011-2004] Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (reboot) via a crafted TrueType font file, aka "TrueType Font Parsing Vulnerability," a different vulnerability than CVE-2011-3402.
6893| [CVE-2011-2003] Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted .fon file, aka "Font Library File Buffer Overrun Vulnerability."
6894| [CVE-2011-2002] win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle TrueType fonts, which allows local users to cause a denial of service (system hang) via a crafted font file, aka "Win32k TrueType Font Type Translation Vulnerability."
6895| [CVE-2011-1991] Multiple untrusted search path vulnerabilities in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allow local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .doc, .rtf, or .txt file, related to (1) deskpan.dll in the Display Panning CPL Extension, (2) EAPHost Authenticator Service, (3) Folder Redirection, (4) HyperTerminal, (5) the Japanese Input Method Editor (IME), and (6) Microsoft Management Console (MMC), aka "Windows Components Insecure Library Loading Vulnerability."
6896| [CVE-2011-1990] Microsoft Excel 2007 SP2
6897| [CVE-2011-1989] Microsoft Excel 2003 SP3 and 2007 SP2
6898| [CVE-2011-1988] Microsoft Excel 2003 SP3 and 2007 SP2
6899| [CVE-2011-1987] Array index error in Microsoft Excel 2003 SP3 and 2007 SP2
6900| [CVE-2011-1986] Use-after-free vulnerability in Microsoft Excel 2003 SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Use after Free WriteAV Vulnerability."
6901| [CVE-2011-1985] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via a crafted application, aka "Win32k Null Pointer De-reference Vulnerability."
6902| [CVE-2011-1984] WINS in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 allows local users to gain privileges by sending crafted packets over the loopback interface, aka "WINS Local Elevation of Privilege Vulnerability."
6903| [CVE-2011-1983] Use-after-free vulnerability in Microsoft Office 2007 SP2 and SP3, Office 2010 Gold and SP1, and Office for Mac 2011 allows remote attackers to execute arbitrary code via a crafted Word document, aka "Word Use After Free Vulnerability."
6904| [CVE-2011-1982] Microsoft Office 2007 SP2, and 2010 Gold and SP1, does not initialize an unspecified object pointer during the opening of Word documents, which allows remote attackers to execute arbitrary code via a crafted document, aka "Office Uninitialized Object Pointer Vulnerability."
6905| [CVE-2011-1980] Untrusted search path vulnerability in Microsoft Office 2003 SP3 and 2007 SP2 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .doc, .ppt, or .xls file, aka "Office Component Insecure Library Loading Vulnerability."
6906| [CVE-2011-1979] Microsoft Visio 2003 SP3 and 2007 SP2 does not properly validate objects in memory during Visio file parsing, which allows remote attackers to execute arbitrary code via a crafted file, aka "Move Around the Block RCE Vulnerability."
6907| [CVE-2011-1978] Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4 does not properly validate the System.Net.Sockets trust level, which allows remote attackers to obtain sensitive information or trigger arbitrary outbound network traffic via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Socket Restriction Bypass Vulnerability."
6908| [CVE-2011-1976] Cross-site scripting (XSS) vulnerability in the Report Viewer Control in Microsoft Visual Studio 2005 SP1 and Report Viewer 2005 SP1 allows remote attackers to inject arbitrary web script or HTML via a parameter in a data source, aka "Report Viewer Controls XSS Vulnerability."
6909| [CVE-2011-1975] Untrusted search path vulnerability in the Data Access Tracing component in Windows Data Access Components (Windows DAC) 6.0 in Microsoft Windows 7 Gold and SP1 and Windows Server 2008 R2 and R2 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains an Excel .xlsx file, aka "Data Access Components Insecure Library Loading Vulnerability."
6910| [CVE-2011-1974] NDISTAPI.sys in the NDISTAPI driver in Remote Access Service (RAS) in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "NDISTAPI Elevation of Privilege Vulnerability."
6911| [CVE-2011-1972] Microsoft Visio 2003 SP3, 2007 SP2, and 2010 Gold and SP1 does not properly validate objects in memory during Visio file parsing, which allows remote attackers to execute arbitrary code via a crafted file, aka "pStream Release RCE Vulnerability."
6912| [CVE-2011-1971] The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly parse file metadata, which allows local users to cause a denial of service (reboot) via a crafted file, aka "Windows Kernel Metadata Parsing DOS Vulnerability."
6913| [CVE-2011-1970] The DNS server in Microsoft Windows Server 2003 SP2 and Windows Server 2008 SP2, R2, and R2 SP1 does not properly initialize memory, which allows remote attackers to cause a denial of service (service outage) via a query for a nonexistent domain, aka "DNS Uninitialized Memory Corruption Vulnerability."
6914| [CVE-2011-1968] The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 does not properly process packets in memory, which allows remote attackers to cause a denial of service (reboot) by sending crafted RDP packets triggering access to an object that (1) was not properly initialized or (2) is deleted, as exploited in the wild in 2011, aka "Remote Desktop Protocol Vulnerability."
6915| [CVE-2011-1967] Winsrv.dll in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly check permissions for sending inter-process device-event messages from low-integrity processes to high-integrity processes, which allows local users to gain privileges via a crafted application, aka "CSRSS Vulnerability."
6916| [CVE-2011-1966] The DNS server in Microsoft Windows Server 2008 SP2, R2, and R2 SP1 does not properly handle NAPTR queries that trigger recursive processing, which allows remote attackers to execute arbitrary code via a crafted query, aka "DNS NAPTR Query Vulnerability."
6917| [CVE-2011-1965] Tcpip.sys in the TCP/IP stack in Microsoft Windows 7 Gold and SP1 and Windows Server 2008 R2 and R2 SP1 does not properly implement URL-based QoS, which allows remote attackers to cause a denial of service (reboot) via a crafted URL to a web server, aka "TCP/IP QOS Denial of Service Vulnerability."
6918| [CVE-2011-1894] The MHTML protocol handler in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle a MIME format in a request for embedded content in an HTML document, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted EMBED element in a web page that is visited in Internet Explorer, aka "MHTML Mime-Formatted Request Vulnerability."
6919| [CVE-2011-1893] Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2010, Windows SharePoint Services 2.0 and 3.0 SP2, and SharePoint Foundation 2010 allows remote attackers to inject arbitrary web script or HTML via the URI, aka "SharePoint XSS Vulnerability."
6920| [CVE-2011-1892] Microsoft Office Groove 2007 SP2, SharePoint Workspace 2010 Gold and SP1, Office Forms Server 2007 SP2, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Office Groove Data Bridge Server 2007 SP2, Office Groove Management Server 2007 SP2, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, and Office Web Apps 2010 Gold and SP1 do not properly handle Web Parts containing XML classes referencing external entities, which allows remote authenticated users to read arbitrary files via a crafted XML and XSL file, aka "SharePoint Remote File Disclosure Vulnerability."
6921| [CVE-2011-1888] win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Null Pointer De-reference Vulnerability."
6922| [CVE-2011-1887] win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Null Pointer De-reference Vulnerability."
6923| [CVE-2011-1885] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Null Pointer De-reference Vulnerability."
6924| [CVE-2011-1884] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
6925| [CVE-2011-1883] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
6926| [CVE-2011-1882] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
6927| [CVE-2011-1881] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Null Pointer De-reference Vulnerability."
6928| [CVE-2011-1880] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Null Pointer De-reference Vulnerability."
6929| [CVE-2011-1879] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
6930| [CVE-2011-1878] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
6931| [CVE-2011-1877] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, aka "Win32k Use After Free Vulnerability."
6932| [CVE-2011-1876] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
6933| [CVE-2011-1875] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
6934| [CVE-2011-1874] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
6935| [CVE-2011-1873] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 on 64-bit platforms does not properly validate pointers during the parsing of OpenType (aka OTF) fonts, which allows remote attackers to execute arbitrary code via a crafted font file, aka "Win32k OTF Validation Vulnerability."
6936| [CVE-2011-1872] Hyper-V in Microsoft Windows Server 2008 Gold, SP2, R2, and R2 SP1 allows guest OS users to cause a denial of service (host OS infinite loop) via malformed machine instructions in a VMBus packet, aka "VMBus Persistent DoS Vulnerability."
6937| [CVE-2011-1871] Tcpip.sys in the TCP/IP stack in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (reboot) via a series of crafted ICMP messages, aka "ICMP Denial of Service Vulnerability."
6938| [CVE-2011-1870] Integer overflow in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP SrvWriteConsoleOutputString Vulnerability."
6939| [CVE-2011-1869] The Distributed File System (DFS) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote DFS servers to cause a denial of service (system hang) via a crafted referral response, aka "DFS Referral Response Vulnerability."
6940| [CVE-2011-1868] The Distributed File System (DFS) implementation in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate fields in DFS responses, which allows remote DFS servers to execute arbitrary code via a crafted response, aka "DFS Memory Corruption Vulnerability."
6941| [CVE-2011-1508] Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, does not properly manage memory allocations for function pointers, which allows user-assisted remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Function Pointer Overwrite Vulnerability."
6942| [CVE-2011-1284] Integer overflow in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP SrvWriteConsoleOutput Vulnerability."
6943| [CVE-2011-1283] The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2 does not ensure that an unspecified array index has a non-negative value before performing read and write operations, which allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP SrvSetConsoleNumberOfCommand Vulnerability."
6944| [CVE-2011-1282] The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly initialize memory and consequently uses a NULL pointer in an unspecified function call, which allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP SrvSetConsoleLocalEUDC Vulnerability."
6945| [CVE-2011-1281] The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly restrict the number of console objects for a process, which allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP AllocConsole Vulnerability."
6946| [CVE-2011-1280] The XML Editor in Microsoft InfoPath 2007 SP2 and 2010
6947| [CVE-2011-1279] Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel Out of Bounds WriteAV Vulnerability."
6948| [CVE-2011-1278] Microsoft Excel 2002 SP3 and Office 2004 for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel WriteAV Vulnerability."
6949| [CVE-2011-1277] Microsoft Excel 2002 SP3, Office 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel Memory Corruption Vulnerability."
6950| [CVE-2011-1276] Buffer overflow in Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2
6951| [CVE-2011-1275] Microsoft Excel 2002 SP3
6952| [CVE-2011-1274] Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2
6953| [CVE-2011-1273] Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010
6954| [CVE-2011-1272] Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2
6955| [CVE-2011-1270] Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "Presentation Buffer Overrun RCE Vulnerability."
6956| [CVE-2011-1269] Microsoft PowerPoint 2002 SP3, 2003 SP3, and 2007 SP2
6957| [CVE-2011-1268] The SMB client in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote SMB servers to execute arbitrary code via a crafted (1) SMBv1 or (2) SMBv2 response, aka "SMB Response Parsing Vulnerability."
6958| [CVE-2011-1267] The SMB server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (system hang) via a crafted (1) SMBv1 or (2) SMBv2 request, aka "SMB Request Parsing Vulnerability."
6959| [CVE-2011-1264] Cross-site scripting (XSS) vulnerability in Active Directory Certificate Services Web Enrollment in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, R2, and R2 SP1 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "Active Directory Certificate Services Vulnerability."
6960| [CVE-2011-1263] Cross-site scripting (XSS) vulnerability in the logon page in Remote Desktop Web Access (RD Web Access) in Microsoft Windows Server 2008 R2 and R2 SP1 allows remote attackers to inject arbitrary web script or HTML via the URI, aka "Remote Desktop Web Access Vulnerability."
6961| [CVE-2011-1253] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.0.60831, does not properly restrict inheritance, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4) a crafted Silverlight application, aka ".NET Framework Class Inheritance Vulnerability."
6962| [CVE-2011-1252] Cross-site scripting (XSS) vulnerability in the SafeHTML function in the toStaticHTML API in Microsoft Internet Explorer 7 and 8, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified strings, aka "toStaticHTML Information Disclosure Vulnerability" or "HTML Sanitization Vulnerability."
6963| [CVE-2011-1249] The Ancillary Function Driver (AFD) in afd.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."
6964| [CVE-2011-1248] WINS in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, R2, and R2 SP1 does not properly handle socket send exceptions, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted packets, related to unintended stack-frame values and buffer passing, aka "WINS Service Failed Response Vulnerability."
6965| [CVE-2011-1247] Untrusted search path vulnerability in the Microsoft Active Accessibility component in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "Active Accessibility Insecure Library Loading Vulnerability."
6966| [CVE-2011-1242] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
6967| [CVE-2011-1241] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
6968| [CVE-2011-1240] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
6969| [CVE-2011-1239] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
6970| [CVE-2011-1238] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
6971| [CVE-2011-1237] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
6972| [CVE-2011-1236] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
6973| [CVE-2011-1235] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
6974| [CVE-2011-1234] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
6975| [CVE-2011-1233] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
6976| [CVE-2011-1232] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
6977| [CVE-2011-1231] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
6978| [CVE-2011-1230] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
6979| [CVE-2011-1229] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
6980| [CVE-2011-1228] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
6981| [CVE-2011-1227] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
6982| [CVE-2011-1226] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
6983| [CVE-2011-1225] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
6984| [CVE-2011-0980] Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse Office Art objects, which allows remote attackers to execute arbitrary code via vectors related to a function pointer, aka "Excel Dangling Pointer Vulnerability."
6985| [CVE-2011-0979] Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010
6986| [CVE-2011-0978] Stack-based buffer overflow in Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2
6987| [CVE-2011-0977] Use-after-free vulnerability in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via malformed shape data in the Office drawing file format, aka "Microsoft Office Graphic Object Dereferencing Vulnerability."
6988| [CVE-2011-0976] Microsoft PowerPoint 2002 SP3, 2003 SP3, and 2007 SP2
6989| [CVE-2011-0677] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
6990| [CVE-2011-0676] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
6991| [CVE-2011-0675] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
6992| [CVE-2011-0674] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
6993| [CVE-2011-0672] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
6994| [CVE-2011-0671] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
6995| [CVE-2011-0670] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
6996| [CVE-2011-0667] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
6997| [CVE-2011-0666] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
6998| [CVE-2011-0665] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
6999| [CVE-2011-0664] Microsoft .NET Framework 2.0 SP1 and SP2, 3.5 Gold and SP1, 3.5.1, and 4.0, and Silverlight 4 before 4.0.60531.0, does not properly validate arguments to unspecified networking API functions, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4) a crafted Silverlight application, aka ".NET Framework Array Offset Vulnerability."
7000| [CVE-2011-0662] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
7001| [CVE-2011-0661] The SMB Server service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate fields in SMB requests, which allows remote attackers to execute arbitrary code via a malformed request in a (1) SMBv1 or (2) SMBv2 packet, aka "SMB Transaction Parsing Vulnerability."
7002| [CVE-2011-0660] The SMB client in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote SMB servers to execute arbitrary code via a crafted (1) SMBv1 or (2) SMBv2 response, aka "SMB Client Response Parsing Vulnerability."
7003| [CVE-2011-0658] Integer underflow in the OLE Automation protocol implementation in VBScript.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted WMF file, aka "OLE Automation Underflow Vulnerability."
7004| [CVE-2011-0657] DNSAPI.dll in the DNS client in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process DNS queries, which allows remote attackers to execute arbitrary code via (1) a crafted LLMNR broadcast query or (2) a crafted application, aka "DNS Query Vulnerability."
7005| [CVE-2011-0656] Microsoft PowerPoint 2002 SP3, 2003 SP3, 2007 SP2, and 2010
7006| [CVE-2011-0655] Microsoft PowerPoint 2007 SP2 and 2010
7007| [CVE-2011-0654] Integer underflow in the BowserWriteErrorLogEntry function in the Common Internet File System (CIFS) browser service in Mrxsmb.sys or bowser.sys in Active Directory in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via a malformed BROWSER ELECTION message, leading to a heap-based buffer overflow, aka "Browser Pool Corruption Vulnerability." NOTE: some of these details are obtained from third party information.
7008| [CVE-2011-0107] Untrusted search path vulnerability in Microsoft Office XP SP3, Office 2003 SP3, and Office 2007 SP2 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .docx file, aka "Office Component Insecure Library Loading Vulnerability."
7009| [CVE-2011-0105] Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac obtain a certain length value from an uninitialized memory location, which allows remote attackers to trigger a buffer overflow and execute arbitrary code via a crafted Excel file, aka "Excel Data Initialization Vulnerability."
7010| [CVE-2011-0104] Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HLink record in an Excel file, aka "Excel Buffer Overwrite Vulnerability."
7011| [CVE-2011-0103] Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted record information in an Excel file, aka "Excel Memory Corruption Vulnerability."
7012| [CVE-2011-0101] Microsoft Excel 2002 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted RealTimeData record, related to a stTopic field, doubly-byte characters, and an incorrect pointer calculation, aka "Excel Record Parsing WriteAV Vulnerability."
7013| [CVE-2011-0098] Integer signedness error in Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010
7014| [CVE-2011-0097] Integer underflow in Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010
7015| [CVE-2011-0096] The MHTML protocol handler in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle a MIME format in a request for content blocks in a document, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site that is visited in Internet Explorer, aka "MHTML Mime-Formatted Request Vulnerability."
7016| [CVE-2011-0093] ELEMENTS.DLL in Microsoft Visio 2002 SP2, 2003 SP3, and 2007 SP2 does not properly parse structures during the opening of a Visio file, which allows remote attackers to execute arbitrary code via a file containing a malformed structure, aka "Visio Data Type Memory Corruption Vulnerability."
7017| [CVE-2011-0092] The LZW stream decompression functionality in ORMELEMS.DLL in Microsoft Visio 2002 SP2, 2003 SP3, and 2007 SP2 allows remote attackers to execute arbitrary code via a Visio file with a malformed VisioDocument stream that triggers an exception handler that accesses an object that has not been fully initialized, which triggers memory corruption, aka "Visio Object Memory Corruption Vulnerability."
7018| [CVE-2011-0091] Kerberos in Microsoft Windows Server 2008 R2 and Windows 7 does not prevent a session from changing from strong encryption to DES encryption, which allows man-in-the-middle attackers to spoof network traffic and obtain sensitive information via a DES downgrade, aka "Kerberos Spoofing Vulnerability."
7019| [CVE-2011-0090] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Vulnerability."
7020| [CVE-2011-0089] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Window Class Improper Pointer Validation Vulnerability."
7021| [CVE-2011-0088] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Window Class Pointer Confusion Vulnerability."
7022| [CVE-2011-0087] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Insufficient User Input Validation Vulnerability."
7023| [CVE-2011-0086] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Improper User Input Validation Vulnerability."
7024| [CVE-2011-0043] Kerberos in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 supports weak hashing algorithms, which allows local users to gain privileges by operating a service that sends crafted service tickets, as demonstrated by the CRC32 algorithm, aka "Kerberos Unkeyed Checksum Vulnerability."
7025| [CVE-2011-0042] SBE.dll in the Stream Buffer Engine in Windows Media Player and Windows Media Center in Microsoft Windows XP SP2 and SP3, Windows XP Media Center Edition 2005 SP3, Windows Vista SP1 and SP2, Windows 7 Gold and SP1, and Windows Media Center TV Pack for Windows Vista does not properly parse Digital Video Recording (.dvr-ms) files, which allows remote attackers to execute arbitrary code via a crafted file, aka "DVR-MS Vulnerability."
7026| [CVE-2011-0041] Integer overflow in gdiplus.dll in GDI+ in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold and SP2, and Office XP SP3 allows remote attackers to execute arbitrary code via a crafted EMF image, aka "GDI+ Integer Overflow Vulnerability."
7027| [CVE-2011-0040] The server in Microsoft Active Directory on Windows Server 2003 SP2 does not properly handle an update request for a service principal name (SPN), which allows remote attackers to cause a denial of service (authentication downgrade or outage) via a crafted request that triggers name collisions, aka "Active Directory SPN Validation Vulnerability."
7028| [CVE-2011-0039] The Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly process authentication requests, which allows local users to gain privileges via a request with a crafted length, aka "LSASS Length Validation Vulnerability."
7029| [CVE-2011-0034] Stack-based buffer overflow in the OpenType Compact Font Format (aka OTF or CFF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via crafted parameter values in an OpenType font, aka "OpenType Font Stack Overflow Vulnerability."
7030| [CVE-2011-0033] The OpenType Compact Font Format (CFF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate parameter values in OpenType fonts, which allows remote attackers to execute arbitrary code via a crafted font, aka "OpenType Font Encoded Character Vulnerability."
7031| [CVE-2011-0032] Untrusted search path vulnerability in DirectShow in Microsoft Windows Vista SP1 and SP2, Windows 7 Gold and SP1, Windows Server 2008 R2 and R2 SP1, and Windows Media Center TV Pack for Windows Vista allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a Digital Video Recording (.dvr-ms), Windows Recorded TV Show (.wtv), or .mpg file, aka "DirectShow Insecure Library Loading Vulnerability."
7032| [CVE-2011-0031] The (1) JScript 5.8 and (2) VBScript 5.8 scripting engines in Microsoft Windows Server 2008 R2 and Windows 7 do not properly load decoded scripts obtained from web pages, which allows remote attackers to trigger memory corruption and consequently obtain sensitive information via a crafted web site, aka "Scripting Engines Information Disclosure Vulnerability."
7033| [CVE-2011-0030] The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly kill processes after a logout, which allows local users to obtain sensitive information or gain privileges via a crafted application that continues to execute throughout the logout of one user and the login session of the next user, aka "CSRSS Elevation of Privilege Vulnerability," a different vulnerability than CVE-2010-0023.
7034| [CVE-2011-0028] WordPad in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly parse fields in Word documents, which allows remote attackers to execute arbitrary code via a crafted .doc file, aka "WordPad Converter Parsing Vulnerability."
7035| [CVE-2010-5082] Untrusted search path vulnerability in colorcpl.exe 6.0.6000.16386 in the Color Control Panel in Microsoft Windows Server 2008 SP2, R2, and R2 SP1 allows local users to gain privileges via a Trojan horse sti.dll file in the current working directory, as demonstrated by a directory that contains a .camp, .cdmp, .gmmp, .icc, or .icm file, aka "Color Control Panel Insecure Library Loading Vulnerability."
7036| [CVE-2010-4701] Heap-based buffer overflow in the CDrawPoly::Serialize function in fxscover.exe in Microsoft Windows Fax Services Cover Page Editor 5.2 r2 in Windows XP Professional SP3, Server 2003 R2 Enterprise Edition SP2, and Windows 7 Professional allows remote attackers to execute arbitrary code via a long record in a Fax Cover Page (.cov) file. NOTE: some of these details are obtained from third party information.
7037| [CVE-2010-4669] The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Microsoft Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, and Windows 7 allows remote attackers to cause a denial of service (CPU consumption and system hang) by sending many Router Advertisement (RA) messages with different source addresses, as demonstrated by the flood_router6 program in the thc-ipv6 package.
7038| [CVE-2010-4562] Microsoft Windows 2008, 7, Vista, 2003, 2000, and XP, when using IPv6, allows remote attackers to determine whether a host is sniffing the network by sending an ICMPv6 Echo Request to a multicast address and determining whether an Echo Reply is sent, as demonstrated by thcping. NOTE: due to a typo, some sources map CVE-2010-4562 to a ProFTPd mod_sql vulnerability, but that issue is covered by CVE-2010-4652.
7039| [CVE-2010-4398] Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges, and bypass the User Account Control (UAC) feature, via a crafted REG_BINARY value for a SystemDefaultEUDCFont registry key, aka "Driver Improper Interaction with Windows Kernel Vulnerability."
7040| [CVE-2010-4182] Untrusted search path vulnerability in the Data Access Objects (DAO) library (dao360.dll) in Microsoft Windows XP Professional SP3, Windows Server 2003 R2 Enterprise Edition SP3, Windows Vista Business SP1, and Windows 7 Professional allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse msjet49.dll that is located in the same folder as a file that is processed by dao360.dll. NOTE: the provenance of this information is unknown
7041| [CVE-2010-3974] fxscover.exe in the Fax Cover Page Editor in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly parse FAX cover pages, which allows remote attackers to execute arbitrary code via a crafted .cov file, aka "Fax Cover Page Editor Memory Corruption Vulnerability."
7042| [CVE-2010-3970] Stack-based buffer overflow in the CreateSizedDIBSECTION function in shimgvw.dll in the Windows Shell graphics processor (aka graphics rendering engine) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted .MIC or unspecified Office document containing a thumbnail bitmap with a negative biClrUsed value, as reported by Moti and Xu Hao, aka "Windows Shell Graphics Processing Overrun Vulnerability."
7043| [CVE-2010-3966] Untrusted search path vulnerability in Microsoft Windows Server 2008 R2 and Windows 7, when BranchCache is supported, allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains an EML file, an RSS file, or a WPOST file, aka "BranchCache Insecure Library Loading Vulnerability."
7044| [CVE-2010-3965] Untrusted search path vulnerability in Windows Media Encoder 9 on Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a Windows Media Profile (PRX) file, aka "Insecure Library Loading Vulnerability."
7045| [CVE-2010-3964] Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Office SharePoint Server 2007 SP2, when the Document Conversions Load Balancer Service is enabled, allows remote attackers to execute arbitrary code via a crafted SOAP request to TCP port 8082, aka "Malformed Request Code Execution Vulnerability."
7046| [CVE-2010-3963] Buffer overflow in the Routing and Remote Access NDProxy component in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, related to the Routing and Remote Access service (RRAS) and improper copying from user mode to the kernel, aka "Kernel NDProxy Buffer Overflow Vulnerability."
7047| [CVE-2010-3961] The Consent User Interface (UI) in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly handle an unspecified registry-key value, which allows local users with SeImpersonatePrivilege rights to gain privileges via a crafted application, aka "Consent UI Impersonation Vulnerability."
7048| [CVE-2010-3960] Hyper-V in Microsoft Windows Server 2008 Gold, SP2, and R2 allows guest OS users to cause a denial of service (host OS hang) by sending a crafted encapsulated packet over the VMBus, aka "Hyper-V VMBus Vulnerability."
7049| [CVE-2010-3959] The OpenType Font (OTF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a crafted CMAP table in an OpenType font, aka "OpenType CMAP Table Vulnerability."
7050| [CVE-2010-3958] The x86 JIT compiler in Microsoft .NET Framework 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 does not properly compile function calls, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka ".NET Framework Stack Corruption Vulnerability."
7051| [CVE-2010-3957] Double free vulnerability in the OpenType Font (OTF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a crafted OpenType font, aka "OpenType Font Double Free Vulnerability."
7052| [CVE-2010-3956] The OpenType Font (OTF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly perform array indexing, which allows local users to gain privileges via a crafted OpenType font, aka "OpenType Font Index Vulnerability."
7053| [CVE-2010-3955] pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3 does not properly perform array indexing, which allows remote attackers to execute arbitrary code via a crafted Publisher file that uses an old file format, aka "Array Indexing Memory Corruption Vulnerability."
7054| [CVE-2010-3954] Microsoft Publisher 2002 SP3, 2003 SP3, and 2010 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Publisher file, aka "Microsoft Publisher Memory Corruption Vulnerability."
7055| [CVE-2010-3946] Integer overflow in the PICT image converter in the graphics filters in Microsoft Office XP SP3, Office 2003 SP3, and Office Converter Pack allows remote attackers to execute arbitrary code via a crafted PICT image in an Office document, aka "PICT Image Converter Integer Overflow Vulnerability."
7056| [CVE-2010-3945] Buffer overflow in the CGM image converter in the graphics filters in Microsoft Office XP SP3, Office 2003 SP3, and Office Converter Pack allows remote attackers to execute arbitrary code via a crafted CGM image in an Office document, aka "CGM Image Converter Buffer Overrun Vulnerability."
7057| [CVE-2010-3944] win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Vulnerability."
7058| [CVE-2010-3943] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly link driver objects, which allows local users to gain privileges via a crafted application that triggers linked-list corruption, aka "Win32k Cursor Linking Vulnerability."
7059| [CVE-2010-3942] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly allocate memory for copies from user mode, which allows local users to gain privileges via a crafted application, aka "Win32k WriteAV Vulnerability."
7060| [CVE-2010-3941] Double free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold and SP2, and Windows 7 allows local users to gain privileges via a crafted application, aka "Win32k Double Free Vulnerability."
7061| [CVE-2010-3940] Double free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a crafted application, aka "Win32k PFE Pointer Double Free Vulnerability."
7062| [CVE-2010-3939] Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via vectors related to improper memory allocation for copies from user mode, aka "Win32k Buffer Overflow Vulnerability."
7063| [CVE-2010-3937] Microsoft Exchange Server 2007 SP2 on the x64 platform allows remote authenticated users to cause a denial of service (infinite loop and MSExchangeIS outage) via a crafted RPC request, aka "Exchange Server Infinite Loop Vulnerability."
7064| [CVE-2010-3338] The Windows Task Scheduler in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly determine the security context of scheduled tasks, which allows local users to gain privileges via a crafted application, aka "Task Scheduler Vulnerability." NOTE: this might overlap CVE-2010-3888.
7065| [CVE-2010-3337] Untrusted search path vulnerability in Microsoft Office 2007 SP2 and 2010 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "Insecure Library Loading Vulnerability." NOTE: this might overlap CVE-2010-3141 and CVE-2010-3142.
7066| [CVE-2010-3336] Microsoft Office XP SP3, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "MSO Large SPID Read AV Vulnerability."
7067| [CVE-2010-3335] Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "Drawing Exception Handling Vulnerability."
7068| [CVE-2010-3334] Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via an Office document containing an Office Art Drawing record with crafted msofbtSp records and unspecified flags, which triggers memory corruption, aka "Office Art Drawing Records Vulnerability."
7069| [CVE-2010-3333] Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via crafted RTF data, aka "RTF Stack Buffer Overflow Vulnerability."
7070| [CVE-2010-3332] Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Services (IIS), provides detailed error codes during decryption attempts, which allows remote attackers to decrypt and modify encrypted View State (aka __VIEWSTATE) form data, and possibly forge cookies or read application files, via a padding oracle attack, aka "ASP.NET Padding Oracle Vulnerability."
7071| [CVE-2010-3324] The toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, Office SharePoint Server 2007 SP2, Groove Server 2010, and Office Web Apps, allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism and conduct XSS attacks via a crafted use of the Cascading Style Sheets (CSS) @import rule, aka "HTML Sanitization Vulnerability," a different vulnerability than CVE-2010-1257.
7072| [CVE-2010-3243] Cross-site scripting (XSS) vulnerability in the toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2 and Office SharePoint Server 2007 SP2, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "HTML Sanitization Vulnerability."
7073| [CVE-2010-3242] Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Ghost Record Type Parsing Vulnerability."
7074| [CVE-2010-3241] Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate binary file-format information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Out-of-Bounds Memory Write in Parsing Vulnerability."
7075| [CVE-2010-3240] Microsoft Excel 2002 SP3 and 2007 SP2
7076| [CVE-2010-3239] Microsoft Excel 2002 SP3 does not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Extra Out of Boundary Record Parsing Vulnerability."
7077| [CVE-2010-3238] Microsoft Excel 2002 SP3 and 2003 SP3, and Office 2004 for Mac, does not properly validate binary file-format information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Negative Future Function Vulnerability."
7078| [CVE-2010-3237] Microsoft Excel 2002 SP3 and Office 2004 for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Merge Cell Record Pointer Vulnerability."
7079| [CVE-2010-3236] Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Out Of Bounds Array Vulnerability."
7080| [CVE-2010-3235] Microsoft Excel 2002 SP3 does not properly validate formula information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Formula Biff Record Vulnerability."
7081| [CVE-2010-3234] Microsoft Excel 2002 SP3 does not properly validate formula information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Formula Substream Memory Corruption Vulnerability."
7082| [CVE-2010-3233] Microsoft Excel 2002 SP3 and 2003 SP3 does not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted .wk3 (aka Lotus 1-2-3 workbook) file, aka "Lotus 1-2-3 Workbook Parsing Vulnerability."
7083| [CVE-2010-3232] Microsoft Excel 2003 SP3 and 2007 SP2
7084| [CVE-2010-3231] Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Excel Record Parsing Memory Corruption Vulnerability."
7085| [CVE-2010-3230] Integer overflow in Microsoft Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel document with crafted record information, aka "Excel Record Parsing Integer Overflow Vulnerability."
7086| [CVE-2010-3229] The Secure Channel (aka SChannel) security package in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when IIS 7.x is used, does not properly process client certificates during SSL and TLS handshakes, which allows remote attackers to cause a denial of service (LSASS outage and reboot) via a crafted packet, aka "TLSv1 Denial of Service Vulnerability."
7087| [CVE-2010-3227] Stack-based buffer overflow in the UpdateFrameTitleForDocument method in the CFrameWnd class in mfc42.dll in the Microsoft Foundation Class (MFC) Library in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows context-dependent attackers to execute arbitrary code via a long window title that this library attempts to create at the request of an application, as demonstrated by the Trident PowerZip 7.2 Build 4010 application, aka "Windows MFC Document Title Updating Buffer Overflow Vulnerability."
7088| [CVE-2010-3223] The user interface in Microsoft Cluster Service (MSCS) in Microsoft Windows Server 2008 R2 does not properly set administrative-share permissions for new cluster disks that are shared as part of a failover cluster, which allows remote attackers to read or modify data on these disks via requests to the associated share, aka "Permissions on New Cluster Disks Vulnerability."
7089| [CVE-2010-3222] Stack-based buffer overflow in the Remote Procedure Call Subsystem (RPCSS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted LPC message that requests an LRPC connection from an LPC server to a client, aka "LPC Message Buffer Overrun Vulnerability."
7090| [CVE-2010-3221] Microsoft Word 2002 SP3 and 2003 SP3, Office 2004 for Mac, and Word Viewer do not properly handle a malformed record during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Parsing Vulnerability."
7091| [CVE-2010-3220] Unspecified vulnerability in Microsoft Word 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Word document that triggers memory corruption, aka "Word Parsing Vulnerability."
7092| [CVE-2010-3219] Array index vulnerability in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via a crafted Word document that triggers memory corruption, aka "Word Index Parsing Vulnerability."
7093| [CVE-2010-3218] Heap-based buffer overflow in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via malformed records in a Word document, aka "Word Heap Overflow Vulnerability."
7094| [CVE-2010-3217] Double free vulnerability in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via a Word document with crafted List Format Override (LFO) records, aka "Word Pointer Vulnerability."
7095| [CVE-2010-3216] Microsoft Word 2002 SP3 and Office 2004 for Mac allow remote attackers to execute arbitrary code via a crafted Word document containing bookmarks that trigger use of an invalid pointer and memory corruption, aka "Word Bookmarks Vulnerability."
7096| [CVE-2010-3215] Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly handle unspecified return values during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Return Value Vulnerability."
7097| [CVE-2010-3214] Stack-based buffer overflow in Microsoft Word 2002 SP3, 2003 SP3, 2007 SP2, and 2010
7098| [CVE-2010-3213] Cross-site request forgery (CSRF) vulnerability in Microsoft Outlook Web Access (owa/ev.owa) 2007 through SP2 allows remote attackers to hijack the authentication of e-mail users for requests that perform Outlook requests, as demonstrated by setting the auto-forward rule.
7099| [CVE-2010-3200] MSO.dll in Microsoft Word 2003 SP3 11.8326.11.8324 allows remote attackers to cause a denial of service (NULL pointer dereference and multiple-instance application crash) via a crafted buffer in a Word document, as demonstrated by word_crash_11.8326.8324_poc.doc.
7100| [CVE-2010-3190] Untrusted search path vulnerability in the Microsoft Foundation Class (MFC) Library in Microsoft Visual Studio .NET 2003 SP1
7101| [CVE-2010-3148] Untrusted search path vulnerability in Microsoft Visio 2003 SP3 allows local users to gain privileges via a Trojan horse mfc71enu.dll file in the current working directory, as demonstrated by a directory that contains a .vsd, .vdx, .vst, or .vtx file, aka "Microsoft Visio Insecure Library Loading Vulnerability."
7102| [CVE-2010-3147] Untrusted search path vulnerability in wab.exe 6.00.2900.5512 in Windows Address Book in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a Trojan horse wab32res.dll file in the current working directory, as demonstrated by a directory that contains a Windows Address Book (WAB), VCF (aka vCard), or P7C file, aka "Insecure Library Loading Vulnerability." NOTE: the codebase for this product may overlap the codebase for the product referenced in CVE-2010-3143.
7103| [CVE-2010-3146] Multiple untrusted search path vulnerabilities in Microsoft Groove 2007 SP2 allow local users to gain privileges via a Trojan horse (1) mso.dll or (2) GroovePerfmon.dll file in the current working directory, as demonstrated by a directory that contains a Groove vCard (.vcg) or Groove Tool Archive (.gta) file, aka "Microsoft Groove Insecure Library Loading Vulnerability."
7104| [CVE-2010-3144] Untrusted search path vulnerability in the Internet Connection Signup Wizard in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a Trojan horse smmscrpt.dll file in the current working directory, as demonstrated by a directory that contains an ISP or INS file, aka "Internet Connection Signup Wizard Insecure Library Loading Vulnerability."
7105| [CVE-2010-3142] Untrusted search path vulnerability in Microsoft Office PowerPoint 2007 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse rpawinet.dll that is located in the same folder as a .odp, .pothtml, .potm, .potx, .ppa, .ppam, .pps, .ppt, .ppthtml, .pptm, .pptxml, .pwz, .sldm, .sldx, and .thmx file.
7106| [CVE-2010-2750] Array index error in Microsoft Word 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Word document that triggers memory corruption, aka "Word Index Vulnerability."
7107| [CVE-2010-2748] Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly check an unspecified boundary during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Boundary Check Vulnerability."
7108| [CVE-2010-2747] Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly handle an uninitialized pointer during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Uninitialized Pointer Vulnerability."
7109| [CVE-2010-2746] Heap-based buffer overflow in Comctl32.dll (aka the common control library) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when a third-party SVG viewer is used, allows remote attackers to execute arbitrary code via a crafted HTML document that triggers unspecified messages from this viewer, aka "Comctl32 Heap Overflow Vulnerability."
7110| [CVE-2010-2744] The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly manage a window class, which allows local users to gain privileges by creating a window, then using (1) the SetWindowLongPtr function to modify the popup menu structure, or (2) the SwitchWndProc function with a switch window information pointer, which is not re-initialized when a WM_NCCREATE message is processed, aka "Win32k Window Class Vulnerability."
7111| [CVE-2010-2742] The Netlogon RPC Service in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, and R2, when the domain controller role is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via a crafted RPC packet, aka "Netlogon RPC Null dereference DOS Vulnerability."
7112| [CVE-2010-2741] The OpenType Font (OTF) format driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 performs an incorrect integer calculation during font processing, which allows local users to gain privileges via a crafted application, aka "OpenType Font Validation Vulnerability."
7113| [CVE-2010-2740] The OpenType Font (OTF) format driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly perform memory allocation during font parsing, which allows local users to gain privileges via a crafted application, aka "OpenType Font Parsing Vulnerability."
7114| [CVE-2010-2739] Buffer overflow in the CreateDIBPalette function in win32k.sys in Microsoft Windows XP SP3, Server 2003 R2 Enterprise SP2, Vista Business SP1, Windows 7, and Server 2008 SP2 allows local users to cause a denial of service (crash) and possibly execute arbitrary code by performing a clipboard operation (GetClipboardData API function) with a crafted bitmap with a palette that contains a large number of colors.
7115| [CVE-2010-2738] The Uniscribe (aka new Unicode Script Processor) implementation in USP10.DLL in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2, and Microsoft Office XP SP3, 2003 SP3, and 2007 SP2, does not properly validate tables associated with malformed OpenType fonts, which allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) Office document, aka "Uniscribe Font Parsing Engine Memory Corruption Vulnerability."
7116| [CVE-2010-2729] The Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when printer sharing is enabled, does not properly validate spooler access permissions, which allows remote attackers to create files in a system directory, and consequently execute arbitrary code, by sending a crafted print request over RPC, as exploited in the wild in September 2010, aka "Print Spooler Service Impersonation Vulnerability."
7117| [CVE-2010-2728] Heap-based buffer overflow in Microsoft Outlook 2002 SP3, 2003 SP3, and 2007 SP2, when Online Mode for an Exchange Server is enabled, allows remote attackers to execute arbitrary code via a crafted e-mail message, aka "Heap Based Buffer Overflow in Outlook Vulnerability."
7118| [CVE-2010-2573] Integer underflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3, PowerPoint Viewer SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint Integer Underflow Causes Heap Corruption Vulnerability."
7119| [CVE-2010-2572] Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95 document, aka "PowerPoint Parsing Buffer Overflow Vulnerability."
7120| [CVE-2010-2571] Array index error in pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher 97 file, aka "Memory Corruption Due To Invalid Index Into Array in Pubconv.dll Vulnerability."
7121| [CVE-2010-2570] Heap-based buffer overflow in pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3, 2003 SP3, 2007 SP2, and 2010 allows remote attackers to execute arbitrary code via a crafted Publisher file that uses an old file format, aka "Heap Overrun in pubconv.dll Vulnerability."
7122| [CVE-2010-2569] pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3, 2003 SP3, and 2007 SP2 does not properly handle an unspecified size field in certain older file formats, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted Publisher file, aka "Size Value Heap Corruption in pubconv.dll Vulnerability."
7123| [CVE-2010-2568] Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code via a crafted (1) .LNK or (2) .PIF shortcut file, which is not properly handled during icon display in Windows Explorer, as demonstrated in the wild in July 2010, and originally reported for malware that leverages CVE-2010-2772 in Siemens WinCC SCADA systems.
7124| [CVE-2010-2567] The RPC client implementation in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly allocate memory during the parsing of responses, which allows remote RPC servers and man-in-the-middle attackers to execute arbitrary code via a malformed response, aka "RPC Memory Corruption Vulnerability."
7125| [CVE-2010-2566] The Secure Channel (aka SChannel) security package in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, does not properly validate certificate request messages from TLS and SSL servers, which allows remote servers to execute arbitrary code via a crafted SSL response, aka "SChannel Malformed Certificate Request Remote Code Execution Vulnerability."
7126| [CVE-2010-2563] The Word 97 text converter in the WordPad Text Converters in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly parse malformed structures in Word 97 documents, which allows remote attackers to execute arbitrary code via a crafted document containing an unspecified value that is used in a loop counter, aka "WordPad Word 97 Text Converter Memory Corruption Vulnerability."
7127| [CVE-2010-2562] Microsoft Office Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Excel file, aka "Excel Memory Corruption Vulnerability."
7128| [CVE-2010-2555] The Tracing Feature for Services in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly determine the length of strings in the registry, which allows local users to gain privileges or cause a denial of service (memory corruption) via vectors involving a long string, aka "Tracing Memory Corruption Vulnerability."
7129| [CVE-2010-2554] The Tracing Feature for Services in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 has incorrect ACLs on its registry keys, which allows local users to gain privileges via vectors involving a named pipe and impersonation, aka "Tracing Registry Key ACL Vulnerability."
7130| [CVE-2010-2552] Stack consumption vulnerability in the SMB Server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to cause a denial of service (system hang) via a malformed SMBv2 compounded request, aka "SMB Stack Exhaustion Vulnerability."
7131| [CVE-2010-2551] The SMB Server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate an internal variable in an SMB packet, which allows remote attackers to cause a denial of service (system hang) via a crafted (1) SMBv1 or (2) SMBv2 packet, aka "SMB Variable Validation Vulnerability."
7132| [CVE-2010-2550] The SMB Server in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate fields in an SMB request, which allows remote attackers to execute arbitrary code via a crafted SMB packet, aka "SMB Pool Overflow Vulnerability."
7133| [CVE-2010-2549] Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2 and Server 2008 Gold and SP2 allows local users to gain privileges or cause a denial of service (system crash) by using a large number of calls to the NtUserCheckAccessForIntegrityLevel function to trigger a failure in the LockProcessByClientId function, leading to deletion of an in-use process object, aka "Win32k Reference Count Vulnerability."
7134| [CVE-2010-2265] Cross-site scripting (XSS) vulnerability in the GetServerName function in sysinfo/commonFunc.js in Microsoft Windows Help and Support Center for Windows XP and Windows Server 2003 allows remote attackers to inject arbitrary web script or HTML via the svr parameter to sysinfo/sysinfomain.htm. NOTE: this can be leveraged with CVE-2010-1885 to execute arbitrary commands without user interaction.
7135| [CVE-2010-2091] Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7 on Windows Server 2003 is used, does not properly handle the id parameter in a Folder IPF.Note action to the default URI, which might allow remote attackers to obtain sensitive information or conduct cross-site scripting (XSS) attacks via an invalid value.
7136| [CVE-2010-2084] Microsoft ASP.NET 2.0 does not prevent setting the InnerHtml property on a control that inherits from HtmlContainerControl, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to an attribute.
7137| [CVE-2010-1903] Microsoft Office Word 2002 SP3 and 2003 SP3, and Office Word Viewer, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed record in a Word file, aka "Word HTML Linked Objects Memory Corruption Vulnerability."
7138| [CVE-2010-1902] Buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2
7139| [CVE-2010-1901] Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2
7140| [CVE-2010-1900] Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2
7141| [CVE-2010-1898] The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP1, 2.0 SP2, 3.5, 3.5 SP1, and 3.5.1, and Microsoft Silverlight 2 and 3 before 3.0.50611.0 on Windows and before 3.0.41130.0 on Mac OS X, does not properly handle interfaces and delegations to virtual methods, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft Silverlight and Microsoft .NET Framework CLR Virtual Method Delegate Vulnerability."
7142| [CVE-2010-1897] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly validate pseudo-handle values in callback parameters during window creation, which allows local users to gain privileges via a crafted application, aka "Win32k Window Creation Vulnerability."
7143| [CVE-2010-1896] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2 do not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Win32k User Input Validation Vulnerability."
7144| [CVE-2010-1895] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, do not properly perform memory allocation before copying user-mode data to kernel mode, which allows local users to gain privileges via a crafted application, aka "Win32k Pool Overflow Vulnerability."
7145| [CVE-2010-1894] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, do not properly handle unspecified exceptions, which allows local users to gain privileges via a crafted application, aka "Win32k Exception Handling Vulnerability."
7146| [CVE-2010-1893] Integer overflow in the TCP/IP stack in Microsoft Windows Vista SP1, Windows Server 2008 Gold and R2, and Windows 7 allows local users to gain privileges via a buffer of user-mode data that is copied to kernel mode, aka "Integer Overflow in Windows Networking Vulnerability."
7147| [CVE-2010-1892] The TCP/IP stack in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly handle malformed IPv6 packets, which allows remote attackers to cause a denial of service (system hang) via multiple crafted packets, aka "IPv6 Memory Corruption Vulnerability."
7148| [CVE-2010-1891] The Client/Server Runtime Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2, when a Chinese, Japanese, or Korean locale is enabled, does not properly allocate memory for transactions, which allows local users to gain privileges via a crafted application, aka "CSRSS Local Elevation of Privilege Vulnerability."
7149| [CVE-2010-1890] The kernel in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate ACLs on kernel objects, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Improper Validation Vulnerability."
7150| [CVE-2010-1889] Double free vulnerability in the kernel in Microsoft Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2, allows local users to gain privileges via a crafted application, related to object initialization during error handling, aka "Windows Kernel Double Free Vulnerability."
7151| [CVE-2010-1887] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly validate an unspecified system-call argument, which allows local users to cause a denial of service (system hang) via a crafted application, aka "Win32k Bounds Checking Vulnerability."
7152| [CVE-2010-1886] Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2, and Windows 7 allow local users to gain privileges by leveraging access to a process with NetworkService credentials, as demonstrated by TAPI Server, SQL Server, and IIS processes, and related to the Windows Service Isolation feature. NOTE: the vendor states that privilege escalation from NetworkService to LocalSystem does not cross a "security boundary."
7153| [CVE-2010-1885] The MPC::HexToNum function in helpctr.exe in Microsoft Windows Help and Support Center in Windows XP and Windows Server 2003 does not properly handle malformed escape sequences, which allows remote attackers to bypass the trusted documents whitelist (fromHCP option) and execute arbitrary commands via a crafted hcp:// URL, aka "Help Center URL Validation Vulnerability."
7154| [CVE-2010-1883] Integer overflow in the Embedded OpenType (EOT) Font Engine in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to execute arbitrary code via a crafted table in an embedded font, aka "Embedded OpenType Font Integer Overflow Vulnerability."
7155| [CVE-2010-1882] Multiple buffer overflows in the MPEG Layer-3 Audio Codec for Microsoft DirectShow in l3codecx.ax in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allow remote attackers to execute arbitrary code via an MPEG Layer-3 audio stream in (1) a crafted media file or (2) crafted streaming content, aka "MPEG Layer-3 Audio Decoder Buffer Overflow Vulnerability."
7156| [CVE-2010-1881] The FieldList ActiveX control in the Microsoft Access Wizard Controls in ACCWIZ.dll in Microsoft Office Access 2003 SP3 does not properly interact with the memory-access approach used by Internet Explorer and Office during instantiation, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via an HTML document that references this control along with crafted persistent storage data, aka "ACCWIZ.dll Uninitialized Variable Vulnerability."
7157| [CVE-2010-1880] Unspecified vulnerability in Quartz.dll for DirectShow on Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1, and Server 2008 allows remote attackers to execute arbitrary code via a media file with crafted compression data, aka "MJPEG Media Decompression Vulnerability."
7158| [CVE-2010-1735] The SfnLOGONNOTIFY function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service (system crash) via a 0x4c value in the second argument (aka the Msg argument) of a PostMessage function call for the DDEMLEvent window.
7159| [CVE-2010-1734] The SfnINSTRING function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service (system crash) via a 0x18d value in the second argument (aka the Msg argument) of a PostMessage function call for the DDEMLEvent window.
7160| [CVE-2010-1690] The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 does not verify that transaction IDs of responses match transaction IDs of queries, which makes it easier for man-in-the-middle attackers to spoof DNS responses, a different vulnerability than CVE-2010-0024 and CVE-2010-0025.
7161| [CVE-2010-1689] The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 uses predictable transaction IDs that are formed by incrementing a previous ID by 1, which makes it easier for man-in-the-middle attackers to spoof DNS responses, a different vulnerability than CVE-2010-0024 and CVE-2010-0025.
7162| [CVE-2010-1263] Windows Shell and WordPad in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7
7163| [CVE-2010-1257] Cross-site scripting (XSS) vulnerability in the toStaticHTML API, as used in Microsoft Office InfoPath 2003 SP3, 2007 SP1, and 2007 SP2
7164| [CVE-2010-1255] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 Gold and SP2, Windows 7, and Server 2008 R2 allows local users to execute arbitrary code via vectors related to "glyph outline information" and TrueType fonts, aka "Win32k TrueType Font Parsing Vulnerability."
7165| [CVE-2010-1253] Microsoft Office Excel 2002 SP3, 2007 SP1, and SP2
7166| [CVE-2010-1252] Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Excel file, aka "Excel String Variable Vulnerability."
7167| [CVE-2010-1251] Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Excel file, aka "Excel Record Stack Corruption Vulnerability."
7168| [CVE-2010-1250] Heap-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with malformed (1) EDG (0x88) and (2) Publisher (0x89) records, aka "Excel EDG Memory Corruption Vulnerability."
7169| [CVE-2010-1249] Buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed ExternName (0x23) record, aka "Excel Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0823 and CVE-2010-1247.
7170| [CVE-2010-1248] Buffer overflow in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed HFPicture (0x866) record, aka "Excel HFPicture Memory Corruption Vulnerability."
7171| [CVE-2010-1247] Unspecified vulnerability in Microsoft Office Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel file with a malformed RTD (0x813) record that triggers heap corruption, aka "Excel Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0823 and CVE-2010-1249.
7172| [CVE-2010-1246] Stack-based buffer overflow in Microsoft Office Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel file with a malformed RTD (0x813) record, aka "Excel RTD Memory Corruption Vulnerability."
7173| [CVE-2010-1245] Unspecified vulnerability in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed SxView (0xB0) record, aka "Excel Record Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0824 and CVE-2010-0821.
7174| [CVE-2010-1225] The memory-management implementation in the Virtual Machine Monitor (aka VMM or hypervisor) in Microsoft Virtual PC 2007 Gold and SP1, Virtual Server 2005 Gold and R2 SP1, and Windows Virtual PC does not properly restrict access from the guest OS to memory locations in the VMM work area, which allows context-dependent attackers to bypass certain anti-exploitation protection mechanisms on the guest OS via crafted input to a vulnerable application. NOTE: the vendor reportedly found that only systems with an otherwise vulnerable application are affected, because "the memory areas accessible from the guest cannot be leveraged to achieve either remote code execution or elevation of privilege and ... no data from the host is exposed to the guest OS."
7175| [CVE-2010-1175] Microsoft Internet Explorer 7.0 on Windows XP and Windows Server 2003 allows remote attackers to have an unspecified impact via a certain XML document that references a crafted web site in the SRC attribute of an image element, related to a "0day Vulnerability."
7176| [CVE-2010-0917] Stack-based buffer overflow in VBScript in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, might allow user-assisted remote attackers to execute arbitrary code via a long string in the fourth argument (aka helpfile argument) to the MsgBox function, leading to code execution when the F1 key is pressed, a different vulnerability than CVE-2010-0483.
7177| [CVE-2010-0824] Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed WOPT (0x80B) record, aka "Excel Record Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0821 and CVE-2010-1245.
7178| [CVE-2010-0823] Unspecified vulnerability in Microsoft Office Excel 2002 SP3, 2003 SP3, 2007 SP1 and SP2
7179| [CVE-2010-0822] Stack-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a crafted OBJ (0x5D) record, aka "Excel Object Stack Overflow Vulnerability."
7180| [CVE-2010-0821] Unspecified vulnerability in Microsoft Office Excel 2002 SP3, 2003 SP3, 2007 SP1 and SP2
7181| [CVE-2010-0820] Heap-based buffer overflow in the Local Security Authority Subsystem Service (LSASS), as used in Active Directory in Microsoft Windows Server 2003 SP2 and Windows Server 2008 Gold, SP2, and R2
7182| [CVE-2010-0819] Unspecified vulnerability in the Windows OpenType Compact Font Format (CFF) driver in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users to execute arbitrary code via unknown vectors related to improper validation when copying data from user mode to kernel mode, aka "OpenType CFF Font Driver Memory Corruption Vulnerability."
7183| [CVE-2010-0818] The MPEG-4 codec in the Windows Media codecs in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 does not properly handle crafted media content with MPEG-4 video encoding, which allows remote attackers to execute arbitrary code via a file in an unspecified "supported format," aka "MPEG-4 Codec Vulnerability."
7184| [CVE-2010-0817] Cross-site scripting (XSS) vulnerability in _layouts/help.aspx in Microsoft SharePoint Server 2007 12.0.0.6421 and possibly earlier, and SharePoint Services 3.0 SP1 and SP2, versions, allows remote attackers to inject arbitrary web script or HTML via the cid0 parameter.
7185| [CVE-2010-0815] VBE6.DLL in Microsoft Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Visual Basic for Applications (VBA), and VBA SDK 6.3 through 6.5 does not properly search for ActiveX controls that are embedded in documents, which allows remote attackers to execute arbitrary code via a crafted document, aka "VBE6.DLL Stack Memory Corruption Vulnerability."
7186| [CVE-2010-0814] The Microsoft Access Wizard Controls in ACCWIZ.dll in Microsoft Office Access 2003 SP3 and 2007 SP1 and SP2 do not properly interact with the memory-allocation approach used by Internet Explorer during instantiation, which allows remote attackers to execute arbitrary code via a web site that references multiple ActiveX controls, as demonstrated by the ImexGrid and FieldList controls, aka "Access ActiveX Control Vulnerability."
7187| [CVE-2010-0812] Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to bypass intended IPv4 source-address restrictions via a mismatched IPv6 source address in a tunneled ISATAP packet, aka "ISATAP IPv6 Source Address Spoofing Vulnerability."
7188| [CVE-2010-0811] Multiple unspecified vulnerabilities in the Microsoft Internet Explorer 8 Developer Tools ActiveX control in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allow remote attackers to execute arbitrary code via unknown vectors that "corrupt the system state," aka "Microsoft Internet Explorer 8 Developer Tools Vulnerability."
7189| [CVE-2010-0810] The kernel in Microsoft Windows Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2, does not properly handle unspecified exceptions, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Exception Handler Vulnerability."
7190| [CVE-2010-0719] An unspecified API in Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, and Windows 7 does not validate arguments, which allows local users to cause a denial of service (system crash) via a crafted application.
7191| [CVE-2010-0487] The Authenticode Signature verification functionality in cabview.dll in Cabinet File Viewer Shell Extension 5.1, 6.0, and 6.1 in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly use unspecified fields in a file digest, which allows remote attackers to execute arbitrary code via a modified cabinet (aka .CAB) file that incorrectly appears to have a valid signature, aka "Cabview Corruption Validation Vulnerability."
7192| [CVE-2010-0486] The WinVerifyTrust function in Authenticode Signature Verification 5.1, 6.0, and 6.1 in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly use unspecified fields in a file digest, which allows user-assisted remote attackers to execute arbitrary code via a modified (1) Portable Executable (PE) or (2) cabinet (aka .CAB) file that incorrectly appears to have a valid signature, aka "WinVerifyTrust Signature Validation Vulnerability."
7193| [CVE-2010-0485] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 Gold and SP2, Windows 7, and Server 2008 R2 "do not properly validate all callback parameters when creating a new window," which allows local users to execute arbitrary code, aka "Win32k Window Creation Vulnerability."
7194| [CVE-2010-0484] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 "do not properly validate changes in certain kernel objects," which allows local users to execute arbitrary code via vectors related to Device Contexts (DC) and the GetDCEx function, aka "Win32k Improper Data Validation Vulnerability."
7195| [CVE-2010-0483] vbscript.dll in VBScript 5.1, 5.6, 5.7, and 5.8 in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, allows user-assisted remote attackers to execute arbitrary code by referencing a (1) local pathname, (2) UNC share pathname, or (3) WebDAV server with a crafted .hlp file in the fourth argument (aka helpfile argument) to the MsgBox function, leading to code execution involving winhlp32.exe when the F1 key is pressed, aka "VBScript Help Keypress Vulnerability."
7196| [CVE-2010-0482] The kernel in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate relocation sections of image files, which allows local users to cause a denial of service (reboot) via a crafted file, aka "Windows Kernel Malformed Image Vulnerability."
7197| [CVE-2010-0481] The kernel in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly translate a registry key's virtual path to its real path, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Virtual Path Parsing Vulnerability."
7198| [CVE-2010-0480] Multiple stack-based buffer overflows in the MPEG Layer-3 audio codecs in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to execute arbitrary code via a crafted AVI file, aka "MPEG Layer-3 Audio Decoder Stack Overflow Vulnerability."
7199| [CVE-2010-0479] Buffer overflow in Microsoft Office Publisher 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Microsoft Office Publisher File Conversion TextBox Processing Buffer Overflow Vulnerability."
7200| [CVE-2010-0478] Stack-based buffer overflow in nsum.exe in the Windows Media Unicast Service in Media Services for Microsoft Windows 2000 Server SP4 allows remote attackers to execute arbitrary code via crafted packets associated with transport information, aka "Media Services Stack-based Buffer Overflow Vulnerability."
7201| [CVE-2010-0477] The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly handle (1) SMBv1 and (2) SMBv2 response packets, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted packet that causes the client to read the entirety of the response, and then improperly interact with the Winsock Kernel (WSK), aka "SMB Client Message Size Vulnerability."
7202| [CVE-2010-0476] The SMB client in Microsoft Windows Server 2003 SP2, Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2 allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and reboot) via a crafted SMB transaction response that uses (1) SMBv1 or (2) SMBv2, aka "SMB Client Response Parsing Vulnerability."
7203| [CVE-2010-0278] A certain ActiveX control in msgsc.14.0.8089.726.dll in Microsoft Windows Live Messenger 2009 build 14.0.8089.726 on Windows Vista and Windows 7 allows remote attackers to cause a denial of service (msnmsgr.exe crash) by calling the ViewProfile method with a crafted argument during an MSN Messenger session.
7204| [CVE-2010-0270] The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate fields in SMB transaction responses, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and reboot) via a crafted (1) SMBv1 or (2) SMBv2 response, aka "SMB Client Transaction Vulnerability."
7205| [CVE-2010-0269] The SMB client in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly allocate memory for SMB responses, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted (1) SMBv1 or (2) SMBv2 response, aka "SMB Client Memory Allocation Vulnerability."
7206| [CVE-2010-0268] Unspecified vulnerability in the Windows Media Player ActiveX control in Windows Media Player (WMP) 9 on Microsoft Windows 2000 SP4 and XP SP2 and SP3 allows remote attackers to execute arbitrary code via crafted media content, aka "Media Player Remote Code Execution Vulnerability."
7207| [CVE-2010-0266] Microsoft Office Outlook 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 does not properly verify e-mail attachments with a PR_ATTACH_METHOD property value of ATTACH_BY_REFERENCE, which allows user-assisted remote attackers to execute arbitrary code via a crafted message, aka "Microsoft Outlook SMB Attachment Vulnerability."
7208| [CVE-2010-0265] Buffer overflow in Microsoft Windows Movie Maker 2.1, 2.6, and 6.0, and Microsoft Producer 2003, allows remote attackers to execute arbitrary code via a crafted project (.MSWMM) file, aka "Movie Maker and Producer Buffer Overflow Vulnerability."
7209| [CVE-2010-0264] Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Microsoft Office Excel DbOrParamQry Record Parsing Vulnerability."
7210| [CVE-2010-0263] Microsoft Office Excel 2007 SP1 and SP2
7211| [CVE-2010-0262] Microsoft Office Excel 2007 SP1 and SP2 and Office 2004 for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet that triggers access of an uninitialized stack variable, aka "Microsoft Office Excel FNGROUPNAME Record Uninitialized Memory Vulnerability."
7212| [CVE-2010-0261] Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2 and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted spreadsheet in which "a MDXSET record is broken up into several records," aka "Microsoft Office Excel MDXSET Record Heap Overflow Vulnerability."
7213| [CVE-2010-0260] Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2
7214| [CVE-2010-0258] Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
7215| [CVE-2010-0257] Microsoft Office Excel 2002 SP3 does not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Microsoft Office Excel Record Memory Corruption Vulnerability."
7216| [CVE-2010-0256] Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 and SP2 does not properly calculate unspecified indexes associated with Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Visio Index Calculation Memory Corruption Vulnerability."
7217| [CVE-2010-0254] Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 and SP2 does not properly validate attributes in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Visio Attribute Validation Memory Corruption Vulnerability."
7218| [CVE-2010-0252] The Microsoft Data Analyzer ActiveX control (aka the Office Excel ActiveX control for Data Analysis) in max3activex.dll in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to execute arbitrary code via a crafted web page that corrupts the "system state," aka "Microsoft Data Analyzer ActiveX Control Vulnerability."
7219| [CVE-2010-0250] Heap-based buffer overflow in DirectShow in Microsoft DirectX, as used in the AVI Filter on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2, and in Quartz on Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, allows remote attackers to execute arbitrary code via an AVI file with a crafted length field in an unspecified video stream, which is not properly handled by the RLE video decompressor, aka "DirectShow Heap Overflow Vulnerability."
7220| [CVE-2010-0249] Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4
7221| [CVE-2010-0243] Buffer overflow in MSO.DLL in Microsoft Office XP SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Office document, aka "MSO.DLL Buffer Overflow."
7222| [CVE-2010-0242] The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows remote attackers to cause a denial of service (system hang) via crafted packets with malformed TCP selective acknowledgement (SACK) values, aka "TCP/IP Selective Acknowledgement Vulnerability."
7223| [CVE-2010-0241] The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when IPv6 is enabled, does not properly perform bounds checking on ICMPv6 Route Information packets, which allows remote attackers to execute arbitrary code via crafted packets, aka "ICMPv6 Route Information Vulnerability."
7224| [CVE-2010-0240] The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when a custom network driver is used, does not properly handle local fragmentation of Encapsulating Security Payload (ESP) over UDP packets, which allows remote attackers to execute arbitrary code via crafted packets, aka "Header MDL Fragmentation Vulnerability."
7225| [CVE-2010-0239] The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when IPv6 is enabled, does not properly perform bounds checking on ICMPv6 Router Advertisement packets, which allows remote attackers to execute arbitrary code via crafted packets, aka "ICMPv6 Router Advertisement Vulnerability."
7226| [CVE-2010-0238] Unspecified vulnerability in registry-key validation in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Registry Key Vulnerability."
7227| [CVE-2010-0237] The kernel in Microsoft Windows 2000 SP4 and XP SP2 and SP3 allows local users to gain privileges by creating a symbolic link from an untrusted registry hive to a trusted registry hive, aka "Windows Kernel Symbolic Link Creation Vulnerability."
7228| [CVE-2010-0236] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold does not properly allocate memory for the destination key associated with a symbolic-link registry key, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Allocation Vulnerability."
7229| [CVE-2010-0235] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold does not perform the expected validation before creating a symbolic link, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Symbolic Link Value Vulnerability."
7230| [CVE-2010-0234] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not properly validate a registry-key argument to an unspecified system call, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Null Pointer Vulnerability."
7231| [CVE-2010-0233] Double free vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows local users to gain privileges via a crafted application, aka "Windows Kernel Double Free Vulnerability."
7232| [CVE-2010-0232] The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges by crafting a VDM_TIB data structure in the Thread Environment Block (TEB), and then calling the NtVdmControl function to start the Windows Virtual DOS Machine (aka NTVDM) subsystem, leading to improperly handled exceptions involving the #GP trap handler (nt!KiTrap0D), aka "Windows Kernel Exception Handler Vulnerability."
7233| [CVE-2010-0231] The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not use a sufficient source of entropy, which allows remote attackers to obtain access to files and other SMB resources via a large number of authentication requests, related to server-generated challenges, certain "duplicate values," and spoofing of an authentication token, aka "SMB NTLM Authentication Lack of Entropy Vulnerability."
7234| [CVE-2010-0035] The Key Distribution Center (KDC) in Kerberos in Microsoft Windows 2000 SP4, Server 2003 SP2, and Server 2008 Gold and SP2, when a trust relationship with a non-Windows Kerberos realm exists, allows remote authenticated users to cause a denial of service (NULL pointer dereference and domain controller outage) via a crafted Ticket Granting Ticket (TGT) renewal request, aka "Kerberos Null Pointer Dereference Vulnerability."
7235| [CVE-2010-0034] Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "Office PowerPoint Viewer TextCharsAtom Record Stack Overflow Vulnerability."
7236| [CVE-2010-0033] Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint Viewer TextBytesAtom Record Stack Overflow Vulnerability."
7237| [CVE-2010-0032] Use-after-free vulnerability in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "OEPlaceholderAtom Use After Free Vulnerability."
7238| [CVE-2010-0031] Array index error in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3, and PowerPoint in Office 2004 for Mac, allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint OEPlaceholderAtom 'placementId' Invalid Array Indexing Vulnerability."
7239| [CVE-2010-0030] Heap-based buffer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint LinkedSlideAtom Heap Overflow Vulnerability."
7240| [CVE-2010-0029] Buffer overflow in Microsoft Office PowerPoint 2002 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint File Path Handling Buffer Overflow Vulnerability."
7241| [CVE-2010-0028] Integer overflow in Microsoft Paint in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted JPEG (.JPG) file, aka "MS Paint Integer Overflow Vulnerability."
7242| [CVE-2010-0027] The URL validation functionality in Microsoft Internet Explorer 5.01, 6, 6 SP1, 7 and 8, and the ShellExecute API function in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."
7243| [CVE-2010-0026] The Hyper-V server implementation in Microsoft Windows Server 2008 Gold, SP2, and R2 on the x64 platform allows guest OS users to cause a denial of service (host OS hang) via a crafted application that executes a malformed series of machine instructions, aka "Hyper-V Instruction Set Validation Vulnerability."
7244| [CVE-2010-0025] The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2000 SP3, does not properly allocate memory for SMTP command replies, which allows remote attackers to read fragments of e-mail messages by sending a series of invalid commands and then sending a STARTTLS command, aka "SMTP Memory Allocation Vulnerability."
7245| [CVE-2010-0024] The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2003 SP2, does not properly parse MX records, which allows remote DNS servers to cause a denial of service (service outage) via a crafted response to a DNS MX record query, aka "SMTP Server MX Record Vulnerability."
7246| [CVE-2010-0023] The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly kill processes after a logout, which allows local users to obtain sensitive information or gain privileges via a crafted application that continues to execute throughout the logout of one user and the login session of the next user, aka "CSRSS Local Privilege Elevation Vulnerability."
7247| [CVE-2010-0022] The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate the share and servername fields in SMB packets, which allows remote attackers to cause a denial of service (system hang) via a crafted packet, aka "SMB Null Pointer Vulnerability."
7248| [CVE-2010-0021] Multiple race conditions in the SMB implementation in the Server service in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allow remote attackers to cause a denial of service (system hang) via a crafted (1) SMBv1 or (2) SMBv2 Negotiate packet, aka "SMB Memory Corruption Vulnerability."
7249| [CVE-2010-0020] The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate request fields, which allows remote authenticated users to execute arbitrary code via a malformed request, aka "SMB Pathname Overflow Vulnerability."
7250| [CVE-2010-0018] Integer overflow in the Embedded OpenType (EOT) Font Engine (t2embed.dll) in Microsoft Windows 2000 SP4
7251| [CVE-2010-0017] Race condition in the SMB client implementation in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code, and in the SMB client implementation in Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows local users to gain privileges, via a crafted SMB Negotiate response, aka "SMB Client Race Condition Vulnerability."
7252| [CVE-2010-0016] The SMB client implementation in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly validate response fields, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted response, aka "SMB Client Pool Corruption Vulnerability."
7253| [CVE-2009-4313] ir32_32.dll 3.24.15.3 in the Indeo32 codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to cause a denial of service (heap corruption) or execute arbitrary code via malformed data in a stream in a media file, as demonstrated by an AVI file.
7254| [CVE-2009-4312] Unspecified vulnerability in the Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via crafted media content, as reported to Microsoft by Dave Lenoe of Adobe.
7255| [CVE-2009-4311] Unspecified vulnerability in the Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via crafted media content, as reported to Microsoft by Paul Byrne of NGS Software. NOTE: this might overlap CVE-2008-3615.
7256| [CVE-2009-4310] Stack-based buffer overflow in the Intel Indeo41 codec for Windows Media Player in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via crafted compressed video data in an IV41 stream in a media file, leading to many loop iterations, as demonstrated by data in an AVI file.
7257| [CVE-2009-4309] Heap-based buffer overflow in the Intel Indeo41 codec for Windows Media Player in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a large size value in a movi record in an IV41 stream in a media file, as demonstrated by an AVI file.
7258| [CVE-2009-4210] The Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted media content.
7259| [CVE-2009-3830] The download functionality in Team Services in Microsoft Office SharePoint Server 2007 12.0.0.4518 and 12.0.0.6219 allows remote attackers to read ASP.NET source code via pathnames in the SourceUrl and Source parameters to _layouts/download.aspx.
7260| [CVE-2009-3678] Integer overflow in cdd.dll in the Canonical Display Driver (CDD) in Microsoft Windows Server 2008 R2 and Windows 7 on 64-bit platforms, when the Windows Aero theme is installed, allows context-dependent attackers to cause a denial of service (reboot) or possibly execute arbitrary code via a crafted image file that triggers incorrect data parsing after user-mode data is copied to kernel mode, as demonstrated using "Browse with Irfanview" and certain actions on a folder containing a large number of thumbnail images in Resample mode, possibly related to the ATI graphics driver or win32k.sys, aka "Canonical Display Driver Integer Overflow Vulnerability."
7261| [CVE-2009-3677] The Internet Authentication Service (IAS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly verify the credentials in an MS-CHAP v2 Protected Extensible Authentication Protocol (PEAP) authentication request, which allows remote attackers to access network resources via a malformed request, aka "MS-CHAP Authentication Bypass Vulnerability."
7262| [CVE-2009-3676] The SMB client in the kernel in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle attackers to cause a denial of service (infinite loop and system hang) via a (1) SMBv1 or (2) SMBv2 response packet that contains (a) an incorrect length value in a NetBIOS header or (b) an additional length field at the end of this response packet, aka "SMB Client Incomplete Response Vulnerability."
7263| [CVE-2009-3675] LSASS.exe in the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote authenticated users to cause a denial of service (CPU consumption) via a malformed ISAKMP request over IPsec, aka "Local Security Authority Subsystem Service Resource Exhaustion Vulnerability."
7264| [CVE-2009-3450] Multiple cross-site scripting (XSS) vulnerabilities in WebCoreModule.ashx in RADactive I-Load before 2008.2.5.0 allow remote attackers to inject arbitrary web script or HTML via parameters with names beginning with __ (underscore underscore) sequences, which are incompatible with an XSS protection mechanism provided by Microsoft ASP.NET.
7265| [CVE-2009-3135] Stack-based buffer overflow in Microsoft Office Word 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, Open XML File Format Converter for Mac, Office Word Viewer 2003 SP3, and Office Word Viewer allow remote attackers to execute arbitrary code via a Word document with a malformed File Information Block (FIB) structure, aka "Microsoft Office Word File Information Memory Corruption Vulnerability."
7266| [CVE-2009-3134] Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
7267| [CVE-2009-3133] Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a spreadsheet containing a malformed object that triggers memory corruption, related to "loading Excel records," aka "Excel Document Parsing Memory Corruption Vulnerability."
7268| [CVE-2009-3132] Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
7269| [CVE-2009-3131] Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
7270| [CVE-2009-3130] Heap-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via a spreadsheet containing a malformed Binary File Format (aka BIFF) record that triggers memory corruption, aka "Excel Document Parsing Heap Overflow Vulnerability."
7271| [CVE-2009-3129] Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
7272| [CVE-2009-3128] Microsoft Office Excel 2002 SP3 and 2003 SP3, and Office Excel Viewer 2003 SP3, does not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a spreadsheet with a malformed record object, aka "Excel SxView Memory Corruption Vulnerability."
7273| [CVE-2009-3127] Microsoft Office Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, Open XML File Format Converter for Mac, and Office Excel Viewer 2003 SP3 do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Cache Memory Corruption Vulnerability."
7274| [CVE-2009-3126] Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted PNG image file, aka "GDI+ PNG Integer Overflow Vulnerability."
7275| [CVE-2009-3103] Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via an & (ampersand) character in a Process ID High header field in a NEGOTIATE PROTOCOL REQUEST packet, which triggers an attempted dereference of an out-of-bounds memory location, aka "SMBv2 Negotiation Vulnerability." NOTE: some of these details are obtained from third party information.
7276| [CVE-2009-3020] win32k.sys in Microsoft Windows Server 2003 SP2 allows remote attackers to cause a denial of service (system crash) by referencing a crafted .eot file in the src descriptor of an @font-face Cascading Style Sheets (CSS) rule in an HTML document, possibly related to the Embedded OpenType (EOT) Font Engine, a different vulnerability than CVE-2006-0010, CVE-2009-0231, and CVE-2009-0232. NOTE: some of these details are obtained from third party information.
7277| [CVE-2009-2653] ** DISPUTED ** The NtUserConsoleControl function in win32k.sys in Microsoft Windows XP SP2 and SP3, and Server 2003 before SP1, allows local administrators to bypass unspecified "security software" and gain privileges via a crafted call that triggers an overwrite of an arbitrary memory location. NOTE: the vendor disputes the significance of this report, stating that 'the Administrator to SYSTEM "escalation" is not a security boundary we defend.'
7278| [CVE-2009-2532] Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC do not properly process the command value in an SMB Multi-Protocol Negotiate Request packet, which allows remote attackers to execute arbitrary code via a crafted SMBv2 packet to the Server service, aka "SMBv2 Command Value Vulnerability."
7279| [CVE-2009-2526] Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 do not properly validate fields in SMBv2 packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted packet to the Server service, aka "SMBv2 Infinite Loop Vulnerability."
7280| [CVE-2009-2524] Integer underflow in the NTLM authentication feature in the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to cause a denial of service (reboot) via a malformed packet, aka "Local Security Authority Subsystem Service Integer Overflow Vulnerability."
7281| [CVE-2009-2523] The License Logging Server (llssrv.exe) in Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrary code via an RPC message containing a string without a null terminator, which triggers a heap-based buffer overflow in the LlsrLicenseRequestW method, aka "License Logging Server Heap Overflow Vulnerability."
7282| [CVE-2009-2519] The DHTML Editing Component ActiveX control in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly format HTML markup, which allows remote attackers to execute arbitrary code via a crafted web site that triggers "system state" corruption, aka "DHTML Editing Component ActiveX Control Vulnerability."
7283| [CVE-2009-2517] The kernel in Microsoft Windows Server 2003 SP2 does not properly handle unspecified exceptions when an error condition occurs, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Exception Handler Vulnerability."
7284| [CVE-2009-2516] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly validate data sent from user mode, which allows local users to gain privileges via a crafted PE .exe file that triggers a NULL pointer dereference during chain traversal, aka "Windows Kernel NULL Pointer Dereference Vulnerability."
7285| [CVE-2009-2515] Integer underflow in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows local users to gain privileges via a crafted application that triggers an incorrect truncation of a 64-bit integer to a 32-bit integer, aka "Windows Kernel Integer Underflow Vulnerability."
7286| [CVE-2009-2514] win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not correctly parse font code during construction of a directory-entry table, which allows remote attackers to execute arbitrary code via a crafted Embedded OpenType (EOT) font, aka "Win32k EOT Parsing Vulnerability."
7287| [CVE-2009-2513] The Graphics Device Interface (GDI) in win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Insufficient Data Validation Vulnerability."
7288| [CVE-2009-2511] Integer overflow in the CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows man-in-the-middle attackers to spoof arbitrary SSL servers and other entities via an X.509 certificate that has a malformed ASN.1 Object Identifier (OID) and was issued by a legitimate Certification Authority, aka "Integer Overflow in X.509 Object Identifiers Vulnerability."
7289| [CVE-2009-2510] The CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, as used by Internet Explorer and other applications, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, aka "Null Truncation in X.509 Common Name Vulnerability," a related issue to CVE-2009-2408.
7290| [CVE-2009-2509] Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly validate headers in HTTP requests, which allows remote authenticated users to execute arbitrary code via a crafted request to an IIS web server, aka "Remote Code Execution in ADFS Vulnerability."
7291| [CVE-2009-2508] The single sign-on implementation in Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly remove credentials at the end of a network session, which allows physically proximate attackers to obtain the credentials of a previous user of the same web browser by using data from the browser's cache, aka "Single Sign On Spoofing in ADFS Vulnerability."
7292| [CVE-2009-2507] A certain ActiveX control in the Indexing Service in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly process URLs, which allows remote attackers to execute arbitrary programs via unspecified vectors that cause a "vulnerable binary" to load and run, aka "Memory Corruption in Indexing Service Vulnerability."
7293| [CVE-2009-2506] Integer overflow in the text converters in Microsoft Office Word 2002 SP3 and 2003 SP3
7294| [CVE-2009-2505] The Internet Authentication Service (IAS) in Microsoft Windows Vista SP2 and Server 2008 SP2 does not properly validate MS-CHAP v2 Protected Extensible Authentication Protocol (PEAP) authentication requests, which allows remote attackers to execute arbitrary code via crafted structures in a malformed request, aka "Internet Authentication Service Memory Corruption Vulnerability."
7295| [CVE-2009-2504] Multiple integer overflows in unspecified APIs in GDI+ in Microsoft .NET Framework 1.1 SP1, .NET Framework 2.0 SP1 and SP2, Windows XP SP2 and SP3, Windows Server 2003 SP2, Vista Gold and SP1, Server 2008 Gold, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allow remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "GDI+ .NET API Vulnerability."
7296| [CVE-2009-2503] GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 does not properly allocate an unspecified buffer, which allows remote attackers to execute arbitrary code via a crafted TIFF image file that triggers memory corruption, aka "GDI+ TIFF Memory Corruption Vulnerability."
7297| [CVE-2009-2502] Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted TIFF image file, aka "GDI+ TIFF Buffer Overflow Vulnerability."
7298| [CVE-2009-2501] Heap-based buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted PNG image file, aka "GDI+ PNG Heap Overflow Vulnerability."
7299| [CVE-2009-2500] Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted WMF image file, aka "GDI+ WMF Integer Overflow Vulnerability."
7300| [CVE-2009-2498] Microsoft Windows Media Format Runtime 9.0, 9.5, and 11 and Windows Media Services 9.1 and 2008 do not properly parse malformed headers in Advanced Systems Format (ASF) files, which allows remote attackers to execute arbitrary code via a crafted (1) .asf, (2) .wmv, or (3) .wma file, aka "Windows Media Header Parsing Invalid Free Vulnerability."
7301| [CVE-2009-2497] The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0, 2.0 SP1, 2.0 SP2, 3.5, and 3.5 SP1, and Silverlight 2, does not properly handle interfaces, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted Silverlight application, (3) a crafted ASP.NET application, or (4) a crafted .NET Framework application, aka "Microsoft Silverlight and Microsoft .NET Framework CLR Vulnerability."
7302| [CVE-2009-2496] Heap-based buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 SP1, and Office Small Business Accounting 2006 allows remote attackers to execute arbitrary code via unspecified parameters to unknown methods, aka "Office Web Components Heap Corruption Vulnerability."
7303| [CVE-2009-2495] The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1 does not properly enforce string termination, which allows remote attackers to obtain sensitive information via a crafted HTML document with an ATL (1) component or (2) control that triggers a buffer over-read, related to ATL headers and buffer allocation, aka "ATL Null String Vulnerability."
7304| [CVE-2009-2494] The Active Template Library (ATL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via vectors related to erroneous free operations after reading a variant from a stream and deleting this variant, aka "ATL Object Type Mismatch Vulnerability."
7305| [CVE-2009-2493] The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1
7306| [CVE-2009-1930] The Telnet service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote Telnet servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user, aka "Telnet Credential Reflection Vulnerability," a related issue to CVE-2000-0834.
7307| [CVE-2009-1929] Heap-based buffer overflow in the Microsoft Terminal Services Client ActiveX control running RDP 6.1 on Windows XP SP2, Vista SP1 or SP2, or Server 2008 Gold or SP2
7308| [CVE-2009-1928] Stack consumption vulnerability in the LDAP service in Active Directory on Microsoft Windows 2000 SP4, Server 2003 SP2, and Server 2008 Gold and SP2
7309| [CVE-2009-1926] Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to cause a denial of service (TCP outage) via a series of TCP sessions that have pending data and a (1) small or (2) zero receive window size, and remain in the FIN-WAIT-1 or FIN-WAIT-2 state indefinitely, aka "TCP/IP Orphaned Connections Vulnerability."
7310| [CVE-2009-1925] The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 does not properly manage state information, which allows remote attackers to execute arbitrary code by sending packets to a listening service, and thereby triggering misinterpretation of an unspecified field as a function pointer, aka "TCP/IP Timestamps Code Execution Vulnerability."
7311| [CVE-2009-1924] Integer overflow in the Windows Internet Name Service (WINS) component for Microsoft Windows 2000 SP4 allows remote WINS replication partners to execute arbitrary code via crafted data structures in a packet, aka "WINS Integer Overflow Vulnerability."
7312| [CVE-2009-1923] Heap-based buffer overflow in the Windows Internet Name Service (WINS) component for Microsoft Windows 2000 SP4 and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted WINS replication packet that triggers an incorrect buffer-length calculation, aka "WINS Heap Overflow Vulnerability."
7313| [CVE-2009-1922] The Message Queuing (aka MSMQ) service for Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP2, and Vista Gold does not properly validate unspecified IOCTL request data from user mode before passing this data to kernel mode, which allows local users to gain privileges via a crafted request, aka "MSMQ Null Pointer Vulnerability."
7314| [CVE-2009-1546] Integer overflow in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windows allows remote attackers to execute arbitrary code on a Windows 2000 SP4 system via a crafted AVI file, or cause a denial of service on a Windows XP SP2 or SP3, Server 2003 SP2, Vista Gold, SP1, or SP2, or Server 2008 Gold or SP2 system via a crafted AVI file, aka "AVI Integer Overflow Vulnerability."
7315| [CVE-2009-1545] Unspecified vulnerability in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a malformed header in a crafted AVI file, aka "Malformed AVI Header Vulnerability."
7316| [CVE-2009-1544] Double free vulnerability in the Workstation service in Microsoft Windows allows remote authenticated users to gain privileges via a crafted RPC message to a Windows XP SP2 or SP3 or Server 2003 SP2 system, or cause a denial of service via a crafted RPC message to a Vista Gold, SP1, or SP2 or Server 2008 Gold or SP2 system, aka "Workstation Service Memory Corruption Vulnerability."
7317| [CVE-2009-1542] The Virtual Machine Monitor (VMM) in Microsoft Virtual PC 2004 SP1, 2007, and 2007 SP1, and Microsoft Virtual Server 2005 R2 SP1, does not enforce CPU privilege-level requirements for all machine instructions, which allows guest OS users to execute arbitrary kernel-mode code and gain privileges within the guest OS via a crafted application, aka "Virtual PC and Virtual Server Privileged Instruction Decoding Vulnerability."
7318| [CVE-2009-1539] The QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 does not properly validate unspecified size fields in QuickTime media files, which allows remote attackers to execute arbitrary code via a crafted file, aka "DirectX Size Validation Vulnerability."
7319| [CVE-2009-1538] The QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 performs updates to pointers without properly validating unspecified data values, which allows remote attackers to execute arbitrary code via a crafted QuickTime media file, aka "DirectX Pointer Validation Vulnerability."
7320| [CVE-2009-1537] Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted QuickTime media file, as exploited in the wild in May 2009, aka "DirectX NULL Byte Overwrite Vulnerability."
7321| [CVE-2009-1536] ASP.NET in Microsoft .NET Framework 2.0 SP1 and SP2 and 3.5 Gold and SP1, when ASP 2.0 is used in integrated mode on IIS 7.0, does not properly manage request scheduling, which allows remote attackers to cause a denial of service (daemon outage) via a series of crafted HTTP requests, aka "Remote Unauthenticated Denial of Service in ASP.NET Vulnerability."
7322| [CVE-2009-1534] Buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2000 Web Components SP3, Office XP Web Components SP3, BizTalk Server 2002, and Visual Studio .NET 2003 SP1 allows remote attackers to execute arbitrary code via crafted property values, aka "Office Web Components Buffer Overflow Vulnerability."
7323| [CVE-2009-1533] Buffer overflow in the Works for Windows document converters in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, Office 2007 SP1, and Works 8.5 and 9 allows remote attackers to execute arbitrary code via a crafted Works .wps file that triggers memory corruption, aka "File Converter Buffer Overflow Vulnerability."
7324| [CVE-2009-1491] McAfee GroupShield for Microsoft Exchange on Exchange Server 2000, and possibly other anti-virus or anti-spam products from McAfee or other vendors, does not scan X- headers for malicious content, which allows remote attackers to bypass virus detection via a crafted message, as demonstrated by a message with an X-Testing header and no message body.
7325| [CVE-2009-1216] Multiple unspecified vulnerabilities in (1) unlzh.c and (2) unpack.c in the gzip libraries in Microsoft Windows Server 2008, Windows Services for UNIX 3.0 and 3.5, and the Subsystem for UNIX-based Applications (SUA)
7326| [CVE-2009-1141] Microsoft Internet Explorer 6 for Windows XP SP2 and SP3 and Server 2003 SP2 allows remote attackers to execute arbitrary code via unspecified DHTML function calls related to a tr element and the "insertion, deletion and attributes of a table cell," which trigger memory corruption when the window is destroyed, aka "DHTML Object Memory Corruption Vulnerability."
7327| [CVE-2009-1139] Memory leak in the LDAP service in Active Directory on Microsoft Windows 2000 SP4 and Server 2003 SP2, and Active Directory Application Mode (ADAM) on Windows XP SP2 and SP3 and Server 2003 SP2, allows remote attackers to cause a denial of service (memory consumption and service outage) via (1) LDAP or (2) LDAPS requests with unspecified OID filters, aka "Active Directory Memory Leak Vulnerability."
7328| [CVE-2009-1138] The LDAP service in Active Directory on Microsoft Windows 2000 SP4 does not properly free memory for LDAP and LDAPS requests, which allows remote attackers to execute arbitrary code via a request that uses hexadecimal encoding, whose associated memory is not released, related to a "DN AttributeValue," aka "Active Directory Invalid Free Vulnerability." NOTE: this issue is probably a memory leak.
7329| [CVE-2009-1137] Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0223, CVE-2009-0226, and CVE-2009-0227.
7330| [CVE-2009-1136] The Microsoft Office Web Components Spreadsheet ActiveX control (aka OWC10 or OWC11), as distributed in Office XP SP3 and Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 Gold and SP1, and Office Small Business Accounting 2006, when used in Internet Explorer, allows remote attackers to execute arbitrary code via a crafted call to the msDataSourceObject method, as exploited in the wild in July and August 2009, aka "Office Web Components HTML Script Vulnerability."
7331| [CVE-2009-1135] Microsoft Internet Security and Acceleration (ISA) Server 2006 Gold and SP1, when Radius OTP is enabled, uses the HTTP-Basic authentication method, which allows remote attackers to gain the privileges of an arbitrary account, and access published web pages, via vectors involving attempted access to a network resource behind the ISA Server, aka "Radius OTP Bypass Vulnerability."
7332| [CVE-2009-1134] Excel in 2007 Microsoft Office System SP1 and SP2
7333| [CVE-2009-1133] Heap-based buffer overflow in Microsoft Remote Desktop Connection (formerly Terminal Services Client) running RDP 5.0 through 6.1 on Windows, and Remote Desktop Connection Client for Mac 2.0, allows remote attackers to execute arbitrary code via unspecified parameters, aka "Remote Desktop Connection Heap Overflow Vulnerability."
7334| [CVE-2009-1132] Heap-based buffer overflow in the Wireless LAN AutoConfig Service (aka Wlansvc) in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a malformed wireless frame, aka "Wireless Frame Parsing Remote Code Execution Vulnerability."
7335| [CVE-2009-1131] Multiple stack-based buffer overflows in Microsoft Office PowerPoint 2000 SP3 allow remote attackers to execute arbitrary code via a large amount of data associated with unspecified atoms in a PowerPoint file that triggers memory corruption, aka "Data Out of Bounds Vulnerability."
7336| [CVE-2009-1130] Heap-based buffer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a crafted structure in a Notes container in a PowerPoint file that causes PowerPoint to read more data than was allocated when creating a C++ object, leading to an overwrite of a function pointer, aka "Heap Corruption Vulnerability."
7337| [CVE-2009-1129] Multiple stack-based buffer overflows in the PowerPoint 95 importer (PP7X32.DLL) in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allow remote attackers to execute arbitrary code via an inconsistent record length in sound data in a file that uses a PowerPoint 95 (PPT95) native file format, aka "PP7 Memory Corruption Vulnerability," a different vulnerability than CVE-2009-1128.
7338| [CVE-2009-1128] Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 95 native file format, leading to memory corruption, aka "PP7 Memory Corruption Vulnerability," a different vulnerability than CVE-2009-1129.
7339| [CVE-2009-1127] win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not correctly validate an argument to an unspecified system call, which allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, aka "Win32k NULL Pointer Dereferencing Vulnerability."
7340| [CVE-2009-1126] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly validate the user-mode input associated with the editing of an unspecified desktop parameter, which allows local users to gain privileges via a crafted application, aka "Windows Desktop Parameter Edit Vulnerability."
7341| [CVE-2009-1125] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate an argument to an unspecified system call, which allows local users to gain privileges via a crafted application, aka "Windows Driver Class Registration Vulnerability."
7342| [CVE-2009-1124] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate user-mode pointers in unspecified error conditions, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Pointer Validation Vulnerability."
7343| [CVE-2009-1123] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Desktop Vulnerability."
7344| [CVE-2009-1122] The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote attackers to bypass authentication, and possibly read or create files, via a crafted HTTP request, aka "IIS 5.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1535.
7345| [CVE-2009-1043] Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors triggered by clicking on a link, as demonstrated by Nils during a PWN2OWN competition at CanSecWest 2009.
7346| [CVE-2009-1011] Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on reliable researcher claims that this issue is for multiple integer overflows in a function that parses an optional data stream within a Microsoft Office file, leading to a heap-based buffer overflow.
7347| [CVE-2009-0901] The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold, and Visual C++ 2005 SP1 and 2008 Gold and SP1
7348| [CVE-2009-0568] The RPC Marshalling Engine (aka NDR) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly maintain its internal state, which allows remote attackers to overwrite arbitrary memory locations via a crafted RPC message that triggers incorrect pointer reading, related to "IDL interfaces containing a non-conformant varying array" and FC_SMVARRAY, FC_LGVARRAY, FC_VARIABLE_REPEAT, and FC_VARIABLE_OFFSET, aka "RPC Marshalling Engine Vulnerability."
7349| [CVE-2009-0566] Microsoft Office Publisher 2007 SP1 does not properly calculate object handler data for Publisher files, which allows remote attackers to execute arbitrary code via a crafted file in a legacy format that triggers memory corruption, aka "Pointer Dereference Vulnerability."
7350| [CVE-2009-0565] Buffer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, and 2007 SP1 and SP2
7351| [CVE-2009-0563] Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
7352| [CVE-2009-0562] The Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 SP1, and Office Small Business Accounting 2006 does not properly allocate memory, which allows remote attackers to execute arbitrary code via unspecified vectors that trigger "system state" corruption, aka "Office Web Components Memory Allocation Vulnerability."
7353| [CVE-2009-0561] Integer overflow in Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac
7354| [CVE-2009-0560] Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac
7355| [CVE-2009-0559] Stack-based buffer overflow in Excel in Microsoft Office 2000 SP3 and Office XP SP3 allows remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "String Copy Stack-Based Overrun Vulnerability."
7356| [CVE-2009-0558] Array index error in Excel in Microsoft Office 2000 SP3 and Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac, allows remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Array Indexing Memory Corruption Vulnerability."
7357| [CVE-2009-0557] Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac
7358| [CVE-2009-0556] Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an an invalid index value that triggers memory corruption, as exploited in the wild in April 2009 by Exploit:Win32/Apptom.gen, aka "Memory Corruption Vulnerability."
7359| [CVE-2009-0554] Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka "Uninitialized Memory Corruption Vulnerability."
7360| [CVE-2009-0553] Microsoft Internet Explorer 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka "Uninitialized Memory Corruption Vulnerability."
7361| [CVE-2009-0552] Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 on Windows XP SP2 and SP3, and 6 on Windows Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka "Uninitialized Memory Corruption Vulnerability."
7362| [CVE-2009-0551] Microsoft Internet Explorer 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 does not properly handle transition errors in a request for one HTTP document followed by a request for a second HTTP document, which allows remote attackers to execute arbitrary code via vectors involving (1) multiple crafted pages on a web site or (2) a web page with crafted inline content such as banner advertisements, aka "Page Transition Memory Corruption Vulnerability."
7363| [CVE-2009-0550] Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008
7364| [CVE-2009-0549] Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac
7365| [CVE-2009-0320] Microsoft Windows XP, Server 2003 and 2008, and Vista exposes I/O activity measurements of all processes, which allows local users to obtain sensitive information, as demonstrated by reading the I/O Other Bytes column in Task Manager (aka taskmgr.exe) to estimate the number of characters that a different user entered at a runas.exe password prompt, related to a "benchmarking attack."
7366| [CVE-2009-0239] Cross-site scripting (XSS) vulnerability in Windows Search 4.0 for Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted file that appears in a preview in a search result, aka "Script Execution in Windows Search Vulnerability."
7367| [CVE-2009-0238] Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1
7368| [CVE-2009-0235] Stack-based buffer overflow in the Word 97 text converter in WordPad in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted Word 97 file that triggers memory corruption, related to use of inconsistent integer data sizes for an unspecified length field, aka "WordPad Word 97 Text Converter Stack Overflow Vulnerability."
7369| [CVE-2009-0234] The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008 does not properly cache crafted DNS responses, which makes it easier for remote attackers to predict transaction IDs and poison caches by sending many crafted DNS queries that trigger "unnecessary lookups," aka "DNS Server Response Validation Vulnerability."
7370| [CVE-2009-0233] The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not reuse cached DNS responses in all applicable situations, which makes it easier for remote attackers to predict transaction IDs and poison caches by simultaneously sending crafted DNS queries and responses, aka "DNS Server Query Validation Vulnerability."
7371| [CVE-2009-0232] Integer overflow in the Embedded OpenType (EOT) Font Engine in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted name table, aka "Embedded OpenType Font Integer Overflow Vulnerability."
7372| [CVE-2009-0231] The Embedded OpenType (EOT) Font Engine (T2EMBED.DLL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted name table in a data record that triggers an integer truncation and a heap-based buffer overflow, aka "Embedded OpenType Font Heap Overflow Vulnerability."
7373| [CVE-2009-0230] The Windows Print Spooler in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows remote authenticated users to gain privileges via a crafted RPC message that triggers loading of a DLL file from an arbitrary directory, aka "Print Spooler Load Library Vulnerability."
7374| [CVE-2009-0229] The Windows Printing Service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows local users to read arbitrary files via a crafted separator page, aka "Print Spooler Read File Vulnerability."
7375| [CVE-2009-0228] Stack-based buffer overflow in the EnumeratePrintShares function in Windows Print Spooler Service (win32spl.dll) in Microsoft Windows 2000 SP4 allows remote printer servers to execute arbitrary code via a a crafted ShareName in a response to an RPC request, related to "printing data structures," aka "Buffer Overflow in Print Spooler Vulnerability."
7376| [CVE-2009-0227] Stack-based buffer overflow in the PowerPoint 4.2 conversion filter (PP4X32.DLL) in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via a large number of structures in sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0223, CVE-2009-0226, and CVE-2009-1137.
7377| [CVE-2009-0226] Stack-based buffer overflow in the PowerPoint 4.2 conversion filter in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via a long string in sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0223, CVE-2009-0227, and CVE-2009-1137.
7378| [CVE-2009-0225] Microsoft Office PowerPoint 2002 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 95 native file format, leading to improper "array indexing" and memory corruption, aka "PP7 Memory Corruption Vulnerability."
7379| [CVE-2009-0224] Microsoft Office PowerPoint 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
7380| [CVE-2009-0223] Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0226, CVE-2009-0227, and CVE-2009-1137.
7381| [CVE-2009-0222] Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 4.0 native file format, leading to a "pointer overwrite" and memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0223, CVE-2009-0226, CVE-2009-0227, and CVE-2009-1137.
7382| [CVE-2009-0221] Integer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a PowerPoint file containing a crafted record type for "collaboration information for different slides" that contains a field that specifies a large number of records, which triggers an under-allocated buffer and a heap-based buffer overflow, aka "Integer Overflow Vulnerability."
7383| [CVE-2009-0220] Multiple stack-based buffer overflows in the PowerPoint 4.0 importer (PP4X32.DLL) in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allow remote attackers to execute arbitrary code via crafted formatting data for paragraphs in a file that uses a PowerPoint 4.0 native file format, related to (1) an incorrect calculation from a record header, or (2) an interget that is used to specify the number of bytes to copy, aka "Legacy File Format Vulnerability."
7384| [CVE-2009-0202] Array index error in FL21WIN.DLL in the PowerPoint Freelance Windows 2.1 Translator in Microsoft PowerPoint 2000 and 2002 allows remote attackers to execute arbitrary code via a Freelance file with unspecified "layout information" that triggers a heap-based buffer overflow.
7385| [CVE-2009-0102] Microsoft Project 2000 SR1 and 2002 SP1, and Office Project 2003 SP3, does not properly handle memory allocation for Project files, which allows remote attackers to execute arbitrary code via a malformed file, aka "Project Memory Validation Vulnerability."
7386| [CVE-2009-0100] Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1
7387| [CVE-2009-0099] The Electronic Messaging System Microsoft Data Base (EMSMDB32) provider in Microsoft Exchange 2000 Server SP3 and Exchange Server 2003 SP2, as used in Exchange System Attendant, allows remote attackers to cause a denial of service (application outage) via a malformed MAPI command, aka "Literal Processing Vulnerability."
7388| [CVE-2009-0098] Microsoft Exchange 2000 Server SP3, Exchange Server 2003 SP2, and Exchange Server 2007 SP1 do not properly interpret Transport Neutral Encapsulation (TNEF) properties, which allows remote attackers to execute arbitrary code via a crafted TNEF message, aka "Memory Corruption Vulnerability."
7389| [CVE-2009-0097] Microsoft Office Visio 2002 SP2 and 2003 SP3 does not properly validate memory allocation for Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Memory Corruption Vulnerability."
7390| [CVE-2009-0096] Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 does not properly perform memory copy operations for object data, which allows remote attackers to execute arbitrary code via a crafted Visio document, aka "Memory Corruption Vulnerability."
7391| [CVE-2009-0095] Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 does not properly validate object data in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Memory Validation Vulnerability."
7392| [CVE-2009-0094] The WINS server in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 does not restrict registration of the (1) "wpad" and (2) "isatap" NetBIOS names, which allows remote authenticated users to hijack the Web Proxy Auto-Discovery (WPAD) and Intra-Site Automatic Tunnel Addressing Protocol (ISATAP) features, and conduct man-in-the-middle attacks by spoofing a proxy server or ISATAP route, by registering one of these names in the WINS database, aka "WPAD WINS Server Registration Vulnerability," a related issue to CVE-2007-1692.
7393| [CVE-2009-0093] Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not restrict registration of the "wpad" hostname, which allows remote authenticated users to hijack the Web Proxy Auto-Discovery (WPAD) feature, and conduct man-in-the-middle attacks by spoofing a proxy server, via a Dynamic Update request for this hostname, aka "DNS Server Vulnerability in WPAD Registration Vulnerability," a related issue to CVE-2007-1692.
7394| [CVE-2009-0091] Microsoft .NET Framework 2.0, 2.0 SP1, and 3.5 does not properly enforce a certain type-equality constraint in .NET verifiable code, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft .NET Framework Type Verification Vulnerability."
7395| [CVE-2009-0090] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, and 2.0 SP1 does not properly validate .NET verifiable code, which allows remote attackers to obtain unintended access to stack memory, and execute arbitrary code, via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft .NET Framework Pointer Verification Vulnerability."
7396| [CVE-2009-0089] Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Vista Gold allows remote web servers to impersonate arbitrary https web sites by using DNS spoofing to "forward a connection" to a different https web site that has a valid certificate matching its own domain name, but not a certificate matching the domain name of the host requested by the user, aka "Windows HTTP Services Certificate Name Mismatch Vulnerability."
7397| [CVE-2009-0088] The WordPerfect 6.x Converter (WPFT632.CNV, 1998.1.27.0) in Microsoft Office Word 2000 SP3 and Microsoft Office Converter Pack does not properly validate the length of an unspecified string, which allows remote attackers to execute arbitrary code via a crafted WordPerfect 6.x file, related to an unspecified counter and control structures on the stack, aka "Word 2000 WordPerfect 6.x Converter Stack Corruption Vulnerability."
7398| [CVE-2009-0087] Unspecified vulnerability in the Word 6 text converter in WordPad in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2
7399| [CVE-2009-0086] Integer underflow in Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote HTTP servers to execute arbitrary code via crafted parameter values in a response, related to error handling, aka "Windows HTTP Services Integer Underflow Vulnerability."
7400| [CVE-2009-0085] The Secure Channel (aka SChannel) authentication component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008, when certificate authentication is used, does not properly validate the client's key exchange data in Transport Layer Security (TLS) handshake messages, which allows remote attackers to spoof authentication by crafting a TLS packet based on knowledge of the certificate but not the private key, aka "SChannel Spoofing Vulnerability."
7401| [CVE-2009-0083] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 does not properly handle invalid pointers, which allows local users to gain privileges via an application that triggers use of a crafted pointer, aka "Windows Kernel Invalid Pointer Vulnerability."
7402| [CVE-2009-0082] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate handles, which allows local users to gain privileges via a crafted application that triggers unspecified "actions," aka "Windows Kernel Handle Validation Vulnerability."
7403| [CVE-2009-0081] The graphics device interface (GDI) implementation in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate input received from user mode, which allows remote attackers to execute arbitrary code via a crafted (1) Windows Metafile (aka WMF) or (2) Enhanced Metafile (aka EMF) image file, aka "Windows Kernel Input Validation Vulnerability."
7404| [CVE-2009-0079] The RPCSS service in Microsoft Windows XP SP2 and SP3 and Server 2003 SP1 and SP2 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by accessing the resources of one of the processes, aka "Windows RPCSS Service Isolation Vulnerability."
7405| [CVE-2009-0078] The Windows Management Instrumentation (WMI) provider in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by accessing the resources of one of the processes, aka "Windows WMI Service Isolation Vulnerability."
7406| [CVE-2008-7217] Microsoft Office 2008 for Mac, when running on Macintosh systems that restrict Office access to administrators, does not enforce this restriction for user ID 502, which allows local users with that ID to bypass intended security policy and access Office programs, related to permissions and ownership for certain directories.
7407| [CVE-2008-6819] win32k.sys in Microsoft Windows Server 2003 and Vista allows local users to cause a denial of service (system crash) via vectors related to CreateWindow, TranslateMessage, and DispatchMessage, possibly a race condition between threads, a different vulnerability than CVE-2008-1084. NOTE: some of these details are obtained from third party information.
7408| [CVE-2008-6219] nsrexecd.exe in multiple EMC Networker products including EMC NetWorker Server, Storage Node, and Client 7.3.x and 7.4, 7.4.1, 7.4.2, Client and Storage Node for Open VMS 7.3.2 ECO6 and earlier, Module for Microsoft Exchange 5.1 and earlier, Module for Microsoft Applications 2.0 and earlier, Module for Meditech 2.0 and earlier, and PowerSnap 2.4 SP1 and earlier does not properly control the allocation of memory, which allows remote attackers to cause a denial of service (memory exhaustion) via multiple crafted RPC requests.
7409| [CVE-2008-6063] Microsoft Word 2007, when the "Save as PDF" add-on is enabled, places an absolute pathname in the Subject field during an "Email as PDF" operation, which allows remote attackers to obtain sensitive information such as the sender's account name and a Temporary Internet Files subdirectory name.
7410| [CVE-2008-5912] An unspecified function in the JavaScript implementation in Microsoft Internet Explorer creates and exposes a "temporary footprint" when there is a current login to a web site, which makes it easier for remote attackers to trick a user into acting upon a spoofed pop-up message, aka an "in-session phishing attack." NOTE: as of 20090116, the only disclosure is a vague pre-advisory with no actionable information. However, because it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.
7411| [CVE-2008-5823] An ActiveX control in prtstb06.dll in Microsoft Money 2006, when used with WScript in Windows Script Host (WSH) on Windows Vista, allows remote attackers to cause a denial of service (access violation and application crash) via a zero value for the Startup property.
7412| [CVE-2008-5416] Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier
7413| [CVE-2008-5232] Buffer overflow in the CallHTMLHelp method in the Microsoft Windows Media Services ActiveX control in nskey.dll 4.1.00.3917 in Windows Media Services on Microsoft Windows NT and 2000, and Avaya Media and Message Application servers, allows remote attackers to execute arbitrary code via a long argument. NOTE: the provenance of this information is unknown
7414| [CVE-2008-5112] The LDAP server in Active Directory in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 responds differently to a failed bind attempt depending on whether the user account exists and is permitted to login, which allows remote attackers to enumerate valid usernames via a series of LDAP bind requests, as demonstrated by ldapuserenum.
7415| [CVE-2008-5100] The strong name (SN) implementation in Microsoft .NET Framework 2.0.50727 relies on the digital signature Public Key Token embedded in the pathname of a DLL file instead of the digital signature of this file itself, which makes it easier for attackers to bypass Global Assembly Cache (GAC) and Code Access Security (CAS) protection mechanisms, aka MSRC ticket MSRC8566gs.
7416| [CVE-2008-5044] Race condition in Microsoft Windows Server 2003 and Vista allows local users to cause a denial of service (crash or hang) via a multi-threaded application that makes many calls to UnhookWindowsHookEx while certain other desktop activity is occurring.
7417| [CVE-2008-4844] Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via DSO bindings involving (1) an XML Island, (2) XML DSOs, or (3) Tabular Data Control (TDC) in a crafted HTML or XML document, as demonstrated by nested SPAN or MARQUEE elements, and exploited in the wild in December 2008.
7418| [CVE-2008-4841] The WordPad Text Converter for Word 97 files in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf Word 97 file that triggers memory corruption, as exploited in the wild in December 2008. NOTE: As of 20081210, it is unclear whether this vulnerability is related to a WordPad issue disclosed on 20080925 with a 2008-crash.doc.rar example, but there are insufficient details to be sure.
7419| [CVE-2008-4837] Stack-based buffer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
7420| [CVE-2008-4835] SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside the SMB packets" in an NT Trans2 request, related to "insufficiently validating the buffer size," aka "SMB Validation Remote Code Execution Vulnerability."
7421| [CVE-2008-4834] Buffer overflow in SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside the SMB packets" in an NT Trans request, aka "SMB Buffer Overflow Remote Code Execution Vulnerability."
7422| [CVE-2008-4493] Microsoft PicturePusher ActiveX control (PipPPush.DLL 7.00.0709), as used in Microsoft Digital Image 2006 Starter Edition, allows remote attackers to force the upload of arbitrary files by using the AddString and Post methods and a modified PostURL to construct an HTTP POST request. NOTE: this issue might only be exploitable in limited environments or non-default browser settings.
7423| [CVE-2008-4295] Microsoft Windows Mobile 6.0 on HTC Wiza 200 and HTC MDA 8125 devices does not properly handle the first attempt to establish a Bluetooth connection to a peer with a long name, which allows remote attackers to cause a denial of service (device reboot) by configuring a Bluetooth device with a long hci name and (1) connecting directly to the Windows Mobile system or (2) waiting for the Windows Mobile system to scan for nearby devices.
7424| [CVE-2008-4269] The search-ms protocol handler in Windows Explorer in Microsoft Windows Vista Gold and SP1 and Server 2008 uses untrusted parameter data obtained from incorrect parsing, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "Windows Search Parsing Vulnerability."
7425| [CVE-2008-4268] The Windows Search component in Microsoft Windows Vista Gold and SP1 and Server 2008 does not properly free memory during a save operation for a Windows Search file, which allows remote attackers to execute arbitrary code via a crafted saved-search file, aka "Windows Saved Search Vulnerability."
7426| [CVE-2008-4266] Array index vulnerability in Microsoft Office Excel 2000 SP3, 2002 SP3, and 2003 SP3
7427| [CVE-2008-4265] Microsoft Office Excel 2000 SP3 allows remote attackers to execute arbitrary code via a crafted Excel spreadsheet that contains a malformed object, which triggers memory corruption during the loading of records from this spreadsheet, aka "File Format Parsing Vulnerability."
7428| [CVE-2008-4264] Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
7429| [CVE-2008-4261] Stack-based buffer overflow in Microsoft Internet Explorer 5.01 SP4, 6 SP1 on Windows 2000, and 6 on Windows XP and Server 2003 does not properly handle extraneous data associated with an object embedded in a web page, which allows remote attackers to execute arbitrary code via crafted HTML tags that trigger memory corruption, aka "HTML Rendering Memory Corruption Vulnerability."
7430| [CVE-2008-4256] The Charts ActiveX control in Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the "system state," aka "Charts Control Memory Corruption Vulnerability."
7431| [CVE-2008-4255] Heap-based buffer overflow in mscomct2.ocx (aka Windows Common ActiveX control or Microsoft Animation ActiveX control) in Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2, and Office Project 2003 SP3 and 2007 Gold and SP1 allows remote attackers to execute arbitrary code via an AVI file with a crafted stream length, which triggers an "allocation error" and memory corruption, aka "Windows Common AVI Parsing Overflow Vulnerability."
7432| [CVE-2008-4253] The FlexGrid ActiveX control in Microsoft Visual Basic 6.0, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2, Office FrontPage 2002 SP3, and Office Project 2003 SP3 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the "system state," aka "FlexGrid Control Memory Corruption Vulnerability."
7433| [CVE-2008-4250] The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by Gimmiv.A in October 2008, aka "Server Service Vulnerability."
7434| [CVE-2008-4114] srv.sys in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via an SMB WRITE_ANDX packet with an offset that is inconsistent with the packet size, related to "insufficiently validating the buffer size," as demonstrated by a request to the \PIPE\lsarpc named pipe, aka "SMB Validation Denial of Service Vulnerability."
7435| [CVE-2008-4110] Buffer overflow in the SQLVDIRLib.SQLVDirControl ActiveX control in Tools\Binn\sqlvdir.dll in Microsoft SQL Server 2000 (aka SQL Server 8.0) allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a long URL in the second argument to the Connect method. NOTE: this issue is not a vulnerability in many environments, since the control is not marked as safe for scripting and would not execute with default Internet Explorer settings.
7436| [CVE-2008-4038] Buffer underflow in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via a Server Message Block (SMB) request that contains a filename with a crafted length, aka "SMB Buffer Underflow Vulnerability."
7437| [CVE-2008-4037] Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote SMB servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user, as demonstrated by backrush, aka "SMB Credential Reflection Vulnerability." NOTE: some reliable sources report that this vulnerability exists because of an insufficient fix for CVE-2000-0834.
7438| [CVE-2008-4036] Integer overflow in Memory Manager in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows local users to gain privileges via a crafted application that triggers an erroneous decrement of a variable, related to validation of parameters for Virtual Address Descriptors (VADs) and a "memory allocation mapping error," aka "Virtual Address Descriptor Elevation of Privilege Vulnerability."
7439| [CVE-2008-4032] Microsoft Office SharePoint Server 2007 Gold and SP1 and Microsoft Search Server 2008 do not properly perform authentication and authorization for administrative functions, which allows remote attackers to cause a denial of service (server load), obtain sensitive information, and "create scripts that would run in the context of the site" via requests to administrative URIs, aka "Access Control Vulnerability."
7440| [CVE-2008-4031] Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
7441| [CVE-2008-4030] Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
7442| [CVE-2008-4028] Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
7443| [CVE-2008-4027] Double free vulnerability in Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
7444| [CVE-2008-4026] Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
7445| [CVE-2008-4025] Integer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
7446| [CVE-2008-4024] Microsoft Office Word 2000 SP3 and 2002 SP3 and Office 2004 for Mac allow remote attackers to execute arbitrary code via a Word document with a crafted lcbPlcfBkfSdt field in the File Information Block (FIB), which bypasses an initialization step and triggers an "arbitrary free," aka "Word Memory Corruption Vulnerability."
7447| [CVE-2008-4023] Active Directory in Microsoft Windows 2000 SP4 does not properly allocate memory for (1) LDAP and (2) LDAPS requests, which allows remote attackers to execute arbitrary code via a crafted request, aka "Active Directory Overflow Vulnerability."
7448| [CVE-2008-4019] Integer overflow in the REPT function in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1
7449| [CVE-2008-3956] orgchart.exe in Microsoft Organization Chart 2.00 allows user-assisted attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted .opx file.
7450| [CVE-2008-3704] Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions before 6.0.84.18, in Microsoft Visual Studio 6.0, Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 allows remote attackers to execute arbitrary code via a long Mask parameter, related to not "validating property values with boundary checks," as exploited in the wild in August 2008, aka "Masked Edit Control Memory Corruption Vulnerability."
7451| [CVE-2008-3648] nslookup.exe in Microsoft Windows XP SP2 allows user-assisted remote attackers to execute arbitrary code, as demonstrated by an attempted DNS zone transfer, and as exploited in the wild in August 2008.
7452| [CVE-2008-3636] Integer overflow in the IopfCompleteRequest API in the kernel in Microsoft Windows 2000, XP, Server 2003, and Vista allows context-dependent attackers to gain privileges. NOTE: this issue was originally reported for GEARAspiWDM.sys 2.0.7.5 in Gear Software CD DVD Filter driver before 4.001.7, as used in other products including Apple iTunes and multiple Symantec and Norton products, which allows local users to gain privileges via repeated IoAttachDevice IOCTL calls to \\.\GEARAspiWDMDevice in this GEARAspiWDM.sys. However, the root cause is the integer overflow in the API call itself.
7453| [CVE-2008-3479] Heap-based buffer overflow in the Microsoft Message Queuing (MSMQ) service (mqsvc.exe) in Microsoft Windows 2000 SP4 allows remote attackers to read memory contents and execute arbitrary code via a crafted RPC call, related to improper processing of parameters to string APIs, aka "Message Queuing Service Remote Code Execution Vulnerability."
7454| [CVE-2008-3477] Microsoft Excel 2000 SP3, 2002 SP3, and 2003 SP2 and SP3 does not properly validate data in the VBA Performance Cache when processing an Office document with an embedded object, which allows remote attackers to execute arbitrary code via an Excel file containing a crafted value, leading to heap-based buffer overflows, integer overflows, array index errors, and memory corruption, aka "Calendar Object Validation Vulnerability."
7455| [CVE-2008-3471] Stack-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1
7456| [CVE-2008-3466] Microsoft Host Integration Server (HIS) 2000, 2004, and 2006 does not limit RPC access to administrative functions, which allows remote attackers to bypass authentication and execute arbitrary programs via a crafted SNA RPC message using opcode 1 or 6 to call the CreateProcess function, aka "HIS Command Execution Vulnerability."
7457| [CVE-2008-3465] Heap-based buffer overflow in an API in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows context-dependent attackers to cause a denial of service or execute arbitrary code via a WMF file with a malformed file-size parameter, which would not be properly handled by a third-party application that uses this API for a copy operation, aka "GDI Heap Overflow Vulnerability."
7458| [CVE-2008-3464] afd.sys in the Ancillary Function Driver (AFD) component in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP1 and SP2 does not properly validate input sent from user mode to the kernel, which allows local users to gain privileges via a crafted application, as demonstrated using crafted pointers and lengths that bypass intended ProbeForRead and ProbeForWrite restrictions, aka "AFD Kernel Overwrite Vulnerability."
7459| [CVE-2008-3460] WPGIMP32.FLT in Microsoft Office 2000 SP3, XP SP3, and 2003 SP2
7460| [CVE-2008-3068] Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times and IP addresses of recipients, and port-scan results, via a crafted certificate with an Authority Information Access (AIA) extension.
7461| [CVE-2008-3021] Microsoft Office 2000 SP3, XP SP3, and 2003 SP2
7462| [CVE-2008-3020] Microsoft Office 2000 SP3 and XP SP3
7463| [CVE-2008-3019] Microsoft Office 2000 SP3, XP SP3, and 2003 SP2
7464| [CVE-2008-3018] Microsoft Office 2000 SP3, XP SP3, and 2003 SP2
7465| [CVE-2008-3015] Integer overflow in gdiplus.dll in GDI+ in Microsoft Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a BMP image file with a malformed BitMapInfoHeader that triggers a buffer overflow, aka "GDI+ BMP Integer Overflow Vulnerability."
7466| [CVE-2008-3014] Buffer overflow in gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a malformed WMF image file that triggers improper memory allocation, aka "GDI+ WMF Buffer Overrun Vulnerability."
7467| [CVE-2008-3013] gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a malformed GIF image file containing many extension markers for graphic control extensions and subsequent unknown labels, aka "GDI+ GIF Parsing Vulnerability."
7468| [CVE-2008-3012] gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 does not properly perform memory allocation, which allows remote attackers to execute arbitrary code via a malformed EMF image file, aka "GDI+ EMF Memory Corruption Vulnerability."
7469| [CVE-2008-3009] Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1, 9, and 2008 do not properly use the Service Principal Name (SPN) identifier when validating replies to authentication requests, which allows remote servers to execute arbitrary code via vectors that employ NTLM credential reflection, aka "SPN Vulnerability."
7470| [CVE-2008-3007] Argument injection vulnerability in a URI handler in Microsoft Office XP SP3, 2003 SP2 and SP3, 2007 Office System Gold and SP1, and Office OneNote 2007 Gold and SP1 allow remote attackers to execute arbitrary code via a crafted onenote:// URL, aka "Uniform Resource Locator Validation Error Vulnerability."
7471| [CVE-2008-3006] Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1
7472| [CVE-2008-3005] Array index vulnerability in Microsoft Office Excel 2000 SP3 and 2002 SP3, and Office 2004 and 2008 for Mac allows remote attackers to execute arbitrary code via an Excel file with a crafted array index for a FORMAT record, aka the "Excel Index Array Vulnerability."
7473| [CVE-2008-3004] Microsoft Office Excel 2000 SP3, 2002 SP3, and 2003 SP2 and SP3
7474| [CVE-2008-3003] Microsoft Office Excel 2007 Gold and SP1 does not properly delete the PWD (password) string from connections.xml when a .xlsx file is configured not to save the remote data session password, which allows local users to obtain sensitive information and obtain access to a remote data source, aka the "Excel Credential Caching Vulnerability."
7475| [CVE-2008-2752] Microsoft Word 2000 9.0.2812 and 2003 11.8106.8172 does not properly handle unordered lists, which allows user-assisted remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .doc file. NOTE: some of these details are obtained from third party information.
7476| [CVE-2008-2540] Apple Safari on Mac OS X, and before 3.1.2 on Windows, does not prompt the user before downloading an object that has an unrecognized content type, which allows remote attackers to place malware into the (1) Desktop directory on Windows or (2) Downloads directory on Mac OS X, and subsequently allows remote attackers to execute arbitrary code on Windows by leveraging an untrusted search path vulnerability in (a) Internet Explorer 7 on Windows XP or (b) the SearchPath function in Windows XP, Vista, and Server 2003 and 2008, aka a "Carpet Bomb" and a "Blended Threat Elevation of Privilege Vulnerability," a different issue than CVE-2008-1032. NOTE: Apple considers this a vulnerability only because the Microsoft products can load application libraries from the desktop and, as of 20080619, has not covered the issue in an advisory for Mac OS X.
7477| [CVE-2008-2463] The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snapshot Viewer and Microsoft Office Access 2000 through 2003, allows remote attackers to download arbitrary files to a client machine via a crafted HTML document or e-mail message, probably involving use of the SnapshotPath and CompressedPath properties and the PrintSnapshot method. NOTE: this can be leveraged for code execution by writing to a Startup folder.
7478| [CVE-2008-2252] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate parameters sent from user mode to the kernel, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Corruption Vulnerability."
7479| [CVE-2008-2251] Double free vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows local users to gain privileges via a crafted application that makes system calls within multiple threads, aka "Windows Kernel Unhandled Exception Vulnerability." NOTE: according to Microsoft, this is not a duplicate of CVE-2008-4510.
7480| [CVE-2008-2250] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate window properties sent from a parent window to a child window during creation of a new window, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Window Creation Vulnerability."
7481| [CVE-2008-2249] Integer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via a malformed header in a crafted WMF file, which triggers a buffer overflow, aka "GDI Integer Overflow Vulnerability."
7482| [CVE-2008-2246] Microsoft Windows Vista through SP1 and Server 2008 do not properly import the default IPsec policy from a Windows Server 2003 domain to a Windows Server 2008 domain, which prevents IPsec rules from being enforced and allows remote attackers to bypass intended access restrictions.
7483| [CVE-2008-2245] Heap-based buffer overflow in the InternalOpenColorProfile function in mscms.dll in Microsoft Windows Image Color Management System (MSCMS) in the Image Color Management (ICM) component on Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted image file.
7484| [CVE-2008-2244] Microsoft Office Word 2002 SP3 allows remote attackers to execute arbitrary code via a .doc file that contains malformed data, as exploited in the wild in July 2008, and as demonstrated by attachement.doc.
7485| [CVE-2008-1898] A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and 2007, allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via an invalid WksPictureInterface property value, which triggers an improper function call.
7486| [CVE-2008-1888] Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 2.0 allows remote attackers to inject arbitrary web script or HTML via the Picture Source (aka picture object source) field in the Rich Text Editor.
7487| [CVE-2008-1547] Open redirect vulnerability in exchweb/bin/redir.asp in Microsoft Outlook Web Access (OWA) for Exchange Server 2003 SP2 (aka build 6.5.7638) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the URL parameter.
7488| [CVE-2008-1457] The Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate per-user subscriptions, which allows remote authenticated users to execute arbitrary code via a crafted event subscription request.
7489| [CVE-2008-1456] Array index vulnerability in the Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote authenticated users to execute arbitrary code via a crafted event subscription request that is used to access an array of function pointers.
7490| [CVE-2008-1455] A "memory calculation error" in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, 2003 SP2, and 2007 through SP1
7491| [CVE-2008-1454] Unspecified vulnerability in Microsoft DNS in Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008 allows remote attackers to conduct cache poisoning attacks via unknown vectors related to accepting "records from a response that is outside the remote server's authority," aka "DNS Cache Poisoning Vulnerability," a different vulnerability than CVE-2008-1447.
7492| [CVE-2008-1451] The WINS service on Microsoft Windows 2000 SP4, and Server 2003 SP1 and SP2, does not properly validate data structures in WINS network packets, which allows local users to gain privileges via a crafted packet, aka "Memory Overwrite Vulnerability."
7493| [CVE-2008-1446] Integer overflow in the Internet Printing Protocol (IPP) ISAPI extension in Microsoft Internet Information Services (IIS) 5.0 through 7.0 on Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to execute arbitrary code via an HTTP POST request that triggers an outbound IPP connection from a web server to a machine operated by the attacker, aka "Integer Overflow in IPP Service Vulnerability."
7494| [CVE-2008-1445] Active Directory on Microsoft Windows 2000 Server SP4, XP Professional SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to cause a denial of service (system hang or reboot) via a crafted LDAP request.
7495| [CVE-2008-1444] Stack-based buffer overflow in Microsoft DirectX 7.0 and 8.1 on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a Synchronized Accessible Media Interchange (SAMI) file with crafted parameters for a Class Name variable, aka the "SAMI Format Parsing Vulnerability."
7496| [CVE-2008-1441] Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to cause a denial of service (system hang) via a series of Pragmatic General Multicast (PGM) packets with invalid fragment options, aka the "PGM Malformed Fragment Vulnerability."
7497| [CVE-2008-1440] Microsoft Windows XP SP2 and SP3, and Server 2003 SP1 and SP2, does not properly validate the option length field in Pragmatic General Multicast (PGM) packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted PGM packet, aka the "PGM Invalid Length Vulnerability."
7498| [CVE-2008-1436] Microsoft Windows XP Professional SP2, Vista, and Server 2003 and 2008 does not properly assign activities to the (1) NetworkService and (2) LocalService accounts, which might allow context-dependent attackers to gain privileges by using one service process to capture a resource from a second service process that has a LocalSystem privilege-escalation ability, related to improper management of the SeImpersonatePrivilege user right, as originally reported for Internet Information Services (IIS), aka Token Kidnapping.
7499| [CVE-2008-1435] Windows Explorer in Microsoft Windows Vista up to SP1, and Server 2008, allows user-assisted remote attackers to execute arbitrary code via crafted saved-search (.search-ms) files that are not properly handled when saving, aka "Windows Saved Search Vulnerability."
7500| [CVE-2008-1434] Use-after-free vulnerability in Microsoft Word in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 Office System SP1 and earlier allows remote attackers to execute arbitrary code via an HTML document with a large number of Cascading Style Sheets (CSS) selectors, related to a "memory handling error" that triggers memory corruption.
7501| [CVE-2008-1092] Buffer overflow in msjet40.dll before 4.0.9505.0 in Microsoft Jet Database Engine allows remote attackers to execute arbitrary code via a crafted Word file, as exploited in the wild in March 2008. NOTE: as of 20080513, Microsoft has stated that this is the same issue as CVE-2007-6026.
7502| [CVE-2008-1091] Unspecified vulnerability in Microsoft Word in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 Office System SP1 and earlier allows remote attackers to execute arbitrary code via a Rich Text Format (.rtf) file with a malformed string that triggers a "memory calculation error" and a heap-based buffer overflow, aka "Object Parsing Vulnerability."
7503| [CVE-2008-1090] Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows user-assisted remote attackers to execute arbitrary code via a crafted .DXF file, aka "Visio Memory Validation Vulnerability."
7504| [CVE-2008-1089] Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows user-assisted remote attackers to execute arbitrary code via a Visio file containing crafted object header data, aka "Visio Object Header Vulnerability."
7505| [CVE-2008-1088] Microsoft Project 2000 Service Release 1, 2002 SP1, and 2003 SP2 allows user-assisted remote attackers to execute arbitrary code via a crafted Project file, related to improper validation of "memory resource allocations."
7506| [CVE-2008-1087] Stack-based buffer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to execute arbitrary code via an EMF image file with crafted filename parameters, aka "GDI Stack Overflow Vulnerability."
7507| [CVE-2008-1086] The HxTocCtrl ActiveX control (hxvz.dll), as used in Microsoft Internet Explorer 5.01 SP4 and 6 SP1, in Windows XP SP2, Server 2003 SP1 and SP2, Vista SP1, and Server 2008, allows remote attackers to execute arbitrary code via malformed arguments, which triggers memory corruption.
7508| [CVE-2008-1084] Unspecified vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, through Vista SP1, and Server 2008 allows local users to execute arbitrary code via unknown vectors related to improper input validation. NOTE: it was later reported that one affected function is NtUserFnOUTSTRING in win32k.sys.
7509| [CVE-2008-1083] Heap-based buffer overflow in the CreateDIBPatternBrushPt function in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to execute arbitrary code via an EMF or WMF image file with a malformed header that triggers an integer overflow, aka "GDI Heap Overflow Vulnerability."
7510| [CVE-2008-0121] A "memory calculation error" in Microsoft PowerPoint Viewer 2003 allows remote attackers to execute arbitrary code via a PowerPoint file with an invalid picture index that triggers memory corruption, aka "Memory Calculation Vulnerability."
7511| [CVE-2008-0120] Integer overflow in Microsoft PowerPoint Viewer 2003 allows remote attackers to execute arbitrary code via a PowerPoint file with a malformed picture index that triggers memory corruption, related to handling of CString objects, aka "Memory Allocation Vulnerability."
7512| [CVE-2008-0119] Unspecified vulnerability in Microsoft Publisher in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 SP1 and earlier allows remote attackers to execute arbitrary code via a Publisher file with crafted object header data that triggers memory corruption, aka "Publisher Object Handler Validation Vulnerability."
7513| [CVE-2008-0118] Unspecified vulnerability in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, Excel Viewer 2003 up to SP3, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption from an "allocation error," aka "Microsoft Office Memory Corruption Vulnerability."
7514| [CVE-2008-0117] Unspecified vulnerability in Microsoft Excel 2000 SP3 and 2002 SP2, and Office 2004 and 2008 for Mac, allows user-assisted remote attackers to execute arbitrary code via crafted conditional formatting values, aka "Excel Conditional Formatting Vulnerability."
7515| [CVE-2008-0116] Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, Compatibility Pack, and Office 2004 and 2008 for Mac allows user-assisted remote attackers to execute arbitrary code via malformed tags in rich text, aka "Excel Rich Text Validation Vulnerability."
7516| [CVE-2008-0115] Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2007, Viewer 2003, Compatibility Pack, and Office for Mac 2004 allows user-assisted remote attackers to execute arbitrary code via malformed formulas, aka "Excel Formula Parsing Vulnerability."
7517| [CVE-2008-0114] Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office for Mac 2004 allows user-assisted remote attackers to execute arbitrary code via crafted Style records that trigger memory corruption.
7518| [CVE-2008-0113] Unspecified vulnerability in Microsoft Office Excel Viewer 2003 up to SP3 allows user-assisted remote attackers to execute arbitrary code via an Excel document with malformed cell comments that trigger memory corruption from an "allocation error," aka "Microsoft Office Cell Parsing Memory Corruption Vulnerability."
7519| [CVE-2008-0112] Unspecified vulnerability in Microsoft Excel 2000 SP3, and Office for Mac 2004 and 2008 allows user-assisted remote attackers to execute arbitrary code via a crafted .SLK file that is not properly handled when importing the file, aka "Excel File Import Vulnerability."
7520| [CVE-2008-0111] Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2007, Viewer 2003, Compatibility Pack, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted data validation records, aka "Excel Data Validation Record Vulnerability."
7521| [CVE-2008-0110] Unspecified vulnerability in Microsoft Outlook in Office 2000 SP3, XP SP3, 2003 SP2 and Sp3, and Office System allows user-assisted remote attackers to execute arbitrary code via a crafted mailto URI.
7522| [CVE-2008-0109] Word in Microsoft Office 2000 SP3, XP SP3, Office 2003 SP2, and Office Word Viewer 2003 allows remote attackers to execute arbitrary code via crafted fields within the File Information Block (FIB) of a Word file, which triggers length calculation errors and memory corruption.
7523| [CVE-2008-0108] Stack-based buffer overflow in wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted field lengths, aka "Microsoft Works File Converter Field Length Vulnerability."
7524| [CVE-2008-0106] Buffer overflow in Microsoft SQL Server 2005 SP1 and SP2, and 2005 Express Edition SP1 and SP2, allows remote authenticated users to execute arbitrary code via a crafted insert statement.
7525| [CVE-2008-0105] Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section header index table information, aka "Microsoft Works File Converter Index Table Vulnerability."
7526| [CVE-2008-0104] Unspecified vulnerability in Microsoft Office Publisher 2000, 2002, and 2003 SP2 allows remote attackers to execute arbitrary code via a crafted .pub file, aka "Publisher Memory Corruption Vulnerability."
7527| [CVE-2008-0103] Unspecified vulnerability in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Office document that contains a malformed object, related to a "memory handling error," aka "Microsoft Office Execution Jump Vulnerability."
7528| [CVE-2008-0102] Unspecified vulnerability in Microsoft Office Publisher 2000, 2002, and 2003 SP2 allows remote attackers to execute arbitrary code via a crafted .pub file, related to invalid "memory values," aka "Publisher Invalid Memory Reference Vulnerability."
7529| [CVE-2008-0088] Unspecified vulnerability in Active Directory on Microsoft Windows 2000 and Windows Server 2003, and Active Directory Application Mode (ADAM) on XP and Server 2003, allows remote attackers to cause a denial of service (hang and restart) via a crafted LDAP request.
7530| [CVE-2008-0087] The DNS client in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, and Vista uses predictable DNS transaction IDs, which allows remote attackers to spoof DNS responses.
7531| [CVE-2008-0086] Buffer overflow in the convert function in Microsoft SQL Server 2000 SP4, 2000 Desktop Engine (MSDE 2000) SP4, and 2000 Desktop Engine (WMSDE) allows remote authenticated users to execute arbitrary code via a crafted SQL expression.
7532| [CVE-2008-0083] The (1) VBScript (VBScript.dll) and (2) JScript (JScript.dll) scripting engines 5.1 and 5.6, as used in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2, do not properly decode script, which allows remote attackers to execute arbitrary code via unknown vectors.
7533| [CVE-2008-0081] Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted macros, aka "Macro Validation Vulnerability," a different vulnerability than CVE-2007-3490.
7534| [CVE-2008-0080] Heap-based buffer overflow in the WebDAV Mini-Redirector in Microsoft Windows XP SP2, Server 2003 SP1 and SP2, and Vista allows remote attackers to execute arbitrary code via a crafted WebDAV response.
7535| [CVE-2008-0020] Unspecified vulnerability in the Load method in the IPersistStreamInit interface in the Active Template Library (ATL), as used in the Microsoft Video ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via unknown vectors that trigger memory corruption, aka "ATL Header Memcopy Vulnerability," a different vulnerability than CVE-2008-0015.
7536| [CVE-2008-0015] Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted web page, as exploited in the wild in July 2009, aka "Microsoft Video ActiveX Control Vulnerability."
7537| [CVE-2008-0011] Microsoft DirectX 8.1 through 9.0c, and DirectX on Microsoft XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008, does not properly perform MJPEG error checking, which allows remote attackers to execute arbitrary code via a crafted MJPEG stream in a (1) AVI or (2) ASF file, aka the "MJPEG Decoder Vulnerability."
7538| [CVE-2007-6753] Untrusted search path vulnerability in Shell32.dll in Microsoft Windows 2000, Windows XP, Windows Vista, Windows Server 2008, and Windows 7, when using an environment configured with a string such as %APPDATA% or %PROGRAMFILES% in a certain way, allows local users to gain privileges via a Trojan horse DLL under the current working directory, as demonstrated by iTunes and Safari.
7539| [CVE-2007-6357] Stack-based buffer overflow in Microsoft Office Access allows remote, user-assisted attackers to execute arbitrary code via a crafted Microsoft Access Database (.mdb) file. NOTE: due to the lack of details as of 20071210, it is not clear whether this issue is the same as CVE-2007-6026 or CVE-2005-0944.
7540| [CVE-2007-6329] Microsoft Office 2007 12.0.6015.5000 and MSO 12.0.6017.5000 do not sign the metadata of Office Open XML (OOXML) documents, which makes it easier for remote attackers to modify Dublin Core metadata fields, as demonstrated by the (1) LastModifiedBy and (2) creator fields in docProps/core.xml in the OOXML ZIP container.
7541| [CVE-2007-6043] The CryptGenRandom function in Microsoft Windows 2000 generates predictable values, which makes it easier for context-dependent attackers to reduce the effectiveness of cryptographic mechanisms, as demonstrated by attacks on (1) forward security and (2) backward security, related to use of eight instances of the RC4 cipher, and possibly a related issue to CVE-2007-3898.
7542| [CVE-2007-6026] Stack-based buffer overflow in Microsoft msjet40.dll 4.0.8618.0 (aka Microsoft Jet Engine), as used by Access 2003 in Microsoft Office 2003 SP3, allows user-assisted attackers to execute arbitrary code via a crafted MDB file database file containing a column structure with a modified column count. NOTE: this might be the same issue as CVE-2005-0944.
7543| [CVE-2007-5587] Buffer overflow in Macrovision SafeDisc secdrv.sys before 4.3.86.0, as shipped in Microsoft Windows XP SP2, XP Professional x64 and x64 SP2, Server 2003 SP1 and SP2, and Server 2003 x64 and x64 SP2 allows local users to overwrite arbitrary memory locations and gain privileges via a crafted argument to a METHOD_NEITHER IOCTL, as originally discovered in the wild.
7544| [CVE-2007-5352] Unspecified vulnerability in Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows local users to gain privileges via a crafted local procedure call (LPC) request.
7545| [CVE-2007-5348] Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via an image file with crafted gradient sizes in gradient fill input, which triggers a heap-based buffer overflow related to GdiPlus.dll and VGX.DLL, aka "GDI+ VML Buffer Overrun Vulnerability."
7546| [CVE-2007-4991] The SOCKS4 Proxy in Microsoft Internet Security and Acceleration (ISA) Server 2004 SP1 and SP2 allows remote attackers to obtain potentially sensitive information (the destination IP address of another user's session) via an empty packet.
7547| [CVE-2007-4916] Heap-based buffer overflow in the FileFind::FindFile method in (1) MFC42.dll, (2) MFC42u.dll, (3) MFC71.dll, and (4) MFC71u.dll in Microsoft Foundation Class (MFC) Library 8.0, as used by the ListFiles method in hpqutil.dll 2.0.0.138 in Hewlett-Packard (HP) All-in-One and Photo & Imaging Gallery 1.1 and probably other products, allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long first argument.
7548| [CVE-2007-4814] Buffer overflow in the SQLServer ActiveX control in the Distributed Management Objects OLE DLL (sqldmo.dll) 2000.085.2004.00 in Microsoft SQL Server Enterprise Manager 8.05.2004 allows remote attackers to execute arbitrary code via a long second argument to the Start method.
7549| [CVE-2007-3930] Interpretation conflict between Microsoft Internet Explorer and DocuWiki before 2007-06-26b allows remote attackers to inject arbitrary JavaScript and conduct cross-site scripting (XSS) attacks when spellchecking UTF-8 encoded messages via the spell_utf8test function in lib/exe/spellcheck.php, which triggers HTML document identification and script execution by Internet Explorer even though the Content-Type header is text/plain.
7550| [CVE-2007-3924] Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Netscape installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a -chrome argument to the navigatorurl URI, which are inserted into the command line that is created when invoking netscape.exe, a related issue to CVE-2007-3670. NOTE: there has been debate about whether the issue is in Internet Explorer or Netscape. As of 20070713, it is CVE's opinion that IE appears to not properly delimit the URL argument when invoking Netscape
7551| [CVE-2007-3899] Unspecified vulnerability in Microsoft Word 2000 SP3, Word 2002 SP3, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a malformed string in a Word file, aka "Word Memory Corruption Vulnerability."
7552| [CVE-2007-3898] The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS servers, which allows remote attackers to spoof DNS replies, poison the DNS cache, and facilitate further attack vectors.
7553| [CVE-2007-3896] The URL handling in Shell32.dll in the Windows shell in Microsoft Windows XP and Server 2003, with Internet Explorer 7 installed, allows remote attackers to execute arbitrary programs via invalid "%" sequences in a mailto: or other URI handler, as demonstrated using mIRC, Outlook, Firefox, Adobe Reader, Skype, and other applications. NOTE: this issue might be related to other issues involving URL handlers in Windows systems, such as CVE-2007-3845. There also might be separate but closely related issues in the applications that are invoked by the handlers.
7554| [CVE-2007-3890] Microsoft Excel in Office 2000 SP3, Office XP SP3, Office 2003 SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via a Workspace with a certain index value that triggers memory corruption.
7555| [CVE-2007-3670] Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Firefox installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a (1) FirefoxURL or (2) FirefoxHTML URI, which are inserted into the command line that is created when invoking firefox.exe. NOTE: it has been debated as to whether the issue is in Internet Explorer or Firefox. As of 20070711, it is CVE's opinion that IE appears to be failing to properly delimit the URL argument when invoking Firefox, and this issue could arise with other protocol handlers in IE as well. However, Mozilla has stated that it will address the issue with a "defense in depth" fix that will "prevent IE from sending Firefox malicious data."
7556| [CVE-2007-3490] Unspecified vulnerability in Microsoft Excel 2003 SP2 allows remote attackers to have an unknown impact via unspecified vectors, possibly related to the sheet name, as demonstrated by 2670.xls.
7557| [CVE-2007-3300] Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070619 allow remote attackers to bypass scanning via a crafted header in a (1) LHA or (2) RAR archive.
7558| [CVE-2007-3040] Stack-based buffer overflow in agentdpv.dll 2.0.0.3425 in Microsoft Agent on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a crafted URL to the Agent (Agent.Control) ActiveX control, which triggers an overflow within the Agent Service (agentsrv.exe) process, a different issue than CVE-2007-1205.
7559| [CVE-2007-3039] Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Windows 2000 Professional SP4, and Windows XP SP2 allows attackers to execute arbitrary code via a long string in an opnum 0x06 RPC call to port 2103. NOTE: this is remotely exploitable on Windows 2000 Server.
7560| [CVE-2007-3036] Unspecified vulnerability in the (1) Windows Services for UNIX 3.0 and 3.5, and (2) Subsystem for UNIX-based Applications in Microsoft Windows 2000, XP, Server 2003, and Vista allows local users to gain privileges via unspecified vectors related to "certain setuid binary files."
7561| [CVE-2007-3034] Integer overflow in the AttemptWrite function in Graphics Rendering Engine (GDI) on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted metafile (image) with a large record length value, which triggers a heap-based buffer overflow.
7562| [CVE-2007-3030] Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, and 2003 Viewer allows user-assisted remote attackers to execute arbitrary code via a malformed Excel file involving the "denoting [of] the start of a Workspace designation", which results in memory corruption, aka the "Workbook Memory Corruption Vulnerability".
7563| [CVE-2007-3029] Unspecified vulnerability in Microsoft Excel 2002 SP3 and 2003 SP2 allows user-assisted remote attackers to execute arbitrary code via a malformed Excel file containing multiple active worksheets, which results in memory corruption.
7564| [CVE-2007-3028] The LDAP service in Windows Active Directory in Microsoft Windows 2000 Server SP4 does not properly check "the number of convertible attributes", which allows remote attackers to cause a denial of service (service unavailability) via a crafted LDAP request, related to "client sent LDAP request logic," aka "Windows Active Directory Denial of Service Vulnerability". NOTE: this is probably a different issue than CVE-2007-0040.
7565| [CVE-2007-2999] Microsoft Windows Server 2003, when time restrictions are in effect for user accounts, generates different error messages for failed login attempts with a valid user name than for those with an invalid user name, which allows context-dependent attackers to determine valid Active Directory account names.
7566| [CVE-2007-2967] Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070522 allow remote attackers to cause a denial of service (file scanning infinite loop) via certain crafted (1) ARJ archives or (2) FSG packed files.
7567| [CVE-2007-2966] Buffer overflow in the LHA decompresion component in F-Secure anti-virus products for Microsoft Windows and Linux before 20070529 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted LHA archive, related to an integer wrap, a similar issue to CVE-2006-4335.
7568| [CVE-2007-2903] Buffer overflow in the HelpPopup method in the Microsoft Office 2000 Controllo UA di Microsoft Office ActiveX control (OUACTRL.OCX) 1.0.1.9 allows remote attackers to cause a denial of service (probably winhlp32.exe crash) via a long first argument. NOTE: it is not clear whether this issue crosses privilege boundaries.
7569| [CVE-2007-2593] The Terminal Server in Microsoft Windows 2003 Server, when using TLS, allows remote attackers to bypass SSL and self-signed certificate requirements, downgrade the server security, and possibly conduct man-in-the-middle attacks via unspecified vectors, as demonstrated using the Remote Desktop Protocol (RDP) 6.0 client. NOTE: a third party claims that the vendor may have fixed this in approximately 2006.
7570| [CVE-2007-2581] Multiple cross-site scripting (XSS) vulnerabilities in Microsoft Windows SharePoint Services 3.0 for Windows Server 2003 and Office SharePoint Server 2007 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (query string) in "every main page," as demonstrated by default.aspx.
7571| [CVE-2007-2374] Unspecified vulnerability in Microsoft Windows 2000, XP, and Server 2003 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors. NOTE: this information is based upon a vague pre-advisory with no actionable information. However, the advisory is from a reliable source.
7572| [CVE-2007-2228] rpcrt4.dll (aka the RPC runtime library) in Microsoft Windows XP SP2, XP Professional x64 Edition, Server 2003 SP1 and SP2, Server 2003 x64 Edition and x64 Edition SP2, and Vista and Vista x64 Edition allows remote attackers to cause a denial of service (RPCSS service stop and system restart) via an RPC request that uses NTLMSSP PACKET authentication with a zero-valued verification trailer signature, which triggers an invalid dereference. NOTE: this also affects Windows 2000 SP4, although the impact is an information leak.
7573| [CVE-2007-2224] Object linking and embedding (OLE) Automation, as used in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Office 2004 for Mac, and Visual Basic 6.0 allows remote attackers to execute arbitrary code via the substringData method on a TextNode object, which causes an integer overflow that leads to a buffer overflow.
7574| [CVE-2007-2221] Unspecified vulnerability in the mdsauth.dll COM object in Microsoft Windows Media Server in the Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4
7575| [CVE-2007-2219] Unspecified vulnerability in the Win32 API on Microsoft Windows 2000, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via certain parameters to an unspecified function.
7576| [CVE-2007-2218] Unspecified vulnerability in the Windows Schannel Security Package for Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2, allows remote servers to execute arbitrary code or cause a denial of service via crafted digital signatures that are processed during an SSL handshake.
7577| [CVE-2007-2217] Kodak Image Viewer in Microsoft Windows 2000 SP4, and in some cases XP SP2 and Server 2003 SP1 and SP2, allows remote attackers to execute arbitrary code via crafted image files that trigger memory corruption, as demonstrated by a certain .tif (TIFF) file.
7578| [CVE-2007-1911] Multiple unspecified vulnerabilities in Microsoft Word 2007 allow remote attackers to cause a denial of service (CPU consumption) via crafted documents, as demonstrated by (1) file798-1.doc and (2) file613-1.doc, possibly related to a buffer overflow.
7579| [CVE-2007-1910] Buffer overflow in wwlib.dll in Microsoft Word 2007 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted document, as demonstrated by file789-1.doc.
7580| [CVE-2007-1765] Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malformed ANI file, which results in memory corruption when processing cursors, animated cursors, and icons, a similar issue to CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this issue might be a duplicate of CVE-2007-0038
7581| [CVE-2007-1756] Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, and Office Excel 2007 does not properly validate version information, which allows user-assisted remote attackers to execute arbitrary code via a crafted Excel file, aka "Calculation Error Vulnerability".
7582| [CVE-2007-1754] PUBCONV.DLL in Microsoft Office Publisher 2007 does not properly clear memory when transferring data from disk to memory, which allows user-assisted remote attackers to execute arbitrary code via a malformed .pub page via a certain negative value, which bypasses a sanitization procedure that initializes critical pointers to NULL, aka the "Publisher Invalid Memory Reference Vulnerability".
7583| [CVE-2007-1748] Stack-based buffer overflow in the RPC interface in the Domain Name System (DNS) Server Service in Microsoft Windows 2000 Server SP 4, Server 2003 SP 1, and Server 2003 SP 2 allows remote attackers to execute arbitrary code via a long zone name containing character constants represented by escape sequences.
7584| [CVE-2007-1747] Unspecified vulnerability in MSO.dll in Microsoft Office 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and 2007 allows user-assisted remote attackers to execute arbitrary code via a malformed drawing object, which triggers memory corruption.
7585| [CVE-2007-1645] Buffer overflow in FutureSoft TFTP Server 2000 on Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrary code via a long request on UDP port 69. NOTE: this issue might overlap CVE-2006-4781 or CVE-2005-1812.
7586| [CVE-2007-1537] \Device\NdisTapi (NDISTAPI.sys) in Microsoft Windows XP SP2 and 2003 SP1 uses weak permissions, which allows local users to write to the device and cause a denial of service, as demonstrated by using an IRQL to acquire a spinlock on paged memory via the NdisTapiDispatch function.
7587| [CVE-2007-1512] Stack-based buffer overflow in the AfxOleSetEditMenu function in the MFC component in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 Gold and SP1, and Visual Studio .NET 2002 Gold and SP1, and 2003 Gold and SP1 allows user-assisted remote attackers to have an unknown impact (probably crash) via an RTF file with a malformed OLE object, which results in writing two 0x00 characters past the end of szBuffer, aka the "MFC42u.dll Off-by-Two Overflow." NOTE: this issue is due to an incomplete patch (MS07-012) for CVE-2007-0025.
7588| [CVE-2007-1347] Microsoft Windows Explorer on Windows 2000 SP4 FR and XP SP2 FR, and possibly other versions and platforms, allows remote attackers to cause a denial of service (memory corruption and crash) via an Office file with crafted document summary information, which causes an error in Ole32.dll.
7589| [CVE-2007-1239] Microsoft Excel 2003 does not properly parse .XLS files, which allows remote attackers to cause a denial of service (application crash) via a file with a (1) corrupted XML format or a (2) corrupted XLS format, which triggers a NULL pointer dereference.
7590| [CVE-2007-1238] Microsoft Office 2003 allows user-assisted remote attackers to cause a denial of service (application crash) by attempting to insert a corrupted WMF file.
7591| [CVE-2007-1215] Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4
7592| [CVE-2007-1214] Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, and 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a crafted AutoFilter filter record in an Excel BIFF8 format XLS file, which triggers memory corruption.
7593| [CVE-2007-1213] The TrueType Fonts rasterizer in Microsoft Windows 2000 SP4 allows local users to gain privileges via crafted TrueType fonts, which result in an uninitialized function pointer.
7594| [CVE-2007-1212] Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4
7595| [CVE-2007-1211] Unspecified kernel GDI functions in Microsoft Windows 2000 SP4
7596| [CVE-2007-1205] Unspecified vulnerability in Microsoft Agent (msagent\agentsvr.exe) in Windows 2000 SP4, XP SP2, and Server 2003, 2003 SP1, and 2003 SP2 allows remote attackers to execute arbitrary code via crafted URLs, which result in memory corruption.
7597| [CVE-2007-1203] Unspecified vulnerability in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, 2004 for Mac, and 2007 allows user-assisted remote attackers to execute arbitrary code via a crafted set font value in an Excel file, which results in memory corruption.
7598| [CVE-2007-1202] Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006 does not properly parse certain rich text "property strings of certain control words," which allows user-assisted remote attackers to trigger heap corruption and execute arbitrary code, aka the "Word RTF Parsing Vulnerability."
7599| [CVE-2007-1201] Unspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user-assisted remote attackers to execute arbitrary code via vectors related to DataSource that trigger memory corruption, aka "Office Web Components DataSource Vulnerability."
7600| [CVE-2007-1117] Unspecified vulnerability in Publisher 2007 in Microsoft Office 2007 allows remote attackers to execute arbitrary code via unspecified vectors, related to a "file format vulnerability." NOTE: this information is based upon a vague pre-advisory with no actionable information. However, the advisory is from a reliable source.
7601| [CVE-2007-1090] Microsoft Windows Explorer on Windows XP and 2003 allows remote user-assisted attackers to cause a denial of service (crash) via a malformed WMF file, which triggers the crash when the user browses the folder.
7602| [CVE-2007-1083] Buffer overflow in the Configuration Checker (ConfigChk) ActiveX control in VSCnfChk.dll 2.0.0.2 for Verisign Managed PKI Service, Secure Messaging for Microsoft Exchange, and Go Secure! allows remote attackers to execute arbitrary code via long arguments to the VerCompare method.
7603| [CVE-2007-0948] Heap-based buffer overflow in Microsoft Virtual PC 2004 and PC for Mac 7.1 and 7, and Virtual Server 2005 and 2005 R2, allows local guest OS administrators to execute arbitrary code on the host OS via unspecified vectors related to "interaction and initialization of components."
7604| [CVE-2007-0947] Use-after-free vulnerability in Microsoft Internet Explorer 7 on Windows XP SP2, Windows Server 2003 SP1 or SP2, or Windows Vista allows remote attackers to execute arbitrary code via crafted HTML objects, resulting in accessing deallocated memory of CMarkup objects, aka the second of two "HTML Objects Memory Corruption Vulnerabilities" and a different issue than CVE-2007-0946.
7605| [CVE-2007-0946] Unspecified vulnerability in Microsoft Internet Explorer 7 on Windows XP SP2, Windows Server 2003 SP1 or SP2, or Windows Vista allows remote attackers to execute arbitrary code via crafted HTML objects, which results in memory corruption, aka the first of two "HTML Objects Memory Corruption Vulnerabilities" and a different issue than CVE-2007-0947.
7606| [CVE-2007-0945] Microsoft Internet Explorer 6 SP1 on Windows 2000 SP4
7607| [CVE-2007-0944] Unspecified vulnerability in the CTableCol::OnPropertyChange method in Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4
7608| [CVE-2007-0942] Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4
7609| [CVE-2007-0940] Unspecified vulnerability in the Cryptographic API Component Object Model Certificates ActiveX control (CAPICOM.dll) in Microsoft CAPICOM and BizTalk Server 2004 SP1 and SP2 allows remote attackers to execute arbitrary code via unspecified vectors, aka the "CAPICOM.Certificates Vulnerability."
7610| [CVE-2007-0939] Cross-site scripting (XSS) vulnerability in Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving HTML redirection queries, aka "Cross-site Scripting and Spoofing Vulnerability."
7611| [CVE-2007-0938] Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 does not properly handle certain characters in a crafted HTTP GET request, which allows remote attackers to execute arbitrary code, aka the "CMS Memory Corruption Vulnerability."
7612| [CVE-2007-0936] Multiple unspecified vulnerabilities in Microsoft Visio 2002 allow remote user-assisted attackers to execute arbitrary code via a Visio (.VSD, VSS, .VST) file with a crafted packed object that triggers memory corruption, aka "Visio Document Packaging Vulnerability."
7613| [CVE-2007-0934] Unspecified vulnerability in Microsoft Visio 2002 allows remote user-assisted attackers to execute arbitrary code via a Visio (.VSD, VSS, .VST) file with a crafted version number that triggers memory corruption.
7614| [CVE-2007-0913] Unspecified vulnerability in Microsoft Powerpoint allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as exploited by Trojan.PPDropper.G. NOTE: as of 20070213, it is not clear whether this is the same issue as CVE-2006-5296, CVE-2006-4694, CVE-2006-3876, CVE-2006-3877, or older issues.
7615| [CVE-2007-0870] Unspecified vulnerability in Microsoft Word 2000 allows remote attackers to cause a denial of service (crash) via unknown vectors, a different vulnerability than CVE-2006-5994, CVE-2006-6456, CVE-2006-6561, and CVE-2007-0515, a variant of Exploit-MS06-027.
7616| [CVE-2007-0843] The ReadDirectoryChangesW API function on Microsoft Windows 2000, XP, Server 2003, and Vista does not check permissions for child objects, which allows local users to bypass permissions by opening a directory with LIST (READ) access and using ReadDirectoryChangesW to monitor changes of files that do not have LIST permissions, which can be leveraged to determine filenames, access times, and other sensitive information.
7617| [CVE-2007-0811] Microsoft Internet Explorer 6.0 SP1 on Windows 2000, and 6.0 SP2 on Windows XP, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an HTML document containing a certain JavaScript for loop with an empty loop body, possibly involving getElementById.
7618| [CVE-2007-0671] Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.
7619| [CVE-2007-0612] Multiple ActiveX controls in Microsoft Windows 2000, XP, 2003, and Vista allows remote attackers to cause a denial of service (Internet Explorer crash) by accessing the bgColor, fgColor, linkColor, alinkColor, vlinkColor, or defaultCharset properties in the (1) giffile, (2) htmlfile, (3) jpegfile, (4) mhtmlfile, (5) ODCfile, (6) pjpegfile, (7) pngfile, (8) xbmfile, (9) xmlfile, (10) xslfile, or (11) wdfile objects in (a) mshtml.dll
7620| [CVE-2007-0515] Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of service on Word 2003, via unknown attack vectors that trigger memory corruption, as exploited by Trojan.Mdropper.W and later by Trojan.Mdropper.X, a different issue than CVE-2006-6456, CVE-2006-5994, and CVE-2006-6561.
7621| [CVE-2007-0351] Microsoft Windows XP and Windows Server 2003 do not properly handle user logoff, which might allow local users to gain the privileges of a previous system user, possibly related to user profile unload failure. NOTE: it is not clear whether this is an issue in Windows itself, or an interaction with another product. The issue might involve ZoneAlarm not being able to terminate processes when it cannot prompt the user.
7622| [CVE-2007-0221] Integer overflow in the IMAP (IMAP4) support in Microsoft Exchange Server 2000 SP3 allows remote attackers to cause a denial of service (service hang) via crafted literals in an IMAP command, aka the "IMAP Literal Processing Vulnerability."
7623| [CVE-2007-0220] Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2000 SP3, and 2003 SP1 and SP2 allows remote attackers to execute arbitrary scripts, spoof content, or obtain sensitive information via certain UTF-encoded, script-based e-mail attachments, involving an "incorrectly handled UTF character set label".
7624| [CVE-2007-0216] wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section length headers, aka "Microsoft Works File Converter Input Validation Vulnerability."
7625| [CVE-2007-0215] Stack-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, and 2003 Viewer allows user-assisted remote attackers to execute arbitrary code via a .XLS BIFF file with a malformed Named Graph record, which results in memory corruption.
7626| [CVE-2007-0214] The HTML Help ActiveX control (Hhctrl.ocx) in Microsoft Windows 2000 SP3, XP SP2 and Professional, 2003 SP1 allows remote attackers to execute arbitrary code via unspecified functions, related to uninitialized parameters.
7627| [CVE-2007-0213] Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 does not properly decode certain MIME encoded e-mails, which allows remote attackers to execute arbitrary code via a crafted base64-encoded MIME e-mail message.
7628| [CVE-2007-0211] The hardware detection functionality in the Windows Shell in Microsoft Windows XP SP2 and Professional, and Server 2003 SP1 allows local users to gain privileges via an unvalidated parameter to a function related to the "detection and registration of new hardware."
7629| [CVE-2007-0209] Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a Word file with a malformed drawing object, which leads to memory corruption.
7630| [CVE-2007-0208] Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac does not correctly check the properties of certain documents and warn the user of macro content, which allows user-assisted remote attackers to execute arbitrary code.
7631| [CVE-2007-0069] Unspecified vulnerability in the kernel in Microsoft Windows XP SP2, Server 2003, and Vista allows remote attackers to cause a denial of service (CPU consumption) and possibly execute arbitrary code via crafted (1) IGMPv3 and (2) MLDv2 packets that trigger memory corruption, aka "Windows Kernel TCP/IP/IGMPv3 and MLDv2 Vulnerability."
7632| [CVE-2007-0066] The kernel in Microsoft Windows 2000 SP4, XP SP2, and Server 2003, when ICMP Router Discovery Protocol (RDP) is enabled, allows remote attackers to cause a denial of service via fragmented router advertisement ICMP packets that trigger an out-of-bounds read, aka "Windows Kernel TCP/IP/ICMP Vulnerability."
7633| [CVE-2007-0065] Heap-based buffer overflow in Object Linking and Embedding (OLE) Automation in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, Office 2004 for Mac, and Visual basic 6.0 SP6 allows remote attackers to execute arbitrary code via a crafted script request.
7634| [CVE-2007-0064] Heap-based buffer overflow in Windows Media Format Runtime 7.1, 9, 9.5, 9.5 x64 Edition, 11, and Windows Media Services 9.1 for Microsoft Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via a crafted Advanced Systems Format (ASF) file.
7635| [CVE-2007-0043] The Just In Time (JIT) Compiler service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer," probably a buffer overflow, aka ".NET JIT Compiler Vulnerability".
7636| [CVE-2007-0042] Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to access configuration files and obtain sensitive information, and possibly bypass security mechanisms that try to constrain the final substring of a string, via %00 characters, related to use of %00 as a string terminator within POSIX functions but a data character within .NET strings, aka "Null Byte Termination Vulnerability."
7637| [CVE-2007-0041] The PE Loader service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer" and unvalidated message lengths, probably a buffer overflow.
7638| [CVE-2007-0040] The LDAP service in Windows Active Directory in Microsoft Windows 2000 Server SP4, Server 2003 SP1 and SP2, Server 2003 x64 Edition and SP2, and Server 2003 for Itanium-based Systems SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted LDAP request with an unspecified number of "convertible attributes."
7639| [CVE-2007-0039] The Exchange Collaboration Data Objects (EXCDO) functionality in Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 allows remote attackers to cause a denial of service (crash) via an Internet Calendar (iCal) file containing multiple X-MICROSOFT-CDO-MODPROPS (MODPROPS) properties in which the second MODPROPS is longer than the first, which triggers a NULL pointer dereference and an unhandled exception.
7640| [CVE-2007-0038] Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a large length value in the second (or later) anih block of a RIFF .ANI, cur, or .ico file, which results in memory corruption when processing cursors, animated cursors, and icons, a variant of CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this might be a duplicate of CVE-2007-1765
7641| [CVE-2007-0035] Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006 does not properly handle data in a certain array, which allows user-assisted remote attackers to execute arbitrary code, aka the "Word Array Overflow Vulnerability."
7642| [CVE-2007-0034] Buffer overflow in the Advanced Search (Finder.exe) feature of Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted Outlook Saved Searches (OSS) file that triggers memory corruption, aka "Microsoft Outlook Advanced Find Vulnerability."
7643| [CVE-2007-0033] Microsoft Outlook 2002 and 2003 allows user-assisted remote attackers to execute arbitrary code via a malformed VEVENT record in an .iCal meeting request or ICS file.
7644| [CVE-2007-0031] Heap-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via a BIFF8 spreadsheet with a PALETTE record that contains a large number of entries.
7645| [CVE-2007-0030] Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via an Excel file with an out-of-range Column field in certain BIFF8 record types, which references arbitrary memory.
7646| [CVE-2007-0029] Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via a malformed string, aka "Excel Malformed String Vulnerability."
7647| [CVE-2007-0028] Microsoft Excel 2000, 2002, 2003, Viewer 2003, Office 2004 for Mac, and Office v.X for Mac does not properly handle certain opcodes, which allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file, which results in an "Improper Memory Access Vulnerability." NOTE: an early disclosure of this issue used CVE-2006-3432, but only CVE-2007-0028 should be used.
7648| [CVE-2007-0027] Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via malformed IMDATA records that trigger memory corruption.
7649| [CVE-2007-0026] The OLE Dialog component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption.
7650| [CVE-2007-0025] The MFC component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 and Visual Studio .NET 2000, 2002 SP1, 2003, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption. NOTE: this might be due to a stack-based buffer overflow in the AfxOleSetEditMenu function in MFC42u.dll.
7651| [CVE-2007-0024] Integer overflow in the Vector Markup Language (VML) implementation (vgx.dll) in Microsoft Internet Explorer 5.01, 6, and 7 on Windows 2000 SP4, XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted web page that contains unspecified integer properties that cause insufficient memory allocation and trigger a buffer overflow, aka the "VML Buffer Overrun Vulnerability."
7652| [CVE-2006-7210] Microsoft Windows 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (cpu consumption) via a PNG image with crafted (1) Width and (2) Height values in the IHDR block.
7653| [CVE-2006-7192] Microsoft ASP .NET Framework 2.0.50727.42 does not properly handle comment (/* */) enclosures, which allows remote attackers to bypass request filtering and conduct cross-site scripting (XSS) attacks, or cause a denial of service, as demonstrated via an xss:expression STYLE attribute in a closing XSS HTML tag.
7654| [CVE-2006-7027] Microsoft Internet Security and Acceleration (ISA) Server 2004 logs unusual ASCII characters in the Host header, including the tab, which allows remote attackers to manipulate portions of the log file and possibly leverage this for other attacks.
7655| [CVE-2006-6723] The Workstation service in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to cause a denial of service (memory consumption) via a large maxlen value in an NetrWkstaUserEnum RPC request.
7656| [CVE-2006-6696] Double free vulnerability in Microsoft Windows 2000, XP, 2003, and Vista allows local users to gain privileges by calling the MessageBox function with a MB_SERVICE_NOTIFICATION message with crafted data, which sends a HardError message to Client/Server Runtime Server Subsystem (CSRSS) process, which is not properly handled when invoking the UserHardError and GetHardErrorText functions in WINSRV.DLL.
7657| [CVE-2006-6617] projectserver/logon/pdsrequest.asp in Microsoft Project Server 2003 allows remote authenticated users to obtain the MSProjectUser password for a SQL database via a GetInitializationData request, which includes the information in the UserName and Password tags of the response.
7658| [CVE-2006-6561] Unspecified vulnerability in Microsoft Word 2000, 2002, and Word Viewer 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted DOC file that triggers memory corruption, as demonstrated via the 12122006-djtest.doc file, a different issue than CVE-2006-5994 and CVE-2006-6456.
7659| [CVE-2006-6456] Unspecified vulnerability in Microsoft Word 2000, 2002, and 2003 and Word Viewer 2003 allows remote attackers to execute code via unspecified vectors related to malformed data structures that trigger memory corruption, a different vulnerability than CVE-2006-5994.
7660| [CVE-2006-6296] The RpcGetPrinterData function in the Print Spooler (spoolsv.exe) service in Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 and earlier, allows remote attackers to cause a denial of service (memory consumption) via an RPC request that specifies a large 'offered' value (output buffer size), a variant of CVE-2005-3644.
7661| [CVE-2006-6134] Heap-based buffer overflow in the WMCheckURLScheme function in WMVCORE.DLL in Microsoft Windows Media Player (WMP) 10.00.00.4036 on Windows XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via a long HREF attribute, using an unrecognized protocol, in a REF element in an ASX PlayList file.
7662| [CVE-2006-6133] Stack-based buffer overflow in Visual Studio Crystal Reports for Microsoft Visual Studio .NET 2002 and 2002 SP1, .NET 2003 and 2003 SP1, and 2005 and 2005 SP1 (formerly Business Objects Crystal Reports XI Professional) allows user-assisted remote attackers to execute arbitrary code via a crafted RPT file.
7663| [CVE-2006-5994] Unspecified vulnerability in Microsoft Word 2000 and 2002, Office Word and Word Viewer 2003, Word 2004 and 2004 v. X for Mac, and Works 2004, 2005, and 2006 allows remote attackers to execute arbitrary code via a Word document with a malformed string that triggers memory corruption, a different vulnerability than CVE-2006-6456.
7664| [CVE-2006-5758] The Graphics Rendering Engine in Microsoft Windows 2000 through 2000 SP4 and Windows XP through SP2 maps GDI Kernel structures on a global shared memory section that is mapped with read-only permissions, but can be remapped by other processes as read-write, which allows local users to cause a denial of service (memory corruption and crash) and gain privileges by modifying the kernel structures.
7665| [CVE-2006-5586] The Graphics Rendering Engine in Microsoft Windows 2000 SP4 and XP SP2 allows local users to gain privileges via "invalid application window sizes" in layered application windows, aka the "GDI Invalid Window Size Elevation of Privilege Vulnerability."
7666| [CVE-2006-5585] The Client-Server Run-time Subsystem in Microsoft Windows XP SP2 and Server 2003 allows local users to gain privileges via a crafted file manifest within an application, aka "File Manifest Corruption Vulnerability."
7667| [CVE-2006-5584] The Remote Installation Service (RIS) in Microsoft Windows 2000 SP4 uses a TFTP server that allows anonymous access, which allows remote attackers to upload and overwrite arbitrary files to gain privileges on systems that use RIS.
7668| [CVE-2006-5583] Buffer overflow in the SNMP Service in Microsoft Windows 2000 SP4, XP SP2, Server 2003, Server 2003 SP1, and possibly other versions allows remote attackers to execute arbitrary code via a crafted SNMP packet, aka "SNMP Memory Corruption Vulnerability."
7669| [CVE-2006-5574] Unspecified vulnerability in the Brazilian Portuguese Grammar Checker in Microsoft Office 2003 and the Multilingual Interface for Office 2003, Project 2003, and Visio 2003 allows user-assisted remote attackers to execute arbitrary code via crafted text that is not properly parsed.
7670| [CVE-2006-5296] PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record length, which allows user-assisted attackers to cause a denial of service (NULL dereference and application crash) via a crafted PowerPoint (.PPT) file, as demonstrated by Nanika.ppt, and a different vulnerability than CVE-2006-3435, CVE-2006-3876, CVE-2006-3877, and CVE-2006-4694. NOTE: the impact of this issue was originally claimed to be arbitrary code execution, but later analysis demonstrated that this was erroneous.
7671| [CVE-2006-4854] ** REJECT ** Unspecified vulnerability in Microsoft Office 2000 (Chinese Edition) and Microsoft PowerPoint 2000 (Chinese Edition) allows user-assisted attackers to execute arbitrary code via a crafted PPT document, as exploited by malware such as Trojan.PPDropper.E. NOTE: on 20060919, Microsoft notified CVE that this is a duplicate of CVE-2006-0009.
7672| [CVE-2006-4704] Cross-zone scripting vulnerability in the WMI Object Broker (WMIScriptUtils.WMIObjectBroker2) ActiveX control (WmiScriptUtils.dll) in Microsoft Visual Studio 2005 allows remote attackers to bypass Internet zone restrictions and execute arbitrary code by instantiating dangerous objects, aka "WMI Object Broker Vulnerability."
7673| [CVE-2006-4702] Buffer overflow in the Windows Media Format Runtime in Microsoft Windows Media Player (WMP) 6.4 and Windows XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted Advanced Systems Format (ASF) file.
7674| [CVE-2006-4696] Unspecified vulnerability in the Server service in Microsoft Windows 2000 SP4, Server 2003 SP1 and earlier, and XP SP2 and earlier allows remote attackers to execute arbitrary code via a crafted packet, aka "SMB Rename Vulnerability."
7675| [CVE-2006-4695] Unspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user-assisted remote attackers to execute arbitrary code via a crafted URL, aka "Office Web Components URL Parsing Vulnerability."
7676| [CVE-2006-4694] Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office XP and Office 2003 allows user-assisted attackers to execute arbitrary code via a crafted record in a PPT file, as exploited by malware such as Exploit:Win32/Controlppt.W, Exploit:Win32/Controlppt.X, and Exploit-PPT.d/Trojan.PPDropper.F. NOTE: it has been reported that the attack vector involves SlideShowWindows.View.GotoNamedShow.
7677| [CVE-2006-4693] Unspecified vulnerability in Microsoft Word 2004 for Mac and v.X for Mac allows remote user-assisted attackers to execute arbitrary code via a crafted string in a Word file, a different issue than CVE-2006-3647 and CVE-2006-3651.
7678| [CVE-2006-4692] Argument injection vulnerability in the Windows Object Packager (packager.exe) in Microsoft Windows XP SP1 and SP2 and Server 2003 SP1 and earlier allows remote user-assisted attackers to execute arbitrary commands via a crafted file with a "/" (slash) character in the filename of the Command Line property, followed by a valid file extension, which causes the command before the slash to be executed, aka "Object Packager Dialogue Spoofing Vulnerability."
7679| [CVE-2006-4691] Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to execute arbitrary code via NetrJoinDomain2 RPC messages with a long hostname.
7680| [CVE-2006-4689] Unspecified vulnerability in the driver for the Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to cause a denial of service (hang and reboot) via has unknown attack vectors, aka "NetWare Driver Denial of Service Vulnerability."
7681| [CVE-2006-4688] Buffer overflow in Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via crafted messages, aka "Client Service for NetWare Memory Corruption Vulnerability."
7682| [CVE-2006-4534] Unspecified vulnerability in Microsoft Word 2000, 2002, and Office 2003 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors involving a crafted file resulting in a malformed stack, as exploited by malware with names including Trojan.Mdropper.Q, Mofei, and Femo.
7683| [CVE-2006-4495] Microsoft Internet Explorer allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Windows 2000 ActiveX COM Objects including (1) ciodm.dll, (2) myinfo.dll, (3) msdxm.ocx, and (4) creator.dll.
7684| [CVE-2006-4274] ** REJECT ** Unknown vulnerability in Microsoft PowerPoint allows user-assisted attackers to execute arbitrary code via a crafted PPT document, as exploited by malware such as TROJ_MDROPPER.BH. NOTE: on 20060822, it was determined that TROJ_MDROPPER.BH was exploiting CVE-2006-0009, so this is not a new vulnerability.
7685| [CVE-2006-4219] The Terminal Services COM object (tsuserex.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by instantiating it as an ActiveX object in Internet Explorer 6.0 SP1 on Microsoft Windows 2003 EE SP1 CN.
7686| [CVE-2006-4183] Heap-based buffer overflow in Microsoft DirectX SDK (February 2006) and probably earlier, including 9.0c End User Runtimes, allows context-dependent attackers to execute arbitrary code via a crafted Targa file with a run-length-encoding (RLE) compression that produces more data than expected when decoding.
7687| [CVE-2006-4071] Sign extension vulnerability in the createBrushIndirect function in the GDI library (gdi32.dll) in Microsoft Windows XP, Server 2003, and possibly other versions, allows user-assisted attackers to cause a denial of service (application crash) via a crafted WMF file.
7688| [CVE-2006-3992] Unspecified vulnerability in the Centrino (1) w22n50.sys, (2) w22n51.sys, (3) w29n50.sys, and (4) w29n51.sys Microsoft Windows drivers for Intel 2200BG and 2915ABG PRO/Wireless Network Connection before 10.5 with driver 9.0.4.16 allows remote attackers to execute arbitrary code via certain frames that trigger memory corruption.
7689| [CVE-2006-3942] The server driver (srv.sys) in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (system crash) via an SMB_COM_TRANSACTION SMB message that contains a string without null character termination, which leads to a NULL dereference in the ExecuteTransaction function, possibly related to an "SMB PIPE," aka the "Mailslot DOS" vulnerability. NOTE: the name "Mailslot DOS" was derived from incomplete initial research
7690| [CVE-2006-3897] Stack overflow in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a denial of service (application crash) by creating an NMSA.ASFSourceMediaDescription.1 ActiveX object with a long dispValue property.
7691| [CVE-2006-3880] ** DISPUTED ** Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Small Business Server 2003 allow remote attackers to cause a denial of service (IP stack hang) via a continuous stream of packets on TCP port 135 that have incorrect TCP header checksums and random numbers in certain TCP header fields, as demonstrated by the Achilles Windows Attack Tool. NOTE: the researcher reports that the Microsoft Security Response Center has stated "Our investigation which has included code review, review of the TCPDump, and attempts on reproing the issue on multiple fresh installs of various Windows Operating Systems have all resulted in non confirmation."
7692| [CVE-2006-3877] Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via an unspecified "crafted file," a different vulnerability than CVE-2006-3435, CVE-2006-4694, and CVE-2006-3876.
7693| [CVE-2006-3876] Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via a crafted Data record in a PPT file, a different vulnerability than CVE-2006-3435 and CVE-2006-4694.
7694| [CVE-2006-3875] Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, and Excel Viewer 2003 allows user-assisted attackers to execute arbitrary code via a crafted COLINFO record in an XLS file, a different vulnerability than CVE-2006-2387 and CVE-2006-3867.
7695| [CVE-2006-3873] Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP SP1, with versions the MS06-042 patch before 20060912, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL in a GZIP-encoded website that was the target of an HTTP redirect, due to an incomplete fix for CVE-2006-3869.
7696| [CVE-2006-3869] Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP SP1, with versions the MS06-042 patch before 20060824, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL on a website that uses HTTP 1.1 compression.
7697| [CVE-2006-3868] Unspecified vulnerability in Microsoft Office XP and 2003 allows remote user-assisted attackers to execute arbitrary code via a malformed Smart Tag.
7698| [CVE-2006-3867] Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, and Excel Viewer 2003 allows user-assisted attackers to execute arbitrary code via a crafted Lotus 1-2-3 file, a different vulnerability than CVE-2006-2387 and CVE-2006-3875.
7699| [CVE-2006-3864] Unspecified vulnerability in mso.dll in Microsoft Office 2000, XP, and 2003, and Microsoft PowerPoint 2000, XP, and 2003, allows remote user-assisted attackers to execute arbitrary code via a malformed record in a (1) .DOC, (2) .PPT, or (3) .XLS file that triggers memory corruption, related to an "array boundary condition" (possibly an array index overflow), a different vulnerability than CVE-2006-3434, CVE-2006-3650, and CVE-2006-3868.
7700| [CVE-2006-3841] Cross-site scripting (XSS) vulnerability in WebScarab before 20060718-1904, when used with Microsoft Internet Explorer 6 SP2 or Konqueror 3.5.3, allows remote attackers to inject arbitrary web script or HTML via the URL, which is not sanitized before being returned in an error message when WebScarab is not able to access the URL.
7701| [CVE-2006-3660] Unspecified vulnerability in Microsoft PowerPoint 2003 has unknown impact and user-assisted attack vectors related to powerpnt.exe. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3655, CVE-2006-3656, and CVE-2006-3590, although it is possible that they are all different.
7702| [CVE-2006-3656] Unspecified vulnerability in Microsoft PowerPoint 2003 allows user-assisted attackers to cause memory corruption via a crafted PowerPoint file, which triggers the corruption when the file is closed. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3655, CVE-2006-3660, and CVE-2006-3590, although it is possible that they are all different.
7703| [CVE-2006-3655] Unspecified vulnerability in mso.dll in Microsoft PowerPoint 2003 allows user-assisted attackers to execute arbitrary code via a crafted PowerPoint file. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3656, CVE-2006-3660, and CVE-2006-3590, although it is possible that they are all different.
7704| [CVE-2006-3652] Microsoft Internet Security and Acceleration (ISA) Server 2004 allows remote attackers to bypass file extension filters via a request with a trailing "#" character. NOTE: as of 20060715, this could not be reproduced by third parties.
7705| [CVE-2006-3651] Unspecified vulnerability in Microsoft Word 2000, 2002, and Office 2003 allows remote user-assisted attackers to execute arbitrary code via a crafted mail merge file, a different vulnerability than CVE-2006-3647 and CVE-2006-4693.
7706| [CVE-2006-3650] Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac do not properly parse the length of a chart record, which allows remote user-assisted attackers to execute arbitrary code via a Word document with an embedded malformed chart record that triggers an overwrite of pointer values with values from the document, a different vulnerability than CVE-2006-3434, CVE-2006-3864, and CVE-2006-3868.
7707| [CVE-2006-3649] Buffer overflow in Microsoft Visual Basic for Applications (VBA) SDK 6.0 through 6.4, as used by Microsoft Office 2000 SP3, Office XP SP3, Project 2000 SR1, Project 2002 SP1, Access 2000 Runtime SP3, Visio 2002 SP2, and Works Suite 2004 through 2006, allows user-assisted attackers to execute arbitrary code via unspecified document properties that are not verified when VBA is invoked to open documents.
7708| [CVE-2006-3648] Unspecified vulnerability in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 and 2003 SP1, allows remote attackers to execute arbitrary code via unspecified vectors involving unhandled exceptions, memory resident applications, and incorrectly "unloading chained exception."
7709| [CVE-2006-3647] Integer overflow in Microsoft Word 2000, 2002, 2003, 2004 for Mac, and v.X for Mac allows remote user-assisted attackers to execute arbitrary code via a crafted string in a Word document, which overflows a 16-bit integer length value, aka "Memmove Code Execution," a different vulnerability than CVE-2006-3651 and CVE-2006-4693.
7710| [CVE-2006-3643] Cross-site scripting (XSS) vulnerability in Internet Explorer 5.01 and 6 in Microsoft Windows 2000 SP4 permits access to local "HTML-embedded resource files" in the Microsoft Management Console (MMC) library, which allows remote authenticated users to execute arbitrary commands, aka "MMC Redirect Cross-Site Scripting Vulnerability."
7711| [CVE-2006-3590] mso.dll, as used by Microsoft PowerPoint 2000 through 2003, allows user-assisted attackers to execute arbitrary commands via a malformed shape container in a PPT file that leads to memory corruption, as exploited by Trojan.PPDropper.B, a different issue than CVE-2006-1540 and CVE-2006-3493.
7712| [CVE-2006-3510] The Remote Data Service Object (RDS.DataControl) in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a denial of service (crash) via a series of operations that result in an invalid length calculation when using SysAllocStringLen, then triggers a buffer over-read.
7713| [CVE-2006-3493] Buffer overflow in LsCreateLine function (mso_203) in mso.dll and mso9.dll, as used by Microsoft Word and possibly other products in Microsoft Office 2003, 2002, and 2000, allows remote user-assisted attackers to cause a denial of service (crash) via a crafted Word DOC or other Office file type. NOTE: this issue was originally reported to allow code execution, but on 20060710 Microsoft stated that code execution is not possible, and the original researcher agrees.
7714| [CVE-2006-3449] Unspecified vulnerability in Microsoft PowerPoint 2000 through 2003, possibly a buffer overflow, allows user-assisted remote attackers to execute arbitrary commands via a malformed record in the BIFF file format used in a PPT file, a different issue than CVE-2006-1540, aka "Microsoft PowerPoint Malformed Record Vulnerability."
7715| [CVE-2006-3448] Buffer overflow in the Step-by-Step Interactive Training in Microsoft Windows 2000 SP4, XP SP2 and Professional, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a long Syllabus string in crafted bookmark link files (cbo, cbl, or .cbm), a different issue than CVE-2005-1212.
7716| [CVE-2006-3445] Integer overflow in the ReadWideString function in agentdpv.dll in Microsoft Agent on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a large length value in an .ACF file, which results in a heap-based buffer overflow.
7717| [CVE-2006-3444] Unspecified vulnerability in the kernel in Microsoft Windows 2000 SP4, probably a buffer overflow, allows local users to obtain privileges via unspecified vectors involving an "unchecked buffer."
7718| [CVE-2006-3443] Untrusted search path vulnerability in Winlogon in Microsoft Windows 2000 SP4, when SafeDllSearchMode is disabled, allows local users to gain privileges via a malicious DLL in the UserProfile directory, aka "User Profile Elevation of Privilege Vulnerability."
7719| [CVE-2006-3441] Buffer overflow in the DNS Client service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted record response. NOTE: while MS06-041 implies that there is a single issue, there are multiple vectors, and likely multiple vulnerabilities, related to (1) a heap-based buffer overflow in a DNS server response to the client, (2) a DNS server response with malformed ATMA records, and (3) a length miscalculation in TXT, HINFO, X25, and ISDN records.
7720| [CVE-2006-3440] Buffer overflow in the Winsock API in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka "Winsock Hostname Vulnerability."
7721| [CVE-2006-3439] Buffer overflow in the Server Service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers, including anonymous users, to execute arbitrary code via a crafted RPC message, a different vulnerability than CVE-2006-1314.
7722| [CVE-2006-3436] Cross-site scripting (XSS) vulnerability in Microsoft .NET Framework 2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving "ASP.NET controls that set the AutoPostBack property to true".
7723| [CVE-2006-3435] PowerPoint in Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac does not properly parse the slide notes field in a document, which allows remote user-assisted attackers to execute arbitrary code via crafted data in this field, which triggers an erroneous object pointer calculation that uses data from within the document. NOTE: this issue is different than other PowerPoint vulnerabilities including CVE-2006-4694.
7724| [CVE-2006-3434] Unspecified vulnerability in Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac allows remote user-assisted attackers to execute arbitrary code via a crafted string that triggers memory corruption.
7725| [CVE-2006-3431] Buffer overflow in certain Asian language versions of Microsoft Excel might allow user-assisted attackers to execute arbitrary code via a crafted STYLE record in a spreadsheet that triggers the overflow when the user attempts to repair the document or selects the "Style" option, as demonstrated by nanika.xls. NOTE: Microsoft has confirmed to CVE via e-mail that this is different than the other Excel vulnerabilities announced before 20060707, including CVE-2006-3059 and CVE-2006-3086.
7726| [CVE-2006-3059] Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors. NOTE: this is a different vulnerability than CVE-2006-3086.
7727| [CVE-2006-2492] Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 20060519 for a zero-day attack.
7728| [CVE-2006-2389] Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via an Office file with a malformed property that triggers memory corruption related to record lengths, aka "Microsoft Office Property Vulnerability," a different vulnerability than CVE-2006-1316.
7729| [CVE-2006-2388] Microsoft Office Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via malformed cell comments, which lead to modification of "critical data offsets" during the rebuilding process.
7730| [CVE-2006-2387] Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, Excel Viewer 2003, and Microsoft Works Suite 2004 through 2006 allows user-assisted attackers to execute arbitrary code via a crafted DATETIME record in an XLS file, a different vulnerability than CVE-2006-3867 and CVE-2006-3875.
7731| [CVE-2006-2380] Microsoft Windows 2000 SP4 does not properly validate an RPC server during mutual authentication over SSL, which allows remote attackers to spoof an RPC server, aka the "RPC Mutual Authentication Vulnerability."
7732| [CVE-2006-2379] Buffer overflow in the TCP/IP Protocol driver in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via unknown vectors related to IP source routing.
7733| [CVE-2006-2378] Buffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and Sp2, Server 2003 SP1 and earlier, and Windows 98 and Me allows remote attackers to execute arbitrary code via a crafted ART image that causes heap corruption.
7734| [CVE-2006-2374] The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to cause a denial of service (hang) by calling the MrxSmbCscIoctlCloseForCopyChunk with the file handle of the shadow device, which results in a deadlock, aka the "SMB Invalid Handle Vulnerability."
7735| [CVE-2006-2373] The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to execute arbitrary code by calling the MrxSmbCscIoctlOpenForCopyChunk function with the METHOD_NEITHER method flag and an arbitrary address, possibly for kernel memory, aka the "SMB Driver Elevation of Privilege Vulnerability."
7736| [CVE-2006-2372] Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a crafted DHCP response.
7737| [CVE-2006-2371] Buffer overflow in the Remote Access Connection Manager service (RASMAN) service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," that lead to registry corruption and stack corruption, aka the "RASMAN Registry Corruption Vulnerability."
7738| [CVE-2006-2370] Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," aka the "RRAS Memory Corruption Vulnerability."
7739| [CVE-2006-2334] The RtlDosPathNameToNtPathName_U API function in NTDLL.DLL in Microsoft Windows 2000 SP4 and XP SP2 does not properly convert DOS style paths with trailing spaces into NT style paths, which allows context-dependent attackers to create files that cannot be accessed through the expected DOS path or prevent access to other similarly named files in the same directory, which prevents those files from being detected or disinfected by certain anti-virus and anti-spyware software.
7740| [CVE-2006-2094] Microsoft Internet Explorer before Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1, when Prompt is configured in Security Settings, uses modal dialogs to verify that a user wishes to run an ActiveX control or perform other risky actions, which allows user-assisted remote attackers to construct a race condition that tricks a user into clicking an object or pressing keys that are actually applied to a "Yes" approval for executing the control.
7741| [CVE-2006-2055] Argument injection vulnerability in Microsoft Outlook 2003 SP1 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via " (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft Outlook with an arbitrary filename as an attachment. NOTE: it is not clear whether this issue is implementation-specific or a problem in the Microsoft API.
7742| [CVE-2006-1654] Directory traversal vulnerability in the HP Color LaserJet 2500 Toolbox and Color LaserJet 4600 Toolbox on Microsoft Windows before 20060402 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request to TCP port 5225.
7743| [CVE-2006-1651] ** DISPUTED ** Microsoft ISA Server 2004 allows remote attackers to bypass certain filtering rules, including ones for (1) ICMP and (2) TCP, via IPv6 packets. NOTE: An established researcher has disputed this issue, saying that "Neither ISA Server 2004 nor Windows 2003 Basic Firewall support IPv6 filtering ... This is different network protocol."
7744| [CVE-2006-1540] MSO.DLL in Microsoft Office 2000, Office XP (2002), and Office 2003 allows user-assisted attackers to cause a denial of service and execute arbitrary code via multiple attack vectors, as originally demonstrated using a crafted document record with a malformed string, as demonstrated by replacing a certain "01 00 00 00" byte sequence with an "FF FF FF FF" byte sequence, possibly causing an invalid array index, in (1) an Excel .xls document, which triggers an access violation in ole32.dll
7745| [CVE-2006-1316] Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via an Office file with malformed string that triggers memory corruption related to record lengths, aka "Microsoft Office Parsing Vulnerability," a different vulnerability than CVE-2006-2389.
7746| [CVE-2006-1315] The Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to obtain sensitive information via crafted requests that leak information in SMB buffers, which are not properly initialized, aka "SMB Information Disclosure Vulnerability."
7747| [CVE-2006-1314] Heap-based buffer overflow in the Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to execute arbitrary code via crafted first-class Mailslot messages that triggers memory corruption and bypasses size restrictions on second-class Mailslot messages.
7748| [CVE-2006-1313] Microsoft JScript 5.1, 5.5, and 5.6 on Windows 2000 SP4, and 5.6 on Windows XP, Server 2003, Windows 98 and Windows Me, will "release objects early" in certain cases, which results in memory corruption and allows remote attackers to execute arbitrary code.
7749| [CVE-2006-1311] The RichEdit component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1
7750| [CVE-2006-1309] Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted LABEL record that triggers memory corruption.
7751| [CVE-2006-1308] Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted FNGROUPCOUNT value.
7752| [CVE-2006-1306] Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted BIFF record with an attacker-controlled array index that is used for a function pointer, aka "Malformed OBJECT record Vulnerability."
7753| [CVE-2006-1305] Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to cause a denial of service (memory exhaustion and interrupted mail recovery) via malformed e-mail header information, possibly related to (1) long subject lines or (2) large numbers of recipients in To or CC headers.
7754| [CVE-2006-1304] Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted COLINFO record, which triggers the overflow during a "data filling operation."
7755| [CVE-2006-1302] Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with certain crafted fields in a SELECTION record, which triggers memory corruption, aka "Malformed SELECTION record Vulnerability."
7756| [CVE-2006-1301] Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted SELECTION record that triggers memory corruption, a different vulnerability than CVE-2006-1302.
7757| [CVE-2006-1300] Microsoft .NET framework 2.0 (ASP.NET) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to bypass access restrictions via unspecified "URL paths" that can access Application Folder objects "explicitly by name."
7758| [CVE-2006-1257] The sample files in the authfiles directory in Microsoft Commerce Server 2002 before SP2 allow remote attackers to bypass authentication by logging in to authfiles/login.asp with a valid username and any password, then going to the main site twice.
7759| [CVE-2006-1193] Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2000 SP1 through SP3, when running Outlook Web Access (OWA), allows user-assisted remote attackers to inject arbitrary HTML or web script via unknown vectors related to "HTML parsing."
7760| [CVE-2006-1184] Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0, 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to cause a denial of service (crash) via a BuildContextW request with a large (1) UuidString or (2) GuidIn of a certain length, which causes an out-of-range memory access, aka the MSDTC Denial of Service Vulnerability. NOTE: this is a variant of CVE-2005-2119.
7761| [CVE-2006-0988] The default configuration of the DNS Server service on Windows Server 2003 and Windows 2000, and the Microsoft DNS Server service on Windows NT 4.0, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed source IP addresses.
7762| [CVE-2006-0935] Microsoft Word 2003 allows remote attackers to cause a denial of service (application crash) via a crafted file, as demonstrated by 101_filefuzz.
7763| [CVE-2006-0187] By design, Microsoft Visual Studio 2005 automatically executes code in the Load event of a user-defined control (UserControl1_Load function), which allows user-assisted attackers to execute arbitrary code by tricking the user into opening a malicious Visual Studio project file.
7764| [CVE-2006-0034] Heap-based buffer overflow in the CRpcIoManagerServer::BuildContext function in msdtcprx.dll for Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0 and Windows 2000 SP2 and SP3 allows remote attackers to execute arbitrary code via a long fifth argument to the BuildContextW or BuildContext opcode, which triggers a bug in the NdrAllocate function, aka the MSDTC Invalid Memory Access Vulnerability.
7765| [CVE-2006-0033] Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted PNG image that triggers memory corruption when it is parsed.
7766| [CVE-2006-0032] Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL, which is injected into an error message whose charset is set to UTF-7.
7767| [CVE-2006-0031] Stack-based buffer overflow in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed record with a modified length value, which leads to memory corruption.
7768| [CVE-2006-0030] Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed graphic, which leads to memory corruption.
7769| [CVE-2006-0029] Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed description, which leads to memory corruption.
7770| [CVE-2006-0028] Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via a BIFF parsing format file containing malformed BOOLERR records that lead to memory corruption, probably involving invalid pointers.
7771| [CVE-2006-0023] Microsoft Windows XP SP1 and SP2 before August 2004, and possibly other operating systems and versions, uses insecure default ACLs that allow the Authenticated Users group to gain privileges by modifying critical configuration information for the (1) Simple Service Discovery Protocol (SSDP), (2) Universal Plug and Play Device Host (UPnP), (3) NetBT, (4) SCardSvr, (5) DHCP, and (6) DnsCache services, aka "Permissive Windows Services DACLs." NOTE: the NetBT, SCardSvr, DHCP, DnsCache already require privileged access to exploit.
7772| [CVE-2006-0022] Unspecified vulnerability in Microsoft PowerPoint in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP1 and SP2, Office 2004 for Mac, and v. X for Mac allows user-assisted attackers to execute arbitrary code via a PowerPoint document with a malformed record, which triggers memory corruption.
7773| [CVE-2006-0021] Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang) via an IGMP packet with an invalid IP option, aka the "IGMP v3 DoS Vulnerability."
7774| [CVE-2006-0020] An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a crafted WMF file with a manipulated WMF header size, possibly involving an integer overflow, a different vulnerability than CVE-2005-4560, and aka "WMF Image Parsing Memory Corruption Vulnerability."
7775| [CVE-2006-0015] Cross-site scripting (XSS) vulnerability in _vti_bin/_vti_adm/fpadmdll.dll in Microsoft FrontPage Server Extensions 2002 and SharePoint Team Services allows remote attackers to inject arbitrary web script or HTML, then leverage the attack to execute arbitrary programs or create new accounts, via the (1) operation, (2) command, and (3) name parameters.
7776| [CVE-2006-0013] Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote authenticated users or Guests to execute arbitrary code via crafted RPC requests, a different vulnerability than CVE-2005-1207.
7777| [CVE-2006-0012] Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and "crafted files and directories," aka the "Windows Shell Vulnerability."
7778| [CVE-2006-0010] Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.
7779| [CVE-2006-0009] Buffer overflow in Microsoft Office 2000 SP3, XP SP3, and other versions and packages, allows user-assisted attackers to execute arbitrary code via a routing slip that is longer than specified by the provided length field, as exploited by malware such as TROJ_MDROPPER.BH and Trojan.PPDropper.E in attacks against PowerPoint.
7780| [CVE-2006-0008] The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program that displays the about box.
7781| [CVE-2006-0007] Buffer overflow in GIFIMP32.FLT, as used in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted GIF image that triggers memory corruption when it is parsed.
7782| [CVE-2006-0006] Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap (.BMP) file that specifies a size of 0 but contains additional data.
7783| [CVE-2006-0004] Microsoft PowerPoint 2000 in Office 2000 SP3 has an interaction with Internet Explorer that allows remote attackers to obtain sensitive information via a PowerPoint presentation that attempts to access objects in the Temporary Internet Files Folder (TIFF).
7784| [CVE-2006-0002] Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.
7785| [CVE-2006-0001] Stack-based buffer overflow in Microsoft Publisher 2000 through 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted PUB file, which causes an overflow when parsing fonts.
7786| [CVE-2005-4717] Microsoft Internet Explorer 6.0 on Windows NT 4.0 SP6a, Windows 2000 SP4, Windows XP SP1, Windows XP SP2, and Windows Server 2003 SP1 allows remote attackers to cause a denial of service (client crash) via a certain combination of a malformed HTML file and a CSS file that triggers a null dereference, probably related to rendering of a DIV element that contains a malformed IMG tag, as demonstrated by IEcrash.htm and IEcrash.rar.
7787| [CVE-2005-4269] mshtml.dll in Microsoft Windows XP, Server 2003, and Internet Explorer 6.0 SP1 allows attackers to cause a denial of service (access violation) by causing mshtml.dll to process button-focus events at the same time that a document is reloading, as seen in Microsoft Office InfoPath 2003 by repeatedly clicking the "Delete" button in a repeating section in a form. NOTE: the normal operation of InfoPath appears to involve a local user without any privilege boundaries, so this might not be a vulnerability in InfoPath. If no realistic scenarios exist for this problem in other products, then perhaps it should be excluded from CVE.
7788| [CVE-2005-4131] Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed range, which could lead to memory corruption involving an argument to the msvcrt.memmove function, aka "Brand new Microsoft Excel Vulnerability," as originally placed for sale on eBay as item number 7203336538.
7789| [CVE-2005-3981] ** DISPUTED ** NOTE: this issue has been disputed by third parties. Microsoft Windows XP, 2000, and 2003 allows local users to kill a writable process by using the CreateRemoteThread function with certain arguments on a process that has been opened using the OpenProcess function, possibly involving an invalid address for the start routine. NOTE: followup posts have disputed this issue, saying that if a user already has privileges to write to a process, then other functions could be called or the process could be terminated using PROCESS_TERMINATE.
7790| [CVE-2005-3945] The SynAttackProtect protection in Microsoft Windows 2003 before SP1 and Windows 2000 before SP4 with Update Roll-up uses a hash of predictable data, which allows remote attackers to cause a denial of service (CPU consumption) via a flood of SYN packets that produce identical hash values, which slows down the hash table lookups.
7791| [CVE-2005-3644] PNP_GetDeviceList (upnp_getdevicelist) in UPnP for Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 and earlier, allows remote attackers to cause a denial of service (memory consumption) via a DCE RPC request that specifies a large output buffer size, a variant of CVE-2006-6296, and a different vulnerability than CVE-2005-2120.
7792| [CVE-2005-3177] CHKDSK in Microsoft Windows 2000 before Update Rollup 1 for SP4, Windows XP, and Windows Server 2003, when running in fix mode, does not properly handle security descriptors if the master file table contains a large number of files or if the descriptors do not satisfy certain NTFS conventions, which could cause ACLs for some files to be reverted to less secure defaults, or cause security descriptors to be removed.
7793| [CVE-2005-3176] Microsoft Windows 2000 before Update Rollup 1 for SP4 does not record the IP address of a Windows Terminal Services client in a security log event if the client connects successfully, which could make it easier for attackers to escape detection.
7794| [CVE-2005-3175] Microsoft Windows 2000 before Update Rollup 1 for SP4 allows a local administrator to unlock a computer even if it has been locked by a domain administrator, which allows the local administrator to access the session as the domain administrator.
7795| [CVE-2005-3174] Microsoft Windows 2000 before Update Rollup 1 for SP4 allows users to log on to the domain, even when their password has expired, if the fully qualified domain name (FQDN) is 8 characters long.
7796| [CVE-2005-3173] Microsoft Windows 2000 before Update Rollup 1 for SP4 does not apply group policies if the user logs on using UPN credentials with a trailing dot, which prevents Windows 2000 from finding the correct domain controller and could allow the user to bypass intended restrictions.
7797| [CVE-2005-3172] The WideCharToMultiByte function in Microsoft Windows 2000 before Update Rollup 1 for SP4 does not properly convert strings with Japanese composite characters in the last character, which could prevent the string from being null terminated and lead to data corruption or enable buffer overflow attacks.
7798| [CVE-2005-3171] Microsoft Windows 2000 before Update Rollup 1 for SP4 records Event ID 1704 to indicate that Group Policy security settings were successfully updated, even when the processing fails such as when Ntuser.pol cannot be accessed, which could cause system administrators to believe that the system is compliant with the specified settings.
7799| [CVE-2005-3170] The LDAP client on Microsoft Windows 2000 before Update Rollup 1 for SP4 accepts certificates using LDAP Secure Sockets Layer (LDAPS) even when the Certificate Authority (CA) is not trusted, which could allow attackers to trick users into believing that they are accessing a trusted site.
7800| [CVE-2005-3169] Microsoft Windows 2000 before Update Rollup 1 for SP4, when the "audit directory service access" policy is enabled, does not record a 565 event message for File Delete Child operations on an Active Directory object in the security event log, which could allow attackers to conduct unauthorized activities without detection.
7801| [CVE-2005-3168] The SECEDIT command on Microsoft Windows 2000 before Update Rollup 1 for SP4, when using a security template to set Access Control Lists (ACLs) on folders, does not apply ACLs on folders that are listed after a long folder entry, which could result in less secure permissions than specified by the template.
7802| [CVE-2005-2122] Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to execute arbitrary commands via a shortcut (.lnk) file with long font properties that lead to a buffer overflow in the Client/Server Runtime Server Subsystem (CSRSS), a different vulnerability than CVE-2005-2118.
7803| [CVE-2005-2120] Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of "\" (backslash) characters in a registry key name, which triggers the overflow in a wsprintfW function call.
7804| [CVE-2005-2118] Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote user-assisted attackers to execute arbitrary commands via a crafted shortcut (.lnk) file with long font properties that lead to a buffer overflow when the user views the file's properties using Windows Explorer, a different vulnerability than CVE-2005-2122.
7805| [CVE-2005-2117] Web View in Windows Explorer on Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 does not properly handle certain HTML characters in preview fields, which allows remote user-assisted attackers to execute arbitrary code.
7806| [CVE-2005-1985] The Client Service for NetWare (CSNW) on Microsoft Windows 2000 SP4, XP SP1 and Sp2, and Server 2003 SP1 and earlier, allows remote attackers to execute arbitrary code due to an "unchecked buffer" when processing certain crafted network messages.
7807| [CVE-2005-1984] Buffer overflow in the Print Spooler service (Spoolsv.exe) for Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via a malicious message.
7808| [CVE-2005-1983] Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1 allows remote attackers to execute arbitrary code via a crafted packet, and local users to gain privileges via a malicious application, as exploited by the Zotob (aka Mytob) worm.
7809| [CVE-2005-1982] Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.
7810| [CVE-2005-1981] Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message.
7811| [CVE-2005-1907] The ISA Firewall service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (Wspsrv.exe crash) via a large amount of SecureNAT network traffic.
7812| [CVE-2005-1683] Buffer overflow in winword.exe 10.2627.6714 and earlier in Microsoft Word for the Macintosh, before SP3 for Word 2002, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted mcw file.
7813| [CVE-2005-1218] The Microsoft Windows kernel in Microsoft Windows 2000 Server, Windows XP, and Windows Server 2003 allows remote attackers to cause a denial of service (crash) via crafted Remote Desktop Protocol (RDP) requests.
7814| [CVE-2005-1216] Microsoft ISA Server 2000 allows remote attackers to connect to services utilizing the NetBIOS protocol via a NetBIOS connection with an ISA Server that uses the NetBIOS (all) predefined packet filter.
7815| [CVE-2005-1215] Microsoft ISA Server 2000 allows remote attackers to poison the ISA cache or bypass content restriction policies via a malformed HTTP request packet containing multiple Content-Length headers.
7816| [CVE-2005-1208] Integer overflow in Microsoft Windows 98, 2000, XP SP2 and earlier, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via a crafted compiled Help (.CHM) file with a large size field that triggers a heap-based buffer overflow, as demonstrated using a "ms-its:" URL in Internet Explorer.
7817| [CVE-2005-1207] Buffer overflow in the Web Client service in Microsoft Windows XP and Windows Server 2003 allows remote authenticated users to execute arbitrary code via a crafted WebDAV request containing special parameters.
7818| [CVE-2005-1206] Buffer overflow in the Server Message Block (SMB) functionality for Microsoft Windows 2000, XP SP1 and SP2, and Server 2003 and SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka the "Server Message Block Vulnerability."
7819| [CVE-2005-1205] The Telnet client for Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX allows remote attackers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.
7820| [CVE-2005-1052] Microsoft Outlook 2003 and Outlook Web Access (OWA) 2003 do not properly display comma separated addresses in the From field in an e-mail message, which could allow remote attackers to spoof e-mail addresses.
7821| [CVE-2005-0921] Microsoft Outlook 2002 Connector for IBM Lotus Domino 2.0 allows local users to save passwords and login credentials locally, even when password caching is disabled by a group policy.
7822| [CVE-2005-0820] Microsoft Office InfoPath 2003 SP1 includes sensitive information in the Manifest.xsf file in a custom .xsn form, which allows attackers to obtain printer and network information, obtain the database name, username, and password, or obtain the internal web server name.
7823| [CVE-2005-0738] Stack consumption vulnerability in Microsoft Exchange Server 2003 SP1 allows users to cause a denial of service (hang) by deleting or moving a folder with deeply nested subfolders, which causes Microsoft Exchange Information Store service (Store.exe) to hang as a result of a large number of recursive calls.
7824| [CVE-2005-0564] Stack-based buffer overflow in Microsoft Word 2000 and Word 2002, and Microsoft Works Suites 2000 through 2004, might allow remote attackers to execute arbitrary code via a .doc file with long font information.
7825| [CVE-2005-0558] Buffer overflow in Microsoft Word 2000, Word 2002, and Word 2003 allows remote attackers to execute arbitrary code via a crafted document.
7826| [CVE-2005-0551] Stack-based buffer overflow in WINSRV.DLL in the Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application that provides console window information with a long FaceName value.
7827| [CVE-2005-0550] Buffer overflow in Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to cause a denial of service (i.e., system crash) via a malformed request, aka "Object Management Vulnerability".
7828| [CVE-2005-0545] Microsoft Windows XP Pro SP2 and Windows 2000 Server SP4 running Active Directory allow local users to bypass group policies that restrict access to hidden drives by using the browse feature in Office 10 applications such as Word or Excel, or using a flash drive. NOTE: this issue has been disputed in a followup post.
7829| [CVE-2005-0063] The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.
7830| [CVE-2005-0061] The kernel of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via certain access requests.
7831| [CVE-2005-0060] Buffer overflow in the font processing component of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application.
7832| [CVE-2005-0059] Buffer overflow in the Message Queuing component of Microsoft Windows 2000 and Windows XP SP1 allows remote attackers to execute arbitrary code via a crafted message.
7833| [CVE-2005-0058] Buffer overflow in the Telephony Application Programming Interface (TAPI) for Microsoft Windows 98, Windows 98 SE, Windows ME, Windows 2000, Windows XP, and Windows Server 2003 allows attackers elevate privileges or execute arbitrary code via a crafted message.
7834| [CVE-2005-0048] Microsoft Windows XP SP2 and earlier, 2000 SP3 and SP4, Server 2003, and older operating systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IP packets with malformed options, aka the "IP Validation Vulnerability."
7835| [CVE-2004-2527] The local and remote desktop login screens in Microsoft Windows XP before SP2 and 2003 allow remote attackers to cause a denial of service (CPU and memory consumption) by repeatedly using the WinKey+"U" key combination, which causes multiple copies of Windows Utility Manager to be loaded more quickly than they can be closed when the copies detect that another instance is running.
7836| [CVE-2004-2482] Microsoft Outlook 2000 and 2003, when configured to use Microsoft Word 2000 or 2003 as the e-mail editor and when forwarding e-mail, does not properly handle an opening OBJECT tag that does not have a closing OBJECT tag, which causes Outlook to automatically download the URI in the data property of the OBJECT tag and might allow remote attackers to execute arbitrary code.
7837| [CVE-2004-2365] Memory leak in Microsoft Windows XP and Windows Server 2003 allows local users to cause a denial of service (memory exhaustion) by repeatedly creating and deleting directories using a non-standard tool such as smbmount.
7838| [CVE-2004-2339] ** DISPUTED ** Microsoft Windows 2000, XP, and possibly 2003 allows local users with the SeDebugPrivilege privilege to execute arbitrary code as kernel and read or write kernel memory via the NtSystemDebugControl function, which does not verify its pointer arguments. Note: this issue has been disputed, since Administrator privileges are typically required to exploit this issue, thus privilege boundaries are not crossed.
7839| [CVE-2004-1080] The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42, aka the "Association Context Vulnerability."
7840| [CVE-2004-0963] Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause a denial of service (application exception) and possibly execute arbitrary code in winword.exe via certain unexpected values in a .doc file, including (1) an offset that triggers an out-of-bounds memory access, (2) a certain value that causes a large memory copy as triggered by an integer conversion error, and other values.
7841| [CVE-2004-0897] The Indexing Service for Microsoft Windows XP and Server 2003 does not properly validate the length of a message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.
7842| [CVE-2004-0892] Microsoft Proxy Server 2.0 and Microsoft ISA Server 2000 (which is included in Small Business Server 2000 and Small Business Server 2003 Premium Edition) allows remote attackers to spoof trusted Internet content on a specially crafted webpage via spoofed reverse DNS lookup results.
7843| [CVE-2004-0846] Unknown vulnerability in Microsoft Excel 2000, 2002, 2001 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via a malicious file containing certain parameters that are not properly validated.
7844| [CVE-2004-0840] The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows Server 2003 64-bit Edition, and the Exchange Routing Engine component of Exchange Server 2003, allows remote attackers to execute arbitrary code via a malicious DNS response message containing length values that are not properly validated.
7845| [CVE-2004-0728] The Remote Control Client service in Microsoft's Systems Management Server (SMS) 2.50.2726.0 allows remote attackers to cause a denial of service (crash) via a data packet to TCP port 2702 that causes the server to read or write to an invalid memory address.
7846| [CVE-2004-0726] The Windows Media Player control in Microsoft Windows 2000 allows remote attackers to execute arbitrary script in the local computer zone via an ASX filename that contains javascript, which is executed in the local context in a preview panel.
7847| [CVE-2004-0575] Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit Edition allows remote attackers to execute arbitrary code via compressed (zipped) folders that involve an "unchecked buffer" and improper length validation.
7848| [CVE-2004-0574] The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an "unchecked buffer," leading to off-by-one and heap-based buffer overflows.
7849| [CVE-2004-0573] Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website.
7850| [CVE-2004-0540] Microsoft Windows 2000, when running in a domain whose Fully Qualified Domain Name (FQDN) is exactly 8 characters long, does not prevent users with expired passwords from logging on to the domain.
7851| [CVE-2004-0503] Microsoft Outlook 2003 allows remote attackers to bypass the default zone restrictions and execute script within media files via a Rich Text Format (RTF) message containing an OLE object for the Windows Media Player, which bypasses Media Player's setting to disallow scripting and may lead to unprompted installation of an executable when exploited in conjunction with predictable-file-location exposures such as CVE-2004-0502.
7852| [CVE-2004-0379] Multiple cross-site scripting (XSS) vulnerabilities in Microsoft SharePoint Portal Server 2001 allow remote attackers to process arbitrary web content and steal cookies via certain server scripts.
7853| [CVE-2004-0284] Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if "Do not save encrypted pages to disk" is disabled, via a web site or HTML e-mail that contains two null characters (%00) after the host name.
7854| [CVE-2004-0214] Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.
7855| [CVE-2004-0211] The kernel for Microsoft Windows Server 2003 does not reset certain values in CPU data structures, which allows local users to cause a denial of service (system crash) via a malicious program.
7856| [CVE-2004-0210] The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.
7857| [CVE-2004-0209] Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats that involve "an unchecked buffer."
7858| [CVE-2004-0208] The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions.
7859| [CVE-2004-0207] "Shatter" style vulnerability in the Window Management application programming interface (API) for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to gain privileges by using certain API functions to change properties of privileged programs using the SetWindowLong and SetWIndowLongPtr API functions.
7860| [CVE-2004-0206] Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow.
7861| [CVE-2004-0204] Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and other products, allows remote attackers to read and delete arbitrary files via ".." sequences in the dynamicimag argument to crystalimagehandler.aspx.
7862| [CVE-2004-0202] IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.
7863| [CVE-2004-0201] Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.
7864| [CVE-2004-0199] Help and Support Center in Microsoft Windows XP and Windows Server 2003 SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code, as demonstrated using certain hcp:// URLs that access the DVD Upgrade capability (dvdupgrd.htm).
7865| [CVE-2004-0124] The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability."
7866| [CVE-2004-0121] Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.
7867| [CVE-2004-0120] The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages.
7868| [CVE-2004-0116] An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field.
7869| [CVE-2003-1378] Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs via an HTML email with the CODEBASE parameter set to the program, a vulnerability similar to CAN-2002-0077.
7870| [CVE-2003-1106] The SMTP service in Microsoft Windows 2000 before SP4 allows remote attackers to cause a denial of service (crash or hang) via an e-mail message with a malformed time stamp in the FILETIME attribute.
7871| [CVE-2003-0908] The Utility Manager in Microsoft Windows 2000 executes winhlp32.exe with system privileges, which allows local users to execute arbitrary code via a "Shatter" style attack using a Windows message that accesses the context sensitive help button in the GUI, as demonstrated using the File Open dialog in the Help window, a different vulnerability than CVE-2004-0213.
7872| [CVE-2003-0906] Buffer overflow in the rendering for (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1 allows remote attackers to execute arbitrary code via a malformed WMF or EMF image.
7873| [CVE-2003-0904] Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reuse HTTP connections, which can cause OWA users to view mailboxes of other users when Kerberos has been disabled as an authentication method for IIS 6.0, e.g. when SharePoint Services 2.0 is installed.
7874| [CVE-2003-0839] Directory traversal vulnerability in the "Shell Folders" capability in Microsoft Windows Server 2003 allows remote attackers to read arbitrary files via .. (dot dot) sequences in a "shell:" link.
7875| [CVE-2003-0825] The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code.
7876| [CVE-2003-0824] Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.
7877| [CVE-2003-0822] Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to execute arbitrary code via a crafted chunked encoded request.
7878| [CVE-2003-0821] Microsoft Excel 97, 2000, and 2002 allows remote attackers to execute arbitrary code via a spreadsheet with a malicious XLM (Excel 4) macro that bypasses the macro security model.
7879| [CVE-2003-0820] Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.
7880| [CVE-2003-0819] Buffer overflow in the H.323 filter of Microsoft Internet Security and Acceleration Server 2000 allows remote attackers to execute arbitrary code in the Microsoft Firewall Service via certain H.323 traffic, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.
7881| [CVE-2003-0818] Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.
7882| [CVE-2003-0807] Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a crafted request.
7883| [CVE-2003-0806] Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1, when a member of a domain, allows remote attackers to execute arbitrary code.
7884| [CVE-2003-0719] Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets.
7885| [CVE-2003-0665] Buffer overflow in the ActiveX control for Microsoft Access Snapshot Viewer for Access 97, 2000, and 2002 allows remote attackers to execute arbitrary code via long parameters to the control.
7886| [CVE-2003-0664] Microsoft Word 2002, 2000, 97, and 98(J) does not properly check certain properties of a document, which allows attackers to bypass the macro security model and automatically execute arbitrary macros via a malicious document.
7887| [CVE-2003-0662] Buffer overflow in Troubleshooter ActiveX Control (Tshoot.ocx) in Microsoft Windows 2000 SP4 and earlier allows remote attackers to execute arbitrary code via an HTML document with a long argument to the RunQuery2 method.
7888| [CVE-2003-0660] The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to download and install ActiveX controls when the system is low on memory, which could allow remote attackers execute arbitrary code without user approval.
7889| [CVE-2003-0533] Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.
7890| [CVE-2003-0526] Cross-site scripting (XSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to inject arbitrary web script via a URL containing the script in the domain name portion, which is not properly cleansed in the default error pages (1) 500.htm for "500 Internal Server error" or (2) 404.htm for "404 Not Found."
7891| [CVE-2003-0506] Microsoft NetMeeting 3.01 2000 before SP4 allows remote attackers to cause a denial of service (shutdown of NetMeeting conference) via malformed packets, as demonstrated via the chat conversation.
7892| [CVE-2003-0505] Directory traversal vulnerability in Microsoft NetMeeting 3.01 2000 before SP4 allows remote attackers to read arbitrary files via "..\.." (dot dot) sequences in a file transfer request.
7893| [CVE-2003-0496] Microsoft SQL Server before Windows 2000 SP4 allows local users to gain privileges as the SQL Server user by calling the xp_fileexist extended stored procedure with a named pipe as an argument instead of a normal file.
7894| [CVE-2003-0352] Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message, as exploited by the Blaster/MSblast/LovSAN and Nachi/Welchia worms.
7895| [CVE-2003-0345] Buffer overflow in the SMB capability for Microsoft Windows XP, 2000, and NT allows remote attackers to cause a denial of service and possibly execute arbitrary code via an SMB packet that specifies a smaller buffer length than is required.
7896| [CVE-2003-0232] Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local Procedure Calls (LPC) port that leads to a buffer overflow.
7897| [CVE-2003-0231] Microsoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial of service (crash or hang) via a long request to a named pipe.
7898| [CVE-2003-0230] Microsoft SQL Server 7, 2000, and MSDE allows local users to gain privileges by hijacking a named pipe during the authentication of another user, aka the "Named Pipe Hijacking" vulnerability.
7899| [CVE-2003-0227] The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft Windows NT 4.0 and 2000, nsiislog.dll, allows remote attackers to cause a denial of service in Internet Information Server (IIS) and execute arbitrary code via a certain network request.
7900| [CVE-2003-0118] SQL injection vulnerability in the Document Tracking and Administration (DTA) website of Microsoft BizTalk Server 2000 and 2002 allows remote attackers to execute operating system commands via a request to (1) rawdocdata.asp or (2) RawCustomSearchField.asp containing an embedded SQL statement.
7901| [CVE-2003-0117] Buffer overflow in the HTTP receiver function (BizTalkHTTPReceive.dll ISAPI) of Microsoft BizTalk Server 2002 allows attackers to execute arbitrary code via a certain request to the HTTP receiver.
7902| [CVE-2003-0110] The Winsock Proxy service in Microsoft Proxy Server 2.0 and the Microsoft Firewall service in Internet Security and Acceleration (ISA) Server 2000 allow remote attackers to cause a denial of service (CPU consumption or packet storm) via a spoofed, malformed packet to UDP port 1745.
7903| [CVE-2003-0109] Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0.
7904| [CVE-2003-0011] Unknown vulnerability in the DNS intrusion detection application filter for Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (blocked traffic to DNS servers) via a certain type of incoming DNS request that is not properly handled.
7905| [CVE-2003-0007] Microsoft Outlook 2002 does not properly handle requests to encrypt email messages with V1 Exchange Server Security certificates, which causes Outlook to send the email in plaintext, aka "Flaw in how Outlook 2002 handles V1 Exchange Server Security Certificates could lead to Information Disclosure."
7906| [CVE-2003-0003] Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter information.
7907| [CVE-2003-0002] Cross-site scripting vulnerability (XSS) in ManualLogin.asp script for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary script via the REASONTXT parameter.
7908| [CVE-2002-2101] Microsoft Outlook 2002 allows remote attackers to execute arbitrary JavaScript code, even when scripting is disabled, via an "about:" or "javascript:" URI in the href attribute of an "a" tag.
7909| [CVE-2002-2100] Microsoft Outlook 2002 allows remote attackers to embed bypass the file download restrictions for attachments via an HTML email message that uses an IFRAME to reference malicious content.
7910| [CVE-2002-1984] Microsoft Internet Explorer 5.0.1 through 6.0 on Windows 2000 or Windows XP allows remote attackers to cause a denial of service (crash) via an OBJECT tag that contains a crafted CLASSID (CLSID) value of "CLSID:00022613-0000-0000-C000-000000000046".
7911| [CVE-2002-1981] Microsoft SQL Server 2000 through SQL Server 2000 SP2 allows the "public" role to execute the (1) sp_MSSetServerProperties or (2) sp_MSsetalertinfo stored procedures, which allows attackers to modify configuration including SQL server startup and alert settings.
7912| [CVE-2002-1933] The terminal services screensaver for Microsoft Windows 2000 does not automatically lock the terminal window if the window is minimized, which could allow local users to gain access to the terminal server window.
7913| [CVE-2002-1932] Microsoft Windows XP and Windows 2000, when configured to send administrative alerts and the "Do not overwrite events (clear log manually)" option is set, does not notify the administrator when the log reaches its maximum size, which allows local users and remote attackers to avoid detection.
7914| [CVE-2002-1876] Microsoft Exchange 2000 allows remote authenticated attackers to cause a denial of service via a large number of rapid requests, which consumes all of the licenses that are granted to Exchange by IIS.
7915| [CVE-2002-1873] Microsoft Exchange 2000, when used with Microsoft Remote Procedure Call (MSRPC), allows remote attackers to cause a denial of service (crash or memory consumption) via malformed MSRPC calls.
7916| [CVE-2002-1872] Microsoft SQL Server 6.0 through 2000, with SQL Authentication enabled, uses weak password encryption (XOR), which allows remote attackers to sniff and decrypt the password.
7917| [CVE-2002-1776] ** DISPUTED ** NOTE: this issue has been disputed by the vendor. Symantec Norton AntiVirus 2002 allows remote attackers to bypass virus protection via a Word Macro virus with a .nch or .dbx extension, which is automatically recognized and executed as a Microsoft Office document. NOTE: the vendor has disputed this issue, acknowledging that the initial scan is bypassed, but the Office plug-in would detect the virus before it is executed.
7918| [CVE-2002-1712] Microsoft Windows 2000 allows remote attackers to cause a denial of service (memory consumption) by sending a flood of empty TCP/IP packets with the ACK and FIN bits set to the NetBIOS port (TCP/139), as demonstrated by stream3.
7919| [CVE-2002-1256] The SMB signing capability in the Server Message Block (SMB) protocol in Microsoft Windows 2000 and Windows XP allows attackers to disable the digital signing settings in an SMB session to force the data to be sent unsigned, then inject data into the session without detection, e.g. by modifying group policy information sent from a domain controller.
7920| [CVE-2002-1255] Microsoft Outlook 2002 allows remote attackers to cause a denial of service (repeated failure) via an email message with a certain invalid header field that is accessed using POP3, IMAP, or WebDAV, aka "E-mail Header Processing Flaw Could Cause Outlook 2002 to Fail."
7921| [CVE-2002-1214] Buffer overflow in Microsoft PPTP Service on Windows XP and Windows 2000 allows remote attackers to cause a denial of service (hang) and possibly execute arbitrary code via a certain PPTP packet with malformed control data.
7922| [CVE-2002-1184] The system root folder of Microsoft Windows 2000 has default permissions of Everyone group with Full access (Everyone:F) and is in the search path when locating programs during login or application launch from the desktop, which could allow attackers to gain privileges as other users via Trojan horse programs.
7923| [CVE-2002-1145] The xp_runwebtask stored procedure in the Web Tasks component of Microsoft SQL Server 7.0 and 2000, Microsoft Data Engine (MSDE) 1.0, and Microsoft Desktop Engine (MSDE) 2000 can be executed by PUBLIC, which allows an attacker to gain privileges by updating a webtask that is owned by the database owner through the msdb.dbo.mswebtasks table, which does not have strong permissions.
7924| [CVE-2002-1141] An input validation error in the Sun Microsystems RPC library Services for Unix 3.0 Interix SD, as implemented on Microsoft Windows NT4, 2000, and XP, allows remote attackers to cause a denial of service via malformed fragmented RPC client packets, aka "Denial of service by sending an invalid RPC request."
7925| [CVE-2002-1140] The Sun Microsystems RPC library Services for Unix 3.0 Interix SD, as implemented on Microsoft Windows NT4, 2000, and XP, allows remote attackers to cause a denial of service (service hang) via malformed packet fragments, aka "Improper parameter size check leading to denial of service."
7926| [CVE-2002-1138] Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, writes output files for scheduled jobs under its own privileges instead of the entity that launched it, which allows attackers to overwrite system files, aka "Flaw in Output File Handling for Scheduled Jobs."
7927| [CVE-2002-1137] Buffer overflow in the Database Console Command (DBCC) that handles user inputs in Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, allows attackers to execute arbitrary code via a long SourceDB argument in a "non-SQL OLEDB data source" such as FoxPro, a variant of CAN-2002-0644.
7928| [CVE-2002-1123] Buffer overflow in the authentication function for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows remote attackers to execute arbitrary code via a long request to TCP port 1433, aka the "Hello" overflow.
7929| [CVE-2002-1117] Veritas Backup Exec 8.5 and earlier requires that the "RestrictAnonymous" registry key for Microsoft Exchange 2000 must be set to 0, which enables anonymous listing of the SAM database and shares.
7930| [CVE-2002-1056] Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary scripts via an email that the user forwards or replies to.
7931| [CVE-2002-0982] Microsoft SQL Server 2000 SP2, when configured as a distributor, allows attackers to execute arbitrary code via the @scriptfile parameter to the sp_MScopyscript stored procedure.
7932| [CVE-2002-0975] Buffer overflow in Microsoft DirectX Files Viewer ActiveX control (xweb.ocx) 2.0.6.15 and earlier allows remote attackers to execute arbitrary via a long File parameter.
7933| [CVE-2002-0863] Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka "Weak Encryption in RDP Protocol."
7934| [CVE-2002-0861] Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to bypass the "Allow paste operations via script" setting, even when it is disabled, via the (1) Copy method of the Cell object or (2) the Paste method of the Range object.
7935| [CVE-2002-0860] The LoadText method in the spreadsheet component in Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to read arbitrary files through Internet Explorer via a URL that redirects to the target file.
7936| [CVE-2002-0859] Buffer overflow in the OpenDataSource function of the Jet engine on Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code.
7937| [CVE-2002-0729] Microsoft SQL Server 2000 allows remote attackers to cause a denial of service via a malformed 0x08 packet that is missing a colon separator.
7938| [CVE-2002-0727] The Host function in Microsoft Office Web Components (OWC) 2000 and 2002 is exposed in components that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via the setTimeout method.
7939| [CVE-2002-0724] Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows attackers to cause a denial of service (crash) via a SMB_COM_TRANSACTION packet with a request for the (1) NetShareEnum, (2) NetServerEnum2, or (3) NetServerEnum3, aka "Unchecked Buffer in Network Share Provider Can Lead to Denial of Service".
7940| [CVE-2002-0721] Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could allow unprivileged users, and possibly remote attackers, to run stored procedures with administrator privileges via (1) xp_execresultset, (2) xp_printstatements, or (3) xp_displayparamstmt.
7941| [CVE-2002-0719] SQL injection vulnerability in the function that services for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary commands via an MCMS resource request for image files or other files.
7942| [CVE-2002-0718] Web authoring command in Microsoft Content Management Server (MCMS) 2001 allows attackers to authenticate and upload executable content, by modifying the upload location, aka "Program Execution via MCMS Authoring Function."
7943| [CVE-2002-0700] Buffer overflow in a system function that performs user authentication for Microsoft Content Management Server (MCMS) 2001 allows attackers to execute code in the Local System context by authenticating to a web page that calls the function, aka "Unchecked Buffer in MDAC Function Could Enable SQL Server Compromise."
7944| [CVE-2002-0699] Unknown vulnerability in the Certificate Enrollment ActiveX Control in Microsoft Windows 98, Windows 98 Second Edition, Windows Millennium, Windows NT 4.0, Windows 2000, and Windows XP allow remote attackers to delete digital certificates on a user's system via HTML.
7945| [CVE-2002-0695] Buffer overflow in the Transact-SQL (T-SQL) OpenRowSet component of Microsoft Data Access Components (MDAC) 2.5 through 2.7 for SQL Server 7.0 or 2000 allows remote attackers to execute arbitrary code via a query that calls the OpenRowSet command.
7946| [CVE-2002-0694] The HTML Help facility in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP uses the Local Computer Security Zone when opening .chm files from the Temporary Internet Files folder, which allows remote attackers to execute arbitrary code via HTML mail that references or inserts a malicious .chm file containing shortcuts that can be executed, aka "Code Execution via Compiled HTML Help File."
7947| [CVE-2002-0693] Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute code via (1) a long parameter to the Alink function, or (2) script containing a long argument to the showHelp function.
7948| [CVE-2002-0692] Buffer overflow in SmartHTML Interpreter (shtml.dll) in Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to cause a denial of service (CPU consumption) or run arbitrary code, respectively, via a certain type of web file request.
7949| [CVE-2002-0650] The keep-alive mechanism for Microsoft SQL Server 2000 allows remote attackers to cause a denial of service (bandwidth consumption) via a "ping" style packet to the Resolution Service (UDP port 1434) with a spoofed IP address of another SQL Server system, which causes the two servers to exchange packets in an infinite loop.
7950| [CVE-2002-0649] Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSDE) allow remote attackers to cause a denial of service or execute arbitrary code via UDP packets to port 1434 in which (1) a 0x04 byte that causes the SQL Monitor thread to generate a long registry key name, or (2) a 0x08 byte with a long string causes heap corruption, as exploited by the Slammer/Sapphire worm.
7951| [CVE-2002-0645] SQL injection vulnerability in stored procedures for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 may allow authenticated users to execute arbitrary commands.
7952| [CVE-2002-0644] Buffer overflow in several Database Consistency Checkers (DBCCs) for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows members of the db_owner and db_ddladmin roles to execute arbitrary code.
7953| [CVE-2002-0643] The installation of Microsoft Data Engine 1.0 (MSDE 1.0), and Microsoft SQL Server 2000 creates setup.iss files with insecure permissions and does not delete them after installation, which allows local users to obtain sensitive data, including weakly encrypted passwords, to gain privileges, aka "SQL Server Installation Process May Leave Passwords on System."
7954| [CVE-2002-0642] The registry key containing the SQL Server service account information in Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, has insecure permissions, which allows local users to gain privileges, aka "Incorrect Permission on SQL Server Service Account Registry Key."
7955| [CVE-2002-0641] Buffer overflow in bulk insert procedure of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows attackers with database administration privileges to execute arbitrary code via a long filename in the BULK INSERT query.
7956| [CVE-2002-0624] Buffer overflow in the password encryption function of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows remote attackers to gain control of the database and execute arbitrary code via SQL Server Authentication, aka "Unchecked Buffer in Password Encryption Procedure."
7957| [CVE-2002-0623] Buffer overflow in AuthFilter ISAPI filter on Microsoft Commerce Server 2000 and 2002 allows remote attackers to execute arbitrary code via long authentication data, aka "New Variant of the ISAPI Filter Buffer Overrun".
7958| [CVE-2002-0622] The Office Web Components (OWC) package installer for Microsoft Commerce Server 2000 allows remote attackers to execute commands by passing the commands as input to the OWC package installer, aka "OWC Package Command Execution".
7959| [CVE-2002-0621] Buffer overflow in the Office Web Components (OWC) package installer used by Microsoft Commerce Server 2000 allows remote attackers to cause the process to fail or run arbitrary code in the LocalSystem security context via certain input to the OWC package installer.
7960| [CVE-2002-0620] Buffer overflow in the Profile Service of Microsoft Commerce Server 2000 allows remote attackers to cause the server to fail or run arbitrary code in the LocalSystem security context via an input field using an affected API.
7961| [CVE-2002-0619] The Mail Merge Tool in Microsoft Word 2002 for Windows, when Microsoft Access is present on a system, allows remote attackers to execute Visual Basic (VBA) scripts within a mail merge document that is saved in HTML format, aka a "Variant of MS00-071, Word Mail Merge Vulnerability" (CVE-2000-0788).
7962| [CVE-2002-0618] The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code in the Local Computer zone by embedding HTML scripts within an Excel workbook that contains an XSL stylesheet, aka "Excel XSL Stylesheet Script Execution".
7963| [CVE-2002-0617] The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code by creating a hyperlink on a drawing shape in a source workbook that points to a destination workbook containing an autoexecute macro, aka "Hyperlinked Excel Workbook Macro Bypass."
7964| [CVE-2002-0616] The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code by attaching an inline macro to an object within an Excel workbook, aka the "Excel Inline Macros Vulnerability."
7965| [CVE-2002-0597] LANMAN service on Microsoft Windows 2000 allows remote attackers to cause a denial of service (CPU/memory exhaustion) via a stream of malformed data to microsoft-ds port 445.
7966| [CVE-2002-0444] Microsoft Windows 2000 running the Terminal Server 90-day trial version, and possibly other versions, does not apply group policies to incoming users when the number of connections to the SYSVOL share exceeds the maximum, e.g. with a maximum number of licenses, which can allow remote authenticated users to bypass group policies.
7967| [CVE-2002-0443] Microsoft Windows 2000 allows local users to bypass the policy that prohibits reusing old passwords by changing the current password before it expires, which does not enable the check for previous passwords.
7968| [CVE-2002-0373] The Windows Media Device Manager (WMDM) Service in Microsoft Windows Media Player 7.1 on Windows 2000 systems allows local users to obtain LocalSystem rights via a program that calls the WMDM service to connect to an invalid local storage device, aka "Privilege Elevation through Windows Media Device Manager Service".
7969| [CVE-2002-0371] Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote attackers to execute arbitrary code via a gopher:// URL that redirects the user to a real or simulated gopher server that sends a long response.
7970| [CVE-2002-0368] The Store Service in Microsoft Exchange 2000 allows remote attackers to cause a denial of service (CPU consumption) via a mail message with a malformed RFC message attribute, aka "Malformed Mail Attribute can Cause Exchange 2000 to Exhaust CPU Resources."
7971| [CVE-2002-0224] The MSDTC (Microsoft Distributed Transaction Service Coordinator) for Microsoft Windows 2000, Microsoft IIS 5.0 and SQL Server 6.5 through SQL 2000 0.0 allows remote attackers to cause a denial of service (crash or hang) via malformed (random) input.
7972| [CVE-2002-0187] Cross-site scripting vulnerability in the SQLXML component of Microsoft SQL Server 2000 allows an attacker to execute arbitrary script via the root parameter as part of an XML SQL query, aka "Script Injection via XML Tag."
7973| [CVE-2002-0186] Buffer overflow in the SQLXML ISAPI extension of Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code via data queries with a long content-type parameter, aka "Unchecked Buffer in SQLXML ISAPI Extension."
7974| [CVE-2002-0154] Buffer overflows in extended stored procedures for Microsoft SQL Server 7.0 and 2000 allow remote attackers to cause a denial of service or execute arbitrary code via a database query with certain long arguments.
7975| [CVE-2002-0152] Buffer overflow in various Microsoft applications for Macintosh allows remote attackers to cause a denial of service (crash) or execute arbitrary code by invoking the file:// directive with a large number of / characters, which affects Internet Explorer 5.1, Outlook Express 5.0 through 5.0.2, Entourage v. X and 2001, PowerPoint v. X, 2001, and 98, and Excel v. X and 2001 for Macintosh.
7976| [CVE-2002-0055] SMTP service in Microsoft Windows 2000, Windows XP Professional, and Exchange 2000 allows remote attackers to cause a denial of service via a command with a malformed data transfer (BDAT) request.
7977| [CVE-2002-0054] SMTP service in (1) Microsoft Windows 2000 and (2) Internet Mail Connector (IMC) in Exchange Server 5.5 does not properly handle responses to NTLM authentication, which allows remote attackers to perform mail relaying via an SMTP AUTH command using null session credentials.
7978| [CVE-2002-0050] Buffer overflow in AuthFilter ISAPI filter on Microsoft Commerce Server 2000 allows remote attackers to execute arbitrary code via long authentication data.
7979| [CVE-2002-0049] Microsoft Exchange Server 2000 System Attendant gives "Everyone" group privileges to the WinReg key, which could allow remote attackers to read or modify registry keys.
7980| [CVE-2002-0034] The Microsoft CONVERT.EXE program, when used on Windows 2000 and Windows XP systems, does not apply the default NTFS permissions when converting a FAT32 file system, which could cause the conversion to produce a file system with less secure permissions than expected.
7981| [CVE-2002-0018] In Microsoft Windows NT and Windows 2000, a trusting domain that receives authorization information from a trusted domain does not verify that the trusted domain is authoritative for all listed SIDs, which allows remote attackers to gain Domain Administrator privileges on the trusting domain by injecting SIDs from untrusted domains into the authorization data that comes from from the trusted domain.
7982| [CVE-2001-1533] ** DISPUTED * Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets. NOTE: the vendor disputes this issue, saying that it requires high bandwidth to exploit, and the server does not experience any instability. Therefore this "laws of physics" issue might not be included in CVE.
7983| [CVE-2001-1451] Memory leak in the SNMP LAN Manager (LANMAN) MIB extension for Microsoft Windows 2000 before SP3, when the Print Spooler is not running, allows remote attackers to cause a denial of service (memory consumption) via a large number of GET or GETNEXT requests.
7984| [CVE-2001-1319] Microsoft Exchange 5.5 2000 allows remote attackers to cause a denial of service (hang) via exceptional BER encodings for the LDAP filter type field, as demonstrated by the PROTOS LDAPv3 test suite.
7985| [CVE-2001-1099] The default configuration of Norton AntiVirus for Microsoft Exchange 2000 2.x allows remote attackers to identify the recipient's INBOX file path by sending an email with an attachment containing malicious content, which includes the path in the rejection notice.
7986| [CVE-2001-0986] SQLQHit.asp sample file in Microsoft Index Server 2.0 allows remote attackers to obtain sensitive information such as the physical path, file attributes, or portions of source code by directly calling sqlqhit.asp with a CiScope parameter set to (1) webinfo, (2) extended_fileinfo, (3) extended_webinfo, or (4) fileinfo.
7987| [CVE-2001-0718] Vulnerability in (1) Microsoft Excel 2002 and earlier and (2) Microsoft PowerPoint 2002 and earlier allows attackers to bypass macro restrictions and execute arbitrary commands by modifying the data stream in the document.
7988| [CVE-2001-0666] Outlook Web Access (OWA) in Microsoft Exchange 2000 allows an authenticated user to cause a denial of service (CPU consumption) via a malformed OWA request for a deeply nested folder within the user's mailbox.
7989| [CVE-2001-0658] Cross-site scripting (CSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause other clients to execute certain script or read cookies via malicious script in an invalid URL that is not properly quoted in an error message.
7990| [CVE-2001-0628] Microsoft Word 2000 does not check AutoRecovery (.asd) files for macros, which allows a local attacker to execute arbitrary macros with the user ID of the Word user.
7991| [CVE-2001-0547] Memory leak in the proxy service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows local attackers to cause a denial of service (resource exhaustion).
7992| [CVE-2001-0546] Memory leak in H.323 Gatekeeper Service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (resource exhaustion) via a large amount of malformed H.323 data.
7993| [CVE-2001-0542] Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow attackers with access to SQL Server to execute arbitrary code through the functions (1) raiserror, (2) formatmessage, or (3) xp_sprintf. NOTE: the C runtime format string vulnerability reported in MS01-060 is identified by CVE-2001-0879.
7994| [CVE-2001-0538] Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTML e-mail message or web page.
7995| [CVE-2001-0509] Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs.
7996| [CVE-2001-0505] Multiple memory leaks in Microsoft Services for Unix 2.0 allow remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed requests to (1) the Telnet service, or (2) the NFS service.
7997| [CVE-2001-0504] Vulnerability in authentication process for SMTP service in Microsoft Windows 2000 allows remote attackers to use incorrect credentials to gain privileges and conduct activites such as mail relaying.
7998| [CVE-2001-0501] Microsoft Word 2002 and earlier allows attackers to automatically execute macros without warning the user by embedding the macros in a manner that escapes detection by the security scanner.
7999| [CVE-2001-0351] Microsoft Windows 2000 telnet service allows a local user to make a certain system call that allows the user to terminate a Telnet session and cause a denial of service.
8000| [CVE-2001-0350] Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the second of two variants of this vulnerability.
8001| [CVE-2001-0349] Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the first of two variants of this vulnerability.
8002| [CVE-2001-0348] Microsoft Windows 2000 telnet service allows attackers to cause a denial of service (crash) via a long logon command that contains a backspace.
8003| [CVE-2001-0347] Information disclosure vulnerability in Microsoft Windows 2000 telnet service allows remote attackers to determine the existence of user accounts such as Guest, or log in to the server without specifying the domain name, via a malformed userid.
8004| [CVE-2001-0346] Handle leak in Microsoft Windows 2000 telnet service allows attackers to cause a denial of service by starting a large number of sessions and terminating them.
8005| [CVE-2001-0345] Microsoft Windows 2000 telnet service allows attackers to prevent idle Telnet sessions from timing out, causing a denial of service by creating a large number of idle sessions.
8006| [CVE-2001-0344] An SQL query method in Microsoft SQL Server 2000 Gold and 7.0 using Mixed Mode allows local database users to gain privileges by reusing a cached connection of the sa administrator account.
8007| [CVE-2001-0340] An interaction between the Outlook Web Access (OWA) service in Microsoft Exchange 2000 Server and Internet Explorer allows attackers to execute malicious script code against a user's mailbox via a message attachment that contains HTML code, which is executed automatically.
8008| [CVE-2001-0261] Microsoft Windows 2000 Encrypted File System does not properly destroy backups of files that are encrypted, which allows a local attacker to recover the text of encrypted files.
8009| [CVE-2001-0245] Microsoft Index Server 2.0 in Windows NT 4.0, and Indexing Service in Windows 2000, allows remote attackers to read server-side include files via a malformed search request, aka a new variant of the "Malformed Hit-Highlighting" vulnerability.
8010| [CVE-2001-0244] Buffer overflow in Microsoft Index Server 2.0 allows remote attackers to execute arbitrary commands via a long search parameter.
8011| [CVE-2001-0240] Microsoft Word before Word 2002 allows attackers to automatically execute macros without warning the user via a Rich Text Format (RTF) document that links to a template with the embedded macro.
8012| [CVE-2001-0239] Microsoft Internet Security and Acceleration (ISA) Server 2000 Web Proxy allows remote attackers to cause a denial of service via a long web request with a specific type.
8013| [CVE-2001-0237] Memory leak in Microsoft 2000 domain controller allows remote attackers to cause a denial of service by repeatedly connecting to the Kerberos service and then disconnecting without sending any data.
8014| [CVE-2001-0146] IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly sending a series of specially formatted URL's.
8015| [CVE-2001-0048] The "Configure Your Server" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to install malicious programs, aka the "Directory Service Restore Mode Password" vulnerability.
8016| [CVE-2001-0005] Buffer overflow in the parsing mechanism of the file loader in Microsoft PowerPoint 2000 allows attackers to execute arbitrary commands.
8017| [CVE-2001-0003] Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials and possibly obtain the password, aka the "Web Client NTLM Authentication" vulnerability.
8018| [CVE-2000-1218] The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query, which allows remote attackers to poison the DNS cache.
8019| [CVE-2000-1217] Microsoft Windows 2000 before Service Pack 2 (SP2), when running in a non-Windows 2000 domain and using NTLM authentication, and when credentials of an account are locally cached, allows local users to bypass account lockout policies and make an unlimited number of login attempts, aka the "Domain Account Lockout" vulnerability.
8020| [CVE-2000-1209] The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq Insight Manager, and (6) Visio 2000, which allows remote attackers to gain privileges, as exploited by worms such as Voyager Alpha Force and Spida.
8021| [CVE-2000-1139] The installation of Microsoft Exchange 2000 before Rev. A creates a user account with a known password, which could allow attackers to gain privileges, aka the "Exchange User Account" vulnerability.
8022| [CVE-2000-1088] The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
8023| [CVE-2000-1087] The xp_proxiedmetadata function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
8024| [CVE-2000-1086] The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
8025| [CVE-2000-1085] The xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
8026| [CVE-2000-1079] Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote attackers to modify dynamic NetBIOS name cache entries via a spoofed Browse Frame Request in a unicast or UDP broadcast datagram.
8027| [CVE-2000-0942] The CiWebHitsFile component in Microsoft Indexing Services for Windows 2000 allows remote attackers to conduct a cross site scripting (CSS) attack via a CiRestriction parameter in a .htw request, aka the "Indexing Services Cross Site Scripting" vulnerability.
8028| [CVE-2000-0854] When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as riched20.dll and msi.dll, which could allow an attacker to execute arbitrary commands by inserting a Trojan Horse DLL into the same directory as the document.
8029| [CVE-2000-0771] Microsoft Windows 2000 allows local users to cause a denial of service by corrupting the local security policy via malformed RPC traffic, aka the "Local Security Policy Corruption" vulnerability.
8030| [CVE-2000-0765] Buffer overflow in the HTML interpreter in Microsoft Office 2000 allows an attacker to execute arbitrary commands via a long embedded object tag, aka the "Microsoft Office HTML Object Tag" vulnerability.
8031| [CVE-2000-0756] Microsoft Outlook 2000 does not properly process long or malformed fields in vCard (.vcf) files, which allows attackers to cause a denial of service.
8032| [CVE-2000-0710] The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers determine the physical path of the server components by requesting an invalid URL whose name includes a standard DOS device name.
8033| [CVE-2000-0709] The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to cause a denial of service in some components by requesting a URL whose name includes a standard DOS device name.
8034| [CVE-2000-0637] Microsoft Excel 97 and 2000 allows an attacker to execute arbitrary commands by specifying a malicious .dll using the Register.ID function, aka the "Excel REGISTER.ID Function" vulnerability.
8035| [CVE-2000-0621] Microsoft Outlook 98 and 2000, and Outlook Express 4.0x and 5.0x, allow remote attackers to read files on the client's system via a malformed HTML message that stores files outside of the cache, aka the "Cache Bypass" vulnerability.
8036| [CVE-2000-0597] Microsoft Office 2000 (Excel and PowerPoint) and PowerPoint 97 are marked as safe for scripting, which allows remote attackers to force Internet Explorer or some email clients to save files to arbitrary locations via the Visual Basic for Applications (VBA) SaveAs function, aka the "Office HTML Script" vulnerability.
8037| [CVE-2000-0331] Buffer overflow in Microsoft command processor (CMD.EXE) for Windows NT and Windows 2000 allows a local user to cause a denial of service via a long environment variable, aka the "Malformed Environment Variable" vulnerability.
8038| [CVE-2000-0277] Microsoft Excel 97 and 2000 does not warn the user when executing Excel Macro Language (XLM) macros in external text files, which could allow an attacker to execute a macro virus, aka the "XLM Text Macro" vulnerability.
8039| [CVE-2013-2557] The sandbox protection mechanism in Microsoft Internet Explorer 9 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, as demonstrated against Adobe Flash Player by VUPEN during a Pwn2Own competition at CanSecWest 2013.
8040| [CVE-2013-2556] Unspecified vulnerability in Microsoft Windows 7 allows attackers to bypass the ASLR protection mechanism via unknown vectors, as demonstrated against Adobe Flash Player by VUPEN during a Pwn2Own competition at CanSecWest 2013.
8041| [CVE-2013-2554] Unspecified vulnerability in Microsoft Windows 7 allows attackers to bypass the ASLR and DEP protection mechanisms via unknown vectors, as demonstrated against Firefox by VUPEN during a Pwn2Own competition at CanSecWest 2013, a different vulnerability than CVE-2013-0787.
8042| [CVE-2013-2553] Unspecified vulnerability in the kernel in Microsoft Windows 7 allows local users to gain privileges via unknown vectors, as demonstrated by Nils and Jon of MWR Labs during a Pwn2Own competition at CanSecWest 2013, a different vulnerability than CVE-2013-0912.
8043| [CVE-2013-2552] Unspecified vulnerability in Microsoft Internet Explorer 10 on Windows 8 allows remote attackers to bypass the sandbox protection mechanism by leveraging access to a Medium integrity process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013.
8044| [CVE-2013-2551] Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1308 and CVE-2013-1309.
8045| [CVE-2013-1347] Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly allocated or (2) is deleted, as exploited in the wild in May 2013.
8046| [CVE-2013-1305] HTTP.sys in Microsoft Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (infinite loop) via a crafted HTTP header, aka "HTTP.sys Denial of Service Vulnerability."
8047| [CVE-2013-1290] Microsoft SharePoint Server 2013, in certain configurations involving legacy My Sites, does not properly establish default access controls for a SharePoint list, which allows remote authenticated users to bypass intended restrictions on reading list items via a direct request for a list's location, aka "Incorrect Access Rights Information Disclosure Vulnerability."
8048| [CVE-2013-1289] Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1, Groove Server 2010 SP1, SharePoint Foundation 2010 SP1, and Office Web Apps 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted string, aka "HTML Sanitization Vulnerability."
8049| [CVE-2013-1284] Race condition in the kernel in Microsoft Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Kernel Race Condition Vulnerability."
8050| [CVE-2013-0096] Writer in Microsoft Windows Essentials 2011 and 2012 allows remote attackers to bypass proxy settings and overwrite arbitrary files via crafted URL parameters, aka "Windows Essentials Improper URI Handling Vulnerability."
8051| [CVE-2013-0086] Microsoft OneNote 2010 SP1 does not properly determine buffer sizes during memory allocation, which allows remote attackers to obtain sensitive information via a crafted OneNote file, aka "Buffer Size Validation Vulnerability."
8052| [CVE-2013-0085] Buffer overflow in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to cause a denial of service (W3WP process crash and site outage) via a crafted URL, aka "Buffer Overflow Vulnerability."
8053| [CVE-2013-0084] Directory traversal vulnerability in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to bypass intended read restrictions for content, and hijack user accounts, via a crafted URL, aka "SharePoint Directory Traversal Vulnerability."
8054| [CVE-2013-0083] Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via crafted content, leading to administrative command execution, aka "SharePoint XSS Vulnerability."
8055| [CVE-2013-0080] Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allow remote attackers to bypass intended read restrictions for content, and hijack user accounts, via a crafted URL, aka "Callback Function Vulnerability."
8056| [CVE-2013-0079] Microsoft Visio Viewer 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Visio file that triggers incorrect memory allocation, aka "Visio Viewer Tree Object Type Confusion Vulnerability."
8057| [CVE-2013-0005] The WCF Replace function in the Open Data (aka OData) protocol implementation in Microsoft .NET Framework 3.5, 3.5 SP1, 3.5.1, and 4, and the Management OData IIS Extension on Windows Server 2012, allows remote attackers to cause a denial of service (resource consumption and daemon restart) via crafted values in HTTP requests, aka "Replace Denial of Service Vulnerability."
8058| [CVE-2012-4969] Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site, as exploited in the wild in September 2012.
8059| [CVE-2012-4792] Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object, and exploited in the wild in December 2012.
8060| [CVE-2012-3456] Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in Calligra 2.4.3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ODF style in an ODF document. NOTE: this is the same vulnerability as CVE-2012-3455, but it was SPLIT by the CNA even though Calligra and KOffice share the same codebase.
8061| [CVE-2012-3455] Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in KOffice 2.3.3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ODF style in an ODF document. NOTE: this is the same vulnerability as CVE-2012-3456, but it was SPLIT by the CNA even though Calligra and KOffice share the same codebase.
8062| [CVE-2012-2290] The client in EMC NetWorker Module for Microsoft Applications (NMM) 2.2.1, 2.3 before build 122, and 2.4 before build 375 allows remote attackers to execute arbitrary code by sending a crafted message over a TCP communication channel.
8063| [CVE-2012-2284] The (1) install and (2) upgrade processes in EMC NetWorker Module for Microsoft Applications (NMM) 2.2.1, 2.3 before build 122, and 2.4 before build 375, when Exchange Server is used, allow local users to read cleartext administrator credentials via unspecified vectors.
8064| [CVE-2012-1945] Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allow local users to obtain sensitive information via an HTML document that loads a shortcut (aka .lnk) file for display within an IFRAME element, as demonstrated by a network share implemented by (1) Microsoft Windows or (2) Samba.
8065| [CVE-2012-1894] Microsoft Office for Mac 2011 uses world-writable permissions for the "Applications/Microsoft Office 2011/" directory and certain other directories, which allows local users to gain privileges by placing a Trojan horse executable file in one of these directories, aka "Office for Mac Improper Folder Permissions Vulnerability."
8066| [CVE-2012-1892] Cross-site scripting (XSS) vulnerability in Microsoft Visual Studio Team Foundation Server 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "XSS Vulnerability."
8067| [CVE-2012-1891] Heap-based buffer overflow in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2 and Windows Data Access Components (WDAC) 6.0 allows remote attackers to execute arbitrary code via crafted XML data that triggers access to an uninitialized object in memory, aka "ADO Cachesize Heap Overflow RCE Vulnerability."
8068| [CVE-2012-1888] Buffer overflow in Microsoft Visio 2010 SP1 and Visio Viewer 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Visio file, aka "Visio DXF File Format Buffer Overflow Vulnerability."
8069| [CVE-2012-1876] Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by attempting to access a nonexistent object, leading to a heap-based buffer overflow, aka "Col Element Remote Code Execution Vulnerability," as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012.
8070| [CVE-2012-1861] Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 Gold and SP1, SharePoint Foundation 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "SharePoint Script in Username Vulnerability."
8071| [CVE-2012-1859] Cross-site scripting (XSS) vulnerability in scriptresx.ashx in Microsoft SharePoint Server 2010 Gold and SP1, SharePoint Foundation 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "XSS scriptresx.ashx Vulnerability."
8072| [CVE-2012-1857] Cross-site scripting (XSS) vulnerability in the Enterprise Portal component in Microsoft Dynamics AX 2012 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Dynamics AX Enterprise Portal XSS Vulnerability."
8073| [CVE-2012-1849] Untrusted search path vulnerability in Microsoft Lync 2010, 2010 Attendee, and 2010 Attendant allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .ocsmeet file, aka "Lync Insecure Library Loading Vulnerability."
8074| [CVE-2012-1545] Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, allows remote attackers to bypass Protected Mode or cause a denial of service (memory corruption) by leveraging access to a Low integrity process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012.
8075| [CVE-2012-1436] The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \2D\6C\68 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.
8076| [CVE-2012-1435] The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \50\4B\4C\49\54\45 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.
8077| [CVE-2012-1434] The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \19\04\00\10 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.
8078| [CVE-2012-1433] The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \4a\46\49\46 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.
8079| [CVE-2012-0447] Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize data for image/vnd.microsoft.icon images, which allows remote attackers to obtain potentially sensitive information by reading a PNG image that was created through conversion from an ICO image.
8080| [CVE-2012-0147] Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 does not properly configure the default web site, which allows remote attackers to obtain sensitive information via a crafted HTTPS request, aka "Unfiltered Access to UAG Default Website Vulnerability."
8081| [CVE-2012-0146] Open redirect vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka "UAG Blind HTTP Redirect Vulnerability."
8082| [CVE-2012-0145] Cross-site scripting (XSS) vulnerability in wizardlist.aspx in Microsoft Office SharePoint Server 2010 Gold and SP1 and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in wizardlist.aspx Vulnerability."
8083| [CVE-2012-0144] Cross-site scripting (XSS) vulnerability in themeweb.aspx in Microsoft Office SharePoint Server 2010 Gold and SP1 and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in themeweb.aspx Vulnerability."
8084| [CVE-2012-0138] Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0019, CVE-2012-0020, CVE-2012-0136, and CVE-2012-0137.
8085| [CVE-2012-0137] Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0019, CVE-2012-0020, CVE-2012-0136, and CVE-2012-0138.
8086| [CVE-2012-0136] Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0019, CVE-2012-0020, CVE-2012-0137, and CVE-2012-0138.
8087| [CVE-2012-0020] Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0019, CVE-2012-0136, CVE-2012-0137, and CVE-2012-0138.
8088| [CVE-2012-0019] Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0020, CVE-2012-0136, CVE-2012-0137, and CVE-2012-0138.
8089| [CVE-2012-0018] Microsoft Visio Viewer 2010 Gold and SP1 does not properly validate attributes in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "VSD File Format Memory Corruption Vulnerability."
8090| [CVE-2012-0017] Cross-site scripting (XSS) vulnerability in inplview.aspx in Microsoft SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in inplview.aspx Vulnerability."
8091| [CVE-2011-4695] Unspecified vulnerability in Microsoft Windows 7 SP1, when Java is installed, allows local users to bypass Internet Explorer sandbox restrictions and gain privileges via unknown vectors, as demonstrated by the White Phosphorus wp_ie_sandbox_escape module for Immunity CANVAS. NOTE: as of 20111207, this disclosure has no actionable information. However, because the module author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.
8092| [CVE-2011-2012] Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 does not properly validate session cookies, which allows remote attackers to cause a denial of service (IIS outage) via unspecified network traffic, aka "Null Session Cookie Crash."
8093| [CVE-2011-2010] The Microsoft Office Input Method Editor (IME) for Simplified Chinese in Microsoft Pinyin IME 2010, Office Pinyin SimpleFast Style 2010, and Office Pinyin New Experience Style 2010 does not properly restrict access to configuration options, which allows local users to gain privileges via the Microsoft Pinyin (aka MSPY) IME toolbar, aka "Pinyin IME Elevation Vulnerability."
8094| [CVE-2011-1969] Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 provides the MicrosoftClient.jar file containing a signed Java applet, which allows remote attackers to execute arbitrary code on client machines via unspecified vectors, aka "Poisoned Cup of Code Execution Vulnerability."
8095| [CVE-2011-1897] Cross-site scripting (XSS) vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Default Reflected XSS Vulnerability."
8096| [CVE-2011-1896] Cross-site scripting (XSS) vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "ExcelTable Reflected XSS Vulnerability."
8097| [CVE-2011-1895] CRLF injection vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary HTTP headers, and conduct HTTP response splitting attacks and cross-site scripting (XSS) attacks, via unspecified vectors, aka "ExcelTable Response Splitting XSS Vulnerability."
8098| [CVE-2011-1891] Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in a request to a script, aka "Contact Details Reflected XSS Vulnerability."
8099| [CVE-2011-1890] Cross-site scripting (XSS) vulnerability in EditForm.aspx in Microsoft Office SharePoint Server 2010 and SharePoint Foundation 2010 allows remote attackers to inject arbitrary web script or HTML via a post, aka "Editform Script Injection Vulnerability."
8100| [CVE-2011-1889] The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute arbitrary code via vectors involving unspecified requests, aka "TMG Firewall Client Memory Corruption Vulnerability."
8101| [CVE-2011-1417] Integer overflow in QuickLook, as used in Apple Mac OS X before 10.6.7 and MobileSafari in Apple iOS before 4.2.7 and 4.3.x before 4.3.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a Microsoft Office document with a crafted size field in the OfficeArtMetafileHeader, related to OfficeArtBlip, as demonstrated on the iPhone by Charlie Miller and Dion Blazakis during a Pwn2Own competition at CanSecWest 2011.
8102| [CVE-2011-1347] Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to bypass Protected Mode and create arbitrary files by leveraging access to a Low integrity process, as demonstrated by Stephen Fewer as the third of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011.
8103| [CVE-2011-1346] Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors, as demonstrated by Stephen Fewer as the second of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011.
8104| [CVE-2011-1345] Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, as demonstrated by Stephen Fewer as the first of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011, aka "Object Management Memory Corruption Vulnerability."
8105| [CVE-2011-1265] The Bluetooth Stack 2.1 in Microsoft Windows Vista SP1 and SP2 and Windows 7 Gold and SP1 does not prevent access to objects in memory that (1) were not properly initialized or (2) have been deleted, which allows remote attackers to execute arbitrary code via crafted Bluetooth packets, aka "Bluetooth Stack Vulnerability."
8106| [CVE-2011-0653] Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2010 Gold and SP1, and SharePoint Foundation 2010, allows remote attackers to inject arbitrary web script or HTML via the URI, aka "XSS in SharePoint Calendar Vulnerability."
8107| [CVE-2011-0647] The irccd.exe service in EMC Replication Manager Client before 5.3 and NetWorker Module for Microsoft Applications 2.1.x and 2.2.x allows remote attackers to execute arbitrary commands via the RunProgram function to TCP port 6542.
8108| [CVE-2011-0627] Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content, as possibly exploited in the wild in May 2011 by a Microsoft Office document with an embedded .swf file.
8109| [CVE-2011-0037] Microsoft Malware Protection Engine before 1.1.6603.0, as used in Microsoft Malicious Software Removal Tool (MSRT), Windows Defender, Security Essentials, Forefront Client Security, Forefront Endpoint Protection 2010, and Windows Live OneCare, allows local users to gain privileges via a crafted value of an unspecified user registry key.
8110| [CVE-2011-0027] Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, does not properly validate memory allocation for internal data structures, which allows remote attackers to execute arbitrary code, possibly via a large CacheSize property that triggers an integer wrap and a buffer overflow, aka "ADO Record Memory Vulnerability." NOTE: this might be a duplicate of CVE-2010-1117 or CVE-2010-1118.
8111| [CVE-2011-0026] Integer signedness error in the SQLConnectW function in an ODBC API (odbc32.dll) in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, allows remote attackers to execute arbitrary code via a long string in the Data Source Name (DSN) and a crafted szDSN argument, which bypasses a signed comparison and leads to a buffer overflow, aka "DSN Overflow Vulnerability."
8112| [CVE-2010-4643] Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Truevision TGA (TARGA) file in an ODF or Microsoft Office document.
8113| [CVE-2010-4253] Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file in an ODF or Microsoft Office document, as demonstrated by a PowerPoint (aka PPT) document.
8114| [CVE-2010-4121] ** DISPUTED ** The TCP-to-ODBC gateway in IBM Tivoli Provisioning Manager for OS Deployment 7.1.1.3 does not require authentication for SQL statements, which allows remote attackers to modify, create, or read database records via a session on TCP port 2020. NOTE: the vendor disputes this issue, stating that the "default Microsoft Access database is not password protected because it is intended to be used for evaluation purposes only."
8115| [CVE-2010-3967] Untrusted search path vulnerability in Microsoft Windows Movie Maker (WMM) 2.6 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a Movie Maker (MSWMM) file, aka "Insecure Library Loading Vulnerability."
8116| [CVE-2010-3962] Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token sequences and the clip attribute, aka an "invalid flag reference" issue or "Uninitialized Memory Corruption Vulnerability," as exploited in the wild in November 2010.
8117| [CVE-2010-3936] Cross-site scripting (XSS) vulnerability in Signurl.asp in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "XSS in Signurl.asp Vulnerability."
8118| [CVE-2010-3889] Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the wild in July 2010 by the Stuxnet worm, and identified by Microsoft researchers and other researchers.
8119| [CVE-2010-3888] Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the wild in July 2010 by the Stuxnet worm, and identified by Kaspersky Lab researchers and other researchers.
8120| [CVE-2010-3497] Symantec Norton AntiVirus 2011 does not properly interact with the processing of hcp:// URLs by the Microsoft Help and Support Center, which makes it easier for remote attackers to execute arbitrary code via malware that is correctly detected by this product, but with a detection approach that occurs too late to stop the code execution. NOTE: the researcher indicates that a vendor response was received, stating that this issue "falls into the work of our Firewall and not our AV (per our methodology of layers of defense)."
8121| [CVE-2010-3454] Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted typography information in a Microsoft Word .DOC file that triggers an out-of-bounds write.
8122| [CVE-2010-3453] The WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle an unspecified number of list levels in user-defined list styles in WW8 data in a Microsoft Word document, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted .DOC file that triggers an out-of-bounds write.
8123| [CVE-2010-3141] Untrusted search path vulnerability in Microsoft PowerPoint 2010 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse pptimpconv.dll that is located in the same folder as a .odp, .pot, .potm, .potx, .ppa, .pps, .ppsm, .ppsx, .ppt, .pptm, .pptx, .pwz, .sldm, or .sldx file.
8124| [CVE-2010-2743] The kernel-mode drivers in Microsoft Windows XP SP3 do not properly perform indexing of a function-pointer table during the loading of keyboard layouts from disk, which allows local users to gain privileges via a crafted application, as demonstrated in the wild in July 2010 by the Stuxnet worm, aka "Win32k Keyboard Layout Vulnerability." NOTE: this might be a duplicate of CVE-2010-3888 or CVE-2010-3889.
8125| [CVE-2010-2734] Cross-site scripting (XSS) vulnerability in the mobile portal in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "XSS Issue on UAG Mobile Portal Website in Forefront Unified Access Gateway Vulnerability."
8126| [CVE-2010-2733] Cross-site scripting (XSS) vulnerability in the Web Monitor in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "UAG XSS Allows EOP Vulnerability."
8127| [CVE-2010-2732] Open redirect vulnerability in the web interface in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka "UAG Redirection Spoofing Vulnerability."
8128| [CVE-2010-2564] Buffer overflow in Microsoft Windows Movie Maker (WMM) 2.1, 2.6, and 6.0 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted project file, aka "Movie Maker Memory Corruption Vulnerability."
8129| [CVE-2010-1184] The Microsoft wireless keyboard uses XOR encryption with a key derived from the MAC address, which makes it easier for remote attackers to obtain keystroke information and inject arbitrary commands via a nearby wireless device, as demonstrated by Keykeriki 2.
8130| [CVE-2010-1118] Unspecified vulnerability in Internet Explorer 8 on Microsoft Windows 7 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to a use-after-free issue, as demonstrated by Peter Vreugdenhil during a Pwn2Own competition at CanSecWest 2010.
8131| [CVE-2010-1117] Heap-based buffer overflow in Internet Explorer 8 on Microsoft Windows 7 allows remote attackers to discover the base address of a Windows .dll file, and possibly have unspecified other impact, via unknown vectors, as demonstrated by Peter Vreugdenhil during a Pwn2Own competition at CanSecWest 2010.
8132| [CVE-2010-0806] Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object, as exploited in the wild in March 2010, aka "Uninitialized Memory Corruption Vulnerability."
8133| [CVE-2010-0716] _layouts/Upload.aspx in the Documents module in Microsoft SharePoint before 2010 uses URLs with the same hostname and port number for a web site's primary files and individual users' uploaded files (aka attachments), which allows remote authenticated users to leverage same-origin relationships and conduct cross-site scripting (XSS) attacks by uploading TXT files, a related issue to CVE-2008-5026. NOTE: the vendor disputes the significance of this issue, because cross-domain isolation can be implemented when needed.
8134| [CVE-2009-3555] The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.
8135| [CVE-2008-5750] Argument injection vulnerability in Microsoft Internet Explorer 8 beta 2 on Windows XP SP3 allows remote attackers to execute arbitrary commands via the --renderer-path option in a chromehtml: URI.
8136| [CVE-2008-5556] ** DISPUTED ** The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 does not recognize attack patterns designed to operate against web pages that are encoded with utf-7, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting crafted utf-7 content. NOTE: the vendor reportedly disputes this issue, stating "Behaviour is by design."
8137| [CVE-2008-5555] Microsoft Internet Explorer 8.0 Beta 2 relies on the XDomainRequestAllowed HTTP header to authorize data exchange between domains, which allows remote attackers to bypass the product's XSS Filter protection mechanism, and conduct XSS and cross-domain attacks, by injecting this header after a CRLF sequence, related to "XDomainRequest Allowed Injection (XAI)." NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
8138| [CVE-2008-5554] The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 does not properly handle some HTTP headers that appear after a CRLF sequence in a URI, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS or redirection attacks, as demonstrated by the (1) Location and (2) Set-Cookie HTTP headers. NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
8139| [CVE-2008-5553] The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 disables itself upon encountering a certain X-XSS-Protection HTTP header, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting this header after a CRLF sequence. NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
8140| [CVE-2008-5552] The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks via a CRLF sequence in conjunction with a crafted Content-Type header, as demonstrated by a header with a utf-7 charset value. NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
8141| [CVE-2008-5551] The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting data at two different positions within an HTML document, related to STYLE elements and the CSS expression property, aka a "double injection."
8142| [CVE-2008-5180] Microsoft Communicator, and Communicator in Microsoft Office 2010 beta, allows remote attackers to cause a denial of service (memory consumption) via a large number of SIP INVITE requests, which trigger the creation of many sessions.
8143| [CVE-2008-4211] Integer signedness error in (1) QuickLook in Apple Mac OS X 10.5.5 and (2) Office Viewer in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted Microsoft Excel file that triggers an out-of-bounds memory access, related to "handling of columns."
8144| [CVE-2007-5351] Unspecified vulnerability in Server Message Block Version 2 (SMBv2) signing support in Microsoft Windows Vista allows remote attackers to force signature re-computation and execute arbitrary code via a crafted SMBv2 packet, aka "SMBv2 Signing Vulnerability."
8145| [CVE-2007-2729] Comodo Firewall Pro 2.4.18.184 and Comodo Personal Firewall 2.3.6.81, and probably older Comodo Firewall versions, do not properly test for equivalence of process identifiers for certain Microsoft Windows API functions in the NT kernel 5.0 and greater, which allows local users to call these functions, and bypass firewall rules or gain privileges, via a modified identifier that is one, two, or three greater than the canonical identifier.
8146| [CVE-2007-1534] DFSR.exe in Windows Meeting Space in Microsoft Windows Vista remains available for remote connections on TCP port 5722 for 2 minutes after Windows Meeting Space is closed, which allows remote attackers to have an unknown impact by connecting to this port during the time window.
8147| [CVE-2007-0341] Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.1 and earlier, when Microsoft Internet Explorer 6 is used, allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in a CSS style in the convcharset parameter to the top-level URI, a different vulnerability than CVE-2005-0992.
8148| [CVE-2006-5559] The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the second argument is a BSTR, which allows remote attackers to cause a denial of service (Internet Explorer crash) and possibly execute arbitrary code via certain strings in the second and third arguments.
8149| [CVE-2006-4686] Buffer overflow in the Extensible Stylesheet Language Transformations (XSLT) processing in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 allows remote attackers to execute arbitrary code via a crafted Web page.
8150| [CVE-2006-4685] The XMLHTTP ActiveX control in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 does not properly handle HTTP server-side redirects, which allows remote user-assisted attackers to access content from other domains.
8151| [CVE-2006-1359] Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer.
8152| [CVE-2006-0761] Buffer overflow in BlackBerry Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server 2.2 and 4.0 before SP3 Hotfix 4 for IBM Lotus Domino, 3.6 before SP7 and 5.0 before SP3 Hotfix 3 for Microsoft Exchangem, and 4.0 for Novell GroupWise before SP3 Hotfix 1 might allow user-assisted remote attackers to execute arbitrary code on the server via a crafted Microsoft Word document that is opened on a wireless device.
8153| [CVE-2006-0753] Memory leak in Microsoft Internet Explorer 6 for Windows XP Service Pack 2 allows remote attackers to cause a denial of service (memory consumption) via JavaScript that uses setInterval to repeatedly call a function to set the value of window.status.
8154| [CVE-2006-0544] urlmon.dll in Microsoft Internet Explorer 7.0 beta 2 (aka 7.0.5296.0) allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a BGSOUND element with its SRC attribute set to "file://" followed by a large number of "-" (dash of hyphen) characters.
8155| [CVE-2006-0003] Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and distributed in Microsoft Data Access Components (MDAC) 2.7 and 2.8, allows remote attackers to execute arbitrary code via unknown attack vectors.
8156| [CVE-2005-1929] Multiple heap-based buffer overflows in (1) isaNVWRequest.dll and (2) relay.dll in Trend Micro ServerProtect Management Console 5.58 and earlier, as used in Control Manager 2.5 and 3.0 and Damage Cleanup Server 1.1, allow remote attackers to execute arbitrary code via "wrapped" length values in Chunked transfer requests. NOTE: the original report suggests that the relay.dll issue is related to a problem in which a Microsoft Foundation Classes (MFC) static library returns invalid values under heavy load. As such, this might not be a vulnerability in Trend Micro's product.
8157| [CVE-2005-0852] Microsoft Windows XP SP1 allows local users to cause a denial of service (system crash) via an empty datagram to a raw IP over IP socket (IP protocol 4), as originally demonstrated using code in Python 2.3.
8158| [CVE-2004-1322] Cisco Unity 2.x, 3.x, and 4.x, when integrated with Microsoft Exchange, has several hard coded usernames and passwords, which allows remote attackers to gain unauthorized access and change configuration settings or read outgoing or incoming e-mail messages.
8159| [CVE-2003-1306] Microsoft URLScan 2.5, with the RemoveServerHeader option enabled, allows remote attackers to obtain sensitive information (server name and version) via an HTTP request that generates certain errors such as 400 "Bad Request," which leak the Server header in the response.
8160| [CVE-2003-0903] Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request.
8161| [CVE-2003-0353] Buffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary code via a long response to a broadcast request to UDP port 1434.
8162| [CVE-2002-1918] Buffer overflow in Microsoft Active Data Objects (ADO) in Microsoft MDAC 2.5 through 2.7 allows remote attackers to have unknown impact with unknown attack vectors. NOTE: due to the lack of details available regarding this issue, perhaps it should be REJECTED.
8163| [CVE-2002-1142] Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.
8164| [CVE-2002-1015] RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to execute arbitrary script in the Local computer zone by inserting the script into the skin.ini file of an RJS archive, then referencing skin.ini from a web page after it has been extracted, which is parsed as HTML by Internet Explorer or other Microsoft-based web readers.
8165| [CVE-2002-0697] Microsoft Metadirectory Services (MMS) 2.2 allows remote attackers to bypass authentication and modify sensitive data by using an LDAP client to directly connect to MMS and bypass the checks for MMS credentials.
8166| [CVE-2002-0057] XMLHTTP control in Microsoft XML Core Services 2.6 and later does not properly handle IE Security Zone settings, which allows remote attackers to read arbitrary files by specifying a local file as an XML Data Source.
8167| [CVE-2001-1218] Microsoft Internet Explorer for Unix 5.0SP1 allows local users to possibly cause a denial of service (crash) in CDE or the X server on Solaris 2.6 by rapidly scrolling Chinese characters or maximizing the window.
8168| [CVE-2000-0563] The URLConnection function in MacOS Runtime Java (MRJ) 2.1 and earlier and the Microsoft virtual machine (VM) for MacOS allows a malicious web site operator to connect to arbitrary hosts using a HTTP redirection, in violation of the Java security model.
8169| [CVE-1999-1097] Microsoft NetMeeting 2.1 allows one client to read the contents of another client's clipboard via a CTRL-C in the chat box when the box is empty.
8170|
8171| SecurityFocus - https://www.securityfocus.com/bid/:
8172| [83154] Microsoft Windows 2000 Server CVE-2004-0540 Remote Security Vulnerability
8173| [45297] Microsoft Exchange Server 2007 Infinite Loop Remote Denial of Service Vulnerability
8174| [43419] Microsoft Excel 2002 Memory Corruption Vulnerability
8175| [43189] Microsoft Visual C++ 2008 Redistributable Package DLL Loading Arbitrary Code Execution Vulnerability
8176| [42742] Microsoft PowerPoint 2007 Multiple DLL Loading Arbitrary Code Execution Vulnerability
8177| [42695] Microsoft Groove 2007 'mso.dll' DLL Loading Arbitrary Code Execution Vulnerability
8178| [42681] Microsoft Visio 2003 'mfc71enu.dll' DLL Loading Arbitrary Code Execution Vulnerability
8179| [41843] Microsoft Outlook Web Access for Exchange Server 2003 Cross Site Request Forgery Vulnerability
8180| [39776] Microsoft SharePoint Server 2007 '_layouts/help.aspx' Cross Site Scripting Vulnerability
8181| [37196] RETIRED: Microsoft December 2009 Advance Notification Multiple Vulnerabilities
8182| [36940] RETIRED: Microsoft November 2009 Advance Notification Multiple Vulnerabilities
8183| [36633] RETIRED: Microsoft October 2009 Advance Notification Multiple Vulnerabilities
8184| [36239] RETIRED: Microsoft September 2009 Advance Notification Multiple Vulnerabilities
8185| [35974] RETIRED: Microsoft August 2009 Advance Notification Multiple Vulnerabilities
8186| [35617] RETIRED: Microsoft July 2009 Advance Notification Multiple Vulnerabilities
8187| [35213] RETIRED: Microsoft June 2009 Advance Notification Multiple Vulnerabilities
8188| [34867] RETIRED: Microsoft May 2009 Advance Notification Multiple Vulnerabilities
8189| [34532] Microsoft IAG 2007 ActiveX Control Multiple Stack Based Buffer Overflow Vulnerabilities
8190| [34469] Microsoft Word 2000 WordPerfect Converter Remote Code Execution Vulnerability
8191| [34450] RETIRED: Microsoft April 2009 Advance Notification Multiple Vulnerabilities
8192| [34005] RETIRED: Microsoft March 2009 Advance Notification Multiple Vulnerabilities
8193| [33639] RETIRED: Microsoft February 2009 Advance Notification Multiple Vulnerabilities
8194| [33170] RETIRED: Microsoft January 2009 Advance Notification Multiple Vulnerabilities
8195| [32632] RETIRED: Microsoft December 2008 Advance Notification Multiple Vulnerabilities
8196| [32153] Retired: Microsoft November 2008 Advance Notification Multiple Vulnerabilities
8197| [31667] Retired: Microsoft October 2008 Advance Notification Multiple Vulnerabilities
8198| [31129] RETIRED: Microsoft SQL Server 2000 'sqlvdir.dll' ActiveX Buffer Overflow Vulnerability
8199| [31014] RETIRED: Microsoft September 2008 Advance Notification Multiple Vulnerabilities
8200| [30593] RETIRED: Microsoft August 2008 Advance Notification Multiple Vulnerabilities
8201| [30075] RETIRED: Microsoft July 2008 Advance Notification Multiple Vulnerabilities
8202| [29576] RETIRED: Microsoft June 2008 Advance Notification Multiple Vulnerabilities
8203| [29108] RETIRED: Microsoft May 2008 Advance Notification Multiple Vulnerabilities
8204| [28598] RETIRED: Microsoft April 2008 Advance Notification Multiple Vulnerabilities
8205| [28124] Retired: Microsoft March 2008 Advance Notification Multiple Vulnerabilities
8206| [27674] RETIRED: Microsoft February 2008 Advance Notification Multiple Vulnerabilities
8207| [27119] RETIRED: Microsoft January 2008 Advance Notification Multiple Vulnerabilities
8208| [26739] RETIRED: Microsoft December 2007 Advance Notification Multiple Vulnerabilities
8209| [26414] Microsoft Forms 2.0 ActiveX Control Memory Access Violation Denial of Service Vulnerabilities
8210| [26380] Retired: Microsoft November 2007 Advance Notification Multiple Vulnerabilities
8211| [25991] RETIRED: Microsoft Office 2000 and XP Unspecified Word Document Handling DoS Vulnerability
8212| [25922] RETIRED: Microsoft October 2007 Advance Notification Multiple Vulnerabilities
8213| [25573] RETIRED: Microsoft September 2007 Advance Notification Multiple Vulnerabilities
8214| [25247] Retired: Microsoft August 2007 Advance Notification Multiple Vulnerabilities
8215| [24771] Retired: Microsoft July 2007 Advance Notification Multiple Vulnerabilities
8216| [24366] RETIRED: Microsoft June 2007 Advance Notification Multiple Vulnerabilities
8217| [24118] Microsoft Office 2000 UA OUACTRL.OCX ActiveX Control Buffer Overflow Vulnerability
8218| [23800] RETIRED: Microsoft May 2007 Advance Notification Multiple Vulnerabilities
8219| [23380] Microsoft Word 2007 WWLib.DLL Unspecified Document File Buffer Overflow Vulnerability
8220| [23335] RETIRED: Microsoft April 2007 Advance Notification Multiple Vulnerabilities
8221| [22716] Microsoft Office 2003 Denial of Service Vulnerability
8222| [22567] Microsoft Word 2000/2002 Document Stream Remote Code Execution Vulnerability
8223| [22328] RETIRED: Microsoft Word 2003 Unspecified Code Execution Vulnerability
8224| [22225] Microsoft Word 2000 Malformed Function Code Execution Vulnerability
8225| [21611] Microsoft Project Server 2003 PDSRequest.ASP XML Request Information Disclosure Vulnerability
8226| [21495] Microsoft Windows 2000 Remote Installation Service Remote Code Execution Vulnerability
8227| [20843] Microsoft Visual Studio 2005 WMI Object Broker Remote Code Execution Vulnerability
8228| [19636] Microsoft Windows 2000 Multiple COM Object Instantiation Code Execution Vulnerabilities
8229| [19388] Microsoft Windows 2000 Kernel Local Privilege Escalation Vulnerability
8230| [17134] Microsoft Commerce Server 2002 Authentication Bypass Vulnerability
8231| [16634] Microsoft PowerPoint 2000 Remote Information Disclosure Vulnerability
8232| [14772] Microsoft Exchange Server 2003 Exchange Information Store Denial Of Service Vulnerability
8233| [14093] Microsoft Update Rollup 1 for Windows 2000 SP4 Released - Multiple Vulnerabilities Fixed
8234| [13564] Microsoft SQL Server 2000 Multiple Vulnerabilities
8235| [13008] Microsoft Windows Server 2003 SMB Redirector Local Denial Of Service Vulnerability
8236| [12972] Microsoft Windows Server 2003 Service Pack 1 Released - Multiple Vulnerabilities Fixed
8237| [12913] Microsoft Outlook 2002 Connector For IBM Lotus Domino Policy Bypass Vulnerability
8238| [12824] Microsoft InfoPath 2003 Insecure Information Storage Vulnerability
8239| [12641] Microsoft Windows 2000 Group Policy Bypass Vulnerability
8240| [12141] Microsoft FrontPage 2000 Internet Publishing Service Provider DAV File Upload Vulnerability
8241| [11820] Microsoft Windows 2000 Resource Kit W3Who.DLL Multiple Remote Vulnerabilities
8242| [11446] Microsoft Outlook 2003 Security Policy Bypass Vulnerability
8243| [11387] Microsoft Windows 2003 Services Default SACL Access Right Weakness
8244| [10901] Microsoft Windows 2000/XP CRL File Failed Integrity Check Denial Of Service Vulnerability
8245| [10693] Microsoft Windows 2000 Media Player Control Media Preview Script Execution Vulnerability
8246| [10484] Microsoft ISA Server 2000 FTP Bounce Filtering Vulnerability
8247| [10480] Microsoft ISA Server 2000 Site And Content Rule Bypass Vulnerability
8248| [10440] Microsoft Windows 2000 Domain Expired Account Security Policy Violation Weakness
8249| [10369] Microsoft Outlook 2003 Media File Script Execution Vulnerability
8250| [10307] Microsoft Outlook 2003 Predictable File Location Weakness
8251| [10114] Microsoft Windows 2000 Domain Controller LDAP Denial Of Service Vulnerability
8252| [9409] Microsoft Exchange Server 2003 Outlook Web Access Random Mailbox Access Vulnerability
8253| [9408] Microsoft ISA Server 2000 H.323 Filter Remote Buffer Overflow Vulnerability
8254| [9118] Microsoft Exchange Server 2003 Outlook Web Access Lowered Security Settings Weakness
8255| [8833] Microsoft Windows 2000 TroubleShooter ActiveX Control Buffer Overflow Vulnerability
8256| [8522] Multiple Microsoft Windows 2003 Stack Protection Implementation Weaknesses
8257| [8397] Microsoft Windows 2000 Subnet Bandwidth Manager RSVP Server Authority Hijacking Vulnerability
8258| [8104] Microsoft Windows 2000 Unauthorized RPC Connection Weakness
8259| [8098] Microsoft Windows 2000 Terminal Services Named Pipe System Account Access Vulnerability
8260| [8093] Microsoft Windows 2000 Active Directory Forest Origin Validation Vulnerability
8261| [8090] Microsoft Windows 2000 ShellExecute() Buffer Overflow Vulnerability
8262| [8089] Microsoft Windows 2000 Unspecified Cryptnet.DLL Memory Leakage Vulnerability
8263| [8086] Microsoft Windows 2000 Port Name Buffers Potential Buffer Overflow Vulnerability
8264| [8085] Microsoft Windows 2000 ModifyDN Request Denial of Service Vulnerability
8265| [8083] Microsoft Windows 2000 Domain Controller Spoofing Vulnerability
8266| [8081] Microsoft Windows 2000 USBH_IoctlGetNodeConnectionDriverKeyName Information Disclosure Vulnerability
8267| [8063] Microsoft Commerce Server 2002 Weak Registry Key Permissions Weakness
8268| [8045] Microsoft Windows 2000 SP4 Released - Multiple Vulnerabilities Fixed
8269| [7930] Microsoft Windows 2000 Active Directory Remote Stack Overflow Vulnerability
8270| [7788] Microsoft Windows 2000/XP/2003 IPV6 ICMP Flood Denial Of Service Vulnerability
8271| [7469] Microsoft BizTalk Server 2002 HTTP Receiver Buffer Overflow Vulnerability
8272| [7360] Microsoft Windows 2000/XP Registry Editor Custom Permissions Weakness
8273| [7102] Microsoft Windows 2000 Help Facility .CNT File :Link Buffer Overflow Vulnerability
8274| [6769] Microsoft Windows 2000 RPC Service Privilege Escalation Vulnerability
8275| [6766] Microsoft Windows 2000 NetBIOS Continuation Packets Kernel Memory Leak Vulnerability
8276| [6667] Microsoft Outlook 2002 V1 Exchange Server Security Certificate Information Leakage Vulnerability
8277| [6319] Microsoft Outlook 2002 Email Header Processing Denial of Service Vulnerability
8278| [6030] Microsoft Windows 2000 SNMP Printer Query Denial of Service Vulnerability
8279| [5972] Microsoft Windows 2000/XP Full Event Log Administrative Alert Weakness
8280| [5922] Microsoft Content Management Server 2001 Cross-Site Scripting Vulnerability
8281| [5480] Microsoft Windows 2000 Network Connection Manager Privilege Elevation Vulnerability
8282| [5422] Microsoft Content Management Server 2001 SQL Injection Vulnerability
8283| [5421] Microsoft Content Management Server 2001 Arbitrary Upload Location Vulnerability
8284| [5420] Microsoft Content Management Server 2001 User Authentication Buffer Overflow Vulnerability
8285| [5415] Microsoft Windows 2000 Insecure Default File Permissions Vulnerability
8286| [5413] Microsoft Exchange 2000 Post Authorization License Exhaustion Denial Of Service Vulnerability
8287| [5412] Microsoft Exchange 2000 Multiple MSRPC Denial Of Service Vulnerabilities
8288| [5312] Microsoft SQL Server 2000 Resolution Service Denial of Service Vulnerability
8289| [5311] Microsoft SQL Server 2000 Resolution Service Stack Overflow Vulnerability
8290| [5310] Microsoft SQL Server 2000 Resolution Service Heap Overflow Vulnerability
8291| [5309] Microsoft SQL Server 2000 sp_MScopyscript SQL Injection Vulnerability
8292| [5307] Microsoft SQL Server 2000 Database Consistency Checkers Buffer Overflow Vulnerability
8293| [5253] Microsoft Windows 2000 Narrator Password Disclosure Vulnerability
8294| [5205] Microsoft SQL Server 2000 Incorrect Registry Key Permissions Vulnerability
8295| [5111] Microsoft Commerce Server 2000 OWC Package Installer Local Command Execution Vulnerability
8296| [5014] Microsoft SQL Server 2000 Password Encrypt Procedure Buffer Overflow Vulnerability
8297| [4881] Microsoft Exchange 2000 Malformed Mail Attribute DoS Vulnerability
8298| [4853] Microsoft Commerce Server 2000 Profile Service Buffer Overflow Vulnerability
8299| [4852] Microsoft Windows 2000 Remote Access Service Buffer Overflow Vulnerability
8300| [4847] Microsoft SQL Server 2000 Bulk Insert Procedure Buffer Overflow Vulnerability
8301| [4797] Microsoft MSDE/SQL Server 2000 Desktop Engine Default Configuration Vulnerability
8302| [4683] Microsoft Windows 2000 / NT Path Precedence Vulnerability
8303| [4532] Microsoft Windows 2000 Lanman Denial of Service Vulnerability
8304| [4438] Microsoft Windows 2000 Group Policy Evasion Vulnerability
8305| [4426] Microsoft Windows 2000 / NT / XP MUP UNC Request Buffer Overflow Vulnerability
8306| [4287] Microsoft Windows 2000 / NT 4.0 Process Handle Local Privilege Elevation Vulnerability
8307| [4256] Microsoft Windows 2000 Password Policy Bypass Vulnerability
8308| [4157] Microsoft Commerce Server 2000 ISAPI Buffer Overflow Vulnerability
8309| [4095] Microsoft Windows 2000 Server Terminal Services Failure To Lock Terminal Vulnerability
8310| [3652] Microsoft Windows 2000 Internet Key Exchange DoS Vulnerability
8311| [3481] Microsoft Windows 2000/XP GDI Denial of Service Vulnerability
8312| [3479] Microsoft Windows 2000 NTFS With Macintosh Client Directory Permission Vulnerability
8313| [3445] Microsoft Windows 2000/NT Terminal Server Service RDP DoS Vulnerability
8314| [3339] Microsoft Index Server 2.0 File Information and Path Disclosure Vulnerability
8315| [3305] Norton AntiVirus for Microsoft Exchange 2000 Information Disclosure Vulnerability
8316| [3291] Microsoft Windows 2000 RunAs Service Denial of Services Vulnerability
8317| [3215] Microsoft Windows 2000 IrDA Buffer Overflow Denial of Service Vulnerability
8318| [3185] Microsoft Windows 2000 RunAs Service Named Pipe Hijacking Vulnerability
8319| [3184] Microsoft Windows 2000 RunAs User Credentials Exposure Vulnerability
8320| [3146] Microsoft Windows 2000 System File Replacement Vulnerability
8321| [3115] Microsoft Windows NT and 2000 Command Prompt Reboot Vulnerability
8322| [3063] Microsoft Windows 2000 Unauthorized Password Change Vulnerability
8323| [3033] Microsoft Windows 2000 Task Manager Process Termination Vulnerability
8324| [2988] Microsoft Windows 2000 SMTP Improper Authentication Vulnerability
8325| [2929] Microsoft Windows 2000 LDAP SSL Password Modification Vulnerability
8326| [2849] Microsoft Windows 2000 Telnet Privilege Escalation Vulnerability
8327| [2846] Microsoft Windows 2000 Telnet System Call DoS Vulnerability
8328| [2844] Microsoft Windows 2000 Telnet Service DoS Vulnerability
8329| [2843] Microsoft Windows 2000 Telnet Multiple Sessions DoS Vulnerability
8330| [2838] Microsoft Windows 2000 Telnet Username DoS Vulnerability
8331| [2460] Microsoft Windows 2000 Event Viewer Buffer Overflow Vulnerability
8332| [2441] Microsoft Exchange 2000 / IIS 5.0 Multiple Invalid URL Request DoS Vulnerability
8333| [2394] Microsoft Windows 2000 Domain Controller DoS Vulnerability
8334| [2341] Microsoft Windows 2000 Network DDE Escalated Privileges Vulnerability
8335| [2326] Microsoft Windows 2000 RDP DoS Vulnerability
8336| [2133] Microsoft Windows 2000 Directory Services Restore Mode Blank Password Vulnerability
8337| [2066] Microsoft Windows NT 4.0 / 2000 SNMP Registry Key Modification Vulnerability
8338| [2018] Microsoft Windows 2000 Telnet Session Timeout DoS Vulnerability
8339| [2007] Microsoft Windows 2000 DNS Memory Leak Vulnerability
8340| [1973] Microsoft Windows 2000 Domain Account Lockout Bypass Vulnerability
8341| [1958] Microsoft Exchange 2000 Server EUSR_EXSTOREEVENT Account Vulnerability
8342| [1933] Microsoft Indexing Services for Windows 2000 File Verification Vulnerability
8343| [1899] Microsoft Windows 2000 ActiveX Control Buffer Overflow Vulnerability
8344| [1811] Microsoft Site Server 2.0 with IIS 4.0 Malicious File Upload Vulnerability
8345| [1758] Microsoft Windows 2000 Unattended Install OEMPreinstall Vulnerability
8346| [1753] Microsoft Windows NT 4.0 / 2000 Spoofed LPC Request Vulnerability
8347| [1748] Microsoft Windows NT 4.0 / 2000 Predictable LPC Message Identifier Multiple Vulnerabilities
8348| [1745] Microsoft Windows NT 4.0 / 2000 LPC Zone Memory Depletion DoS Vulnerability
8349| [1729] Microsoft Windows 2000 Simplified Chinese IME Vulnerability
8350| [1695] Microsoft Proxy 2.0 FTP Permissions Bypass Vulnerability
8351| [1692] Microsoft Proxy 2.0 Internal Network Access Vulnerability
8352| [1683] Microsoft Windows 2000 telnet.exe NTLM Authentication Vulnerability
8353| [1673] Microsoft Windows 2000 Malformed RPC Packet DoS Vulnerability
8354| [1651] Microsoft Windows 2000 Still Image Service Privilege Escalation Vulnerability
8355| [1632] Microsoft Windows 98 / NT 4.0 / 2000 File Extension Validation Vulnerability
8356| [1620] Microsoft Windows 9x / NT 4.0 / 2000 NetBIOS Cache Corruption Vulnerability
8357| [1613] Microsoft Windows 2000 Local Security Policy Corruption Vulnerability
8358| [1566] Microsoft Word 97 / 2000 Mail Merge Code Execution Vulnerability
8359| [1561] Microsoft Word / Excel / Powerpoint 2000 Object Tag Buffer Overflow Vulnerability
8360| [1535] Microsoft Windows 2000 Named Pipes Predictability Vulnerability
8361| [1507] Microsoft Windows NT 4.0 / 2000 Unspecified Executable Path Vulnerability
8362| [1451] Microsoft Excel 97 / 2000 Register.ID Vulnerability
8363| [1435] Microsoft FrontPage 2000 Server Extensions Denial Of Service Vulnerability
8364| [1415] Microsoft Windows 2000 Remote CPU-overload Vulnerability
8365| [1414] Microsoft Windows 2000 Telnet Server DoS Vulnerability
8366| [1399] Microsoft Internet Explorer 5.01 and Excel/Powerpoint 2000 ActiveX Object Execution Vulnerability
8367| [1398] Microsoft Internet Explorer 5.01 and Access 2000 / 97 VBA Code Execution Vulnerability
8368| [1350] Microsoft Windows 2000 Windows Station Access Vulnerability
8369| [1304] Microsoft Windows NT 4.0 / 2000 SMB Write Request DoS Vulnerability
8370| [1301] Microsoft Windows NT 4.0 / 2000 Ignored SMB Response DoS Vulnerability
8371| [1295] Microsoft Windows 2000 Default 40-bit Encrypted Protected Store Vulnerability
8372| [1198] Microsoft Windows 2000 Default SYSKEY Configuration Vulnerability
8373| [1197] Microsoft Office 2000 UA Control Vulnerability
8374| [990] Microsoft Windows 2000 Install Unprotected ADMIN$ Share Vulnerability
8375| [945] Microsoft SMS 2.0 Default Permissions Vulnerability
8376| [539] Microsoft Windows 2000 EFS Vulnerability
8377| [180] Microsoft Windows April Fools 2001 Vulnerability
8378| [71487] Microsoft December 2014 Advance Notification Multiple Vulnerabilities
8379| [70966] RETIRED: Microsoft November 2014 Advance Notification Multiple Vulnerabilities
8380| [70367] RETIRED: Microsoft October 2014 Advance Notification Multiple Vulnerabilities
8381| [69636] RETIRED: Microsoft September 2014 Advance Notification Multiple Vulnerabilities
8382| [69108] Microsoft August 2014 Advance Notification Multiple Vulnerabilities
8383| [68367] Microsoft July 2014 Advance Notification Multiple Vulnerabilities
8384| [67905] Microsoft June 2014 Advance Notification Multiple Vulnerabilities
8385| [67298] Microsoft May 2014 Advance Notification Multiple Vulnerabilities
8386| [66639] RETIRED: Microsoft April 2014 Advance Notification Multiple Vulnerabilities
8387| [66016] Microsoft March 2014 Notification Multiple Vulnerabilities
8388| [65426] Microsoft February 2014 Notification Multiple Vulnerabilities
8389| [64757] RETIRED: Microsoft January 2014 Advance Notification Multiple Vulnerabilities
8390| [64083] RETIRED: Microsoft December 2013 Advance Notification Multiple Vulnerabilities
8391| [63604] RETIRED: Microsoft November 2013 Advance Notification Multiple Vulnerabilities
8392| [62797] RETIRED: Microsoft October 2013 Advance Notification Multiple Vulnerabilities
8393| [62228] RETIRED: Microsoft September 2013 Advance Notification Multiple Vulnerabilities
8394| [62181] Microsoft Office Pinyin IME 2010 CVE-2013-3859 Local Privilege Escalation Vulnerability
8395| [61686] Microsoft August 2013 Advance Notification Multiple Vulnerabilities
8396| [60960] RETIRED: Microsoft July 2013 Advance Notification Multiple Vulnerabilities
8397| [60394] Microsoft June 2013 Advance Notification Multiple Vulnerabilities
8398| [59785] RETIRED: Microsoft May 2013 Advance Notification Multiple Vulnerabilities
8399| [58881] RETIRED: Microsoft April 2013 Advance Notification Multiple Vulnerabilities
8400| [58380] RETIRED: Microsoft March 2013 Advance Notification Multiple Vulnerabilities
8401| [57846] RETIRED: Microsoft February 2013 Advance Notification Multiple Vulnerabilities
8402| [57137] RETIRED: Microsoft January 2013 Advance Notification Multiple Vulnerabilities
8403| [56838] RETIRED: Microsoft December 2012 Advance Notification Multiple Vulnerabilities
8404| [56450] RETIRED: Microsoft November 2012 Advance Notification Multiple Vulnerabilities
8405| [56304] Microsoft Office Excel 2010 Memory Corruption Denial of Service Vulnerability
8406| [55794] RETIRED: Microsoft October 2012 Advance Notification Multiple Vulnerabilities
8407| [55472] RETIRED: Microsoft September 2012 Advance Notification Multiple Vulnerabilities
8408| [54944] RETIRED: Microsoft August 2012 Advance Notification Multiple Vulnerabilities
8409| [54318] RETIRED: Microsoft July 2012 Advance Notification Multiple Vulnerabilities
8410| [53862] RETIRED: Microsoft June 2012 Advance Notification Multiple Vulnerabilities
8411| [53372] RETIRED: Microsoft May 2012 Advance Notification Multiple Vulnerabilities
8412| [52910] RETIRED: Microsoft April 2012 Advance Notification Multiple Vulnerabilities
8413| [52366] RETIRED: Microsoft March 2012 Advance Notification Multiple Vulnerabilities
8414| [51944] RETIRED: Microsoft February 2012 Advance Notification Multiple Vulnerabilities
8415| [51289] RETIRED: Microsoft January 2012 Advance Notification Multiple Vulnerabilities
8416| [50980] RETIRED: Microsoft December 2011 Advance Notification Multiple Vulnerabilities
8417| [50513] RETIRED: Microsoft November 2011 Advance Notification Multiple Vulnerabilities
8418| [49994] RETIRED: Microsoft October 2011 Advance Notification Multiple Vulnerabilities
8419| [49515] RETIRED: Microsoft September 2011 Advance Notification Multiple Vulnerabilities
8420| [49017] RETIRED: Microsoft August 2011 Advance Notification Multiple Vulnerabilities
8421| [48616] RETIRED: Microsoft July 2011 Advance Notification Multiple Vulnerabilities
8422| [48235] Microsoft Lync Server 2010 'ReachJoin.aspx' Remote Command Injection Vulnerability
8423| [48193] RETIRED: Microsoft June 2011 Advance Notification Multiple Vulnerabilities
8424| [47725] RETIRED: Microsoft May 2011 Advance Notification Multiple Vulnerabilities
8425| [47255] RETIRED: Microsoft April 2011 Advance Notification Multiple Vulnerabilities
8426| [46675] RETIRED: Microsoft March 2011 Advance Notification Multiple Vulnerabilities
8427| [46132] RETIRED: Microsoft February 2011 Advance Notification Multiple Vulnerabilities
8428| [45696] RETIRED: Microsoft January 2011 Advance Notification Multiple Vulnerabilities
8429| [45307] RETIRED: Microsoft December 2010 Advance Notification Multiple Vulnerabilities
8430| [44649] RETIRED: Microsoft November 2010 Advance Notification Multiple Vulnerabilities
8431| [43831] RETIRED: Microsoft October 2010 Advance Notification Multiple Vulnerabilities
8432| [43115] RETIRED: Microsoft September 2010 Advance Notification Multiple Vulnerabilities
8433| [42234] RETIRED: Microsoft August 2010 Advance Notification Multiple Vulnerabilities
8434| [41474] RETIRED: Microsoft July 2010 Advance Notification Multiple Vulnerabilities
8435| [40548] RETIRED: Microsoft June 2010 Advance Notification Multiple Vulnerabilities
8436| [39961] RETIRED: Microsoft May 2010 Advance Notification Multiple Vulnerabilities
8437| [39313] RETIRED: Microsoft April 2010 Advance Notification Multiple Vulnerabilities
8438| [38540] RETIRED: Microsoft March 2010 Advance Notification Multiple Vulnerabilities
8439| [38096] RETIRED: Microsoft February 2010 Advance Notification Multiple Vulnerabilities
8440| [37887] RETIRED: Microsoft January 2010 Advance Notification Multiple Vulnerabilities
8441| [37664] RETIRED: Microsoft January 2010 Advance Notification Multiple Vulnerabilities
8442| [32642] Microsoft Word RTF Malformed Control Word Variant 2 Remote Code Execution Vulnerability
8443|
8444| IBM X-Force - https://exchange.xforce.ibmcloud.com:
8445| [82417] Microsoft Windows Knowledge Base Article 2801261 update is not installed
8446| [82415] Microsoft Windows Knowledge Base Article 2807986 update is not installed
8447| [82410] Microsoft Windows Knowledge Base Article 2809289 update is not installed
8448| [81859] Microsoft Windows Knowledge Base Article 2802968 update is not installed
8449| [81857] Microsoft Windows Knowledge Base Article 2809279 update is not installed
8450| [81668] Microsoft Windows Knowledge Base Article 2800277 update is not installed
8451| [77323] Microsoft Windows Knowledge Base Article 2706045 update is not installed
8452| [75949] Microsoft Windows Knowledge Base Article 2707960 update is not installed
8453| [75942] Microsoft Windows Knowledge Base Article 2706726 update is not installed
8454| [75934] Microsoft Windows Knowledge Base Article 2709162 update is not installed
8455| [75926] Microsoft Windows Knowledge Base Article 2709100 update is not installed
8456| [75905] Microsoft Windows Knowledge Base Article 2707956 update is not installed
8457| [71991] Microsoft Windows Knowledge Base Article 2607664 update is not installed
8458| [71542] Microsoft Windows Knowledge Base Article 2607702 update is not installed
8459| [70945] Microsoft Windows Knowledge Base Article 2603381 update is not installed
8460| [70150] Microsoft Windows Knowledge Base Article 2607670 update is not installed
8461| [67755] Microsoft Windows Knowledge Base Article 2503665 update is not installed
8462| [67749] Microsoft Windows Knowledge Base Article 2507938 update is not installed
8463| [66845] Microsoft Windows Knowledge Base Article 2506014 update is not installed
8464| [66844] Microsoft Windows Knowledge Base Article 2501584 update is not installed
8465| [66448] Microsoft Windows Knowledge Base Article 2508272 update is not installed
8466| [66442] Microsoft Windows Knowledge Base Article 2509553 update is not installed
8467| [66440] Microsoft Windows Knowledge Base Article 2508429 update is not installed
8468| [66438] Microsoft Windows Knowledge Base Article 2507618 update is not installed
8469| [66430] Microsoft Windows Knowledge Base Article 2503658 update is not installed
8470| [66425] Microsoft Windows Knowledge Base Article 2506223 update is not installed
8471| [65570] Microsoft Windows Knowledge Base Article 2500212 update is not installed
8472| [65568] Microsoft Windows Knowledge Base Article 2508062 update is not installed
8473| [63840] Microsoft Visual C++ 2008 Redistributable Package dynamic-linked library (DLL) code execution
8474| [63780] Microsoft PowerPoint 2007 dynamic-linked library (rpawinet.dll) code execution
8475| [63775] Microsoft Visio 2003 dynamic-linked library (mfc71enu.dll) code execution
8476| [63586] Microsoft Windows Knowledge Base Article 2207559 update is not installed
8477| [63573] Microsoft Windows Knowledge Base Article 2407132 update is not installed
8478| [62797] Microsoft Windows Knowledge Base Article 2305420 update is not installed
8479| [62149] Microsoft Windows Knowledge Base Article 2207566 update is not installed
8480| [62133] Microsoft Windows Knowledge Base Article 2405882 update is not installed
8481| [53980] Microsoft Windows 2000 License Logging Server buffer overflow
8482| [53601] Microsoft Office 2008 for Mac user ID 502 security bypass
8483| [50973] Microsoft Windows Server 2003 and Vista win32k.sys denial of service
8484| [50759] Microsoft Windows 2000 Active Directory LDAP code execution
8485| [48595] Microsoft Word 2007 Email as PDF information disclosure
8486| [46102] Microsoft Windows 2003 SP2 is not installed on the system
8487| [46101] Microsoft Windows 2003 SP1 is not installed on the system
8488| [45186] Microsoft SQL Server 2000 SQLVDIRLib.SQLVDirControl ActiveX control buffer overflow
8489| [37200] Microsoft SQL Server 2000 Service Pack 1 update is not installed
8490| [37198] Microsoft SQL Server 2000 Service Pack 3 update is not installed
8491| [34634] Microsoft Windows Server 2003 Active Directory information disclosure
8492| [34599] Microsoft Windows Server 2003 terminal server security bypass
8493| [34473] Microsoft Office 2000 ActiveX control buffer overflow
8494| [33713] Microsoft Word 2007 multiple unspecified denial of service
8495| [33712] Microsoft Word 2007 wwlib.dll buffer overflow
8496| [32631] Microsoft SQL Server 2000 Service Pack 2 update is not installed
8497| [31821] Microsoft Windows time zone update for year 2007
8498| [31196] Microsoft Office 2003 Brazilian Grammar Checker buffer overflow
8499| [30905] Microsoft Project Server 2003 pdsrequest.asp information disclosure
8500| [29546] Microsoft Windows 2000/2003 user logoff initiated
8501| [29545] Microsoft Windows 2000/2003 system time changed
8502| [29544] Microsoft Windows 2000/2003 system security access removed
8503| [29543] Microsoft Windows 2000/2003 security access granted
8504| [29542] Microsoft Windows 2000/2003 SAM notification package loaded
8505| [29541] Microsoft Windows 2000/2003 primary security token issued
8506| [29540] Microsoft Windows 2000/2003 user password reset successful
8507| [29539] Microsoft Windows 2000/2003 object indirectly accessed
8508| [29538] Microsoft Windows 2000/2003 object handle duplicated
8509| [29537] Microsoft Windows 2000/2003 logon with explicit credentials success
8510| [29536] Microsoft Windows 2000/2003 logon attempt using explicit credentials unsuccessful
8511| [29535] Microsoft Windows 2000/2003 IPSEC policy agent failed
8512| [29534] Microsoft Windows 2000/2003 IPSEC policy agent disabled
8513| [29533] Microsoft Windows 2000/2003 IPSEC policy agent changed
8514| [29532] Microsoft Windows 2000/2003 IKE security association established
8515| [29531] Microsoft Windows 2000/2003 IKE quick mode association ended
8516| [29530] Microsoft Windows 2000/2003 IKE main mode association ended
8517| [29529] Microsoft Windows 2000/2003 IKE association negotiation failed
8518| [29528] Microsoft Windows 2000/2003 IKE association peer authentication failed
8519| [29527] Microsoft Windows 2000/2003 IKE association failed invalid proposal
8520| [29526] Microsoft Windows 2000/2003 IKE association failed authentication parameters
8521| [29525] Microsoft Windows 2000/2003 DPAPI master key backup attempted
8522| [29524] Microsoft Windows 2000/2003 DPAPI key recovery attempted
8523| [29523] Microsoft Windows 2000/2003 DPAPI auditable data unprotected
8524| [29522] Microsoft Windows 2000/2003 administrative group security descriptor set
8525| [29521] Microsoft Windows 2000/2003 account name changed
8526| [29507] Microsoft Office 2003 unspecified PowerPoint NULL pointer dereference denial of service
8527| [28512] Microsoft Internet Explorer multiple Windows 2000 COM object denial of service
8528| [28005] Microsoft Windows 2000 Management Console (MMC) resource file cross-site scripting
8529| [26118] Microsoft Office 2003 mailto: information disclosure
8530| [25330] Microsoft Commerce Server 2002 authfiles/login.asp authentication bypass
8531| [24474] Microsoft Windows 2000 LDAP client accepts untrusted CA
8532| [24473] Microsoft Windows 2000 event ID 565 not logged
8533| [24472] Microsoft Windows 2000 Event ID 1704 records incorrect group policy settings
8534| [24407] Microsoft Windows 2000 SECEDIT command fails to set ACLs correctly
8535| [24405] Microsoft Windows 2000 UPN credentials with trailing dot group policy bypass
8536| [24403] Microsoft Windows 2000 WideCharToMultiByte() incorrect Japanese character conversion
8537| [24402] Microsoft Windows 2000 Terminal Service client IP not logged
8538| [24400] Microsoft Windows 2000 domain authentication can be bypassed by a local administrator
8539| [23066] Microsoft Windows XP and 2000 Server MSRPC memory allocation denial of service
8540| [22318] Microsoft SQL Server 2000 Service Pack 4 update is not installed
8541| [22183] Microsoft Exchange Server 2003 public folder denial of service
8542| [21345] Microsoft Windows 2000 Update Rollup 1 for Service Pack 4 has not been installed
8543| [21315] Microsoft Outlook 2002 connector for Domino bypass restrictions
8544| [19969] Multiple Microsoft Windows Server 2003 Edition printer driver denial of service
8545| [19965] Multiple Microsoft Windows Server 2003 Editions SMB redirector denial of service
8546| [19727] Microsoft Windows 2000 GDI32.DLL denial of service
8547| [19629] Microsoft Exchange Server 2003 folder denial of service
8548| [17826] Microsoft Outlook 2003 CID security bypass
8549| [17624] Microsoft Windows XP and Windows Server 2003 Compressed Folders buffer overflow
8550| [17621] Microsoft Windows 2003 SMTP service code execution
8551| [17560] Microsoft Windows 2000 and XP GDI library denial of service
8552| [17521] Microsoft Windows 2000 Service Pack 4 is not installed
8553| [16913] Microsoft Windows 2003 users with Synchronize directory service data privilege
8554| [16912] Microsoft Windows 2003 groups with Synchronize directory service data privilege
8555| [16909] Microsoft Windows 2003 groups with Remove computer from docking station privilege
8556| [16907] Microsoft Windows 2003 users with Create global objects privilege
8557| [16905] Microsoft Windows 2003 users or groups with Create global objects privilege
8558| [16851] Microsoft Windows 2003 and XP WinKey and U key denial of service
8559| [16704] Microsoft Windows 2000 Media Player control code execution
8560| [16582] Microsoft Windows Server 2003 kernel CPU denial of service
8561| [16572] Microsoft Windows 2003 Users with Impersonate a client after authentication privilege
8562| [16570] Microsoft Windows 2003 Users with Create global objects privilege
8563| [16564] Microsoft Windows 2003 Groups with Create global objects privilege
8564| [16562] Microsoft Windows 2003 Groups with "
8565| [16522] Microsoft Windows 2003 Impersonate a client after authentication privilege
8566| [16521] Microsoft Windows 2003 Deny Logon Through Terminal Services privilege
8567| [16520] Microsoft Windows 2003 Create global objects privilege
8568| [16276] Microsoft Windows 2000 Advanced Server fully qualified domain name security bypass
8569| [16173] Microsoft Outlook 2003 OLE object bypass restricted security zone
8570| [16119] Microsoft Outlook 2000 URL spoofing
8571| [16104] Microsoft Outlook 2003 predictable file location could allow code execution
8572| [16095] Microsoft Windows XP and Windows Server 2003 HCP URL code execution
8573| [15704] Microsoft Windows XP and Windows Server 2003 HCP URL code execution
8574| [15700] Microsoft Windows 2000 Domain Controller LSASS LDAP message denial of service
8575| [15632] Microsoft Windows 2000 Utility Manger allows privilege escalation
8576| [15414] Microsoft Outlook 2002 mailto URL allows execution of code
8577| [15263] Microsoft Windows XP and 2000 Server kernel allows elevated privileges
8578| [15057] Microsoft Windows XP and Windows Server 2003 smbmount Linux client denial of service
8579| [15038] Microsoft Windows 2000 Server Windows Media Services denial of service
8580| [15037] Microsoft Windows Server 2003 WINS /GS flag denial of service
8581| [14178] Microsoft ISA Exchange Server 2003 MS04-002 patch is not installed
8582| [14167] Microsoft ISA Server 2000 H.323 filter buffer overflow
8583| [13426] Microsoft Windows 2000 and XP RPC race condition
8584| [13423] Microsoft Windows 2000 Local Troubleshooter ActiveX control buffer overflow
8585| [13407] Microsoft Windows 2000 Server mqsvc.exe MQLocateBegin packet buffer overflow
8586| [13385] Microsoft Windows Server 2003 "
8587| [13211] Microsoft Windows 2000 and XP URG memory leak
8588| [13171] Microsoft Windows Server 2003 can allow attacker to bypass mechanism used to detect buffer overflows
8589| [13131] Microsoft Windows 2000 Message Queue Manager buffer overflow
8590| [12684] Microsoft Exchange Server OWA Outlook 2003 denial of service
8591| [12652] Microsoft Windows 2000 and NT 4.0 Server IIS ISAPI nsiislog.dll extension POST request buffer overflow
8592| [12620] Microsoft Windows 2000 Server SMTP FILETIME denial of service
8593| [12543] Microsoft Windows 2000 Accessibility Utility Manager could allow an attacker to gain privileges
8594| [12493] Microsoft Windows Shell32.dll 2000 ShellExecute function buffer overflow
8595| [12489] Microsoft Windows 2000 Server Active Directory buffer overflow
8596| [12128] Microsoft Windows 2000 and Windows NT MS03-019 patch is not installed
8597| [12092] Microsoft Windows 2000 and NT 4.0 Server IIS ISAPI nsiislog.dll extension buffer overflow
8598| [12048] Microsoft Windows 2000 and Windows Server 2003 LAN Manager hash creation enabled
8599| [11901] Microsoft BizTalk Server 2002 SQL injection
8600| [11900] Microsoft BizTalk Server 2002 HTTP Receiver function buffer overflow
8601| [11816] Microsoft Windows 2000 Terminal Services MSGINA.DLL insecure access permissions
8602| [11696] Microsoft Windows 2000 Terminal Services man-in-the-middle attack
8603| [11617] Microsoft Windows 2000 MS03-007 patch is not installed on the system
8604| [11546] Microsoft Windows 2000 Windows Help Facility .cnt file buffer overflow
8605| [11329] Microsoft Windows NT and 2000 cmd.exe CD path name buffer overflow
8606| [11274] Microsoft Windows 2000 NetBIOS continuation packets denial of service
8607| [11273] Microsoft Windows 2000 RPC service could allow an attacker to gain elevated privileges
8608| [11216] Microsoft Windows NT and 2000 command prompt denial of service
8609| [11141] Microsoft Windows 2000 Terminal Services MSGINA.DLL denial of service
8610| [11133] Microsoft Outlook 2002 using V1 Exchange Server Security certificates transmits plaintext emails
8611| [10843] Microsoft Windows 2000 and XP SMB signing group policy modification
8612| [10431] Microsoft Windows 2000 SNMP LANMAN Extension memory leak denial of service
8613| [10400] Microsoft Windows 2000 RPC TCP port 135 denial of service
8614| [10377] Microsoft Windows XP and 2000 administrative alerts fail when security event log is full
8615| [10199] Microsoft Windows 2000/XP PPTP packet buffer overflow
8616| [10195] Microsoft FrontPage Server Extensions (FPSE) 2002 SmartHTML Interpreter buffer overflow
8617| [10194] Microsoft FrontPage Server Extensions (FPSE) 2000 SmartHTML Interpreter denial of service
8618| [9946] Microsoft Windows 2000 Terminal Services session screensaver fails to lock the console
8619| [9856] Microsoft Windows 2000 NCM handler routine could allow elevated privileges
8620| [9779] Microsoft Windows 2000 weak system partition permissions
8621| [9752] Microsoft Windows 2000 Service Pack 3 is not installed
8622| [9746] Microsoft Windows 2000 HTML Help item parameter buffer overflow
8623| [9625] Microsoft Windows 2000 Narrator allows login information to be audible
8624| [9154] Microsoft Data Engine (MSDE) and Microsoft SQL Server 2000 Desktop Engine have a default blank "
8625| [8867] Microsoft Windows 2000 LanMan denial of service
8626| [8813] Microsoft Windows 2000 Terminal Services allows attacker to bypass group policy settings
8627| [8759] Microsoft Windows 2000 could allow an attacker to block the application of Group Policy settings
8628| [8752] Microsoft Windows NT, 2000, and XP MUP buffer overflow
8629| [8739] Microsoft Windows 2000 DCOM memory leak
8630| [8708] Microsoft Outlook 2000 and 2002 executes embedded script in object tag when replying or forwarding HTML mail
8631| [8402] Microsoft Windows 2000 allows an attacker to bypass password policy
8632| [8307] Microsoft Windows 2000, Windows XP, and Exchange 2000 SMTP data transfer command denial of service
8633| [8304] Microsoft Windows 2000 and Exchange 5.5 SMTP service unauthorized mail privileges
8634| [8254] Microsoft Commerce Server 2000 AuthFilter ISAPI filter buffer overflow
8635| [8199] Microsoft Windows 2000 Terminal Services unlocked client
8636| [8094] Microsoft Windows 2000 and Interix 2.2 Telnet protocol option buffer overflow
8637| [8092] Microsoft Exchange 2000 System Attendant sets incorrect registry permissions
8638| [8043] Microsoft Windows NT, 2000, and XP using NTFS could allow files to be hidden
8639| [8037] Microsoft Windows 2000 empty TCP packet denial of service
8640| [8023] Microsoft Windows NT and Windows 2000 SIDs could allow an attacker to gain elevated privileges in another domain
8641| [7919] Microsoft IIS 4.0 and Norton Internet Security 2001 default permissions could allow an attacker to modify log files
8642| [7667] Microsoft Windows 2000 IKE UDP packet flood denial of service
8643| [7566] Microsoft IIS 2.0 and 3.0 upgraded to Microsoft IIS 4.0 fails to remove the ism.dll file
8644| [7538] Microsoft Windows 2000 and XP Terminal services allow an attacker to spoof IP addresses
8645| [7533] Microsoft Windows 2000 RunAs service denial of service
8646| [7532] Microsoft Windows 2000 RunAs service allows local attacker to bypass pipe authentication
8647| [7531] Microsoft Windows 2000 RunAs service reveals sensitive information
8648| [7528] Microsoft Windows NT and Windows 2000 malformed RPC request denial of service
8649| [7409] Microsoft Windows 2000 and Windows XP GDI denial of service
8650| [7302] Microsoft Windows NT and 2000 Terminal Server malformed RDP packet series denial of service
8651| [7008] Microsoft Windows 2000 IrDA device denial of service
8652| [6977] Microsoft Windows NT and 2000 NNTP memory leak denial of service
8653| [6931] Microsoft Windows 2000 without Service Pack 2
8654| [6919] Microsoft Windows 2000 Task Manager does not terminate malicious files with the same name as a system process
8655| [6912] Microsoft Windows NT and 2000 Terminal Server RDP memory leak denial of service
8656| [6876] Microsoft Windows 2000 could allow an attacker to change network passwords
8657| [6803] Microsoft Windows 2000 SMTP service allows mail relaying
8658| [6745] Microsoft Windows 2000 LDAP function could allow domain user password change
8659| [6669] Microsoft Windows 2000 Telnet system call denial of service
8660| [6668] Microsoft Windows 2000 Telnet handle leak denial of service
8661| [6667] Microsoft Windows 2000 Telnet multiple idle sessions denial of service
8662| [6666] Microsoft Windows 2000 Telnet username denial of service
8663| [6665] Microsoft Windows 2000 Telnet service weak domain authentication
8664| [6664] Microsoft Windows 2000 Telnet service predictable pipe names could allow elevation of privileges
8665| [6652] Microsoft Exchange 2000 OWA script execution
8666| [6590] Microsoft Windows 2000 debug registers allow attacker to gain elevated privileges
8667| [6506] Microsoft Windows 2000 Server Kerberos denial of service
8668| [6443] Microsoft Windows 2000 catalog file could remove installed hotfixes
8669| [6160] Microsoft Windows 2000 event viewer buffer overflow
8670| [6136] Microsoft Windows 2000 domain controller denial of service
8671| [6035] Microsoft Windows 2000 Server RDP denial of service
8672| [5973] Microsoft Windows 2000 EFS allows local user to recover sensitive data
8673| [5936] Microsoft Windows 2000 Server Directory Service Restore Mode allows user to login with blank password
8674| [5800] Microsoft Windows 2000 Index Service ActiveX controls allow unauthorized access to file information
8675| [5623] Microsoft Windows NT and 2000 Phone Book service buffer overflow
8676| [5598] Microsoft Windows 2000 Telnet daemon could allow a denial of service
8677| [5585] Microsoft Windows 2000 brute force attack
8678| [5502] Microsoft Windows 2000 Indexing Services ixsso.query
8679| [5467] Microsoft Windows 2000 System Monitor ActiveX control buffer overflow
8680| [5399] Microsoft Windows NT and 2000 Network Monitor buffer overflow
8681| [5301] Microsoft Windows 2000 Simplified Chinese IME State Recognition
8682| [5263] Microsoft Office 2000 executes .dll without users knowledge
8683| [5242] Microsoft Windows 2000 Telnet client NTLM authentication weakness
8684| [5222] Microsoft Windows 2000 malformed RPC packet denial of service
8685| [5203] Microsoft Windows 2000 still image service
8686| [5171] Microsoft Windows 2000 Local Security Policy corruption
8687| [5080] Microsoft Office 2000 HTML object tag buffer overflow
8688| [5033] Microsoft Windows 2000 without Service Pack 1
8689| [5031] Microsoft Windows 2000 Service Control Manager named pipe could allow a unauthorized user to gain privileges
8690| [5015] Microsoft Windows NT and 2000 executable path
8691| [4887] Microsoft Windows 2000 Kerberos ticket renewed
8692| [4886] Microsoft Windows 2000 logon session reconnected
8693| [4885] Microsoft Windows 2000 logon session disconnected
8694| [4882] Microsoft Windows 2000 Kerberos pre-authentication failed
8695| [4873] Microsoft Windows 2000 user account mapped for logon
8696| [4872] Microsoft Windows 2000 account logon failed
8697| [4871] Microsoft Windows 2000 account used for logon
8698| [4855] Microsoft Windows 2000 group type change
8699| [4842] Microsoft Internet Explorer and Microsoft Powerpoint 2000 ActiveX object execution
8700| [4841] Microsoft Internet Explorer and Microsoft Access 2000 VBA code execution
8701| [4823] Microsoft Windows 2000 Telnet server binary stream denial of service
8702| [4819] Microsoft Windows 2000 default SYSKEY configuration
8703| [4787] Microsoft Windows 2000 user account locked out
8704| [4786] Microsoft Windows 2000 computer account created
8705| [4785] Microsoft Windows 2000 computer account changed
8706| [4784] Microsoft Windows 2000 computer account deleted
8707| [4714] Microsoft Windows 2000 "
8708| [4589] Microsoft Windows 2000 protected store can be compromised by brute force attack
8709| [4278] Microsoft Windows 2000 unattended install does not secure All Users profile
8710| [4138] Microsoft Windows 2000 system file integrity feature is disabled
8711| [4086] Microsoft Windows 2000 may not start Jaz drives correctly
8712| [4085] Microsoft Windows 2000 non-Gregorial calendar error
8713| [4084] Microsoft Windows 2000 may prevent Adobe FrameMaker files from being saved in some formats
8714| [4083] Microsoft Windows 2000 Terminal Services may damage Office files saved as HTML
8715| [4082] Microsoft Windows 2000 and Iomega parallel port drives display error
8716| [4080] Microsoft Windows 2000 AOL image support
8717| [4079] Microsoft Windows 2000 High Encryption Pack
8718| [3854] Microsoft Office 2000 security setting
8719| [1376] Microsoft Proxy 2.0 denial of service
8720| [86256] Microsoft Windows Knowledge Base Article 2876063 update is not installed
8721| [86097] Microsoft Windows Knowledge Base Article 2859537 update is not installed
8722| [86091] Microsoft Windows Knowledge Base Article 2868623 update is not installed
8723| [86089] Microsoft Windows Knowledge Base Article 2862772 update is not installed
8724| [86075] Microsoft Windows Knowledge Base Article 2850869 update is not installed
8725| [86073] Microsoft Windows Knowledge Base Article 2873872 update is not installed
8726| [86070] Microsoft Windows Knowledge Base Article 2849568 update is not installed
8727| [85245] Microsoft Windows Knowledge Base Article 2848295 update is not installed
8728| [85244] Microsoft Windows Knowledge Base Article 2847927 update is not installed
8729| [85243] Microsoft Windows Knowledge Base Article 2861561 update is not installed
8730| [85236] Microsoft Windows Knowledge Base Article 2850851 update is not installed
8731| [85227] Microsoft Windows Knowledge Base Article 2847883 update is not installed
8732| [85223] Microsoft Windows Knowledge Base Article 2846071 update is not installed
8733| [85205] Microsoft Windows Knowledge Base Article 2845187 update is not installed
8734| [84621] Microsoft Windows Knowledge Base Article 2845690 update is not installed
8735| [84619] Microsoft Windows Knowledge Base Article 2839894 update is not installed
8736| [84617] Microsoft Windows Knowledge Base Article 2839571 update is not installed
8737| [84615] Microsoft Windows Knowledge Base Article 2839229 update is not installed
8738| [84613] Microsoft Windows Knowledge Base Article 2838727 update is not installed
8739| [84156] Microsoft Windows Knowledge Base Article 2847204 update is not installed
8740| [83912] Microsoft Windows Knowledge Base Article 2829254 update is not installed
8741| [83910] Microsoft Windows Knowledge Base Article 2829530 update is not installed
8742| [83898] Microsoft Windows Knowledge Base Article 2830397 update is not installed
8743| [83886] Microsoft Windows Knowledge Base Article 2830399 update is not installed
8744| [83884] Microsoft Windows Knowledge Base Article 2834692 update is not installed
8745| [83882] Microsoft Windows Knowledge Base Article 2834695 update is not installed
8746| [83880] Microsoft Windows Knowledge Base Article 2836440 update is not installed
8747| [83876] Microsoft Windows Knowledge Base Article 2840221 update is not installed
8748| [83192] Microsoft Windows Knowledge Base Article 2817183 update is not installed
8749| [83100] Microsoft Windows Knowledge Base Article 2830914 update is not installed
8750| [83098] Microsoft Windows Knowledge Base Article 2829996 update is not installed
8751| [83093] Microsoft Windows Knowledge Base Article 2828223 update is not installed
8752| [83091] Microsoft Windows Knowledge Base Article 2813170 update is not installed
8753| [83088] Microsoft Windows Knowledge Base Article 2827663 update is not installed
8754| [83086] Microsoft Windows Knowledge Base Article 2823482 update is not installed
8755| [83084] Microsoft Windows Knowledge Base Article 2821818 update is not installed
8756| [83082] Microsoft Windows Knowledge Base Article 2820917 update is not installed
8757| [82600] Microsoft Windows Knowledge Base Article 2813707 update is not installed
8758| [82424] Microsoft Windows Knowledge Base Article 2814124 update is not installed
8759| [82422] Microsoft Windows Knowledge Base Article 2780176 update is not installed
8760| [82401] Microsoft Windows Knowledge Base Article 2813682 update is not installed
8761| [82399] Microsoft Windows Knowledge Base Article 2816264 update is not installed
8762| [81683] Microsoft Windows Knowledge Base Article 2780091 update is not installed
8763| [81681] Microsoft Windows Knowledge Base Article 2784242 update is not installed
8764| [81680] Microsoft Windows Knowledge Base Article 2790113 update is not installed
8765| [81678] Microsoft Windows Knowledge Base Article 2790655 update is not installed
8766| [81676] Microsoft Windows Knowledge Base Article 2790978 update is not installed
8767| [81674] Microsoft Windows Knowledge Base Article 2797052 update is not installed
8768| [81672] Microsoft Windows Knowledge Base Article 2799494 update is not installed
8769| [81666] Microsoft Windows Knowledge Base Article 2778344 update is not installed
8770| [81634] Microsoft Windows Knowledge Base Article 2792100 update is not installed
8771| [81339] Microsoft Windows Knowledge Base Article 2799329 update is not installed
8772| [80875] Microsoft Windows Knowledge Base Article 2756145 update is not installed
8773| [80872] Microsoft Windows Knowledge Base Article 2769324 update is not installed
8774| [80867] Microsoft Windows Knowledge Base Article 2769327 update is not installed
8775| [80865] Microsoft Windows Knowledge Base Article 2769369 update is not installed
8776| [80863] Microsoft Windows Knowledge Base Article 2778930 update is not installed
8777| [80861] Microsoft Windows Knowledge Base Article 2785220 update is not installed
8778| [80365] Microsoft Windows Knowledge Base Article 2761465 update is not installed
8779| [80360] Microsoft Windows Knowledge Base Article 2765809 update is not installed
8780| [80358] Microsoft Windows Knowledge Base Article 2770660 update is not installed
8781| [80356] Microsoft Windows Knowledge Base Article 2780642 update is not installed
8782| [80352] Microsoft Windows Knowledge Base Article 2783534 update is not installed
8783| [80349] Microsoft Windows Knowledge Base Article 2784126 update is not installed
8784| [79693] Microsoft Windows Knowledge Base Article 2745030 update is not installed
8785| [79687] Microsoft Windows Knowledge Base Article 2761451 update is not installed
8786| [79683] Microsoft Windows Knowledge Base Article 2761226 update is not installed
8787| [79679] Microsoft Windows Knowledge Base Article 2758857 update is not installed
8788| [79677] Microsoft Windows Knowledge Base Article 2727528 update is not installed
8789| [78864] Microsoft Windows Knowledge Base Article 2754670 update is not installed
8790| [78862] Microsoft Windows Knowledge Base Article 2743555 update is not installed
8791| [78858] Microsoft Windows Knowledge Base Article 2754849 update is not installed
8792| [78856] Microsoft Windows Knowledge Base Article 2724197 update is not installed
8793| [78853] Microsoft Windows Knowledge Base Article 2741517 update is not installed
8794| [78851] Microsoft Windows Knowledge Base Article 2742319 update is not installed
8795| [78848] Microsoft Windows Knowledge Base Article 2742321 update is not installed
8796| [78760] Microsoft Windows Knowledge Base Article 2744842 update is not installed
8797| [78077] Microsoft Windows Knowledge Base Article 2741528 update is not installed
8798| [78075] Microsoft Windows Knowledge Base Article 2720184 update is not installed
8799| [78071] Microsoft Windows Knowledge Base Article 2748552 update is not installed
8800| [77512] Microsoft Windows Knowledge Base Article 2740358 update is not installed
8801| [77362] Microsoft Windows Knowledge Base Article 2733918 update is not installed
8802| [77360] Microsoft Windows Knowledge Base Article 2733829 update is not installed
8803| [77357] Microsoft Windows Knowledge Base Article 2733594 update is not installed
8804| [77352] Microsoft Windows Knowledge Base Article 2731879 update is not installed
8805| [77350] Microsoft Windows Knowledge Base Article 2731847 update is not installed
8806| [77348] Microsoft Windows Knowledge Base Article 2723135 update is not installed
8807| [77346] Microsoft Windows Knowledge Base Article 2722913 update is not installed
8808| [77342] Microsoft Windows Knowledge Base Article 2720573 update is not installed
8809| [77325] Microsoft Windows Knowledge Base Article 2719584 update is not installed
8810| [76808] Microsoft Windows Knowledge Base Article 2721015 update is not installed
8811| [76725] Microsoft Windows Knowledge Base Article 2722479 update is not installed
8812| [76724] Microsoft Windows Knowledge Base Article 2719177 update is not installed
8813| [76721] Microsoft Windows Knowledge Base Article 2718523 update is not installed
8814| [76718] Microsoft Windows Knowledge Base Article 2698365 update is not installed
8815| [76711] Microsoft Windows Knowledge Base Article 2695502 update is not installed
8816| [76704] Microsoft Windows Knowledge Base Article 2691442 update is not installed
8817| [76702] Microsoft Windows Knowledge Base Article 2655992 update is not installed
8818| [75963] Microsoft Windows Knowledge Base Article 2699988 update is not installed
8819| [75939] Microsoft Windows Knowledge Base Article 2685939 update is not installed
8820| [75928] Microsoft Windows Knowledge Base Article 2711167 update is not installed
8821| [75136] Microsoft Windows Knowledge Base Article 2693777 update is not installed
8822| [75132] Microsoft Windows Knowledge Base Article 2690533 update is not installed
8823| [75130] Microsoft Windows Knowledge Base Article 2688338 update is not installed
8824| [75127] Microsoft Windows Knowledge Base Article 2681578 update is not installed
8825| [75123] Microsoft Windows Knowledge Base Article 2680352 update is not installed
8826| [75116] Microsoft Windows Knowledge Base Article 2597981 update is not installed
8827| [74556] Microsoft Windows Knowledge Base Article 2639185 update is not installed
8828| [74384] Microsoft Windows Knowledge Base Article 2675157 update is not installed
8829| [74378] Microsoft Windows Knowledge Base Article 2671605 update is not installed
8830| [74373] Microsoft Windows Knowledge Base Article 2664258 update is not installed
8831| [74369] Microsoft Windows Knowledge Base Article 2663860 update is not installed
8832| [73543] Microsoft Windows Knowledge Base Article 2671387 update is not installed
8833| [73540] Microsoft Windows Knowledge Base Article 2665364 update is not installed
8834| [73538] Microsoft Windows Knowledge Base Article 2651019 update is not installed
8835| [73536] Microsoft Windows Knowledge Base Article 2651018 update is not installed
8836| [73533] Microsoft Windows Knowledge Base Article 2647170 update is not installed
8837| [73530] Microsoft Windows Knowledge Base Article 2641653 update is not installed
8838| [72887] Microsoft Windows Knowledge Base Article 2663841 update is not installed
8839| [72873] Microsoft Windows Knowledge Base Article 2663830 update is not installed
8840| [72867] Microsoft Windows Knowledge Base Article 2663510 update is not installed
8841| [72857] Microsoft Windows Knowledge Base Article 2661637 update is not installed
8842| [72855] Microsoft Windows Knowledge Base Article 2660465 update is not installed
8843| [72853] Microsoft Windows Knowledge Base Article 2653956 update is not installed
8844| [72851] Microsoft Windows Knowledge Base Article 2654428 update is not installed
8845| [72849] Microsoft Windows Knowledge Base Article 2651026 update is not installed
8846| [72846] Microsoft Windows Knowledge Base Article 2647516 update is not installed
8847| [72841] Microsoft Windows Knowledge Base Article 2645640 update is not installed
8848| [72838] Microsoft Windows Knowledge Base Article 2643719 update is not installed
8849| [72029] Microsoft Windows Knowledge Base Article 2638420 update is not installed
8850| [72003] Microsoft Windows Knowledge Base Article 2646524 update is not installed
8851| [71998] Microsoft Windows Knowledge Base Article 2644615 update is not installed
8852| [71995] Microsoft Windows Knowledge Base Article 2643584 update is not installed
8853| [71994] Microsoft Windows Knowledge Base Article 2636391 update is not installed
8854| [71565] Microsoft Windows Knowledge Base Article 2648048 update is not installed
8855| [71562] Microsoft Windows Knowledge Base Article 2640241 update is not installed
8856| [71560] Microsoft Windows Knowledge Base Article 2640045 update is not installed
8857| [71558] Microsoft Windows Knowledge Base Article 2639417 update is not installed
8858| [71557] Microsoft Windows Knowledge Base Article 2639142 update is not installed
8859| [71554] Microsoft Windows Knowledge Base Article 2633171 update is not installed
8860| [71552] Microsoft Windows Knowledge Base Article 2624667 update is not installed
8861| [71550] Microsoft Windows Knowledge Base Article 2620712 update is not installed
8862| [71548] Microsoft Windows Knowledge Base Article 2618451 update is not installed
8863| [71546] Microsoft Windows Knowledge Base Article 2618444 update is not installed
8864| [71538] Microsoft Windows Knowledge Base Article 2590602 update is not installed
8865| [70951] Microsoft Windows Knowledge Base Article 2630837 update is not installed
8866| [70949] Microsoft Windows Knowledge Base Article 2620704 update is not installed
8867| [70947] Microsoft Windows Knowledge Base Article 2617657 update is not installed
8868| [70943] Microsoft Windows Knowledge Base Article 2588516 update is not installed
8869| [70152] Microsoft Windows Knowledge Base Article 2623699 update is not installed
8870| [70140] Microsoft Windows Knowledge Base Article 2652016 update is not installed
8871| [70130] Microsoft Windows Knowledge Base Article 2586448 update is not installed
8872| [70115] Microsoft Windows Knowledge Base Article 2567053 update is not installed
8873| [69501] Microsoft Windows Knowledge Base Article 2587634 update is not installed
8874| [69498] Microsoft Windows Knowledge Base Article 2587505 update is not installed
8875| [69492] Microsoft Windows Knowledge Base Article 2571621 update is not installed
8876| [69490] Microsoft Windows Knowledge Base Article 2570947 update is not installed
8877| [68840] Microsoft Windows Knowledge Base Article 2451858 update is not installed
8878| [68833] Microsoft Windows Knowledge Base Article 2567943 update is not installed
8879| [68831] Microsoft Windows Knowledge Base Article 2570222 update is not installed
8880| [68829] Microsoft Windows Knowledge Base Article 2567951 update is not installed
8881| [68827] Microsoft Windows Knowledge Base Article 2578230 update is not installed
8882| [68825] Microsoft Windows Knowledge Base Article 2546250 update is not installed
8883| [68823] Microsoft Windows Knowledge Base Article 2559049 update is not installed
8884| [68816] Microsoft Windows Knowledge Base Article 2556532 update is not installed
8885| [68814] Microsoft Windows Knowledge Base Article 2560656 update is not installed
8886| [68812] Microsoft Windows Knowledge Base Article 2560978 update is not installed
8887| [68809] Microsoft Windows Knowledge Base Article 2562485 update is not installed
8888| [68806] Microsoft Windows Knowledge Base Article 2566454 update is not installed
8889| [68804] Microsoft Windows Knowledge Base Article 2563894 update is not installed
8890| [68801] Microsoft Windows Knowledge Base Article 2567680 update is not installed
8891| [68315] Microsoft Windows Knowledge Base Article 2555917 update is not installed
8892| [68299] Microsoft Windows Knowledge Base Article 2566220 update is not installed
8893| [68283] Microsoft Windows Knowledge Base Article 2560847 update is not installed
8894| [67955] Microsoft Windows Knowledge Base Article 2530548 update is not installed
8895| [67943] Microsoft Windows Knowledge Base Article 2544521 update is not installed
8896| [67762] Microsoft Windows Knowledge Base Article 2543893 update is not installed
8897| [67759] Microsoft Windows Knowledge Base Article 2544893 update is not installed
8898| [67757] Microsoft Windows Knowledge Base Article 2476490 update is not installed
8899| [67753] Microsoft Windows Knowledge Base Article 2514842 update is not installed
8900| [67751] Microsoft Windows Knowledge Base Article 2518295 update is not installed
8901| [67737] Microsoft Windows Knowledge Base Article 2520426 update is not installed
8902| [67733] Microsoft Windows Knowledge Base Article 2525694 update is not installed
8903| [67731] Microsoft Windows Knowledge Base Article 2525835 update is not installed
8904| [67728] Microsoft Windows Knowledge Base Article 2535512 update is not installed
8905| [67725] Microsoft Windows Knowledge Base Article 2536275 update is not installed
8906| [67722] Microsoft Windows Knowledge Base Article 2536276 update is not installed
8907| [67718] Microsoft Windows Knowledge Base Article 2537146 update is not installed
8908| [67709] Microsoft Windows Knowledge Base Article 2538814 update is not installed
8909| [67302] Microsoft Windows Knowledge Base Article 2545814 update is not installed
8910| [67101] Microsoft Windows Knowledge Base Article 2524426 update is not installed
8911| [66446] Microsoft Windows Knowledge Base Article 2514666 update is not installed
8912| [66444] Microsoft Windows Knowledge Base Article 2511455 update is not installed
8913| [66436] Microsoft Windows Knowledge Base Article 2497640 update is not installed
8914| [66432] Microsoft Windows Knowledge Base Article 2527308 update is not installed
8915| [66428] Microsoft Windows Knowledge Base Article 2489979 update is not installed
8916| [66423] Microsoft Windows kernel-mode driver (win32k.sys) variant 29 privilege escalation
8917| [66422] Microsoft Windows kernel-mode driver (win32k.sys) variant 28 privilege escalation
8918| [66421] Microsoft Windows kernel-mode driver (win32k.sys) variant 27 privilege escalation
8919| [66420] Microsoft Windows kernel-mode driver (win32k.sys) variant 26 privilege escalation
8920| [66419] Microsoft Windows kernel-mode driver (win32k.sys) variant 25 privilege escalation
8921| [66418] Microsoft Windows kernel-mode driver (win32k.sys) variant 24 privilege escalation
8922| [66417] Microsoft Windows kernel-mode driver (win32k.sys) variant 23 privilege escalation
8923| [66416] Microsoft Windows kernel-mode driver (win32k.sys) variant 22 privilege escalation
8924| [66415] Microsoft Windows kernel-mode driver (win32k.sys) variant 21 privilege escalation
8925| [66414] Microsoft Windows kernel-mode driver (win32k.sys) variant 20 privilege escalation
8926| [66396] Microsoft Windows kernel-mode driver (win32k.sys) variant 2 privilege escalation
8927| [66394] Microsoft Windows Knowledge Base Article 2485663 update is not installed
8928| [65588] Microsoft Windows Knowledge Base Article 2489279 update is not installed
8929| [65581] Microsoft Windows Knowledge Base Article 2510030 update is not installed
8930| [65580] Microsoft Windows Knowledge Base Article 2489283 update is not installed
8931| [65575] Microsoft Windows Knowledge Base Article 2489293 update is not installed
8932| [65573] Microsoft Windows Knowledge Base Article 2494047 update is not installed
8933| [64973] Microsoft Windows Knowledge Base Article 2478960 update is not installed
8934| [64971] Microsoft Windows Knowledge Base Article 2479628 update is not installed
8935| [64927] Microsoft Windows Knowledge Base Article 2393802 update is not installed
8936| [64925] Microsoft Windows Knowledge Base Article 2451879 update is not installed
8937| [64920] Microsoft Windows Knowledge Base Article 2475792 update is not installed
8938| [64918] Microsoft Windows Knowledge Base Article 2476687 update is not installed
8939| [64916] Microsoft Windows Knowledge Base Article 2478953 update is not installed
8940| [64914] Microsoft Windows Knowledge Base Article 2482017 update is not installed
8941| [64910] Microsoft Windows Knowledge Base Article 2483185 update is not installed
8942| [64909] Microsoft Windows Knowledge Base Article 2484015 update is not installed
8943| [64907] Microsoft Windows Knowledge Base Article 2485376 update is not installed
8944| [64905] Microsoft Windows Knowledge Base Article 2489256 update is not installed
8945| [64902] Microsoft Windows Knowledge Base Article 2496930 update is not installed
8946| [64342] Microsoft Windows Knowledge Base Article 2451910 update is not installed
8947| [64339] Microsoft Windows Knowledge Base Article 2478935 update is not installed
8948| [63584] Microsoft Windows Knowledge Base Article 2424434 update is not installed
8949| [63582] Microsoft Windows Knowledge Base Article 2423089 update is not installed
8950| [63580] Microsoft Windows Knowledge Base Article 2436673 update is not installed
8951| [63571] Microsoft Windows Knowledge Base Article 2440591 update is not installed
8952| [63569] Microsoft Windows Knowledge Base Article 2385678 update is not installed
8953| [63566] Microsoft Windows Knowledge Base Article 2442962 update is not installed
8954| [63564] Microsoft Windows Knowledge Base Article 2345316 update is not installed
8955| [63562] Microsoft Windows Knowledge Base Article 2296199 update is not installed
8956| [63558] Microsoft Windows Knowledge Base Article 2416400 update is not installed
8957| [63550] Microsoft Windows Knowledge Base Article 2447961 update is not installed
8958| [63548] Microsoft Windows Knowledge Base Article 2443105 update is not installed
8959| [63546] Microsoft Windows Knowledge Base Article 2455005 update is not installed
8960| [63544] Microsoft Windows Knowledge Base Article 2292970 update is not installed
8961| [62805] Microsoft Windows Knowledge Base Article 2316074 update is not installed
8962| [62793] Microsoft Windows Knowledge Base Article 2293386 update is not installed
8963| [62789] Microsoft Windows Knowledge Base Article 2423930 update is not installed
8964| [62170] Microsoft Windows Knowledge Base Article 2296011 update is not installed
8965| [62166] Microsoft Windows Knowledge Base Article 2294255 update is not installed
8966| [62163] Microsoft Windows Knowledge Base Article 2281679 update is not installed
8967| [62154] Microsoft Windows Knowledge Base Article 2279986 update is not installed
8968| [62147] Microsoft Windows Knowledge Base Article 2160841 update is not installed
8969| [62134] Microsoft Windows Knowledge Base Article 2412048 update is not installed
8970| [62129] Microsoft Windows Knowledge Base Article 2387149 update is not installed
8971| [62126] Microsoft Windows Knowledge Base Article 2378111 update is not installed
8972| [62123] Microsoft Windows Knowledge Base Article 2360937 update is not installed
8973| [62118] Microsoft Windows Knowledge Base Article 2293211 update is not installed
8974| [62104] Microsoft Windows Knowledge Base Article 2360131 update is not installed
8975| [62098] Microsoft Windows Knowledge Base Article 2293194 update is not installed
8976| [62069] Microsoft Windows Knowledge Base Article 2418042 update is not installed
8977| [61519] Microsoft Windows Knowledge Base Article 2121546 update is not installed
8978| [61517] Microsoft Windows Knowledge Base Article 2259922 update is not installed
8979| [61514] Microsoft Windows Knowledge Base Article 2267960 update is not installed
8980| [61510] Microsoft Windows Knowledge Base Article 2315011 update is not installed
8981| [61507] Microsoft Windows Knowledge Base Article 2320113 update is not installed
8982| [61504] Microsoft Windows Knowledge Base Article 2347290 update is not installed
8983| [60736] Microsoft Windows Knowledge Base Article 2265906 update is not installed
8984| [60734] Microsoft Windows Knowledge Base Article 2269638 update is not installed
8985| [60728] Microsoft Windows Knowledge Base Article 2269707 update is not installed
8986| [60724] Microsoft Windows Knowledge Base Article 2286198 update is not installed
8987| [60713] Microsoft Windows Knowledge Base Article 2183461 update is not installed
8988| [60698] Microsoft Windows Knowledge Base Article 2160329 update is not installed
8989| [60686] Microsoft Windows Knowledge Base Article 2115168 update is not installed
8990| [60684] Microsoft Windows Knowledge Base Article 2079403 update is not installed
8991| [60680] Microsoft Windows Knowledge Base Article 2264072 update is not installed
8992| [59901] Microsoft Windows Knowledge Base Article 2229593 update is not installed
8993| [59898] Microsoft Windows Knowledge Base Article 2229593 update is not installed
8994| [58913] Microsoft Windows Knowledge Base Article 2027452 update is not installed
8995| [58891] Microsoft Windows Knowledge Base Article 2028554 update is not installed
8996| [17004] Microsoft Windows XP Service Pack 2 is not installed on the system
8997| [9187] Microsoft Passport SDK 2.1 Component Configuration Document (CCD) permission
8998| [9146] Microsoft Passport SDK 2.1 events reporting disabled
8999| [9068] Microsoft Passport SDK 2.1 registry default permission exposure
9000| [9067] Microsoft Passport SDK 2.1 default test site exposure
9001| [9066] Microsoft Passport SDK 2.1 Adventure Works Sample Site exposure
9002| [9065] Microsoft Passport SDK 2.1 Adventure Works Sample Site global.asa file default permission exposure
9003| [9064] Microsoft Passport SDK 2.1 default time window exposure
9004| [1271] Microsoft IIS version 2 installed
9005| [621] Microsoft IIS 3.0 script source revealed by appending 2E to requests
9006|
9007| Exploit-DB - https://www.exploit-db.com:
9008| [30756] Microsoft Forms 2.0 ActiveX Control 2.0 Memory Access Violation Denial of Service Vulnerabilities
9009| [30749] Microsoft Office 2003 Web Component Memory Access Violation Denial of Service Vulnerability
9010| [30636] Microsoft Windows 2000/2003 Recursive DNS Spoofing Vulnerability (2)
9011| [30635] Microsoft Windows 2000/2003 Recursive DNS Spoofing Vulnerability (1)
9012| [30281] Microsoft .Net Framework <= 2.0 - Multiple Null Byte Injection Vulnerabilities
9013| [29664] Microsoft Office Publisher 2007 - Remote Denial of Service (DoS) Vulnerability
9014| [29660] Microsoft Office 2003 - Denial of Service (DoS) Vulnerability
9015| [29630] Microsoft Windows 2003/XP ReadDirectoryChangesW Information Disclosure Vulnerability
9016| [29524] Microsoft Word 2000 - Malformed Function Code Execution Vulnerability
9017| [28420] Microsoft Windows 2000 Multiple COM Object Instantiation Code Execution Vulnerabilities
9018| [28357] Microsoft Windows Explorer 2000/2003/XP Drag and Drop Remote Code Execution Vulnerability
9019| [28227] Microsoft Windows 2000/XP Registry Access Local Denial of Service Vulnerability
9020| [28226] Microsoft PowerPoint 2003 PPT File Closure Memory Corruption
9021| [28225] Microsoft PowerPoint 2003 powerpnt.exe Unspecified Issue
9022| [28224] Microsoft PowerPoint 2003 mso.dll PPT Processing Unspecified Code Execution
9023| [28198] Microsoft Office 2000/2002 Property Code Execution Vulnerability
9024| [28189] Microsoft Excel 2000-2004 Style Handling and Repair Remote Code Execution Vulnerability
9025| [28087] Microsoft Office 2003 Embedded Shockwave Flash Object Security Bypass Weakness
9026| [28005] Microsoft Exchange Server 2000/2003 Outlook Web Access Script Injection Vulnerability
9027| [26690] Microsoft Windows 2000/2003/XP CreateRemoteThread Local Denial of Service Vulnerability
9028| [26517] Microsoft Office PowerPoint 2007 - Crash PoC
9029| [26341] Microsoft Windows 2000/2003/XP MSDTC TIP Denial of Service Vulnerability
9030| [26222] Microsoft Windows 2000/2003/XP Keyboard Event Privilege Escalation Weakness
9031| [25384] Microsoft Windows 2000/XP Internet Protocol Validation Remote Code Execution Vulnerability (2)
9032| [25383] Microsoft Windows 2000/XP Internet Protocol Validation Remote Code Execution Vulnerability (1)
9033| [25231] Microsoft Windows 2000/2003/XP Graphical Device Interface Library Denial of Service Vulnerability
9034| [25085] Microsoft Office XP 2000/2002 HTML Link Processing Remote Buffer Overflow Vulnerability
9035| [25084] Microsoft Outlook 2003 Web Access Login Form Remote URI Redirection Vulnerability
9036| [25050] Microsoft Windows 2000/2003/XP winhlp32 Phrase Heap Overflow Vulnerability
9037| [25049] Microsoft Windows 2000/2003/XP winhlp32 Phrase Integer Overflow Vulnerability
9038| [24686] Microsoft Outlook 2003 Security Policy Bypass Vulnerability
9039| [24277] Microsoft Windows 2000/NT 4 POSIX Subsystem Buffer Overflow Local Privilege Escalation Vulnerability
9040| [24114] Microsoft Outlook 2003Mail Client E-mail Address Verification Weakness
9041| [24101] Microsoft Outlook 2003 Predictable File Location Weakness
9042| [23989] Microsoft Windows 2000/NT 4 Local Descriptor Table Local Privilege Escalation Vulnerability
9043| [23796] Microsoft Outlook 2002 Mailto Parameter Quoting Zone Bypass Vulnerability
9044| [23019] Microsoft Windows 2000 Subnet Bandwidth Manager RSVP Server Authority Hijacking Vulnerability
9045| [22919] Microsoft ISA Server 2000 Cross-Site Scripting Vulnerabilities
9046| [22883] Microsoft Windows 2000 CreateFile API Named Pipe Privilege Escalation Vulnerability (2)
9047| [22882] Microsoft Windows 2000 CreateFile API Named Pipe Privilege Escalation Vulnerability (1)
9048| [22837] Microsoft Windows 2000/NT 4 Media Services NSIISlog.DLL Remote Buffer Overflow
9049| [22782] Microsoft Windows 2000 Active Directory Remote Stack Overflow Vulnerability
9050| [22591] Microsoft Office Excel 2007 - WriteAV Crash PoC
9051| [22555] Microsoft BizTalk Server 2000/2002 DTA RawCustomSearchField.asp SQL Injection
9052| [22554] Microsoft BizTalk Server 2000/2002 DTA rawdocdata.asp SQL Injection Vulnerability
9053| [22553] Microsoft BizTalk Server 2002 HTTP Receiver Buffer Overflow Vulnerability
9054| [22528] Microsoft Windows 2000 RegEdit.EXE Registry Key Value Buffer Overflow Vulnerability
9055| [22354] Microsoft Windows 2000 Help Facility .CNT File :Link Buffer Overflow Vulnerability
9056| [21920] Microsoft Content Management Server 2001 Cross-Site Scripting Vulnerability
9057| [21718] Microsoft SQL 2000/7.0 Agent Jobs Privilege Elevation Vulnerability
9058| [21693] Microsoft SQL Server 2000 User Authentication Remote Buffer Overflow Vulnerability
9059| [21652] Microsoft SQL Server 2000 Resolution Service Heap Overflow Vulnerability
9060| [21651] Microsoft SQL Server 2000 sp_MScopyscript SQL Injection Vulnerability
9061| [21650] Microsoft SQL Server 2000 Database Consistency Checkers Buffer Overflow Vulnerability
9062| [21549] Microsoft SQL Server 2000 Password Encrypt Procedure Buffer Overflow Vulnerability
9063| [21541] Microsoft SQL Server 2000 SQLXML Script Injection Vulnerability
9064| [21540] Microsoft SQL Server 2000 SQLXML Buffer Overflow Vulnerability
9065| [21389] Microsoft Windows 2000 Lanman Denial of Service Vulnerability (2)
9066| [21388] Microsoft Windows 2000 Lanman Denial of Service Vulnerability (1)
9067| [21344] Microsoft Windows 2000 / NT 4.0 Process Handle Local Privilege Elevation Vulnerability
9068| [21258] Microsoft Windows 2000/NT 4 NTFS File Hiding Vulnerability
9069| [21246] Microsoft Windows 2000/NT 4 TCP Stack DoS Vulnerability (2)
9070| [21245] Microsoft Windows 2000/NT 4 TCP Stack DoS Vulnerability (1)
9071| [21172] Microsoft Windows 2000 Internet Key Exchange DoS Vulnerability (2)
9072| [21171] Microsoft Windows 2000 Internet Key Exchange DoS Vulnerability (1)
9073| [21131] Microsoft Windows 2000/XP GDI Denial of Service Vulnerability
9074| [21123] Microsoft Windows 2000/NT Terminal Server Service RDP DoS Vulnerability
9075| [21113] Microsoft Index Server 2.0 File Information and Path Disclosure Vulnerability
9076| [21099] Microsoft Windows 2000 RunAs Service Denial of Services Vulnerability
9077| [21069] Microsoft Windows 2000 RunAs Service Named Pipe Hijacking Vulnerability
9078| [20907] Microsoft Windows 2000 Telnet Username DoS Vulnerability
9079| [20802] Microsoft IIS 2.0/3.0 Long URL Denial of Service Vulnerability
9080| [20763] Microsoft ISA Server 2000 Web Proxy DoS Vulnerability
9081| [20571] Microsoft Outlook 2000 0/98 0/Express 5.5 Concealed Attachment Vulnerability
9082| [20481] Microsoft IIS 2.0/3.0 Appended Dot Script Source Disclosure Vulnerability
9083| [20399] Microsoft Indexing Services for Windows 2000 File Verification Vulnerability
9084| [20335] Microsoft Indexing Services for Windows 2000/NT 4.0 .htw Cross-Site Scripting Vulnerability
9085| [20305] Microsoft Site Server 2.0 with IIS 4.0 - File Upload Vulnerability
9086| [20265] Microsoft Windows NT 4.0 / 2000 Spoofed LPC Request Vulnerability
9087| [20257] Microsoft Windows NT 4.0 / 2000 Predictable LPC Message Identifier Multiple Vulnerabilities
9088| [20255] Microsoft Windows NT 4.0 / 2000 LPC Zone Memory Depletion DoS Vulnerability
9089| [20222] Microsoft Windows 2000 telnet.exe NTLM Authentication Vulnerability
9090| [20209] Microsoft Windows 2000 Still Image Service Privilege Escalation Vulnerability
9091| [20133] Microsoft Windows 2000 Named Pipes Predictability Vulnerability
9092| [20122] Microsoft Office SharePoint Server 2007 Remote Code Execution
9093| [20096] Microsoft IIS 2.0/3.0/4.0/5.0/5.1 Internal IP Address Disclosure Vulnerability
9094| [20048] Microsoft Windows 2000 Remote CPU-overload Vulnerability
9095| [20047] Microsoft Windows 2000 Telnet Server DoS Vulnerability
9096| [19830] Microsoft Index Server 2.0 '%20' ASP Source Disclosure Vulnerability
9097| [19742] microsoft iis 3.0/4.0,microsoft index server 2.0 - Directory Traversal
9098| [19734] Microsoft Virtual Machine 2000 Series/3000 Series getSystemResource Vulnerability
9099| [19731] microsoft index server 2.0/indexing services for windows 2000 - Directory Traversal
9100| [19728] Microsoft Systems Management Server 2.0 Default Permissions Vulnerability
9101| [19425] Microsoft Data Access Components (MDAC) <= 2.1,Microsoft IIS 3.0/4.0,Microsoft Index Server 2.0,Microsoft Site Server Commerce Edition 3.0 i386 MDAC RDS Vulnerability (2)
9102| [19424] Microsoft Data Access Components (MDAC) <= 2.1,Microsoft IIS 3.0/4.0,Microsoft Index Server 2.0,Microsoft Site Server Commerce Edition 3.0 i386 MDAC RDS Vulnerability (1)
9103| [19376] Microsoft IIS 2.0/3.0/4.0 ISAPI GetExtensionVersion() Vulnerability
9104| [19143] "Microsoft Windows ""April Fools 2001"" Vulnerability"
9105| [19118] Microsoft IIS 3.0/4.0,Microsoft Personal Web Server 2.0/3.0/4.0 ASP Alternate Data Streams Vulnerability
9106| [18334] Microsoft Office 2003 Home/Pro 0day
9107| [18087] MS11-021 Microsoft Office 2007 Excel .xlb Buffer Overflow
9108| [18078] Microsoft Excel 2003 11.8335.8333 Use After Free
9109| [18067] Microsoft Excel 2007 SP2 Buffer Overwrite Exploit
9110| [17305] "Microsoft Windows Vista/Server 2008 ""nsiproxy.sys"" Local Kernel DoS Exploit"
9111| [14971] MOAUB #11 - Microsoft Office Word 2007 sprmCMajority Buffer Overflow
9112| [14782] Microsoft Office PowerPoint 2007 DLL Hijacking Exploit (rpawinet.dll)
9113| [14746] Microsoft Office Groove 2007 DLL Hijacking Exploit (mso.dll)
9114| [14744] Microsoft Visio 2003 DLL Hijacking Exploit (mfc71enu.dll)
9115| [12450] Microsoft SharePoint Server 2007 XSS Vulnerability
9116| [10068] Microsoft Windows 2000-2008 Embedded OpenType Font Engine Remote Code Execution
9117| [4121] Microsoft Excel 2000/2003 Sheet Name Vulnerability PoC
9118| [3973] Microsoft Office 2000 (OUACTRL.OCX 1.0.1.9) - Remote DoS Exploit
9119| [3690] microsoft office word 2007 - Multiple Vulnerabilities
9120| [3260] Microsoft Word 2000 Unspecified Code Execution Exploit (0day)
9121| [2523] Microsoft Office 2003 PPT Local Buffer Overflow PoC
9122| [2091] Microsoft PowerPoint 2003 SP2 Local Code Execution Exploit (french)
9123| [2001] Microsoft Word 2000/2003 Unchecked Boundary Condition Vulnerability
9124| [1999] Microsoft Word 2000/2003 Hlink Local Buffer Overflow Exploit PoC
9125| [1988] Microsoft Excel 2003 Hlink Local Buffer Overflow Exploit (italian)
9126| [1986] Microsoft Excel 2000/2003 Hlink Local Buffer Overflow Exploit (french)
9127| [1958] Microsoft Excel 2003 Hlink Stack/SEH Buffer Overflow Exploit
9128| [28238] Microsoft SharePoint 2013 (Cloud) - Persistent Exception Handling Vulnerability MS13-067
9129| [23034] Microsoft URLScan 2.5/ RSA Security SecurID 5.0 Configuration Enumeration Weakness
9130| [22850] Microsoft Office OneNote 2010 Crash PoC
9131| [22679] Microsoft Visio 2010 Crash PoC
9132| [22655] Microsoft Publisher 2013 Crash PoC
9133| [22621] Microsoft Netmeeting 2.1/3.0.1 4.4.3385 CALLTO URL Buffer Overflow Vulnerability
9134| [22330] Microsoft Office Excel 2010 Crash PoC
9135| [22310] Microsoft Office Publisher 2010 Crash PoC
9136| [22237] Microsoft Office Picture Manager 2010 Crash PoC
9137| [22215] Microsoft Office Word 2010 Crash PoC
9138| [19451] Microsoft Windows 98 a/98 b/98SE,Solaris 2.6 IRDP Vulnerability
9139| [19440] Microsoft Windows NT 4.0/SP 1/SP 2/Sp 3/SP 4/SP 5 Malformed Dialer Entry Vulnerability
9140| [19372] Microsoft Windows NT 4.0/SP 1/SP 2/SP 3/SP 4/SP 5 Null Session Admin Name Vulnerability
9141| [17164] Microsoft Reader <= 2.1.1.3143 NULL Byte Write
9142| [17163] Microsoft Reader <= 2.1.1.3143 Array Overflow
9143| [17162] Microsoft Reader <= 2.1.1.3143 Integer Overflow
9144| [17161] Microsoft Reader <= 2.1.1.3143 Heap Overflow
9145| [17160] Microsoft Reader <= 2.1.1.3143 Integer Overflow
9146| [14731] Microsoft Windows Movie Maker <= 2.6.4038.0 DLL Hijacking Exploit (hhctrl.ocx)
9147| [14723] Microsoft Power Point 2010 DLL Hijacking Exploit (pptimpconv.dll)
9148|
9149| OpenVAS (Nessus) - http://www.openvas.org:
9150| [902250] Microsoft Word 2003 'MSO.dll' Null Pointer Dereference Vulnerability
9151| [900125] Microsoft SQL Server 2000 sqlvdir.dll ActiveX Buffer Overflow Vulnerability
9152| [801597] Microsoft Office Excel 2003 Invalid Object Type Remote Code Execution Vulnerability
9153| [801596] Microsoft Excel 2007 Office Drawing Layer Remote Code Execution Vulnerability
9154| [801594] Microsoft PowerPoint 2007 OfficeArt Atom Remote Code Execution Vulnerability
9155| [800687] Microsoft Windows Server 2003 OpenType Font Engine DoS Vulnerability
9156| [800577] Microsoft Windows Server 2003 win32k.sys DoS Vulnerability
9157| [800343] Microsoft Word 2007 Sensitive Information Disclosure Vulnerability
9158| [103254] Microsoft SharePoint Server 2007 '_layouts/help.aspx' Cross Site Scripting Vulnerability
9159| [11992] Vulnerability in Microsoft ISA Server 2000 H.323 Filter(816458)
9160| [902931] Microsoft Office Remote Code Execution Vulnerabilities - 2720184 (Mac OS X)
9161| [902678] Microsoft Silverlight Code Execution Vulnerabilities - 2681578 (Mac OS X)
9162| [901210] Microsoft Office Privilege Elevation Vulnerability - 2721015 (Mac OS X)
9163|
9164| SecurityTracker - https://www.securitytracker.com:
9165| [1015347] Microsoft Windows 2000 Kernel APC Queue Bug Lets Local Users Gain Elevated Privileges
9166| [1013454] Microsoft Office InfoPath 2003 May Disclose System and Authentication Information to Remote Users
9167| [1013284] Microsoft Windows 2000 and XP Group Policy Can Be Bypassed By Microsoft Office Applications and By Flash Drives
9168| [1010687] Microsoft Windows 2000/NT POSIX Subsystem Buffer Overflow Lets Local Users Gain Elevated Privileges
9169| [1010352] Microsoft Windows 2000 Domains With Eight Characters May Let Remote Users With Expired Passwords Login
9170| [1010189] Microsoft Outlook 2003 Scripting Restrictions Can Be Bypassed By Remote Users
9171| [1010125] Microsoft Outlook 2003 Lets Remote Users Send E-mail to Cause the Recipient's Client to Contact a Remote Server
9172| [1009767] Microsoft Windows 2000 Domain Controller LDAP Flaw May Let Remote Users Restart the Authentication Service
9173| [1008324] Microsoft Exchange 2003 With Outlook Web Access and Windows SharePoint Services May Grant Incorrect E-mail Account Access to Remote Authenticated Users
9174| [1007905] Microsoft Windows Server 2003 Shell Folders Can Be Referenced Using Directory Traversal Characters
9175| [1007238] Microsoft Outlook Web Access Can Be Crashed By Remote Authenticated Users With an Outlook 2003 Client
9176| [1007152] Microsoft Windows 2000 Accessibility Utility Manager Lets Local Users Gain Elevated Privileges
9177| [1007099] Microsoft Windows 2000 ShellExecute() Buffer Overflow May Let Users Execute Arbitrary Code
9178| [1007093] Microsoft Active Directory Stack Overflow in 'Lsaas.exe' Lets Remote Users Crash the Windows 2000 Server
9179| [1006959] Microsoft Windows Server 2003 Drivers May Leak Information From Memory Via Ethernet Packets Containing TCP Streams
9180| [1006580] Microsoft Windows 2003 'win2k.sys' Printing Bug Lets Users Crash the System
9181| [1006534] Microsoft Proxy Service in Proxy Server 2.0 Has Unspecified Flaw That Lets Remote Users Stop Traffic
9182| [1006286] Microsoft Windows 2000/XP PostMessage() API Flaw May Let Local Users Grab Passwords from Local Dialog Boxes
9183| [1006280] Protegrity Secure.Data for Microsoft SQL Server 2000 Contains Buffer Oveflows That Let Remote Users Execute Arbitrary Code
9184| [1005254] Microsoft NT, 2000, and XP Operating Systems May Execute a 16-bit Application Even When The File Has No Execute Permissions
9185| [1005068] Microsoft NTFS Filesystem in Windows NT and Windows 2000 Has Auditing Hole That Lets Local Users Access Files Without the File Access Being Audited
9186| [1004587] Microsoft SQL Server 2000 Buffer Overflow in OpenDataSource() Function May Let Remote Users Gain SYSTEM Privileges on the Server
9187| [1004528] Microsoft SQLXML Component of Microsoft SQL Server 2000 Contains an Input Validation Flaw in an XML SQL Tag That Allows Cross-Site Scripting Attacks
9188| [1004527] Microsoft SQLXML Component of Microsoft SQL Server 2000 Contains a Buffer Overflow That Lets Remote Users Take Full Control of the System
9189| [1004407] Microsoft Exchange 2000 Flaw in Processing a Certain Malformed SMTP Command Allows Remote Users to Deny Service to the Server
9190| [1004357] Microsoft Windows Debugging Facility for Windows NT4 and 2000 Has Authentication Hole That Lets Local Users Execute Arbitrary Code with SYSTEM Privileges
9191| [1004083] Microsoft Windows 2000 'microsoft-ds' Service Flaw Allows Remote Users to Create Denial of Service Conditions By Sending Malformed Packets
9192| [1004022] Microsoft Windows 2000 Group Policy Object Enforcement Can Be Circumvented if User License Limits are Exceeded
9193| [1003975] Microsoft Windows NT, 2000, and XP Kernel Buffer Overflow in Processing Multiple UNC Provider (MUP) Requests May Let Local Users Obtain System Level Privileges
9194| [1003949] Microsoft Windows 2000 DCOM Implementation Flaw May Disclose Memory Contents to Remote Users
9195| [1003816] Microsoft Windows 2000 Automatic Log Off Policy Fails to Expire Sessions in Progress
9196| [1003688] Microsoft Exchange Server 2000 Command Processing Bug Lets Remote Users Cause the SMTP Service to Crash
9197| [1003687] Microsoft Windows 2000 and Windows XP SMTP Service Command Processing Bug Lets Remote Users Cause the SMTP Service to Crash
9198| [1003634] Microsoft XML Core Services in SQL Server 2000 Lets Remote Scripts Access and Send Local Files
9199| [1003629] Microsoft Commerce Server 2000 AuthFilter Buffer Overflow Lets Remote Users Execute Arbitrary Code on the Server With LocalSystem Privileges to Gain Full Control of the Server
9200| [1003472] Microsoft Telnet Server for Windows 2000 and for Interix Has a Buffer Overflow That May Let Remote Users Execute Code on the Server with System Level Privileges
9201| [1003469] Microsoft Exchange 2000 Server Allows Remote Users to View and Possibly Modify Registry Settings
9202| [1003402] Microsoft Windows NT 4.0 and Windows 2000 Domain Controllers May Give Elevated Privileges to Remote Users Who Are Valid Administrators on Other Trusted Domains
9203| [1002922] Microsoft Windows 2000 Internet Key Exchange (IKE) Service Can Be Crashed By Remote Users
9204| [1002754] Terminal Services on Microsoft Windows 2000 and XP Allow Remote Users to Log Bogus IP Addresses Instead of the User's Genuine Address
9205| [1002731] Microsoft Windows 2000 RunAs Service May Disclose Authentication Credentials to Local Users
9206| [1002730] Microsoft Windows 2000 RunAs Utility May Disclose Sensitive Information to Local Users
9207| [1002729] Microsoft Windows 2000 RunAs Service Allows Local Users to Disable the Service
9208| [1002356] Microsoft Outlook 2000 Animated Assistant Prevents the Screen Saver from Activating, Allowing Physically Local Users to Access the System
9209| [1002206] Microsoft Internet Security and Acceleration (ISA) Server 2000 Can Be Disrupted By Remote Users Due to Memory Leaks and Also Allows Cross-Site Scripting Attacks
9210| [1002106] Microsoft Windows 2000 and Windows NT 4.0 RPC Input Validation Failure Lets Remote Users Destabilize the Operating System
9211| [1002099] Microsoft Windows 2000 Telnet Service Can Be Crashed By Remote Users
9212| [1002098] Windows Terminal Services in Microsoft Windows 2000 and NT 4.0 Can Be Crashed By Remote Users Due to a Memory Leak
9213| [1001993] Microsoft Windows 2000, Linux 2.4, NetBSD, FreeBSD, and OpenBSD May Let Remote Users Affect TCP Performance
9214| [1001931] Microsoft Windows 2000 SMTP Service May Allow Unauthorized Remote Users to Relay E-mail via the Service
9215| [1001832] Microsoft Windows 2000 LDAP Server Lets Remote Users Gain Administrator Access to the Domain Controller When Configured to Support LDAP over SSL
9216| [1001701] Microsoft Windows 2000 Telnet Server Allows Local Users to Gain System-Level Privileges and Lets Remote Users Crash the Server
9217| [1001605] Microsoft Windows 2000 Allows Local Users to Elevate Privileges
9218| [1001565] Microsoft IIS Web Server on Windows 2000 Allows Remote Users to Cause the Server to Consume All Available Memory Due to Memory Leak in WebDAV Lock Method
9219| [1001513] Microsoft Windows 2000 Indexing Service Allows Remote Users to View Include Programming Files
9220| [1001501] Microsoft Windows 2000 Domain Controllers Can Be Effectively Halted By Remote Users
9221| [1001464] Microsoft Internet Information Server IIS 5.0 for Windows 2000 Lets Remote Users Execute Arbitrary Code on the Server and Gain Control of the Server
9222| [1001240] Microsoft FTP Client for Windows 2000 Still Vulnerable to Executing Arbitrary Code in Limited Situations
9223| [1001088] Microsoft Internet Explorer with Services for Unix 2.0 Can Create Malicious Files on the User's Host
9224|
9225| OSVDB - http://www.osvdb.org:
9226| [90257] Microsoft Windows Server 2003 ICACLS.EXE Permission Inheritance Weakness
9227| [86790] Microsoft Virtual PC 2007 Crafted x86 Instruction Sequence Handling Local DoS
9228| [86061] Microsoft Windows Server 2008 R1 CSRSS ReadConsole / CloseHandle Local DoS
9229| [79442] Microsoft Windows Server 2008 DNS Server Service Cache Update Policy Deleted Domain Name Resolving Weakness
9230| [72670] Microsoft Windows Server 2003 ActiveDirectory BROWSER ELECTION Remote Overflow
9231| [68554] Microsoft Windows Server 2008 Shared Cluster Disks Addition Default Permission Weakness
9232| [62251] Microsoft Windows Server 2008 Hyper-V Crafted Instruction Sequence DoS
9233| [60329] Microsoft Windows 2000 NetBIOS Continuation Packet Remote DoS
9234| [59733] Microsoft Windows 2000 Terminal Services Screensaver Screen Minimization Locking Weakness
9235| [59731] Microsoft Windows 2000 DCOM Client Alter Context Request Remote Information Disclosure
9236| [59730] Microsoft Windows 2000 Terminal Services Disconnect Feature Local Privilege Escalation
9237| [59514] Microsoft Windows 2000 Task Manager Uppercase Process Name Termination Weakness
9238| [59509] Microsoft Windows 2000 Encrypted File System Cleartext Backup File Local Disclosure
9239| [59346] Microsoft Windows 2000 Crafted TCP/UDP Traffic CPU Consumption Remote DoS
9240| [55836] Microsoft ISA Server 2006 Radius OTP Security Bypass
9241| [53663] Microsoft Office Word 2000 WordPerfect 6.x Converter Document Handling Stack Corruption
9242| [50589] Microsoft SQL Server 2000 sp_replwritetovarbin() Stored Procedure Overflow
9243| [37629] Microsoft Windows 2000 RPC Authentication Unspecified Information Disclosure
9244| [37628] Microsoft Windows 2000 RPC Authentication Crafted Request Remote DoS
9245| [36034] Microsoft Office 2000 Controllo ActiveX (OUACTRL.OCX) HelpPopup Method Overflow
9246| [34489] Microsoft Office 2003 Malformed WMF File Handling DoS
9247| [34488] Microsoft Excel 2003 XLS Handling Corrupt Format DoS
9248| [31251] Microsoft Office 2003 Brazilian Portuguese Grammar Checker Arbitrary Code Execution
9249| [29529] Microsoft Windows 2000 creator.dll ActiveX COM Object Memory Corruption
9250| [29528] Microsoft Windows 2000 msdxm.ocx ActiveX COM Object Memory Corruption
9251| [29527] Microsoft Windows 2000 myinfo.dll ActiveX COM Object Memory Corruption
9252| [29526] Microsoft Windows 2000 ciodm.dll ActiveX COM Object Memory Corruption
9253| [28539] Microsoft Word 2000 Unspecified Code Execution
9254| [24121] Microsoft Commerce Server 2002 authfiles/login.asp Authentication Bypass
9255| [24081] Microsoft Outlook 2003 Unspecified Malformed Word Attachment DoS
9256| [23484] Microsoft SQLServer 2000 sp_addalias Procedure Privileged Alias Creation
9257| [23234] Microsoft SQLServer 2000 Unspecified Invalid Client Buffer DoS
9258| [23231] Microsoft SQL Server 2000 SQL Profiler Multiple Method DoS
9259| [23205] Microsoft SQLServer 2000 Crafted Sort Command User Mode Scheduler (UMS) Bypass DoS
9260| [23203] Microsoft SQL Server 2000 Database Name Transact-SQL Statement Privilege Escalation
9261| [23202] Microsoft SQLServer 2000 sysmembers Virtual Table Query Overflow
9262| [23201] Microsoft SQL Server 2000 Dynamic Transact-SQL Statement Disclosure
9263| [23200] Microsoft SQLServer 2000 Encrypted Stored Procedure Dynamic Query Disclosure
9264| [21907] Microsoft Office InfoPath 2003 Mshtml.dll Form Handling DoS
9265| [21598] Microsoft Windows 2000 NetBIOS Port Malformed TCP Packet Parsing Remote DoS
9266| [20256] Microsoft Windows 2000 NTFS Volume Macintosh Client Directory Permission Modification
9267| [20222] Microsoft Windows 2000 runas.exe Named Pipe Spoofing Information Disclosure
9268| [20221] Microsoft Windows 2000 runas.exe Named Pipe Single Thread DoS
9269| [20220] Microsoft Windows 2000 runas.exe Cleartext Authentication Information Disclosure
9270| [20002] Microsoft Windows 2000 CHKDSK Fix Mode File ACL Failure
9271| [20001] Microsoft Windows 2000 Terminal Service Client Connection IP Logging Failure
9272| [20000] Microsoft Windows 2000 Domain Administrator Computer Lock Bypass
9273| [19999] Microsoft Windows 2000 FQDN Domain Login Password Expiry Bypass
9274| [19998] Microsoft Windows 2000 UPN Credentialed Login Group Policy Failure
9275| [19997] Microsoft Windows 2000 WideCharToMultiByte Function String Termination Issue
9276| [19996] Microsoft Windows 2000 Event ID 1704 Group Policy Failure
9277| [19995] Microsoft Windows 2000 SECEDIT Long Folder ACL Set Issue
9278| [19994] Microsoft Windows 2000 audit directory service access 565 Event Logging Failure
9279| [19993] Microsoft Windows 2000 LDAPS CA Trust Issue
9280| [19264] Microsoft Exchange Server 2003 Crafted IMAP4 Folder Listing Request DoS
9281| [17031] Microsoft ISA Server 2000 SecureNAT Traffic Saturation DoS
9282| [15343] Microsoft Windows Server 2003 Malformed HTTP Cookie Header CGI DoS
9283| [15341] Microsoft Windows Server 2003 SMB Redirector Processing DoS
9284| [15340] Microsoft Windows Server 2003 Terminal Service Client Print DoS
9285| [15338] Microsoft Windows Server 2003 Terminal Session Close DoS
9286| [15337] Microsoft Windows Server 2003 CreateProcessWithLogonW() Function Process Disclosure
9287| [15336] Microsoft Windows Server 2003 Shutdown.exe Shut Down Failure
9288| [15335] Microsoft Windows Server 2003 MIT Kerberos Realm Authentication Group Policy Failure
9289| [15334] Microsoft Windows Server 2003 Shared Folder Permission Weakness
9290| [15333] Microsoft Windows Server 2003 EFS File Copy LDAP Connection DoS
9291| [15332] Microsoft Windows Server 2003 Citrix Metaframe Encryption Policy Failure
9292| [15331] Microsoft Windows Server 2003 Home Folder Path Permission Inheritance Failure
9293| [14617] Microsoft Exchange Server 2003 Folder Handling DoS
9294| [14430] Microsoft Commerce Server 2000 Profile Service Affected API Overflow
9295| [13996] Microsoft Windows 2000 IKE Malformed Packet Saturation Remote DoS
9296| [13762] Microsoft 2000 Domain Controller Directory Service Restore Mode Blank Password
9297| [13761] Microsoft Exchange 2000 Malformed URL Request DoS
9298| [13475] Microsoft Windows 2000 Telnet Service Predictable Named Pipe Arbitrary Command Execution Variant
9299| [13474] Microsoft Windows 2000 Telnet Service Predictable Named Pipe Arbitrary Command Execution
9300| [13441] Microsoft Windows 2000 Security Interface Change Password Option Account Enumeration
9301| [13437] Microsoft Windows 2000 Debug Register Local Privilege Escalation
9302| [13424] Microsoft Windows 2000 Current Password Change Policy Bypass
9303| [13423] Microsoft Windows 2000 Terminal Server SYSVOL Share Connection Saturation Restriction Bypass
9304| [13415] Microsoft Windows 2000 System Root Folder Search Path Permission Weakness
9305| [13410] Microsoft Windows 2000 Accessibility Utility Manager Arbitrary Code Execution
9306| [11958] Microsoft Outlook 2003 Image Rendering Security Policy Bypass
9307| [11945] Microsoft Outlook 2002 IFRAME Tag Embedded URL
9308| [11944] Microsoft Outlook 2002 HREF Tag Embedded JavaScript Execution
9309| [11750] Microsoft Windows 2000 Message Queue Manager Queue Registration Request Overflow DoS
9310| [11712] Microsoft ISA Server 2000 H.323 Filter Overflow
9311| [10633] Microsoft Windows 2000 Protected Store Weak Encryption Default
9312| [9386] Microsoft Windows 2000 msinfo32.exe msinfo_file Variable Overflow
9313| [8243] Microsoft SMS Port 2702 DoS
9314| [7202] Microsoft PowerPoint 2000 File Loader Overflow
9315| [7179] Microsoft Windows 2000 Event Viewer Snap-in Overflow
9316| [6971] Microsoft ISA Server 2000 ICMP Rule Bypass During Startup
9317| [6970] Microsoft ISA Server 2000 Web Publishing Unencrypted Credentials Disclosure
9318| [6969] Microsoft ISA Server 2000 Invalid DNS Request DoS
9319| [6968] Microsoft ISA Server 2000 FTP Port Scan Bounce Weakness
9320| [6967] Microsoft ISA Server 2000 UDP Packet Winsock DoS
9321| [6965] Microsoft ISA Server 2000 SSL Packet DoS
9322| [6964] Microsoft ISA Server 2000 DNS Intrusion Detection Filter DoS
9323| [6515] Microsoft Windows 2000 Domain Expired Account Authentication
9324| [5179] Microsoft Windows 2000 microsoft-ds DoS
9325| [5171] Microsoft Word 2002 Mail Merge Tool Execute Arbitrary Script
9326| [4779] Microsoft Desktop Engine (MSDE) 2000 Stored Procedure SQL Injection
9327| [4778] Microsoft SQL Server 2000 Stored Procedure SQL Injection
9328| [4777] Microsoft Desktop Engine (MSDE) 2000 Database Consistency Checkers (DBCCs) Overflow
9329| [4776] Microsoft SQL Server 2000 Database Consistency Checkers (DBCCs) 2000 Overflow
9330| [4170] Microsoft Windows 2000 Server Media Services TCP Packet Handling Remote DoS
9331| [4168] Microsoft Outlook 2002 mailto URI Script Injection
9332| [3490] Microsoft Exchange 2003 OWA Mailbox Access Information Disclosure
9333| [2705] Microsoft Windows 2000 Windows Troubleshooter ActiveX Overflow
9334| [2655] Microsoft Windows Server 2003 Shell Folders Arbitrary File Access
9335| [2540] Microsoft Windows 2003 Server Buffer Overflow Protection Mechanism Bypass
9336| [2244] Microsoft Windows 2000 ShellExecute() API Let
9337| [2237] Microsoft Windows 2000 Active Directory Lsass.exe Overflow
9338| [1949] Symantec Norton Anti-Virus for Microsoft Exchange 2000 INBOX Path Information Disclosure
9339| [1764] Microsoft Windows 2000 Domain Controller DoS
9340| [1758] Microsoft Windows 2000 Network DDE Escalated Privileges
9341| [1755] Microsoft Windows 2000 RDP Malformed Packet Handling Remote DoS
9342| [1672] Microsoft Windows 2000 Telnet Session Timeout DoS
9343| [1633] Microsoft Windows 2000 System Monitor ActiveX LogFileName Parameter Validation Overflow
9344| [1621] Microsoft Indexing Services for Windows 2000 .htw XSS
9345| [1591] Microsoft Windows 2000 OEMPreinstall Installation Permission Weakness
9346| [1578] Microsoft Windows 2000 Simplified Chinese IME Local Privilege Escalation
9347| [1500] Microsoft Word / Excel / Powerpoint 2000 Object Tag Buffer Overflow
9348| [1437] Microsoft Windows 2000 Telnet Server Binary Zero Parsing Remote DoS
9349| [1399] Microsoft Windows 2000 Windows Station Access
9350| [1328] Microsoft Office 2000 UA Control ActiveX (Ouactrl.ocx) Show Me Function Remote Code Execution
9351| [1297] Microsoft Windows 2000 Active Directory Object Attribute
9352| [1292] Microsoft Windows NT 4.0 / 2000 cmd.exe Buffer Overflow
9353| [773] Microsoft Windows 2000 Group Policy File Lock DoS
9354| [515] Microsoft Windows 2000 LDAP Server Arbitrary User Password Modification
9355| [454] Microsoft Windows 2000 NTLM Domain Account Lockout Policy Bypass
9356| [403] Microsoft Windows 2000 Still Image Service WM_USER Message Local Overflow
9357| [398] Microsoft Windows 2000 Malformed RPC Traffic Local Security Policy Corruption DoS
9358| [307] Microsoft FrontPage 2000 Server Extensions shtml.exe Path Disclosure
9359| [69085] Microsoft Office 2010 RTF File Handling pFragments Buffer Overflow Arbitrary Code Execution
9360|_
9361Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
9362Aggressive OS guesses: Microsoft Windows Server 2012 (98%), Microsoft Windows Server 2012 or Windows Server 2012 R2 (98%), Microsoft Windows Server 2012 R2 (98%), Minix 2.0.4 (95%), Oracle Solaris 11 (94%), Sun Solaris 10 (94%), Linux 2.6.32 (92%), Linux 3.18 (92%), Microsoft Windows 7 Professional (91%), Microsoft Windows Server 2008 R2 SP1 (90%)
9363No exact OS matches for host (test conditions non-ideal).
9364Uptime guess: 15.004 days (since Fri Sep 27 09:10:44 2019)
9365Network Distance: 11 hops
9366TCP Sequence Prediction: Difficulty=261 (Good luck!)
9367IP ID Sequence Generation: Incremental
9368Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
9369
9370TRACEROUTE (using port 80/tcp)
9371HOP RTT ADDRESS
93721 37.03 ms 10.243.204.1
93732 54.62 ms vlan102.as02.qc1.ca.m247.com (176.113.74.17)
93743 54.66 ms irb-0.agg1.qc1.ca.m247.com (37.120.128.168)
93754 54.61 ms te-1-5-2-0.bb1.fra2.de.m247.com (82.102.29.44)
93765 54.66 ms motl-b1-link.telia.net (62.115.162.41)
93776 54.69 ms toro-b1-link.telia.net (62.115.134.48)
93787 54.74 ms chi-b21-link.telia.net (62.115.118.230)
93798 54.76 ms hurricane-ic-350465-chi-b21.c.telia.net (62.115.181.206)
93809 72.36 ms 216.66.76.146
938110 54.78 ms 216.111.200.58
938211 50.16 ms a67-209-250-173.cust.mi.winntel.net (67.209.250.173)
9383
9384NSE: Script Post-scanning.
9385Initiating NSE at 09:15
9386Completed NSE at 09:15, 0.00s elapsed
9387Initiating NSE at 09:15
9388Completed NSE at 09:15, 0.00s elapsed
9389######################################################################################################################################
9390Starting Nmap 7.80 ( https://nmap.org ) at 2019-10-12 09:16 EDT
9391NSE: Loaded 163 scripts for scanning.
9392NSE: Script Pre-scanning.
9393Initiating NSE at 09:16
9394Completed NSE at 09:16, 0.00s elapsed
9395Initiating NSE at 09:16
9396Completed NSE at 09:16, 0.00s elapsed
9397Initiating Parallel DNS resolution of 1 host. at 09:16
9398Completed Parallel DNS resolution of 1 host. at 09:16, 0.02s elapsed
9399Initiating SYN Stealth Scan at 09:16
9400Scanning a67-209-250-173.cust.mi.winntel.net (67.209.250.173) [1 port]
9401Discovered open port 443/tcp on 67.209.250.173
9402Completed SYN Stealth Scan at 09:16, 0.11s elapsed (1 total ports)
9403Initiating Service scan at 09:16
9404Scanning 1 service on a67-209-250-173.cust.mi.winntel.net (67.209.250.173)
9405Completed Service scan at 09:16, 12.96s elapsed (1 service on 1 host)
9406Initiating OS detection (try #1) against a67-209-250-173.cust.mi.winntel.net (67.209.250.173)
9407adjust_timeouts2: packet supposedly had rtt of -189221 microseconds. Ignoring time.
9408adjust_timeouts2: packet supposedly had rtt of -189221 microseconds. Ignoring time.
9409Retrying OS detection (try #2) against a67-209-250-173.cust.mi.winntel.net (67.209.250.173)
9410Initiating Traceroute at 09:16
9411Completed Traceroute at 09:16, 0.15s elapsed
9412Initiating Parallel DNS resolution of 11 hosts. at 09:16
9413Completed Parallel DNS resolution of 11 hosts. at 09:16, 0.21s elapsed
9414NSE: Script scanning 67.209.250.173.
9415Initiating NSE at 09:16
9416Completed NSE at 09:18, 106.09s elapsed
9417Initiating NSE at 09:18
9418Completed NSE at 09:18, 0.69s elapsed
9419Nmap scan report for a67-209-250-173.cust.mi.winntel.net (67.209.250.173)
9420Host is up (0.077s latency).
9421
9422PORT STATE SERVICE VERSION
9423443/tcp open ssl/http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
9424| http-brute:
9425|_ Path "/" does not require authentication
9426|_http-chrono: Request times for /; avg: 402.97ms; min: 350.03ms; max: 461.07ms
9427|_http-csrf: Couldn't find any CSRF vulnerabilities.
9428|_http-date: Sat, 12 Oct 2019 13:17:03 GMT; +26s from local time.
9429|_http-devframework: Couldn't determine the underlying framework or CMS. Try increasing 'httpspider.maxpagecount' value to spider more pages.
9430|_http-dombased-xss: Couldn't find any DOM based XSS.
9431|_http-drupal-enum: Nothing found amongst the top 100 resources,use --script-args number=<number|all> for deeper analysis)
9432| http-errors:
9433| Spidering limited to: maxpagecount=40; withinhost=a67-209-250-173.cust.mi.winntel.net
9434| Found the following error pages:
9435|
9436| Error Code: 404
9437|_ https://a67-209-250-173.cust.mi.winntel.net:443/
9438|_http-feed: Couldn't find any feeds.
9439|_http-fetch: Please enter the complete path of the directory to save data in.
9440| http-headers:
9441| Content-Type: text/html; charset=us-ascii
9442| Server: Microsoft-HTTPAPI/2.0
9443| Date: Sat, 12 Oct 2019 13:17:06 GMT
9444| Connection: close
9445| Content-Length: 315
9446|
9447|_ (Request type: GET)
9448|_http-jsonp-detection: Couldn't find any JSONP endpoints.
9449|_http-mobileversion-checker: No mobile version detected.
9450| http-security-headers:
9451| Strict_Transport_Security:
9452|_ HSTS not configured in HTTPS Server
9453|_http-server-header: Microsoft-HTTPAPI/2.0
9454| http-sitemap-generator:
9455| Directory structure:
9456| Longest directory structure:
9457| Depth: 0
9458| Dir: /
9459| Total files found (by extension):
9460|_
9461|_http-stored-xss: Couldn't find any stored XSS vulnerabilities.
9462|_http-title: Not Found
9463| http-vhosts:
9464|_127 names had status 404
9465|_http-wordpress-enum: Nothing found amongst the top 100 resources,use --script-args search-limit=<number|all> for deeper analysis)
9466|_http-wordpress-users: [Error] Wordpress installation was not found. We couldn't find wp-login.php
9467|_http-xssed: No previously reported XSS vuln.
9468| vulscan: VulDB - https://vuldb.com:
9469| [141625] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 DirectX memory corruption
9470| [141624] Microsoft Windows 7 SP1/Server 2008 R2 SP1 Graphics Component information disclosure
9471| [139966] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Kernel information disclosure
9472| [139923] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Graphics Component information disclosure
9473| [139905] Microsoft Windows Server 2008 SP2 DHCP Server memory corruption
9474| [137573] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
9475| [137567] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
9476| [137566] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
9477| [137565] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
9478| [137564] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
9479| [136343] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
9480| [136342] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
9481| [136341] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
9482| [136316] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
9483| [136315] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
9484| [136313] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
9485| [136311] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
9486| [136309] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
9487| [136302] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
9488| [136298] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
9489| [136297] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Win32k memory corruption
9490| [131683] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Win32k memory corruption
9491| [131642] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Active Directory privilege escalation
9492| [127822] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2012 Kernel information disclosure
9493| [125103] Microsoft Windows Server 2008 SP2 Graphics Component information disclosure
9494| [123853] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Kernel Memory information disclosure
9495| [122858] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 LNK memory corruption
9496| [122833] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI+ memory corruption
9497| [121109] Microsoft Wireless Display Adapter V2 2.0.8350/2.0.8365/2.0.8372 privilege escalation
9498| [120449] Microsoft Forefront Unified Access Gateway 2000 InitParams.aspx Parameter Server-Side Request Forgery
9499| [119469] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Kernel privilege escalation
9500| [116015] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1 memory corruption
9501| [114563] Microsoft Office 2007 SP3/2010 SP2/2013/2013 RT SP1 memory corruption
9502| [114528] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI privilege escalation
9503| [114524] Microsoft ASP.NET Core 2.0 denial of service
9504| [114523] Microsoft ASP.NET Core 2.0 Kestrel Web Application privilege escalation
9505| [113257] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2012 Kernel information disclosure
9506| [113256] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2012 Kernel information disclosure
9507| [113255] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2012 Kernel information disclosure
9508| [113247] Microsoft Windows 7 SP1/Server 2008 R2 SP1 EOT Font Engine information disclosure
9509| [113246] Microsoft Windows 7 SP1/Server 2008 R2 SP1 EOT Font Engine information disclosure
9510| [113245] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2012 EOT Font Engine information disclosure
9511| [113244] Microsoft Windows 7 SP1/Server 2008 R2 SP1 EOT Font Engine information disclosure
9512| [113235] Microsoft Outlook 2007 SP3/2010 SP2/2013 SP1/2016 privilege escalation
9513| [113234] Microsoft Office 2007 SP2/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
9514| [113216] Microsoft Outlook 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
9515| [112285] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
9516| [112284] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
9517| [112283] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
9518| [112282] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
9519| [111578] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
9520| [111577] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
9521| [111576] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
9522| [111575] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
9523| [111574] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
9524| [111573] Microsoft Office 2007/2010/2013/2016 Equation Editor memory corruption
9525| [111572] Microsoft Office 2007/2010/2013/2016 Equation Editor memory corruption
9526| [111570] Microsoft Office 2007/2010/2013/2016 Equation Editor memory corruption
9527| [111568] Microsoft Excel 2007/2010/2013/2016 memory corruption
9528| [111566] Microsoft Word 2007/2010/2013/2016 memory corruption
9529| [111565] Microsoft Word 2007/2010/2013 Email Message memory corruption
9530| [111563] Microsoft Outlook 2007/2010/2013/2016 Email Message privilege escalation
9531| [111347] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Color Management Icm32.dll information disclosure
9532| [109388] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2016 memory corruption
9533| [109387] Microsoft ASP.NET Core 2.0 privilege escalation
9534| [109386] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
9535| [109385] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 Security Feature Macro privilege escalation
9536| [109381] Microsoft Office/Word 2007 SP3/2010 SP2 memory corruption
9537| [107703] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
9538| [106530] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
9539| [106528] Microsoft PowerPoint 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
9540| [106515] Microsoft Publisher 2007 SP3/2010 SP2 memory corruption
9541| [106497] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Uniscribe memory corruption
9542| [106476] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
9543| [106475] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
9544| [105051] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Font Library privilege escalation
9545| [105032] Microsoft Internet Explorer 9/10 on Server 2008/Server 2012 memory corruption
9546| [102513] Microsoft Windows Server 2003 SP2/XP SP3 OLE olecnv32.dll privilege escalation
9547| [102512] Microsoft Windows Server 2003 SP2/XP SP3 rpc privilege escalation
9548| [102511] Microsoft Windows Server 2003 SP2/XP SP3 RDP EsteemAudit privilege escalation
9549| [102447] Microsoft PowerPoint/SharePoint Server 2007 SP3 privilege escalation
9550| [102444] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 privilege escalation
9551| [102442] Microsoft Outlook 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 Bypass privilege escalation
9552| [102441] Microsoft Outlook 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
9553| [102401] Microsoft Windows 7 SP1/Server 2008 R2 SP1 GDI USP10!NextCharInLiga Uniscribe Font information disclosure
9554| [101491] Microsoft Windows up to XP SP3/Server 2003 SP2 Remote Desktop Protocol gpkcsp.dll memory corruption
9555| [101017] Microsoft Office 2007 SP3/2010 SP2/2016 memory corruption
9556| [101012] Microsoft Office 2007 SP3/2010 SP2/2011/2013 SP1/2016 memory corruption
9557| [101011] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 ActiveX Object Memory memory corruption
9558| [100854] Microsoft Windows Server 2003 SP2 RRAS ERRATICGOPHER memory corruption
9559| [99904] Microsoft Windows Server 2003 SP2/XP SP3 SmartCard Authentication RDP Packet EsteemAudit privilege escalation
9560| [99698] Microsoft OneNote 2007 SP3/2010 SP2 DLL Loader privilege escalation
9561| [99684] Microsoft Excel 2007 SP3/2010 SP2 Memory information disclosure
9562| [99654] Microsoft Outlook 2007 SP3/2010 SP2/2011/2013 SP1/2016 Email Message privilege escalation
9563| [99653] Microsoft Outlook 2007 SP3/2010 SP2/2011/2013 SP1/2016 Email Message privilege escalation
9564| [99533] Microsoft Office 2007/2010/2013/2016 RTF Document Necurs Dridex memory corruption
9565| [98561] Microsoft IIS 6.0 on Windows Server 2003 WebDAV ScStoragePathFromUrl Long Header memory corruption
9566| [98092] Microsoft SharePoint Server 2007 SP3 memory corruption
9567| [98088] Microsoft SharePoint Server 2007 SP3 memory corruption
9568| [98087] Microsoft Office 2007 SP3/2010 SP2 memory corruption
9569| [98086] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
9570| [98085] Microsoft Excel 2007 SP3 memory corruption
9571| [98084] Microsoft Word 2007 SP3/2010 SP2/2011 memory corruption
9572| [98083] Microsoft Word 2007 SP3/2010 SP2/2011 memory corruption
9573| [98078] Microsoft Word/Excel 2007 SP3 memory corruption
9574| [98072] Microsoft Office 2007 SP3/2010 SP2/Word Viewer Graphics Component privilege escalation
9575| [98071] Microsoft Office 2007 SP3/2010 SP2/Word Viewer GDI+ information disclosure
9576| [98070] Microsoft Office 2007 SP3/2010 SP2/Word Viewer GDI+ information disclosure
9577| [94450] Microsoft Office 2007 SP3/2010 SP2/2011 memory corruption
9578| [94449] Microsoft Office 2007 SP3/2010 SP2/2011/2013 SP1 information disclosure
9579| [94448] Microsoft Office 2007 SP3/2010 SP2/2011/2013 SP1 information disclosure
9580| [94445] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1 information disclosure
9581| [94441] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 privilege escalation
9582| [94440] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
9583| [94439] Microsoft Office 2007 SP3/2011 privilege escalation
9584| [94438] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 privilege escalation
9585| [93542] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1 memory corruption
9586| [93541] Microsoft Office 2007 SP3 denial of service
9587| [93539] Microsoft Office 2007/2010 SP2/2011 memory corruption
9588| [93538] Microsoft Office 2007/2010 SP2/2011/2013 SP1 memory corruption
9589| [93537] Microsoft Office 2007/2010 SP2/2011 memory corruption
9590| [93396] Microsoft Office 2007/2010/2011 memory corruption
9591| [93395] Microsoft Office 2007/2010/2011 memory corruption
9592| [93394] Microsoft Office 2007/2010 memory corruption
9593| [92596] Microsoft Windows 7 SP1/Server 2008 R2/Server 2008 SP2/Vista SP2 Internet Messaging API File information disclosure
9594| [91554] Microsoft Exchange 2007/2010/2013/2016 Email information disclosure
9595| [91553] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
9596| [91552] Microsoft Office 2007/2010/2013/2013 RT/2016 spoofing
9597| [91551] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
9598| [91549] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
9599| [91548] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
9600| [91546] Microsoft Office 2007/2010/2013/2013 RT memory corruption
9601| [91545] Microsoft Office 2007/2010 memory corruption
9602| [91544] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
9603| [91542] Microsoft Office 2007/2010/2013/2013 RT/2016 information disclosure
9604| [90707] Microsoft OneNote 2007/2010/2013/2013 RT/2016 information disclosure
9605| [90706] Microsoft Office 2007/2010/2013/2013 RT Graphics memory corruption
9606| [90705] Microsoft Office 2007/2010/2011 memory corruption
9607| [90703] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
9608| [89039] Microsoft Office 2007 SP3/2010 SP2/2011/2013 RT SP1/2013 SP1 memory corruption
9609| [89034] Microsoft Windows Server 2008/Vista SP2 JScript/VBScript memory corruption
9610| [87960] Microsoft Windows Server 2008 R2/Server 2012/Server 2012 R2 Active Directory denial of service
9611| [87955] Microsoft Exchange 2007/2010/2013/2016 Oracle Outside In Libraries privilege escalation
9612| [87954] Microsoft Exchange 2007/2010/2013/2016 Oracle Outside In Libraries privilege escalation
9613| [87953] Microsoft Exchange 2007/2010/2013/2016 Oracle Outside In Libraries privilege escalation
9614| [87939] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 OLE DLL memory corruption
9615| [87938] Microsoft Office 2007 SP3/2010 SP2/2011 information disclosure
9616| [87937] Microsoft Office 2007 SP3/2010 SP2/2011 memory corruption
9617| [87935] Microsoft Windows Server 2008 R2 SP1/Server 2008 SP2/Vista SP2 VBScript/JScript memory corruption
9618| [87934] Microsoft Windows Server 2008 R2 SP1/Server 2008 SP2/Vista SP2 VBScript/JScript memory corruption
9619| [87933] Microsoft Windows Server 2008 R2 SP1/Server 2008 SP2/Vista SP2 VBScript/JScript memory corruption
9620| [87147] Microsoft Office 2007/2010 memory corruption
9621| [87145] Microsoft Windows Server 2008/Vista SP2 JScript/VBScript memory corruption
9622| [87144] Microsoft Windows Server 2008/Vista SP2 JScript/VBScript memory corruption
9623| [82228] Microsoft Excel 2007 SP3/2010 SP2 Office Document memory corruption
9624| [82225] Microsoft Word 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1 Office Document memory corruption
9625| [82224] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 Office Document memory corruption
9626| [81273] Microsoft Office 2007/2010/2013/2016 memory corruption
9627| [81272] Microsoft Office 2007/2010/2013 memory corruption
9628| [81265] Microsoft Windows Server 2008/Vista SP2 Library Loader memory corruption
9629| [80872] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
9630| [80871] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
9631| [80869] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
9632| [79506] Microsoft Windows 7/Server 2008/Server 2008 R2/Vista Library Loader memory corruption
9633| [79505] Microsoft Office 2007 memory corruption
9634| [79504] Microsoft Office 2007/2010/2013/2016 memory corruption
9635| [79503] Microsoft Office 2007/2010/2013 memory corruption
9636| [79502] Microsoft Office 2007/2010/2011 memory corruption
9637| [79501] Microsoft Office 2007/2010 memory corruption
9638| [79499] Microsoft Windows 7/Server 2008 R2 Uniscribe memory corruption
9639| [79493] Microsoft Windows Server 2008/Vista Graphics memory corruption
9640| [79190] Microsoft Word 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 Office Document memory corruption
9641| [79189] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 Office Document memory corruption
9642| [79187] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2016 Sandbox privilege escalation
9643| [79167] Microsoft Windows 7/Server 2008/Server 2008 R2/Vista Journal memory corruption
9644| [78372] Microsoft Visio 2007 SP3/2010 SP2 UML Data memory corruption
9645| [78371] Microsoft SharePoint Server 2007 SP3/2010 SP2 InfoPath Forms Services XXE information disclosure
9646| [77646] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1 EPS Image memory corruption
9647| [77629] Microsoft Excel 2007 SP3/2010 SP2/2011/2016 Office Document memory corruption
9648| [77627] Microsoft Excel 2007 SP3/2010 SP2 Office Document memory corruption
9649| [77626] Microsoft Excel 2007 SP3/2010 SP2/2011/2016 Office Document memory corruption
9650| [77617] Microsoft Office 2007 SP3/2010 SP2 OpenType Font memory corruption
9651| [77252] Microsoft Office 2007 SP3/2010 SP2 Office Graphics Library Font memory corruption
9652| [77038] Microsoft Windows Server 2008 SP2 UDDI Services cross site scripting
9653| [76497] Microsoft PowerPoint 2007 SP3/2010 SP2/2013 SP1 Office Document memory corruption
9654| [76491] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1 Office Document memory corruption
9655| [76467] Microsoft Word 2007 SP3/2010 SP2/2011/2013 RT SP1/2013 SP1 Office Document memory corruption
9656| [76466] Microsoft Word 2007 SP3/2010 SP2/2011/2013 RT SP1/2013 SP1 Office Document memory corruption
9657| [76464] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1 Office Document memory corruption
9658| [76463] Microsoft Excel 2007 SP3/2010 SP2/2011/2013 RT SP1/2013 SP1 Office Document memory corruption
9659| [76449] Microsoft Windows 8/8.1/Server 2008/Server 2012/Server 2012 R2 Hyper-V memory corruption
9660| [76440] Microsoft SQL Server 2008/2008 R2/2012/2014 Virtual Function Uninitialized Memory memory corruption
9661| [76439] Microsoft SQL Server 2008/2008 R2/2012/2014 Uninitialized Memory memory corruption
9662| [76438] Microsoft SQL Server 2008/2008 R2/2012/2014 Pointer Casting privilege escalation
9663| [75783] Microsoft Windows Server 2008/Server 2012 Active Directory Federation Services cross site scripting
9664| [75338] Microsoft SharePoint 2007/2010/2013 Content privilege escalation
9665| [75337] Microsoft Office 2007 SP3/2010 SP2/2011/2013 RT SP1/2013 SP1 memory corruption
9666| [75336] Microsoft Office 2007 SP3/2010 SP2/2011/2013 RT SP1/2013 SP1 memory corruption
9667| [74845] Microsoft Office 2007/2010/2013 Document Use-After-Free memory corruption
9668| [74844] Microsoft Office 2007/2010 Document Use-After-Free memory corruption
9669| [74837] Microsoft Office 2007/2010/2011/2013 RTF Document Use-After-Free privilege escalation
9670| [73979] Microsoft Exchange Server 2003 CU7/2003 SP1 Meeting privilege escalation
9671| [73978] Microsoft Exchange Server 2003 CU7/2003 SP1 cross site scripting
9672| [73977] Microsoft Exchange Server 2003 CU7/2003 SP1 cross site scripting
9673| [73976] Microsoft Exchange Server 2003 CU7/2003 SP1 cross site scripting
9674| [73975] Microsoft Exchange Server 2003 CU7/2003 SP1 cross site scripting
9675| [73964] Microsoft SharePoint 2007/2010/2013 cross site scripting
9676| [69158] Microsoft Office 2007/2010/2013 Use-After-Free memory corruption
9677| [69157] Microsoft Office 2007/2010/2013 OneTableDocumentStream memory corruption
9678| [68416] Microsoft Exchange 2007/2010/2013 Outlook Web Access Token spoofing
9679| [68409] Microsoft Office 2007/2010/2013 Use-After-Free memory corruption
9680| [68408] Microsoft Excel 2007/2010/2013 memory corruption
9681| [68407] Microsoft Excel 2007/2010 memory corruption
9682| [68405] Microsoft Word 2007/2010 Index Use-After-Free memory corruption
9683| [68195] Microsoft Windows 7/Server 2003/Server 2008/Vista Input Method Editor Sandbox privilege escalation
9684| [68189] Microsoft Windows Server 2003 SP2 TCP/IP Stack Stack-Based memory corruption
9685| [68188] Microsoft Word 2007 File memory corruption
9686| [68187] Microsoft Word 2007 File memory corruption
9687| [68186] Microsoft Word 2007 File memory corruption
9688| [67829] Microsoft Office 2007/2010/2011 Object memory corruption
9689| [67825] Microsoft .NET Framework 2.0/3.5/3.5.1 ASLR privilege escalation
9690| [71337] Microsoft Office 2000/2004/XP memory corruption
9691| [67355] Microsoft OneNote 2007 File Processing privilege escalation
9692| [67354] Microsoft SQL Server 2008 R2 SP2/2008 SP3/2012 SP1/2014 SQL Master Data Services cross site scripting
9693| [67353] Microsoft SQL Server 2008 R2 SP2/2008 SP3/2012 SP1/2014 T-SQL Query Stack-Based memory corruption
9694| [67018] Microsoft Windows Server 2008/Server 2012/Server 2012 R2 Service Bus AMQP Message denial of service
9695| [13545] Microsoft Word 2007 Embedded Font memory corruption
9696| [13397] Microsoft Windows 2000/Server 2003/XP DHCP Response DHCP ACK spoofing
9697| [13462] Microsoft Visual Studio 2002/2003/2005/2010 Debug Interface msdia.dll PDB File memory corruption
9698| [13229] Microsoft Office 2007/2010/2013 Common Control Library MSCOMCTL.OCX privilege escalation
9699| [13227] Microsoft Office 2007/2010/2013 Chinese Grammar Checker Library privilege escalation
9700| [13226] Microsoft SharePoint Server 2007/2010/2013 Page memory corruption
9701| [13225] Microsoft SharePoint Server 2007/2010/2013 cross site scripting
9702| [13224] Microsoft SharePoint Server 2007/2010/2013 Page memory corruption
9703| [12859] Microsoft Word 2003 Office Document Stack-Based memory corruption
9704| [12852] Microsoft Publisher 2003/2007 Publisher File pubconv.dll memory corruption
9705| [12845] Microsoft Word 2003 Office File Stack-Based memory corruption
9706| [12844] Microsoft Word 2007/2010 Office File memory corruption
9707| [12843] Microsoft Office 2007/2010/2011/2013 XML Parser Nested Entities Memory Consumption denial of service
9708| [12687] Microsoft Word/Office/Outlook 2003/2007/2010/2013 RTF Document memory corruption
9709| [12530] Microsoft Windows Server 2003/Server 2008/Server 2012/Vista/XP Security Account Manager Lockout privilege escalation
9710| [12266] Microsoft .NET Framework 2.0 SP2/3.5.1 ASLR Bypass privilege escalation
9711| [12070] Apple Pages 2.0/2.0.1/2.0.2/5.0/5.0.1 on Mac Microsoft Word Document memory corruption
9712| [11950] Microsoft Office Compability Pack/Word 2007 SP3 File memory corruption
9713| [11949] Microsoft Word Viewer/Office Compatibility Pack/Word 2003 SP3/2007 SP3 File memory corruption
9714| [11494] Microsoft .NET Framework 2.0 SP2/3.5.1/4/4.5/4.5.1 MAC Authentication privilege escalation
9715| [11448] Microsoft Office 2007/2010 Address Space Layout Randomization privilege escalation
9716| [11148] Microsoft Office 2003/2007 WordPerfect Document epsimp32.flt memory corruption
9717| [11146] Microsoft Office 2003/2007 epsimp32.flt memory corruption
9718| [11230] Microsoft Word 2003 DOC Document Embedded Image denial of service
9719| [11081] Microsoft Windows Server 2008/Vista TIFF Image memory corruption
9720| [10648] Microsoft Word 2007 Word File memory corruption
9721| [10647] Microsoft Word 2003 Word File memory corruption
9722| [10643] Microsoft SharePoint Server 2007/2010/2013 Input Sanitizer memory corruption
9723| [10642] Microsoft SharePoint Server 2007/2010 Content Display in Frames privilege escalation
9724| [10247] Microsoft SharePoint Server 2007/2010/2013 Online Cloud cross site scripting
9725| [10245] Microsoft Office 2003/2007/2010 Word File memory corruption
9726| [10244] Microsoft Office 2003 SP3 Word File memory corruption
9727| [10243] Microsoft Office 2003/2007 Word File memory corruption
9728| [10242] Microsoft Office 2007 Word File memory corruption
9729| [10241] Microsoft Office 2007 Word File memory corruption
9730| [10240] Microsoft Office 2003/2007/2010 Word File memory corruption
9731| [10239] Microsoft Office 2003/2007 Word File memory corruption
9732| [10238] Microsoft Excel 2003/2007 XML External Entity Data information disclosure
9733| [10237] Microsoft Excel 2003/2007/2010 XML External Entity Data information disclosure
9734| [10236] Microsoft Word/Office 2003/2007 XML External Entity Data information disclosure
9735| [10234] Microsoft Word/Sharepoint 2003 SP3/2007 SP3/2010 SP1 Office File memory corruption
9736| [10232] Microsoft Word/Sharepoint 2003 SP3/2007 SP3/2010 SP1 Office File memory corruption
9737| [10231] Microsoft Word/Sharepoint 2003 SP3/2007 SP3/2010 SP1 Office File memory corruption
9738| [10230] Microsoft Word/Sharepoint 2003 SP3/2007 SP3/2010 SP1 Office File memory corruption
9739| [10229] Microsoft Access 2007/2010/2013 Access File ACCDB File memory corruption
9740| [10228] Microsoft Access 2007/2010/2013 Access File ACCDB File memory corruption
9741| [10227] Microsoft Access 2007/2010/2013 Access File ACCDB File memory corruption
9742| [10192] Microsoft Windows 7/2000/Server 2003 SP2/Vista/XP SP3 Windows Theme File privilege escalation
9743| [10191] Microsoft Windows Server 2003/XP OLE Object privilege escalation
9744| [10190] Microsoft Windows 7/8/Server 2008/Vista Active Directory denial of service
9745| [10189] Microsoft Outlook 2007/2010 S/MIME privilege escalation
9746| [9941] Microsoft Windows Server 2003/XP Unicode Scripts Processor USP10.DLL Uniscribe Font memory corruption
9747| [9929] Microsoft Windows Server 2008/Server 2012 Active Directory Federation Services Unspecified Account information disclosure
9748| [9715] Microsoft PowerPoint 2007 DirectShow Runtime quartz.dll GetMaxSampleSize denial of service
9749| [9397] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 Array privilege escalation
9750| [9394] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 on 64-bit Array memory corruption
9751| [9393] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 Permission privilege escalation
9752| [8738] Microsoft Visio 2003 SP3/2007 SP3/2010 SP1 XML Parser File information disclosure
9753| [8737] Microsoft Word 2003 SP3 Shape Data Parser File memory corruption
9754| [8736] Microsoft Publisher 2003 SP3 PUB File memory corruption
9755| [8735] Microsoft Publisher 2003 SP3/2007 SP3/2010 SP1 PUB File memory corruption
9756| [8734] Microsoft Publisher 2003 SP3 PUB File memory corruption
9757| [8733] Microsoft Publisher 2003 SP3 PUB File memory corruption
9758| [8732] Microsoft Publisher 2003 SP3 PUB File memory corruption
9759| [8731] Microsoft Publisher 2003 SP3 PUB File memory corruption
9760| [8730] Microsoft Publisher 2003 SP3 PUB File memory corruption
9761| [8729] Microsoft Publisher 2003 SP3 PUB File memory corruption
9762| [8728] Microsoft Publisher 2003 SP3 PUB File memory corruption
9763| [8727] Microsoft Publisher 2003 SP3 PUB File memory corruption
9764| [8726] Microsoft Publisher 2003 PUB File Eingabe memory corruption
9765| [8723] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 XML File spoofing
9766| [7643] Microsoft Windows Server 2008 R2/Server 2012 NFS Server NULL Pointer Dereference denial of service
9767| [7642] Microsoft Exchange 2007/2010 Outlook Web Access vspdx.dll) privilege escalation
9768| [7641] Microsoft Windows Server 2003/Server 2008/Vista/XP DirectShow Quartz.dll memory corruption
9769| [8589] Microsoft System Center Operations Manager 2007 R2/2007 SP1 ViewTypeManager.aspx cross site scripting
9770| [7252] Microsoft System Center Operations Manager 2007 ExecuteTask.aspx cross site scripting
9771| [7251] Microsoft System Center Operations Manager 2007 cross site scripting
9772| [7248] Microsoft Windows 7/Server 2008 R2 Print Spooler privilege escalation
9773| [7121] Microsoft Exchange 2007/2010 RSS Feed denial of service
9774| [7118] Microsoft Windows Server 2008 R2/Server 2012 IP-HTTPS unknown vulnerability
9775| [62914] Microsoft Office 2003 SP3/2007 SP3/2008/2010 SP1/2011 Spreadsheet Use-After-Free memory corruption
9776| [7058] Microsoft Windows 7/Server 2008 R2 DHCPv6 Message denial of service
9777| [6935] Microsoft Office Excel 2003/2007/2010 Input Sanitizer File Stack-based memory corruption
9778| [6934] Microsoft Office Excel 2003/2007/2010 Input Sanitizer memory corruption
9779| [6933] Microsoft Office Excel 2003/2007/2010 SerAuxErrBar File memory corruption
9780| [6929] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 Web Proxy Setting Auto-Discovery memory corruption
9781| [6927] Microsoft .NET Framework 2.0 SP2/3.5.1 Trusted Code Function information disclosure
9782| [6918] Microsoft Excel 2007 SP2 Input Sanitizer File memory corruption
9783| [6830] Microsoft Word 2007/2010 File memory corruption
9784| [6819] Microsoft Excel 2007 File memory corruption
9785| [6627] Microsoft Windows 7/Server 2008 R2 Kerberos denial of service
9786| [6626] Microsoft SharePoint/Lync/Infopath 2007/2010 HTML Sanitization cross site scripting
9787| [6621] Microsoft Word 2007 PAPX memory corruption
9788| [62239] Microsoft Systems Management Server 2003 Configuration Manager Reflected cross site scripting
9789| [5945] Microsoft Office 2007/2010 Computer Graphics Metafile memory corruption
9790| [5939] Microsoft Windows 7/Server 2003/Server 2008 R2/Vista/XP Print Spooler Service memory corruption
9791| [5938] Microsoft Windows 7/Server 2003/Server 2008 R2/Vista/XP Remote Administration Protocol netapi32.dll RAP Request denial of service
9792| [5933] Microsoft SQL Server 2000/2005/2008/2008 R2 Common Controls TabStrip ActiveX MSCOMCTL.OCX memory corruption
9793| [5932] Microsoft Office 2003/2007/2010 Common Controls TabStrip ActiveX MSCOMCTL.OCX memory corruption
9794| [5654] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP information disclosure
9795| [5653] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP win32k.sys memory corruption
9796| [5652] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP win32k.sys memory corruption
9797| [5650] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP memory corruption
9798| [5649] Microsoft Office 2003/2007/2010 libraries memory corruption
9799| [5645] Microsoft SharePoint 2007/2010/3.0 Reflected cross site scripting
9800| [5643] Microsoft SharePoint 2007/2010 information disclosure
9801| [5642] Microsoft SharePoint 2007 cross site request forgery
9802| [5553] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP OpenType Font atmfd.dll denial of service
9803| [5524] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP memory corruption
9804| [5518] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 memory corruption
9805| [5362] Microsoft Office 2003/2007 GDI+ memory corruption
9806| [5291] Microsoft Visual Studio 2008 Incremental Linker link.exe ConvertRgImgSymToRgImgSymEx memory corruption
9807| [5268] Microsoft Office 2008 on Mac RTF Pfragment File memory corruption
9808| [5080] Microsoft SQL Server 2005/2008/2008R2 CREATE DATABASE sql injection
9809| [5050] Microsoft Office 2007 WPS Converter Heap-based memory corruption
9810| [5049] Microsoft SQL Server 2000/2005/2008 MSCOMCTL.OCX privilege escalation
9811| [5048] Microsoft Office 2003/2007/2010 MSCOMCTL.OCX privilege escalation
9812| [5046] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Windows Authenticode Signature Verification WinVerifyTrust Signature privilege escalation
9813| [4803] Microsoft Windows Server 2003/Server 2008 DNS Server Domain Resource Record Query Parser denial of service
9814| [4802] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Remote Desktop Protocol denial of service
9815| [4798] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Remote Desktop Service memory corruption
9816| [60205] Microsoft .NET Framework 2.0 SP2/3.5.1 Heap-based memory corruption
9817| [4642] Microsoft .NET Framework 2.0 SP2/3.5.1/4 XAML Browser Application memory corruption
9818| [60065] Microsoft Windows 2000 mod_sql unknown vulnerability
9819| [4535] Microsoft Windows Server 2003/XP Object Packager packager.exe privilege escalation
9820| [4534] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Line21 DirectShow Filter Quartz.dll/Qdvd.dll Media File memory corruption
9821| [4533] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Multimedia Library winmm.dll MIDI File memory corruption
9822| [4507] Microsoft .NET Framework 2.0 SP2/3.5 SP1/3.5.1/4.0 Forms Authentication privilege escalation
9823| [59666] Microsoft Publisher 2003/2007 "Publisher memory corruption
9824| [4482] Microsoft Word 2007/2010/2011 Document Parser memory corruption
9825| [4480] Microsoft Excel 2003 memory corruption
9826| [4478] Microsoft Windows Server 2003/XP OLE Objects Memory Management memory corruption
9827| [4477] Microsoft PowerPoint 2007 SP2/2008 OfficeArt Use-After-Free memory corruption
9828| [4474] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Active Directory Query memory corruption
9829| [4473] Microsoft PowerPoint 2007 SP2/2010 DLL-Loader memory corruption
9830| [4471] Microsoft Office 2003/2007 Publisher Out-of-Bounds memory corruption
9831| [4470] Microsoft Office 2003 SP3 memory corruption
9832| [4453] Microsoft Excel 2003 Record Parser memory corruption
9833| [4446] Microsoft Office 2007/2008 OfficeArt Record Parser memory corruption
9834| [4445] Microsoft Office 2007/2010/2011 Word Document Parser memory corruption
9835| [4438] Microsoft Windows 7/Server 2008/Vista TCP/IP Reference Counter denial of service
9836| [5358] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP TrueType Font Handling memory corruption
9837| [59005] Microsoft Host Integration Server 2004 denial of service
9838| [58492] Microsoft SharePoint Server 2007 Spreadsheet memory corruption
9839| [58491] Microsoft Office 2004/2007/2008/2010/2011 Spreadsheet memory corruption
9840| [58490] Microsoft Office Compatibility Pack 2007 Spreadsheet memory corruption
9841| [58489] Microsoft Office 2004/2007/2008/2010/2011 Spreadsheet memory corruption
9842| [58488] Microsoft Office 2007/2010 memory corruption
9843| [4412] Microsoft Office 2003/2007 Library Loader unknown vulnerability
9844| [4411] Microsoft Excel 2003 memory corruption
9845| [4409] Microsoft Windows Server 2003/Server 2008 WINS unknown vulnerability
9846| [58240] Microsoft Visio 2003/2007 memory corruption
9847| [58237] Microsoft Visio 2003/2007/2010 memory corruption
9848| [4396] Microsoft Windows 7/Server 2008/Vista TCP/IP Stack denial of service
9849| [4393] Microsoft Windows Server 2008 DNS Service memory corruption
9850| [4391] Microsoft .NET Framework 2.0 SP2/3.5.1/4 Socket Restriction privilege escalation
9851| [4390] Microsoft Windows Server 2008 Remote Desktop Web Access cross site scripting
9852| [4388] Microsoft Windows 7/Server 2008/Vista File Metadata Parser denial of service
9853| [57691] Microsoft SQL Server 2008 Web Service information disclosure
9854| [57690] Microsoft Excel 2002/2003 Spreadsheet memory corruption
9855| [57689] Microsoft Excel 2002 Spreadsheet memory corruption
9856| [57688] Microsoft Excel 2002 Spreadsheet memory corruption
9857| [57687] Microsoft Excel 2002/2003/2007 Spreadsheet memory corruption
9858| [57686] Microsoft Excel 2002 Spreadsheet memory corruption
9859| [57685] Microsoft Excel 2002/2003/2007 Array Access memory corruption
9860| [57684] Microsoft Excel 2002/2003/2007/2010 Spreadsheet memory corruption
9861| [4369] Microsoft Excel 2002/2003/2007 memory corruption
9862| [4367] Microsoft Windows Server 2008 Hyper-V VMBus denial of service
9863| [4362] Microsoft Windows 7/Server 2008/Vista denial of service
9864| [57420] Microsoft PowerPoint 2002/2003 memory corruption
9865| [4349] Microsoft Office 2004/2007/2008 Presentation File Parser memory corruption
9866| [4348] Microsoft PowerPoint 2002/2003/2007 memory corruption
9867| [57077] Microsoft Excel 2002 Uninitialized Memory memory corruption
9868| [57078] Microsoft Office 2003/2007/Xp docx unknown vulnerability
9869| [57079] Microsoft PowerPoint 2002/2003/2007/2010 memory corruption
9870| [57076] Microsoft Excel 2002/2003 memory corruption
9871| [57075] Microsoft Excel 2002/2003 memory corruption
9872| [57074] Microsoft Excel 2002 memory corruption
9873| [57073] Microsoft Excel 2002/2003/2007/2010 memory corruption
9874| [4334] Microsoft .NET Framework 2.0 SP2/3.5 SP1/3.5.1/4.0 JIT Compiler memory corruption
9875| [4332] Microsoft PowerPoint 2007/2010 memory corruption
9876| [4301] Microsoft Windows Server 2003 SMB Browser Heap-based denial of service
9877| [56475] Microsoft Office 2004/2008 memory corruption
9878| [56414] Microsoft Visio 2002/2003/2007 ELEMENTS.DLL memory corruption
9879| [56413] Microsoft Visio 2002/2003/2007 Exception ORMELEMS.DLL memory corruption
9880| [4298] Microsoft Windows 7/Server 2008 JScript/VBScript Engine information disclosure
9881| [4297] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP OpenType Compact Font Format Driver privilege escalation
9882| [4296] Microsoft Windows Server 2003/XP LSASS Authentication Request unknown vulnerability
9883| [4295] Microsoft Windows 7/Server 2008 Kerberos weak authentication
9884| [4294] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Driver win32k.sys unknown vulnerability
9885| [4293] Microsoft Windows Server 2003/XP Kerberos CRC32 Checksum privilege escalation
9886| [4292] Microsoft Windows Server 2003/XP CSRSS Logoff privilege escalation
9887| [4289] Microsoft Excel 2007 Shape Data Parser memory corruption
9888| [4286] Microsoft PowerPoint 2002 SP3/2003 SP3/2004/2007 SP2/2008 OfficeArt Container Parser memory corruption
9889| [4279] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP MHTML cross site scripting
9890| [56176] Microsoft Windows 7/Server 2003/XP fxscover.exe CDrawPoly::Serialize memory corruption
9891| [55772] Microsoft Publisher 2002 pubconv.dll memory corruption
9892| [55771] Microsoft Publisher 2002/2003/2010 memory corruption
9893| [55765] Microsoft Office 2003/Xp Integer memory corruption
9894| [55764] Microsoft Office 2003/Xp memory corruption
9895| [55750] Microsoft Publisher 2002/2003 pubconv.dll memory corruption
9896| [55749] Microsoft Publisher 2002/2003/2007/2010 pubconv.dll memory corruption
9897| [55748] Microsoft Publisher 2002/2003/2007 pubconv.dll memory corruption
9898| [4230] Microsoft Exchange 2007 on 64-bit RPC store.exe MAPI Request denial of service
9899| [4229] Microsoft SharePoint 2007 Document Conversion Launcher Service Eingabeung\xC3\xBCltigkeit
9900| [4228] Microsoft Windows Server 2008 Hyper-V VMBus denial of service
9901| [4224] Microsoft Windows 7/Server 2008/Vista Consent User Interface privilege escalation
9902| [4231] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Driver win32k.sys GreEnableEUDC denial of service
9903| [55420] Microsoft Office 2007/2010 memory corruption
9904| [55419] Microsoft Office 2004/2008/2011/Xp memory corruption
9905| [55412] Microsoft PowerPoint Viewer 2007 memory corruption
9906| [55411] Microsoft PowerPoint 2002/2003 memory corruption
9907| [4204] Microsoft Windows Server 2008 Color Control Panel Eingabeung\xC3\xBCltigkeit
9908| [54995] Microsoft Office 2004/2008 memory corruption
9909| [54994] Microsoft Office 2004/2008 Out-of-Bounds memory corruption
9910| [54993] Microsoft Office Compatibility Pack 2007 memory corruption
9911| [54992] Microsoft Excel 2002 memory corruption
9912| [54991] Microsoft Office 2004 Future memory corruption
9913| [54990] Microsoft Office 2004 memory corruption
9914| [54989] Microsoft Office 2004/2008 memory corruption
9915| [54988] Microsoft Excel 2002 memory corruption
9916| [54987] Microsoft Excel 2002 memory corruption
9917| [54986] Microsoft Excel 2002/2003 memory corruption
9918| [54985] Microsoft Office Compatibility Pack 2003/2004/2007/2008 memory corruption
9919| [54984] Microsoft Office 2004/2008 memory corruption
9920| [54983] Microsoft Excel 2002 Integer memory corruption
9921| [54980] Microsoft Word 2002/2003 memory corruption
9922| [54979] Microsoft Word 2002 memory corruption
9923| [54978] Microsoft Word 2002 memory corruption
9924| [54977] Microsoft Word 2002 Heap-based memory corruption
9925| [54976] Microsoft Word 2002 memory corruption
9926| [54975] Microsoft Word 2002 memory corruption
9927| [54974] Microsoft Word 2002 memory corruption
9928| [54973] Microsoft Word 2002 memory corruption
9929| [54972] Microsoft Word 2002 memory corruption
9930| [54971] Microsoft Word 2002 memory corruption
9931| [4197] Microsoft SharePoint 2007/3.0 cross site scripting
9932| [4196] Microsoft Word 2002/2003/2007/2010 Stack-based memory corruption
9933| [4194] Microsoft Windows 7/Server 2008/Vista SChannel Client Certificate Request denial of service
9934| [54774] Microsoft Word 2003 word_crash_11.8326.8324_poc.doc denial of service
9935| [54757] Microsoft SharePoint Server 2007 HTML Sanitization SafeHTML cross site scripting
9936| [4186] Microsoft Outlook 2002/2003/2007 Content Parser Heap-based memory corruption
9937| [54584] Microsoft Visual C++ 2005 AtlTraceTool8.exe unknown vulnerability
9938| [54554] Microsoft Groove 2007 mso.dll memory corruption
9939| [4187] Microsoft Windows 7/Server 2008/Vista TCP/IP Stack Ipv4SetEchoRequestCreate denial of service
9940| [54322] Microsoft Word 2002/2003 memory corruption
9941| [54321] Microsoft Office Compatibility Pack 2007 memory corruption
9942| [54320] Microsoft Office Compatibility Pack 2007 memory corruption
9943| [54319] Microsoft Office Compatibility Pack 2007 memory corruption
9944| [54318] Microsoft .NET Framework 2.0 SP1/2.0 SP2/3.5/3.5 SP1/3.5.1 Interfaces memory corruption
9945| [4165] Microsoft Windows 7/Server 2008/Vista TCP/IP Stack denial of service
9946| [4162] Microsoft Windows 7/Server 2008/Vista Kernel memory corruption
9947| [4159] Microsoft Excel 2002/2003 SXDB PivotTable Cache Data Record memory corruption
9948| [4149] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Shell Shortcut Parser memory corruption
9949| [54083] Microsoft Access 2003 ActiveX Control ACCWIZ.dll memory corruption
9950| [4146] Microsoft Outlook 2002/2003/2007 SMB Attachment PR_ATTACH_METHOD memory corruption
9951| [4145] Microsoft Access 2003/2007 ActiveX ACCWIZ.dll memory corruption
9952| [54617] Microsoft Outlook Web Access up to 2007 cross site request forgery
9953| [4151] Microsoft Windows Server 2008/Vista NtUserCheckAccessForIntegrityLevel memory corruption
9954| [53591] Microsoft Windows Server 2003 GetServerName cross site scripting
9955| [53505] Microsoft Excel 2002/2007 memory corruption
9956| [53501] Microsoft Excel 2002 memory corruption
9957| [53500] Microsoft Excel 2002 memory corruption
9958| [53499] Microsoft Excel 2002 memory corruption
9959| [53495] Microsoft Excel 2002/2003/2007 memory corruption
9960| [53494] Microsoft Excel 2002 Stack-based memory corruption
9961| [53504] Microsoft Excel 2002 memory corruption
9962| [53503] Microsoft Excel 2002 Stack-Based memory corruption
9963| [53502] Microsoft Excel 2002 Heap-based memory corruption
9964| [53498] Microsoft Excel 2002 Stack-based memory corruption
9965| [53497] Microsoft Excel 2002 memory corruption
9966| [53496] Microsoft Excel 2002 memory corruption
9967| [53493] Microsoft Excel 2002/2003/2007 memory corruption
9968| [4133] Microsoft Office 2003/2007/Xp COM Object Instantiator memory corruption
9969| [53366] Microsoft ASP.NET 2.0 cross site scripting
9970| [53385] Microsoft Exchange Server 2007 Outlook Web Access cross site scripting
9971| [53164] Microsoft Office 2003/2007/Xp ActiveX Control VBE6.DLL memory corruption
9972| [53054] Microsoft VISIO 2002/2003/2007 VISIODWG.DLL memory corruption
9973| [4125] Microsoft SharePoint 2007/3.0 help.aspx cross site scripting
9974| [52777] Microsoft Publisher 2002/2003/2007 memory corruption
9975| [52773] Microsoft Visio 2002/2003/2007 memory corruption
9976| [52772] Microsoft Visio 2002/2003/2007 memory corruption
9977| [4107] Microsoft Windows 7/Server 2008 Kernel denial of service
9978| [4103] Microsoft Windows Server 2003 Media Services Stack-based memory corruption
9979| [52543] Microsoft Virtual PC 2007 unknown vulnerability
9980| [52148] Microsoft Office 2004/2007/2008 Uninitialized Memory memory corruption
9981| [52147] Microsoft Office 2004/2007/2008 Spreadsheet Uninitialized Memory memory corruption
9982| [52146] Microsoft Office 2004/2007/2008 Spreadsheet Heap-based memory corruption
9983| [52145] Microsoft Office 2004/2007/2008 Spreadsheet Heap-based memory corruption
9984| [52144] Microsoft Office 2004/2007/2008 Spreadsheet memory corruption
9985| [52143] Microsoft Office 2004/2007/2008 Spreadsheet memory corruption
9986| [4090] Microsoft Excel 2002/2003/2007 memory corruption
9987| [52036] Microsoft Windows 2000 MsgBox memory corruption
9988| [51995] Microsoft SharePoint Server up to 2006 cross site scripting
9989| [51810] Microsoft Office 2004/Xp MSO.DLL memory corruption
9990| [51802] Microsoft PowerPoint 2003 Stack-based memory corruption
9991| [51801] Microsoft PowerPoint 2003 Stack-based memory corruption
9992| [51800] Microsoft PowerPoint 2002/2003 Use-After-Free memory corruption
9993| [51799] Microsoft PowerPoint 2002/2003 memory corruption
9994| [51798] Microsoft PowerPoint 2002/2003 Heap-based memory corruption
9995| [4082] Microsoft PowerPoint 2002 SP3 memory corruption
9996| [54550] Microsoft PowerPoint 2007 rpawinet.dll memory corruption
9997| [54556] Microsoft Visio 2003 mfc71enu.dll unknown vulnerability
9998| [51497] Microsoft Windows Live Messenger 2009 ActiveX Control msnmsgr.exe denial of service
9999| [51133] Microsoft Windows 2000 SP4/Server 2003 SP2/SP3/XP SP2 memory corruption
10000| [51074] Microsoft Office 2002/2003 Integer memory corruption
10001| [4069] Microsoft Project 2003/2007 Project Memory Validator memory corruption
10002| [50794] Microsoft Office 2004/2008 Spreadsheet memory corruption
10003| [50793] Microsoft Office 2004/2008 Spreadsheet memory corruption
10004| [50792] Microsoft Office 2004/2008 Spreadsheet memory corruption
10005| [50791] Microsoft Office 2004/2008 Spreadsheet memory corruption
10006| [50790] Microsoft Office 2004/2008 Spreadsheet Heap-based memory corruption
10007| [50788] Microsoft Office 2004/2008 Spreadsheet memory corruption
10008| [50787] Microsoft Office 2004/2008 Spreadsheet memory corruption
10009| [50786] Microsoft Windows 2000 llssrv.exe memory corruption
10010| [50789] Microsoft Office 2004/2008 Spreadsheet memory corruption
10011| [4056] Microsoft Word 2002/2003 File Information Block Parser Stack-based memory corruption
10012| [50660] Microsoft SharePoint Server 2007 unknown vulnerability
10013| [50443] Microsoft PowerPoint 2007 Integer memory corruption
10014| [50432] Microsoft .NET Framework 2.0/2.0 SP1/2.0 SP2/3.5/3.5 SP1 memory corruption
10015| [49866] Microsoft Windows Server 2003 memory corruption
10016| [4031] Microsoft Windows Server 2008/Vista SMB Processor EducatedScholar memory corruption
10017| [4030] Microsoft Windows Server 2008/Vista Wireless LAN AutoConfig Service Heap-based memory corruption
10018| [4029] Microsoft Windows 2000/XP TCP/IP Window Size denial of service
10019| [49745] Microsoft Windows Server 2003 denial of service
10020| [49395] Microsoft Office 2000/2003/XP Office Web Components Heap-based memory corruption
10021| [49394] Microsoft Windows Server 2003 memory corruption
10022| [49389] Microsoft Office 2000/2003/XP Office Web Components memory corruption
10023| [49390] Microsoft Office 2000/2003/XP Office Web Components memory corruption
10024| [49198] Microsoft Visual Studio 2005 information disclosure
10025| [49047] Microsoft Virtual Server 2005 privilege escalation
10026| [49046] Microsoft Windows Server 2003 quartz.dll memory corruption
10027| [49045] Microsoft Windows Server 2003 quartz.dll memory corruption
10028| [49044] Microsoft ISA Server 2006 privilege escalation
10029| [3999] Microsoft Office 2007 Pointer memory corruption
10030| [4000] Microsoft Office 2003/Sp3/Xp Web Components memory corruption
10031| [48894] Microsoft Windows Server 2003 msvidctl.dll memory corruption
10032| [48572] Microsoft PowerPoint 2002 FL21WIN.DLL memory corruption
10033| [48517] Microsoft Windows 2000 Memory Leak memory corruption
10034| [48516] Microsoft Windows Server 2008 unknown vulnerability
10035| [48512] Microsoft Windows Server 2008 unknown vulnerability
10036| [48515] Microsoft Office Word Viewer 2003 memory corruption
10037| [48514] Microsoft Office Word Viewer 2003 Stack-based memory corruption
10038| [48554] Microsoft Excel 2000/2003/2007 memory corruption
10039| [48157] Microsoft PowerPoint 2002 Sound memory corruption
10040| [48156] Microsoft PowerPoint 2000 Stack-based memory corruption
10041| [48154] Microsoft PowerPoint 2002 Sound PP7X32.DLL memory corruption
10042| [48152] Microsoft PowerPoint 2002 PP4X32.DLL memory corruption
10043| [48150] Microsoft PowerPoint 2002 Sound memory corruption
10044| [48147] Microsoft PowerPoint 2002 Sound memory corruption
10045| [48146] Microsoft PowerPoint 2002 Integer memory corruption
10046| [48155] Microsoft PowerPoint 2002 Notes Container Heap-based memory corruption
10047| [48153] Microsoft PowerPoint 2002 Sound memory corruption
10048| [48151] Microsoft PowerPoint 2002 Stack-based memory corruption
10049| [48149] Microsoft PowerPoint 2002 memory corruption
10050| [48148] Microsoft PowerPoint 2002 Sound memory corruption
10051| [3974] Microsoft PowerPoint 2000/2002/2003 Sound Data Stack-based memory corruption
10052| [3973] Microsoft PowerPoint 2000/2002/2003 Notes Container Stack-based memory corruption
10053| [3972] Microsoft PowerPoint 2000/2002/2003 BuildList memory corruption
10054| [3971] Microsoft PowerPoint 2000/2002/2003 Object Stack-based memory corruption
10055| [3970] Microsoft PowerPoint 2000/2002/2003 Paragraph Stack-based memory corruption
10056| [3969] Microsoft PowerPoint 2000/2002/2003 Atom Stack-based memory corruption
10057| [47719] Microsoft Windows 2000 Stack-based memory corruption
10058| [47720] Microsoft Internet Security And Acceleration Server 2006 Forms Authentication cookieauth.dll cross site scripting
10059| [47716] Microsoft Office Converter Pack 2003 WPFT632.CNV memory corruption
10060| [47715] Microsoft Windows 2000 Wordpad memory corruption
10061| [47718] Microsoft Excel 2000/2002/2003/2007 Spreadsheet memory corruption
10062| [3960] Microsoft Windows 2000/Server 2003/XP DirectShow MJPEG memory corruption
10063| [3952] Microsoft ISA Server 2004/2006 denial of service
10064| [3946] Microsoft PowerPoint 2000/2002/2003/2004 memory corruption
10065| [47091] Microsoft Windows Server 2008 unknown vulnerability
10066| [47090] Microsoft Windows Server 2008 unknown vulnerability
10067| [3939] Microsoft Windows 2000 DNS spoofing
10068| [3938] Microsoft Windows 2000 SSL weak authentication
10069| [3937] Microsoft Windows 2000 memory corruption
10070| [3932] Microsoft Excel 2000/2002/2003/2004/2007 Object Reference memory corruption
10071| [46620] Microsoft Windows Live Messenger 2009 msnmsgr.exe denial of service
10072| [46455] Microsoft Exchange Server 2007 denial of service
10073| [46454] Microsoft Exchange Server 2007 memory corruption
10074| [46453] Microsoft Visio 2002/2003/2007 memory corruption
10075| [46452] Microsoft Visio 2002/2003/2007 memory corruption
10076| [46451] Microsoft Visio 2002/2003/2007 memory corruption
10077| [46327] Microsoft Word 2007 information disclosure
10078| [45758] Microsoft Money 2006 ActiveX Control prtstb06.dll denial of service
10079| [45381] Microsoft Windows Server 2008/Vista SP1 Explorer memory corruption
10080| [45380] Microsoft Windows Server 2008/Vista SP1 Search memory corruption
10081| [45379] Microsoft Office SharePoint Server 2007 denial of service
10082| [3896] Microsoft SQL Server up to 2005 sp_replwritetovarbin memory corruption
10083| [3892] Microsoft Excel 2000/2002/2003 Formula memory corruption
10084| [3891] Microsoft Excel 2000/2002/2003 memory corruption
10085| [3890] Microsoft Excel 2000/2002/2003 NAME Index memory corruption
10086| [3889] Microsoft Word 2000/2002/2003/2007 Table Property Stack-based memory corruption
10087| [3888] Microsoft Word 2000/2002/2003/2007 RTF Stylesheet memory corruption
10088| [3887] Microsoft Word 2000/2002/2003/2007 memory corruption
10089| [3886] Microsoft Word 2000/2002/2003/2007 ControlWord Heap-based memory corruption
10090| [3885] Microsoft Word 2000/2002/2003/2007 memory corruption
10091| [3884] Microsoft Word 2000/2002/2003/2007 memory corruption
10092| [3883] Microsoft Word 2000/2002/2003/2007 RTF Heap-based memory corruption
10093| [3882] Microsoft Word 2000/2002/2003/2007 LFO memory corruption
10094| [3880] Microsoft Visual Basic up to 2003 ActiveX Control Mschrt20.ocx memory corruption
10095| [3879] Microsoft Visual Basic up to 2003 ActiveX Control mscomct2.ocx memory corruption
10096| [3878] Microsoft Visual Basic up to 2003 ActiveX Control mshflxgd.ocx memory corruption
10097| [3877] Microsoft Visual Basic up to 2003 ActiveX Control msflxgrd.ocx memory corruption
10098| [3876] Microsoft Visual Basic up to 2003 ActiveX Control msdatgrd.ocx memory corruption
10099| [45197] Microsoft Windows 2000 nskey.dll memory corruption
10100| [45063] Microsoft Windows Server 2003 Active Directory unknown vulnerability
10101| [45040] Microsoft .NET Framework 2.0.50727 Code Access Security unknown vulnerability
10102| [44855] DjVu Activex Control For Microsoft Office 2000 3.0 ActiveX Control DjVu_ActiveX_MSOffice.dll memory corruption
10103| [44665] Microsoft Peachtree Accounting 2004 ActiveX Control PAWWeb11.ocx unknown vulnerability
10104| [44589] Microsoft Exchange Server 2003 Outlook Web Access unknown vulnerability
10105| [3845] Microsoft Windows 2000 SP4 Active Directory memory corruption
10106| [44533] Microsoft Windows 2000 mqsvc.exe memory corruption
10107| [3844] Microsoft Excel 2003 REPT memory corruption
10108| [3843] Microsoft Excel up to 2007 BIFF File Heap-based memory corruption
10109| [3842] Microsoft Excel 2003 VBA Performance Cache Stack-based memory corruption
10110| [44405] Microsoft Digital Image 2006 ActiveX Control PipPPush.DLL unknown vulnerability
10111| [44047] Microsoft SQL Server 2000 ActiveX Control SQLVDIRLib.SQLVDirControl memory corruption
10112| [43981] Microsoft Organization Chart 2.00 orgchart.exe memory corruption
10113| [43957] Microsoft Office 2003/2007/Xp gdiplus.dll memory corruption
10114| [43956] Microsoft Office 2003/2007/Xp gdiplus.dll memory corruption
10115| [43955] Microsoft Office 2003/2007/Xp gdiplus.dll memory corruption
10116| [43952] Microsoft Office 2003/2007/Xp URI memory corruption
10117| [43676] Microsoft Windows 2000/Server 2003/Vista/XP memory corruption
10118| [43675] Microsoft Windows 2000/Server 2003/Vista/XP of memory corruption
10119| [43662] Microsoft PowerPoint Viewer 2000 SP3/2002 SP3/2003 SP2/2007 SP1 memory corruption
10120| [43661] Microsoft PowerPoint Viewer 2003 memory corruption
10121| [43660] Microsoft PowerPoint Viewer 2003 Integer memory corruption
10122| [43657] Microsoft Office 2000/2003/Xp memory corruption
10123| [43654] Microsoft SharePoint Server 2007 memory corruption
10124| [43653] Microsoft Office 2000/2002/2004/2008 memory corruption
10125| [43652] Microsoft Office 2000/2002/2003/2004/2008 memory corruption
10126| [3797] Microsoft Windows Server 2008/Vista IPsec Policy Designfehler
10127| [3796] Microsoft Office 2000 WPG memory corruption
10128| [3795] Microsoft Office 2000/2003/Xp BMP Image BMPIMP32.FLT memory corruption
10129| [3794] Microsoft Office 2000/2003/Xp PICT bits_per_pixel memory corruption
10130| [3793] Microsoft Office 2000/2003/Xp PICT memory corruption
10131| [3792] Microsoft Office 2000 EPS File memory corruption
10132| [3783] Microsoft Word 2002 memory corruption
10133| [43103] Microsoft Exchange Srv 2007 Sp1 Outlook Web Access cross site scripting
10134| [43102] Microsoft Windows 2000 SP4/Server 2003 SP2/Server 2008 DNS Cache privilege escalation
10135| [3778] Microsoft Exchange 2003/2007 Outlook Web Access cross site scripting
10136| [3777] Microsoft Windows Server 2008/Vista SP1 Explorer memory corruption
10137| [43087] Microsoft Office Snapshot Viewer ActiveX up to Office 2003 Snapshot Viewer ActiveX Control snapview.ocx memory corruption
10138| [43096] Microsoft Publisher 2003/2007 Crypto API unknown vulnerability
10139| [42816] Microsoft Word 2000/2003 memory corruption
10140| [42732] Microsoft Windows Server 2003/Vista/XP denial of service
10141| [42731] Microsoft Windows Server 2003 denial of service
10142| [3732] Microsoft Windows 2000/Server 2003 WINS memory corruption
10143| [3701] Microsoft Word 2003 CSS Heap-based memory corruption
10144| [3700] Microsoft Word 2003 RTF Document Heap-based memory corruption
10145| [42065] Microsoft SharePoint Server 2.0 Rich Text Editor cross site scripting
10146| [41881] Microsoft Office 2003/2007/2007 Sp1/Xp memory corruption
10147| [41880] Microsoft Project 2000/2002/2003 memory corruption
10148| [41879] Microsoft Windows 2000/Server 2003/Vista Stack-based memory corruption
10149| [41878] Microsoft Windows 2000/Server 2003/Vista spoofing
10150| [41877] Microsoft Windows Server 2003 vbscript.dll memory corruption
10151| [3671] Microsoft Visio 2002/2003/2003 Sp3/2007/2007 Sp1 memory corruption
10152| [3670] Microsoft Visio 2002/2003/2003 Sp3/2007/2007 Sp1 Object memory corruption
10153| [41455] Microsoft Office 2000/2003/2004/Xp memory corruption
10154| [41454] Microsoft Excel 2000/2002/2003/2007 memory corruption
10155| [41453] Microsoft Excel 2000/2002/2003 memory corruption
10156| [41452] Microsoft Excel 2000/2002/2003/2007 memory corruption
10157| [41451] Microsoft Excel 2000/2002/2003 memory corruption
10158| [41450] Microsoft Excel 2000 memory corruption
10159| [41449] Microsoft Excel 2000/2002/2003 memory corruption
10160| [41448] Microsoft Office 2000/Xp Office Web Components memory corruption
10161| [3648] Microsoft Excel 2003 memory corruption
10162| [3647] Microsoft Outlook up to 2007 mailto URI memory corruption
10163| [41003] Microsoft Office 2000/2003/2004/Xp memory corruption
10164| [41002] Microsoft Office 2000/2003/Xp memory corruption
10165| [41001] Microsoft Works 2005/8.0 wkcvqd01.dll memory corruption
10166| [41000] Microsoft Works 2005/8.0 memory corruption
10167| [40998] Microsoft Publisher 2000/2002/2003 memory corruption
10168| [40994] Microsoft Works 2005/8.0 wkcvqd01.dll memory corruption
10169| [40987] Microsoft Windows 2000 denial of service
10170| [40736] Microsoft ActiveX 2.0 ActiveX Control privilege escalation
10171| [3552] Microsoft Excel 2000/2002/2003 File memory corruption
10172| [40242] Microsoft Publisher 2000/2002/2003/2007 Crash denial of service
10173| [40020] Microsoft Office 2007 ZIP Container unknown vulnerability
10174| [39769] Microsoft Windows 2000 cryptgenrandom weak encryption
10175| [39749] Microsoft Windows 2000 msjet40.dll memory corruption
10176| [39655] Microsoft Windows Server 2003 spoofing
10177| [39324] Microsoft Windows Mobile 2005 SMS unknown vulnerability
10178| [3373] Microsoft Word 2000/2002 memory corruption
10179| [38999] Microsoft Windows Server 2003 explorer.exe denial of service
10180| [38899] Microsoft ISA Server 2004 information disclosure
10181| [38728] Microsoft SQL Server 2005 Enterprise Manager sqldmo.dll memory corruption
10182| [38326] Microsoft Windows 2000 attemptwrite memory corruption
10183| [3241] Microsoft Excel 2000/2003/2004/XP SP3 rtWnDesk memory corruption
10184| [3223] Microsoft Windows Server 2003/XP URI privilege escalation
10185| [3212] Microsoft DirectX February 2006 RLE Compression Targa Files Heap-based memory corruption
10186| [37739] Microsoft Excel 2000/2002/2003/2004/2007 memory corruption
10187| [37738] Microsoft Office 2002/2003 memory corruption
10188| [3176] Microsoft Excel 2000/2002/2003/2007 File Attribute memory corruption
10189| [3175] Microsoft Excel 2000/2002/2003/2007 Active Worksheet memory corruption
10190| [3174] Microsoft Excel 2000/2002/2003/2007 Version Information memory corruption
10191| [3172] Microsoft Office Publisher 2007 Pointer memory corruption
10192| [37566] Microsoft Excel 2003 unknown vulnerability
10193| [37526] Microsoft Windows 2000/Server 2003 denial of service
10194| [37248] Microsoft Visio 2002 Packaging memory corruption
10195| [37251] Microsoft Windows 2000 memory corruption
10196| [3119] Microsoft Visio 2002 Object memory corruption
10197| [3118] Microsoft Visio 2002 Data memory corruption
10198| [37093] Microsoft Windows Server 2003 Error Message unknown vulnerability
10199| [37010] Microsoft Office 2000 ActiveX Control ouactrl.ocx memory corruption
10200| [36628] Microsoft Word 2000/2002/2003/2004 winword.exe memory corruption
10201| [36616] Microsoft Works 2004/2005/2006 memory corruption
10202| [36621] Microsoft Exchange Server 2000 Integer denial of service
10203| [36620] Microsoft Exchange Server 2000 Outlook Web Access cross site scripting
10204| [36619] Microsoft Exchange Server 2000/2003/2007 MIME Email memory corruption
10205| [36618] Microsoft Exchange Server 2000 NULL Pointer Dereference denial of service
10206| [36617] Microsoft Excel 2000/2002/2003/2004 memory corruption
10207| [36623] Microsoft BizTalk Server 2004 ActiveX Control capicom.dll memory corruption
10208| [3067] Microsoft Office 2000/2003/2004/2007/Xp Drawing Object memory corruption
10209| [3065] Microsoft Excel 2000/2002/2003/2007 Filter Stack-based memory corruption
10210| [3064] Microsoft Excel 2000/2002/2003/2004/2007 set Font memory corruption
10211| [3063] Microsoft Excel 2000/2002/2003/2007 BIFF Record Stack-based memory corruption
10212| [3012] Microsoft Windows 2000/Server 2003 DNS Service Stack-based memory corruption
10213| [36039] Microsoft Content Management Server 2001 memory corruption
10214| [36052] Microsoft Windows 2000 Heap-based memory corruption
10215| [36051] Microsoft Word 2007 file798-1.doc memory corruption
10216| [36050] Microsoft Word 2007 file789-1.doc memory corruption
10217| [36040] Microsoft Content Management Server 2001 cross site scripting
10218| [3004] Microsoft Windows up to 2003/XP URL Parser memory corruption
10219| [36041] Microsoft .NET Framework 2.0.50727.42 cross site scripting
10220| [36002] Microsoft Windows 2000/XP denial of service
10221| [2990] Microsoft Windows 2000/Vista/XP Animated Cursor Stack-based memory corruption
10222| [36515] Microsoft Windows 2000/Server 2003/XP memory corruption
10223| [35846] Microsoft Windows 2000/Server 2003 Default Configuration information disclosure
10224| [35373] Microsoft Excel 2003 denial of service
10225| [35372] Microsoft Office 2003 denial of service
10226| [35206] Microsoft Windows Server 2003/XP Crash denial of service
10227| [35161] Microsoft ISA Server 2004 unknown vulnerability
10228| [35236] Microsoft Publisher 2007 memory corruption
10229| [2939] Microsoft Word 2000 memory corruption
10230| [34994] Microsoft Windows 2000 OLE Dialog memory corruption
10231| [34993] Microsoft Office 2000/2003/Xp memory corruption
10232| [35001] Microsoft Office 2000/2003/2004/Xp memory corruption
10233| [35000] Microsoft Word 2000/2002/2003 memory corruption
10234| [2933] Microsoft Windows 2000 SP4/Server 2003 SP1/XP SP2 OLE Dialog Stack-based memory corruption
10235| [2894] Microsoft Office 2000/2003/2004/Xp Undefined String Format String
10236| [2884] Microsoft Word 2000/2002/2003 memory corruption
10237| [34321] Microsoft Office 2000/2003/2004/Xp Spreadsheet Heap-based memory corruption
10238| [34320] Microsoft Office 2000/2003/2004/Xp memory corruption
10239| [34319] Microsoft Office 2000/2003/2004/Xp memory corruption
10240| [34318] Microsoft Office 2000/2003/2004/Xp memory corruption
10241| [34322] Microsoft Office 2000/2003/Xp memory corruption
10242| [2811] Microsoft Windows 2000/Server 2003/XP VML Vector Markup Language Integer memory corruption
10243| [2810] Microsoft Outlook 2000/2002/2003 Office Saved Search OSS File memory corruption
10244| [2809] Microsoft Outlook 2000/2002/2003 Header denial of service
10245| [2808] Microsoft Outlook 2000/2002/2003 Meeting VEVENT memory corruption
10246| [2807] Microsoft Excel 2000/2002/2003 XLS File memory corruption
10247| [34126] Microsoft Office 2003 memory corruption
10248| [34122] Microsoft Office Web Components 2000 memory corruption
10249| [2789] Microsoft Windows 2000/XP RPC Request NetrWkstaUserEnum denial of service
10250| [2765] Microsoft Project Server 2003 pdsrequest.asp weak authentication
10251| [33851] Microsoft Word 2000/2002/2003 12122006-djtest.doc memory corruption
10252| [2739] Microsoft Windows 2000 Remote Installation Service Fehlende Authentifizierung
10253| [2738] Microsoft Windows 2000/Server 2003/XP SNMP memory corruption
10254| [2737] Microsoft Windows Server 2003/XP Manifest denial of service
10255| [33766] Microsoft Word 2000/2002/2003 memory corruption
10256| [2718] Microsoft Word 2000/2002/2003 DOC Document memory corruption
10257| [2717] Microsoft Windows 2000 Print Spooler Memory Consumption denial of service
10258| [2689] Microsoft Windows up to 2000 SP4 Active Directory denial of service
10259| [2688] Microsoft Windows 2000/Server 2003/XP Client Service for Netware denial of service
10260| [2687] Microsoft Windows 2000/Server 2003/XP Agent ActiveX ACF File Heap-based memory corruption
10261| [2686] Microsoft Windows 2000/Server 2003/XP Client Service for Netware memory corruption
10262| [2684] Microsoft Windows 2000/XP Workstation Service Stack-based memory corruption
10263| [2659] Microsoft Windows 2000/XP GDI Crash memory corruption
10264| [2655] Microsoft Windows 2000/Server 2003/XP XML Core Services memory corruption
10265| [33067] Microsoft Visual Studio .net 2005 ActiveX Control wmiscriptutils.dll memory corruption
10266| [2610] Microsoft PowerPoint 2003 PPT Document NULL Pointer Dereference denial of service
10267| [32693] Microsoft Word 2004 memory corruption
10268| [32686] Microsoft Office 2000/2001/2003/2004 Integer memory corruption
10269| [32690] Microsoft Office 2000/2003/2004/Xp memory corruption
10270| [32676] Microsoft Office 2000/2001/2003/2004 memory corruption
10271| [32675] Microsoft Office 2000/2003/2004/Xp memory corruption
10272| [32694] Microsoft Windows 2000 memory corruption
10273| [32689] Microsoft Excel 2000/2002/2003/2004/XP memory corruption
10274| [32688] Microsoft Excel 2000/2002/2003/2004/XP memory corruption
10275| [32687] Microsoft Word 2000/2002 memory corruption
10276| [32685] Microsoft Office 2000/2001/2003/2004 memory corruption
10277| [2601] Microsoft Windows Server 2003/XP IPv6 Stack denial of service
10278| [2600] Microsoft Windows Server 2003/XP IPv6 Stack TCP denial of service
10279| [2599] Microsoft Windows Server 2003/XP IPv6 Stack ICMP denial of service
10280| [2598] Microsoft Windows Server 2003/XP Object Packager privilege escalation
10281| [2597] Microsoft Office 2003/Xp Smart-Tag Parser memory corruption
10282| [2596] Microsoft Office 2000/2003/2004/Xp Value Read memory corruption
10283| [2595] Microsoft Office 2000/2001/2003/2004 Diagram Value memory corruption
10284| [2594] Microsoft Office 2000/2001/2003/2004 Document memory corruption
10285| [2593] Microsoft ASP.NET 2.0 cross site scripting
10286| [141652] Microsoft Windows up to Server 2019 Common Log File System Driver information disclosure
10287| [141639] Microsoft SharePoint Foundation 2013 SP1 cross site request forgery
10288| [141637] Microsoft Windows up to Server 2019 AppX Deployment Server privilege escalation
10289| [141636] Microsoft ASP.NET Core 2.1/2.2/3.0 Project Template privilege escalation
10290| [141635] Microsoft .NET Core 2.1/2.2 denial of service
10291| [141633] Microsoft Excel up to 2019 memory corruption
10292| [141631] Microsoft Windows up to Server 2019 SMB Client Driver information disclosure
10293| [141630] Microsoft Windows up to Server 2019 denial of service
10294| [141629] Microsoft Windows up to Server 2019 Update Delivery Optimization privilege escalation
10295| [141627] Microsoft Windows up to Server 2019 GDI information disclosure
10296| [141626] Microsoft Windows up to Server 2019 Win32k memory corruption
10297| [141621] Microsoft Windows up to Server 2019 Kernel information disclosure
10298| [141620] Microsoft Windows up to Server 2019 Active Directory Federation Services cross site scripting
10299| [141619] Microsoft Windows up to Server 2019 ALPC privilege escalation
10300| [141618] Microsoft Windows up to Server 2019 hdAudio.sys privilege escalation
10301| [141617] Microsoft Windows up to Server 2019 Store Installer privilege escalation
10302| [141616] Microsoft Windows up to Server 2019 ALPC privilege escalation
10303| [141615] Microsoft Windows up to Server 2019 Winlogon privilege escalation
10304| [141614] Microsoft Windows up to Server 2019 Compatibility Appraiser privilege escalation
10305| [141611] Microsoft Office up to 2019 Security Feature privilege escalation
10306| [141610] Microsoft Excel up to 2019 information disclosure
10307| [141609] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
10308| [141608] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site request forgery
10309| [141607] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016/2019 privilege escalation
10310| [141606] Microsoft Windows up to Server 2019 Win32k memory corruption
10311| [141605] Microsoft Windows up to Server 2019 Hyper-V information disclosure
10312| [141604] Microsoft Windows up to Server 2019 AppX Deployment Server privilege escalation
10313| [141603] Microsoft Windows up to Server 2019 GDI information disclosure
10314| [141602] Microsoft Windows up to Server 2019 DirectWrite information disclosure
10315| [141601] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10316| [141600] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10317| [141599] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10318| [141598] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10319| [141597] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10320| [141596] Microsoft Windows up to Server 2019 DirectWrite information disclosure
10321| [141595] Microsoft Windows up to Server 2019 DirectWrite information disclosure
10322| [141594] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10323| [141593] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10324| [141592] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10325| [141591] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10326| [141590] Microsoft Windows up to Server 2019 Text Service Framework command injection
10327| [141589] Microsoft Exchange Server 2016 CU12/2016 CU13/2019 CU1/2019 CU2 denial of service
10328| [141583] Microsoft Lync Server 2013 Conference directory traversal
10329| [141581] Microsoft Windows up to Server 2016 Hyper-V denial of service
10330| [141580] Microsoft Windows up to Server 2019 Transaction Manager information disclosure
10331| [141579] Microsoft Windows up to Server 2016 DirectX information disclosure
10332| [141577] Microsoft Windows up to Server 2019 Common Log File System Driver privilege escalation
10333| [141575] Microsoft Windows up to Server 2019 lnk File privilege escalation
10334| [141564] Microsoft SharePoint Enterprise Server 2010 SP1/2013 SP1/2016/2019 Markup Application Package privilege escalation
10335| [141561] Microsoft Windows up to Server 2019 Remote Desktop privilege escalation
10336| [141560] Microsoft Windows up to Server 2019 Remote Desktop privilege escalation
10337| [139972] Microsoft Windows up to Server 2019 HTTP2 HTTP.sys denial of service
10338| [139971] Microsoft Windows up to Server 2019 HTTP2 HTTP.sys denial of service
10339| [139970] Microsoft Windows up to Server 2019 HTTP2 HTTP.sys denial of service
10340| [139969] Microsoft Windows up to Server 2019 HTTP2 HTTP.sys denial of service
10341| [139968] Microsoft Windows up to Server 2019 HTTP2 HTTP.sys denial of service
10342| [139965] Microsoft Windows up to Server 2019 Kernel information disclosure
10343| [139963] Microsoft Windows up to Server 2019 Remote Desktop Protocol information disclosure
10344| [139962] Microsoft Windows up to Server 2019 Remote Desktop Protocol denial of service
10345| [139960] Microsoft Windows up to Server 2019 DHCP Server denial of service
10346| [139958] Microsoft Windows up to Server 2019 DHCP Server denial of service
10347| [139957] Microsoft SharePoint Server 2013 SP1/2016/2019 cross site scripting
10348| [139956] Microsoft SharePoint 2010 SP2/2013 SP1/2016/2019 Session Object information disclosure
10349| [139955] Microsoft Windows up to Server 2019 SyncController.dll privilege escalation
10350| [139949] Microsoft Windows up to Server 2019 XmlLite Runtime XmlLite.dll denial of service
10351| [139946] Microsoft Windows up to Server 2019 Core Shell COM Server Registrar COM Call privilege escalation
10352| [139942] Microsoft Windows up to Server 2019 rpcss.dll memory corruption
10353| [139941] Microsoft Windows up to Server 2019 DirectX memory corruption
10354| [139937] Microsoft Windows up to Server 2019 Azure Active Directory information disclosure
10355| [139936] Microsoft Windows up to Server 2019 SymCrypt information disclosure
10356| [139935] Microsoft Windows 10 1809/10 1903/Server 1903/Server 2019 NTFS privilege escalation
10357| [139934] Microsoft Windows 7 SP1/Server 2018 R2 SP1/Server 2018 SP2 Win32k memory corruption
10358| [139933] Microsoft Windows up to Server 2019 p2pimsvc privilege escalation
10359| [139932] Microsoft Windows up to Server 2019 Kernel memory corruption
10360| [139931] Microsoft Windows up to Server 2019 File Signature Security Feature CAB File privilege escalation
10361| [139930] Microsoft Windows up to Server 2019 ALPC privilege escalation
10362| [139928] Microsoft Windows up to Server 2019 Kernel memory corruption
10363| [139927] Microsoft Windows up to Server 2019 Graphics Component information disclosure
10364| [139926] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10365| [139925] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10366| [139924] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10367| [139922] Microsoft Windows up to Server 2019 Graphics Component information disclosure
10368| [139921] Microsoft Windows up to Server 2019 Graphics Component information disclosure
10369| [139920] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10370| [139919] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10371| [139918] Microsoft Windows up to Server 2019 Graphics Component information disclosure
10372| [139917] Microsoft Windows up to Server 2019 Graphics Component information disclosure
10373| [139916] Microsoft Windows up to Server 2019 XML Core Services MSXML Parser privilege escalation
10374| [139914] Microsoft Windows up to Server 2019 Hyper-V Network Switch denial of service
10375| [139913] Microsoft Windows up to Server 2019 Hyper-V Network Switch denial of service
10376| [139912] Microsoft Windows 10 1809/10 1903/Server 1903/Server 2019 Hyper-V Network Switch denial of service
10377| [139911] Microsoft Windows up to Server 2019 denial of service
10378| [139910] Microsoft Windows up to Server 2019 Hyper-V Network Switch denial of service
10379| [139909] Microsoft Windows up to Server 2019 Hyper-V Network Switch denial of service
10380| [139908] Microsoft Windows up to Server 2019 Bluetooth weak encryption
10381| [139907] Microsoft Windows up to Server 2019 Remote Desktop Service privilege escalation
10382| [139906] Microsoft Windows up to Server 2019 Remote Desktop Service privilege escalation
10383| [139902] Microsoft Word up to 2019 memory corruption
10384| [139901] Microsoft Outlook up to 2019 memory corruption
10385| [139895] Microsoft Windows up to Server 2019 lnk File privilege escalation
10386| [139894] Microsoft Windows up to Server 2019 VBScript Engine memory corruption
10387| [139893] Microsoft Windows up to Server 2019 Remote Desktop Service privilege escalation
10388| [139892] Microsoft Windows up to Server 2019 Remote Desktop Service privilege escalation
10389| [139891] Microsoft Windows up to Server 2019 Font Library memory corruption
10390| [139890] Microsoft Windows up to Server 2019 Font Library memory corruption
10391| [139889] Microsoft Windows up to Server 2019 Font Library memory corruption
10392| [139888] Microsoft Windows up to Server 2019 Font Library memory corruption
10393| [139887] Microsoft Windows up to Server 2019 Font Library memory corruption
10394| [139886] Microsoft Windows up to Server 2019 Font Library memory corruption
10395| [139880] Microsoft Windows up to Server 2019 Hyper-V memory corruption
10396| [139879] Microsoft Windows up to Server 2019 DHCP Client memory corruption
10397| [139878] Microsoft Windows up to Server 2019 Hyper-V Network Switch memory corruption
10398| [139877] Microsoft Outlook up to 2019 memory corruption
10399| [139876] Microsoft Windows up to Server 2019 Remote Desktop Service privilege escalation
10400| [139875] Microsoft Windows up to Server 2019 Remote Desktop Service privilege escalation
10401| [137590] Microsoft ASP.NET Core 2.1/2.2 Open Redirect
10402| [137589] Microsoft Exchange Server 2013 CU23/2016 CU12/2016 CU13/2019 CU1/2019 CU2 cross site scripting
10403| [137588] Microsoft Exchange Server 2010 SP3/2013 CU23/2016 CU12/2016 CU13 Web Services privilege escalation
10404| [137587] Microsoft SharePoint Server 2013 SP1/2016/2019 cross site scripting
10405| [137586] Microsoft Windows up to Server 2019 AppX Deployment Service privilege escalation
10406| [137585] Microsoft Windows up to Server 2019 AppX Deployment Service privilege escalation
10407| [137584] Microsoft Windows up to Server 2019 DirectWrite memory corruption
10408| [137583] Microsoft Windows up to Server 2019 DirectWrite memory corruption
10409| [137581] Microsoft Windows up to Server 2019 DirectWrite memory corruption
10410| [137580] Microsoft Windows up to Server 2019 DirectWrite memory corruption
10411| [137579] Microsoft Windows up to Server 2019 DirectWrite memory corruption
10412| [137578] Microsoft Windows up to Server 2019 DirectWrite memory corruption
10413| [137577] Microsoft Windows up to Server 2019 DirectWrite memory corruption
10414| [137576] Microsoft Windows up to Server 2019 DirectWrite memory corruption
10415| [137575] Microsoft Windows up to Server 2019 DirectWrite memory corruption
10416| [137574] Microsoft Windows up to Server 2019 DirectWrite memory corruption
10417| [137568] Microsoft Windows up to Server 2019 Remote Desktop Protocol information disclosure
10418| [137563] Microsoft Windows up to Server 2019 DirectWrite information disclosure
10419| [137562] Microsoft Windows up to Server 2019 Win32k information disclosure
10420| [137561] Microsoft Windows up to Server 2019 GDI information disclosure
10421| [137560] Microsoft Windows up to Server 2019 GDI information disclosure
10422| [137559] Microsoft Windows up to Server 2019 DirectWrite information disclosure
10423| [137555] Microsoft Windows up to Server 2019 Audio Service privilege escalation
10424| [137554] Microsoft Windows up to Server 2019 Audio Service privilege escalation
10425| [137553] Microsoft Windows up to Server 2019 Audio Service privilege escalation
10426| [137549] Microsoft Windows up to Server 2016 DLL privilege escalation
10427| [137544] Microsoft Windows up to Server 2019 Kernel information disclosure
10428| [137543] Microsoft Windows up to Server 2019 Kernel information disclosure
10429| [137542] Microsoft SQL Server 2014 SP2/2016 SP1/2017 privilege escalation
10430| [137541] Microsoft Windows up to Server 2019 memory corruption
10431| [137540] Microsoft Windows up to Server 2019 Error Reporting privilege escalation
10432| [137539] Microsoft Windows up to Server 2016 DirectX memory corruption
10433| [137538] Microsoft Windows Server 1803/Server 1903/Server 2016/Server 2019 ADFS Security Feature privilege escalation
10434| [137537] Microsoft Windows up to Server 2019 Hyper-V denial of service
10435| [137535] Microsoft Windows up to Server 2019 Remote Desktop Service privilege escalation
10436| [137533] Microsoft Windows up to Server 2019 SymCrypt denial of service
10437| [137527] Microsoft Windows up to Server 2019 GDI+ memory corruption
10438| [137512] Microsoft Windows up to Server 2019 DHCP memory corruption
10439| [136414] Microsoft Azure DevOps Server 2019 cross site request forgery
10440| [136349] Microsoft Windows up to Server 2019 Event Viewer eventvwr.msc XML External Entity
10441| [136348] Microsoft Windows up to Server 2019 Task Scheduler privilege escalation
10442| [136347] Microsoft Windows up to Server 2019 AppXSVC privilege escalation
10443| [136345] Microsoft Windows up to Server 2019 Windows Shell privilege escalation
10444| [136344] Microsoft Windows up to Server 2019 GDI information disclosure
10445| [136340] Microsoft Windows up to Server 2019 GDI information disclosure
10446| [136337] Microsoft Windows up to Server 2019 Comctl32.dll memory corruption
10447| [136336] Microsoft Windows up to Server 2019 Kernel privilege escalation
10448| [136335] Microsoft Windows up to Server 2019 NTLM Downgrade weak authentication
10449| [136334] Microsoft Windows up to Server 2019 Kernel information disclosure
10450| [136333] Microsoft SharePoint Server 2010 SP2/2013 SP1/2016/2019 cross site scripting
10451| [136330] Microsoft SharePoint Server 2010 SP2/2013 SP1/2016/2019 cross site scripting
10452| [136329] Microsoft SharePoint Server 2016/2019 cross site scripting
10453| [136328] Microsoft SharePoint Server 2010 SP2/2013 SP1/2016/2019 cross site scripting
10454| [136327] Microsoft Lync Server 2010/2013 denial of service
10455| [136326] Microsoft Windows up to Server 2019 Audio Service privilege escalation
10456| [136325] Microsoft Windows up to Server 2019 Audio Service privilege escalation
10457| [136324] Microsoft Windows up to Server 2019 Audio Service privilege escalation
10458| [136323] Microsoft Windows up to Server 2019 denial of service
10459| [136321] Microsoft Windows 10 1809/10 1903/Server 1903/Server 2019 Audio Service privilege escalation
10460| [136320] Microsoft Windows up to Server 2019 Audio Service privilege escalation
10461| [136319] Microsoft Windows up to Server 2019 Security Credentials information disclosure
10462| [136318] Microsoft Windows up to Server 2019 DirectX privilege escalation
10463| [136317] Microsoft Windows up to Server 2019 Win32k memory corruption
10464| [136314] Microsoft Windows up to Server 2019 Win32k memory corruption
10465| [136312] Microsoft Windows up to Server 2019 GDI information disclosure
10466| [136310] Microsoft Windows up to Server 2019 GDI information disclosure
10467| [136308] Microsoft Windows up to Server 2019 Audio Service privilege escalation
10468| [136306] Microsoft Windows up to Server 2019 Storage Service privilege escalation
10469| [136305] Microsoft Windows up to Server 2019 User Profile Service privilege escalation
10470| [136304] Microsoft Windows up to Server 2019 Common Log File System Driver privilege escalation
10471| [136303] Microsoft Windows up to Server 2019 Storage Service privilege escalation
10472| [136301] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10473| [136299] Microsoft Windows up to Server 2019 Local Security Authority Subsystem Service Reboot denial of service
10474| [136296] Microsoft Windows up to Server 2019 Common Log File System Driver memory corruption
10475| [136295] Microsoft Windows up to Server 2019 ALPC privilege escalation
10476| [136293] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10477| [136292] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10478| [136291] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10479| [136290] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10480| [136289] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10481| [136288] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10482| [136287] Microsoft Windows up to Server 2019 Hyper-V denial of service
10483| [136286] Microsoft Windows up to Server 2019 Hyper-V denial of service
10484| [136285] Microsoft Windows up to Server 2019 Hyper-V denial of service
10485| [136284] Microsoft Windows up to Server 2019 Kernel memory corruption
10486| [136276] Microsoft Windows up to Server 2019 Hyper-V memory corruption
10487| [136275] Microsoft Windows 10/10 1607/10 1703/10 1709/Server 2016 Hyper-V memory corruption
10488| [136274] Microsoft Windows up to Server 2019 ActiveX memory corruption
10489| [136273] Microsoft Windows up to Server 2019 Hyper-V memory corruption
10490| [134750] Microsoft ASP.NET Core 2.1/2.2 denial of service
10491| [134745] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
10492| [134744] Microsoft Windows up to Server 2019 GDI information disclosure
10493| [134743] Microsoft SharePoint Server 2013 SP1/2016 cross site scripting
10494| [134742] Microsoft SharePoint Enterprise Server 2016/2019 cross site scripting
10495| [134741] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
10496| [134740] Microsoft SharePoint Enterprise Server 2013 SP1/2016 privilege escalation
10497| [134739] Microsoft SharePoint Foundation 2010 SP2/2013 SP2 cross site scripting
10498| [134738] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
10499| [134737] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
10500| [134736] Microsoft Office 2010 SP2 Access Connectivity Engine memory corruption
10501| [134735] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
10502| [134734] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
10503| [134733] Microsoft Windows up to Server 2019 Unified Write Filter privilege escalation
10504| [134731] Microsoft Windows up to Server 2019 Symlink privilege escalation
10505| [134729] Microsoft Windows up to Server 2019 Storage Service privilege escalation
10506| [134725] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10507| [134724] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10508| [134723] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10509| [134722] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10510| [134721] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10511| [134720] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10512| [134719] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10513| [134718] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10514| [134717] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10515| [134716] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10516| [134715] Microsoft Windows up to Server 2019 Win32k memory corruption
10517| [134714] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10518| [134713] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10519| [134712] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10520| [134710] Microsoft Windows up to Server 2019 GDI information disclosure
10521| [134709] Microsoft Windows up to Server 2019 Kernel privilege escalation
10522| [134706] Microsoft Windows up to Server 2019 Error Reporting privilege escalation
10523| [134701] Microsoft Windows up to Server 2019 Windows Defender Application Control privilege escalation
10524| [134700] Microsoft Windows up to Server 2019 Diagnostic Hub privilege escalation
10525| [134699] Microsoft Windows up to Server 2019 NDIS ndis.sys memory corruption
10526| [134698] Microsoft Windows up to Server 2019 OLE memory corruption
10527| [134684] Microsoft Windows up to Server 2019 DHCP Server memory corruption
10528| [134678] Microsoft Windows up to Server 2019 GDI+ memory corruption
10529| [133236] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10530| [133234] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10531| [133232] Microsoft Azure DevOps Server 2019 cross site scripting
10532| [133229] Microsoft Azure DevOps Server 2019 cross site scripting
10533| [133224] Microsoft Exchange Server 2013 CU22/2016 CU11/2016 CU12/2019/2019 CU1 Outlook Web Access privilege escalation
10534| [133223] Microsoft Azure DevOps Server 2019 Content Security Policy privilege escalation
10535| [133222] Microsoft Windows up to Server 2019 Remote Registry Service memory corruption
10536| [133221] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10537| [133220] Microsoft Windows up to Server 2019 GDI Memory information disclosure
10538| [133219] Microsoft Windows up to Server 2019 Win32k Memory information disclosure
10539| [133218] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10540| [133217] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10541| [133216] Microsoft Windows up to Server 2019 Kernel Memory information disclosure
10542| [133215] Microsoft Windows up to Server 2019 VBScript Engine memory corruption
10543| [133214] Microsoft Windows up to Server 2019 AppX Deployment Service privilege escalation
10544| [133213] Microsoft Windows up to Server 2019 Kernel Memory information disclosure
10545| [133212] Microsoft Windows up to Server 2019 Terminal Services Memory information disclosure
10546| [133211] Microsoft Windows up to Server 2019 Task Scheduler information disclosure
10547| [133209] Microsoft Windows up to Server 2019 LUAFV Driver luafv.sys privilege escalation
10548| [133206] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016/2019 cross site scripting
10549| [133205] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site scripting
10550| [133204] Microsoft Office/Excel up to 2019 memory corruption
10551| [133203] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
10552| [133202] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
10553| [133201] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
10554| [133200] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
10555| [133199] Microsoft Office 2010 SP2 Access Connectivity Engine memory corruption
10556| [133198] Microsoft Exchange Server up to 2019 CU1 Outlook Web Access cross site scripting
10557| [133197] Microsoft ASP.NET Core 2.2 Request denial of service
10558| [133196] Microsoft Windows up to Server 2019 Win32k information disclosure
10559| [133195] Microsoft Windows up to Server 2019 LUAFV Driver luafv.sys privilege escalation
10560| [133194] Microsoft Windows up to Server 2019 GDI Memory information disclosure
10561| [133193] Microsoft Windows up to Server 2019 LUAFV Driver luafv.sys privilege escalation
10562| [133192] Microsoft Windows up to Server 2019 OLE Automation privilege escalation
10563| [133189] Microsoft Windows up to Server 2019 CSRSS memory corruption
10564| [133188] Microsoft Windows up to Server 2019 LUAFV Driver luafv.sys privilege escalation
10565| [133187] Microsoft Windows up to Server 2019 LUAFV Driver luafv.sys privilege escalation
10566| [133186] Microsoft Windows up to Server 2019 TCP/IP Stack Fragmented IP Packet information disclosure
10567| [133185] Microsoft Windows up to Server 2019 Win32k memory corruption
10568| [133183] Microsoft Windows up to Server 2019 Win32k memory corruption
10569| [133182] Microsoft Windows up to Server 2019 Win32k memory corruption
10570| [133181] Microsoft Office/Excel/PowerPoint up to 2019 URL Document Code Execution
10571| [133180] Microsoft Windows up to Server 2019 MS XML Code Execution
10572| [133179] Microsoft Windows up to Server 2019 MS XML Code Execution
10573| [133177] Microsoft Windows up to Server 2019 Device Guard luafv.sys privilege escalation
10574| [133174] Microsoft Windows up to Server 2019 GDI+ privilege escalation
10575| [133173] Microsoft Windows up to Server 2019 IOleCvt Interface privilege escalation
10576| [133166] Microsoft Windows up to Server 2019 MS XML Code Execution
10577| [133165] Microsoft Windows up to Server 2019 MS XML Code Execution
10578| [133164] Microsoft Windows up to Server 2019 MS XML Code Execution
10579| [133163] Microsoft Windows up to Server 2019 MS XML Code Execution
10580| [133162] Microsoft Windows up to Server 2019 MS XML Code Execution
10581| [131687] Microsoft Team Foundation Server 2017 Update 3.1/2018 Update 3.2/2018 Updated 1.2 cross site scripting
10582| [131685] Microsoft Windows up to Server 2019 SMB information disclosure
10583| [131684] Microsoft Visual Studio 2017 Version 15.9 C++ Redistributable Installer privilege escalation
10584| [131681] Microsoft Windows up to Server 2019 Win32k memory corruption
10585| [131679] Microsoft Windows up to Server 2019 Kernel information disclosure
10586| [131675] Microsoft SharePoint 2013 SP1/2016 cross site scripting
10587| [131674] Microsoft Windows up to Server 2019 Win32k information disclosure
10588| [131673] Microsoft Windows up to Server 2019 Kernel information disclosure
10589| [131672] Microsoft Windows up to Server 2019 GDI information disclosure
10590| [131671] Microsoft Windows up to Server 2019 VBScript Engine memory corruption
10591| [131668] Microsoft Windows up to Server 2019 AppX Deployment Server privilege escalation
10592| [131667] Microsoft Windows up to Server 2019 Comctl32.dll memory corruption
10593| [131663] Microsoft Windows up to Server 2019 Print Spooler information disclosure
10594| [131658] Microsoft Windows up to Server 2019 information disclosure
10595| [131657] Microsoft Windows up to Server 2019 denial of service
10596| [131656] Microsoft Office 2010 SP2 Connectivity Engine memory corruption
10597| [131653] Microsoft Windows up to Server 2019 SMB information disclosure
10598| [131652] Microsoft Windows up to Server 2019 SMB information disclosure
10599| [131651] Microsoft Windows up to Server 2019 Kernel information disclosure
10600| [131650] Microsoft Windows 10 1803/10 1809/Server 1803/Server 2019 Hyper-V denial of service
10601| [131649] Microsoft Windows up to Server 2019 Kernel memory corruption
10602| [131648] Microsoft Windows up to Server 2019 Hyper-V denial of service
10603| [131644] Microsoft Windows up to Server 2019 Hyper-V denial of service
10604| [131638] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10605| [131632] Microsoft Windows 10 1803/10 1809/Server 1803/Server 2019 DHCP Client memory corruption
10606| [131631] Microsoft Windows 10 1803/10 1809/Server 1803/Server 2019 DHCP Client memory corruption
10607| [131630] Microsoft Windows 10 1803/10 1809/Server 1803/Server 2019 DHCP Client memory corruption
10608| [131629] Microsoft Windows up to Server 2019 Deployment Services TFTP Server memory corruption
10609| [131628] Microsoft Windows up to Server 2019 ActiveX memory corruption
10610| [131619] Microsoft Windows up to Server 2019 MS XML privilege escalation
10611| [131334] Microsoft Team Foundation Server 2018 Update 3.2 cross site scripting
10612| [131333] Microsoft Team Foundation Server 2018 Update 3.2 cross site scripting
10613| [131328] Microsoft Windows up to Server 2016 Kernel information disclosure
10614| [130832] Microsoft 2013 SP1 spoofing
10615| [130828] Microsoft Exchange Server 2010 SP3/2013 CU22/2016 CU12/2019 CU1 EWS privilege escalation
10616| [130826] Microsoft Office 2010 SP2 Connectivity Engine memory corruption
10617| [130825] Microsoft Office up to 2019 Connectivity Engine memory corruption
10618| [130824] Microsoft Office up to 2019 Connectivity Engine memory corruption
10619| [130823] Microsoft Office up to 2019 Connectivity Engine privilege escalation
10620| [130822] Microsoft Office up to 2019 Connectivity Engine privilege escalation
10621| [130821] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
10622| [130820] Microsoft Windows up to Server 2012 R2 GDI information disclosure
10623| [130818] Microsoft Windows up to Server 2019 GDI information disclosure
10624| [130817] Microsoft Windows up to Server 2019 Storage Service privilege escalation
10625| [130814] Microsoft Windows up to Server 2019 privilege escalation
10626| [130809] Microsoft Windows up to Server 2019 Defender Firewall Security privilege escalation
10627| [130808] Microsoft Windows up to Server 2019 information disclosure
10628| [130807] Microsoft Windows up to Server 2019 Hyper-V information disclosure
10629| [130806] Microsoft Windows up to Server 2019 SMB privilege escalation
10630| [130805] Microsoft Windows up to Server 2019 Device Guard privilege escalation
10631| [130804] Microsoft Windows up to Server 2019 Device Guard privilege escalation
10632| [130803] Microsoft Windows up to Server 2019 SMB privilege escalation
10633| [130802] Microsoft Windows up to Server 2019 Win32k information disclosure
10634| [130801] Microsoft Windows up to Server 2019 Device Guard privilege escalation
10635| [130800] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10636| [130799] Microsoft Windows up to Server 2016 Win32k memory corruption
10637| [130798] Microsoft Windows up to Server 2019 GDI information disclosure
10638| [130797] Microsoft Windows up to Server 2019 GDI information disclosure
10639| [130796] Microsoft Windows up to Server 2019 GDI information disclosure
10640| [130793] Microsoft Windows up to Server 2019 GDI information disclosure
10641| [130792] Microsoft Windows up to Server 2019 HID information disclosure
10642| [130791] Microsoft Windows up to Server 2019 HID information disclosure
10643| [130790] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10644| [130789] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10645| [130788] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10646| [130787] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10647| [130786] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10648| [130784] Microsoft Windows up to Server 2019 GDI+ memory corruption
10649| [130782] Microsoft Windows up to Server 2019 DHCP Server memory corruption
10650| [130781] Microsoft Windows up to Server 2019 GDI+ memory corruption
10651| [129847] Microsoft Team Foundation Server 2017 Update 3.1/2018 Update 1.2/2018 Update 3.2 information disclosure
10652| [129846] Microsoft Team Foundation Server 2018 Update 3.2 cross site scripting
10653| [129845] Microsoft Skype for Business 2015 CU 8 Request cross site scripting
10654| [128765] Microsoft Visual Studio 2017 Version 15.9 C++ Construct privilege escalation
10655| [128764] Microsoft Exchange Server 2010 SP3/2013 CU21/2016 CU10/2016 CU11/2019 PowerShell API information disclosure
10656| [128761] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
10657| [128760] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
10658| [128759] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
10659| [128758] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
10660| [128757] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
10661| [128756] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
10662| [128755] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
10663| [128754] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
10664| [128753] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
10665| [128752] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
10666| [128751] Microsoft Windows up to Server 2019 Data Sharing Service privilege escalation
10667| [128750] Microsoft Windows up to Server 2019 Runtime privilege escalation
10668| [128749] Microsoft Windows up to Server 2019 Kernel information disclosure
10669| [128747] Microsoft ASP.NET Core 2.1 Web Request denial of service
10670| [128746] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site scripting
10671| [128745] Microsoft Office up to 2019 Word Macro information disclosure
10672| [128742] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site scripting
10673| [128741] Microsoft SharePoint Enterprise Server 2016 cross site scripting
10674| [128740] Microsoft SharePoint Enterprise Server 2013 SP1 cross site scripting
10675| [128739] Microsoft Windows up to Server 2019 Kernel information disclosure
10676| [128738] Microsoft Windows up to Server 2019 Subsystem for Linux information disclosure
10677| [128737] Microsoft Windows up to Server 2019 COM Desktop Broker privilege escalation
10678| [128736] Microsoft Windows up to Server 2019 Kernel information disclosure
10679| [128735] Microsoft ASP.NET Core 2.1/2.2 Web Request denial of service
10680| [128733] Microsoft Windows up to Server 2019 Authentication Request privilege escalation
10681| [128729] Microsoft Visual Studio 2010 SP1/2012 Update 5 vscontent File information disclosure
10682| [128728] Microsoft Windows up to Server 2019 Kernel information disclosure
10683| [128727] Microsoft Windows up to Server 2019 Data Sharing Service privilege escalation
10684| [128726] Microsoft Windows up to Server 2019 Data Sharing Service privilege escalation
10685| [128725] Microsoft Windows up to Server 2019 Data Sharing Service privilege escalation
10686| [128718] Microsoft Windows up to Server 2019 Hyper-V memory corruption
10687| [128717] Microsoft Windows 10 1803/10 1809/Server 1803/Server 2019 Hyper-V memory corruption
10688| [127925] Microsoft SharePoint Enterprise Server 2016 Web Request cross site scripting
10689| [127882] Microsoft Dynamics NAV 2016/2017 Web Request cross site scripting
10690| [127881] Microsoft Windows 10 1809/Server 2019 Object denial of service
10691| [127880] Microsoft Windows up to Server 2019 Win32k Object memory corruption
10692| [127828] Microsoft Windows up to Server 2019 Win32k memory corruption
10693| [127827] Microsoft Windows 10 1809/Server 2019 DirectX information disclosure
10694| [127826] Microsoft Windows 10 1803/10 1809/Server 1803/Server 2019 Win32k ASLR privilege escalation
10695| [127825] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016 privilege escalation
10696| [127824] Microsoft Excel up to 2019 Out-of-Bounds memory corruption
10697| [127823] Microsoft Windows up to Server 2012 R2 Kernel information disclosure
10698| [127821] Microsoft Windows up to Server 2019 Connected User Experiences and Telemetry Service denial of service
10699| [127820] Microsoft Windows up to Server 2019 Kernel memory corruption
10700| [127819] Microsoft Exchange Server 2016 CU10/2016 CU11 Profile Data privilege escalation
10701| [127817] Microsoft Excel up to 2019 information disclosure
10702| [127816] Microsoft Windows up to Server 2019 GDI information disclosure
10703| [127815] Microsoft Windows up to Server 2019 GDI information disclosure
10704| [127814] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016 Search cross site request forgery
10705| [127812] Microsoft Windows up to Server 2019 Remote Procedure Call information disclosure
10706| [127806] Microsoft Outlook up to 2019 memory corruption
10707| [127805] Microsoft Excel up to 2019 memory corruption
10708| [127804] Microsoft Excel up to 2019 memory corruption
10709| [127803] Microsoft Windows up to Server 2019 Text-To-Speech memory corruption
10710| [127801] Microsoft Windows up to Server 2019 DNS Server privilege escalation
10711| [126938] Microsoft Team Foundation Server 2018 Update 1.1/2018 Update 3 Code Execution
10712| [126755] Microsoft .NET Core 2.1 privilege escalation
10713| [126754] Microsoft Skype for Business/Lync Server 2013 SP1/2016 Emoji denial of service
10714| [126750] Microsoft Windows up to Server 2019 ALPC privilege escalation
10715| [126749] Microsoft Exchange Server 2010/2013/2016/2019 privilege escalation
10716| [126747] Microsoft SharePoint Enterprise Server 2013 SP1 Folder information disclosure
10717| [126746] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
10718| [126745] Microsoft Project 2010 SP2/2013 SP1/2016 memory corruption
10719| [126744] Microsoft Office up to 2019 Word memory corruption
10720| [126743] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site scripting
10721| [126742] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site scripting
10722| [126739] Microsoft Windows up to Server 2012 R2 Win32k information disclosure
10723| [126737] Microsoft Windows up to Server 2012 R2 DirectX information disclosure
10724| [126736] Microsoft Windows up to Server 2019 Win32k memory corruption
10725| [126735] Microsoft Windows up to Server 2019 DirectX privilege escalation
10726| [126733] Microsoft Windows 10 1803/10 1809/Server 1803/Server 2019 DirectX memory corruption
10727| [126730] Microsoft Windows up to Server 2019 Active Directory Federation Services cross site scripting
10728| [126728] Microsoft Office/SharePoint 2010 SP2 Word memory corruption
10729| [126727] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
10730| [126726] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
10731| [126725] Microsoft Windows up to Server 2019 DirectX memory corruption
10732| [126722] Microsoft Windows up to Server 2019 PowerShell privilege escalation
10733| [126718] Microsoft Windows up to Server 2016 Search memory corruption
10734| [126717] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016/2019 memory corruption
10735| [126716] Microsoft Office up to 2019 Excel memory corruption
10736| [126714] Microsoft Windows up to Server 2019 PowerShell unknown vulnerability
10737| [126713] Microsoft Windows up to Server 2019 VBScript Engine memory corruption
10738| [126712] Microsoft Windows up to Server 2016 Graphics Component memory corruption
10739| [126711] Microsoft Windows up to Server 2019 Deployment Services TFTP Server memory corruption
10740| [125123] Microsoft Windows up to Server 2019 Codecs Library information disclosure
10741| [125122] Microsoft Windows up to Server 2016 TCP/IP information disclosure
10742| [125121] Microsoft Windows up to Server 2019 DirectX memory corruption
10743| [125120] Microsoft Windows up to Server 2019 Windows Media Player information disclosure
10744| [125119] Microsoft Windows up to Server 2019 Windows Media Player information disclosure
10745| [125116] Microsoft Exchange Server 2013 CU21/2016 CU10 privilege escalation
10746| [125115] Microsoft Windows up to Server 2019 Theme API privilege escalation
10747| [125114] Microsoft Windows up to Server 2019 Windows Shell privilege escalation
10748| [125113] Microsoft Windows up to Server 2019 Kernel memory corruption
10749| [125111] Microsoft Windows up to Server 2019 Device Guard Code Integrity Policy privilege escalation
10750| [125110] Microsoft Windows up to Server 2019 DNS Global Blocklist privilege escalation
10751| [125109] Microsoft Windows up to Server 2019 NTFS privilege escalation
10752| [125108] Microsoft Windows up to Server 2019 Filter Manager memory corruption
10753| [125107] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
10754| [125106] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
10755| [125105] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
10756| [125104] Microsoft SharePoint Enterprise Server 2016 cross site scripting
10757| [125102] Microsoft Office/Word 2010 SP2/2013 RT SP1/2013 SP1/2016/2019 Protected View memory corruption
10758| [125100] Microsoft Office/PowerPoint 2010 SP2/2013 RT SP1/2013 SP1/2016/2019 Protected View memory corruption
10759| [125099] Microsoft Office/Excel up to 2019 Protected View memory corruption
10760| [125098] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
10761| [125097] Microsoft Windows up to Server 2019 DirectX Graphics memory corruption
10762| [125096] Microsoft Windows up to Server 2019 Win32k memory corruption
10763| [125095] Microsoft Exchange Server 2013 CU21/2016 CU10 Outlook Web Access cross site scripting
10764| [125093] Microsoft Windows up to Server 2019 Hyper-V memory corruption
10765| [125092] Microsoft Windows up to Server 2019 Hyper-V memory corruption
10766| [125091] Microsoft Windows up to Server 2019 MS XML privilege escalation
10767| [124371] Microsoft Exchange Server up to 2010 SP3 Outlook Web Access /owa/auth/logon.aspx Parameter Server-Side Request Forgery
10768| [124217] Microsoft Windows Server 2012/Server 2016 Active Directory Federation Services /adfs/ls Server-Side Request Forgery
10769| [123995] Microsoft Lync 2011 on Mac Security Feature Messages Download privilege escalation
10770| [123881] Microsoft Windows up to Server 2016 Sandbox privilege escalation
10771| [123874] Microsoft Windows up to Server 2016 Kernel information disclosure
10772| [123872] Microsoft Windows 8.1/10/RT 8.1/Server 2012/Server 2012 R2 SMB information disclosure
10773| [123868] Microsoft Windows up to Server 2016 Hyper-V denial of service
10774| [123864] Microsoft Windows up to Server 2016 Hyper-V information disclosure
10775| [123862] Microsoft SharePoint Enterprise Server 2010 SP2/2013 RT SP1/2013 SP1/2016 cross site scripting
10776| [123861] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R information disclosure
10777| [123860] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
10778| [123859] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016 cross site scripting
10779| [123851] Microsoft Windows up to Server 2016 ALPC privilege escalation
10780| [123849] Microsoft Windows up to Server 2016 SMB denial of service
10781| [123846] Microsoft Office 2016 on Win/Mac memory corruption
10782| [123844] Microsoft Word 2013 RT SP1/2013 SP1/2016 PDF File memory corruption
10783| [123843] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
10784| [123842] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
10785| [123830] Microsoft Windows up to Server 2016 Hyper-V memory corruption
10786| [123828] Microsoft Windows up to Server 2016 Win32k Graphics privilege escalation
10787| [123827] Microsoft Windows up to Server 2016 Image memory corruption
10788| [123825] Microsoft Windows up to Server 2016 MSXML Parser privilege escalation
10789| [123823] Microsoft Windows up to Server 2016 Hyper-V privilege escalation
10790| [122887] Microsoft Office 2016 on Mac AutoUpdate memory corruption
10791| [122886] Microsoft Windows up to Server 2016 DirectX Graphics memory corruption
10792| [122885] Microsoft Windows up to Server 2016 DirectX Graphics memory corruption
10793| [122884] Microsoft Windows up to Server 2016 Win32k memory corruption
10794| [122883] Microsoft Windows up to Server 2016 DirectX Graphics memory corruption
10795| [122875] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R information disclosure
10796| [122874] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
10797| [122873] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R information disclosure
10798| [122871] Microsoft PowerPoint 2010 SP2 memory corruption
10799| [122870] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
10800| [122861] Microsoft Windows up to Server 2016 Microsoft COM for Windows privilege escalation
10801| [122850] Microsoft Visual Studio 2015 Update 3/2017/2017 Version 15.8 Diagnostic Hub privilege escalation
10802| [122849] Microsoft Windows up to Server 2016 Diagnostic Hub privilege escalation
10803| [122848] Microsoft Windows Security Feature 2FA weak authentication
10804| [122834] Microsoft Windows up to Server 2016 LNK memory corruption
10805| [122825] Microsoft Windows up to Server 2016 Graphics memory corruption
10806| [122823] Microsoft SQL Server 2016 SP1/2016 SP2/2017 memory corruption
10807| [121208] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R Attachment privilege escalation
10808| [121118] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
10809| [121116] Microsoft Windows up to Server 2016 Sandbox privilege escalation
10810| [121114] Microsoft Access 2013 SP1/2016/2016 C2R memory corruption
10811| [121111] Microsoft Windows up to Server 2016 Kernel memory corruption
10812| [121110] Microsoft Windows up to Server 2016 Wordpad privilege escalation
10813| [121107] Microsoft Windows up to Server 2016 DNSAPI DNSAPI.dll denial of service
10814| [121106] Microsoft SharePoint Enterprise Server 2013 SP1/2016 privilege escalation
10815| [121105] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
10816| [121098] Microsoft Office 2016/2016 C2R memory corruption
10817| [121092] Microsoft Windows up to Server 2016 FTP Server denial of service
10818| [121090] Microsoft Visual Studio up to 2017 Version 15.8 Preview privilege escalation
10819| [119479] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
10820| [119477] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016 information disclosure
10821| [119476] Microsoft Publisher 2010 SP2 OLE Object PUB File privilege escalation
10822| [119475] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016 Attachment privilege escalation
10823| [119474] Microsoft Windows up to Server 2016 GDI information disclosure
10824| [119470] Microsoft Windows up to Server 2016 HTTP HTTP.sys denial of service
10825| [119468] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
10826| [119467] Microsoft Windows up to Server 2016 Hypervisor privilege escalation
10827| [119465] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
10828| [119464] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
10829| [119463] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
10830| [119461] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
10831| [119460] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
10832| [119459] Microsoft Windows up to Server 2016 memory corruption
10833| [119457] Microsoft Windows up to Server 2016 Desktop Bridge privilege escalation
10834| [119456] Microsoft Windows up to Server 2016 Kernel information disclosure
10835| [119455] Microsoft Windows up to Server 2016 denial of service
10836| [119454] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
10837| [119452] Microsoft Windows up to Server 2016 HIDParser memory corruption
10838| [119448] Microsoft Windows up to Server 2016 Code Integrity Module denial of service
10839| [119447] Microsoft Windows up to Server 2016 NTFS privilege escalation
10840| [119441] Microsoft Windows up to Server 2016 Media Foundation memory corruption
10841| [119437] Microsoft Windows up to Server 2016 HTTP Protocol Stack Http.sys memory corruption
10842| [119436] Microsoft Windows up to Server 2016 memory corruption
10843| [119431] Microsoft Windows up to Server 2016 DNSAPI DNSAPI.dll DNS Response privilege escalation
10844| [118120] Microsoft Office 2016 on Mac XML Data Code Execution
10845| [117561] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1 Web Request cross site scripting
10846| [117560] Microsoft Exchange Server up to 2016 CU9 Code Execution memory corruption
10847| [117559] Microsoft Exchange Server 2016 CU8/2016 CU9 Outlook Web Access Web Request cross site scripting
10848| [117558] Microsoft Windows up to Server 2016 Code Execution memory corruption
10849| [117507] Microsoft Infopath 2013 SP1 memory corruption
10850| [117505] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R information disclosure
10851| [117504] Microsoft Office 2010 SP2 information disclosure
10852| [117503] Microsoft Exchange Server 2013 CU19/2013 CU20/2016 CU8/2016 CU9 Outlook Web Access cross site scripting
10853| [117502] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016 cross site scripting
10854| [117501] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
10855| [117500] Microsoft Exchange Server 2016 CU8/2016 CU9 Outlook Web Access cross site scripting
10856| [117499] Microsoft Exchange Server up to 2016 CU9 information disclosure
10857| [117498] Microsoft Office 2016 C2R Security Feature privilege escalation
10858| [117497] Microsoft SharePoint Enterprise Server 2010/2013 SP1/2016 cross site scripting
10859| [117480] Microsoft Windows up to Server 2016 COM Serialized privilege escalation
10860| [117473] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
10861| [117472] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
10862| [117471] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
10863| [117470] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
10864| [117469] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
10865| [117468] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
10866| [117444] Microsoft Windows up to Server 2016 Hyper-V vSMB memory corruption
10867| [117443] Microsoft Windows up to Server 2016 Hyper-V memory corruption
10868| [117442] Microsoft Windows up to Server 2016 VBScript Engine memory corruption
10869| [116132] Microsoft Office 2016 Memory information disclosure
10870| [116051] Microsoft SharePoint Enterprise Server 2016 cross site scripting
10871| [116050] Microsoft SharePoint Enterprise Server 2010 SP2/2013/2016 cross site scripting
10872| [116049] Microsoft SharePoint Enterprise Server 2013/2016 privilege escalation
10873| [116048] Microsoft Windows up to Server 2016 DirectX Graphics Kernel Subsystem memory corruption
10874| [116047] Microsoft Windows up to Server 2016 OpenType Font Driver atmfd.dll memory corruption
10875| [116046] Microsoft SharePoint Enterprise Server 2013/2016 Share cross site scripting
10876| [116045] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
10877| [116039] Microsoft Windows up to Server 2016 Remote Desktop Protocol denial of service
10878| [116031] Microsoft Windows up to Server 2016 Kernel ASLR information disclosure
10879| [116030] Microsoft Windows up to Server 2016 SNMP Service denial of service
10880| [116026] Microsoft Windows up to Server 2016 Kernel information disclosure
10881| [116024] Microsoft Windows up to Server 2016 HTTP.sys denial of service
10882| [116023] Microsoft Office up to 2016 C2R information disclosure
10883| [116022] Microsoft Excel 2010 SP2 memory corruption
10884| [116020] Microsoft Windows 10 1607/10 1703/10 1709/Server 1709/Server 2016 Active Directory privilege escalation
10885| [116019] Microsoft Windows up to Server 2016 Kernel information disclosure
10886| [116018] Microsoft Office 2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
10887| [116017] Microsoft Excel up to 2016 C2R memory corruption
10888| [116016] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 Graphics memory corruption
10889| [116014] Microsoft Office 2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
10890| [116013] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1 memory corruption
10891| [116008] Microsoft Windows up to Server 2016 Graphics memory corruption
10892| [116007] Microsoft Windows up to Server 2016 Graphics memory corruption
10893| [116006] Microsoft Windows up to Server 2016 Graphics memory corruption
10894| [116005] Microsoft Windows up to Server 2016 Graphics memory corruption
10895| [116004] Microsoft Windows up to Server 2016 Graphics memory corruption
10896| [116003] Microsoft Windows up to Server 2016 VBScript Engine memory corruption
10897| [115994] Microsoft Windows up to Server 2016 Malware Protection Engine memory corruption
10898| [115804] Microsoft Windows up to Server 2016 Malware Protection Engine privilege escalation
10899| [114579] Microsoft Exchange Server up to 2017 CU8 Outlook Web Access information disclosure
10900| [114574] Microsoft SharePoint Enterprise Server 2016 privilege escalation
10901| [114573] Microsoft SharePoint Enterprise Server 2016 cross site scripting
10902| [114571] Microsoft Exchange Server 2016 CU7/2016 CU8 Outlook Web Access information disclosure
10903| [114570] Microsoft Exchange Server 2010 SP3/2013 CU18/2013 CU19/2016 CU7/2016 CU8 Outlook Web Access Fake privilege escalation
10904| [114565] Microsoft Windows 10 1607/10 1703/10 1709/Server 1709/Server 2016 Kernel information disclosure
10905| [114564] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
10906| [114562] Microsoft SharePoint Enterprise Server 2016 cross site scripting
10907| [114560] Microsoft SharePoint Enterprise Server 2016 cross site scripting
10908| [114559] Microsoft SharePoint Enterprise Server 2016 cross site scripting
10909| [114558] Microsoft SharePoint Enterprise Server 2016 cross site scripting
10910| [114557] Microsoft SharePoint Enterprise Server 2016 cross site scripting
10911| [114556] Microsoft SharePoint Enterprise Server 2016 cross site scripting
10912| [114555] Microsoft SharePoint Enterprise Server 2016 cross site scripting
10913| [114554] Microsoft SharePoint Enterprise Server 2016 cross site scripting
10914| [114553] Microsoft SharePoint Enterprise Server 2016 cross site scripting
10915| [114552] Microsoft SharePoint Enterprise Server 2016 cross site scripting
10916| [114551] Microsoft Excel up to 2016 C2R Security Feature privilege escalation
10917| [114549] Microsoft Access 2010 SP2/2013 SP1/2016 memory corruption
10918| [114548] Microsoft Windows up to Server 2016 CNG Security Feature cng.sys privilege escalation
10919| [114547] Microsoft Windows up to Server 2016 Kernel information disclosure
10920| [114546] Microsoft Windows up to Server 2016 Kernel information disclosure
10921| [114545] Microsoft Windows up to Server 2016 Kernel information disclosure
10922| [114544] Microsoft Windows up to Server 2016 Kernel information disclosure
10923| [114543] Microsoft Windows up to Server 2016 Kernel information disclosure
10924| [114542] Microsoft Windows up to Server 2016 Kernel information disclosure
10925| [114541] Microsoft Windows up to Server 2016 Kernel information disclosure
10926| [114540] Microsoft Windows up to Server 2016 Kernel information disclosure
10927| [114536] Microsoft Windows up to Server 2016 CredSSP privilege escalation
10928| [114535] Microsoft Windows up to Server 2016 Hyper-V denial of service
10929| [114531] Microsoft Windows up to Server 2016 Windows Installer privilege escalation
10930| [114530] Microsoft Windows up to Server 2016 GDI privilege escalation
10931| [114529] Microsoft Windows up to Server 2016 GDI privilege escalation
10932| [114527] Microsoft Windows up to Server 2016 Kernel information disclosure
10933| [114526] Microsoft Windows up to Server 2016 Kernel information disclosure
10934| [114525] Microsoft Windows up to Server 2016 Kernel information disclosure
10935| [114522] Microsoft Windows 10 1607/10 1703/Server 2016 Desktop Bridge privilege escalation
10936| [114521] Microsoft Windows up to Server 2016 Video Control privilege escalation
10937| [114520] Microsoft Windows 10/Server 1709/Server 2016 Desktop Bridge privilege escalation
10938| [114518] Microsoft Windows up to Server 2016 Remote Assistance information disclosure
10939| [114517] Microsoft Windows 10/Server 1709/Server 2016 Desktop Bridge VFS privilege escalation
10940| [114516] Microsoft Windows up to Server 2016 Windows Shell privilege escalation
10941| [113835] Microsoft Identity Manager 2016 SP1 cross site scripting
10942| [113264] Microsoft Windows 8.1/RT 8.1/Server 2012 R2 SMBv2/SMBv3 denial of service
10943| [113260] Microsoft Windows up to Server 2016 Kernel memory corruption
10944| [113259] Microsoft Windows 10/Server 1709/Server 2016 NTFS privilege escalation
10945| [113254] Microsoft Windows up to Server 2016 Kernel information disclosure
10946| [113253] Microsoft Windows 10/Server 1709/Server 2016 Kernel memory corruption
10947| [113252] Microsoft Windows up to Server 2016 Kernel memory corruption
10948| [113250] Microsoft Windows 10/Server 1709/Server 2016 Kernel memory corruption
10949| [113249] Microsoft Windows up to Server 2016 Kernel memory corruption
10950| [113248] Microsoft Windows up to Server 2016 Kernel information disclosure
10951| [113243] Microsoft Windows 10/Server 2016 MultiPoint Management privilege escalation
10952| [113242] Microsoft Windows up to Server 2016 Common Log File System Driver memory corruption
10953| [113241] Microsoft Windows up to Server 2016 Common Log File System Driver memory corruption
10954| [113240] Microsoft Windows 10/Server 1709/Server 2016 AppContainer privilege escalation
10955| [113237] Microsoft SharePoint Enterprise Server 2016 cross site scripting
10956| [113236] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
10957| [113233] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 Uninitialized Memory information disclosure
10958| [113232] Microsoft Excel 2016 memory corruption
10959| [113230] Microsoft Windows up to Server 2016 Scripting Engine information disclosure
10960| [113229] Microsoft Windows up to Server 2016 StructuredQuery memory corruption
10961| [111580] Microsoft Office 2016 on Mac Email Attachment spoofing
10962| [111571] Microsoft SharePoint Enterprise Server 2013/2016 Access cross site scripting
10963| [111567] Microsoft Office 2010/2013/2016 memory corruption
10964| [111564] Microsoft Word 2016 memory corruption
10965| [111562] Microsoft SharePoint Server 2010/2013/2016 Web Request cross site scripting
10966| [111561] Microsoft SharePoint Server 2010/2013/2016 Web Request cross site scripting
10967| [128730] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
10968| [111358] Microsoft Windows up to Server 2016 IPsec denial of service
10969| [110553] Microsoft Office 2016 C2R information disclosure
10970| [110552] Microsoft SharePoint Enterprise Server 2016 Web Request privilege escalation
10971| [110551] Microsoft Excel 2016 C2R memory corruption
10972| [110550] Microsoft PowerPoint 2013 RT SP1/2013 SP1/2016 information disclosure
10973| [110549] Microsoft Exchange Server 2016 CU6/2016 CU7 Outlook Web Access privilege escalation
10974| [110547] Microsoft Windows up to Server 2016 its:// Protocol information disclosure
10975| [110531] Microsoft Windows 10/Server 2016 Device Guard privilege escalation
10976| [110522] Microsoft Windows up to Server 2016 RRAS privilege escalation
10977| [110350] Microsoft Windows up to Server 2016 Malware Protection Engine memory corruption
10978| [110318] Microsoft Windows up to Server 2016 Malware Protection Engine memory corruption
10979| [109391] Microsoft SharePoint Enterprise Server 2016 Project Server cross site request forgery
10980| [109389] Microsoft Excel 2016 Click-to-Run memory corruption
10981| [109360] Microsoft Windows up to Server 2016 Windows Search denial of service
10982| [107759] Microsoft Windows up to Server 2016 SMB denial of service
10983| [107757] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
10984| [107756] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
10985| [107753] Microsoft Windows 10/Server 2016 SMB privilege escalation
10986| [107744] Microsoft Windows up to Server 2016 DNSAPI DNSAPI.dll DNS Response privilege escalation
10987| [107741] Microsoft Outlook 2016 Secure Connection Mail information disclosure
10988| [107740] Microsoft Windows up to Server 2016 Graphics memory corruption
10989| [107739] Microsoft Windows up to Server 2016 Graphics memory corruption
10990| [107738] Microsoft Windows up to Server 2016 Search information disclosure
10991| [107734] Microsoft Windows 10/Server 2016 SMB privilege escalation
10992| [107732] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016 Bypass privilege escalation
10993| [107730] Microsoft Windows up to Server 2016 Search Remote memory corruption
10994| [107729] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
10995| [107728] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
10996| [107727] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
10997| [107724] Microsoft Windows up to Server 2016 Text Services Framework memory corruption
10998| [107723] Microsoft Windows up to Server 2016 SMB information disclosure
10999| [107698] Microsoft Office 2016 memory corruption
11000| [107593] InFocus Mondopad 2.2.08 Excel Spreadsheet Microsoft Office Document Credentials information disclosure
11001| [106544] Microsoft Exchange Server 2016 Outlook Web Access cross site scripting
11002| [106531] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
11003| [106529] Microsoft PowerPoint 2016 memory corruption
11004| [106523] Microsoft Windows up to Server 2016 PDF Library memory corruption
11005| [106518] Microsoft Edge on Win10/Server 2016 memory corruption
11006| [106516] Microsoft Windows up to Server 2016 PDF Library memory corruption
11007| [106498] Microsoft Windows up to Server 2016 Shell privilege escalation
11008| [106496] Microsoft Windows up to Server 2016 Uniscribe information disclosure
11009| [106495] Microsoft Windows up to Server 2012 R2 Uniscribe memory corruption
11010| [106492] Microsoft Windows Server 2012/Server 2012 R2/Server 2016 DHCP Service memory corruption
11011| [106489] Microsoft Windows up to Server 2016 Graphics Win32k win32k!fsc_CalcGrayRow memory corruption
11012| [106474] Microsoft Office 2016 memory corruption
11013| [106473] Microsoft SharePoint Server 2013 SP1 cross site scripting
11014| [106472] Microsoft Windows up to Server 2016 Bluetooth Driver Object BlueBorne spoofing
11015| [106470] Microsoft Excel 2011 on Mac memory corruption
11016| [106455] Microsoft Exchange Server 2013/2016 information disclosure
11017| [106454] Microsoft Windows up to Server 2016 Windows NetBT Session Services race condition memory corruption
11018| [105048] Microsoft Edge on Win10/Server 2016 Scripting Engine memory corruption
11019| [105047] Microsoft Edge on Win10/Server 2016 Scripting Engine EntryCall memory corruption
11020| [105046] Microsoft Edge on Win10/Server 2016 Javascript Engine memory corruption
11021| [105040] Microsoft Edge on Win10/Server 2016 Scripting Engine memory corruption
11022| [105038] Microsoft Edge on Win10/Server 2016 Javascript Engine Out-of-Bounds memory corruption
11023| [105037] Microsoft Edge on Win10/Server 2016 Javascript Engine PreVisitCatch memory corruption
11024| [105035] Microsoft SharePoint Server 2010 SP2 cross site scripting
11025| [105033] Microsoft Edge 38.14393.1066.0 on Win10/Server 2016 Use-After-Free information disclosure
11026| [105029] Microsoft Edge on Win10/Server 2016 Javascript Engine ProcessLinkFailedAsmJsModule memory corruption
11027| [105027] Microsoft Edge on Win10/Server 2016 _SelectValueInternal information disclosure
11028| [105024] Microsoft Edge on Win10/Server 2016 Javascript Engine memory corruption
11029| [105023] Microsoft Edge on Win10/Server 2016 Javascript Engine memory corruption
11030| [105017] Microsoft Windows up to Server 2016 Error Reporting information disclosure
11031| [105013] Microsoft Windows 10 1607/10 1703/Server 2016 Hyper-V denial of service
11032| [105011] Microsoft Windows up to Server 2016 Windows Search memory corruption
11033| [105010] Microsoft Windows up to Server 2016 Win32k memory corruption
11034| [105009] Microsoft Windows up to Server 2016 Input Method Editor memory corruption
11035| [105008] Microsoft SQL Server 2012/2014/2016 Analysis Services information disclosure
11036| [104990] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
11037| [104989] Microsoft Windows up to Server 2016 NetBIOS denial of service
11038| [104584] Microsoft Outlook up to 2016 C2R Document File privilege escalation
11039| [104583] Microsoft Outlook up to 2016 C2R Email memory corruption
11040| [104582] Microsoft Outlook up to 2016 C2R Object memory corruption
11041| [103468] Microsoft Exchange Server 2010 SP3/2013 CU16/2013 SP3/2016 CU5 Open Redirect
11042| [103446] Microsoft Windows up to Server 2016 Search Object privilege escalation
11043| [103445] Microsoft Windows up to Server 2016 Wordpad privilege escalation
11044| [103444] Microsoft Windows up to Server 2016 Explorer denial of service
11045| [103442] Microsoft Windows 10/Server 2016 HoloLens WiFi Packet privilege escalation
11046| [103441] Microsoft Windows up to Server 2016 Object HTTP.sys information disclosure
11047| [103431] Microsoft Windows up to Server 2016 PowerShell PSObject Object privilege escalation
11048| [103429] Microsoft Windows up to Server 2016 Kerberos weak authentication
11049| [103426] Microsoft Exchange Server 2010 SP3/2013 CU16/2013 SP3/2016 CU5 OWA Request cross site scripting
11050| [103425] Microsoft Exchange Server 2010 SP3/2013 CU16/2013 SP3/2016 CU5 OWA Request cross site scripting
11051| [103420] Microsoft Windows up to Server 2016 Kerberos Bypass privilege escalation
11052| [103417] Microsoft Windows up to Server 2016 Windows Shell privilege escalation
11053| [102544] Microsoft Edge on Win10/Server 2016 Fetch API information disclosure
11054| [102543] Microsoft Edge on Win10/Server 2016 Javascript XML DOM Object information disclosure
11055| [102463] Microsoft Project Server 2013 SP1 cross site scripting
11056| [102460] Microsoft Outlook 2016 on Mac HTML spoofing
11057| [102448] Microsoft SharePoint Enterprise Server 2016 Reflected cross site scripting
11058| [102446] Microsoft Office up to 2016 privilege escalation
11059| [102445] Microsoft Office 2010 SP2/2011/2013 RT SP1/2013 SP1/2016 privilege escalation
11060| [102443] Microsoft Office up to 2016 privilege escalation
11061| [102412] Microsoft Windows up to Server 2016 PDF information disclosure
11062| [102397] Microsoft Outlook 2010 SP1/2013 SP1/2016 DLL Loader privilege escalation
11063| [102396] Microsoft Office 2013 SP1/2016 DLL Loader privilege escalation
11064| [102386] Microsoft Windows up to Server 2012 R2 Uniscribe privilege escalation
11065| [102385] Microsoft Windows up to Server 2016 Font Library privilege escalation
11066| [102376] Microsoft Windows up to Server 2016 CAB File privilege escalation
11067| [102375] Microsoft Windows up to Server 2016 PDF Parser privilege escalation
11068| [102374] Microsoft Windows up to Server 2016 PDF Parser privilege escalation
11069| [102373] Microsoft Windows up to Server 2016 Uniscribe Font USP10!MergeLigRecords memory corruption
11070| [101817] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
11071| [101816] Microsoft Windows up to Server 2016 Malware Protection Engine setCaller memory corruption
11072| [101815] Microsoft Windows up to Server 2016 Malware Protection Engine Use-After-Free memory corruption
11073| [101814] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
11074| [101813] Microsoft Windows up to Server 2016 Malware Protection Engine memory corruption
11075| [101812] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
11076| [101811] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
11077| [101810] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
11078| [101028] Microsoft Windows 10/Server 2016 Hyper-V vSMB privilege escalation
11079| [101020] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
11080| [101019] Microsoft Skype for Business 2016 memory corruption
11081| [101018] Microsoft SharePoint 2010 SP2/2013 SP1/2016 memory corruption
11082| [101016] Microsoft PowerPoint 2011 on Mac memory corruption
11083| [101015] Microsoft PowerPoint 2011 on Mac memory corruption
11084| [101014] Microsoft Office 2010 SP2/2016 memory corruption
11085| [101013] Microsoft Office 2010 SP2/2016 memory corruption
11086| [101002] Microsoft Windows up to Server 2016 SMBv1 Server memory corruption
11087| [101001] Microsoft Windows up to Server 2016 SMBv1 Server memory corruption
11088| [101000] Microsoft Windows up to Server 2016 SMBv1 Server memory corruption
11089| [100999] Microsoft Windows up to Server 2016 SMBv1 Server memory corruption
11090| [100918] Microsoft Windows 8/8.1/10/Server 2012/Server 2016 Malware Protection Service Type Confusion privilege escalation
11091| [99697] Microsoft SharePoint Server 2010 SP1/2010 SP2 Excel Services cross site scripting
11092| [99683] Microsoft Windows 10 1607/10 1703/Server 2012 R2/Server 2016 Active Directory Lockout privilege escalation
11093| [99682] Microsoft Outlook 2011 on Mac HTML Tag Validator spoofing
11094| [99681] Microsoft Windows up to Server 2016 OLE Integrity-Level Check privilege escalation
11095| [99667] Microsoft Windows 10/Server 2016 Active Directory Service Unresponsive denial of service
11096| [98272] Microsoft Windows up to 10/Server 2016 Local Session privilege escalation
11097| [98096] Microsoft Exchange 2013 SP1 privilege escalation
11098| [98095] Microsoft Lync for Mac 2011 Certificate Validation weak authentication
11099| [98094] Microsoft SharePoint Server 2013 SP1 cross site scripting
11100| [98093] Microsoft SharePoint Server/Office Web Apps 2010 SP2 memory corruption
11101| [98091] Microsoft SharePoint Server/Office Web Apps 2010 SP2 memory corruption
11102| [98090] Microsoft SharePoint Server 2010 SP2/2013 SP1 information disclosure
11103| [98089] Microsoft Office Web Apps 2013 SP1 memory corruption
11104| [98082] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 denial of service
11105| [98081] Microsoft Excel up to 2016 information disclosure
11106| [98080] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
11107| [98079] Microsoft Word 2016 memory corruption
11108| [98076] Microsoft Lync/Skype for Business 2010/2013/2016 Graphics Component privilege escalation
11109| [98075] Microsoft Lync/Skype for Business 2010/2013/2016 GDI+ information disclosure
11110| [98074] Microsoft Lync/Skype for Business 2010/2013/2016 GDI+ information disclosure
11111| [98073] Microsoft Office 2010 SP2/Word Viewer Graphics Component information disclosure
11112| [98069] Microsoft Windows up to Server 2012 R2 Color Management memory corruption
11113| [98056] Microsoft Windows up to Server 2016 DNS Query information disclosure
11114| [98054] Microsoft Windows up to Server 2016 SMBv2/SMBv3 NULL Pointer Dereference memory corruption
11115| [98017] Microsoft Windows up to Server 2016 PDF memory corruption
11116| [98015] Microsoft Windows 10/Server 2016 Hyper-V denial of service
11117| [98013] Microsoft Windows 10/Server 2016 Hyper-V vSMB memory corruption
11118| [98007] Microsoft Windows 10/Server 2016 Hyper-V Network Switch denial of service
11119| [98006] Microsoft Windows 10/Server 2016 Hyper-V vSMB memory corruption
11120| [96521] Microsoft Windows 8.1/10/Server 2012/Server 2016 SMB Response mrxsmb20.sys denial of service
11121| [95781] Microsoft PowerPoint 2016 Java Embedded Object privilege escalation
11122| [95125] Microsoft Word/SharePoint Enterprise Server 2016 Document privilege escalation
11123| [94451] Microsoft Office 2011 memory corruption
11124| [94447] Microsoft Office 2010 SP2 memory corruption
11125| [94446] Microsoft Office 2016 memory corruption
11126| [94444] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 OLE DLL Loader memory corruption
11127| [94443] Microsoft Office up to 2016 information disclosure
11128| [94442] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 privilege escalation
11129| [93964] Microsoft Windows 7 Excel Starter 2010 XXE information disclosure
11130| [93543] Microsoft SQL Server 2016 FILESTREAM Path privilege escalation
11131| [93540] Microsoft Excel 2010 SP2/2011/2016 memory corruption
11132| [93416] Microsoft SQL Server 2014 SP2/2016/up to 2012 SP3 Server Agent atxcore.dll privilege escalation
11133| [93415] Microsoft SQL Server 2016 MDS API cross site scripting
11134| [93414] Microsoft SQL Server up to 2012 SP3 RDBMS Engine privilege escalation
11135| [93413] Microsoft SQL Server 2016/up to 2014 SP2 RDBMS Engine privilege escalation
11136| [93412] Microsoft SQL Server 2016 RDBMS Engine privilege escalation
11137| [93393] Microsoft Office up to 2016 memory corruption
11138| [93392] Microsoft Office up to 2016 memory corruption
11139| [93391] Microsoft Office up to 2016 memory corruption
11140| [93389] Microsoft Windows up to Server 2016 Media Foundation memory corruption
11141| [93388] Microsoft Windows up to Server 2016 Animation Manager Stylesheets memory corruption
11142| [92587] Microsoft Windows 8.1/10/RT 8.1/Server 2012/Server 2012 R2 Transaction Manager privilege escalation
11143| [92584] Microsoft Office up to 2016 memory corruption
11144| [91571] Microsoft Windows 8.1/10/RT 8.1/Server 2012/Server 2012 R2 PDF Library information disclosure
11145| [91570] Microsoft Windows 8.1/10/RT 8.1/Server 2012/Server 2012 R2 PDF Library information disclosure
11146| [91556] Microsoft Exchange 2016 Meeting Invation cross site scripting
11147| [91555] Microsoft Exchange 2013/2016 Link spoofing
11148| [91550] Microsoft Office 2016 memory corruption
11149| [91547] Microsoft Office 2010 memory corruption
11150| [91543] Microsoft Office up to 2016 memory corruption
11151| [91541] Microsoft Office 2013/2016 APP-V ASLR privilege escalation
11152| [90711] Microsoft Windows 8.1/10/RT 8.1/Server 2012/Server 2012 R2 PDF privilege escalation
11153| [90710] Microsoft Windows 8.1/RT 8.1/Server 2012/Server 2012 R2 Netlogon privilege escalation
11154| [90704] Microsoft Office 2013/2013 RT/2016 memory corruption
11155| [89043] Microsoft Office up to 2016 memory corruption
11156| [89041] Microsoft Office up to 2016 memory corruption
11157| [89040] Microsoft Office 2010 SP2/2011/2013 RT SP1/2013 SP1/2016 memory corruption
11158| [89038] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 Security Feature privilege escalation
11159| [89037] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
11160| [87961] Microsoft Windows up to Server 2012 R2 Search denial of service
11161| [87959] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 PDF information disclosure
11162| [87958] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 PDF memory corruption
11163| [87957] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 PDF information disclosure
11164| [87956] Microsoft Exchange 2013/2016 Oracle Outside In Libraries information disclosure
11165| [87944] Microsoft Windows Server 2012/Server 2012 R2 Virtual PCI Memory information disclosure
11166| [87940] Microsoft Windows Server 2012/Server 2012 R2 DNS Server Use-After-Free memory corruption
11167| [87936] Microsoft Office up to 2016 memory corruption
11168| [87166] Microsoft Windows up to Server 2012 R2 DirectX Graphics Kernel Subsystem privilege escalation
11169| [87156] Microsoft Windows 8.1/10/RT 8.1/Server 2012 R2 Shell memory corruption
11170| [87149] Microsoft Office up to 2016 memory corruption
11171| [87148] Microsoft Office 2010 Graphics memory corruption
11172| [87146] Microsoft Office 2011/2013/2013 RT/2016 memory corruption
11173| [82229] Microsoft Excel 2010 SP2 Office Document memory corruption
11174| [82223] Microsoft Windows 8.1/10/Server 2012 R2 Hyper-V Memory information disclosure
11175| [82222] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 Memory information disclosure
11176| [82221] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 Hyper-V privilege escalation
11177| [81274] Microsoft Office up to 2016 memory corruption
11178| [81270] Microsoft Windows 8.1/10/RT 8.1/Server 2012/Server 2012 R2 PDF Library memory corruption
11179| [81269] Microsoft Windows up to Server 2012 R2 Media Parser memory corruption
11180| [81268] Microsoft Windows up to Server 2012 R2 Media Parser memory corruption
11181| [80886] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
11182| [80885] Microsoft Windows 7 SP1/8.1/10/Server 2012/Server 2012 R2 RDP memory corruption
11183| [80878] Microsoft Windows Server 2012 R2 Active Directory Federation Service denial of service
11184| [80874] Microsoft Windows 7 SP1/8.1/10/Server 2012/Server 2012 R2 RDP privilege escalation
11185| [80870] Microsoft Office up to 2016 memory corruption
11186| [80868] Microsoft Office up to 2016 memory corruption
11187| [80867] Microsoft Office up to 2016 memory corruption
11188| [80865] Microsoft Windows 8.1/RT 8.1/Server 2012/Server 2012 R2 DLL Loader memory corruption
11189| [80860] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 Reader memory corruption
11190| [80859] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 PDF Library memory corruption
11191| [80231] Microsoft Excel up to 2016 Office Document memory corruption
11192| [80229] Microsoft Exchange Server 2013 CU 10/2013 CU 11/2013 SP1/2016 Outlook Web Access cross site scripting
11193| [80228] Microsoft Exchange Server 2016 Outlook Web Access cross site scripting
11194| [80227] Microsoft Exchange Server 2013 CU 10/2013 SP1/2016 Outlook Web Access cross site scripting
11195| [80226] Microsoft Exchange Server 2016 Outlook Web Access cross site scripting
11196| [80218] Microsoft Office up to 2016 ASLR privilege escalation
11197| [80217] Microsoft SharePoint Foundation 2013 SP1 Access Control Policy cross site scripting
11198| [80216] Microsoft Office up to 2016 Office Document memory corruption
11199| [80206] Microsoft SharePoint Foundation 2013 SP1 Access Control Policy cross site scripting
11200| [128763] Microsoft Exchange Server 2016 CU10/2016 CU11/2019 memory corruption
11201| [79508] Microsoft Windows up to Server 2012 R2 Library Loader memory corruption
11202| [79500] Microsoft Office 2010/2011/2016 memory corruption
11203| [79183] Microsoft Windows up to Server 2012 R2 IPsec denial of service
11204| [79173] Microsoft Windows up to Server 2012 R2 Graphics information disclosure
11205| [79117] Microsoft Outlook 2011/2016 on Mac HTML spoofing
11206| [78375] Microsoft SharePoint Server/SharePoint Foundation 2013 SP1 cross site scripting
11207| [77645] Microsoft Exchange Server 2013 CU8/2013 CU9 Outlook Web Access cross site scripting
11208| [77644] Microsoft Exchange Server 2013 CU8/2013 CU9 Outlook Web Access cross site scripting
11209| [77638] Microsoft Lync Server 2013 cross site scripting
11210| [77628] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
11211| [77612] Microsoft Exchange Server 2013 CU8/2013 CU9 Outlook Web Access Stack-Based information disclosure
11212| [77050] Microsoft Office up to 2016 memory corruption
11213| [77037] Microsoft Windows Server 2012/Server 2012 R2 System Center Operations Manager cross site scripting
11214| [76461] Microsoft Windows up to Server 2012 R2 Domain-Controller Communication Credentials information disclosure
11215| [76460] Microsoft Windows 7 SP1/8/Server 2012 RDP Server Service memory corruption
11216| [76448] Microsoft Windows 8.1/Server 2012 R2 Hyper-V memory corruption
11217| [75793] Microsoft Exchange Server 2013 CU8 cross site scripting
11218| [75792] Microsoft Exchange Server 2013 SP1 CU8 cross site request forgery
11219| [75791] Microsoft Office 2013 SP1 Office Document Uninitialized Memory memory corruption
11220| [75787] Microsoft Exchange Server 2013 SP1 CU8 Same Origin Policy privilege escalation
11221| [75786] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1 Office Document memory corruption
11222| [66976] Microsoft Access 2010 VBA Datatype denial of service
11223| [74848] Microsoft SharePoint Foundation/SharePoint Server 2013 SP1 cross site scripting
11224| [74842] Microsoft Windows 8.1/Server 2012 R2 Hyper-V denial of service
11225| [74836] Microsoft Project Server 2010 SP2/2013 SP1 cross site scripting
11226| [74835] Microsoft Office 2011 on Mac Use-After-Free cross site scripting
11227| [74834] Microsoft Windows Server 2012 R2 Active Directory Federation Services 3.0 privilege escalation
11228| [74833] Microsoft Windows 7 SP1/8/8.1/Server 2012/Server 2012 R2 HTTP Request HTTP.sys privilege escalation
11229| [74393] Microsoft SharePoint Server 2013 Foundation cross site scripting
11230| [73967] Microsoft Office up to 2013 SP1 Office File memory corruption
11231| [73966] Microsoft Office up to 2013 SP1 RTF File memory corruption
11232| [73965] Microsoft Office up to 2013 SP1 Use-After-Free memory corruption
11233| [73961] Microsoft Windows 7 SP1/8/8.1/Server 2012/Server 2012 R2 Remote Desktop Protocol Object Management denial of service
11234| [69162] Microsoft System Center Virtual Machine Manager 2012 privilege escalation
11235| [69160] Microsoft Windows up to Server 2012 Process privilege escalation
11236| [69156] Microsoft Office 2010 Object memory corruption
11237| [68593] Microsoft Windows up to Server 2012 Network Location Awareness Service privilege escalation
11238| [68417] Microsoft Exchange 2013 Outlook Web Access Token spoofing
11239| [68191] Microsoft SharePoint 2010 cross site scripting
11240| [67828] Microsoft ASP.NET MVC 2/3/4/5/5.1 System.Web.Mvc.dll cross site scripting
11241| [67518] Microsoft Lync 2013 denial of service
11242| [67517] Microsoft Lync 2013 Script Reflected cross site scripting
11243| [67516] Microsoft Lync 2010/2013 denial of service
11244| [67362] Microsoft Windows up to Server 2012 R2 Remote Procedure Call privilege escalation
11245| [67360] Microsoft SharePoint 2013 App Permission Management cross site scripting
11246| [13549] Microsoft Windows 7/8/8.1/Server 2012 Remote Desktop Protocol weak encryption
11247| [13547] Microsoft Lync 2010/2013 Meeting cross site scripting
11248| [13228] Microsoft Office 2013 Document privilege escalation
11249| [68577] Microsoft ASP.NET 2014.3.1209 Telerik UI RadAsyncUpload directory traversal
11250| [12267] Microsoft Forefront Security for Exchange Server 2010 Mail memory corruption
11251| [12263] Microsoft Windows up to Server 2012 Direct2D 2D Geometric Figure memory corruption
11252| [12238] Microsoft Windows 8/RT/Server 2012 IPv6 denial of service
11253| [12185] Microsoft .NET Framework 2/4 HMAC weak authentication
11254| [12183] Microsoft .NET Framework 2/4 DTD denial of service
11255| [11673] Microsoft Windows Live Movie Maker 2011 WAV File denial of service
11256| [11468] Microsoft Exchange 2010/2013 cross site scripting
11257| [11466] Microsoft Office 2013 File Response information disclosure
11258| [11457] Microsoft SharePoint Server/Office Web Apps 2010 SP1/2010 SP2/2013 W3WP Service Account privilege escalation
11259| [11150] Microsoft Windows 8/Server 2012 Hyper-V Data Structure Value Crash privilege escalation
11260| [11004] Microsoft Windows Server 2012 R2 RDP Restricted Admin Mode weak authentication
11261| [10250] Microsoft SharePoint Server up to 2013 W3WP Process denial of service
11262| [10249] Microsoft SharePoint 2010/2003/2007/2.0/3.0 Workflow memory corruption
11263| [10248] Microsoft SharePoint Server up to 2013 cross site scripting
11264| [9943] Microsoft Windows Server 2012 NAT Driver ICMP Packet denial of service
11265| [8739] Microsoft Windows Essentials up to 2012 Windows Writer Eingabe information disclosure
11266| [8725] Microsoft Lync 2010/2013 Use-After-Free memory corruption
11267| [8722] Microsoft Windows 8/RT/Server 2012 HTTP.sys denial of service
11268| [8206] Microsoft SharePoint Server 2010 SP1 HTML Sanitization Component cross site scripting
11269| [8203] Microsoft Windows up to 2012 AD LDAP Query denial of service
11270| [8200] Microsoft SharePoint Server 2013 ACL information disclosure
11271| [7971] Microsoft Office for Mac 2011 up to 14.3.1 on Mac HTML5 Mail Message Parser File information disclosure
11272| [7969] Microsoft OneNote 2010 SP1 ONE File information disclosure
11273| [7968] Microsoft SharePoint Server 2010 SP1 Input Validator Eingabe Crash denial of service
11274| [7967] Microsoft SharePoint Server 2010 SP1 User Account Eingabe Crash information disclosure
11275| [7966] Microsoft SharePoint Server 2010 SP1 Eingabe Crash cross site scripting
11276| [7965] Microsoft SharePoint Server 2010 SP1 User Account Callback URL privilege escalation
11277| [7964] Microsoft Visio 2010 Tree Object Type File memory corruption
11278| [7343] Microsoft Lync 2012 HTTP Format String
11279| [7258] Microsoft Windows up to 8/Server 2012 SSL/TLS race condition
11280| [7230] Microsoft Excel 2010 SP1 on 32-bit XLS File Formatting Information Crash denial of service
11281| [6831] Microsoft Office Picture Manager 2010 File memory corruption
11282| [62720] EMC NetWorker Module for Microsoft Applications up to 2.2.0 memory corruption
11283| [6624] Microsoft SQL Server up to 2012 Report Manager cross site scripting
11284| [62238] Microsoft Visual Studio Team Foundation Server 2010 cross site scripting
11285| [5946] Microsoft Visio/Visio Viewer up to 2010 SP1 File memory corruption
11286| [5644] Microsoft SharePoint 2010 scriptesx.ashx cross site scripting
11287| [5641] Microsoft SharePoint 2010 cross site scripting
11288| [60943] Microsoft Dynamics AX 2012 Enterprise Portal cross site scripting
11289| [12311] Microsoft Lync 2010 Search race condition
11290| [60570] Microsoft Forefront Unified Access Gateway 2010 information disclosure
11291| [60569] Microsoft Forefront Unified Access Gateway 2010 spoofing
11292| [60208] Microsoft Visio Viewer 2010 memory corruption
11293| [60207] Microsoft Visio Viewer 2010 memory corruption
11294| [60206] Microsoft Visio Viewer 2010 memory corruption
11295| [4640] Microsoft SharePoint 2010 inplview.aspx cross site scripting
11296| [4636] Microsoft SharePoint 2010 wizardlist.aspx cross site scripting
11297| [4635] Microsoft SharePoint 2010 themeweb.aspx cross site scripting
11298| [59008] Microsoft Forefront Unified Access Gateway 2010 Crash denial of service
11299| [58995] Microsoft Forefront Unified Access Gateway 2010 memory corruption
11300| [58994] Microsoft Forefront Unified Access Gateway 2010 Reflected cross site scripting
11301| [58993] Microsoft Forefront Unified Access Gateway 2010 Reflected cross site scripting
11302| [4424] Microsoft Host Integration Server up to 2010 denial of service
11303| [4420] Microsoft Forefront Unified Access Gateway 2010 memory corruption
11304| [58487] Microsoft SharePoint Foundation 2010 cross site scripting
11305| [58486] Microsoft SharePoint Foundation 2010 Reflected cross site scripting
11306| [58485] Microsoft SharePoint Foundation 2010 EditForm.aspx cross site scripting
11307| [4414] Microsoft SharePoint 2010 cross site scripting
11308| [4413] Microsoft SharePoint 2010/2007/3.0 XML/XLS unknown vulnerability
11309| [91971] Microsoft Skype 2.2.x/5.2.x/5.3.x denial of service
11310| [57693] Microsoft Forefront Threat Management Gateway 2010 NSPLookupServiceNext memory corruption
11311| [56028] Microsoft Data Access Components 2.8 memory corruption
11312| [55777] Microsoft Windows Movie Maker 2.6 memory corruption
11313| [55424] Microsoft Forefront Unified Access Gateway 2010 Signurl.asp cross site scripting
11314| [55415] Microsoft Forefront Unified Access Gateway 2010 cross site scripting
11315| [55414] Microsoft Forefront Unified Access Gateway 2010 cross site scripting
11316| [55413] Microsoft Forefront Unified Access Gateway 2010 spoofing
11317| [54341] Microsoft Windows Movie Maker 2.1 memory corruption
11318| [54549] Microsoft PowerPoint 2010 pptimpconv.dll memory corruption
11319| [4009] Microsoft NET Framework 2.x/3.x denial of service
11320| [45681] Microsoft Internet Explorer 8 Beta 2 privilege escalation
11321| [45449] Microsoft Internet Explorer 8 Beta 2 XSS Filter cross site scripting
11322| [45448] Microsoft Internet Explorer 8 Beta 2 XSS Filter cross site scripting
11323| [45446] Microsoft Internet Explorer 8 Beta 2 XSS Filter cross site scripting
11324| [2927] Microsoft Data Access Components 2.x ADODB.Connection ActiveX Control memory corruption
11325| [32692] Microsoft XML Core Services up to 2.6 memory corruption
11326| [32691] Microsoft XML Core Services up to 2.6 memory corruption
11327|
11328| MITRE CVE - https://cve.mitre.org:
11329| [CVE-2013-3661] The EPATHOBJ::bFlatten function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not check whether linked-list traversal is continually accessing the same list member, which allows local users to cause a denial of service (infinite traversal) via vectors that trigger a crafted PATHRECORD chain.
11330| [CVE-2013-3660] The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 does not properly initialize a pointer for the next object in a certain list, which allows local users to obtain write access to the PATHRECORD chain, and consequently gain privileges, by triggering excessive consumption of paged memory and then making many FlattenPath function calls, aka "Win32k Read AV Vulnerability."
11331| [CVE-2013-3174] DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 allows remote attackers to execute arbitrary code via a crafted GIF file, aka "DirectShow Arbitrary Memory Overwrite Vulnerability."
11332| [CVE-2013-3173] Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Win32k Buffer Overwrite Vulnerability."
11333| [CVE-2013-3172] Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to cause a denial of service (system hang) via a crafted application that leverages improper handling of objects in memory, aka "Win32k Buffer Overflow Vulnerability."
11334| [CVE-2013-3171] The serialization functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly check the permissions of delegate objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a partial-trust relationship, aka "Delegate Serialization Vulnerability."
11335| [CVE-2013-3167] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Information Disclosure Vulnerability."
11336| [CVE-2013-3154] The signature-update functionality in Windows Defender on Microsoft Windows 7 and Windows Server 2008 R2 relies on an incorrect pathname, which allows local users to gain privileges via a Trojan horse application in the %SYSTEMDRIVE% top-level directory, aka "Microsoft Windows 7 Defender Improper Pathname Vulnerability."
11337| [CVE-2013-3138] Integer overflow in the TCP/IP kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (system hang) via crafted TCP packets, aka "TCP/IP Integer Overflow Vulnerability."
11338| [CVE-2013-3136] The kernel in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, and Windows 8 on 32-bit platforms does not properly handle unspecified page-fault system calls, which allows local users to obtain sensitive information from kernel memory via a crafted application, aka "Kernel Information Disclosure Vulnerability."
11339| [CVE-2013-3134] The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 on 64-bit platforms does not properly allocate arrays of structures, which allows remote attackers to execute arbitrary code via a crafted .NET Framework application that changes array data, aka "Array Allocation Vulnerability."
11340| [CVE-2013-3133] Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "Anonymous Method Injection Vulnerability."
11341| [CVE-2013-3132] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "Delegate Reflection Bypass Vulnerability."
11342| [CVE-2013-3131] Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5, and Silverlight 5 before 5.1.20513.0, does not properly prevent changes to data in multidimensional arrays of structures, which allows remote attackers to execute arbitrary code via (1) a crafted .NET Framework application or (2) a crafted Silverlight application, aka "Array Access Violation Vulnerability."
11343| [CVE-2013-1345] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Vulnerability."
11344| [CVE-2013-1340] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Dereference Vulnerability."
11345| [CVE-2013-1339] The Print Spooler in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly manage memory during deletion of printer connections, which allows remote authenticated users to execute arbitrary code via a crafted request, aka "Print Spooler Vulnerability."
11346| [CVE-2013-1336] The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check signatures, which allows remote attackers to make undetected changes to signed XML documents via unspecified vectors that preserve signature validity, aka "XML Digital Signature Spoofing Vulnerability."
11347| [CVE-2013-1335] Microsoft Word 2003 SP3 and Word Viewer allow remote attackers to execute arbitrary code via crafted shape data in a Word document, aka "Word Shape Corruption Vulnerability."
11348| [CVE-2013-1334] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Window Handle Vulnerability."
11349| [CVE-2013-1332] dxgkrnl.sys (aka the DirectX graphics kernel subsystem) in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "DirectX Graphics Kernel Subsystem Double Fetch Vulnerability."
11350| [CVE-2013-1331] Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Office document, leading to improper memory allocation, aka "Office Buffer Overflow Vulnerability."
11351| [CVE-2013-1329] Integer signedness error in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers a buffer underflow, aka "Publisher Buffer Underflow Vulnerability."
11352| [CVE-2013-1328] Microsoft Publisher 2003 SP3, 2007 SP3, and 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers incorrect pointer handling, aka "Publisher Pointer Handling Vulnerability."
11353| [CVE-2013-1327] Integer signedness error in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers an improper memory allocation, aka "Publisher Signed Integer Vulnerability."
11354| [CVE-2013-1323] Microsoft Publisher 2003 SP3 does not properly handle NULL values for unspecified data items, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Incorrect NULL Value Handling Vulnerability."
11355| [CVE-2013-1322] Microsoft Publisher 2003 SP3 does not properly check table range data, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Invalid Range Check Vulnerability."
11356| [CVE-2013-1321] Microsoft Publisher 2003 SP3 does not properly check the data type of an unspecified return value, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Return Value Validation Vulnerability."
11357| [CVE-2013-1320] Buffer overflow in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Buffer Overflow Vulnerability."
11358| [CVE-2013-1319] Microsoft Publisher 2003 SP3 does not properly check the return value of an unspecified method, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Return Value Handling Vulnerability."
11359| [CVE-2013-1318] Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers access to an invalid pointer, aka "Publisher Corrupt Interface Pointer Vulnerability."
11360| [CVE-2013-1317] Integer overflow in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers an improper allocation-size calculation, aka "Publisher Integer Overflow Vulnerability."
11361| [CVE-2013-1316] Microsoft Publisher 2003 SP3 does not properly validate the size of an unspecified array, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Negative Value Allocation Vulnerability."
11362| [CVE-2013-1302] Microsoft Communicator 2007 R2, Lync 2010, Lync 2010 Attendee, and Lync Server 2013 do not properly handle objects in memory, which allows remote attackers to execute arbitrary code via an invitation that triggers access to a deleted object, aka "Lync RCE Vulnerability."
11363| [CVE-2013-1301] Microsoft Visio 2003 SP3 2007 SP3, and 2010 SP1 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, aka "XML External Entities Resolution Vulnerability."
11364| [CVE-2013-1300] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Memory Allocation Vulnerability."
11365| [CVE-2013-1295] The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "CSRSS Memory Corruption Vulnerability."
11366| [CVE-2013-1294] Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Kernel Race Condition Vulnerability."
11367| [CVE-2013-1293] The NTFS kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via a crafted application that leverages improper handling of objects in memory, aka "NTFS NULL Pointer Dereference Vulnerability."
11368| [CVE-2013-1292] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Win32k Race Condition Vulnerability."
11369| [CVE-2013-1291] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 Gold and SP1, and Windows 8 allows local users to cause a denial of service (reboot) via a crafted OpenType font, aka "OpenType Font Parsing Vulnerability" or "Win32k Font Parsing Vulnerability."
11370| [CVE-2013-1287] The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Windows USB Descriptor Vulnerability," a different vulnerability than CVE-2013-1285 and CVE-2013-1286.
11371| [CVE-2013-1286] The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Windows USB Descriptor Vulnerability," a different vulnerability than CVE-2013-1285 and CVE-2013-1287.
11372| [CVE-2013-1285] The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Windows USB Descriptor Vulnerability," a different vulnerability than CVE-2013-1286 and CVE-2013-1287.
11373| [CVE-2013-1283] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Win32k Race Condition Vulnerability."
11374| [CVE-2013-1281] The NFS server in Microsoft Windows Server 2008 R2 and R2 SP1 and Server 2012 allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via an attempted renaming of a file or folder located on a read-only share, aka "NULL Dereference Vulnerability."
11375| [CVE-2013-1280] The kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Reference Count Vulnerability."
11376| [CVE-2013-1279] Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages incorrect handling of objects in memory, aka "Kernel Race Condition Vulnerability," a different vulnerability than CVE-2013-1278.
11377| [CVE-2013-1278] Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages incorrect handling of objects in memory, aka "Kernel Race Condition Vulnerability," a different vulnerability than CVE-2013-1279.
11378| [CVE-2013-1277] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
11379| [CVE-2013-1276] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
11380| [CVE-2013-1275] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
11381| [CVE-2013-1274] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
11382| [CVE-2013-1273] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
11383| [CVE-2013-1272] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
11384| [CVE-2013-1271] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
11385| [CVE-2013-1270] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
11386| [CVE-2013-1269] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
11387| [CVE-2013-1268] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
11388| [CVE-2013-1267] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
11389| [CVE-2013-1266] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
11390| [CVE-2013-1265] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
11391| [CVE-2013-1264] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
11392| [CVE-2013-1263] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
11393| [CVE-2013-1262] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
11394| [CVE-2013-1261] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
11395| [CVE-2013-1260] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
11396| [CVE-2013-1259] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
11397| [CVE-2013-1258] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
11398| [CVE-2013-1257] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
11399| [CVE-2013-1256] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
11400| [CVE-2013-1255] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
11401| [CVE-2013-1254] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
11402| [CVE-2013-1253] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
11403| [CVE-2013-1252] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
11404| [CVE-2013-1251] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
11405| [CVE-2013-1250] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
11406| [CVE-2013-1249] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
11407| [CVE-2013-1248] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
11408| [CVE-2013-0095] Outlook in Microsoft Office for Mac 2008 before 12.3.6 and Office for Mac 2011 before 14.3.2 allows remote attackers to trigger access to a remote URL and consequently confirm the rendering of an HTML e-mail message by including unspecified HTML5 elements and leveraging the installation of a WebKit browser on the victim's machine, aka "Unintended Content Loading Vulnerability."
11409| [CVE-2013-0077] Quartz.dll in DirectShow in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows remote attackers to execute arbitrary code via crafted media content in (1) a media file, (2) a media stream, or (3) a Microsoft Office document, aka "Media Decompression Vulnerability."
11410| [CVE-2013-0076] The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Reference Count Vulnerability."
11411| [CVE-2013-0075] The TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (reboot) via a crafted packet that terminates a TCP connection, aka "TCP FIN WAIT Vulnerability."
11412| [CVE-2013-0073] The Windows Forms (aka WinForms) component in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly restrict the privileges of a callback function during object creation, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "WinForms Callback Elevation Vulnerability."
11413| [CVE-2013-0013] The SSL provider component in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle encrypted packets, which allows man-in-the-middle attackers to conduct SSLv2 downgrade attacks against (1) SSLv3 sessions or (2) TLS sessions by intercepting handshakes and injecting content, aka "Microsoft SSL Version 3 and TLS Protocol Security Feature Bypass Vulnerability."
11414| [CVE-2013-0011] The Print Spooler in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted print job, aka "Windows Print Spooler Components Vulnerability."
11415| [CVE-2013-0010] Cross-site scripting (XSS) vulnerability in Microsoft System Center Operations Manager 2007 SP1 and R2 allows remote attackers to inject arbitrary web script or HTML via crafted input, aka "System Center Operations Manager Web Console XSS Vulnerability," a different vulnerability than CVE-2013-0009.
11416| [CVE-2013-0009] Cross-site scripting (XSS) vulnerability in Microsoft System Center Operations Manager 2007 SP1 and R2 allows remote attackers to inject arbitrary web script or HTML via crafted input, aka "System Center Operations Manager Web Console XSS Vulnerability," a different vulnerability than CVE-2013-0010.
11417| [CVE-2013-0008] win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle window broadcast messages, which allows local users to gain privileges via a crafted application, aka "Win32k Improper Message Handling Vulnerability."
11418| [CVE-2013-0004] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate the permissions of objects in memory, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "Double Construction Vulnerability."
11419| [CVE-2013-0003] Buffer overflow in a System.DirectoryServices.Protocols (S.DS.P) namespace method in Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a missing array-size check during a memory copy operation, aka "S.DS.P Buffer Overflow Vulnerability."
11420| [CVE-2013-0002] Buffer overflow in the Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages improper counting of objects during a memory copy operation, aka "WinForms Buffer Overflow Vulnerability."
11421| [CVE-2013-0001] The Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 4, and 4.5 does not properly initialize memory arrays, which allows remote attackers to obtain sensitive information via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a pointer to an unmanaged memory location, aka "System Drawing Information Disclosure Vulnerability."
11422| [CVE-2012-5672] Microsoft Excel Viewer (aka Xlview.exe) and Excel in Microsoft Office 2007 (aka Office 12) allow remote attackers to cause a denial of service (read access violation and application crash) via a crafted spreadsheet file, as demonstrated by a .xls file with battery voltage data.
11423| [CVE-2012-4791] Microsoft Exchange Server 2007 SP3 and 2010 SP1 and SP2 allows remote authenticated users to cause a denial of service (Information Store service hang) by subscribing to a crafted RSS feed, aka "RSS Feed May Cause Exchange DoS Vulnerability."
11424| [CVE-2012-4786] The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allow remote attackers to execute arbitrary code via a crafted TrueType Font (TTF) file, aka "TrueType Font Parsing Vulnerability."
11425| [CVE-2012-4776] The Web Proxy Auto-Discovery (WPAD) functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not validate configuration data that is returned during acquisition of proxy settings, which allows remote attackers to execute arbitrary JavaScript code by providing crafted data during execution of (1) an XAML browser application (aka XBAP) or (2) a .NET Framework application, aka "Web Proxy Auto-Discovery Vulnerability."
11426| [CVE-2012-4774] Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allow remote attackers to execute arbitrary code via a crafted (1) file name or (2) subfolder name that triggers use of unallocated memory as the destination of a copy operation, aka "Windows Filename Parsing Vulnerability."
11427| [CVE-2012-2897] The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT, as used by Google Chrome before 22.0.1229.79 and other programs, do not properly handle objects in memory, which allows remote attackers to execute arbitrary code via a crafted TrueType font file, aka "Windows Font Parsing Vulnerability" or "TrueType Font Parsing Vulnerability."
11428| [CVE-2012-2556] The OpenType Font (OTF) driver in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to execute arbitrary code via a crafted OpenType font file, aka "OpenType Font Parsing Vulnerability."
11429| [CVE-2012-2553] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application, aka "Win32k Use After Free Vulnerability."
11430| [CVE-2012-2552] Cross-site scripting (XSS) vulnerability in the SQL Server Report Manager in Microsoft SQL Server 2000 Reporting Services SP2 and SQL Server 2005 SP4, 2008 SP2 and SP3, 2008 R2 SP1, and 2012 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "Reflected XSS Vulnerability."
11431| [CVE-2012-2551] The server in Kerberos in Microsoft Windows Server 2008 R2 and R2 SP1, and Windows 7 Gold and SP1, allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via a crafted session request, aka "Kerberos NULL Dereference Vulnerability."
11432| [CVE-2012-2543] Stack-based buffer overflow in Microsoft Excel 2007 SP2 and SP3 and 2010 SP1
11433| [CVE-2012-2539] Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1
11434| [CVE-2012-2536] Cross-site scripting (XSS) vulnerability in Microsoft Systems Management Server 2003 SP3 and System Center Configuration Manager 2007 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Reflected XSS Vulnerability."
11435| [CVE-2012-2530] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application, aka "Win32k Use After Free Vulnerability."
11436| [CVE-2012-2529] Integer overflow in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Windows Kernel Integer Overflow Vulnerability."
11437| [CVE-2012-2528] Use-after-free vulnerability in Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1
11438| [CVE-2012-2527] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application, aka "Win32k Use After Free Vulnerability."
11439| [CVE-2012-2524] Microsoft Office 2007 SP2 and SP3 and 2010 SP1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Computer Graphics Metafile (CGM) file, aka "CGM File Format Memory Corruption Vulnerability."
11440| [CVE-2012-2520] Cross-site scripting (XSS) vulnerability in Microsoft InfoPath 2007 SP2 and SP3 and 2010 SP1, Communicator 2007 R2, Lync 2010 and 2010 Attendee, SharePoint Server 2007 SP2 and SP3 and 2010 SP1, Groove Server 2010 SP1, Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010 SP1, and Office Web Apps 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted string, aka "HTML Sanitization Vulnerability."
11441| [CVE-2012-2519] Untrusted search path vulnerability in Entity Framework in ADO.NET in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, and 4 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .NET application, aka ".NET Framework Insecure Library Loading Vulnerability."
11442| [CVE-2012-1896] Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly consider trust levels during construction of output data, which allows remote attackers to obtain sensitive information via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka "Code Access Security Info Disclosure Vulnerability."
11443| [CVE-2012-1895] The reflection implementation in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4 does not properly enforce object permissions, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka "Reflection Bypass Vulnerability."
11444| [CVE-2012-1893] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate callback parameters during creation of a hook procedure, which allows local users to gain privileges via a crafted application, aka "Win32k Incorrect Type Handling Vulnerability."
11445| [CVE-2012-1890] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle keyboard-layout files, which allows local users to gain privileges via a crafted application, aka "Keyboard Layout Vulnerability."
11446| [CVE-2012-1887] Use-after-free vulnerability in Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 SP1, and Office 2008 and 2011 for Mac, allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel SST Invalid Length Use After Free Vulnerability."
11447| [CVE-2012-1886] Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 SP1
11448| [CVE-2012-1885] Heap-based buffer overflow in Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 SP1
11449| [CVE-2012-1870] The CBC mode in the TLS protocol, as used in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and other products, allows remote web servers to obtain plaintext data by triggering multiple requests to a third-party HTTPS server and sniffing the network during the resulting HTTPS session, aka "TLS Protocol Vulnerability."
11450| [CVE-2012-1867] Integer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted TrueType font file that triggers incorrect memory allocation, aka "Font Resource Refcount Integer Overflow Vulnerability."
11451| [CVE-2012-1866] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle user-mode input passed to kernel mode for driver objects, which allows local users to gain privileges via a crafted application, aka "Clipboard Format Atom Name Handling Vulnerability."
11452| [CVE-2012-1865] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle user-mode input passed to kernel mode for driver objects, which allows local users to gain privileges via a crafted application, aka "String Atom Class Name Handling Vulnerability," a different vulnerability than CVE-2012-1864.
11453| [CVE-2012-1864] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle user-mode input passed to kernel mode for driver objects, which allows local users to gain privileges via a crafted application, aka "String Atom Class Name Handling Vulnerability," a different vulnerability than CVE-2012-1865.
11454| [CVE-2012-1863] Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2007 SP2 and SP3 Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "SharePoint Reflected List Parameter Vulnerability."
11455| [CVE-2012-1862] Open redirect vulnerability in Microsoft Office SharePoint Server 2007 SP2 and SP3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka "SharePoint URL Redirection Vulnerability."
11456| [CVE-2012-1860] Microsoft Office SharePoint Server 2007 SP2 and SP3, SharePoint Server 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 do not properly check permissions for search scopes, which allows remote authenticated users to obtain sensitive information or cause a denial of service (data modification) by changing a parameter in a search-scope URL, aka "SharePoint Search Scope Vulnerability."
11457| [CVE-2012-1858] The toStaticHTML API (aka the SafeHTML component) in Microsoft Internet Explorer 8 and 9, Communicator 2007 R2, and Lync 2010 and 2010 Attendee does not properly handle event attributes and script, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted HTML document, aka "HTML Sanitization Vulnerability."
11458| [CVE-2012-1856] The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Server 2000 SP4, SQL Server 2005 SP4, SQL Server 2008 SP2, SP3, R2, R2 SP1, and R2 SP2, Commerce Server 2002 SP4, Commerce Server 2007 SP2, Commerce Server 2009 Gold and R2, Host Integration Server 2004 SP1, Visual FoxPro 8.0 SP1, Visual FoxPro 9.0 SP2, and Visual Basic 6.0 Runtime allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption, aka "MSCOMCTL.OCX RCE Vulnerability."
11459| [CVE-2012-1855] Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly handle function pointers, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka ".NET Framework Memory Access Vulnerability."
11460| [CVE-2012-1854] Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1
11461| [CVE-2012-1851] Format string vulnerability in the Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted response, aka "Print Spooler Service Format String Vulnerability."
11462| [CVE-2012-1850] The Remote Administration Protocol (RAP) implementation in the LanmanWorkstation service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle RAP responses, which allows remote attackers to cause a denial of service (service hang) via crafted RAP packets, aka "Remote Administration Protocol Denial of Service Vulnerability."
11463| [CVE-2012-1848] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly handle user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Scrollbar Calculation Vulnerability."
11464| [CVE-2012-1847] Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1
11465| [CVE-2012-1537] Heap-based buffer overflow in DirectPlay in DirectX 9.0 through 11.1 in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 allows remote attackers to execute arbitrary code via a crafted Office document, aka "DirectPlay Heap Overflow Vulnerability."
11466| [CVE-2012-1528] Integer overflow in Windows Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 allows local users to gain privileges via a crafted briefcase, aka "Windows Briefcase Integer Overflow Vulnerability."
11467| [CVE-2012-1527] Integer underflow in Windows Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 allows local users to gain privileges via a crafted briefcase, aka "Windows Briefcase Integer Underflow Vulnerability."
11468| [CVE-2012-1459] The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, nProtect Anti-Virus 2011-01-17.01, Panda Antivirus 10.0.2.7, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field corresponding to that entire entry, plus part of the header of the next entry. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
11469| [CVE-2012-1457] The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field that exceeds the total TAR file size. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
11470| [CVE-2012-1453] The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Trend Micro AntiVirus 9.120.0.1004, McAfee Gateway (formerly Webwasher) 2010.1C, Emsisoft Anti-Malware 5.1.0.1, CA eTrust Vet Antivirus 36.1.8511, Antiy Labs AVL SDK 2.0.3.7, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Rising Antivirus 22.83.00.03, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via a CAB file with a modified coffFiles field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.
11471| [CVE-2012-1443] The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Command Antivirus 5.2.11.5, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Emsisoft Anti-Malware 5.1.0.1, PC Tools AntiVirus 7.0.3.5, F-Prot Antivirus 4.6.2.117, VirusBuster 13.6.151.0, Fortinet Antivirus 4.2.254.0, Antiy Labs AVL SDK 2.0.3.7, K7 AntiVirus 9.77.3565, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Jiangmin Antivirus 13.0.900, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Sophos Anti-Virus 4.61.0, NOD32 Antivirus 5795, Avira AntiVir 7.11.1.163, Norman Antivirus 6.06.12, McAfee Anti-Virus Scanning Engine 5.400.0.1158, Panda Antivirus 10.0.2.7, McAfee Gateway (formerly Webwasher) 2010.1C, Trend Micro AntiVirus 9.120.0.1004, Comodo Antivirus 7424, Bitdefender 7.2, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, nProtect Anti-Virus 2011-01-17.01, AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, avast! Antivirus 4.8.1351.0 and 5.0.677.0, and VBA32 3.12.14.2 allows user-assisted remote attackers to bypass malware detection via a RAR file with an initial MZ character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different RAR parser implementations.
11472| [CVE-2012-1420] The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Panda Antivirus 10.0.2.7, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial \7fELF character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
11473| [CVE-2012-1194] The resolver in the DNS Server service in Microsoft Windows Server 2008 before R2 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack.
11474| [CVE-2012-0185] Heap-based buffer overflow in Microsoft Excel 2007 SP2 and SP3 and 2010 Gold and SP1, Excel Viewer, and Office Compatibility Pack SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet that triggers incorrect handling of memory during opening, aka "Excel MergeCells Record Heap Overflow Vulnerability."
11475| [CVE-2012-0184] Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1
11476| [CVE-2012-0183] Microsoft Word 2003 SP3 and 2007 SP2 and SP3, Office 2008 and 2011 for Mac, and Office Compatibility Pack SP2 and SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, aka "RTF Mismatch Vulnerability."
11477| [CVE-2012-0182] Microsoft Word 2007 SP2 and SP3 does not properly handle memory during the parsing of Word documents, which allows remote attackers to execute arbitrary code via a crafted document, aka "Word PAPX Section Corruption Vulnerability."
11478| [CVE-2012-0181] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly manage Keyboard Layout files, which allows local users to gain privileges via a crafted application, aka "Keyboard Layout File Vulnerability."
11479| [CVE-2012-0180] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly handle user-mode input passed to kernel mode for (1) windows and (2) messages, which allows local users to gain privileges via a crafted application, aka "Windows and Messages Vulnerability."
11480| [CVE-2012-0179] Double free vulnerability in tcpip.sys in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that binds an IPv6 address to a local interface, aka "TCP/IP Double Free Vulnerability."
11481| [CVE-2012-0178] Race condition in partmgr.sys in Windows Partition Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that makes multiple simultaneous Plug and Play (PnP) Configuration Manager function calls, aka "Plug and Play (PnP) Configuration Manager Vulnerability."
11482| [CVE-2012-0177] Heap-based buffer overflow in the Office Works File Converter in Microsoft Office 2007 SP2, Works 9, and Works 6-9 File Converter allows remote attackers to execute arbitrary code via a crafted Works (aka .wps) file, aka "Office WPS Converter Heap Overflow Vulnerability."
11483| [CVE-2012-0175] The Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted name for a (1) file or (2) directory, aka "Command Injection Vulnerability."
11484| [CVE-2012-0174] Windows Firewall in tcpip.sys in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly enforce firewall rules for outbound broadcast packets, which allows remote attackers to obtain potentially sensitive information by observing broadcast traffic on a local network, aka "Windows Firewall Bypass Vulnerability."
11485| [CVE-2012-0173] The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process packets in memory, which allows remote attackers to execute arbitrary code by sending crafted RDP packets triggering access to an object that (1) was not properly initialized or (2) is deleted, aka "Remote Desktop Protocol Vulnerability," a different vulnerability than CVE-2012-0002.
11486| [CVE-2012-0167] Heap-based buffer overflow in the Office GDI+ library in Microsoft Office 2003 SP3 and 2007 SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted EMF image in an Office document, aka "GDI+ Heap Overflow Vulnerability."
11487| [CVE-2012-0165] GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2 and Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1 does not properly validate record types in EMF images, which allows remote attackers to execute arbitrary code via a crafted image, aka "GDI+ Record Type Vulnerability."
11488| [CVE-2012-0163] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate function parameters, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka ".NET Framework Parameter Validation Vulnerability."
11489| [CVE-2012-0161] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly handle an unspecified exception during use of partially trusted assemblies to serialize input data, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka ".NET Framework Serialization Vulnerability."
11490| [CVE-2012-0160] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly serialize input data, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka ".NET Framework Serialization Vulnerability."
11491| [CVE-2012-0159] Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview
11492| [CVE-2012-0158] The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1
11493| [CVE-2012-0157] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle window messaging, which allows local users to gain privileges via a crafted application that calls the PostMessage function, aka "PostMessage Function Vulnerability."
11494| [CVE-2012-0156] DirectWrite in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly render Unicode characters, which allows remote attackers to cause a denial of service (application hang) via a (1) instant message or (2) web site, aka "DirectWrite Application Denial of Service Vulnerability."
11495| [CVE-2012-0154] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers keyboard layout errors, aka "Keyboard Layout Use After Free Vulnerability."
11496| [CVE-2012-0152] The Remote Desktop Protocol (RDP) service in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (application hang) via a series of crafted packets, aka "Terminal Server Denial of Service Vulnerability."
11497| [CVE-2012-0151] The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to execute arbitrary code via a modified file with additional content, aka "WinVerifyTrust Signature Validation Vulnerability."
11498| [CVE-2012-0150] Buffer overflow in msvcrt.dll in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted media file, aka "Msvcrt.dll Buffer Overflow Vulnerability."
11499| [CVE-2012-0149] afd.sys in the Ancillary Function Driver in Microsoft Windows Server 2003 SP2 does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."
11500| [CVE-2012-0148] afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 on 64-bit platforms does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "AfdPoll Elevation of Privilege Vulnerability."
11501| [CVE-2012-0143] Microsoft Excel 2003 SP3 and Office 2008 for Mac do not properly handle memory during the opening of files, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Memory Corruption Using Various Modified Bytes Vulnerability."
11502| [CVE-2012-0142] Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1
11503| [CVE-2012-0141] Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1
11504| [CVE-2012-0015] Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly calculate the length of an unspecified buffer, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka ".NET Framework Heap Corruption Vulnerability."
11505| [CVE-2012-0014] Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.1.10111, does not properly restrict access to memory associated with unmanaged objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4) a crafted Silverlight application, aka ".NET Framework Unmanaged Objects Vulnerability."
11506| [CVE-2012-0013] Incomplete blacklist vulnerability in the Windows Packager configuration in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted ClickOnce application in a Microsoft Office document, related to .application files, aka "Assembly Execution Vulnerability."
11507| [CVE-2012-0009] Untrusted search path vulnerability in the Windows Object Packager configuration in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a Trojan horse executable file in the current working directory, as demonstrated by a directory that contains a file with an embedded packaged object, aka "Object Packager Insecure Executable Launching Vulnerability."
11508| [CVE-2012-0008] Untrusted search path vulnerability in Microsoft Visual Studio 2008 SP1, 2010, and 2010 SP1 allows local users to gain privileges via a Trojan horse add-in in an unspecified directory, aka "Visual Studio Add-In Vulnerability."
11509| [CVE-2012-0006] The DNS server in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 does not properly handle objects in memory during record lookup, which allows remote attackers to cause a denial of service (daemon restart) via a crafted query, aka "DNS Denial of Service Vulnerability."
11510| [CVE-2012-0005] The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2, when a Chinese, Japanese, or Korean system locale is used, can access uninitialized memory during the processing of Unicode characters, which allows local users to gain privileges via a crafted application, aka "CSRSS Elevation of Privilege Vulnerability."
11511| [CVE-2012-0004] Unspecified vulnerability in DirectShow in DirectX in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted media file, related to Quartz.dll, Qdvd.dll, closed captioning, and the Line21 DirectShow filter, aka "DirectShow Remote Code Execution Vulnerability."
11512| [CVE-2012-0003] Unspecified vulnerability in winmm.dll in Windows Multimedia Library in Windows Media Player (WMP) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows remote attackers to execute arbitrary code via a crafted MIDI file, aka "MIDI Remote Code Execution Vulnerability."
11513| [CVE-2012-0002] The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process packets in memory, which allows remote attackers to execute arbitrary code by sending crafted RDP packets triggering access to an object that (1) was not properly initialized or (2) is deleted, aka "Remote Desktop Protocol Vulnerability."
11514| [CVE-2012-0001] The kernel in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly load structured exception handling tables, which allows context-dependent attackers to bypass the SafeSEH security feature by leveraging a Visual C++ .NET 2003 application, aka "Windows Kernel SafeSEH Bypass Vulnerability."
11515| [CVE-2011-5046] The Graphics Device Interface (GDI) in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted data, as demonstrated by a large height attribute of an IFRAME element rendered by Safari, aka "GDI Access Violation Vulnerability."
11516| [CVE-2011-4434] Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 do not properly enforce AppLocker rules, which allows local users to bypass intended access restrictions via a (1) macro or (2) scripting feature in an application, as demonstrated by Microsoft Office applications and the SANDBOX_INERT and LOAD_IGNORE_CODE_AUTHZ_LEVEL flags.
11517| [CVE-2011-3417] The Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0, when sliding expiry is enabled, does not properly handle cached content, which allows remote attackers to obtain access to arbitrary user accounts via a crafted URL, aka "ASP.NET Forms Authentication Ticket Caching Vulnerability."
11518| [CVE-2011-3416] The Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 allows remote authenticated users to obtain access to arbitrary user accounts via a crafted username, aka "ASP.Net Forms Authentication Bypass Vulnerability."
11519| [CVE-2011-3415] Open redirect vulnerability in the Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted return URL, aka "Insecure Redirect in .NET Form Authentication Vulnerability."
11520| [CVE-2011-3414] The CaseInsensitiveHashProvider.getHashCode function in the HashTable implementation in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters, aka "Collisions in HashTable May Cause DoS Vulnerability."
11521| [CVE-2011-3413] Microsoft PowerPoint 2007 SP2
11522| [CVE-2011-3412] Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, allows remote attackers to execute arbitrary code via a crafted Publisher file that leverages incorrect memory handling, aka "Publisher Memory Corruption Vulnerability."
11523| [CVE-2011-3411] Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that leverages incorrect handling of values in memory, aka "Publisher Invalid Pointer Vulnerability."
11524| [CVE-2011-3410] Array index error in Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, allows remote attackers to execute arbitrary code via a crafted Publisher file that leverages incorrect handling of values in memory, aka "Publisher Out-of-bounds Array Index Vulnerability."
11525| [CVE-2011-3408] Csrsrv.dll in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly check permissions for sending inter-process device-event messages from low-integrity processes to high-integrity processes, which allows local users to gain privileges via a crafted application, aka "CSRSS Local Privilege Elevation Vulnerability."
11526| [CVE-2011-3406] Buffer overflow in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote authenticated users to execute arbitrary code via a crafted query that leverages incorrect memory initialization, aka "Active Directory Buffer Overflow Vulnerability."
11527| [CVE-2011-3403] Microsoft Excel 2003 SP3 and Office 2004 for Mac do not properly handle objects in memory, which allows remote attackers to execute arbitrary code via a crafted Excel spreadsheet, aka "Record Memory Corruption Vulnerability."
11528| [CVE-2011-3402] Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via crafted font data in a Word document or web page, as exploited in the wild in November 2011 by Duqu, aka "TrueType Font Parsing Vulnerability."
11529| [CVE-2011-3400] Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 do not properly handle OLE objects in memory, which allows remote attackers to execute arbitrary code via a crafted object in a file, aka "OLE Property Vulnerability."
11530| [CVE-2011-3397] The Microsoft Time component in DATIME.DLL in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted web site that leverages an unspecified "binary behavior" in Internet Explorer, aka "Microsoft Time Remote Code Execution Vulnerability."
11531| [CVE-2011-3396] Untrusted search path vulnerability in Microsoft PowerPoint 2007 SP2 and 2010 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "PowerPoint Insecure Library Loading Vulnerability."
11532| [CVE-2011-2019] Untrusted search path vulnerability in Microsoft Internet Explorer 9 on Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains an HTML file, aka "Internet Explorer Insecure Library Loading Vulnerability."
11533| [CVE-2011-2018] The kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, and Windows 7 Gold and SP1 does not properly initialize objects, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Exception Handler Vulnerability."
11534| [CVE-2011-2016] Untrusted search path vulnerability in Windows Mail and Windows Meeting Space in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .eml or .wcinv file, aka "Windows Mail Insecure Library Loading Vulnerability."
11535| [CVE-2011-2014] The LDAP over SSL (aka LDAPS) implementation in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not examine Certificate Revocation Lists (CRLs), which allows remote authenticated users to bypass intended certificate restrictions and access Active Directory resources by leveraging a revoked X.509 certificate for a domain account, aka "LDAPS Authentication Bypass Vulnerability."
11536| [CVE-2011-2013] Integer overflow in the TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code by sending a sequence of crafted UDP packets to a closed port, aka "Reference Counter Overflow Vulnerability."
11537| [CVE-2011-2011] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, aka "Win32k Use After Free Vulnerability."
11538| [CVE-2011-2008] Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service outage) via crafted TCP or UDP traffic, aka "Access of Unallocated Memory DoS Vulnerability."
11539| [CVE-2011-2007] Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service outage) via crafted TCP or UDP traffic, aka "Endless Loop DoS in snabase.exe Vulnerability."
11540| [CVE-2011-2005] afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."
11541| [CVE-2011-2004] Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (reboot) via a crafted TrueType font file, aka "TrueType Font Parsing Vulnerability," a different vulnerability than CVE-2011-3402.
11542| [CVE-2011-2003] Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted .fon file, aka "Font Library File Buffer Overrun Vulnerability."
11543| [CVE-2011-2002] win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle TrueType fonts, which allows local users to cause a denial of service (system hang) via a crafted font file, aka "Win32k TrueType Font Type Translation Vulnerability."
11544| [CVE-2011-1991] Multiple untrusted search path vulnerabilities in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allow local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .doc, .rtf, or .txt file, related to (1) deskpan.dll in the Display Panning CPL Extension, (2) EAPHost Authenticator Service, (3) Folder Redirection, (4) HyperTerminal, (5) the Japanese Input Method Editor (IME), and (6) Microsoft Management Console (MMC), aka "Windows Components Insecure Library Loading Vulnerability."
11545| [CVE-2011-1990] Microsoft Excel 2007 SP2
11546| [CVE-2011-1989] Microsoft Excel 2003 SP3 and 2007 SP2
11547| [CVE-2011-1988] Microsoft Excel 2003 SP3 and 2007 SP2
11548| [CVE-2011-1987] Array index error in Microsoft Excel 2003 SP3 and 2007 SP2
11549| [CVE-2011-1986] Use-after-free vulnerability in Microsoft Excel 2003 SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Use after Free WriteAV Vulnerability."
11550| [CVE-2011-1985] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via a crafted application, aka "Win32k Null Pointer De-reference Vulnerability."
11551| [CVE-2011-1984] WINS in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 allows local users to gain privileges by sending crafted packets over the loopback interface, aka "WINS Local Elevation of Privilege Vulnerability."
11552| [CVE-2011-1983] Use-after-free vulnerability in Microsoft Office 2007 SP2 and SP3, Office 2010 Gold and SP1, and Office for Mac 2011 allows remote attackers to execute arbitrary code via a crafted Word document, aka "Word Use After Free Vulnerability."
11553| [CVE-2011-1982] Microsoft Office 2007 SP2, and 2010 Gold and SP1, does not initialize an unspecified object pointer during the opening of Word documents, which allows remote attackers to execute arbitrary code via a crafted document, aka "Office Uninitialized Object Pointer Vulnerability."
11554| [CVE-2011-1980] Untrusted search path vulnerability in Microsoft Office 2003 SP3 and 2007 SP2 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .doc, .ppt, or .xls file, aka "Office Component Insecure Library Loading Vulnerability."
11555| [CVE-2011-1979] Microsoft Visio 2003 SP3 and 2007 SP2 does not properly validate objects in memory during Visio file parsing, which allows remote attackers to execute arbitrary code via a crafted file, aka "Move Around the Block RCE Vulnerability."
11556| [CVE-2011-1978] Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4 does not properly validate the System.Net.Sockets trust level, which allows remote attackers to obtain sensitive information or trigger arbitrary outbound network traffic via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Socket Restriction Bypass Vulnerability."
11557| [CVE-2011-1976] Cross-site scripting (XSS) vulnerability in the Report Viewer Control in Microsoft Visual Studio 2005 SP1 and Report Viewer 2005 SP1 allows remote attackers to inject arbitrary web script or HTML via a parameter in a data source, aka "Report Viewer Controls XSS Vulnerability."
11558| [CVE-2011-1975] Untrusted search path vulnerability in the Data Access Tracing component in Windows Data Access Components (Windows DAC) 6.0 in Microsoft Windows 7 Gold and SP1 and Windows Server 2008 R2 and R2 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains an Excel .xlsx file, aka "Data Access Components Insecure Library Loading Vulnerability."
11559| [CVE-2011-1974] NDISTAPI.sys in the NDISTAPI driver in Remote Access Service (RAS) in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "NDISTAPI Elevation of Privilege Vulnerability."
11560| [CVE-2011-1972] Microsoft Visio 2003 SP3, 2007 SP2, and 2010 Gold and SP1 does not properly validate objects in memory during Visio file parsing, which allows remote attackers to execute arbitrary code via a crafted file, aka "pStream Release RCE Vulnerability."
11561| [CVE-2011-1971] The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly parse file metadata, which allows local users to cause a denial of service (reboot) via a crafted file, aka "Windows Kernel Metadata Parsing DOS Vulnerability."
11562| [CVE-2011-1970] The DNS server in Microsoft Windows Server 2003 SP2 and Windows Server 2008 SP2, R2, and R2 SP1 does not properly initialize memory, which allows remote attackers to cause a denial of service (service outage) via a query for a nonexistent domain, aka "DNS Uninitialized Memory Corruption Vulnerability."
11563| [CVE-2011-1968] The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 does not properly process packets in memory, which allows remote attackers to cause a denial of service (reboot) by sending crafted RDP packets triggering access to an object that (1) was not properly initialized or (2) is deleted, as exploited in the wild in 2011, aka "Remote Desktop Protocol Vulnerability."
11564| [CVE-2011-1967] Winsrv.dll in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly check permissions for sending inter-process device-event messages from low-integrity processes to high-integrity processes, which allows local users to gain privileges via a crafted application, aka "CSRSS Vulnerability."
11565| [CVE-2011-1966] The DNS server in Microsoft Windows Server 2008 SP2, R2, and R2 SP1 does not properly handle NAPTR queries that trigger recursive processing, which allows remote attackers to execute arbitrary code via a crafted query, aka "DNS NAPTR Query Vulnerability."
11566| [CVE-2011-1965] Tcpip.sys in the TCP/IP stack in Microsoft Windows 7 Gold and SP1 and Windows Server 2008 R2 and R2 SP1 does not properly implement URL-based QoS, which allows remote attackers to cause a denial of service (reboot) via a crafted URL to a web server, aka "TCP/IP QOS Denial of Service Vulnerability."
11567| [CVE-2011-1894] The MHTML protocol handler in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle a MIME format in a request for embedded content in an HTML document, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted EMBED element in a web page that is visited in Internet Explorer, aka "MHTML Mime-Formatted Request Vulnerability."
11568| [CVE-2011-1893] Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2010, Windows SharePoint Services 2.0 and 3.0 SP2, and SharePoint Foundation 2010 allows remote attackers to inject arbitrary web script or HTML via the URI, aka "SharePoint XSS Vulnerability."
11569| [CVE-2011-1892] Microsoft Office Groove 2007 SP2, SharePoint Workspace 2010 Gold and SP1, Office Forms Server 2007 SP2, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Office Groove Data Bridge Server 2007 SP2, Office Groove Management Server 2007 SP2, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, and Office Web Apps 2010 Gold and SP1 do not properly handle Web Parts containing XML classes referencing external entities, which allows remote authenticated users to read arbitrary files via a crafted XML and XSL file, aka "SharePoint Remote File Disclosure Vulnerability."
11570| [CVE-2011-1888] win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Null Pointer De-reference Vulnerability."
11571| [CVE-2011-1887] win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Null Pointer De-reference Vulnerability."
11572| [CVE-2011-1885] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Null Pointer De-reference Vulnerability."
11573| [CVE-2011-1884] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
11574| [CVE-2011-1883] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
11575| [CVE-2011-1882] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
11576| [CVE-2011-1881] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Null Pointer De-reference Vulnerability."
11577| [CVE-2011-1880] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Null Pointer De-reference Vulnerability."
11578| [CVE-2011-1879] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
11579| [CVE-2011-1878] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
11580| [CVE-2011-1877] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, aka "Win32k Use After Free Vulnerability."
11581| [CVE-2011-1876] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
11582| [CVE-2011-1875] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
11583| [CVE-2011-1874] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
11584| [CVE-2011-1873] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 on 64-bit platforms does not properly validate pointers during the parsing of OpenType (aka OTF) fonts, which allows remote attackers to execute arbitrary code via a crafted font file, aka "Win32k OTF Validation Vulnerability."
11585| [CVE-2011-1872] Hyper-V in Microsoft Windows Server 2008 Gold, SP2, R2, and R2 SP1 allows guest OS users to cause a denial of service (host OS infinite loop) via malformed machine instructions in a VMBus packet, aka "VMBus Persistent DoS Vulnerability."
11586| [CVE-2011-1871] Tcpip.sys in the TCP/IP stack in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (reboot) via a series of crafted ICMP messages, aka "ICMP Denial of Service Vulnerability."
11587| [CVE-2011-1870] Integer overflow in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP SrvWriteConsoleOutputString Vulnerability."
11588| [CVE-2011-1869] The Distributed File System (DFS) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote DFS servers to cause a denial of service (system hang) via a crafted referral response, aka "DFS Referral Response Vulnerability."
11589| [CVE-2011-1868] The Distributed File System (DFS) implementation in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate fields in DFS responses, which allows remote DFS servers to execute arbitrary code via a crafted response, aka "DFS Memory Corruption Vulnerability."
11590| [CVE-2011-1508] Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, does not properly manage memory allocations for function pointers, which allows user-assisted remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Function Pointer Overwrite Vulnerability."
11591| [CVE-2011-1284] Integer overflow in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP SrvWriteConsoleOutput Vulnerability."
11592| [CVE-2011-1283] The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2 does not ensure that an unspecified array index has a non-negative value before performing read and write operations, which allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP SrvSetConsoleNumberOfCommand Vulnerability."
11593| [CVE-2011-1282] The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly initialize memory and consequently uses a NULL pointer in an unspecified function call, which allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP SrvSetConsoleLocalEUDC Vulnerability."
11594| [CVE-2011-1281] The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly restrict the number of console objects for a process, which allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP AllocConsole Vulnerability."
11595| [CVE-2011-1280] The XML Editor in Microsoft InfoPath 2007 SP2 and 2010
11596| [CVE-2011-1279] Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel Out of Bounds WriteAV Vulnerability."
11597| [CVE-2011-1278] Microsoft Excel 2002 SP3 and Office 2004 for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel WriteAV Vulnerability."
11598| [CVE-2011-1277] Microsoft Excel 2002 SP3, Office 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel Memory Corruption Vulnerability."
11599| [CVE-2011-1276] Buffer overflow in Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2
11600| [CVE-2011-1275] Microsoft Excel 2002 SP3
11601| [CVE-2011-1274] Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2
11602| [CVE-2011-1273] Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010
11603| [CVE-2011-1272] Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2
11604| [CVE-2011-1270] Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "Presentation Buffer Overrun RCE Vulnerability."
11605| [CVE-2011-1269] Microsoft PowerPoint 2002 SP3, 2003 SP3, and 2007 SP2
11606| [CVE-2011-1268] The SMB client in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote SMB servers to execute arbitrary code via a crafted (1) SMBv1 or (2) SMBv2 response, aka "SMB Response Parsing Vulnerability."
11607| [CVE-2011-1267] The SMB server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (system hang) via a crafted (1) SMBv1 or (2) SMBv2 request, aka "SMB Request Parsing Vulnerability."
11608| [CVE-2011-1264] Cross-site scripting (XSS) vulnerability in Active Directory Certificate Services Web Enrollment in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, R2, and R2 SP1 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "Active Directory Certificate Services Vulnerability."
11609| [CVE-2011-1263] Cross-site scripting (XSS) vulnerability in the logon page in Remote Desktop Web Access (RD Web Access) in Microsoft Windows Server 2008 R2 and R2 SP1 allows remote attackers to inject arbitrary web script or HTML via the URI, aka "Remote Desktop Web Access Vulnerability."
11610| [CVE-2011-1253] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.0.60831, does not properly restrict inheritance, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4) a crafted Silverlight application, aka ".NET Framework Class Inheritance Vulnerability."
11611| [CVE-2011-1252] Cross-site scripting (XSS) vulnerability in the SafeHTML function in the toStaticHTML API in Microsoft Internet Explorer 7 and 8, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified strings, aka "toStaticHTML Information Disclosure Vulnerability" or "HTML Sanitization Vulnerability."
11612| [CVE-2011-1249] The Ancillary Function Driver (AFD) in afd.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."
11613| [CVE-2011-1248] WINS in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, R2, and R2 SP1 does not properly handle socket send exceptions, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted packets, related to unintended stack-frame values and buffer passing, aka "WINS Service Failed Response Vulnerability."
11614| [CVE-2011-1247] Untrusted search path vulnerability in the Microsoft Active Accessibility component in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "Active Accessibility Insecure Library Loading Vulnerability."
11615| [CVE-2011-1242] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
11616| [CVE-2011-1241] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
11617| [CVE-2011-1240] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
11618| [CVE-2011-1239] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
11619| [CVE-2011-1238] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
11620| [CVE-2011-1237] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
11621| [CVE-2011-1236] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
11622| [CVE-2011-1235] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
11623| [CVE-2011-1234] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
11624| [CVE-2011-1233] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
11625| [CVE-2011-1232] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
11626| [CVE-2011-1231] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
11627| [CVE-2011-1230] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
11628| [CVE-2011-1229] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
11629| [CVE-2011-1228] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
11630| [CVE-2011-1227] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
11631| [CVE-2011-1226] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
11632| [CVE-2011-1225] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
11633| [CVE-2011-0980] Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse Office Art objects, which allows remote attackers to execute arbitrary code via vectors related to a function pointer, aka "Excel Dangling Pointer Vulnerability."
11634| [CVE-2011-0979] Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010
11635| [CVE-2011-0978] Stack-based buffer overflow in Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2
11636| [CVE-2011-0977] Use-after-free vulnerability in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via malformed shape data in the Office drawing file format, aka "Microsoft Office Graphic Object Dereferencing Vulnerability."
11637| [CVE-2011-0976] Microsoft PowerPoint 2002 SP3, 2003 SP3, and 2007 SP2
11638| [CVE-2011-0677] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
11639| [CVE-2011-0676] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
11640| [CVE-2011-0675] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
11641| [CVE-2011-0674] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
11642| [CVE-2011-0672] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
11643| [CVE-2011-0671] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
11644| [CVE-2011-0670] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
11645| [CVE-2011-0667] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
11646| [CVE-2011-0666] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
11647| [CVE-2011-0665] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
11648| [CVE-2011-0664] Microsoft .NET Framework 2.0 SP1 and SP2, 3.5 Gold and SP1, 3.5.1, and 4.0, and Silverlight 4 before 4.0.60531.0, does not properly validate arguments to unspecified networking API functions, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4) a crafted Silverlight application, aka ".NET Framework Array Offset Vulnerability."
11649| [CVE-2011-0662] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
11650| [CVE-2011-0661] The SMB Server service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate fields in SMB requests, which allows remote attackers to execute arbitrary code via a malformed request in a (1) SMBv1 or (2) SMBv2 packet, aka "SMB Transaction Parsing Vulnerability."
11651| [CVE-2011-0660] The SMB client in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote SMB servers to execute arbitrary code via a crafted (1) SMBv1 or (2) SMBv2 response, aka "SMB Client Response Parsing Vulnerability."
11652| [CVE-2011-0658] Integer underflow in the OLE Automation protocol implementation in VBScript.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted WMF file, aka "OLE Automation Underflow Vulnerability."
11653| [CVE-2011-0657] DNSAPI.dll in the DNS client in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process DNS queries, which allows remote attackers to execute arbitrary code via (1) a crafted LLMNR broadcast query or (2) a crafted application, aka "DNS Query Vulnerability."
11654| [CVE-2011-0656] Microsoft PowerPoint 2002 SP3, 2003 SP3, 2007 SP2, and 2010
11655| [CVE-2011-0655] Microsoft PowerPoint 2007 SP2 and 2010
11656| [CVE-2011-0654] Integer underflow in the BowserWriteErrorLogEntry function in the Common Internet File System (CIFS) browser service in Mrxsmb.sys or bowser.sys in Active Directory in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via a malformed BROWSER ELECTION message, leading to a heap-based buffer overflow, aka "Browser Pool Corruption Vulnerability." NOTE: some of these details are obtained from third party information.
11657| [CVE-2011-0107] Untrusted search path vulnerability in Microsoft Office XP SP3, Office 2003 SP3, and Office 2007 SP2 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .docx file, aka "Office Component Insecure Library Loading Vulnerability."
11658| [CVE-2011-0105] Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac obtain a certain length value from an uninitialized memory location, which allows remote attackers to trigger a buffer overflow and execute arbitrary code via a crafted Excel file, aka "Excel Data Initialization Vulnerability."
11659| [CVE-2011-0104] Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HLink record in an Excel file, aka "Excel Buffer Overwrite Vulnerability."
11660| [CVE-2011-0103] Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted record information in an Excel file, aka "Excel Memory Corruption Vulnerability."
11661| [CVE-2011-0101] Microsoft Excel 2002 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted RealTimeData record, related to a stTopic field, doubly-byte characters, and an incorrect pointer calculation, aka "Excel Record Parsing WriteAV Vulnerability."
11662| [CVE-2011-0098] Integer signedness error in Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010
11663| [CVE-2011-0097] Integer underflow in Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010
11664| [CVE-2011-0096] The MHTML protocol handler in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle a MIME format in a request for content blocks in a document, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site that is visited in Internet Explorer, aka "MHTML Mime-Formatted Request Vulnerability."
11665| [CVE-2011-0093] ELEMENTS.DLL in Microsoft Visio 2002 SP2, 2003 SP3, and 2007 SP2 does not properly parse structures during the opening of a Visio file, which allows remote attackers to execute arbitrary code via a file containing a malformed structure, aka "Visio Data Type Memory Corruption Vulnerability."
11666| [CVE-2011-0092] The LZW stream decompression functionality in ORMELEMS.DLL in Microsoft Visio 2002 SP2, 2003 SP3, and 2007 SP2 allows remote attackers to execute arbitrary code via a Visio file with a malformed VisioDocument stream that triggers an exception handler that accesses an object that has not been fully initialized, which triggers memory corruption, aka "Visio Object Memory Corruption Vulnerability."
11667| [CVE-2011-0091] Kerberos in Microsoft Windows Server 2008 R2 and Windows 7 does not prevent a session from changing from strong encryption to DES encryption, which allows man-in-the-middle attackers to spoof network traffic and obtain sensitive information via a DES downgrade, aka "Kerberos Spoofing Vulnerability."
11668| [CVE-2011-0090] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Vulnerability."
11669| [CVE-2011-0089] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Window Class Improper Pointer Validation Vulnerability."
11670| [CVE-2011-0088] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Window Class Pointer Confusion Vulnerability."
11671| [CVE-2011-0087] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Insufficient User Input Validation Vulnerability."
11672| [CVE-2011-0086] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Improper User Input Validation Vulnerability."
11673| [CVE-2011-0043] Kerberos in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 supports weak hashing algorithms, which allows local users to gain privileges by operating a service that sends crafted service tickets, as demonstrated by the CRC32 algorithm, aka "Kerberos Unkeyed Checksum Vulnerability."
11674| [CVE-2011-0042] SBE.dll in the Stream Buffer Engine in Windows Media Player and Windows Media Center in Microsoft Windows XP SP2 and SP3, Windows XP Media Center Edition 2005 SP3, Windows Vista SP1 and SP2, Windows 7 Gold and SP1, and Windows Media Center TV Pack for Windows Vista does not properly parse Digital Video Recording (.dvr-ms) files, which allows remote attackers to execute arbitrary code via a crafted file, aka "DVR-MS Vulnerability."
11675| [CVE-2011-0041] Integer overflow in gdiplus.dll in GDI+ in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold and SP2, and Office XP SP3 allows remote attackers to execute arbitrary code via a crafted EMF image, aka "GDI+ Integer Overflow Vulnerability."
11676| [CVE-2011-0040] The server in Microsoft Active Directory on Windows Server 2003 SP2 does not properly handle an update request for a service principal name (SPN), which allows remote attackers to cause a denial of service (authentication downgrade or outage) via a crafted request that triggers name collisions, aka "Active Directory SPN Validation Vulnerability."
11677| [CVE-2011-0039] The Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly process authentication requests, which allows local users to gain privileges via a request with a crafted length, aka "LSASS Length Validation Vulnerability."
11678| [CVE-2011-0034] Stack-based buffer overflow in the OpenType Compact Font Format (aka OTF or CFF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via crafted parameter values in an OpenType font, aka "OpenType Font Stack Overflow Vulnerability."
11679| [CVE-2011-0033] The OpenType Compact Font Format (CFF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate parameter values in OpenType fonts, which allows remote attackers to execute arbitrary code via a crafted font, aka "OpenType Font Encoded Character Vulnerability."
11680| [CVE-2011-0032] Untrusted search path vulnerability in DirectShow in Microsoft Windows Vista SP1 and SP2, Windows 7 Gold and SP1, Windows Server 2008 R2 and R2 SP1, and Windows Media Center TV Pack for Windows Vista allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a Digital Video Recording (.dvr-ms), Windows Recorded TV Show (.wtv), or .mpg file, aka "DirectShow Insecure Library Loading Vulnerability."
11681| [CVE-2011-0031] The (1) JScript 5.8 and (2) VBScript 5.8 scripting engines in Microsoft Windows Server 2008 R2 and Windows 7 do not properly load decoded scripts obtained from web pages, which allows remote attackers to trigger memory corruption and consequently obtain sensitive information via a crafted web site, aka "Scripting Engines Information Disclosure Vulnerability."
11682| [CVE-2011-0030] The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly kill processes after a logout, which allows local users to obtain sensitive information or gain privileges via a crafted application that continues to execute throughout the logout of one user and the login session of the next user, aka "CSRSS Elevation of Privilege Vulnerability," a different vulnerability than CVE-2010-0023.
11683| [CVE-2011-0028] WordPad in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly parse fields in Word documents, which allows remote attackers to execute arbitrary code via a crafted .doc file, aka "WordPad Converter Parsing Vulnerability."
11684| [CVE-2010-5082] Untrusted search path vulnerability in colorcpl.exe 6.0.6000.16386 in the Color Control Panel in Microsoft Windows Server 2008 SP2, R2, and R2 SP1 allows local users to gain privileges via a Trojan horse sti.dll file in the current working directory, as demonstrated by a directory that contains a .camp, .cdmp, .gmmp, .icc, or .icm file, aka "Color Control Panel Insecure Library Loading Vulnerability."
11685| [CVE-2010-4701] Heap-based buffer overflow in the CDrawPoly::Serialize function in fxscover.exe in Microsoft Windows Fax Services Cover Page Editor 5.2 r2 in Windows XP Professional SP3, Server 2003 R2 Enterprise Edition SP2, and Windows 7 Professional allows remote attackers to execute arbitrary code via a long record in a Fax Cover Page (.cov) file. NOTE: some of these details are obtained from third party information.
11686| [CVE-2010-4669] The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Microsoft Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, and Windows 7 allows remote attackers to cause a denial of service (CPU consumption and system hang) by sending many Router Advertisement (RA) messages with different source addresses, as demonstrated by the flood_router6 program in the thc-ipv6 package.
11687| [CVE-2010-4562] Microsoft Windows 2008, 7, Vista, 2003, 2000, and XP, when using IPv6, allows remote attackers to determine whether a host is sniffing the network by sending an ICMPv6 Echo Request to a multicast address and determining whether an Echo Reply is sent, as demonstrated by thcping. NOTE: due to a typo, some sources map CVE-2010-4562 to a ProFTPd mod_sql vulnerability, but that issue is covered by CVE-2010-4652.
11688| [CVE-2010-4398] Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges, and bypass the User Account Control (UAC) feature, via a crafted REG_BINARY value for a SystemDefaultEUDCFont registry key, aka "Driver Improper Interaction with Windows Kernel Vulnerability."
11689| [CVE-2010-4182] Untrusted search path vulnerability in the Data Access Objects (DAO) library (dao360.dll) in Microsoft Windows XP Professional SP3, Windows Server 2003 R2 Enterprise Edition SP3, Windows Vista Business SP1, and Windows 7 Professional allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse msjet49.dll that is located in the same folder as a file that is processed by dao360.dll. NOTE: the provenance of this information is unknown
11690| [CVE-2010-3974] fxscover.exe in the Fax Cover Page Editor in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly parse FAX cover pages, which allows remote attackers to execute arbitrary code via a crafted .cov file, aka "Fax Cover Page Editor Memory Corruption Vulnerability."
11691| [CVE-2010-3970] Stack-based buffer overflow in the CreateSizedDIBSECTION function in shimgvw.dll in the Windows Shell graphics processor (aka graphics rendering engine) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted .MIC or unspecified Office document containing a thumbnail bitmap with a negative biClrUsed value, as reported by Moti and Xu Hao, aka "Windows Shell Graphics Processing Overrun Vulnerability."
11692| [CVE-2010-3966] Untrusted search path vulnerability in Microsoft Windows Server 2008 R2 and Windows 7, when BranchCache is supported, allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains an EML file, an RSS file, or a WPOST file, aka "BranchCache Insecure Library Loading Vulnerability."
11693| [CVE-2010-3965] Untrusted search path vulnerability in Windows Media Encoder 9 on Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a Windows Media Profile (PRX) file, aka "Insecure Library Loading Vulnerability."
11694| [CVE-2010-3964] Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Office SharePoint Server 2007 SP2, when the Document Conversions Load Balancer Service is enabled, allows remote attackers to execute arbitrary code via a crafted SOAP request to TCP port 8082, aka "Malformed Request Code Execution Vulnerability."
11695| [CVE-2010-3963] Buffer overflow in the Routing and Remote Access NDProxy component in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, related to the Routing and Remote Access service (RRAS) and improper copying from user mode to the kernel, aka "Kernel NDProxy Buffer Overflow Vulnerability."
11696| [CVE-2010-3961] The Consent User Interface (UI) in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly handle an unspecified registry-key value, which allows local users with SeImpersonatePrivilege rights to gain privileges via a crafted application, aka "Consent UI Impersonation Vulnerability."
11697| [CVE-2010-3960] Hyper-V in Microsoft Windows Server 2008 Gold, SP2, and R2 allows guest OS users to cause a denial of service (host OS hang) by sending a crafted encapsulated packet over the VMBus, aka "Hyper-V VMBus Vulnerability."
11698| [CVE-2010-3959] The OpenType Font (OTF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a crafted CMAP table in an OpenType font, aka "OpenType CMAP Table Vulnerability."
11699| [CVE-2010-3958] The x86 JIT compiler in Microsoft .NET Framework 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 does not properly compile function calls, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka ".NET Framework Stack Corruption Vulnerability."
11700| [CVE-2010-3957] Double free vulnerability in the OpenType Font (OTF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a crafted OpenType font, aka "OpenType Font Double Free Vulnerability."
11701| [CVE-2010-3956] The OpenType Font (OTF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly perform array indexing, which allows local users to gain privileges via a crafted OpenType font, aka "OpenType Font Index Vulnerability."
11702| [CVE-2010-3955] pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3 does not properly perform array indexing, which allows remote attackers to execute arbitrary code via a crafted Publisher file that uses an old file format, aka "Array Indexing Memory Corruption Vulnerability."
11703| [CVE-2010-3954] Microsoft Publisher 2002 SP3, 2003 SP3, and 2010 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Publisher file, aka "Microsoft Publisher Memory Corruption Vulnerability."
11704| [CVE-2010-3946] Integer overflow in the PICT image converter in the graphics filters in Microsoft Office XP SP3, Office 2003 SP3, and Office Converter Pack allows remote attackers to execute arbitrary code via a crafted PICT image in an Office document, aka "PICT Image Converter Integer Overflow Vulnerability."
11705| [CVE-2010-3945] Buffer overflow in the CGM image converter in the graphics filters in Microsoft Office XP SP3, Office 2003 SP3, and Office Converter Pack allows remote attackers to execute arbitrary code via a crafted CGM image in an Office document, aka "CGM Image Converter Buffer Overrun Vulnerability."
11706| [CVE-2010-3944] win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Vulnerability."
11707| [CVE-2010-3943] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly link driver objects, which allows local users to gain privileges via a crafted application that triggers linked-list corruption, aka "Win32k Cursor Linking Vulnerability."
11708| [CVE-2010-3942] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly allocate memory for copies from user mode, which allows local users to gain privileges via a crafted application, aka "Win32k WriteAV Vulnerability."
11709| [CVE-2010-3941] Double free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold and SP2, and Windows 7 allows local users to gain privileges via a crafted application, aka "Win32k Double Free Vulnerability."
11710| [CVE-2010-3940] Double free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a crafted application, aka "Win32k PFE Pointer Double Free Vulnerability."
11711| [CVE-2010-3939] Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via vectors related to improper memory allocation for copies from user mode, aka "Win32k Buffer Overflow Vulnerability."
11712| [CVE-2010-3937] Microsoft Exchange Server 2007 SP2 on the x64 platform allows remote authenticated users to cause a denial of service (infinite loop and MSExchangeIS outage) via a crafted RPC request, aka "Exchange Server Infinite Loop Vulnerability."
11713| [CVE-2010-3338] The Windows Task Scheduler in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly determine the security context of scheduled tasks, which allows local users to gain privileges via a crafted application, aka "Task Scheduler Vulnerability." NOTE: this might overlap CVE-2010-3888.
11714| [CVE-2010-3337] Untrusted search path vulnerability in Microsoft Office 2007 SP2 and 2010 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "Insecure Library Loading Vulnerability." NOTE: this might overlap CVE-2010-3141 and CVE-2010-3142.
11715| [CVE-2010-3336] Microsoft Office XP SP3, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "MSO Large SPID Read AV Vulnerability."
11716| [CVE-2010-3335] Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "Drawing Exception Handling Vulnerability."
11717| [CVE-2010-3334] Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via an Office document containing an Office Art Drawing record with crafted msofbtSp records and unspecified flags, which triggers memory corruption, aka "Office Art Drawing Records Vulnerability."
11718| [CVE-2010-3333] Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via crafted RTF data, aka "RTF Stack Buffer Overflow Vulnerability."
11719| [CVE-2010-3332] Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Services (IIS), provides detailed error codes during decryption attempts, which allows remote attackers to decrypt and modify encrypted View State (aka __VIEWSTATE) form data, and possibly forge cookies or read application files, via a padding oracle attack, aka "ASP.NET Padding Oracle Vulnerability."
11720| [CVE-2010-3324] The toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, Office SharePoint Server 2007 SP2, Groove Server 2010, and Office Web Apps, allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism and conduct XSS attacks via a crafted use of the Cascading Style Sheets (CSS) @import rule, aka "HTML Sanitization Vulnerability," a different vulnerability than CVE-2010-1257.
11721| [CVE-2010-3243] Cross-site scripting (XSS) vulnerability in the toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2 and Office SharePoint Server 2007 SP2, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "HTML Sanitization Vulnerability."
11722| [CVE-2010-3242] Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Ghost Record Type Parsing Vulnerability."
11723| [CVE-2010-3241] Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate binary file-format information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Out-of-Bounds Memory Write in Parsing Vulnerability."
11724| [CVE-2010-3240] Microsoft Excel 2002 SP3 and 2007 SP2
11725| [CVE-2010-3239] Microsoft Excel 2002 SP3 does not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Extra Out of Boundary Record Parsing Vulnerability."
11726| [CVE-2010-3238] Microsoft Excel 2002 SP3 and 2003 SP3, and Office 2004 for Mac, does not properly validate binary file-format information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Negative Future Function Vulnerability."
11727| [CVE-2010-3237] Microsoft Excel 2002 SP3 and Office 2004 for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Merge Cell Record Pointer Vulnerability."
11728| [CVE-2010-3236] Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Out Of Bounds Array Vulnerability."
11729| [CVE-2010-3235] Microsoft Excel 2002 SP3 does not properly validate formula information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Formula Biff Record Vulnerability."
11730| [CVE-2010-3234] Microsoft Excel 2002 SP3 does not properly validate formula information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Formula Substream Memory Corruption Vulnerability."
11731| [CVE-2010-3233] Microsoft Excel 2002 SP3 and 2003 SP3 does not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted .wk3 (aka Lotus 1-2-3 workbook) file, aka "Lotus 1-2-3 Workbook Parsing Vulnerability."
11732| [CVE-2010-3232] Microsoft Excel 2003 SP3 and 2007 SP2
11733| [CVE-2010-3231] Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Excel Record Parsing Memory Corruption Vulnerability."
11734| [CVE-2010-3230] Integer overflow in Microsoft Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel document with crafted record information, aka "Excel Record Parsing Integer Overflow Vulnerability."
11735| [CVE-2010-3229] The Secure Channel (aka SChannel) security package in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when IIS 7.x is used, does not properly process client certificates during SSL and TLS handshakes, which allows remote attackers to cause a denial of service (LSASS outage and reboot) via a crafted packet, aka "TLSv1 Denial of Service Vulnerability."
11736| [CVE-2010-3227] Stack-based buffer overflow in the UpdateFrameTitleForDocument method in the CFrameWnd class in mfc42.dll in the Microsoft Foundation Class (MFC) Library in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows context-dependent attackers to execute arbitrary code via a long window title that this library attempts to create at the request of an application, as demonstrated by the Trident PowerZip 7.2 Build 4010 application, aka "Windows MFC Document Title Updating Buffer Overflow Vulnerability."
11737| [CVE-2010-3223] The user interface in Microsoft Cluster Service (MSCS) in Microsoft Windows Server 2008 R2 does not properly set administrative-share permissions for new cluster disks that are shared as part of a failover cluster, which allows remote attackers to read or modify data on these disks via requests to the associated share, aka "Permissions on New Cluster Disks Vulnerability."
11738| [CVE-2010-3222] Stack-based buffer overflow in the Remote Procedure Call Subsystem (RPCSS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted LPC message that requests an LRPC connection from an LPC server to a client, aka "LPC Message Buffer Overrun Vulnerability."
11739| [CVE-2010-3221] Microsoft Word 2002 SP3 and 2003 SP3, Office 2004 for Mac, and Word Viewer do not properly handle a malformed record during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Parsing Vulnerability."
11740| [CVE-2010-3220] Unspecified vulnerability in Microsoft Word 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Word document that triggers memory corruption, aka "Word Parsing Vulnerability."
11741| [CVE-2010-3219] Array index vulnerability in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via a crafted Word document that triggers memory corruption, aka "Word Index Parsing Vulnerability."
11742| [CVE-2010-3218] Heap-based buffer overflow in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via malformed records in a Word document, aka "Word Heap Overflow Vulnerability."
11743| [CVE-2010-3217] Double free vulnerability in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via a Word document with crafted List Format Override (LFO) records, aka "Word Pointer Vulnerability."
11744| [CVE-2010-3216] Microsoft Word 2002 SP3 and Office 2004 for Mac allow remote attackers to execute arbitrary code via a crafted Word document containing bookmarks that trigger use of an invalid pointer and memory corruption, aka "Word Bookmarks Vulnerability."
11745| [CVE-2010-3215] Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly handle unspecified return values during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Return Value Vulnerability."
11746| [CVE-2010-3214] Stack-based buffer overflow in Microsoft Word 2002 SP3, 2003 SP3, 2007 SP2, and 2010
11747| [CVE-2010-3213] Cross-site request forgery (CSRF) vulnerability in Microsoft Outlook Web Access (owa/ev.owa) 2007 through SP2 allows remote attackers to hijack the authentication of e-mail users for requests that perform Outlook requests, as demonstrated by setting the auto-forward rule.
11748| [CVE-2010-3200] MSO.dll in Microsoft Word 2003 SP3 11.8326.11.8324 allows remote attackers to cause a denial of service (NULL pointer dereference and multiple-instance application crash) via a crafted buffer in a Word document, as demonstrated by word_crash_11.8326.8324_poc.doc.
11749| [CVE-2010-3190] Untrusted search path vulnerability in the Microsoft Foundation Class (MFC) Library in Microsoft Visual Studio .NET 2003 SP1
11750| [CVE-2010-3148] Untrusted search path vulnerability in Microsoft Visio 2003 SP3 allows local users to gain privileges via a Trojan horse mfc71enu.dll file in the current working directory, as demonstrated by a directory that contains a .vsd, .vdx, .vst, or .vtx file, aka "Microsoft Visio Insecure Library Loading Vulnerability."
11751| [CVE-2010-3147] Untrusted search path vulnerability in wab.exe 6.00.2900.5512 in Windows Address Book in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a Trojan horse wab32res.dll file in the current working directory, as demonstrated by a directory that contains a Windows Address Book (WAB), VCF (aka vCard), or P7C file, aka "Insecure Library Loading Vulnerability." NOTE: the codebase for this product may overlap the codebase for the product referenced in CVE-2010-3143.
11752| [CVE-2010-3146] Multiple untrusted search path vulnerabilities in Microsoft Groove 2007 SP2 allow local users to gain privileges via a Trojan horse (1) mso.dll or (2) GroovePerfmon.dll file in the current working directory, as demonstrated by a directory that contains a Groove vCard (.vcg) or Groove Tool Archive (.gta) file, aka "Microsoft Groove Insecure Library Loading Vulnerability."
11753| [CVE-2010-3144] Untrusted search path vulnerability in the Internet Connection Signup Wizard in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a Trojan horse smmscrpt.dll file in the current working directory, as demonstrated by a directory that contains an ISP or INS file, aka "Internet Connection Signup Wizard Insecure Library Loading Vulnerability."
11754| [CVE-2010-3142] Untrusted search path vulnerability in Microsoft Office PowerPoint 2007 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse rpawinet.dll that is located in the same folder as a .odp, .pothtml, .potm, .potx, .ppa, .ppam, .pps, .ppt, .ppthtml, .pptm, .pptxml, .pwz, .sldm, .sldx, and .thmx file.
11755| [CVE-2010-2750] Array index error in Microsoft Word 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Word document that triggers memory corruption, aka "Word Index Vulnerability."
11756| [CVE-2010-2748] Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly check an unspecified boundary during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Boundary Check Vulnerability."
11757| [CVE-2010-2747] Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly handle an uninitialized pointer during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Uninitialized Pointer Vulnerability."
11758| [CVE-2010-2746] Heap-based buffer overflow in Comctl32.dll (aka the common control library) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when a third-party SVG viewer is used, allows remote attackers to execute arbitrary code via a crafted HTML document that triggers unspecified messages from this viewer, aka "Comctl32 Heap Overflow Vulnerability."
11759| [CVE-2010-2744] The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly manage a window class, which allows local users to gain privileges by creating a window, then using (1) the SetWindowLongPtr function to modify the popup menu structure, or (2) the SwitchWndProc function with a switch window information pointer, which is not re-initialized when a WM_NCCREATE message is processed, aka "Win32k Window Class Vulnerability."
11760| [CVE-2010-2742] The Netlogon RPC Service in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, and R2, when the domain controller role is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via a crafted RPC packet, aka "Netlogon RPC Null dereference DOS Vulnerability."
11761| [CVE-2010-2741] The OpenType Font (OTF) format driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 performs an incorrect integer calculation during font processing, which allows local users to gain privileges via a crafted application, aka "OpenType Font Validation Vulnerability."
11762| [CVE-2010-2740] The OpenType Font (OTF) format driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly perform memory allocation during font parsing, which allows local users to gain privileges via a crafted application, aka "OpenType Font Parsing Vulnerability."
11763| [CVE-2010-2739] Buffer overflow in the CreateDIBPalette function in win32k.sys in Microsoft Windows XP SP3, Server 2003 R2 Enterprise SP2, Vista Business SP1, Windows 7, and Server 2008 SP2 allows local users to cause a denial of service (crash) and possibly execute arbitrary code by performing a clipboard operation (GetClipboardData API function) with a crafted bitmap with a palette that contains a large number of colors.
11764| [CVE-2010-2738] The Uniscribe (aka new Unicode Script Processor) implementation in USP10.DLL in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2, and Microsoft Office XP SP3, 2003 SP3, and 2007 SP2, does not properly validate tables associated with malformed OpenType fonts, which allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) Office document, aka "Uniscribe Font Parsing Engine Memory Corruption Vulnerability."
11765| [CVE-2010-2729] The Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when printer sharing is enabled, does not properly validate spooler access permissions, which allows remote attackers to create files in a system directory, and consequently execute arbitrary code, by sending a crafted print request over RPC, as exploited in the wild in September 2010, aka "Print Spooler Service Impersonation Vulnerability."
11766| [CVE-2010-2728] Heap-based buffer overflow in Microsoft Outlook 2002 SP3, 2003 SP3, and 2007 SP2, when Online Mode for an Exchange Server is enabled, allows remote attackers to execute arbitrary code via a crafted e-mail message, aka "Heap Based Buffer Overflow in Outlook Vulnerability."
11767| [CVE-2010-2573] Integer underflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3, PowerPoint Viewer SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint Integer Underflow Causes Heap Corruption Vulnerability."
11768| [CVE-2010-2572] Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95 document, aka "PowerPoint Parsing Buffer Overflow Vulnerability."
11769| [CVE-2010-2571] Array index error in pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher 97 file, aka "Memory Corruption Due To Invalid Index Into Array in Pubconv.dll Vulnerability."
11770| [CVE-2010-2570] Heap-based buffer overflow in pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3, 2003 SP3, 2007 SP2, and 2010 allows remote attackers to execute arbitrary code via a crafted Publisher file that uses an old file format, aka "Heap Overrun in pubconv.dll Vulnerability."
11771| [CVE-2010-2569] pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3, 2003 SP3, and 2007 SP2 does not properly handle an unspecified size field in certain older file formats, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted Publisher file, aka "Size Value Heap Corruption in pubconv.dll Vulnerability."
11772| [CVE-2010-2568] Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code via a crafted (1) .LNK or (2) .PIF shortcut file, which is not properly handled during icon display in Windows Explorer, as demonstrated in the wild in July 2010, and originally reported for malware that leverages CVE-2010-2772 in Siemens WinCC SCADA systems.
11773| [CVE-2010-2567] The RPC client implementation in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly allocate memory during the parsing of responses, which allows remote RPC servers and man-in-the-middle attackers to execute arbitrary code via a malformed response, aka "RPC Memory Corruption Vulnerability."
11774| [CVE-2010-2566] The Secure Channel (aka SChannel) security package in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, does not properly validate certificate request messages from TLS and SSL servers, which allows remote servers to execute arbitrary code via a crafted SSL response, aka "SChannel Malformed Certificate Request Remote Code Execution Vulnerability."
11775| [CVE-2010-2563] The Word 97 text converter in the WordPad Text Converters in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly parse malformed structures in Word 97 documents, which allows remote attackers to execute arbitrary code via a crafted document containing an unspecified value that is used in a loop counter, aka "WordPad Word 97 Text Converter Memory Corruption Vulnerability."
11776| [CVE-2010-2562] Microsoft Office Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Excel file, aka "Excel Memory Corruption Vulnerability."
11777| [CVE-2010-2555] The Tracing Feature for Services in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly determine the length of strings in the registry, which allows local users to gain privileges or cause a denial of service (memory corruption) via vectors involving a long string, aka "Tracing Memory Corruption Vulnerability."
11778| [CVE-2010-2554] The Tracing Feature for Services in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 has incorrect ACLs on its registry keys, which allows local users to gain privileges via vectors involving a named pipe and impersonation, aka "Tracing Registry Key ACL Vulnerability."
11779| [CVE-2010-2552] Stack consumption vulnerability in the SMB Server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to cause a denial of service (system hang) via a malformed SMBv2 compounded request, aka "SMB Stack Exhaustion Vulnerability."
11780| [CVE-2010-2551] The SMB Server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate an internal variable in an SMB packet, which allows remote attackers to cause a denial of service (system hang) via a crafted (1) SMBv1 or (2) SMBv2 packet, aka "SMB Variable Validation Vulnerability."
11781| [CVE-2010-2550] The SMB Server in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate fields in an SMB request, which allows remote attackers to execute arbitrary code via a crafted SMB packet, aka "SMB Pool Overflow Vulnerability."
11782| [CVE-2010-2549] Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2 and Server 2008 Gold and SP2 allows local users to gain privileges or cause a denial of service (system crash) by using a large number of calls to the NtUserCheckAccessForIntegrityLevel function to trigger a failure in the LockProcessByClientId function, leading to deletion of an in-use process object, aka "Win32k Reference Count Vulnerability."
11783| [CVE-2010-2265] Cross-site scripting (XSS) vulnerability in the GetServerName function in sysinfo/commonFunc.js in Microsoft Windows Help and Support Center for Windows XP and Windows Server 2003 allows remote attackers to inject arbitrary web script or HTML via the svr parameter to sysinfo/sysinfomain.htm. NOTE: this can be leveraged with CVE-2010-1885 to execute arbitrary commands without user interaction.
11784| [CVE-2010-2091] Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7 on Windows Server 2003 is used, does not properly handle the id parameter in a Folder IPF.Note action to the default URI, which might allow remote attackers to obtain sensitive information or conduct cross-site scripting (XSS) attacks via an invalid value.
11785| [CVE-2010-2084] Microsoft ASP.NET 2.0 does not prevent setting the InnerHtml property on a control that inherits from HtmlContainerControl, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to an attribute.
11786| [CVE-2010-1903] Microsoft Office Word 2002 SP3 and 2003 SP3, and Office Word Viewer, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed record in a Word file, aka "Word HTML Linked Objects Memory Corruption Vulnerability."
11787| [CVE-2010-1902] Buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2
11788| [CVE-2010-1901] Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2
11789| [CVE-2010-1900] Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2
11790| [CVE-2010-1898] The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP1, 2.0 SP2, 3.5, 3.5 SP1, and 3.5.1, and Microsoft Silverlight 2 and 3 before 3.0.50611.0 on Windows and before 3.0.41130.0 on Mac OS X, does not properly handle interfaces and delegations to virtual methods, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft Silverlight and Microsoft .NET Framework CLR Virtual Method Delegate Vulnerability."
11791| [CVE-2010-1897] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly validate pseudo-handle values in callback parameters during window creation, which allows local users to gain privileges via a crafted application, aka "Win32k Window Creation Vulnerability."
11792| [CVE-2010-1896] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2 do not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Win32k User Input Validation Vulnerability."
11793| [CVE-2010-1895] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, do not properly perform memory allocation before copying user-mode data to kernel mode, which allows local users to gain privileges via a crafted application, aka "Win32k Pool Overflow Vulnerability."
11794| [CVE-2010-1894] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, do not properly handle unspecified exceptions, which allows local users to gain privileges via a crafted application, aka "Win32k Exception Handling Vulnerability."
11795| [CVE-2010-1893] Integer overflow in the TCP/IP stack in Microsoft Windows Vista SP1, Windows Server 2008 Gold and R2, and Windows 7 allows local users to gain privileges via a buffer of user-mode data that is copied to kernel mode, aka "Integer Overflow in Windows Networking Vulnerability."
11796| [CVE-2010-1892] The TCP/IP stack in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly handle malformed IPv6 packets, which allows remote attackers to cause a denial of service (system hang) via multiple crafted packets, aka "IPv6 Memory Corruption Vulnerability."
11797| [CVE-2010-1891] The Client/Server Runtime Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2, when a Chinese, Japanese, or Korean locale is enabled, does not properly allocate memory for transactions, which allows local users to gain privileges via a crafted application, aka "CSRSS Local Elevation of Privilege Vulnerability."
11798| [CVE-2010-1890] The kernel in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate ACLs on kernel objects, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Improper Validation Vulnerability."
11799| [CVE-2010-1889] Double free vulnerability in the kernel in Microsoft Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2, allows local users to gain privileges via a crafted application, related to object initialization during error handling, aka "Windows Kernel Double Free Vulnerability."
11800| [CVE-2010-1887] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly validate an unspecified system-call argument, which allows local users to cause a denial of service (system hang) via a crafted application, aka "Win32k Bounds Checking Vulnerability."
11801| [CVE-2010-1886] Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2, and Windows 7 allow local users to gain privileges by leveraging access to a process with NetworkService credentials, as demonstrated by TAPI Server, SQL Server, and IIS processes, and related to the Windows Service Isolation feature. NOTE: the vendor states that privilege escalation from NetworkService to LocalSystem does not cross a "security boundary."
11802| [CVE-2010-1885] The MPC::HexToNum function in helpctr.exe in Microsoft Windows Help and Support Center in Windows XP and Windows Server 2003 does not properly handle malformed escape sequences, which allows remote attackers to bypass the trusted documents whitelist (fromHCP option) and execute arbitrary commands via a crafted hcp:// URL, aka "Help Center URL Validation Vulnerability."
11803| [CVE-2010-1883] Integer overflow in the Embedded OpenType (EOT) Font Engine in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to execute arbitrary code via a crafted table in an embedded font, aka "Embedded OpenType Font Integer Overflow Vulnerability."
11804| [CVE-2010-1882] Multiple buffer overflows in the MPEG Layer-3 Audio Codec for Microsoft DirectShow in l3codecx.ax in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allow remote attackers to execute arbitrary code via an MPEG Layer-3 audio stream in (1) a crafted media file or (2) crafted streaming content, aka "MPEG Layer-3 Audio Decoder Buffer Overflow Vulnerability."
11805| [CVE-2010-1881] The FieldList ActiveX control in the Microsoft Access Wizard Controls in ACCWIZ.dll in Microsoft Office Access 2003 SP3 does not properly interact with the memory-access approach used by Internet Explorer and Office during instantiation, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via an HTML document that references this control along with crafted persistent storage data, aka "ACCWIZ.dll Uninitialized Variable Vulnerability."
11806| [CVE-2010-1880] Unspecified vulnerability in Quartz.dll for DirectShow on Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1, and Server 2008 allows remote attackers to execute arbitrary code via a media file with crafted compression data, aka "MJPEG Media Decompression Vulnerability."
11807| [CVE-2010-1735] The SfnLOGONNOTIFY function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service (system crash) via a 0x4c value in the second argument (aka the Msg argument) of a PostMessage function call for the DDEMLEvent window.
11808| [CVE-2010-1734] The SfnINSTRING function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service (system crash) via a 0x18d value in the second argument (aka the Msg argument) of a PostMessage function call for the DDEMLEvent window.
11809| [CVE-2010-1690] The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 does not verify that transaction IDs of responses match transaction IDs of queries, which makes it easier for man-in-the-middle attackers to spoof DNS responses, a different vulnerability than CVE-2010-0024 and CVE-2010-0025.
11810| [CVE-2010-1689] The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 uses predictable transaction IDs that are formed by incrementing a previous ID by 1, which makes it easier for man-in-the-middle attackers to spoof DNS responses, a different vulnerability than CVE-2010-0024 and CVE-2010-0025.
11811| [CVE-2010-1263] Windows Shell and WordPad in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7
11812| [CVE-2010-1257] Cross-site scripting (XSS) vulnerability in the toStaticHTML API, as used in Microsoft Office InfoPath 2003 SP3, 2007 SP1, and 2007 SP2
11813| [CVE-2010-1255] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 Gold and SP2, Windows 7, and Server 2008 R2 allows local users to execute arbitrary code via vectors related to "glyph outline information" and TrueType fonts, aka "Win32k TrueType Font Parsing Vulnerability."
11814| [CVE-2010-1253] Microsoft Office Excel 2002 SP3, 2007 SP1, and SP2
11815| [CVE-2010-1252] Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Excel file, aka "Excel String Variable Vulnerability."
11816| [CVE-2010-1251] Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Excel file, aka "Excel Record Stack Corruption Vulnerability."
11817| [CVE-2010-1250] Heap-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with malformed (1) EDG (0x88) and (2) Publisher (0x89) records, aka "Excel EDG Memory Corruption Vulnerability."
11818| [CVE-2010-1249] Buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed ExternName (0x23) record, aka "Excel Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0823 and CVE-2010-1247.
11819| [CVE-2010-1248] Buffer overflow in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed HFPicture (0x866) record, aka "Excel HFPicture Memory Corruption Vulnerability."
11820| [CVE-2010-1247] Unspecified vulnerability in Microsoft Office Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel file with a malformed RTD (0x813) record that triggers heap corruption, aka "Excel Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0823 and CVE-2010-1249.
11821| [CVE-2010-1246] Stack-based buffer overflow in Microsoft Office Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel file with a malformed RTD (0x813) record, aka "Excel RTD Memory Corruption Vulnerability."
11822| [CVE-2010-1245] Unspecified vulnerability in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed SxView (0xB0) record, aka "Excel Record Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0824 and CVE-2010-0821.
11823| [CVE-2010-1225] The memory-management implementation in the Virtual Machine Monitor (aka VMM or hypervisor) in Microsoft Virtual PC 2007 Gold and SP1, Virtual Server 2005 Gold and R2 SP1, and Windows Virtual PC does not properly restrict access from the guest OS to memory locations in the VMM work area, which allows context-dependent attackers to bypass certain anti-exploitation protection mechanisms on the guest OS via crafted input to a vulnerable application. NOTE: the vendor reportedly found that only systems with an otherwise vulnerable application are affected, because "the memory areas accessible from the guest cannot be leveraged to achieve either remote code execution or elevation of privilege and ... no data from the host is exposed to the guest OS."
11824| [CVE-2010-1175] Microsoft Internet Explorer 7.0 on Windows XP and Windows Server 2003 allows remote attackers to have an unspecified impact via a certain XML document that references a crafted web site in the SRC attribute of an image element, related to a "0day Vulnerability."
11825| [CVE-2010-0917] Stack-based buffer overflow in VBScript in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, might allow user-assisted remote attackers to execute arbitrary code via a long string in the fourth argument (aka helpfile argument) to the MsgBox function, leading to code execution when the F1 key is pressed, a different vulnerability than CVE-2010-0483.
11826| [CVE-2010-0824] Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed WOPT (0x80B) record, aka "Excel Record Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0821 and CVE-2010-1245.
11827| [CVE-2010-0823] Unspecified vulnerability in Microsoft Office Excel 2002 SP3, 2003 SP3, 2007 SP1 and SP2
11828| [CVE-2010-0822] Stack-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a crafted OBJ (0x5D) record, aka "Excel Object Stack Overflow Vulnerability."
11829| [CVE-2010-0821] Unspecified vulnerability in Microsoft Office Excel 2002 SP3, 2003 SP3, 2007 SP1 and SP2
11830| [CVE-2010-0820] Heap-based buffer overflow in the Local Security Authority Subsystem Service (LSASS), as used in Active Directory in Microsoft Windows Server 2003 SP2 and Windows Server 2008 Gold, SP2, and R2
11831| [CVE-2010-0819] Unspecified vulnerability in the Windows OpenType Compact Font Format (CFF) driver in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users to execute arbitrary code via unknown vectors related to improper validation when copying data from user mode to kernel mode, aka "OpenType CFF Font Driver Memory Corruption Vulnerability."
11832| [CVE-2010-0818] The MPEG-4 codec in the Windows Media codecs in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 does not properly handle crafted media content with MPEG-4 video encoding, which allows remote attackers to execute arbitrary code via a file in an unspecified "supported format," aka "MPEG-4 Codec Vulnerability."
11833| [CVE-2010-0817] Cross-site scripting (XSS) vulnerability in _layouts/help.aspx in Microsoft SharePoint Server 2007 12.0.0.6421 and possibly earlier, and SharePoint Services 3.0 SP1 and SP2, versions, allows remote attackers to inject arbitrary web script or HTML via the cid0 parameter.
11834| [CVE-2010-0815] VBE6.DLL in Microsoft Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Visual Basic for Applications (VBA), and VBA SDK 6.3 through 6.5 does not properly search for ActiveX controls that are embedded in documents, which allows remote attackers to execute arbitrary code via a crafted document, aka "VBE6.DLL Stack Memory Corruption Vulnerability."
11835| [CVE-2010-0814] The Microsoft Access Wizard Controls in ACCWIZ.dll in Microsoft Office Access 2003 SP3 and 2007 SP1 and SP2 do not properly interact with the memory-allocation approach used by Internet Explorer during instantiation, which allows remote attackers to execute arbitrary code via a web site that references multiple ActiveX controls, as demonstrated by the ImexGrid and FieldList controls, aka "Access ActiveX Control Vulnerability."
11836| [CVE-2010-0812] Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to bypass intended IPv4 source-address restrictions via a mismatched IPv6 source address in a tunneled ISATAP packet, aka "ISATAP IPv6 Source Address Spoofing Vulnerability."
11837| [CVE-2010-0811] Multiple unspecified vulnerabilities in the Microsoft Internet Explorer 8 Developer Tools ActiveX control in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allow remote attackers to execute arbitrary code via unknown vectors that "corrupt the system state," aka "Microsoft Internet Explorer 8 Developer Tools Vulnerability."
11838| [CVE-2010-0810] The kernel in Microsoft Windows Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2, does not properly handle unspecified exceptions, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Exception Handler Vulnerability."
11839| [CVE-2010-0719] An unspecified API in Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, and Windows 7 does not validate arguments, which allows local users to cause a denial of service (system crash) via a crafted application.
11840| [CVE-2010-0487] The Authenticode Signature verification functionality in cabview.dll in Cabinet File Viewer Shell Extension 5.1, 6.0, and 6.1 in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly use unspecified fields in a file digest, which allows remote attackers to execute arbitrary code via a modified cabinet (aka .CAB) file that incorrectly appears to have a valid signature, aka "Cabview Corruption Validation Vulnerability."
11841| [CVE-2010-0486] The WinVerifyTrust function in Authenticode Signature Verification 5.1, 6.0, and 6.1 in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly use unspecified fields in a file digest, which allows user-assisted remote attackers to execute arbitrary code via a modified (1) Portable Executable (PE) or (2) cabinet (aka .CAB) file that incorrectly appears to have a valid signature, aka "WinVerifyTrust Signature Validation Vulnerability."
11842| [CVE-2010-0485] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 Gold and SP2, Windows 7, and Server 2008 R2 "do not properly validate all callback parameters when creating a new window," which allows local users to execute arbitrary code, aka "Win32k Window Creation Vulnerability."
11843| [CVE-2010-0484] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 "do not properly validate changes in certain kernel objects," which allows local users to execute arbitrary code via vectors related to Device Contexts (DC) and the GetDCEx function, aka "Win32k Improper Data Validation Vulnerability."
11844| [CVE-2010-0483] vbscript.dll in VBScript 5.1, 5.6, 5.7, and 5.8 in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, allows user-assisted remote attackers to execute arbitrary code by referencing a (1) local pathname, (2) UNC share pathname, or (3) WebDAV server with a crafted .hlp file in the fourth argument (aka helpfile argument) to the MsgBox function, leading to code execution involving winhlp32.exe when the F1 key is pressed, aka "VBScript Help Keypress Vulnerability."
11845| [CVE-2010-0482] The kernel in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate relocation sections of image files, which allows local users to cause a denial of service (reboot) via a crafted file, aka "Windows Kernel Malformed Image Vulnerability."
11846| [CVE-2010-0481] The kernel in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly translate a registry key's virtual path to its real path, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Virtual Path Parsing Vulnerability."
11847| [CVE-2010-0480] Multiple stack-based buffer overflows in the MPEG Layer-3 audio codecs in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to execute arbitrary code via a crafted AVI file, aka "MPEG Layer-3 Audio Decoder Stack Overflow Vulnerability."
11848| [CVE-2010-0479] Buffer overflow in Microsoft Office Publisher 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Microsoft Office Publisher File Conversion TextBox Processing Buffer Overflow Vulnerability."
11849| [CVE-2010-0478] Stack-based buffer overflow in nsum.exe in the Windows Media Unicast Service in Media Services for Microsoft Windows 2000 Server SP4 allows remote attackers to execute arbitrary code via crafted packets associated with transport information, aka "Media Services Stack-based Buffer Overflow Vulnerability."
11850| [CVE-2010-0477] The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly handle (1) SMBv1 and (2) SMBv2 response packets, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted packet that causes the client to read the entirety of the response, and then improperly interact with the Winsock Kernel (WSK), aka "SMB Client Message Size Vulnerability."
11851| [CVE-2010-0476] The SMB client in Microsoft Windows Server 2003 SP2, Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2 allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and reboot) via a crafted SMB transaction response that uses (1) SMBv1 or (2) SMBv2, aka "SMB Client Response Parsing Vulnerability."
11852| [CVE-2010-0278] A certain ActiveX control in msgsc.14.0.8089.726.dll in Microsoft Windows Live Messenger 2009 build 14.0.8089.726 on Windows Vista and Windows 7 allows remote attackers to cause a denial of service (msnmsgr.exe crash) by calling the ViewProfile method with a crafted argument during an MSN Messenger session.
11853| [CVE-2010-0270] The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate fields in SMB transaction responses, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and reboot) via a crafted (1) SMBv1 or (2) SMBv2 response, aka "SMB Client Transaction Vulnerability."
11854| [CVE-2010-0269] The SMB client in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly allocate memory for SMB responses, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted (1) SMBv1 or (2) SMBv2 response, aka "SMB Client Memory Allocation Vulnerability."
11855| [CVE-2010-0268] Unspecified vulnerability in the Windows Media Player ActiveX control in Windows Media Player (WMP) 9 on Microsoft Windows 2000 SP4 and XP SP2 and SP3 allows remote attackers to execute arbitrary code via crafted media content, aka "Media Player Remote Code Execution Vulnerability."
11856| [CVE-2010-0266] Microsoft Office Outlook 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 does not properly verify e-mail attachments with a PR_ATTACH_METHOD property value of ATTACH_BY_REFERENCE, which allows user-assisted remote attackers to execute arbitrary code via a crafted message, aka "Microsoft Outlook SMB Attachment Vulnerability."
11857| [CVE-2010-0265] Buffer overflow in Microsoft Windows Movie Maker 2.1, 2.6, and 6.0, and Microsoft Producer 2003, allows remote attackers to execute arbitrary code via a crafted project (.MSWMM) file, aka "Movie Maker and Producer Buffer Overflow Vulnerability."
11858| [CVE-2010-0264] Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Microsoft Office Excel DbOrParamQry Record Parsing Vulnerability."
11859| [CVE-2010-0263] Microsoft Office Excel 2007 SP1 and SP2
11860| [CVE-2010-0262] Microsoft Office Excel 2007 SP1 and SP2 and Office 2004 for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet that triggers access of an uninitialized stack variable, aka "Microsoft Office Excel FNGROUPNAME Record Uninitialized Memory Vulnerability."
11861| [CVE-2010-0261] Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2 and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted spreadsheet in which "a MDXSET record is broken up into several records," aka "Microsoft Office Excel MDXSET Record Heap Overflow Vulnerability."
11862| [CVE-2010-0260] Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2
11863| [CVE-2010-0258] Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
11864| [CVE-2010-0257] Microsoft Office Excel 2002 SP3 does not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Microsoft Office Excel Record Memory Corruption Vulnerability."
11865| [CVE-2010-0256] Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 and SP2 does not properly calculate unspecified indexes associated with Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Visio Index Calculation Memory Corruption Vulnerability."
11866| [CVE-2010-0254] Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 and SP2 does not properly validate attributes in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Visio Attribute Validation Memory Corruption Vulnerability."
11867| [CVE-2010-0252] The Microsoft Data Analyzer ActiveX control (aka the Office Excel ActiveX control for Data Analysis) in max3activex.dll in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to execute arbitrary code via a crafted web page that corrupts the "system state," aka "Microsoft Data Analyzer ActiveX Control Vulnerability."
11868| [CVE-2010-0250] Heap-based buffer overflow in DirectShow in Microsoft DirectX, as used in the AVI Filter on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2, and in Quartz on Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, allows remote attackers to execute arbitrary code via an AVI file with a crafted length field in an unspecified video stream, which is not properly handled by the RLE video decompressor, aka "DirectShow Heap Overflow Vulnerability."
11869| [CVE-2010-0249] Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4
11870| [CVE-2010-0243] Buffer overflow in MSO.DLL in Microsoft Office XP SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Office document, aka "MSO.DLL Buffer Overflow."
11871| [CVE-2010-0242] The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows remote attackers to cause a denial of service (system hang) via crafted packets with malformed TCP selective acknowledgement (SACK) values, aka "TCP/IP Selective Acknowledgement Vulnerability."
11872| [CVE-2010-0241] The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when IPv6 is enabled, does not properly perform bounds checking on ICMPv6 Route Information packets, which allows remote attackers to execute arbitrary code via crafted packets, aka "ICMPv6 Route Information Vulnerability."
11873| [CVE-2010-0240] The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when a custom network driver is used, does not properly handle local fragmentation of Encapsulating Security Payload (ESP) over UDP packets, which allows remote attackers to execute arbitrary code via crafted packets, aka "Header MDL Fragmentation Vulnerability."
11874| [CVE-2010-0239] The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when IPv6 is enabled, does not properly perform bounds checking on ICMPv6 Router Advertisement packets, which allows remote attackers to execute arbitrary code via crafted packets, aka "ICMPv6 Router Advertisement Vulnerability."
11875| [CVE-2010-0238] Unspecified vulnerability in registry-key validation in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Registry Key Vulnerability."
11876| [CVE-2010-0237] The kernel in Microsoft Windows 2000 SP4 and XP SP2 and SP3 allows local users to gain privileges by creating a symbolic link from an untrusted registry hive to a trusted registry hive, aka "Windows Kernel Symbolic Link Creation Vulnerability."
11877| [CVE-2010-0236] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold does not properly allocate memory for the destination key associated with a symbolic-link registry key, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Allocation Vulnerability."
11878| [CVE-2010-0235] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold does not perform the expected validation before creating a symbolic link, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Symbolic Link Value Vulnerability."
11879| [CVE-2010-0234] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not properly validate a registry-key argument to an unspecified system call, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Null Pointer Vulnerability."
11880| [CVE-2010-0233] Double free vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows local users to gain privileges via a crafted application, aka "Windows Kernel Double Free Vulnerability."
11881| [CVE-2010-0232] The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges by crafting a VDM_TIB data structure in the Thread Environment Block (TEB), and then calling the NtVdmControl function to start the Windows Virtual DOS Machine (aka NTVDM) subsystem, leading to improperly handled exceptions involving the #GP trap handler (nt!KiTrap0D), aka "Windows Kernel Exception Handler Vulnerability."
11882| [CVE-2010-0231] The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not use a sufficient source of entropy, which allows remote attackers to obtain access to files and other SMB resources via a large number of authentication requests, related to server-generated challenges, certain "duplicate values," and spoofing of an authentication token, aka "SMB NTLM Authentication Lack of Entropy Vulnerability."
11883| [CVE-2010-0035] The Key Distribution Center (KDC) in Kerberos in Microsoft Windows 2000 SP4, Server 2003 SP2, and Server 2008 Gold and SP2, when a trust relationship with a non-Windows Kerberos realm exists, allows remote authenticated users to cause a denial of service (NULL pointer dereference and domain controller outage) via a crafted Ticket Granting Ticket (TGT) renewal request, aka "Kerberos Null Pointer Dereference Vulnerability."
11884| [CVE-2010-0034] Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "Office PowerPoint Viewer TextCharsAtom Record Stack Overflow Vulnerability."
11885| [CVE-2010-0033] Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint Viewer TextBytesAtom Record Stack Overflow Vulnerability."
11886| [CVE-2010-0032] Use-after-free vulnerability in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "OEPlaceholderAtom Use After Free Vulnerability."
11887| [CVE-2010-0031] Array index error in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3, and PowerPoint in Office 2004 for Mac, allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint OEPlaceholderAtom 'placementId' Invalid Array Indexing Vulnerability."
11888| [CVE-2010-0030] Heap-based buffer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint LinkedSlideAtom Heap Overflow Vulnerability."
11889| [CVE-2010-0029] Buffer overflow in Microsoft Office PowerPoint 2002 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint File Path Handling Buffer Overflow Vulnerability."
11890| [CVE-2010-0028] Integer overflow in Microsoft Paint in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted JPEG (.JPG) file, aka "MS Paint Integer Overflow Vulnerability."
11891| [CVE-2010-0027] The URL validation functionality in Microsoft Internet Explorer 5.01, 6, 6 SP1, 7 and 8, and the ShellExecute API function in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."
11892| [CVE-2010-0026] The Hyper-V server implementation in Microsoft Windows Server 2008 Gold, SP2, and R2 on the x64 platform allows guest OS users to cause a denial of service (host OS hang) via a crafted application that executes a malformed series of machine instructions, aka "Hyper-V Instruction Set Validation Vulnerability."
11893| [CVE-2010-0025] The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2000 SP3, does not properly allocate memory for SMTP command replies, which allows remote attackers to read fragments of e-mail messages by sending a series of invalid commands and then sending a STARTTLS command, aka "SMTP Memory Allocation Vulnerability."
11894| [CVE-2010-0024] The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2003 SP2, does not properly parse MX records, which allows remote DNS servers to cause a denial of service (service outage) via a crafted response to a DNS MX record query, aka "SMTP Server MX Record Vulnerability."
11895| [CVE-2010-0023] The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly kill processes after a logout, which allows local users to obtain sensitive information or gain privileges via a crafted application that continues to execute throughout the logout of one user and the login session of the next user, aka "CSRSS Local Privilege Elevation Vulnerability."
11896| [CVE-2010-0022] The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate the share and servername fields in SMB packets, which allows remote attackers to cause a denial of service (system hang) via a crafted packet, aka "SMB Null Pointer Vulnerability."
11897| [CVE-2010-0021] Multiple race conditions in the SMB implementation in the Server service in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allow remote attackers to cause a denial of service (system hang) via a crafted (1) SMBv1 or (2) SMBv2 Negotiate packet, aka "SMB Memory Corruption Vulnerability."
11898| [CVE-2010-0020] The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate request fields, which allows remote authenticated users to execute arbitrary code via a malformed request, aka "SMB Pathname Overflow Vulnerability."
11899| [CVE-2010-0018] Integer overflow in the Embedded OpenType (EOT) Font Engine (t2embed.dll) in Microsoft Windows 2000 SP4
11900| [CVE-2010-0017] Race condition in the SMB client implementation in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code, and in the SMB client implementation in Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows local users to gain privileges, via a crafted SMB Negotiate response, aka "SMB Client Race Condition Vulnerability."
11901| [CVE-2010-0016] The SMB client implementation in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly validate response fields, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted response, aka "SMB Client Pool Corruption Vulnerability."
11902| [CVE-2009-4313] ir32_32.dll 3.24.15.3 in the Indeo32 codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to cause a denial of service (heap corruption) or execute arbitrary code via malformed data in a stream in a media file, as demonstrated by an AVI file.
11903| [CVE-2009-4312] Unspecified vulnerability in the Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via crafted media content, as reported to Microsoft by Dave Lenoe of Adobe.
11904| [CVE-2009-4311] Unspecified vulnerability in the Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via crafted media content, as reported to Microsoft by Paul Byrne of NGS Software. NOTE: this might overlap CVE-2008-3615.
11905| [CVE-2009-4310] Stack-based buffer overflow in the Intel Indeo41 codec for Windows Media Player in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via crafted compressed video data in an IV41 stream in a media file, leading to many loop iterations, as demonstrated by data in an AVI file.
11906| [CVE-2009-4309] Heap-based buffer overflow in the Intel Indeo41 codec for Windows Media Player in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a large size value in a movi record in an IV41 stream in a media file, as demonstrated by an AVI file.
11907| [CVE-2009-4210] The Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted media content.
11908| [CVE-2009-3830] The download functionality in Team Services in Microsoft Office SharePoint Server 2007 12.0.0.4518 and 12.0.0.6219 allows remote attackers to read ASP.NET source code via pathnames in the SourceUrl and Source parameters to _layouts/download.aspx.
11909| [CVE-2009-3678] Integer overflow in cdd.dll in the Canonical Display Driver (CDD) in Microsoft Windows Server 2008 R2 and Windows 7 on 64-bit platforms, when the Windows Aero theme is installed, allows context-dependent attackers to cause a denial of service (reboot) or possibly execute arbitrary code via a crafted image file that triggers incorrect data parsing after user-mode data is copied to kernel mode, as demonstrated using "Browse with Irfanview" and certain actions on a folder containing a large number of thumbnail images in Resample mode, possibly related to the ATI graphics driver or win32k.sys, aka "Canonical Display Driver Integer Overflow Vulnerability."
11910| [CVE-2009-3677] The Internet Authentication Service (IAS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly verify the credentials in an MS-CHAP v2 Protected Extensible Authentication Protocol (PEAP) authentication request, which allows remote attackers to access network resources via a malformed request, aka "MS-CHAP Authentication Bypass Vulnerability."
11911| [CVE-2009-3676] The SMB client in the kernel in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle attackers to cause a denial of service (infinite loop and system hang) via a (1) SMBv1 or (2) SMBv2 response packet that contains (a) an incorrect length value in a NetBIOS header or (b) an additional length field at the end of this response packet, aka "SMB Client Incomplete Response Vulnerability."
11912| [CVE-2009-3675] LSASS.exe in the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote authenticated users to cause a denial of service (CPU consumption) via a malformed ISAKMP request over IPsec, aka "Local Security Authority Subsystem Service Resource Exhaustion Vulnerability."
11913| [CVE-2009-3450] Multiple cross-site scripting (XSS) vulnerabilities in WebCoreModule.ashx in RADactive I-Load before 2008.2.5.0 allow remote attackers to inject arbitrary web script or HTML via parameters with names beginning with __ (underscore underscore) sequences, which are incompatible with an XSS protection mechanism provided by Microsoft ASP.NET.
11914| [CVE-2009-3135] Stack-based buffer overflow in Microsoft Office Word 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, Open XML File Format Converter for Mac, Office Word Viewer 2003 SP3, and Office Word Viewer allow remote attackers to execute arbitrary code via a Word document with a malformed File Information Block (FIB) structure, aka "Microsoft Office Word File Information Memory Corruption Vulnerability."
11915| [CVE-2009-3134] Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
11916| [CVE-2009-3133] Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a spreadsheet containing a malformed object that triggers memory corruption, related to "loading Excel records," aka "Excel Document Parsing Memory Corruption Vulnerability."
11917| [CVE-2009-3132] Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
11918| [CVE-2009-3131] Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
11919| [CVE-2009-3130] Heap-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via a spreadsheet containing a malformed Binary File Format (aka BIFF) record that triggers memory corruption, aka "Excel Document Parsing Heap Overflow Vulnerability."
11920| [CVE-2009-3129] Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
11921| [CVE-2009-3128] Microsoft Office Excel 2002 SP3 and 2003 SP3, and Office Excel Viewer 2003 SP3, does not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a spreadsheet with a malformed record object, aka "Excel SxView Memory Corruption Vulnerability."
11922| [CVE-2009-3127] Microsoft Office Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, Open XML File Format Converter for Mac, and Office Excel Viewer 2003 SP3 do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Cache Memory Corruption Vulnerability."
11923| [CVE-2009-3126] Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted PNG image file, aka "GDI+ PNG Integer Overflow Vulnerability."
11924| [CVE-2009-3103] Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via an & (ampersand) character in a Process ID High header field in a NEGOTIATE PROTOCOL REQUEST packet, which triggers an attempted dereference of an out-of-bounds memory location, aka "SMBv2 Negotiation Vulnerability." NOTE: some of these details are obtained from third party information.
11925| [CVE-2009-3020] win32k.sys in Microsoft Windows Server 2003 SP2 allows remote attackers to cause a denial of service (system crash) by referencing a crafted .eot file in the src descriptor of an @font-face Cascading Style Sheets (CSS) rule in an HTML document, possibly related to the Embedded OpenType (EOT) Font Engine, a different vulnerability than CVE-2006-0010, CVE-2009-0231, and CVE-2009-0232. NOTE: some of these details are obtained from third party information.
11926| [CVE-2009-2653] ** DISPUTED ** The NtUserConsoleControl function in win32k.sys in Microsoft Windows XP SP2 and SP3, and Server 2003 before SP1, allows local administrators to bypass unspecified "security software" and gain privileges via a crafted call that triggers an overwrite of an arbitrary memory location. NOTE: the vendor disputes the significance of this report, stating that 'the Administrator to SYSTEM "escalation" is not a security boundary we defend.'
11927| [CVE-2009-2532] Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC do not properly process the command value in an SMB Multi-Protocol Negotiate Request packet, which allows remote attackers to execute arbitrary code via a crafted SMBv2 packet to the Server service, aka "SMBv2 Command Value Vulnerability."
11928| [CVE-2009-2526] Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 do not properly validate fields in SMBv2 packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted packet to the Server service, aka "SMBv2 Infinite Loop Vulnerability."
11929| [CVE-2009-2524] Integer underflow in the NTLM authentication feature in the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to cause a denial of service (reboot) via a malformed packet, aka "Local Security Authority Subsystem Service Integer Overflow Vulnerability."
11930| [CVE-2009-2523] The License Logging Server (llssrv.exe) in Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrary code via an RPC message containing a string without a null terminator, which triggers a heap-based buffer overflow in the LlsrLicenseRequestW method, aka "License Logging Server Heap Overflow Vulnerability."
11931| [CVE-2009-2519] The DHTML Editing Component ActiveX control in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly format HTML markup, which allows remote attackers to execute arbitrary code via a crafted web site that triggers "system state" corruption, aka "DHTML Editing Component ActiveX Control Vulnerability."
11932| [CVE-2009-2517] The kernel in Microsoft Windows Server 2003 SP2 does not properly handle unspecified exceptions when an error condition occurs, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Exception Handler Vulnerability."
11933| [CVE-2009-2516] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly validate data sent from user mode, which allows local users to gain privileges via a crafted PE .exe file that triggers a NULL pointer dereference during chain traversal, aka "Windows Kernel NULL Pointer Dereference Vulnerability."
11934| [CVE-2009-2515] Integer underflow in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows local users to gain privileges via a crafted application that triggers an incorrect truncation of a 64-bit integer to a 32-bit integer, aka "Windows Kernel Integer Underflow Vulnerability."
11935| [CVE-2009-2514] win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not correctly parse font code during construction of a directory-entry table, which allows remote attackers to execute arbitrary code via a crafted Embedded OpenType (EOT) font, aka "Win32k EOT Parsing Vulnerability."
11936| [CVE-2009-2513] The Graphics Device Interface (GDI) in win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Insufficient Data Validation Vulnerability."
11937| [CVE-2009-2511] Integer overflow in the CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows man-in-the-middle attackers to spoof arbitrary SSL servers and other entities via an X.509 certificate that has a malformed ASN.1 Object Identifier (OID) and was issued by a legitimate Certification Authority, aka "Integer Overflow in X.509 Object Identifiers Vulnerability."
11938| [CVE-2009-2510] The CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, as used by Internet Explorer and other applications, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, aka "Null Truncation in X.509 Common Name Vulnerability," a related issue to CVE-2009-2408.
11939| [CVE-2009-2509] Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly validate headers in HTTP requests, which allows remote authenticated users to execute arbitrary code via a crafted request to an IIS web server, aka "Remote Code Execution in ADFS Vulnerability."
11940| [CVE-2009-2508] The single sign-on implementation in Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly remove credentials at the end of a network session, which allows physically proximate attackers to obtain the credentials of a previous user of the same web browser by using data from the browser's cache, aka "Single Sign On Spoofing in ADFS Vulnerability."
11941| [CVE-2009-2507] A certain ActiveX control in the Indexing Service in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly process URLs, which allows remote attackers to execute arbitrary programs via unspecified vectors that cause a "vulnerable binary" to load and run, aka "Memory Corruption in Indexing Service Vulnerability."
11942| [CVE-2009-2506] Integer overflow in the text converters in Microsoft Office Word 2002 SP3 and 2003 SP3
11943| [CVE-2009-2505] The Internet Authentication Service (IAS) in Microsoft Windows Vista SP2 and Server 2008 SP2 does not properly validate MS-CHAP v2 Protected Extensible Authentication Protocol (PEAP) authentication requests, which allows remote attackers to execute arbitrary code via crafted structures in a malformed request, aka "Internet Authentication Service Memory Corruption Vulnerability."
11944| [CVE-2009-2504] Multiple integer overflows in unspecified APIs in GDI+ in Microsoft .NET Framework 1.1 SP1, .NET Framework 2.0 SP1 and SP2, Windows XP SP2 and SP3, Windows Server 2003 SP2, Vista Gold and SP1, Server 2008 Gold, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allow remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "GDI+ .NET API Vulnerability."
11945| [CVE-2009-2503] GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 does not properly allocate an unspecified buffer, which allows remote attackers to execute arbitrary code via a crafted TIFF image file that triggers memory corruption, aka "GDI+ TIFF Memory Corruption Vulnerability."
11946| [CVE-2009-2502] Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted TIFF image file, aka "GDI+ TIFF Buffer Overflow Vulnerability."
11947| [CVE-2009-2501] Heap-based buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted PNG image file, aka "GDI+ PNG Heap Overflow Vulnerability."
11948| [CVE-2009-2500] Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted WMF image file, aka "GDI+ WMF Integer Overflow Vulnerability."
11949| [CVE-2009-2498] Microsoft Windows Media Format Runtime 9.0, 9.5, and 11 and Windows Media Services 9.1 and 2008 do not properly parse malformed headers in Advanced Systems Format (ASF) files, which allows remote attackers to execute arbitrary code via a crafted (1) .asf, (2) .wmv, or (3) .wma file, aka "Windows Media Header Parsing Invalid Free Vulnerability."
11950| [CVE-2009-2497] The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0, 2.0 SP1, 2.0 SP2, 3.5, and 3.5 SP1, and Silverlight 2, does not properly handle interfaces, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted Silverlight application, (3) a crafted ASP.NET application, or (4) a crafted .NET Framework application, aka "Microsoft Silverlight and Microsoft .NET Framework CLR Vulnerability."
11951| [CVE-2009-2496] Heap-based buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 SP1, and Office Small Business Accounting 2006 allows remote attackers to execute arbitrary code via unspecified parameters to unknown methods, aka "Office Web Components Heap Corruption Vulnerability."
11952| [CVE-2009-2495] The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1 does not properly enforce string termination, which allows remote attackers to obtain sensitive information via a crafted HTML document with an ATL (1) component or (2) control that triggers a buffer over-read, related to ATL headers and buffer allocation, aka "ATL Null String Vulnerability."
11953| [CVE-2009-2494] The Active Template Library (ATL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via vectors related to erroneous free operations after reading a variant from a stream and deleting this variant, aka "ATL Object Type Mismatch Vulnerability."
11954| [CVE-2009-2493] The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1
11955| [CVE-2009-1930] The Telnet service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote Telnet servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user, aka "Telnet Credential Reflection Vulnerability," a related issue to CVE-2000-0834.
11956| [CVE-2009-1929] Heap-based buffer overflow in the Microsoft Terminal Services Client ActiveX control running RDP 6.1 on Windows XP SP2, Vista SP1 or SP2, or Server 2008 Gold or SP2
11957| [CVE-2009-1928] Stack consumption vulnerability in the LDAP service in Active Directory on Microsoft Windows 2000 SP4, Server 2003 SP2, and Server 2008 Gold and SP2
11958| [CVE-2009-1926] Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to cause a denial of service (TCP outage) via a series of TCP sessions that have pending data and a (1) small or (2) zero receive window size, and remain in the FIN-WAIT-1 or FIN-WAIT-2 state indefinitely, aka "TCP/IP Orphaned Connections Vulnerability."
11959| [CVE-2009-1925] The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 does not properly manage state information, which allows remote attackers to execute arbitrary code by sending packets to a listening service, and thereby triggering misinterpretation of an unspecified field as a function pointer, aka "TCP/IP Timestamps Code Execution Vulnerability."
11960| [CVE-2009-1924] Integer overflow in the Windows Internet Name Service (WINS) component for Microsoft Windows 2000 SP4 allows remote WINS replication partners to execute arbitrary code via crafted data structures in a packet, aka "WINS Integer Overflow Vulnerability."
11961| [CVE-2009-1923] Heap-based buffer overflow in the Windows Internet Name Service (WINS) component for Microsoft Windows 2000 SP4 and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted WINS replication packet that triggers an incorrect buffer-length calculation, aka "WINS Heap Overflow Vulnerability."
11962| [CVE-2009-1922] The Message Queuing (aka MSMQ) service for Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP2, and Vista Gold does not properly validate unspecified IOCTL request data from user mode before passing this data to kernel mode, which allows local users to gain privileges via a crafted request, aka "MSMQ Null Pointer Vulnerability."
11963| [CVE-2009-1546] Integer overflow in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windows allows remote attackers to execute arbitrary code on a Windows 2000 SP4 system via a crafted AVI file, or cause a denial of service on a Windows XP SP2 or SP3, Server 2003 SP2, Vista Gold, SP1, or SP2, or Server 2008 Gold or SP2 system via a crafted AVI file, aka "AVI Integer Overflow Vulnerability."
11964| [CVE-2009-1545] Unspecified vulnerability in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a malformed header in a crafted AVI file, aka "Malformed AVI Header Vulnerability."
11965| [CVE-2009-1544] Double free vulnerability in the Workstation service in Microsoft Windows allows remote authenticated users to gain privileges via a crafted RPC message to a Windows XP SP2 or SP3 or Server 2003 SP2 system, or cause a denial of service via a crafted RPC message to a Vista Gold, SP1, or SP2 or Server 2008 Gold or SP2 system, aka "Workstation Service Memory Corruption Vulnerability."
11966| [CVE-2009-1542] The Virtual Machine Monitor (VMM) in Microsoft Virtual PC 2004 SP1, 2007, and 2007 SP1, and Microsoft Virtual Server 2005 R2 SP1, does not enforce CPU privilege-level requirements for all machine instructions, which allows guest OS users to execute arbitrary kernel-mode code and gain privileges within the guest OS via a crafted application, aka "Virtual PC and Virtual Server Privileged Instruction Decoding Vulnerability."
11967| [CVE-2009-1539] The QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 does not properly validate unspecified size fields in QuickTime media files, which allows remote attackers to execute arbitrary code via a crafted file, aka "DirectX Size Validation Vulnerability."
11968| [CVE-2009-1538] The QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 performs updates to pointers without properly validating unspecified data values, which allows remote attackers to execute arbitrary code via a crafted QuickTime media file, aka "DirectX Pointer Validation Vulnerability."
11969| [CVE-2009-1537] Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted QuickTime media file, as exploited in the wild in May 2009, aka "DirectX NULL Byte Overwrite Vulnerability."
11970| [CVE-2009-1536] ASP.NET in Microsoft .NET Framework 2.0 SP1 and SP2 and 3.5 Gold and SP1, when ASP 2.0 is used in integrated mode on IIS 7.0, does not properly manage request scheduling, which allows remote attackers to cause a denial of service (daemon outage) via a series of crafted HTTP requests, aka "Remote Unauthenticated Denial of Service in ASP.NET Vulnerability."
11971| [CVE-2009-1534] Buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2000 Web Components SP3, Office XP Web Components SP3, BizTalk Server 2002, and Visual Studio .NET 2003 SP1 allows remote attackers to execute arbitrary code via crafted property values, aka "Office Web Components Buffer Overflow Vulnerability."
11972| [CVE-2009-1533] Buffer overflow in the Works for Windows document converters in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, Office 2007 SP1, and Works 8.5 and 9 allows remote attackers to execute arbitrary code via a crafted Works .wps file that triggers memory corruption, aka "File Converter Buffer Overflow Vulnerability."
11973| [CVE-2009-1491] McAfee GroupShield for Microsoft Exchange on Exchange Server 2000, and possibly other anti-virus or anti-spam products from McAfee or other vendors, does not scan X- headers for malicious content, which allows remote attackers to bypass virus detection via a crafted message, as demonstrated by a message with an X-Testing header and no message body.
11974| [CVE-2009-1216] Multiple unspecified vulnerabilities in (1) unlzh.c and (2) unpack.c in the gzip libraries in Microsoft Windows Server 2008, Windows Services for UNIX 3.0 and 3.5, and the Subsystem for UNIX-based Applications (SUA)
11975| [CVE-2009-1141] Microsoft Internet Explorer 6 for Windows XP SP2 and SP3 and Server 2003 SP2 allows remote attackers to execute arbitrary code via unspecified DHTML function calls related to a tr element and the "insertion, deletion and attributes of a table cell," which trigger memory corruption when the window is destroyed, aka "DHTML Object Memory Corruption Vulnerability."
11976| [CVE-2009-1139] Memory leak in the LDAP service in Active Directory on Microsoft Windows 2000 SP4 and Server 2003 SP2, and Active Directory Application Mode (ADAM) on Windows XP SP2 and SP3 and Server 2003 SP2, allows remote attackers to cause a denial of service (memory consumption and service outage) via (1) LDAP or (2) LDAPS requests with unspecified OID filters, aka "Active Directory Memory Leak Vulnerability."
11977| [CVE-2009-1138] The LDAP service in Active Directory on Microsoft Windows 2000 SP4 does not properly free memory for LDAP and LDAPS requests, which allows remote attackers to execute arbitrary code via a request that uses hexadecimal encoding, whose associated memory is not released, related to a "DN AttributeValue," aka "Active Directory Invalid Free Vulnerability." NOTE: this issue is probably a memory leak.
11978| [CVE-2009-1137] Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0223, CVE-2009-0226, and CVE-2009-0227.
11979| [CVE-2009-1136] The Microsoft Office Web Components Spreadsheet ActiveX control (aka OWC10 or OWC11), as distributed in Office XP SP3 and Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 Gold and SP1, and Office Small Business Accounting 2006, when used in Internet Explorer, allows remote attackers to execute arbitrary code via a crafted call to the msDataSourceObject method, as exploited in the wild in July and August 2009, aka "Office Web Components HTML Script Vulnerability."
11980| [CVE-2009-1135] Microsoft Internet Security and Acceleration (ISA) Server 2006 Gold and SP1, when Radius OTP is enabled, uses the HTTP-Basic authentication method, which allows remote attackers to gain the privileges of an arbitrary account, and access published web pages, via vectors involving attempted access to a network resource behind the ISA Server, aka "Radius OTP Bypass Vulnerability."
11981| [CVE-2009-1134] Excel in 2007 Microsoft Office System SP1 and SP2
11982| [CVE-2009-1133] Heap-based buffer overflow in Microsoft Remote Desktop Connection (formerly Terminal Services Client) running RDP 5.0 through 6.1 on Windows, and Remote Desktop Connection Client for Mac 2.0, allows remote attackers to execute arbitrary code via unspecified parameters, aka "Remote Desktop Connection Heap Overflow Vulnerability."
11983| [CVE-2009-1132] Heap-based buffer overflow in the Wireless LAN AutoConfig Service (aka Wlansvc) in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a malformed wireless frame, aka "Wireless Frame Parsing Remote Code Execution Vulnerability."
11984| [CVE-2009-1131] Multiple stack-based buffer overflows in Microsoft Office PowerPoint 2000 SP3 allow remote attackers to execute arbitrary code via a large amount of data associated with unspecified atoms in a PowerPoint file that triggers memory corruption, aka "Data Out of Bounds Vulnerability."
11985| [CVE-2009-1130] Heap-based buffer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a crafted structure in a Notes container in a PowerPoint file that causes PowerPoint to read more data than was allocated when creating a C++ object, leading to an overwrite of a function pointer, aka "Heap Corruption Vulnerability."
11986| [CVE-2009-1129] Multiple stack-based buffer overflows in the PowerPoint 95 importer (PP7X32.DLL) in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allow remote attackers to execute arbitrary code via an inconsistent record length in sound data in a file that uses a PowerPoint 95 (PPT95) native file format, aka "PP7 Memory Corruption Vulnerability," a different vulnerability than CVE-2009-1128.
11987| [CVE-2009-1128] Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 95 native file format, leading to memory corruption, aka "PP7 Memory Corruption Vulnerability," a different vulnerability than CVE-2009-1129.
11988| [CVE-2009-1127] win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not correctly validate an argument to an unspecified system call, which allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, aka "Win32k NULL Pointer Dereferencing Vulnerability."
11989| [CVE-2009-1126] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly validate the user-mode input associated with the editing of an unspecified desktop parameter, which allows local users to gain privileges via a crafted application, aka "Windows Desktop Parameter Edit Vulnerability."
11990| [CVE-2009-1125] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate an argument to an unspecified system call, which allows local users to gain privileges via a crafted application, aka "Windows Driver Class Registration Vulnerability."
11991| [CVE-2009-1124] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate user-mode pointers in unspecified error conditions, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Pointer Validation Vulnerability."
11992| [CVE-2009-1123] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Desktop Vulnerability."
11993| [CVE-2009-1122] The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote attackers to bypass authentication, and possibly read or create files, via a crafted HTTP request, aka "IIS 5.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1535.
11994| [CVE-2009-1043] Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors triggered by clicking on a link, as demonstrated by Nils during a PWN2OWN competition at CanSecWest 2009.
11995| [CVE-2009-1011] Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on reliable researcher claims that this issue is for multiple integer overflows in a function that parses an optional data stream within a Microsoft Office file, leading to a heap-based buffer overflow.
11996| [CVE-2009-0901] The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold, and Visual C++ 2005 SP1 and 2008 Gold and SP1
11997| [CVE-2009-0568] The RPC Marshalling Engine (aka NDR) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly maintain its internal state, which allows remote attackers to overwrite arbitrary memory locations via a crafted RPC message that triggers incorrect pointer reading, related to "IDL interfaces containing a non-conformant varying array" and FC_SMVARRAY, FC_LGVARRAY, FC_VARIABLE_REPEAT, and FC_VARIABLE_OFFSET, aka "RPC Marshalling Engine Vulnerability."
11998| [CVE-2009-0566] Microsoft Office Publisher 2007 SP1 does not properly calculate object handler data for Publisher files, which allows remote attackers to execute arbitrary code via a crafted file in a legacy format that triggers memory corruption, aka "Pointer Dereference Vulnerability."
11999| [CVE-2009-0565] Buffer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, and 2007 SP1 and SP2
12000| [CVE-2009-0563] Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
12001| [CVE-2009-0562] The Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 SP1, and Office Small Business Accounting 2006 does not properly allocate memory, which allows remote attackers to execute arbitrary code via unspecified vectors that trigger "system state" corruption, aka "Office Web Components Memory Allocation Vulnerability."
12002| [CVE-2009-0561] Integer overflow in Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac
12003| [CVE-2009-0560] Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac
12004| [CVE-2009-0559] Stack-based buffer overflow in Excel in Microsoft Office 2000 SP3 and Office XP SP3 allows remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "String Copy Stack-Based Overrun Vulnerability."
12005| [CVE-2009-0558] Array index error in Excel in Microsoft Office 2000 SP3 and Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac, allows remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Array Indexing Memory Corruption Vulnerability."
12006| [CVE-2009-0557] Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac
12007| [CVE-2009-0556] Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an an invalid index value that triggers memory corruption, as exploited in the wild in April 2009 by Exploit:Win32/Apptom.gen, aka "Memory Corruption Vulnerability."
12008| [CVE-2009-0554] Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka "Uninitialized Memory Corruption Vulnerability."
12009| [CVE-2009-0553] Microsoft Internet Explorer 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka "Uninitialized Memory Corruption Vulnerability."
12010| [CVE-2009-0552] Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 on Windows XP SP2 and SP3, and 6 on Windows Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka "Uninitialized Memory Corruption Vulnerability."
12011| [CVE-2009-0551] Microsoft Internet Explorer 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 does not properly handle transition errors in a request for one HTTP document followed by a request for a second HTTP document, which allows remote attackers to execute arbitrary code via vectors involving (1) multiple crafted pages on a web site or (2) a web page with crafted inline content such as banner advertisements, aka "Page Transition Memory Corruption Vulnerability."
12012| [CVE-2009-0550] Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008
12013| [CVE-2009-0549] Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac
12014| [CVE-2009-0320] Microsoft Windows XP, Server 2003 and 2008, and Vista exposes I/O activity measurements of all processes, which allows local users to obtain sensitive information, as demonstrated by reading the I/O Other Bytes column in Task Manager (aka taskmgr.exe) to estimate the number of characters that a different user entered at a runas.exe password prompt, related to a "benchmarking attack."
12015| [CVE-2009-0239] Cross-site scripting (XSS) vulnerability in Windows Search 4.0 for Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted file that appears in a preview in a search result, aka "Script Execution in Windows Search Vulnerability."
12016| [CVE-2009-0238] Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1
12017| [CVE-2009-0235] Stack-based buffer overflow in the Word 97 text converter in WordPad in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted Word 97 file that triggers memory corruption, related to use of inconsistent integer data sizes for an unspecified length field, aka "WordPad Word 97 Text Converter Stack Overflow Vulnerability."
12018| [CVE-2009-0234] The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008 does not properly cache crafted DNS responses, which makes it easier for remote attackers to predict transaction IDs and poison caches by sending many crafted DNS queries that trigger "unnecessary lookups," aka "DNS Server Response Validation Vulnerability."
12019| [CVE-2009-0233] The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not reuse cached DNS responses in all applicable situations, which makes it easier for remote attackers to predict transaction IDs and poison caches by simultaneously sending crafted DNS queries and responses, aka "DNS Server Query Validation Vulnerability."
12020| [CVE-2009-0232] Integer overflow in the Embedded OpenType (EOT) Font Engine in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted name table, aka "Embedded OpenType Font Integer Overflow Vulnerability."
12021| [CVE-2009-0231] The Embedded OpenType (EOT) Font Engine (T2EMBED.DLL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted name table in a data record that triggers an integer truncation and a heap-based buffer overflow, aka "Embedded OpenType Font Heap Overflow Vulnerability."
12022| [CVE-2009-0230] The Windows Print Spooler in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows remote authenticated users to gain privileges via a crafted RPC message that triggers loading of a DLL file from an arbitrary directory, aka "Print Spooler Load Library Vulnerability."
12023| [CVE-2009-0229] The Windows Printing Service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows local users to read arbitrary files via a crafted separator page, aka "Print Spooler Read File Vulnerability."
12024| [CVE-2009-0228] Stack-based buffer overflow in the EnumeratePrintShares function in Windows Print Spooler Service (win32spl.dll) in Microsoft Windows 2000 SP4 allows remote printer servers to execute arbitrary code via a a crafted ShareName in a response to an RPC request, related to "printing data structures," aka "Buffer Overflow in Print Spooler Vulnerability."
12025| [CVE-2009-0227] Stack-based buffer overflow in the PowerPoint 4.2 conversion filter (PP4X32.DLL) in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via a large number of structures in sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0223, CVE-2009-0226, and CVE-2009-1137.
12026| [CVE-2009-0226] Stack-based buffer overflow in the PowerPoint 4.2 conversion filter in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via a long string in sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0223, CVE-2009-0227, and CVE-2009-1137.
12027| [CVE-2009-0225] Microsoft Office PowerPoint 2002 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 95 native file format, leading to improper "array indexing" and memory corruption, aka "PP7 Memory Corruption Vulnerability."
12028| [CVE-2009-0224] Microsoft Office PowerPoint 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
12029| [CVE-2009-0223] Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0226, CVE-2009-0227, and CVE-2009-1137.
12030| [CVE-2009-0222] Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 4.0 native file format, leading to a "pointer overwrite" and memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0223, CVE-2009-0226, CVE-2009-0227, and CVE-2009-1137.
12031| [CVE-2009-0221] Integer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a PowerPoint file containing a crafted record type for "collaboration information for different slides" that contains a field that specifies a large number of records, which triggers an under-allocated buffer and a heap-based buffer overflow, aka "Integer Overflow Vulnerability."
12032| [CVE-2009-0220] Multiple stack-based buffer overflows in the PowerPoint 4.0 importer (PP4X32.DLL) in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allow remote attackers to execute arbitrary code via crafted formatting data for paragraphs in a file that uses a PowerPoint 4.0 native file format, related to (1) an incorrect calculation from a record header, or (2) an interget that is used to specify the number of bytes to copy, aka "Legacy File Format Vulnerability."
12033| [CVE-2009-0202] Array index error in FL21WIN.DLL in the PowerPoint Freelance Windows 2.1 Translator in Microsoft PowerPoint 2000 and 2002 allows remote attackers to execute arbitrary code via a Freelance file with unspecified "layout information" that triggers a heap-based buffer overflow.
12034| [CVE-2009-0102] Microsoft Project 2000 SR1 and 2002 SP1, and Office Project 2003 SP3, does not properly handle memory allocation for Project files, which allows remote attackers to execute arbitrary code via a malformed file, aka "Project Memory Validation Vulnerability."
12035| [CVE-2009-0100] Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1
12036| [CVE-2009-0099] The Electronic Messaging System Microsoft Data Base (EMSMDB32) provider in Microsoft Exchange 2000 Server SP3 and Exchange Server 2003 SP2, as used in Exchange System Attendant, allows remote attackers to cause a denial of service (application outage) via a malformed MAPI command, aka "Literal Processing Vulnerability."
12037| [CVE-2009-0098] Microsoft Exchange 2000 Server SP3, Exchange Server 2003 SP2, and Exchange Server 2007 SP1 do not properly interpret Transport Neutral Encapsulation (TNEF) properties, which allows remote attackers to execute arbitrary code via a crafted TNEF message, aka "Memory Corruption Vulnerability."
12038| [CVE-2009-0097] Microsoft Office Visio 2002 SP2 and 2003 SP3 does not properly validate memory allocation for Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Memory Corruption Vulnerability."
12039| [CVE-2009-0096] Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 does not properly perform memory copy operations for object data, which allows remote attackers to execute arbitrary code via a crafted Visio document, aka "Memory Corruption Vulnerability."
12040| [CVE-2009-0095] Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 does not properly validate object data in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Memory Validation Vulnerability."
12041| [CVE-2009-0094] The WINS server in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 does not restrict registration of the (1) "wpad" and (2) "isatap" NetBIOS names, which allows remote authenticated users to hijack the Web Proxy Auto-Discovery (WPAD) and Intra-Site Automatic Tunnel Addressing Protocol (ISATAP) features, and conduct man-in-the-middle attacks by spoofing a proxy server or ISATAP route, by registering one of these names in the WINS database, aka "WPAD WINS Server Registration Vulnerability," a related issue to CVE-2007-1692.
12042| [CVE-2009-0093] Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not restrict registration of the "wpad" hostname, which allows remote authenticated users to hijack the Web Proxy Auto-Discovery (WPAD) feature, and conduct man-in-the-middle attacks by spoofing a proxy server, via a Dynamic Update request for this hostname, aka "DNS Server Vulnerability in WPAD Registration Vulnerability," a related issue to CVE-2007-1692.
12043| [CVE-2009-0091] Microsoft .NET Framework 2.0, 2.0 SP1, and 3.5 does not properly enforce a certain type-equality constraint in .NET verifiable code, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft .NET Framework Type Verification Vulnerability."
12044| [CVE-2009-0090] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, and 2.0 SP1 does not properly validate .NET verifiable code, which allows remote attackers to obtain unintended access to stack memory, and execute arbitrary code, via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft .NET Framework Pointer Verification Vulnerability."
12045| [CVE-2009-0089] Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Vista Gold allows remote web servers to impersonate arbitrary https web sites by using DNS spoofing to "forward a connection" to a different https web site that has a valid certificate matching its own domain name, but not a certificate matching the domain name of the host requested by the user, aka "Windows HTTP Services Certificate Name Mismatch Vulnerability."
12046| [CVE-2009-0088] The WordPerfect 6.x Converter (WPFT632.CNV, 1998.1.27.0) in Microsoft Office Word 2000 SP3 and Microsoft Office Converter Pack does not properly validate the length of an unspecified string, which allows remote attackers to execute arbitrary code via a crafted WordPerfect 6.x file, related to an unspecified counter and control structures on the stack, aka "Word 2000 WordPerfect 6.x Converter Stack Corruption Vulnerability."
12047| [CVE-2009-0087] Unspecified vulnerability in the Word 6 text converter in WordPad in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2
12048| [CVE-2009-0086] Integer underflow in Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote HTTP servers to execute arbitrary code via crafted parameter values in a response, related to error handling, aka "Windows HTTP Services Integer Underflow Vulnerability."
12049| [CVE-2009-0085] The Secure Channel (aka SChannel) authentication component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008, when certificate authentication is used, does not properly validate the client's key exchange data in Transport Layer Security (TLS) handshake messages, which allows remote attackers to spoof authentication by crafting a TLS packet based on knowledge of the certificate but not the private key, aka "SChannel Spoofing Vulnerability."
12050| [CVE-2009-0083] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 does not properly handle invalid pointers, which allows local users to gain privileges via an application that triggers use of a crafted pointer, aka "Windows Kernel Invalid Pointer Vulnerability."
12051| [CVE-2009-0082] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate handles, which allows local users to gain privileges via a crafted application that triggers unspecified "actions," aka "Windows Kernel Handle Validation Vulnerability."
12052| [CVE-2009-0081] The graphics device interface (GDI) implementation in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate input received from user mode, which allows remote attackers to execute arbitrary code via a crafted (1) Windows Metafile (aka WMF) or (2) Enhanced Metafile (aka EMF) image file, aka "Windows Kernel Input Validation Vulnerability."
12053| [CVE-2009-0079] The RPCSS service in Microsoft Windows XP SP2 and SP3 and Server 2003 SP1 and SP2 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by accessing the resources of one of the processes, aka "Windows RPCSS Service Isolation Vulnerability."
12054| [CVE-2009-0078] The Windows Management Instrumentation (WMI) provider in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by accessing the resources of one of the processes, aka "Windows WMI Service Isolation Vulnerability."
12055| [CVE-2008-7217] Microsoft Office 2008 for Mac, when running on Macintosh systems that restrict Office access to administrators, does not enforce this restriction for user ID 502, which allows local users with that ID to bypass intended security policy and access Office programs, related to permissions and ownership for certain directories.
12056| [CVE-2008-6819] win32k.sys in Microsoft Windows Server 2003 and Vista allows local users to cause a denial of service (system crash) via vectors related to CreateWindow, TranslateMessage, and DispatchMessage, possibly a race condition between threads, a different vulnerability than CVE-2008-1084. NOTE: some of these details are obtained from third party information.
12057| [CVE-2008-6219] nsrexecd.exe in multiple EMC Networker products including EMC NetWorker Server, Storage Node, and Client 7.3.x and 7.4, 7.4.1, 7.4.2, Client and Storage Node for Open VMS 7.3.2 ECO6 and earlier, Module for Microsoft Exchange 5.1 and earlier, Module for Microsoft Applications 2.0 and earlier, Module for Meditech 2.0 and earlier, and PowerSnap 2.4 SP1 and earlier does not properly control the allocation of memory, which allows remote attackers to cause a denial of service (memory exhaustion) via multiple crafted RPC requests.
12058| [CVE-2008-6063] Microsoft Word 2007, when the "Save as PDF" add-on is enabled, places an absolute pathname in the Subject field during an "Email as PDF" operation, which allows remote attackers to obtain sensitive information such as the sender's account name and a Temporary Internet Files subdirectory name.
12059| [CVE-2008-5912] An unspecified function in the JavaScript implementation in Microsoft Internet Explorer creates and exposes a "temporary footprint" when there is a current login to a web site, which makes it easier for remote attackers to trick a user into acting upon a spoofed pop-up message, aka an "in-session phishing attack." NOTE: as of 20090116, the only disclosure is a vague pre-advisory with no actionable information. However, because it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.
12060| [CVE-2008-5823] An ActiveX control in prtstb06.dll in Microsoft Money 2006, when used with WScript in Windows Script Host (WSH) on Windows Vista, allows remote attackers to cause a denial of service (access violation and application crash) via a zero value for the Startup property.
12061| [CVE-2008-5416] Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier
12062| [CVE-2008-5232] Buffer overflow in the CallHTMLHelp method in the Microsoft Windows Media Services ActiveX control in nskey.dll 4.1.00.3917 in Windows Media Services on Microsoft Windows NT and 2000, and Avaya Media and Message Application servers, allows remote attackers to execute arbitrary code via a long argument. NOTE: the provenance of this information is unknown
12063| [CVE-2008-5112] The LDAP server in Active Directory in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 responds differently to a failed bind attempt depending on whether the user account exists and is permitted to login, which allows remote attackers to enumerate valid usernames via a series of LDAP bind requests, as demonstrated by ldapuserenum.
12064| [CVE-2008-5100] The strong name (SN) implementation in Microsoft .NET Framework 2.0.50727 relies on the digital signature Public Key Token embedded in the pathname of a DLL file instead of the digital signature of this file itself, which makes it easier for attackers to bypass Global Assembly Cache (GAC) and Code Access Security (CAS) protection mechanisms, aka MSRC ticket MSRC8566gs.
12065| [CVE-2008-5044] Race condition in Microsoft Windows Server 2003 and Vista allows local users to cause a denial of service (crash or hang) via a multi-threaded application that makes many calls to UnhookWindowsHookEx while certain other desktop activity is occurring.
12066| [CVE-2008-4844] Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via DSO bindings involving (1) an XML Island, (2) XML DSOs, or (3) Tabular Data Control (TDC) in a crafted HTML or XML document, as demonstrated by nested SPAN or MARQUEE elements, and exploited in the wild in December 2008.
12067| [CVE-2008-4841] The WordPad Text Converter for Word 97 files in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf Word 97 file that triggers memory corruption, as exploited in the wild in December 2008. NOTE: As of 20081210, it is unclear whether this vulnerability is related to a WordPad issue disclosed on 20080925 with a 2008-crash.doc.rar example, but there are insufficient details to be sure.
12068| [CVE-2008-4837] Stack-based buffer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
12069| [CVE-2008-4835] SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside the SMB packets" in an NT Trans2 request, related to "insufficiently validating the buffer size," aka "SMB Validation Remote Code Execution Vulnerability."
12070| [CVE-2008-4834] Buffer overflow in SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside the SMB packets" in an NT Trans request, aka "SMB Buffer Overflow Remote Code Execution Vulnerability."
12071| [CVE-2008-4493] Microsoft PicturePusher ActiveX control (PipPPush.DLL 7.00.0709), as used in Microsoft Digital Image 2006 Starter Edition, allows remote attackers to force the upload of arbitrary files by using the AddString and Post methods and a modified PostURL to construct an HTTP POST request. NOTE: this issue might only be exploitable in limited environments or non-default browser settings.
12072| [CVE-2008-4295] Microsoft Windows Mobile 6.0 on HTC Wiza 200 and HTC MDA 8125 devices does not properly handle the first attempt to establish a Bluetooth connection to a peer with a long name, which allows remote attackers to cause a denial of service (device reboot) by configuring a Bluetooth device with a long hci name and (1) connecting directly to the Windows Mobile system or (2) waiting for the Windows Mobile system to scan for nearby devices.
12073| [CVE-2008-4269] The search-ms protocol handler in Windows Explorer in Microsoft Windows Vista Gold and SP1 and Server 2008 uses untrusted parameter data obtained from incorrect parsing, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "Windows Search Parsing Vulnerability."
12074| [CVE-2008-4268] The Windows Search component in Microsoft Windows Vista Gold and SP1 and Server 2008 does not properly free memory during a save operation for a Windows Search file, which allows remote attackers to execute arbitrary code via a crafted saved-search file, aka "Windows Saved Search Vulnerability."
12075| [CVE-2008-4266] Array index vulnerability in Microsoft Office Excel 2000 SP3, 2002 SP3, and 2003 SP3
12076| [CVE-2008-4265] Microsoft Office Excel 2000 SP3 allows remote attackers to execute arbitrary code via a crafted Excel spreadsheet that contains a malformed object, which triggers memory corruption during the loading of records from this spreadsheet, aka "File Format Parsing Vulnerability."
12077| [CVE-2008-4264] Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
12078| [CVE-2008-4261] Stack-based buffer overflow in Microsoft Internet Explorer 5.01 SP4, 6 SP1 on Windows 2000, and 6 on Windows XP and Server 2003 does not properly handle extraneous data associated with an object embedded in a web page, which allows remote attackers to execute arbitrary code via crafted HTML tags that trigger memory corruption, aka "HTML Rendering Memory Corruption Vulnerability."
12079| [CVE-2008-4256] The Charts ActiveX control in Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the "system state," aka "Charts Control Memory Corruption Vulnerability."
12080| [CVE-2008-4255] Heap-based buffer overflow in mscomct2.ocx (aka Windows Common ActiveX control or Microsoft Animation ActiveX control) in Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2, and Office Project 2003 SP3 and 2007 Gold and SP1 allows remote attackers to execute arbitrary code via an AVI file with a crafted stream length, which triggers an "allocation error" and memory corruption, aka "Windows Common AVI Parsing Overflow Vulnerability."
12081| [CVE-2008-4253] The FlexGrid ActiveX control in Microsoft Visual Basic 6.0, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2, Office FrontPage 2002 SP3, and Office Project 2003 SP3 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the "system state," aka "FlexGrid Control Memory Corruption Vulnerability."
12082| [CVE-2008-4250] The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by Gimmiv.A in October 2008, aka "Server Service Vulnerability."
12083| [CVE-2008-4114] srv.sys in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via an SMB WRITE_ANDX packet with an offset that is inconsistent with the packet size, related to "insufficiently validating the buffer size," as demonstrated by a request to the \PIPE\lsarpc named pipe, aka "SMB Validation Denial of Service Vulnerability."
12084| [CVE-2008-4110] Buffer overflow in the SQLVDIRLib.SQLVDirControl ActiveX control in Tools\Binn\sqlvdir.dll in Microsoft SQL Server 2000 (aka SQL Server 8.0) allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a long URL in the second argument to the Connect method. NOTE: this issue is not a vulnerability in many environments, since the control is not marked as safe for scripting and would not execute with default Internet Explorer settings.
12085| [CVE-2008-4038] Buffer underflow in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via a Server Message Block (SMB) request that contains a filename with a crafted length, aka "SMB Buffer Underflow Vulnerability."
12086| [CVE-2008-4037] Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote SMB servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user, as demonstrated by backrush, aka "SMB Credential Reflection Vulnerability." NOTE: some reliable sources report that this vulnerability exists because of an insufficient fix for CVE-2000-0834.
12087| [CVE-2008-4036] Integer overflow in Memory Manager in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows local users to gain privileges via a crafted application that triggers an erroneous decrement of a variable, related to validation of parameters for Virtual Address Descriptors (VADs) and a "memory allocation mapping error," aka "Virtual Address Descriptor Elevation of Privilege Vulnerability."
12088| [CVE-2008-4032] Microsoft Office SharePoint Server 2007 Gold and SP1 and Microsoft Search Server 2008 do not properly perform authentication and authorization for administrative functions, which allows remote attackers to cause a denial of service (server load), obtain sensitive information, and "create scripts that would run in the context of the site" via requests to administrative URIs, aka "Access Control Vulnerability."
12089| [CVE-2008-4031] Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
12090| [CVE-2008-4030] Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
12091| [CVE-2008-4028] Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
12092| [CVE-2008-4027] Double free vulnerability in Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
12093| [CVE-2008-4026] Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
12094| [CVE-2008-4025] Integer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
12095| [CVE-2008-4024] Microsoft Office Word 2000 SP3 and 2002 SP3 and Office 2004 for Mac allow remote attackers to execute arbitrary code via a Word document with a crafted lcbPlcfBkfSdt field in the File Information Block (FIB), which bypasses an initialization step and triggers an "arbitrary free," aka "Word Memory Corruption Vulnerability."
12096| [CVE-2008-4023] Active Directory in Microsoft Windows 2000 SP4 does not properly allocate memory for (1) LDAP and (2) LDAPS requests, which allows remote attackers to execute arbitrary code via a crafted request, aka "Active Directory Overflow Vulnerability."
12097| [CVE-2008-4019] Integer overflow in the REPT function in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1
12098| [CVE-2008-3956] orgchart.exe in Microsoft Organization Chart 2.00 allows user-assisted attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted .opx file.
12099| [CVE-2008-3704] Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions before 6.0.84.18, in Microsoft Visual Studio 6.0, Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 allows remote attackers to execute arbitrary code via a long Mask parameter, related to not "validating property values with boundary checks," as exploited in the wild in August 2008, aka "Masked Edit Control Memory Corruption Vulnerability."
12100| [CVE-2008-3648] nslookup.exe in Microsoft Windows XP SP2 allows user-assisted remote attackers to execute arbitrary code, as demonstrated by an attempted DNS zone transfer, and as exploited in the wild in August 2008.
12101| [CVE-2008-3636] Integer overflow in the IopfCompleteRequest API in the kernel in Microsoft Windows 2000, XP, Server 2003, and Vista allows context-dependent attackers to gain privileges. NOTE: this issue was originally reported for GEARAspiWDM.sys 2.0.7.5 in Gear Software CD DVD Filter driver before 4.001.7, as used in other products including Apple iTunes and multiple Symantec and Norton products, which allows local users to gain privileges via repeated IoAttachDevice IOCTL calls to \\.\GEARAspiWDMDevice in this GEARAspiWDM.sys. However, the root cause is the integer overflow in the API call itself.
12102| [CVE-2008-3479] Heap-based buffer overflow in the Microsoft Message Queuing (MSMQ) service (mqsvc.exe) in Microsoft Windows 2000 SP4 allows remote attackers to read memory contents and execute arbitrary code via a crafted RPC call, related to improper processing of parameters to string APIs, aka "Message Queuing Service Remote Code Execution Vulnerability."
12103| [CVE-2008-3477] Microsoft Excel 2000 SP3, 2002 SP3, and 2003 SP2 and SP3 does not properly validate data in the VBA Performance Cache when processing an Office document with an embedded object, which allows remote attackers to execute arbitrary code via an Excel file containing a crafted value, leading to heap-based buffer overflows, integer overflows, array index errors, and memory corruption, aka "Calendar Object Validation Vulnerability."
12104| [CVE-2008-3471] Stack-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1
12105| [CVE-2008-3466] Microsoft Host Integration Server (HIS) 2000, 2004, and 2006 does not limit RPC access to administrative functions, which allows remote attackers to bypass authentication and execute arbitrary programs via a crafted SNA RPC message using opcode 1 or 6 to call the CreateProcess function, aka "HIS Command Execution Vulnerability."
12106| [CVE-2008-3465] Heap-based buffer overflow in an API in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows context-dependent attackers to cause a denial of service or execute arbitrary code via a WMF file with a malformed file-size parameter, which would not be properly handled by a third-party application that uses this API for a copy operation, aka "GDI Heap Overflow Vulnerability."
12107| [CVE-2008-3464] afd.sys in the Ancillary Function Driver (AFD) component in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP1 and SP2 does not properly validate input sent from user mode to the kernel, which allows local users to gain privileges via a crafted application, as demonstrated using crafted pointers and lengths that bypass intended ProbeForRead and ProbeForWrite restrictions, aka "AFD Kernel Overwrite Vulnerability."
12108| [CVE-2008-3460] WPGIMP32.FLT in Microsoft Office 2000 SP3, XP SP3, and 2003 SP2
12109| [CVE-2008-3068] Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times and IP addresses of recipients, and port-scan results, via a crafted certificate with an Authority Information Access (AIA) extension.
12110| [CVE-2008-3021] Microsoft Office 2000 SP3, XP SP3, and 2003 SP2
12111| [CVE-2008-3020] Microsoft Office 2000 SP3 and XP SP3
12112| [CVE-2008-3019] Microsoft Office 2000 SP3, XP SP3, and 2003 SP2
12113| [CVE-2008-3018] Microsoft Office 2000 SP3, XP SP3, and 2003 SP2
12114| [CVE-2008-3015] Integer overflow in gdiplus.dll in GDI+ in Microsoft Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a BMP image file with a malformed BitMapInfoHeader that triggers a buffer overflow, aka "GDI+ BMP Integer Overflow Vulnerability."
12115| [CVE-2008-3014] Buffer overflow in gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a malformed WMF image file that triggers improper memory allocation, aka "GDI+ WMF Buffer Overrun Vulnerability."
12116| [CVE-2008-3013] gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a malformed GIF image file containing many extension markers for graphic control extensions and subsequent unknown labels, aka "GDI+ GIF Parsing Vulnerability."
12117| [CVE-2008-3012] gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 does not properly perform memory allocation, which allows remote attackers to execute arbitrary code via a malformed EMF image file, aka "GDI+ EMF Memory Corruption Vulnerability."
12118| [CVE-2008-3009] Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1, 9, and 2008 do not properly use the Service Principal Name (SPN) identifier when validating replies to authentication requests, which allows remote servers to execute arbitrary code via vectors that employ NTLM credential reflection, aka "SPN Vulnerability."
12119| [CVE-2008-3007] Argument injection vulnerability in a URI handler in Microsoft Office XP SP3, 2003 SP2 and SP3, 2007 Office System Gold and SP1, and Office OneNote 2007 Gold and SP1 allow remote attackers to execute arbitrary code via a crafted onenote:// URL, aka "Uniform Resource Locator Validation Error Vulnerability."
12120| [CVE-2008-3006] Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1
12121| [CVE-2008-3005] Array index vulnerability in Microsoft Office Excel 2000 SP3 and 2002 SP3, and Office 2004 and 2008 for Mac allows remote attackers to execute arbitrary code via an Excel file with a crafted array index for a FORMAT record, aka the "Excel Index Array Vulnerability."
12122| [CVE-2008-3004] Microsoft Office Excel 2000 SP3, 2002 SP3, and 2003 SP2 and SP3
12123| [CVE-2008-3003] Microsoft Office Excel 2007 Gold and SP1 does not properly delete the PWD (password) string from connections.xml when a .xlsx file is configured not to save the remote data session password, which allows local users to obtain sensitive information and obtain access to a remote data source, aka the "Excel Credential Caching Vulnerability."
12124| [CVE-2008-2752] Microsoft Word 2000 9.0.2812 and 2003 11.8106.8172 does not properly handle unordered lists, which allows user-assisted remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .doc file. NOTE: some of these details are obtained from third party information.
12125| [CVE-2008-2540] Apple Safari on Mac OS X, and before 3.1.2 on Windows, does not prompt the user before downloading an object that has an unrecognized content type, which allows remote attackers to place malware into the (1) Desktop directory on Windows or (2) Downloads directory on Mac OS X, and subsequently allows remote attackers to execute arbitrary code on Windows by leveraging an untrusted search path vulnerability in (a) Internet Explorer 7 on Windows XP or (b) the SearchPath function in Windows XP, Vista, and Server 2003 and 2008, aka a "Carpet Bomb" and a "Blended Threat Elevation of Privilege Vulnerability," a different issue than CVE-2008-1032. NOTE: Apple considers this a vulnerability only because the Microsoft products can load application libraries from the desktop and, as of 20080619, has not covered the issue in an advisory for Mac OS X.
12126| [CVE-2008-2463] The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snapshot Viewer and Microsoft Office Access 2000 through 2003, allows remote attackers to download arbitrary files to a client machine via a crafted HTML document or e-mail message, probably involving use of the SnapshotPath and CompressedPath properties and the PrintSnapshot method. NOTE: this can be leveraged for code execution by writing to a Startup folder.
12127| [CVE-2008-2252] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate parameters sent from user mode to the kernel, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Corruption Vulnerability."
12128| [CVE-2008-2251] Double free vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows local users to gain privileges via a crafted application that makes system calls within multiple threads, aka "Windows Kernel Unhandled Exception Vulnerability." NOTE: according to Microsoft, this is not a duplicate of CVE-2008-4510.
12129| [CVE-2008-2250] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate window properties sent from a parent window to a child window during creation of a new window, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Window Creation Vulnerability."
12130| [CVE-2008-2249] Integer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via a malformed header in a crafted WMF file, which triggers a buffer overflow, aka "GDI Integer Overflow Vulnerability."
12131| [CVE-2008-2246] Microsoft Windows Vista through SP1 and Server 2008 do not properly import the default IPsec policy from a Windows Server 2003 domain to a Windows Server 2008 domain, which prevents IPsec rules from being enforced and allows remote attackers to bypass intended access restrictions.
12132| [CVE-2008-2245] Heap-based buffer overflow in the InternalOpenColorProfile function in mscms.dll in Microsoft Windows Image Color Management System (MSCMS) in the Image Color Management (ICM) component on Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted image file.
12133| [CVE-2008-2244] Microsoft Office Word 2002 SP3 allows remote attackers to execute arbitrary code via a .doc file that contains malformed data, as exploited in the wild in July 2008, and as demonstrated by attachement.doc.
12134| [CVE-2008-1898] A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and 2007, allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via an invalid WksPictureInterface property value, which triggers an improper function call.
12135| [CVE-2008-1888] Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 2.0 allows remote attackers to inject arbitrary web script or HTML via the Picture Source (aka picture object source) field in the Rich Text Editor.
12136| [CVE-2008-1547] Open redirect vulnerability in exchweb/bin/redir.asp in Microsoft Outlook Web Access (OWA) for Exchange Server 2003 SP2 (aka build 6.5.7638) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the URL parameter.
12137| [CVE-2008-1457] The Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate per-user subscriptions, which allows remote authenticated users to execute arbitrary code via a crafted event subscription request.
12138| [CVE-2008-1456] Array index vulnerability in the Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote authenticated users to execute arbitrary code via a crafted event subscription request that is used to access an array of function pointers.
12139| [CVE-2008-1455] A "memory calculation error" in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, 2003 SP2, and 2007 through SP1
12140| [CVE-2008-1454] Unspecified vulnerability in Microsoft DNS in Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008 allows remote attackers to conduct cache poisoning attacks via unknown vectors related to accepting "records from a response that is outside the remote server's authority," aka "DNS Cache Poisoning Vulnerability," a different vulnerability than CVE-2008-1447.
12141| [CVE-2008-1451] The WINS service on Microsoft Windows 2000 SP4, and Server 2003 SP1 and SP2, does not properly validate data structures in WINS network packets, which allows local users to gain privileges via a crafted packet, aka "Memory Overwrite Vulnerability."
12142| [CVE-2008-1446] Integer overflow in the Internet Printing Protocol (IPP) ISAPI extension in Microsoft Internet Information Services (IIS) 5.0 through 7.0 on Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to execute arbitrary code via an HTTP POST request that triggers an outbound IPP connection from a web server to a machine operated by the attacker, aka "Integer Overflow in IPP Service Vulnerability."
12143| [CVE-2008-1445] Active Directory on Microsoft Windows 2000 Server SP4, XP Professional SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to cause a denial of service (system hang or reboot) via a crafted LDAP request.
12144| [CVE-2008-1444] Stack-based buffer overflow in Microsoft DirectX 7.0 and 8.1 on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a Synchronized Accessible Media Interchange (SAMI) file with crafted parameters for a Class Name variable, aka the "SAMI Format Parsing Vulnerability."
12145| [CVE-2008-1441] Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to cause a denial of service (system hang) via a series of Pragmatic General Multicast (PGM) packets with invalid fragment options, aka the "PGM Malformed Fragment Vulnerability."
12146| [CVE-2008-1440] Microsoft Windows XP SP2 and SP3, and Server 2003 SP1 and SP2, does not properly validate the option length field in Pragmatic General Multicast (PGM) packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted PGM packet, aka the "PGM Invalid Length Vulnerability."
12147| [CVE-2008-1436] Microsoft Windows XP Professional SP2, Vista, and Server 2003 and 2008 does not properly assign activities to the (1) NetworkService and (2) LocalService accounts, which might allow context-dependent attackers to gain privileges by using one service process to capture a resource from a second service process that has a LocalSystem privilege-escalation ability, related to improper management of the SeImpersonatePrivilege user right, as originally reported for Internet Information Services (IIS), aka Token Kidnapping.
12148| [CVE-2008-1435] Windows Explorer in Microsoft Windows Vista up to SP1, and Server 2008, allows user-assisted remote attackers to execute arbitrary code via crafted saved-search (.search-ms) files that are not properly handled when saving, aka "Windows Saved Search Vulnerability."
12149| [CVE-2008-1434] Use-after-free vulnerability in Microsoft Word in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 Office System SP1 and earlier allows remote attackers to execute arbitrary code via an HTML document with a large number of Cascading Style Sheets (CSS) selectors, related to a "memory handling error" that triggers memory corruption.
12150| [CVE-2008-1092] Buffer overflow in msjet40.dll before 4.0.9505.0 in Microsoft Jet Database Engine allows remote attackers to execute arbitrary code via a crafted Word file, as exploited in the wild in March 2008. NOTE: as of 20080513, Microsoft has stated that this is the same issue as CVE-2007-6026.
12151| [CVE-2008-1091] Unspecified vulnerability in Microsoft Word in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 Office System SP1 and earlier allows remote attackers to execute arbitrary code via a Rich Text Format (.rtf) file with a malformed string that triggers a "memory calculation error" and a heap-based buffer overflow, aka "Object Parsing Vulnerability."
12152| [CVE-2008-1090] Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows user-assisted remote attackers to execute arbitrary code via a crafted .DXF file, aka "Visio Memory Validation Vulnerability."
12153| [CVE-2008-1089] Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows user-assisted remote attackers to execute arbitrary code via a Visio file containing crafted object header data, aka "Visio Object Header Vulnerability."
12154| [CVE-2008-1088] Microsoft Project 2000 Service Release 1, 2002 SP1, and 2003 SP2 allows user-assisted remote attackers to execute arbitrary code via a crafted Project file, related to improper validation of "memory resource allocations."
12155| [CVE-2008-1087] Stack-based buffer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to execute arbitrary code via an EMF image file with crafted filename parameters, aka "GDI Stack Overflow Vulnerability."
12156| [CVE-2008-1086] The HxTocCtrl ActiveX control (hxvz.dll), as used in Microsoft Internet Explorer 5.01 SP4 and 6 SP1, in Windows XP SP2, Server 2003 SP1 and SP2, Vista SP1, and Server 2008, allows remote attackers to execute arbitrary code via malformed arguments, which triggers memory corruption.
12157| [CVE-2008-1084] Unspecified vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, through Vista SP1, and Server 2008 allows local users to execute arbitrary code via unknown vectors related to improper input validation. NOTE: it was later reported that one affected function is NtUserFnOUTSTRING in win32k.sys.
12158| [CVE-2008-1083] Heap-based buffer overflow in the CreateDIBPatternBrushPt function in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to execute arbitrary code via an EMF or WMF image file with a malformed header that triggers an integer overflow, aka "GDI Heap Overflow Vulnerability."
12159| [CVE-2008-0121] A "memory calculation error" in Microsoft PowerPoint Viewer 2003 allows remote attackers to execute arbitrary code via a PowerPoint file with an invalid picture index that triggers memory corruption, aka "Memory Calculation Vulnerability."
12160| [CVE-2008-0120] Integer overflow in Microsoft PowerPoint Viewer 2003 allows remote attackers to execute arbitrary code via a PowerPoint file with a malformed picture index that triggers memory corruption, related to handling of CString objects, aka "Memory Allocation Vulnerability."
12161| [CVE-2008-0119] Unspecified vulnerability in Microsoft Publisher in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 SP1 and earlier allows remote attackers to execute arbitrary code via a Publisher file with crafted object header data that triggers memory corruption, aka "Publisher Object Handler Validation Vulnerability."
12162| [CVE-2008-0118] Unspecified vulnerability in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, Excel Viewer 2003 up to SP3, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption from an "allocation error," aka "Microsoft Office Memory Corruption Vulnerability."
12163| [CVE-2008-0117] Unspecified vulnerability in Microsoft Excel 2000 SP3 and 2002 SP2, and Office 2004 and 2008 for Mac, allows user-assisted remote attackers to execute arbitrary code via crafted conditional formatting values, aka "Excel Conditional Formatting Vulnerability."
12164| [CVE-2008-0116] Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, Compatibility Pack, and Office 2004 and 2008 for Mac allows user-assisted remote attackers to execute arbitrary code via malformed tags in rich text, aka "Excel Rich Text Validation Vulnerability."
12165| [CVE-2008-0115] Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2007, Viewer 2003, Compatibility Pack, and Office for Mac 2004 allows user-assisted remote attackers to execute arbitrary code via malformed formulas, aka "Excel Formula Parsing Vulnerability."
12166| [CVE-2008-0114] Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office for Mac 2004 allows user-assisted remote attackers to execute arbitrary code via crafted Style records that trigger memory corruption.
12167| [CVE-2008-0113] Unspecified vulnerability in Microsoft Office Excel Viewer 2003 up to SP3 allows user-assisted remote attackers to execute arbitrary code via an Excel document with malformed cell comments that trigger memory corruption from an "allocation error," aka "Microsoft Office Cell Parsing Memory Corruption Vulnerability."
12168| [CVE-2008-0112] Unspecified vulnerability in Microsoft Excel 2000 SP3, and Office for Mac 2004 and 2008 allows user-assisted remote attackers to execute arbitrary code via a crafted .SLK file that is not properly handled when importing the file, aka "Excel File Import Vulnerability."
12169| [CVE-2008-0111] Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2007, Viewer 2003, Compatibility Pack, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted data validation records, aka "Excel Data Validation Record Vulnerability."
12170| [CVE-2008-0110] Unspecified vulnerability in Microsoft Outlook in Office 2000 SP3, XP SP3, 2003 SP2 and Sp3, and Office System allows user-assisted remote attackers to execute arbitrary code via a crafted mailto URI.
12171| [CVE-2008-0109] Word in Microsoft Office 2000 SP3, XP SP3, Office 2003 SP2, and Office Word Viewer 2003 allows remote attackers to execute arbitrary code via crafted fields within the File Information Block (FIB) of a Word file, which triggers length calculation errors and memory corruption.
12172| [CVE-2008-0108] Stack-based buffer overflow in wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted field lengths, aka "Microsoft Works File Converter Field Length Vulnerability."
12173| [CVE-2008-0106] Buffer overflow in Microsoft SQL Server 2005 SP1 and SP2, and 2005 Express Edition SP1 and SP2, allows remote authenticated users to execute arbitrary code via a crafted insert statement.
12174| [CVE-2008-0105] Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section header index table information, aka "Microsoft Works File Converter Index Table Vulnerability."
12175| [CVE-2008-0104] Unspecified vulnerability in Microsoft Office Publisher 2000, 2002, and 2003 SP2 allows remote attackers to execute arbitrary code via a crafted .pub file, aka "Publisher Memory Corruption Vulnerability."
12176| [CVE-2008-0103] Unspecified vulnerability in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Office document that contains a malformed object, related to a "memory handling error," aka "Microsoft Office Execution Jump Vulnerability."
12177| [CVE-2008-0102] Unspecified vulnerability in Microsoft Office Publisher 2000, 2002, and 2003 SP2 allows remote attackers to execute arbitrary code via a crafted .pub file, related to invalid "memory values," aka "Publisher Invalid Memory Reference Vulnerability."
12178| [CVE-2008-0088] Unspecified vulnerability in Active Directory on Microsoft Windows 2000 and Windows Server 2003, and Active Directory Application Mode (ADAM) on XP and Server 2003, allows remote attackers to cause a denial of service (hang and restart) via a crafted LDAP request.
12179| [CVE-2008-0087] The DNS client in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, and Vista uses predictable DNS transaction IDs, which allows remote attackers to spoof DNS responses.
12180| [CVE-2008-0086] Buffer overflow in the convert function in Microsoft SQL Server 2000 SP4, 2000 Desktop Engine (MSDE 2000) SP4, and 2000 Desktop Engine (WMSDE) allows remote authenticated users to execute arbitrary code via a crafted SQL expression.
12181| [CVE-2008-0083] The (1) VBScript (VBScript.dll) and (2) JScript (JScript.dll) scripting engines 5.1 and 5.6, as used in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2, do not properly decode script, which allows remote attackers to execute arbitrary code via unknown vectors.
12182| [CVE-2008-0081] Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted macros, aka "Macro Validation Vulnerability," a different vulnerability than CVE-2007-3490.
12183| [CVE-2008-0080] Heap-based buffer overflow in the WebDAV Mini-Redirector in Microsoft Windows XP SP2, Server 2003 SP1 and SP2, and Vista allows remote attackers to execute arbitrary code via a crafted WebDAV response.
12184| [CVE-2008-0020] Unspecified vulnerability in the Load method in the IPersistStreamInit interface in the Active Template Library (ATL), as used in the Microsoft Video ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via unknown vectors that trigger memory corruption, aka "ATL Header Memcopy Vulnerability," a different vulnerability than CVE-2008-0015.
12185| [CVE-2008-0015] Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted web page, as exploited in the wild in July 2009, aka "Microsoft Video ActiveX Control Vulnerability."
12186| [CVE-2008-0011] Microsoft DirectX 8.1 through 9.0c, and DirectX on Microsoft XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008, does not properly perform MJPEG error checking, which allows remote attackers to execute arbitrary code via a crafted MJPEG stream in a (1) AVI or (2) ASF file, aka the "MJPEG Decoder Vulnerability."
12187| [CVE-2007-6753] Untrusted search path vulnerability in Shell32.dll in Microsoft Windows 2000, Windows XP, Windows Vista, Windows Server 2008, and Windows 7, when using an environment configured with a string such as %APPDATA% or %PROGRAMFILES% in a certain way, allows local users to gain privileges via a Trojan horse DLL under the current working directory, as demonstrated by iTunes and Safari.
12188| [CVE-2007-6357] Stack-based buffer overflow in Microsoft Office Access allows remote, user-assisted attackers to execute arbitrary code via a crafted Microsoft Access Database (.mdb) file. NOTE: due to the lack of details as of 20071210, it is not clear whether this issue is the same as CVE-2007-6026 or CVE-2005-0944.
12189| [CVE-2007-6329] Microsoft Office 2007 12.0.6015.5000 and MSO 12.0.6017.5000 do not sign the metadata of Office Open XML (OOXML) documents, which makes it easier for remote attackers to modify Dublin Core metadata fields, as demonstrated by the (1) LastModifiedBy and (2) creator fields in docProps/core.xml in the OOXML ZIP container.
12190| [CVE-2007-6043] The CryptGenRandom function in Microsoft Windows 2000 generates predictable values, which makes it easier for context-dependent attackers to reduce the effectiveness of cryptographic mechanisms, as demonstrated by attacks on (1) forward security and (2) backward security, related to use of eight instances of the RC4 cipher, and possibly a related issue to CVE-2007-3898.
12191| [CVE-2007-6026] Stack-based buffer overflow in Microsoft msjet40.dll 4.0.8618.0 (aka Microsoft Jet Engine), as used by Access 2003 in Microsoft Office 2003 SP3, allows user-assisted attackers to execute arbitrary code via a crafted MDB file database file containing a column structure with a modified column count. NOTE: this might be the same issue as CVE-2005-0944.
12192| [CVE-2007-5587] Buffer overflow in Macrovision SafeDisc secdrv.sys before 4.3.86.0, as shipped in Microsoft Windows XP SP2, XP Professional x64 and x64 SP2, Server 2003 SP1 and SP2, and Server 2003 x64 and x64 SP2 allows local users to overwrite arbitrary memory locations and gain privileges via a crafted argument to a METHOD_NEITHER IOCTL, as originally discovered in the wild.
12193| [CVE-2007-5352] Unspecified vulnerability in Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows local users to gain privileges via a crafted local procedure call (LPC) request.
12194| [CVE-2007-5348] Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via an image file with crafted gradient sizes in gradient fill input, which triggers a heap-based buffer overflow related to GdiPlus.dll and VGX.DLL, aka "GDI+ VML Buffer Overrun Vulnerability."
12195| [CVE-2007-4991] The SOCKS4 Proxy in Microsoft Internet Security and Acceleration (ISA) Server 2004 SP1 and SP2 allows remote attackers to obtain potentially sensitive information (the destination IP address of another user's session) via an empty packet.
12196| [CVE-2007-4916] Heap-based buffer overflow in the FileFind::FindFile method in (1) MFC42.dll, (2) MFC42u.dll, (3) MFC71.dll, and (4) MFC71u.dll in Microsoft Foundation Class (MFC) Library 8.0, as used by the ListFiles method in hpqutil.dll 2.0.0.138 in Hewlett-Packard (HP) All-in-One and Photo & Imaging Gallery 1.1 and probably other products, allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long first argument.
12197| [CVE-2007-4814] Buffer overflow in the SQLServer ActiveX control in the Distributed Management Objects OLE DLL (sqldmo.dll) 2000.085.2004.00 in Microsoft SQL Server Enterprise Manager 8.05.2004 allows remote attackers to execute arbitrary code via a long second argument to the Start method.
12198| [CVE-2007-3930] Interpretation conflict between Microsoft Internet Explorer and DocuWiki before 2007-06-26b allows remote attackers to inject arbitrary JavaScript and conduct cross-site scripting (XSS) attacks when spellchecking UTF-8 encoded messages via the spell_utf8test function in lib/exe/spellcheck.php, which triggers HTML document identification and script execution by Internet Explorer even though the Content-Type header is text/plain.
12199| [CVE-2007-3924] Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Netscape installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a -chrome argument to the navigatorurl URI, which are inserted into the command line that is created when invoking netscape.exe, a related issue to CVE-2007-3670. NOTE: there has been debate about whether the issue is in Internet Explorer or Netscape. As of 20070713, it is CVE's opinion that IE appears to not properly delimit the URL argument when invoking Netscape
12200| [CVE-2007-3899] Unspecified vulnerability in Microsoft Word 2000 SP3, Word 2002 SP3, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a malformed string in a Word file, aka "Word Memory Corruption Vulnerability."
12201| [CVE-2007-3898] The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS servers, which allows remote attackers to spoof DNS replies, poison the DNS cache, and facilitate further attack vectors.
12202| [CVE-2007-3896] The URL handling in Shell32.dll in the Windows shell in Microsoft Windows XP and Server 2003, with Internet Explorer 7 installed, allows remote attackers to execute arbitrary programs via invalid "%" sequences in a mailto: or other URI handler, as demonstrated using mIRC, Outlook, Firefox, Adobe Reader, Skype, and other applications. NOTE: this issue might be related to other issues involving URL handlers in Windows systems, such as CVE-2007-3845. There also might be separate but closely related issues in the applications that are invoked by the handlers.
12203| [CVE-2007-3890] Microsoft Excel in Office 2000 SP3, Office XP SP3, Office 2003 SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via a Workspace with a certain index value that triggers memory corruption.
12204| [CVE-2007-3670] Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Firefox installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a (1) FirefoxURL or (2) FirefoxHTML URI, which are inserted into the command line that is created when invoking firefox.exe. NOTE: it has been debated as to whether the issue is in Internet Explorer or Firefox. As of 20070711, it is CVE's opinion that IE appears to be failing to properly delimit the URL argument when invoking Firefox, and this issue could arise with other protocol handlers in IE as well. However, Mozilla has stated that it will address the issue with a "defense in depth" fix that will "prevent IE from sending Firefox malicious data."
12205| [CVE-2007-3490] Unspecified vulnerability in Microsoft Excel 2003 SP2 allows remote attackers to have an unknown impact via unspecified vectors, possibly related to the sheet name, as demonstrated by 2670.xls.
12206| [CVE-2007-3300] Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070619 allow remote attackers to bypass scanning via a crafted header in a (1) LHA or (2) RAR archive.
12207| [CVE-2007-3040] Stack-based buffer overflow in agentdpv.dll 2.0.0.3425 in Microsoft Agent on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a crafted URL to the Agent (Agent.Control) ActiveX control, which triggers an overflow within the Agent Service (agentsrv.exe) process, a different issue than CVE-2007-1205.
12208| [CVE-2007-3039] Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Windows 2000 Professional SP4, and Windows XP SP2 allows attackers to execute arbitrary code via a long string in an opnum 0x06 RPC call to port 2103. NOTE: this is remotely exploitable on Windows 2000 Server.
12209| [CVE-2007-3036] Unspecified vulnerability in the (1) Windows Services for UNIX 3.0 and 3.5, and (2) Subsystem for UNIX-based Applications in Microsoft Windows 2000, XP, Server 2003, and Vista allows local users to gain privileges via unspecified vectors related to "certain setuid binary files."
12210| [CVE-2007-3034] Integer overflow in the AttemptWrite function in Graphics Rendering Engine (GDI) on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted metafile (image) with a large record length value, which triggers a heap-based buffer overflow.
12211| [CVE-2007-3030] Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, and 2003 Viewer allows user-assisted remote attackers to execute arbitrary code via a malformed Excel file involving the "denoting [of] the start of a Workspace designation", which results in memory corruption, aka the "Workbook Memory Corruption Vulnerability".
12212| [CVE-2007-3029] Unspecified vulnerability in Microsoft Excel 2002 SP3 and 2003 SP2 allows user-assisted remote attackers to execute arbitrary code via a malformed Excel file containing multiple active worksheets, which results in memory corruption.
12213| [CVE-2007-3028] The LDAP service in Windows Active Directory in Microsoft Windows 2000 Server SP4 does not properly check "the number of convertible attributes", which allows remote attackers to cause a denial of service (service unavailability) via a crafted LDAP request, related to "client sent LDAP request logic," aka "Windows Active Directory Denial of Service Vulnerability". NOTE: this is probably a different issue than CVE-2007-0040.
12214| [CVE-2007-2999] Microsoft Windows Server 2003, when time restrictions are in effect for user accounts, generates different error messages for failed login attempts with a valid user name than for those with an invalid user name, which allows context-dependent attackers to determine valid Active Directory account names.
12215| [CVE-2007-2967] Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070522 allow remote attackers to cause a denial of service (file scanning infinite loop) via certain crafted (1) ARJ archives or (2) FSG packed files.
12216| [CVE-2007-2966] Buffer overflow in the LHA decompresion component in F-Secure anti-virus products for Microsoft Windows and Linux before 20070529 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted LHA archive, related to an integer wrap, a similar issue to CVE-2006-4335.
12217| [CVE-2007-2903] Buffer overflow in the HelpPopup method in the Microsoft Office 2000 Controllo UA di Microsoft Office ActiveX control (OUACTRL.OCX) 1.0.1.9 allows remote attackers to cause a denial of service (probably winhlp32.exe crash) via a long first argument. NOTE: it is not clear whether this issue crosses privilege boundaries.
12218| [CVE-2007-2593] The Terminal Server in Microsoft Windows 2003 Server, when using TLS, allows remote attackers to bypass SSL and self-signed certificate requirements, downgrade the server security, and possibly conduct man-in-the-middle attacks via unspecified vectors, as demonstrated using the Remote Desktop Protocol (RDP) 6.0 client. NOTE: a third party claims that the vendor may have fixed this in approximately 2006.
12219| [CVE-2007-2581] Multiple cross-site scripting (XSS) vulnerabilities in Microsoft Windows SharePoint Services 3.0 for Windows Server 2003 and Office SharePoint Server 2007 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (query string) in "every main page," as demonstrated by default.aspx.
12220| [CVE-2007-2374] Unspecified vulnerability in Microsoft Windows 2000, XP, and Server 2003 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors. NOTE: this information is based upon a vague pre-advisory with no actionable information. However, the advisory is from a reliable source.
12221| [CVE-2007-2228] rpcrt4.dll (aka the RPC runtime library) in Microsoft Windows XP SP2, XP Professional x64 Edition, Server 2003 SP1 and SP2, Server 2003 x64 Edition and x64 Edition SP2, and Vista and Vista x64 Edition allows remote attackers to cause a denial of service (RPCSS service stop and system restart) via an RPC request that uses NTLMSSP PACKET authentication with a zero-valued verification trailer signature, which triggers an invalid dereference. NOTE: this also affects Windows 2000 SP4, although the impact is an information leak.
12222| [CVE-2007-2224] Object linking and embedding (OLE) Automation, as used in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Office 2004 for Mac, and Visual Basic 6.0 allows remote attackers to execute arbitrary code via the substringData method on a TextNode object, which causes an integer overflow that leads to a buffer overflow.
12223| [CVE-2007-2221] Unspecified vulnerability in the mdsauth.dll COM object in Microsoft Windows Media Server in the Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4
12224| [CVE-2007-2219] Unspecified vulnerability in the Win32 API on Microsoft Windows 2000, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via certain parameters to an unspecified function.
12225| [CVE-2007-2218] Unspecified vulnerability in the Windows Schannel Security Package for Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2, allows remote servers to execute arbitrary code or cause a denial of service via crafted digital signatures that are processed during an SSL handshake.
12226| [CVE-2007-2217] Kodak Image Viewer in Microsoft Windows 2000 SP4, and in some cases XP SP2 and Server 2003 SP1 and SP2, allows remote attackers to execute arbitrary code via crafted image files that trigger memory corruption, as demonstrated by a certain .tif (TIFF) file.
12227| [CVE-2007-1911] Multiple unspecified vulnerabilities in Microsoft Word 2007 allow remote attackers to cause a denial of service (CPU consumption) via crafted documents, as demonstrated by (1) file798-1.doc and (2) file613-1.doc, possibly related to a buffer overflow.
12228| [CVE-2007-1910] Buffer overflow in wwlib.dll in Microsoft Word 2007 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted document, as demonstrated by file789-1.doc.
12229| [CVE-2007-1765] Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malformed ANI file, which results in memory corruption when processing cursors, animated cursors, and icons, a similar issue to CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this issue might be a duplicate of CVE-2007-0038
12230| [CVE-2007-1756] Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, and Office Excel 2007 does not properly validate version information, which allows user-assisted remote attackers to execute arbitrary code via a crafted Excel file, aka "Calculation Error Vulnerability".
12231| [CVE-2007-1754] PUBCONV.DLL in Microsoft Office Publisher 2007 does not properly clear memory when transferring data from disk to memory, which allows user-assisted remote attackers to execute arbitrary code via a malformed .pub page via a certain negative value, which bypasses a sanitization procedure that initializes critical pointers to NULL, aka the "Publisher Invalid Memory Reference Vulnerability".
12232| [CVE-2007-1748] Stack-based buffer overflow in the RPC interface in the Domain Name System (DNS) Server Service in Microsoft Windows 2000 Server SP 4, Server 2003 SP 1, and Server 2003 SP 2 allows remote attackers to execute arbitrary code via a long zone name containing character constants represented by escape sequences.
12233| [CVE-2007-1747] Unspecified vulnerability in MSO.dll in Microsoft Office 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and 2007 allows user-assisted remote attackers to execute arbitrary code via a malformed drawing object, which triggers memory corruption.
12234| [CVE-2007-1645] Buffer overflow in FutureSoft TFTP Server 2000 on Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrary code via a long request on UDP port 69. NOTE: this issue might overlap CVE-2006-4781 or CVE-2005-1812.
12235| [CVE-2007-1537] \Device\NdisTapi (NDISTAPI.sys) in Microsoft Windows XP SP2 and 2003 SP1 uses weak permissions, which allows local users to write to the device and cause a denial of service, as demonstrated by using an IRQL to acquire a spinlock on paged memory via the NdisTapiDispatch function.
12236| [CVE-2007-1512] Stack-based buffer overflow in the AfxOleSetEditMenu function in the MFC component in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 Gold and SP1, and Visual Studio .NET 2002 Gold and SP1, and 2003 Gold and SP1 allows user-assisted remote attackers to have an unknown impact (probably crash) via an RTF file with a malformed OLE object, which results in writing two 0x00 characters past the end of szBuffer, aka the "MFC42u.dll Off-by-Two Overflow." NOTE: this issue is due to an incomplete patch (MS07-012) for CVE-2007-0025.
12237| [CVE-2007-1347] Microsoft Windows Explorer on Windows 2000 SP4 FR and XP SP2 FR, and possibly other versions and platforms, allows remote attackers to cause a denial of service (memory corruption and crash) via an Office file with crafted document summary information, which causes an error in Ole32.dll.
12238| [CVE-2007-1239] Microsoft Excel 2003 does not properly parse .XLS files, which allows remote attackers to cause a denial of service (application crash) via a file with a (1) corrupted XML format or a (2) corrupted XLS format, which triggers a NULL pointer dereference.
12239| [CVE-2007-1238] Microsoft Office 2003 allows user-assisted remote attackers to cause a denial of service (application crash) by attempting to insert a corrupted WMF file.
12240| [CVE-2007-1215] Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4
12241| [CVE-2007-1214] Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, and 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a crafted AutoFilter filter record in an Excel BIFF8 format XLS file, which triggers memory corruption.
12242| [CVE-2007-1213] The TrueType Fonts rasterizer in Microsoft Windows 2000 SP4 allows local users to gain privileges via crafted TrueType fonts, which result in an uninitialized function pointer.
12243| [CVE-2007-1212] Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4
12244| [CVE-2007-1211] Unspecified kernel GDI functions in Microsoft Windows 2000 SP4
12245| [CVE-2007-1205] Unspecified vulnerability in Microsoft Agent (msagent\agentsvr.exe) in Windows 2000 SP4, XP SP2, and Server 2003, 2003 SP1, and 2003 SP2 allows remote attackers to execute arbitrary code via crafted URLs, which result in memory corruption.
12246| [CVE-2007-1203] Unspecified vulnerability in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, 2004 for Mac, and 2007 allows user-assisted remote attackers to execute arbitrary code via a crafted set font value in an Excel file, which results in memory corruption.
12247| [CVE-2007-1202] Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006 does not properly parse certain rich text "property strings of certain control words," which allows user-assisted remote attackers to trigger heap corruption and execute arbitrary code, aka the "Word RTF Parsing Vulnerability."
12248| [CVE-2007-1201] Unspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user-assisted remote attackers to execute arbitrary code via vectors related to DataSource that trigger memory corruption, aka "Office Web Components DataSource Vulnerability."
12249| [CVE-2007-1117] Unspecified vulnerability in Publisher 2007 in Microsoft Office 2007 allows remote attackers to execute arbitrary code via unspecified vectors, related to a "file format vulnerability." NOTE: this information is based upon a vague pre-advisory with no actionable information. However, the advisory is from a reliable source.
12250| [CVE-2007-1090] Microsoft Windows Explorer on Windows XP and 2003 allows remote user-assisted attackers to cause a denial of service (crash) via a malformed WMF file, which triggers the crash when the user browses the folder.
12251| [CVE-2007-1083] Buffer overflow in the Configuration Checker (ConfigChk) ActiveX control in VSCnfChk.dll 2.0.0.2 for Verisign Managed PKI Service, Secure Messaging for Microsoft Exchange, and Go Secure! allows remote attackers to execute arbitrary code via long arguments to the VerCompare method.
12252| [CVE-2007-0948] Heap-based buffer overflow in Microsoft Virtual PC 2004 and PC for Mac 7.1 and 7, and Virtual Server 2005 and 2005 R2, allows local guest OS administrators to execute arbitrary code on the host OS via unspecified vectors related to "interaction and initialization of components."
12253| [CVE-2007-0947] Use-after-free vulnerability in Microsoft Internet Explorer 7 on Windows XP SP2, Windows Server 2003 SP1 or SP2, or Windows Vista allows remote attackers to execute arbitrary code via crafted HTML objects, resulting in accessing deallocated memory of CMarkup objects, aka the second of two "HTML Objects Memory Corruption Vulnerabilities" and a different issue than CVE-2007-0946.
12254| [CVE-2007-0946] Unspecified vulnerability in Microsoft Internet Explorer 7 on Windows XP SP2, Windows Server 2003 SP1 or SP2, or Windows Vista allows remote attackers to execute arbitrary code via crafted HTML objects, which results in memory corruption, aka the first of two "HTML Objects Memory Corruption Vulnerabilities" and a different issue than CVE-2007-0947.
12255| [CVE-2007-0945] Microsoft Internet Explorer 6 SP1 on Windows 2000 SP4
12256| [CVE-2007-0944] Unspecified vulnerability in the CTableCol::OnPropertyChange method in Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4
12257| [CVE-2007-0942] Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4
12258| [CVE-2007-0940] Unspecified vulnerability in the Cryptographic API Component Object Model Certificates ActiveX control (CAPICOM.dll) in Microsoft CAPICOM and BizTalk Server 2004 SP1 and SP2 allows remote attackers to execute arbitrary code via unspecified vectors, aka the "CAPICOM.Certificates Vulnerability."
12259| [CVE-2007-0939] Cross-site scripting (XSS) vulnerability in Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving HTML redirection queries, aka "Cross-site Scripting and Spoofing Vulnerability."
12260| [CVE-2007-0938] Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 does not properly handle certain characters in a crafted HTTP GET request, which allows remote attackers to execute arbitrary code, aka the "CMS Memory Corruption Vulnerability."
12261| [CVE-2007-0936] Multiple unspecified vulnerabilities in Microsoft Visio 2002 allow remote user-assisted attackers to execute arbitrary code via a Visio (.VSD, VSS, .VST) file with a crafted packed object that triggers memory corruption, aka "Visio Document Packaging Vulnerability."
12262| [CVE-2007-0934] Unspecified vulnerability in Microsoft Visio 2002 allows remote user-assisted attackers to execute arbitrary code via a Visio (.VSD, VSS, .VST) file with a crafted version number that triggers memory corruption.
12263| [CVE-2007-0913] Unspecified vulnerability in Microsoft Powerpoint allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as exploited by Trojan.PPDropper.G. NOTE: as of 20070213, it is not clear whether this is the same issue as CVE-2006-5296, CVE-2006-4694, CVE-2006-3876, CVE-2006-3877, or older issues.
12264| [CVE-2007-0870] Unspecified vulnerability in Microsoft Word 2000 allows remote attackers to cause a denial of service (crash) via unknown vectors, a different vulnerability than CVE-2006-5994, CVE-2006-6456, CVE-2006-6561, and CVE-2007-0515, a variant of Exploit-MS06-027.
12265| [CVE-2007-0843] The ReadDirectoryChangesW API function on Microsoft Windows 2000, XP, Server 2003, and Vista does not check permissions for child objects, which allows local users to bypass permissions by opening a directory with LIST (READ) access and using ReadDirectoryChangesW to monitor changes of files that do not have LIST permissions, which can be leveraged to determine filenames, access times, and other sensitive information.
12266| [CVE-2007-0811] Microsoft Internet Explorer 6.0 SP1 on Windows 2000, and 6.0 SP2 on Windows XP, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an HTML document containing a certain JavaScript for loop with an empty loop body, possibly involving getElementById.
12267| [CVE-2007-0671] Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.
12268| [CVE-2007-0612] Multiple ActiveX controls in Microsoft Windows 2000, XP, 2003, and Vista allows remote attackers to cause a denial of service (Internet Explorer crash) by accessing the bgColor, fgColor, linkColor, alinkColor, vlinkColor, or defaultCharset properties in the (1) giffile, (2) htmlfile, (3) jpegfile, (4) mhtmlfile, (5) ODCfile, (6) pjpegfile, (7) pngfile, (8) xbmfile, (9) xmlfile, (10) xslfile, or (11) wdfile objects in (a) mshtml.dll
12269| [CVE-2007-0515] Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of service on Word 2003, via unknown attack vectors that trigger memory corruption, as exploited by Trojan.Mdropper.W and later by Trojan.Mdropper.X, a different issue than CVE-2006-6456, CVE-2006-5994, and CVE-2006-6561.
12270| [CVE-2007-0351] Microsoft Windows XP and Windows Server 2003 do not properly handle user logoff, which might allow local users to gain the privileges of a previous system user, possibly related to user profile unload failure. NOTE: it is not clear whether this is an issue in Windows itself, or an interaction with another product. The issue might involve ZoneAlarm not being able to terminate processes when it cannot prompt the user.
12271| [CVE-2007-0221] Integer overflow in the IMAP (IMAP4) support in Microsoft Exchange Server 2000 SP3 allows remote attackers to cause a denial of service (service hang) via crafted literals in an IMAP command, aka the "IMAP Literal Processing Vulnerability."
12272| [CVE-2007-0220] Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2000 SP3, and 2003 SP1 and SP2 allows remote attackers to execute arbitrary scripts, spoof content, or obtain sensitive information via certain UTF-encoded, script-based e-mail attachments, involving an "incorrectly handled UTF character set label".
12273| [CVE-2007-0216] wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section length headers, aka "Microsoft Works File Converter Input Validation Vulnerability."
12274| [CVE-2007-0215] Stack-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, and 2003 Viewer allows user-assisted remote attackers to execute arbitrary code via a .XLS BIFF file with a malformed Named Graph record, which results in memory corruption.
12275| [CVE-2007-0214] The HTML Help ActiveX control (Hhctrl.ocx) in Microsoft Windows 2000 SP3, XP SP2 and Professional, 2003 SP1 allows remote attackers to execute arbitrary code via unspecified functions, related to uninitialized parameters.
12276| [CVE-2007-0213] Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 does not properly decode certain MIME encoded e-mails, which allows remote attackers to execute arbitrary code via a crafted base64-encoded MIME e-mail message.
12277| [CVE-2007-0211] The hardware detection functionality in the Windows Shell in Microsoft Windows XP SP2 and Professional, and Server 2003 SP1 allows local users to gain privileges via an unvalidated parameter to a function related to the "detection and registration of new hardware."
12278| [CVE-2007-0209] Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a Word file with a malformed drawing object, which leads to memory corruption.
12279| [CVE-2007-0208] Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac does not correctly check the properties of certain documents and warn the user of macro content, which allows user-assisted remote attackers to execute arbitrary code.
12280| [CVE-2007-0069] Unspecified vulnerability in the kernel in Microsoft Windows XP SP2, Server 2003, and Vista allows remote attackers to cause a denial of service (CPU consumption) and possibly execute arbitrary code via crafted (1) IGMPv3 and (2) MLDv2 packets that trigger memory corruption, aka "Windows Kernel TCP/IP/IGMPv3 and MLDv2 Vulnerability."
12281| [CVE-2007-0066] The kernel in Microsoft Windows 2000 SP4, XP SP2, and Server 2003, when ICMP Router Discovery Protocol (RDP) is enabled, allows remote attackers to cause a denial of service via fragmented router advertisement ICMP packets that trigger an out-of-bounds read, aka "Windows Kernel TCP/IP/ICMP Vulnerability."
12282| [CVE-2007-0065] Heap-based buffer overflow in Object Linking and Embedding (OLE) Automation in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, Office 2004 for Mac, and Visual basic 6.0 SP6 allows remote attackers to execute arbitrary code via a crafted script request.
12283| [CVE-2007-0064] Heap-based buffer overflow in Windows Media Format Runtime 7.1, 9, 9.5, 9.5 x64 Edition, 11, and Windows Media Services 9.1 for Microsoft Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via a crafted Advanced Systems Format (ASF) file.
12284| [CVE-2007-0043] The Just In Time (JIT) Compiler service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer," probably a buffer overflow, aka ".NET JIT Compiler Vulnerability".
12285| [CVE-2007-0042] Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to access configuration files and obtain sensitive information, and possibly bypass security mechanisms that try to constrain the final substring of a string, via %00 characters, related to use of %00 as a string terminator within POSIX functions but a data character within .NET strings, aka "Null Byte Termination Vulnerability."
12286| [CVE-2007-0041] The PE Loader service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer" and unvalidated message lengths, probably a buffer overflow.
12287| [CVE-2007-0040] The LDAP service in Windows Active Directory in Microsoft Windows 2000 Server SP4, Server 2003 SP1 and SP2, Server 2003 x64 Edition and SP2, and Server 2003 for Itanium-based Systems SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted LDAP request with an unspecified number of "convertible attributes."
12288| [CVE-2007-0039] The Exchange Collaboration Data Objects (EXCDO) functionality in Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 allows remote attackers to cause a denial of service (crash) via an Internet Calendar (iCal) file containing multiple X-MICROSOFT-CDO-MODPROPS (MODPROPS) properties in which the second MODPROPS is longer than the first, which triggers a NULL pointer dereference and an unhandled exception.
12289| [CVE-2007-0038] Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a large length value in the second (or later) anih block of a RIFF .ANI, cur, or .ico file, which results in memory corruption when processing cursors, animated cursors, and icons, a variant of CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this might be a duplicate of CVE-2007-1765
12290| [CVE-2007-0035] Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006 does not properly handle data in a certain array, which allows user-assisted remote attackers to execute arbitrary code, aka the "Word Array Overflow Vulnerability."
12291| [CVE-2007-0034] Buffer overflow in the Advanced Search (Finder.exe) feature of Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted Outlook Saved Searches (OSS) file that triggers memory corruption, aka "Microsoft Outlook Advanced Find Vulnerability."
12292| [CVE-2007-0033] Microsoft Outlook 2002 and 2003 allows user-assisted remote attackers to execute arbitrary code via a malformed VEVENT record in an .iCal meeting request or ICS file.
12293| [CVE-2007-0031] Heap-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via a BIFF8 spreadsheet with a PALETTE record that contains a large number of entries.
12294| [CVE-2007-0030] Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via an Excel file with an out-of-range Column field in certain BIFF8 record types, which references arbitrary memory.
12295| [CVE-2007-0029] Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via a malformed string, aka "Excel Malformed String Vulnerability."
12296| [CVE-2007-0028] Microsoft Excel 2000, 2002, 2003, Viewer 2003, Office 2004 for Mac, and Office v.X for Mac does not properly handle certain opcodes, which allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file, which results in an "Improper Memory Access Vulnerability." NOTE: an early disclosure of this issue used CVE-2006-3432, but only CVE-2007-0028 should be used.
12297| [CVE-2007-0027] Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via malformed IMDATA records that trigger memory corruption.
12298| [CVE-2007-0026] The OLE Dialog component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption.
12299| [CVE-2007-0025] The MFC component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 and Visual Studio .NET 2000, 2002 SP1, 2003, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption. NOTE: this might be due to a stack-based buffer overflow in the AfxOleSetEditMenu function in MFC42u.dll.
12300| [CVE-2007-0024] Integer overflow in the Vector Markup Language (VML) implementation (vgx.dll) in Microsoft Internet Explorer 5.01, 6, and 7 on Windows 2000 SP4, XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted web page that contains unspecified integer properties that cause insufficient memory allocation and trigger a buffer overflow, aka the "VML Buffer Overrun Vulnerability."
12301| [CVE-2006-7210] Microsoft Windows 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (cpu consumption) via a PNG image with crafted (1) Width and (2) Height values in the IHDR block.
12302| [CVE-2006-7192] Microsoft ASP .NET Framework 2.0.50727.42 does not properly handle comment (/* */) enclosures, which allows remote attackers to bypass request filtering and conduct cross-site scripting (XSS) attacks, or cause a denial of service, as demonstrated via an xss:expression STYLE attribute in a closing XSS HTML tag.
12303| [CVE-2006-7027] Microsoft Internet Security and Acceleration (ISA) Server 2004 logs unusual ASCII characters in the Host header, including the tab, which allows remote attackers to manipulate portions of the log file and possibly leverage this for other attacks.
12304| [CVE-2006-6723] The Workstation service in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to cause a denial of service (memory consumption) via a large maxlen value in an NetrWkstaUserEnum RPC request.
12305| [CVE-2006-6696] Double free vulnerability in Microsoft Windows 2000, XP, 2003, and Vista allows local users to gain privileges by calling the MessageBox function with a MB_SERVICE_NOTIFICATION message with crafted data, which sends a HardError message to Client/Server Runtime Server Subsystem (CSRSS) process, which is not properly handled when invoking the UserHardError and GetHardErrorText functions in WINSRV.DLL.
12306| [CVE-2006-6617] projectserver/logon/pdsrequest.asp in Microsoft Project Server 2003 allows remote authenticated users to obtain the MSProjectUser password for a SQL database via a GetInitializationData request, which includes the information in the UserName and Password tags of the response.
12307| [CVE-2006-6561] Unspecified vulnerability in Microsoft Word 2000, 2002, and Word Viewer 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted DOC file that triggers memory corruption, as demonstrated via the 12122006-djtest.doc file, a different issue than CVE-2006-5994 and CVE-2006-6456.
12308| [CVE-2006-6456] Unspecified vulnerability in Microsoft Word 2000, 2002, and 2003 and Word Viewer 2003 allows remote attackers to execute code via unspecified vectors related to malformed data structures that trigger memory corruption, a different vulnerability than CVE-2006-5994.
12309| [CVE-2006-6296] The RpcGetPrinterData function in the Print Spooler (spoolsv.exe) service in Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 and earlier, allows remote attackers to cause a denial of service (memory consumption) via an RPC request that specifies a large 'offered' value (output buffer size), a variant of CVE-2005-3644.
12310| [CVE-2006-6134] Heap-based buffer overflow in the WMCheckURLScheme function in WMVCORE.DLL in Microsoft Windows Media Player (WMP) 10.00.00.4036 on Windows XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via a long HREF attribute, using an unrecognized protocol, in a REF element in an ASX PlayList file.
12311| [CVE-2006-6133] Stack-based buffer overflow in Visual Studio Crystal Reports for Microsoft Visual Studio .NET 2002 and 2002 SP1, .NET 2003 and 2003 SP1, and 2005 and 2005 SP1 (formerly Business Objects Crystal Reports XI Professional) allows user-assisted remote attackers to execute arbitrary code via a crafted RPT file.
12312| [CVE-2006-5994] Unspecified vulnerability in Microsoft Word 2000 and 2002, Office Word and Word Viewer 2003, Word 2004 and 2004 v. X for Mac, and Works 2004, 2005, and 2006 allows remote attackers to execute arbitrary code via a Word document with a malformed string that triggers memory corruption, a different vulnerability than CVE-2006-6456.
12313| [CVE-2006-5758] The Graphics Rendering Engine in Microsoft Windows 2000 through 2000 SP4 and Windows XP through SP2 maps GDI Kernel structures on a global shared memory section that is mapped with read-only permissions, but can be remapped by other processes as read-write, which allows local users to cause a denial of service (memory corruption and crash) and gain privileges by modifying the kernel structures.
12314| [CVE-2006-5586] The Graphics Rendering Engine in Microsoft Windows 2000 SP4 and XP SP2 allows local users to gain privileges via "invalid application window sizes" in layered application windows, aka the "GDI Invalid Window Size Elevation of Privilege Vulnerability."
12315| [CVE-2006-5585] The Client-Server Run-time Subsystem in Microsoft Windows XP SP2 and Server 2003 allows local users to gain privileges via a crafted file manifest within an application, aka "File Manifest Corruption Vulnerability."
12316| [CVE-2006-5584] The Remote Installation Service (RIS) in Microsoft Windows 2000 SP4 uses a TFTP server that allows anonymous access, which allows remote attackers to upload and overwrite arbitrary files to gain privileges on systems that use RIS.
12317| [CVE-2006-5583] Buffer overflow in the SNMP Service in Microsoft Windows 2000 SP4, XP SP2, Server 2003, Server 2003 SP1, and possibly other versions allows remote attackers to execute arbitrary code via a crafted SNMP packet, aka "SNMP Memory Corruption Vulnerability."
12318| [CVE-2006-5574] Unspecified vulnerability in the Brazilian Portuguese Grammar Checker in Microsoft Office 2003 and the Multilingual Interface for Office 2003, Project 2003, and Visio 2003 allows user-assisted remote attackers to execute arbitrary code via crafted text that is not properly parsed.
12319| [CVE-2006-5296] PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record length, which allows user-assisted attackers to cause a denial of service (NULL dereference and application crash) via a crafted PowerPoint (.PPT) file, as demonstrated by Nanika.ppt, and a different vulnerability than CVE-2006-3435, CVE-2006-3876, CVE-2006-3877, and CVE-2006-4694. NOTE: the impact of this issue was originally claimed to be arbitrary code execution, but later analysis demonstrated that this was erroneous.
12320| [CVE-2006-4854] ** REJECT ** Unspecified vulnerability in Microsoft Office 2000 (Chinese Edition) and Microsoft PowerPoint 2000 (Chinese Edition) allows user-assisted attackers to execute arbitrary code via a crafted PPT document, as exploited by malware such as Trojan.PPDropper.E. NOTE: on 20060919, Microsoft notified CVE that this is a duplicate of CVE-2006-0009.
12321| [CVE-2006-4704] Cross-zone scripting vulnerability in the WMI Object Broker (WMIScriptUtils.WMIObjectBroker2) ActiveX control (WmiScriptUtils.dll) in Microsoft Visual Studio 2005 allows remote attackers to bypass Internet zone restrictions and execute arbitrary code by instantiating dangerous objects, aka "WMI Object Broker Vulnerability."
12322| [CVE-2006-4702] Buffer overflow in the Windows Media Format Runtime in Microsoft Windows Media Player (WMP) 6.4 and Windows XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted Advanced Systems Format (ASF) file.
12323| [CVE-2006-4696] Unspecified vulnerability in the Server service in Microsoft Windows 2000 SP4, Server 2003 SP1 and earlier, and XP SP2 and earlier allows remote attackers to execute arbitrary code via a crafted packet, aka "SMB Rename Vulnerability."
12324| [CVE-2006-4695] Unspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user-assisted remote attackers to execute arbitrary code via a crafted URL, aka "Office Web Components URL Parsing Vulnerability."
12325| [CVE-2006-4694] Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office XP and Office 2003 allows user-assisted attackers to execute arbitrary code via a crafted record in a PPT file, as exploited by malware such as Exploit:Win32/Controlppt.W, Exploit:Win32/Controlppt.X, and Exploit-PPT.d/Trojan.PPDropper.F. NOTE: it has been reported that the attack vector involves SlideShowWindows.View.GotoNamedShow.
12326| [CVE-2006-4693] Unspecified vulnerability in Microsoft Word 2004 for Mac and v.X for Mac allows remote user-assisted attackers to execute arbitrary code via a crafted string in a Word file, a different issue than CVE-2006-3647 and CVE-2006-3651.
12327| [CVE-2006-4692] Argument injection vulnerability in the Windows Object Packager (packager.exe) in Microsoft Windows XP SP1 and SP2 and Server 2003 SP1 and earlier allows remote user-assisted attackers to execute arbitrary commands via a crafted file with a "/" (slash) character in the filename of the Command Line property, followed by a valid file extension, which causes the command before the slash to be executed, aka "Object Packager Dialogue Spoofing Vulnerability."
12328| [CVE-2006-4691] Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to execute arbitrary code via NetrJoinDomain2 RPC messages with a long hostname.
12329| [CVE-2006-4689] Unspecified vulnerability in the driver for the Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to cause a denial of service (hang and reboot) via has unknown attack vectors, aka "NetWare Driver Denial of Service Vulnerability."
12330| [CVE-2006-4688] Buffer overflow in Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via crafted messages, aka "Client Service for NetWare Memory Corruption Vulnerability."
12331| [CVE-2006-4534] Unspecified vulnerability in Microsoft Word 2000, 2002, and Office 2003 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors involving a crafted file resulting in a malformed stack, as exploited by malware with names including Trojan.Mdropper.Q, Mofei, and Femo.
12332| [CVE-2006-4495] Microsoft Internet Explorer allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Windows 2000 ActiveX COM Objects including (1) ciodm.dll, (2) myinfo.dll, (3) msdxm.ocx, and (4) creator.dll.
12333| [CVE-2006-4274] ** REJECT ** Unknown vulnerability in Microsoft PowerPoint allows user-assisted attackers to execute arbitrary code via a crafted PPT document, as exploited by malware such as TROJ_MDROPPER.BH. NOTE: on 20060822, it was determined that TROJ_MDROPPER.BH was exploiting CVE-2006-0009, so this is not a new vulnerability.
12334| [CVE-2006-4219] The Terminal Services COM object (tsuserex.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by instantiating it as an ActiveX object in Internet Explorer 6.0 SP1 on Microsoft Windows 2003 EE SP1 CN.
12335| [CVE-2006-4183] Heap-based buffer overflow in Microsoft DirectX SDK (February 2006) and probably earlier, including 9.0c End User Runtimes, allows context-dependent attackers to execute arbitrary code via a crafted Targa file with a run-length-encoding (RLE) compression that produces more data than expected when decoding.
12336| [CVE-2006-4071] Sign extension vulnerability in the createBrushIndirect function in the GDI library (gdi32.dll) in Microsoft Windows XP, Server 2003, and possibly other versions, allows user-assisted attackers to cause a denial of service (application crash) via a crafted WMF file.
12337| [CVE-2006-3992] Unspecified vulnerability in the Centrino (1) w22n50.sys, (2) w22n51.sys, (3) w29n50.sys, and (4) w29n51.sys Microsoft Windows drivers for Intel 2200BG and 2915ABG PRO/Wireless Network Connection before 10.5 with driver 9.0.4.16 allows remote attackers to execute arbitrary code via certain frames that trigger memory corruption.
12338| [CVE-2006-3942] The server driver (srv.sys) in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (system crash) via an SMB_COM_TRANSACTION SMB message that contains a string without null character termination, which leads to a NULL dereference in the ExecuteTransaction function, possibly related to an "SMB PIPE," aka the "Mailslot DOS" vulnerability. NOTE: the name "Mailslot DOS" was derived from incomplete initial research
12339| [CVE-2006-3897] Stack overflow in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a denial of service (application crash) by creating an NMSA.ASFSourceMediaDescription.1 ActiveX object with a long dispValue property.
12340| [CVE-2006-3880] ** DISPUTED ** Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Small Business Server 2003 allow remote attackers to cause a denial of service (IP stack hang) via a continuous stream of packets on TCP port 135 that have incorrect TCP header checksums and random numbers in certain TCP header fields, as demonstrated by the Achilles Windows Attack Tool. NOTE: the researcher reports that the Microsoft Security Response Center has stated "Our investigation which has included code review, review of the TCPDump, and attempts on reproing the issue on multiple fresh installs of various Windows Operating Systems have all resulted in non confirmation."
12341| [CVE-2006-3877] Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via an unspecified "crafted file," a different vulnerability than CVE-2006-3435, CVE-2006-4694, and CVE-2006-3876.
12342| [CVE-2006-3876] Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via a crafted Data record in a PPT file, a different vulnerability than CVE-2006-3435 and CVE-2006-4694.
12343| [CVE-2006-3875] Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, and Excel Viewer 2003 allows user-assisted attackers to execute arbitrary code via a crafted COLINFO record in an XLS file, a different vulnerability than CVE-2006-2387 and CVE-2006-3867.
12344| [CVE-2006-3873] Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP SP1, with versions the MS06-042 patch before 20060912, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL in a GZIP-encoded website that was the target of an HTTP redirect, due to an incomplete fix for CVE-2006-3869.
12345| [CVE-2006-3869] Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP SP1, with versions the MS06-042 patch before 20060824, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL on a website that uses HTTP 1.1 compression.
12346| [CVE-2006-3868] Unspecified vulnerability in Microsoft Office XP and 2003 allows remote user-assisted attackers to execute arbitrary code via a malformed Smart Tag.
12347| [CVE-2006-3867] Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, and Excel Viewer 2003 allows user-assisted attackers to execute arbitrary code via a crafted Lotus 1-2-3 file, a different vulnerability than CVE-2006-2387 and CVE-2006-3875.
12348| [CVE-2006-3864] Unspecified vulnerability in mso.dll in Microsoft Office 2000, XP, and 2003, and Microsoft PowerPoint 2000, XP, and 2003, allows remote user-assisted attackers to execute arbitrary code via a malformed record in a (1) .DOC, (2) .PPT, or (3) .XLS file that triggers memory corruption, related to an "array boundary condition" (possibly an array index overflow), a different vulnerability than CVE-2006-3434, CVE-2006-3650, and CVE-2006-3868.
12349| [CVE-2006-3841] Cross-site scripting (XSS) vulnerability in WebScarab before 20060718-1904, when used with Microsoft Internet Explorer 6 SP2 or Konqueror 3.5.3, allows remote attackers to inject arbitrary web script or HTML via the URL, which is not sanitized before being returned in an error message when WebScarab is not able to access the URL.
12350| [CVE-2006-3660] Unspecified vulnerability in Microsoft PowerPoint 2003 has unknown impact and user-assisted attack vectors related to powerpnt.exe. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3655, CVE-2006-3656, and CVE-2006-3590, although it is possible that they are all different.
12351| [CVE-2006-3656] Unspecified vulnerability in Microsoft PowerPoint 2003 allows user-assisted attackers to cause memory corruption via a crafted PowerPoint file, which triggers the corruption when the file is closed. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3655, CVE-2006-3660, and CVE-2006-3590, although it is possible that they are all different.
12352| [CVE-2006-3655] Unspecified vulnerability in mso.dll in Microsoft PowerPoint 2003 allows user-assisted attackers to execute arbitrary code via a crafted PowerPoint file. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3656, CVE-2006-3660, and CVE-2006-3590, although it is possible that they are all different.
12353| [CVE-2006-3652] Microsoft Internet Security and Acceleration (ISA) Server 2004 allows remote attackers to bypass file extension filters via a request with a trailing "#" character. NOTE: as of 20060715, this could not be reproduced by third parties.
12354| [CVE-2006-3651] Unspecified vulnerability in Microsoft Word 2000, 2002, and Office 2003 allows remote user-assisted attackers to execute arbitrary code via a crafted mail merge file, a different vulnerability than CVE-2006-3647 and CVE-2006-4693.
12355| [CVE-2006-3650] Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac do not properly parse the length of a chart record, which allows remote user-assisted attackers to execute arbitrary code via a Word document with an embedded malformed chart record that triggers an overwrite of pointer values with values from the document, a different vulnerability than CVE-2006-3434, CVE-2006-3864, and CVE-2006-3868.
12356| [CVE-2006-3649] Buffer overflow in Microsoft Visual Basic for Applications (VBA) SDK 6.0 through 6.4, as used by Microsoft Office 2000 SP3, Office XP SP3, Project 2000 SR1, Project 2002 SP1, Access 2000 Runtime SP3, Visio 2002 SP2, and Works Suite 2004 through 2006, allows user-assisted attackers to execute arbitrary code via unspecified document properties that are not verified when VBA is invoked to open documents.
12357| [CVE-2006-3648] Unspecified vulnerability in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 and 2003 SP1, allows remote attackers to execute arbitrary code via unspecified vectors involving unhandled exceptions, memory resident applications, and incorrectly "unloading chained exception."
12358| [CVE-2006-3647] Integer overflow in Microsoft Word 2000, 2002, 2003, 2004 for Mac, and v.X for Mac allows remote user-assisted attackers to execute arbitrary code via a crafted string in a Word document, which overflows a 16-bit integer length value, aka "Memmove Code Execution," a different vulnerability than CVE-2006-3651 and CVE-2006-4693.
12359| [CVE-2006-3643] Cross-site scripting (XSS) vulnerability in Internet Explorer 5.01 and 6 in Microsoft Windows 2000 SP4 permits access to local "HTML-embedded resource files" in the Microsoft Management Console (MMC) library, which allows remote authenticated users to execute arbitrary commands, aka "MMC Redirect Cross-Site Scripting Vulnerability."
12360| [CVE-2006-3590] mso.dll, as used by Microsoft PowerPoint 2000 through 2003, allows user-assisted attackers to execute arbitrary commands via a malformed shape container in a PPT file that leads to memory corruption, as exploited by Trojan.PPDropper.B, a different issue than CVE-2006-1540 and CVE-2006-3493.
12361| [CVE-2006-3510] The Remote Data Service Object (RDS.DataControl) in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a denial of service (crash) via a series of operations that result in an invalid length calculation when using SysAllocStringLen, then triggers a buffer over-read.
12362| [CVE-2006-3493] Buffer overflow in LsCreateLine function (mso_203) in mso.dll and mso9.dll, as used by Microsoft Word and possibly other products in Microsoft Office 2003, 2002, and 2000, allows remote user-assisted attackers to cause a denial of service (crash) via a crafted Word DOC or other Office file type. NOTE: this issue was originally reported to allow code execution, but on 20060710 Microsoft stated that code execution is not possible, and the original researcher agrees.
12363| [CVE-2006-3449] Unspecified vulnerability in Microsoft PowerPoint 2000 through 2003, possibly a buffer overflow, allows user-assisted remote attackers to execute arbitrary commands via a malformed record in the BIFF file format used in a PPT file, a different issue than CVE-2006-1540, aka "Microsoft PowerPoint Malformed Record Vulnerability."
12364| [CVE-2006-3448] Buffer overflow in the Step-by-Step Interactive Training in Microsoft Windows 2000 SP4, XP SP2 and Professional, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a long Syllabus string in crafted bookmark link files (cbo, cbl, or .cbm), a different issue than CVE-2005-1212.
12365| [CVE-2006-3445] Integer overflow in the ReadWideString function in agentdpv.dll in Microsoft Agent on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a large length value in an .ACF file, which results in a heap-based buffer overflow.
12366| [CVE-2006-3444] Unspecified vulnerability in the kernel in Microsoft Windows 2000 SP4, probably a buffer overflow, allows local users to obtain privileges via unspecified vectors involving an "unchecked buffer."
12367| [CVE-2006-3443] Untrusted search path vulnerability in Winlogon in Microsoft Windows 2000 SP4, when SafeDllSearchMode is disabled, allows local users to gain privileges via a malicious DLL in the UserProfile directory, aka "User Profile Elevation of Privilege Vulnerability."
12368| [CVE-2006-3441] Buffer overflow in the DNS Client service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted record response. NOTE: while MS06-041 implies that there is a single issue, there are multiple vectors, and likely multiple vulnerabilities, related to (1) a heap-based buffer overflow in a DNS server response to the client, (2) a DNS server response with malformed ATMA records, and (3) a length miscalculation in TXT, HINFO, X25, and ISDN records.
12369| [CVE-2006-3440] Buffer overflow in the Winsock API in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka "Winsock Hostname Vulnerability."
12370| [CVE-2006-3439] Buffer overflow in the Server Service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers, including anonymous users, to execute arbitrary code via a crafted RPC message, a different vulnerability than CVE-2006-1314.
12371| [CVE-2006-3436] Cross-site scripting (XSS) vulnerability in Microsoft .NET Framework 2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving "ASP.NET controls that set the AutoPostBack property to true".
12372| [CVE-2006-3435] PowerPoint in Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac does not properly parse the slide notes field in a document, which allows remote user-assisted attackers to execute arbitrary code via crafted data in this field, which triggers an erroneous object pointer calculation that uses data from within the document. NOTE: this issue is different than other PowerPoint vulnerabilities including CVE-2006-4694.
12373| [CVE-2006-3434] Unspecified vulnerability in Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac allows remote user-assisted attackers to execute arbitrary code via a crafted string that triggers memory corruption.
12374| [CVE-2006-3431] Buffer overflow in certain Asian language versions of Microsoft Excel might allow user-assisted attackers to execute arbitrary code via a crafted STYLE record in a spreadsheet that triggers the overflow when the user attempts to repair the document or selects the "Style" option, as demonstrated by nanika.xls. NOTE: Microsoft has confirmed to CVE via e-mail that this is different than the other Excel vulnerabilities announced before 20060707, including CVE-2006-3059 and CVE-2006-3086.
12375| [CVE-2006-3059] Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors. NOTE: this is a different vulnerability than CVE-2006-3086.
12376| [CVE-2006-2492] Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 20060519 for a zero-day attack.
12377| [CVE-2006-2389] Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via an Office file with a malformed property that triggers memory corruption related to record lengths, aka "Microsoft Office Property Vulnerability," a different vulnerability than CVE-2006-1316.
12378| [CVE-2006-2388] Microsoft Office Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via malformed cell comments, which lead to modification of "critical data offsets" during the rebuilding process.
12379| [CVE-2006-2387] Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, Excel Viewer 2003, and Microsoft Works Suite 2004 through 2006 allows user-assisted attackers to execute arbitrary code via a crafted DATETIME record in an XLS file, a different vulnerability than CVE-2006-3867 and CVE-2006-3875.
12380| [CVE-2006-2380] Microsoft Windows 2000 SP4 does not properly validate an RPC server during mutual authentication over SSL, which allows remote attackers to spoof an RPC server, aka the "RPC Mutual Authentication Vulnerability."
12381| [CVE-2006-2379] Buffer overflow in the TCP/IP Protocol driver in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via unknown vectors related to IP source routing.
12382| [CVE-2006-2378] Buffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and Sp2, Server 2003 SP1 and earlier, and Windows 98 and Me allows remote attackers to execute arbitrary code via a crafted ART image that causes heap corruption.
12383| [CVE-2006-2374] The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to cause a denial of service (hang) by calling the MrxSmbCscIoctlCloseForCopyChunk with the file handle of the shadow device, which results in a deadlock, aka the "SMB Invalid Handle Vulnerability."
12384| [CVE-2006-2373] The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to execute arbitrary code by calling the MrxSmbCscIoctlOpenForCopyChunk function with the METHOD_NEITHER method flag and an arbitrary address, possibly for kernel memory, aka the "SMB Driver Elevation of Privilege Vulnerability."
12385| [CVE-2006-2372] Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a crafted DHCP response.
12386| [CVE-2006-2371] Buffer overflow in the Remote Access Connection Manager service (RASMAN) service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," that lead to registry corruption and stack corruption, aka the "RASMAN Registry Corruption Vulnerability."
12387| [CVE-2006-2370] Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," aka the "RRAS Memory Corruption Vulnerability."
12388| [CVE-2006-2334] The RtlDosPathNameToNtPathName_U API function in NTDLL.DLL in Microsoft Windows 2000 SP4 and XP SP2 does not properly convert DOS style paths with trailing spaces into NT style paths, which allows context-dependent attackers to create files that cannot be accessed through the expected DOS path or prevent access to other similarly named files in the same directory, which prevents those files from being detected or disinfected by certain anti-virus and anti-spyware software.
12389| [CVE-2006-2094] Microsoft Internet Explorer before Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1, when Prompt is configured in Security Settings, uses modal dialogs to verify that a user wishes to run an ActiveX control or perform other risky actions, which allows user-assisted remote attackers to construct a race condition that tricks a user into clicking an object or pressing keys that are actually applied to a "Yes" approval for executing the control.
12390| [CVE-2006-2055] Argument injection vulnerability in Microsoft Outlook 2003 SP1 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via " (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft Outlook with an arbitrary filename as an attachment. NOTE: it is not clear whether this issue is implementation-specific or a problem in the Microsoft API.
12391| [CVE-2006-1654] Directory traversal vulnerability in the HP Color LaserJet 2500 Toolbox and Color LaserJet 4600 Toolbox on Microsoft Windows before 20060402 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request to TCP port 5225.
12392| [CVE-2006-1651] ** DISPUTED ** Microsoft ISA Server 2004 allows remote attackers to bypass certain filtering rules, including ones for (1) ICMP and (2) TCP, via IPv6 packets. NOTE: An established researcher has disputed this issue, saying that "Neither ISA Server 2004 nor Windows 2003 Basic Firewall support IPv6 filtering ... This is different network protocol."
12393| [CVE-2006-1540] MSO.DLL in Microsoft Office 2000, Office XP (2002), and Office 2003 allows user-assisted attackers to cause a denial of service and execute arbitrary code via multiple attack vectors, as originally demonstrated using a crafted document record with a malformed string, as demonstrated by replacing a certain "01 00 00 00" byte sequence with an "FF FF FF FF" byte sequence, possibly causing an invalid array index, in (1) an Excel .xls document, which triggers an access violation in ole32.dll
12394| [CVE-2006-1316] Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via an Office file with malformed string that triggers memory corruption related to record lengths, aka "Microsoft Office Parsing Vulnerability," a different vulnerability than CVE-2006-2389.
12395| [CVE-2006-1315] The Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to obtain sensitive information via crafted requests that leak information in SMB buffers, which are not properly initialized, aka "SMB Information Disclosure Vulnerability."
12396| [CVE-2006-1314] Heap-based buffer overflow in the Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to execute arbitrary code via crafted first-class Mailslot messages that triggers memory corruption and bypasses size restrictions on second-class Mailslot messages.
12397| [CVE-2006-1313] Microsoft JScript 5.1, 5.5, and 5.6 on Windows 2000 SP4, and 5.6 on Windows XP, Server 2003, Windows 98 and Windows Me, will "release objects early" in certain cases, which results in memory corruption and allows remote attackers to execute arbitrary code.
12398| [CVE-2006-1311] The RichEdit component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1
12399| [CVE-2006-1309] Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted LABEL record that triggers memory corruption.
12400| [CVE-2006-1308] Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted FNGROUPCOUNT value.
12401| [CVE-2006-1306] Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted BIFF record with an attacker-controlled array index that is used for a function pointer, aka "Malformed OBJECT record Vulnerability."
12402| [CVE-2006-1305] Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to cause a denial of service (memory exhaustion and interrupted mail recovery) via malformed e-mail header information, possibly related to (1) long subject lines or (2) large numbers of recipients in To or CC headers.
12403| [CVE-2006-1304] Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted COLINFO record, which triggers the overflow during a "data filling operation."
12404| [CVE-2006-1302] Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with certain crafted fields in a SELECTION record, which triggers memory corruption, aka "Malformed SELECTION record Vulnerability."
12405| [CVE-2006-1301] Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted SELECTION record that triggers memory corruption, a different vulnerability than CVE-2006-1302.
12406| [CVE-2006-1300] Microsoft .NET framework 2.0 (ASP.NET) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to bypass access restrictions via unspecified "URL paths" that can access Application Folder objects "explicitly by name."
12407| [CVE-2006-1257] The sample files in the authfiles directory in Microsoft Commerce Server 2002 before SP2 allow remote attackers to bypass authentication by logging in to authfiles/login.asp with a valid username and any password, then going to the main site twice.
12408| [CVE-2006-1193] Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2000 SP1 through SP3, when running Outlook Web Access (OWA), allows user-assisted remote attackers to inject arbitrary HTML or web script via unknown vectors related to "HTML parsing."
12409| [CVE-2006-1184] Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0, 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to cause a denial of service (crash) via a BuildContextW request with a large (1) UuidString or (2) GuidIn of a certain length, which causes an out-of-range memory access, aka the MSDTC Denial of Service Vulnerability. NOTE: this is a variant of CVE-2005-2119.
12410| [CVE-2006-0988] The default configuration of the DNS Server service on Windows Server 2003 and Windows 2000, and the Microsoft DNS Server service on Windows NT 4.0, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed source IP addresses.
12411| [CVE-2006-0935] Microsoft Word 2003 allows remote attackers to cause a denial of service (application crash) via a crafted file, as demonstrated by 101_filefuzz.
12412| [CVE-2006-0187] By design, Microsoft Visual Studio 2005 automatically executes code in the Load event of a user-defined control (UserControl1_Load function), which allows user-assisted attackers to execute arbitrary code by tricking the user into opening a malicious Visual Studio project file.
12413| [CVE-2006-0034] Heap-based buffer overflow in the CRpcIoManagerServer::BuildContext function in msdtcprx.dll for Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0 and Windows 2000 SP2 and SP3 allows remote attackers to execute arbitrary code via a long fifth argument to the BuildContextW or BuildContext opcode, which triggers a bug in the NdrAllocate function, aka the MSDTC Invalid Memory Access Vulnerability.
12414| [CVE-2006-0033] Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted PNG image that triggers memory corruption when it is parsed.
12415| [CVE-2006-0032] Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL, which is injected into an error message whose charset is set to UTF-7.
12416| [CVE-2006-0031] Stack-based buffer overflow in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed record with a modified length value, which leads to memory corruption.
12417| [CVE-2006-0030] Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed graphic, which leads to memory corruption.
12418| [CVE-2006-0029] Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed description, which leads to memory corruption.
12419| [CVE-2006-0028] Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via a BIFF parsing format file containing malformed BOOLERR records that lead to memory corruption, probably involving invalid pointers.
12420| [CVE-2006-0023] Microsoft Windows XP SP1 and SP2 before August 2004, and possibly other operating systems and versions, uses insecure default ACLs that allow the Authenticated Users group to gain privileges by modifying critical configuration information for the (1) Simple Service Discovery Protocol (SSDP), (2) Universal Plug and Play Device Host (UPnP), (3) NetBT, (4) SCardSvr, (5) DHCP, and (6) DnsCache services, aka "Permissive Windows Services DACLs." NOTE: the NetBT, SCardSvr, DHCP, DnsCache already require privileged access to exploit.
12421| [CVE-2006-0022] Unspecified vulnerability in Microsoft PowerPoint in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP1 and SP2, Office 2004 for Mac, and v. X for Mac allows user-assisted attackers to execute arbitrary code via a PowerPoint document with a malformed record, which triggers memory corruption.
12422| [CVE-2006-0021] Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang) via an IGMP packet with an invalid IP option, aka the "IGMP v3 DoS Vulnerability."
12423| [CVE-2006-0020] An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a crafted WMF file with a manipulated WMF header size, possibly involving an integer overflow, a different vulnerability than CVE-2005-4560, and aka "WMF Image Parsing Memory Corruption Vulnerability."
12424| [CVE-2006-0015] Cross-site scripting (XSS) vulnerability in _vti_bin/_vti_adm/fpadmdll.dll in Microsoft FrontPage Server Extensions 2002 and SharePoint Team Services allows remote attackers to inject arbitrary web script or HTML, then leverage the attack to execute arbitrary programs or create new accounts, via the (1) operation, (2) command, and (3) name parameters.
12425| [CVE-2006-0013] Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote authenticated users or Guests to execute arbitrary code via crafted RPC requests, a different vulnerability than CVE-2005-1207.
12426| [CVE-2006-0012] Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and "crafted files and directories," aka the "Windows Shell Vulnerability."
12427| [CVE-2006-0010] Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.
12428| [CVE-2006-0009] Buffer overflow in Microsoft Office 2000 SP3, XP SP3, and other versions and packages, allows user-assisted attackers to execute arbitrary code via a routing slip that is longer than specified by the provided length field, as exploited by malware such as TROJ_MDROPPER.BH and Trojan.PPDropper.E in attacks against PowerPoint.
12429| [CVE-2006-0008] The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program that displays the about box.
12430| [CVE-2006-0007] Buffer overflow in GIFIMP32.FLT, as used in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted GIF image that triggers memory corruption when it is parsed.
12431| [CVE-2006-0006] Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap (.BMP) file that specifies a size of 0 but contains additional data.
12432| [CVE-2006-0004] Microsoft PowerPoint 2000 in Office 2000 SP3 has an interaction with Internet Explorer that allows remote attackers to obtain sensitive information via a PowerPoint presentation that attempts to access objects in the Temporary Internet Files Folder (TIFF).
12433| [CVE-2006-0002] Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.
12434| [CVE-2006-0001] Stack-based buffer overflow in Microsoft Publisher 2000 through 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted PUB file, which causes an overflow when parsing fonts.
12435| [CVE-2005-4717] Microsoft Internet Explorer 6.0 on Windows NT 4.0 SP6a, Windows 2000 SP4, Windows XP SP1, Windows XP SP2, and Windows Server 2003 SP1 allows remote attackers to cause a denial of service (client crash) via a certain combination of a malformed HTML file and a CSS file that triggers a null dereference, probably related to rendering of a DIV element that contains a malformed IMG tag, as demonstrated by IEcrash.htm and IEcrash.rar.
12436| [CVE-2005-4269] mshtml.dll in Microsoft Windows XP, Server 2003, and Internet Explorer 6.0 SP1 allows attackers to cause a denial of service (access violation) by causing mshtml.dll to process button-focus events at the same time that a document is reloading, as seen in Microsoft Office InfoPath 2003 by repeatedly clicking the "Delete" button in a repeating section in a form. NOTE: the normal operation of InfoPath appears to involve a local user without any privilege boundaries, so this might not be a vulnerability in InfoPath. If no realistic scenarios exist for this problem in other products, then perhaps it should be excluded from CVE.
12437| [CVE-2005-4131] Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed range, which could lead to memory corruption involving an argument to the msvcrt.memmove function, aka "Brand new Microsoft Excel Vulnerability," as originally placed for sale on eBay as item number 7203336538.
12438| [CVE-2005-3981] ** DISPUTED ** NOTE: this issue has been disputed by third parties. Microsoft Windows XP, 2000, and 2003 allows local users to kill a writable process by using the CreateRemoteThread function with certain arguments on a process that has been opened using the OpenProcess function, possibly involving an invalid address for the start routine. NOTE: followup posts have disputed this issue, saying that if a user already has privileges to write to a process, then other functions could be called or the process could be terminated using PROCESS_TERMINATE.
12439| [CVE-2005-3945] The SynAttackProtect protection in Microsoft Windows 2003 before SP1 and Windows 2000 before SP4 with Update Roll-up uses a hash of predictable data, which allows remote attackers to cause a denial of service (CPU consumption) via a flood of SYN packets that produce identical hash values, which slows down the hash table lookups.
12440| [CVE-2005-3644] PNP_GetDeviceList (upnp_getdevicelist) in UPnP for Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 and earlier, allows remote attackers to cause a denial of service (memory consumption) via a DCE RPC request that specifies a large output buffer size, a variant of CVE-2006-6296, and a different vulnerability than CVE-2005-2120.
12441| [CVE-2005-3177] CHKDSK in Microsoft Windows 2000 before Update Rollup 1 for SP4, Windows XP, and Windows Server 2003, when running in fix mode, does not properly handle security descriptors if the master file table contains a large number of files or if the descriptors do not satisfy certain NTFS conventions, which could cause ACLs for some files to be reverted to less secure defaults, or cause security descriptors to be removed.
12442| [CVE-2005-3176] Microsoft Windows 2000 before Update Rollup 1 for SP4 does not record the IP address of a Windows Terminal Services client in a security log event if the client connects successfully, which could make it easier for attackers to escape detection.
12443| [CVE-2005-3175] Microsoft Windows 2000 before Update Rollup 1 for SP4 allows a local administrator to unlock a computer even if it has been locked by a domain administrator, which allows the local administrator to access the session as the domain administrator.
12444| [CVE-2005-3174] Microsoft Windows 2000 before Update Rollup 1 for SP4 allows users to log on to the domain, even when their password has expired, if the fully qualified domain name (FQDN) is 8 characters long.
12445| [CVE-2005-3173] Microsoft Windows 2000 before Update Rollup 1 for SP4 does not apply group policies if the user logs on using UPN credentials with a trailing dot, which prevents Windows 2000 from finding the correct domain controller and could allow the user to bypass intended restrictions.
12446| [CVE-2005-3172] The WideCharToMultiByte function in Microsoft Windows 2000 before Update Rollup 1 for SP4 does not properly convert strings with Japanese composite characters in the last character, which could prevent the string from being null terminated and lead to data corruption or enable buffer overflow attacks.
12447| [CVE-2005-3171] Microsoft Windows 2000 before Update Rollup 1 for SP4 records Event ID 1704 to indicate that Group Policy security settings were successfully updated, even when the processing fails such as when Ntuser.pol cannot be accessed, which could cause system administrators to believe that the system is compliant with the specified settings.
12448| [CVE-2005-3170] The LDAP client on Microsoft Windows 2000 before Update Rollup 1 for SP4 accepts certificates using LDAP Secure Sockets Layer (LDAPS) even when the Certificate Authority (CA) is not trusted, which could allow attackers to trick users into believing that they are accessing a trusted site.
12449| [CVE-2005-3169] Microsoft Windows 2000 before Update Rollup 1 for SP4, when the "audit directory service access" policy is enabled, does not record a 565 event message for File Delete Child operations on an Active Directory object in the security event log, which could allow attackers to conduct unauthorized activities without detection.
12450| [CVE-2005-3168] The SECEDIT command on Microsoft Windows 2000 before Update Rollup 1 for SP4, when using a security template to set Access Control Lists (ACLs) on folders, does not apply ACLs on folders that are listed after a long folder entry, which could result in less secure permissions than specified by the template.
12451| [CVE-2005-2122] Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to execute arbitrary commands via a shortcut (.lnk) file with long font properties that lead to a buffer overflow in the Client/Server Runtime Server Subsystem (CSRSS), a different vulnerability than CVE-2005-2118.
12452| [CVE-2005-2120] Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of "\" (backslash) characters in a registry key name, which triggers the overflow in a wsprintfW function call.
12453| [CVE-2005-2118] Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote user-assisted attackers to execute arbitrary commands via a crafted shortcut (.lnk) file with long font properties that lead to a buffer overflow when the user views the file's properties using Windows Explorer, a different vulnerability than CVE-2005-2122.
12454| [CVE-2005-2117] Web View in Windows Explorer on Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 does not properly handle certain HTML characters in preview fields, which allows remote user-assisted attackers to execute arbitrary code.
12455| [CVE-2005-1985] The Client Service for NetWare (CSNW) on Microsoft Windows 2000 SP4, XP SP1 and Sp2, and Server 2003 SP1 and earlier, allows remote attackers to execute arbitrary code due to an "unchecked buffer" when processing certain crafted network messages.
12456| [CVE-2005-1984] Buffer overflow in the Print Spooler service (Spoolsv.exe) for Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via a malicious message.
12457| [CVE-2005-1983] Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1 allows remote attackers to execute arbitrary code via a crafted packet, and local users to gain privileges via a malicious application, as exploited by the Zotob (aka Mytob) worm.
12458| [CVE-2005-1982] Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.
12459| [CVE-2005-1981] Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message.
12460| [CVE-2005-1907] The ISA Firewall service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (Wspsrv.exe crash) via a large amount of SecureNAT network traffic.
12461| [CVE-2005-1683] Buffer overflow in winword.exe 10.2627.6714 and earlier in Microsoft Word for the Macintosh, before SP3 for Word 2002, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted mcw file.
12462| [CVE-2005-1218] The Microsoft Windows kernel in Microsoft Windows 2000 Server, Windows XP, and Windows Server 2003 allows remote attackers to cause a denial of service (crash) via crafted Remote Desktop Protocol (RDP) requests.
12463| [CVE-2005-1216] Microsoft ISA Server 2000 allows remote attackers to connect to services utilizing the NetBIOS protocol via a NetBIOS connection with an ISA Server that uses the NetBIOS (all) predefined packet filter.
12464| [CVE-2005-1215] Microsoft ISA Server 2000 allows remote attackers to poison the ISA cache or bypass content restriction policies via a malformed HTTP request packet containing multiple Content-Length headers.
12465| [CVE-2005-1208] Integer overflow in Microsoft Windows 98, 2000, XP SP2 and earlier, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via a crafted compiled Help (.CHM) file with a large size field that triggers a heap-based buffer overflow, as demonstrated using a "ms-its:" URL in Internet Explorer.
12466| [CVE-2005-1207] Buffer overflow in the Web Client service in Microsoft Windows XP and Windows Server 2003 allows remote authenticated users to execute arbitrary code via a crafted WebDAV request containing special parameters.
12467| [CVE-2005-1206] Buffer overflow in the Server Message Block (SMB) functionality for Microsoft Windows 2000, XP SP1 and SP2, and Server 2003 and SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka the "Server Message Block Vulnerability."
12468| [CVE-2005-1205] The Telnet client for Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX allows remote attackers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.
12469| [CVE-2005-1052] Microsoft Outlook 2003 and Outlook Web Access (OWA) 2003 do not properly display comma separated addresses in the From field in an e-mail message, which could allow remote attackers to spoof e-mail addresses.
12470| [CVE-2005-0921] Microsoft Outlook 2002 Connector for IBM Lotus Domino 2.0 allows local users to save passwords and login credentials locally, even when password caching is disabled by a group policy.
12471| [CVE-2005-0820] Microsoft Office InfoPath 2003 SP1 includes sensitive information in the Manifest.xsf file in a custom .xsn form, which allows attackers to obtain printer and network information, obtain the database name, username, and password, or obtain the internal web server name.
12472| [CVE-2005-0738] Stack consumption vulnerability in Microsoft Exchange Server 2003 SP1 allows users to cause a denial of service (hang) by deleting or moving a folder with deeply nested subfolders, which causes Microsoft Exchange Information Store service (Store.exe) to hang as a result of a large number of recursive calls.
12473| [CVE-2005-0564] Stack-based buffer overflow in Microsoft Word 2000 and Word 2002, and Microsoft Works Suites 2000 through 2004, might allow remote attackers to execute arbitrary code via a .doc file with long font information.
12474| [CVE-2005-0558] Buffer overflow in Microsoft Word 2000, Word 2002, and Word 2003 allows remote attackers to execute arbitrary code via a crafted document.
12475| [CVE-2005-0551] Stack-based buffer overflow in WINSRV.DLL in the Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application that provides console window information with a long FaceName value.
12476| [CVE-2005-0550] Buffer overflow in Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to cause a denial of service (i.e., system crash) via a malformed request, aka "Object Management Vulnerability".
12477| [CVE-2005-0545] Microsoft Windows XP Pro SP2 and Windows 2000 Server SP4 running Active Directory allow local users to bypass group policies that restrict access to hidden drives by using the browse feature in Office 10 applications such as Word or Excel, or using a flash drive. NOTE: this issue has been disputed in a followup post.
12478| [CVE-2005-0063] The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.
12479| [CVE-2005-0061] The kernel of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via certain access requests.
12480| [CVE-2005-0060] Buffer overflow in the font processing component of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application.
12481| [CVE-2005-0059] Buffer overflow in the Message Queuing component of Microsoft Windows 2000 and Windows XP SP1 allows remote attackers to execute arbitrary code via a crafted message.
12482| [CVE-2005-0058] Buffer overflow in the Telephony Application Programming Interface (TAPI) for Microsoft Windows 98, Windows 98 SE, Windows ME, Windows 2000, Windows XP, and Windows Server 2003 allows attackers elevate privileges or execute arbitrary code via a crafted message.
12483| [CVE-2005-0048] Microsoft Windows XP SP2 and earlier, 2000 SP3 and SP4, Server 2003, and older operating systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IP packets with malformed options, aka the "IP Validation Vulnerability."
12484| [CVE-2004-2527] The local and remote desktop login screens in Microsoft Windows XP before SP2 and 2003 allow remote attackers to cause a denial of service (CPU and memory consumption) by repeatedly using the WinKey+"U" key combination, which causes multiple copies of Windows Utility Manager to be loaded more quickly than they can be closed when the copies detect that another instance is running.
12485| [CVE-2004-2482] Microsoft Outlook 2000 and 2003, when configured to use Microsoft Word 2000 or 2003 as the e-mail editor and when forwarding e-mail, does not properly handle an opening OBJECT tag that does not have a closing OBJECT tag, which causes Outlook to automatically download the URI in the data property of the OBJECT tag and might allow remote attackers to execute arbitrary code.
12486| [CVE-2004-2365] Memory leak in Microsoft Windows XP and Windows Server 2003 allows local users to cause a denial of service (memory exhaustion) by repeatedly creating and deleting directories using a non-standard tool such as smbmount.
12487| [CVE-2004-2339] ** DISPUTED ** Microsoft Windows 2000, XP, and possibly 2003 allows local users with the SeDebugPrivilege privilege to execute arbitrary code as kernel and read or write kernel memory via the NtSystemDebugControl function, which does not verify its pointer arguments. Note: this issue has been disputed, since Administrator privileges are typically required to exploit this issue, thus privilege boundaries are not crossed.
12488| [CVE-2004-1080] The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42, aka the "Association Context Vulnerability."
12489| [CVE-2004-0963] Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause a denial of service (application exception) and possibly execute arbitrary code in winword.exe via certain unexpected values in a .doc file, including (1) an offset that triggers an out-of-bounds memory access, (2) a certain value that causes a large memory copy as triggered by an integer conversion error, and other values.
12490| [CVE-2004-0897] The Indexing Service for Microsoft Windows XP and Server 2003 does not properly validate the length of a message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.
12491| [CVE-2004-0892] Microsoft Proxy Server 2.0 and Microsoft ISA Server 2000 (which is included in Small Business Server 2000 and Small Business Server 2003 Premium Edition) allows remote attackers to spoof trusted Internet content on a specially crafted webpage via spoofed reverse DNS lookup results.
12492| [CVE-2004-0846] Unknown vulnerability in Microsoft Excel 2000, 2002, 2001 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via a malicious file containing certain parameters that are not properly validated.
12493| [CVE-2004-0840] The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows Server 2003 64-bit Edition, and the Exchange Routing Engine component of Exchange Server 2003, allows remote attackers to execute arbitrary code via a malicious DNS response message containing length values that are not properly validated.
12494| [CVE-2004-0728] The Remote Control Client service in Microsoft's Systems Management Server (SMS) 2.50.2726.0 allows remote attackers to cause a denial of service (crash) via a data packet to TCP port 2702 that causes the server to read or write to an invalid memory address.
12495| [CVE-2004-0726] The Windows Media Player control in Microsoft Windows 2000 allows remote attackers to execute arbitrary script in the local computer zone via an ASX filename that contains javascript, which is executed in the local context in a preview panel.
12496| [CVE-2004-0575] Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit Edition allows remote attackers to execute arbitrary code via compressed (zipped) folders that involve an "unchecked buffer" and improper length validation.
12497| [CVE-2004-0574] The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an "unchecked buffer," leading to off-by-one and heap-based buffer overflows.
12498| [CVE-2004-0573] Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website.
12499| [CVE-2004-0540] Microsoft Windows 2000, when running in a domain whose Fully Qualified Domain Name (FQDN) is exactly 8 characters long, does not prevent users with expired passwords from logging on to the domain.
12500| [CVE-2004-0503] Microsoft Outlook 2003 allows remote attackers to bypass the default zone restrictions and execute script within media files via a Rich Text Format (RTF) message containing an OLE object for the Windows Media Player, which bypasses Media Player's setting to disallow scripting and may lead to unprompted installation of an executable when exploited in conjunction with predictable-file-location exposures such as CVE-2004-0502.
12501| [CVE-2004-0379] Multiple cross-site scripting (XSS) vulnerabilities in Microsoft SharePoint Portal Server 2001 allow remote attackers to process arbitrary web content and steal cookies via certain server scripts.
12502| [CVE-2004-0284] Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if "Do not save encrypted pages to disk" is disabled, via a web site or HTML e-mail that contains two null characters (%00) after the host name.
12503| [CVE-2004-0214] Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.
12504| [CVE-2004-0211] The kernel for Microsoft Windows Server 2003 does not reset certain values in CPU data structures, which allows local users to cause a denial of service (system crash) via a malicious program.
12505| [CVE-2004-0210] The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.
12506| [CVE-2004-0209] Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats that involve "an unchecked buffer."
12507| [CVE-2004-0208] The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions.
12508| [CVE-2004-0207] "Shatter" style vulnerability in the Window Management application programming interface (API) for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to gain privileges by using certain API functions to change properties of privileged programs using the SetWindowLong and SetWIndowLongPtr API functions.
12509| [CVE-2004-0206] Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow.
12510| [CVE-2004-0204] Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and other products, allows remote attackers to read and delete arbitrary files via ".." sequences in the dynamicimag argument to crystalimagehandler.aspx.
12511| [CVE-2004-0202] IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.
12512| [CVE-2004-0201] Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.
12513| [CVE-2004-0199] Help and Support Center in Microsoft Windows XP and Windows Server 2003 SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code, as demonstrated using certain hcp:// URLs that access the DVD Upgrade capability (dvdupgrd.htm).
12514| [CVE-2004-0124] The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability."
12515| [CVE-2004-0121] Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.
12516| [CVE-2004-0120] The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages.
12517| [CVE-2004-0116] An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field.
12518| [CVE-2003-1378] Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs via an HTML email with the CODEBASE parameter set to the program, a vulnerability similar to CAN-2002-0077.
12519| [CVE-2003-1106] The SMTP service in Microsoft Windows 2000 before SP4 allows remote attackers to cause a denial of service (crash or hang) via an e-mail message with a malformed time stamp in the FILETIME attribute.
12520| [CVE-2003-0908] The Utility Manager in Microsoft Windows 2000 executes winhlp32.exe with system privileges, which allows local users to execute arbitrary code via a "Shatter" style attack using a Windows message that accesses the context sensitive help button in the GUI, as demonstrated using the File Open dialog in the Help window, a different vulnerability than CVE-2004-0213.
12521| [CVE-2003-0906] Buffer overflow in the rendering for (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1 allows remote attackers to execute arbitrary code via a malformed WMF or EMF image.
12522| [CVE-2003-0904] Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reuse HTTP connections, which can cause OWA users to view mailboxes of other users when Kerberos has been disabled as an authentication method for IIS 6.0, e.g. when SharePoint Services 2.0 is installed.
12523| [CVE-2003-0839] Directory traversal vulnerability in the "Shell Folders" capability in Microsoft Windows Server 2003 allows remote attackers to read arbitrary files via .. (dot dot) sequences in a "shell:" link.
12524| [CVE-2003-0825] The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code.
12525| [CVE-2003-0824] Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.
12526| [CVE-2003-0822] Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to execute arbitrary code via a crafted chunked encoded request.
12527| [CVE-2003-0821] Microsoft Excel 97, 2000, and 2002 allows remote attackers to execute arbitrary code via a spreadsheet with a malicious XLM (Excel 4) macro that bypasses the macro security model.
12528| [CVE-2003-0820] Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.
12529| [CVE-2003-0819] Buffer overflow in the H.323 filter of Microsoft Internet Security and Acceleration Server 2000 allows remote attackers to execute arbitrary code in the Microsoft Firewall Service via certain H.323 traffic, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.
12530| [CVE-2003-0818] Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.
12531| [CVE-2003-0807] Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a crafted request.
12532| [CVE-2003-0806] Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1, when a member of a domain, allows remote attackers to execute arbitrary code.
12533| [CVE-2003-0719] Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets.
12534| [CVE-2003-0665] Buffer overflow in the ActiveX control for Microsoft Access Snapshot Viewer for Access 97, 2000, and 2002 allows remote attackers to execute arbitrary code via long parameters to the control.
12535| [CVE-2003-0664] Microsoft Word 2002, 2000, 97, and 98(J) does not properly check certain properties of a document, which allows attackers to bypass the macro security model and automatically execute arbitrary macros via a malicious document.
12536| [CVE-2003-0662] Buffer overflow in Troubleshooter ActiveX Control (Tshoot.ocx) in Microsoft Windows 2000 SP4 and earlier allows remote attackers to execute arbitrary code via an HTML document with a long argument to the RunQuery2 method.
12537| [CVE-2003-0660] The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to download and install ActiveX controls when the system is low on memory, which could allow remote attackers execute arbitrary code without user approval.
12538| [CVE-2003-0533] Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.
12539| [CVE-2003-0526] Cross-site scripting (XSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to inject arbitrary web script via a URL containing the script in the domain name portion, which is not properly cleansed in the default error pages (1) 500.htm for "500 Internal Server error" or (2) 404.htm for "404 Not Found."
12540| [CVE-2003-0506] Microsoft NetMeeting 3.01 2000 before SP4 allows remote attackers to cause a denial of service (shutdown of NetMeeting conference) via malformed packets, as demonstrated via the chat conversation.
12541| [CVE-2003-0505] Directory traversal vulnerability in Microsoft NetMeeting 3.01 2000 before SP4 allows remote attackers to read arbitrary files via "..\.." (dot dot) sequences in a file transfer request.
12542| [CVE-2003-0496] Microsoft SQL Server before Windows 2000 SP4 allows local users to gain privileges as the SQL Server user by calling the xp_fileexist extended stored procedure with a named pipe as an argument instead of a normal file.
12543| [CVE-2003-0352] Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message, as exploited by the Blaster/MSblast/LovSAN and Nachi/Welchia worms.
12544| [CVE-2003-0345] Buffer overflow in the SMB capability for Microsoft Windows XP, 2000, and NT allows remote attackers to cause a denial of service and possibly execute arbitrary code via an SMB packet that specifies a smaller buffer length than is required.
12545| [CVE-2003-0232] Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local Procedure Calls (LPC) port that leads to a buffer overflow.
12546| [CVE-2003-0231] Microsoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial of service (crash or hang) via a long request to a named pipe.
12547| [CVE-2003-0230] Microsoft SQL Server 7, 2000, and MSDE allows local users to gain privileges by hijacking a named pipe during the authentication of another user, aka the "Named Pipe Hijacking" vulnerability.
12548| [CVE-2003-0227] The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft Windows NT 4.0 and 2000, nsiislog.dll, allows remote attackers to cause a denial of service in Internet Information Server (IIS) and execute arbitrary code via a certain network request.
12549| [CVE-2003-0118] SQL injection vulnerability in the Document Tracking and Administration (DTA) website of Microsoft BizTalk Server 2000 and 2002 allows remote attackers to execute operating system commands via a request to (1) rawdocdata.asp or (2) RawCustomSearchField.asp containing an embedded SQL statement.
12550| [CVE-2003-0117] Buffer overflow in the HTTP receiver function (BizTalkHTTPReceive.dll ISAPI) of Microsoft BizTalk Server 2002 allows attackers to execute arbitrary code via a certain request to the HTTP receiver.
12551| [CVE-2003-0110] The Winsock Proxy service in Microsoft Proxy Server 2.0 and the Microsoft Firewall service in Internet Security and Acceleration (ISA) Server 2000 allow remote attackers to cause a denial of service (CPU consumption or packet storm) via a spoofed, malformed packet to UDP port 1745.
12552| [CVE-2003-0109] Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0.
12553| [CVE-2003-0011] Unknown vulnerability in the DNS intrusion detection application filter for Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (blocked traffic to DNS servers) via a certain type of incoming DNS request that is not properly handled.
12554| [CVE-2003-0007] Microsoft Outlook 2002 does not properly handle requests to encrypt email messages with V1 Exchange Server Security certificates, which causes Outlook to send the email in plaintext, aka "Flaw in how Outlook 2002 handles V1 Exchange Server Security Certificates could lead to Information Disclosure."
12555| [CVE-2003-0003] Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter information.
12556| [CVE-2003-0002] Cross-site scripting vulnerability (XSS) in ManualLogin.asp script for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary script via the REASONTXT parameter.
12557| [CVE-2002-2101] Microsoft Outlook 2002 allows remote attackers to execute arbitrary JavaScript code, even when scripting is disabled, via an "about:" or "javascript:" URI in the href attribute of an "a" tag.
12558| [CVE-2002-2100] Microsoft Outlook 2002 allows remote attackers to embed bypass the file download restrictions for attachments via an HTML email message that uses an IFRAME to reference malicious content.
12559| [CVE-2002-1984] Microsoft Internet Explorer 5.0.1 through 6.0 on Windows 2000 or Windows XP allows remote attackers to cause a denial of service (crash) via an OBJECT tag that contains a crafted CLASSID (CLSID) value of "CLSID:00022613-0000-0000-C000-000000000046".
12560| [CVE-2002-1981] Microsoft SQL Server 2000 through SQL Server 2000 SP2 allows the "public" role to execute the (1) sp_MSSetServerProperties or (2) sp_MSsetalertinfo stored procedures, which allows attackers to modify configuration including SQL server startup and alert settings.
12561| [CVE-2002-1933] The terminal services screensaver for Microsoft Windows 2000 does not automatically lock the terminal window if the window is minimized, which could allow local users to gain access to the terminal server window.
12562| [CVE-2002-1932] Microsoft Windows XP and Windows 2000, when configured to send administrative alerts and the "Do not overwrite events (clear log manually)" option is set, does not notify the administrator when the log reaches its maximum size, which allows local users and remote attackers to avoid detection.
12563| [CVE-2002-1876] Microsoft Exchange 2000 allows remote authenticated attackers to cause a denial of service via a large number of rapid requests, which consumes all of the licenses that are granted to Exchange by IIS.
12564| [CVE-2002-1873] Microsoft Exchange 2000, when used with Microsoft Remote Procedure Call (MSRPC), allows remote attackers to cause a denial of service (crash or memory consumption) via malformed MSRPC calls.
12565| [CVE-2002-1872] Microsoft SQL Server 6.0 through 2000, with SQL Authentication enabled, uses weak password encryption (XOR), which allows remote attackers to sniff and decrypt the password.
12566| [CVE-2002-1776] ** DISPUTED ** NOTE: this issue has been disputed by the vendor. Symantec Norton AntiVirus 2002 allows remote attackers to bypass virus protection via a Word Macro virus with a .nch or .dbx extension, which is automatically recognized and executed as a Microsoft Office document. NOTE: the vendor has disputed this issue, acknowledging that the initial scan is bypassed, but the Office plug-in would detect the virus before it is executed.
12567| [CVE-2002-1712] Microsoft Windows 2000 allows remote attackers to cause a denial of service (memory consumption) by sending a flood of empty TCP/IP packets with the ACK and FIN bits set to the NetBIOS port (TCP/139), as demonstrated by stream3.
12568| [CVE-2002-1256] The SMB signing capability in the Server Message Block (SMB) protocol in Microsoft Windows 2000 and Windows XP allows attackers to disable the digital signing settings in an SMB session to force the data to be sent unsigned, then inject data into the session without detection, e.g. by modifying group policy information sent from a domain controller.
12569| [CVE-2002-1255] Microsoft Outlook 2002 allows remote attackers to cause a denial of service (repeated failure) via an email message with a certain invalid header field that is accessed using POP3, IMAP, or WebDAV, aka "E-mail Header Processing Flaw Could Cause Outlook 2002 to Fail."
12570| [CVE-2002-1214] Buffer overflow in Microsoft PPTP Service on Windows XP and Windows 2000 allows remote attackers to cause a denial of service (hang) and possibly execute arbitrary code via a certain PPTP packet with malformed control data.
12571| [CVE-2002-1184] The system root folder of Microsoft Windows 2000 has default permissions of Everyone group with Full access (Everyone:F) and is in the search path when locating programs during login or application launch from the desktop, which could allow attackers to gain privileges as other users via Trojan horse programs.
12572| [CVE-2002-1145] The xp_runwebtask stored procedure in the Web Tasks component of Microsoft SQL Server 7.0 and 2000, Microsoft Data Engine (MSDE) 1.0, and Microsoft Desktop Engine (MSDE) 2000 can be executed by PUBLIC, which allows an attacker to gain privileges by updating a webtask that is owned by the database owner through the msdb.dbo.mswebtasks table, which does not have strong permissions.
12573| [CVE-2002-1141] An input validation error in the Sun Microsystems RPC library Services for Unix 3.0 Interix SD, as implemented on Microsoft Windows NT4, 2000, and XP, allows remote attackers to cause a denial of service via malformed fragmented RPC client packets, aka "Denial of service by sending an invalid RPC request."
12574| [CVE-2002-1140] The Sun Microsystems RPC library Services for Unix 3.0 Interix SD, as implemented on Microsoft Windows NT4, 2000, and XP, allows remote attackers to cause a denial of service (service hang) via malformed packet fragments, aka "Improper parameter size check leading to denial of service."
12575| [CVE-2002-1138] Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, writes output files for scheduled jobs under its own privileges instead of the entity that launched it, which allows attackers to overwrite system files, aka "Flaw in Output File Handling for Scheduled Jobs."
12576| [CVE-2002-1137] Buffer overflow in the Database Console Command (DBCC) that handles user inputs in Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, allows attackers to execute arbitrary code via a long SourceDB argument in a "non-SQL OLEDB data source" such as FoxPro, a variant of CAN-2002-0644.
12577| [CVE-2002-1123] Buffer overflow in the authentication function for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows remote attackers to execute arbitrary code via a long request to TCP port 1433, aka the "Hello" overflow.
12578| [CVE-2002-1117] Veritas Backup Exec 8.5 and earlier requires that the "RestrictAnonymous" registry key for Microsoft Exchange 2000 must be set to 0, which enables anonymous listing of the SAM database and shares.
12579| [CVE-2002-1056] Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary scripts via an email that the user forwards or replies to.
12580| [CVE-2002-0982] Microsoft SQL Server 2000 SP2, when configured as a distributor, allows attackers to execute arbitrary code via the @scriptfile parameter to the sp_MScopyscript stored procedure.
12581| [CVE-2002-0975] Buffer overflow in Microsoft DirectX Files Viewer ActiveX control (xweb.ocx) 2.0.6.15 and earlier allows remote attackers to execute arbitrary via a long File parameter.
12582| [CVE-2002-0863] Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka "Weak Encryption in RDP Protocol."
12583| [CVE-2002-0861] Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to bypass the "Allow paste operations via script" setting, even when it is disabled, via the (1) Copy method of the Cell object or (2) the Paste method of the Range object.
12584| [CVE-2002-0860] The LoadText method in the spreadsheet component in Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to read arbitrary files through Internet Explorer via a URL that redirects to the target file.
12585| [CVE-2002-0859] Buffer overflow in the OpenDataSource function of the Jet engine on Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code.
12586| [CVE-2002-0729] Microsoft SQL Server 2000 allows remote attackers to cause a denial of service via a malformed 0x08 packet that is missing a colon separator.
12587| [CVE-2002-0727] The Host function in Microsoft Office Web Components (OWC) 2000 and 2002 is exposed in components that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via the setTimeout method.
12588| [CVE-2002-0724] Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows attackers to cause a denial of service (crash) via a SMB_COM_TRANSACTION packet with a request for the (1) NetShareEnum, (2) NetServerEnum2, or (3) NetServerEnum3, aka "Unchecked Buffer in Network Share Provider Can Lead to Denial of Service".
12589| [CVE-2002-0721] Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could allow unprivileged users, and possibly remote attackers, to run stored procedures with administrator privileges via (1) xp_execresultset, (2) xp_printstatements, or (3) xp_displayparamstmt.
12590| [CVE-2002-0719] SQL injection vulnerability in the function that services for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary commands via an MCMS resource request for image files or other files.
12591| [CVE-2002-0718] Web authoring command in Microsoft Content Management Server (MCMS) 2001 allows attackers to authenticate and upload executable content, by modifying the upload location, aka "Program Execution via MCMS Authoring Function."
12592| [CVE-2002-0700] Buffer overflow in a system function that performs user authentication for Microsoft Content Management Server (MCMS) 2001 allows attackers to execute code in the Local System context by authenticating to a web page that calls the function, aka "Unchecked Buffer in MDAC Function Could Enable SQL Server Compromise."
12593| [CVE-2002-0699] Unknown vulnerability in the Certificate Enrollment ActiveX Control in Microsoft Windows 98, Windows 98 Second Edition, Windows Millennium, Windows NT 4.0, Windows 2000, and Windows XP allow remote attackers to delete digital certificates on a user's system via HTML.
12594| [CVE-2002-0695] Buffer overflow in the Transact-SQL (T-SQL) OpenRowSet component of Microsoft Data Access Components (MDAC) 2.5 through 2.7 for SQL Server 7.0 or 2000 allows remote attackers to execute arbitrary code via a query that calls the OpenRowSet command.
12595| [CVE-2002-0694] The HTML Help facility in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP uses the Local Computer Security Zone when opening .chm files from the Temporary Internet Files folder, which allows remote attackers to execute arbitrary code via HTML mail that references or inserts a malicious .chm file containing shortcuts that can be executed, aka "Code Execution via Compiled HTML Help File."
12596| [CVE-2002-0693] Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute code via (1) a long parameter to the Alink function, or (2) script containing a long argument to the showHelp function.
12597| [CVE-2002-0692] Buffer overflow in SmartHTML Interpreter (shtml.dll) in Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to cause a denial of service (CPU consumption) or run arbitrary code, respectively, via a certain type of web file request.
12598| [CVE-2002-0650] The keep-alive mechanism for Microsoft SQL Server 2000 allows remote attackers to cause a denial of service (bandwidth consumption) via a "ping" style packet to the Resolution Service (UDP port 1434) with a spoofed IP address of another SQL Server system, which causes the two servers to exchange packets in an infinite loop.
12599| [CVE-2002-0649] Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSDE) allow remote attackers to cause a denial of service or execute arbitrary code via UDP packets to port 1434 in which (1) a 0x04 byte that causes the SQL Monitor thread to generate a long registry key name, or (2) a 0x08 byte with a long string causes heap corruption, as exploited by the Slammer/Sapphire worm.
12600| [CVE-2002-0645] SQL injection vulnerability in stored procedures for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 may allow authenticated users to execute arbitrary commands.
12601| [CVE-2002-0644] Buffer overflow in several Database Consistency Checkers (DBCCs) for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows members of the db_owner and db_ddladmin roles to execute arbitrary code.
12602| [CVE-2002-0643] The installation of Microsoft Data Engine 1.0 (MSDE 1.0), and Microsoft SQL Server 2000 creates setup.iss files with insecure permissions and does not delete them after installation, which allows local users to obtain sensitive data, including weakly encrypted passwords, to gain privileges, aka "SQL Server Installation Process May Leave Passwords on System."
12603| [CVE-2002-0642] The registry key containing the SQL Server service account information in Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, has insecure permissions, which allows local users to gain privileges, aka "Incorrect Permission on SQL Server Service Account Registry Key."
12604| [CVE-2002-0641] Buffer overflow in bulk insert procedure of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows attackers with database administration privileges to execute arbitrary code via a long filename in the BULK INSERT query.
12605| [CVE-2002-0624] Buffer overflow in the password encryption function of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows remote attackers to gain control of the database and execute arbitrary code via SQL Server Authentication, aka "Unchecked Buffer in Password Encryption Procedure."
12606| [CVE-2002-0623] Buffer overflow in AuthFilter ISAPI filter on Microsoft Commerce Server 2000 and 2002 allows remote attackers to execute arbitrary code via long authentication data, aka "New Variant of the ISAPI Filter Buffer Overrun".
12607| [CVE-2002-0622] The Office Web Components (OWC) package installer for Microsoft Commerce Server 2000 allows remote attackers to execute commands by passing the commands as input to the OWC package installer, aka "OWC Package Command Execution".
12608| [CVE-2002-0621] Buffer overflow in the Office Web Components (OWC) package installer used by Microsoft Commerce Server 2000 allows remote attackers to cause the process to fail or run arbitrary code in the LocalSystem security context via certain input to the OWC package installer.
12609| [CVE-2002-0620] Buffer overflow in the Profile Service of Microsoft Commerce Server 2000 allows remote attackers to cause the server to fail or run arbitrary code in the LocalSystem security context via an input field using an affected API.
12610| [CVE-2002-0619] The Mail Merge Tool in Microsoft Word 2002 for Windows, when Microsoft Access is present on a system, allows remote attackers to execute Visual Basic (VBA) scripts within a mail merge document that is saved in HTML format, aka a "Variant of MS00-071, Word Mail Merge Vulnerability" (CVE-2000-0788).
12611| [CVE-2002-0618] The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code in the Local Computer zone by embedding HTML scripts within an Excel workbook that contains an XSL stylesheet, aka "Excel XSL Stylesheet Script Execution".
12612| [CVE-2002-0617] The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code by creating a hyperlink on a drawing shape in a source workbook that points to a destination workbook containing an autoexecute macro, aka "Hyperlinked Excel Workbook Macro Bypass."
12613| [CVE-2002-0616] The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code by attaching an inline macro to an object within an Excel workbook, aka the "Excel Inline Macros Vulnerability."
12614| [CVE-2002-0597] LANMAN service on Microsoft Windows 2000 allows remote attackers to cause a denial of service (CPU/memory exhaustion) via a stream of malformed data to microsoft-ds port 445.
12615| [CVE-2002-0444] Microsoft Windows 2000 running the Terminal Server 90-day trial version, and possibly other versions, does not apply group policies to incoming users when the number of connections to the SYSVOL share exceeds the maximum, e.g. with a maximum number of licenses, which can allow remote authenticated users to bypass group policies.
12616| [CVE-2002-0443] Microsoft Windows 2000 allows local users to bypass the policy that prohibits reusing old passwords by changing the current password before it expires, which does not enable the check for previous passwords.
12617| [CVE-2002-0373] The Windows Media Device Manager (WMDM) Service in Microsoft Windows Media Player 7.1 on Windows 2000 systems allows local users to obtain LocalSystem rights via a program that calls the WMDM service to connect to an invalid local storage device, aka "Privilege Elevation through Windows Media Device Manager Service".
12618| [CVE-2002-0371] Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote attackers to execute arbitrary code via a gopher:// URL that redirects the user to a real or simulated gopher server that sends a long response.
12619| [CVE-2002-0368] The Store Service in Microsoft Exchange 2000 allows remote attackers to cause a denial of service (CPU consumption) via a mail message with a malformed RFC message attribute, aka "Malformed Mail Attribute can Cause Exchange 2000 to Exhaust CPU Resources."
12620| [CVE-2002-0224] The MSDTC (Microsoft Distributed Transaction Service Coordinator) for Microsoft Windows 2000, Microsoft IIS 5.0 and SQL Server 6.5 through SQL 2000 0.0 allows remote attackers to cause a denial of service (crash or hang) via malformed (random) input.
12621| [CVE-2002-0187] Cross-site scripting vulnerability in the SQLXML component of Microsoft SQL Server 2000 allows an attacker to execute arbitrary script via the root parameter as part of an XML SQL query, aka "Script Injection via XML Tag."
12622| [CVE-2002-0186] Buffer overflow in the SQLXML ISAPI extension of Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code via data queries with a long content-type parameter, aka "Unchecked Buffer in SQLXML ISAPI Extension."
12623| [CVE-2002-0154] Buffer overflows in extended stored procedures for Microsoft SQL Server 7.0 and 2000 allow remote attackers to cause a denial of service or execute arbitrary code via a database query with certain long arguments.
12624| [CVE-2002-0152] Buffer overflow in various Microsoft applications for Macintosh allows remote attackers to cause a denial of service (crash) or execute arbitrary code by invoking the file:// directive with a large number of / characters, which affects Internet Explorer 5.1, Outlook Express 5.0 through 5.0.2, Entourage v. X and 2001, PowerPoint v. X, 2001, and 98, and Excel v. X and 2001 for Macintosh.
12625| [CVE-2002-0055] SMTP service in Microsoft Windows 2000, Windows XP Professional, and Exchange 2000 allows remote attackers to cause a denial of service via a command with a malformed data transfer (BDAT) request.
12626| [CVE-2002-0054] SMTP service in (1) Microsoft Windows 2000 and (2) Internet Mail Connector (IMC) in Exchange Server 5.5 does not properly handle responses to NTLM authentication, which allows remote attackers to perform mail relaying via an SMTP AUTH command using null session credentials.
12627| [CVE-2002-0050] Buffer overflow in AuthFilter ISAPI filter on Microsoft Commerce Server 2000 allows remote attackers to execute arbitrary code via long authentication data.
12628| [CVE-2002-0049] Microsoft Exchange Server 2000 System Attendant gives "Everyone" group privileges to the WinReg key, which could allow remote attackers to read or modify registry keys.
12629| [CVE-2002-0034] The Microsoft CONVERT.EXE program, when used on Windows 2000 and Windows XP systems, does not apply the default NTFS permissions when converting a FAT32 file system, which could cause the conversion to produce a file system with less secure permissions than expected.
12630| [CVE-2002-0018] In Microsoft Windows NT and Windows 2000, a trusting domain that receives authorization information from a trusted domain does not verify that the trusted domain is authoritative for all listed SIDs, which allows remote attackers to gain Domain Administrator privileges on the trusting domain by injecting SIDs from untrusted domains into the authorization data that comes from from the trusted domain.
12631| [CVE-2001-1533] ** DISPUTED * Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets. NOTE: the vendor disputes this issue, saying that it requires high bandwidth to exploit, and the server does not experience any instability. Therefore this "laws of physics" issue might not be included in CVE.
12632| [CVE-2001-1451] Memory leak in the SNMP LAN Manager (LANMAN) MIB extension for Microsoft Windows 2000 before SP3, when the Print Spooler is not running, allows remote attackers to cause a denial of service (memory consumption) via a large number of GET or GETNEXT requests.
12633| [CVE-2001-1319] Microsoft Exchange 5.5 2000 allows remote attackers to cause a denial of service (hang) via exceptional BER encodings for the LDAP filter type field, as demonstrated by the PROTOS LDAPv3 test suite.
12634| [CVE-2001-1099] The default configuration of Norton AntiVirus for Microsoft Exchange 2000 2.x allows remote attackers to identify the recipient's INBOX file path by sending an email with an attachment containing malicious content, which includes the path in the rejection notice.
12635| [CVE-2001-0986] SQLQHit.asp sample file in Microsoft Index Server 2.0 allows remote attackers to obtain sensitive information such as the physical path, file attributes, or portions of source code by directly calling sqlqhit.asp with a CiScope parameter set to (1) webinfo, (2) extended_fileinfo, (3) extended_webinfo, or (4) fileinfo.
12636| [CVE-2001-0718] Vulnerability in (1) Microsoft Excel 2002 and earlier and (2) Microsoft PowerPoint 2002 and earlier allows attackers to bypass macro restrictions and execute arbitrary commands by modifying the data stream in the document.
12637| [CVE-2001-0666] Outlook Web Access (OWA) in Microsoft Exchange 2000 allows an authenticated user to cause a denial of service (CPU consumption) via a malformed OWA request for a deeply nested folder within the user's mailbox.
12638| [CVE-2001-0658] Cross-site scripting (CSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause other clients to execute certain script or read cookies via malicious script in an invalid URL that is not properly quoted in an error message.
12639| [CVE-2001-0628] Microsoft Word 2000 does not check AutoRecovery (.asd) files for macros, which allows a local attacker to execute arbitrary macros with the user ID of the Word user.
12640| [CVE-2001-0547] Memory leak in the proxy service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows local attackers to cause a denial of service (resource exhaustion).
12641| [CVE-2001-0546] Memory leak in H.323 Gatekeeper Service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (resource exhaustion) via a large amount of malformed H.323 data.
12642| [CVE-2001-0542] Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow attackers with access to SQL Server to execute arbitrary code through the functions (1) raiserror, (2) formatmessage, or (3) xp_sprintf. NOTE: the C runtime format string vulnerability reported in MS01-060 is identified by CVE-2001-0879.
12643| [CVE-2001-0538] Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTML e-mail message or web page.
12644| [CVE-2001-0509] Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs.
12645| [CVE-2001-0505] Multiple memory leaks in Microsoft Services for Unix 2.0 allow remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed requests to (1) the Telnet service, or (2) the NFS service.
12646| [CVE-2001-0504] Vulnerability in authentication process for SMTP service in Microsoft Windows 2000 allows remote attackers to use incorrect credentials to gain privileges and conduct activites such as mail relaying.
12647| [CVE-2001-0501] Microsoft Word 2002 and earlier allows attackers to automatically execute macros without warning the user by embedding the macros in a manner that escapes detection by the security scanner.
12648| [CVE-2001-0351] Microsoft Windows 2000 telnet service allows a local user to make a certain system call that allows the user to terminate a Telnet session and cause a denial of service.
12649| [CVE-2001-0350] Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the second of two variants of this vulnerability.
12650| [CVE-2001-0349] Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the first of two variants of this vulnerability.
12651| [CVE-2001-0348] Microsoft Windows 2000 telnet service allows attackers to cause a denial of service (crash) via a long logon command that contains a backspace.
12652| [CVE-2001-0347] Information disclosure vulnerability in Microsoft Windows 2000 telnet service allows remote attackers to determine the existence of user accounts such as Guest, or log in to the server without specifying the domain name, via a malformed userid.
12653| [CVE-2001-0346] Handle leak in Microsoft Windows 2000 telnet service allows attackers to cause a denial of service by starting a large number of sessions and terminating them.
12654| [CVE-2001-0345] Microsoft Windows 2000 telnet service allows attackers to prevent idle Telnet sessions from timing out, causing a denial of service by creating a large number of idle sessions.
12655| [CVE-2001-0344] An SQL query method in Microsoft SQL Server 2000 Gold and 7.0 using Mixed Mode allows local database users to gain privileges by reusing a cached connection of the sa administrator account.
12656| [CVE-2001-0340] An interaction between the Outlook Web Access (OWA) service in Microsoft Exchange 2000 Server and Internet Explorer allows attackers to execute malicious script code against a user's mailbox via a message attachment that contains HTML code, which is executed automatically.
12657| [CVE-2001-0261] Microsoft Windows 2000 Encrypted File System does not properly destroy backups of files that are encrypted, which allows a local attacker to recover the text of encrypted files.
12658| [CVE-2001-0245] Microsoft Index Server 2.0 in Windows NT 4.0, and Indexing Service in Windows 2000, allows remote attackers to read server-side include files via a malformed search request, aka a new variant of the "Malformed Hit-Highlighting" vulnerability.
12659| [CVE-2001-0244] Buffer overflow in Microsoft Index Server 2.0 allows remote attackers to execute arbitrary commands via a long search parameter.
12660| [CVE-2001-0240] Microsoft Word before Word 2002 allows attackers to automatically execute macros without warning the user via a Rich Text Format (RTF) document that links to a template with the embedded macro.
12661| [CVE-2001-0239] Microsoft Internet Security and Acceleration (ISA) Server 2000 Web Proxy allows remote attackers to cause a denial of service via a long web request with a specific type.
12662| [CVE-2001-0237] Memory leak in Microsoft 2000 domain controller allows remote attackers to cause a denial of service by repeatedly connecting to the Kerberos service and then disconnecting without sending any data.
12663| [CVE-2001-0146] IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly sending a series of specially formatted URL's.
12664| [CVE-2001-0048] The "Configure Your Server" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to install malicious programs, aka the "Directory Service Restore Mode Password" vulnerability.
12665| [CVE-2001-0005] Buffer overflow in the parsing mechanism of the file loader in Microsoft PowerPoint 2000 allows attackers to execute arbitrary commands.
12666| [CVE-2001-0003] Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials and possibly obtain the password, aka the "Web Client NTLM Authentication" vulnerability.
12667| [CVE-2000-1218] The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query, which allows remote attackers to poison the DNS cache.
12668| [CVE-2000-1217] Microsoft Windows 2000 before Service Pack 2 (SP2), when running in a non-Windows 2000 domain and using NTLM authentication, and when credentials of an account are locally cached, allows local users to bypass account lockout policies and make an unlimited number of login attempts, aka the "Domain Account Lockout" vulnerability.
12669| [CVE-2000-1209] The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq Insight Manager, and (6) Visio 2000, which allows remote attackers to gain privileges, as exploited by worms such as Voyager Alpha Force and Spida.
12670| [CVE-2000-1139] The installation of Microsoft Exchange 2000 before Rev. A creates a user account with a known password, which could allow attackers to gain privileges, aka the "Exchange User Account" vulnerability.
12671| [CVE-2000-1088] The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
12672| [CVE-2000-1087] The xp_proxiedmetadata function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
12673| [CVE-2000-1086] The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
12674| [CVE-2000-1085] The xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
12675| [CVE-2000-1079] Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote attackers to modify dynamic NetBIOS name cache entries via a spoofed Browse Frame Request in a unicast or UDP broadcast datagram.
12676| [CVE-2000-0942] The CiWebHitsFile component in Microsoft Indexing Services for Windows 2000 allows remote attackers to conduct a cross site scripting (CSS) attack via a CiRestriction parameter in a .htw request, aka the "Indexing Services Cross Site Scripting" vulnerability.
12677| [CVE-2000-0854] When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as riched20.dll and msi.dll, which could allow an attacker to execute arbitrary commands by inserting a Trojan Horse DLL into the same directory as the document.
12678| [CVE-2000-0771] Microsoft Windows 2000 allows local users to cause a denial of service by corrupting the local security policy via malformed RPC traffic, aka the "Local Security Policy Corruption" vulnerability.
12679| [CVE-2000-0765] Buffer overflow in the HTML interpreter in Microsoft Office 2000 allows an attacker to execute arbitrary commands via a long embedded object tag, aka the "Microsoft Office HTML Object Tag" vulnerability.
12680| [CVE-2000-0756] Microsoft Outlook 2000 does not properly process long or malformed fields in vCard (.vcf) files, which allows attackers to cause a denial of service.
12681| [CVE-2000-0710] The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers determine the physical path of the server components by requesting an invalid URL whose name includes a standard DOS device name.
12682| [CVE-2000-0709] The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to cause a denial of service in some components by requesting a URL whose name includes a standard DOS device name.
12683| [CVE-2000-0637] Microsoft Excel 97 and 2000 allows an attacker to execute arbitrary commands by specifying a malicious .dll using the Register.ID function, aka the "Excel REGISTER.ID Function" vulnerability.
12684| [CVE-2000-0621] Microsoft Outlook 98 and 2000, and Outlook Express 4.0x and 5.0x, allow remote attackers to read files on the client's system via a malformed HTML message that stores files outside of the cache, aka the "Cache Bypass" vulnerability.
12685| [CVE-2000-0597] Microsoft Office 2000 (Excel and PowerPoint) and PowerPoint 97 are marked as safe for scripting, which allows remote attackers to force Internet Explorer or some email clients to save files to arbitrary locations via the Visual Basic for Applications (VBA) SaveAs function, aka the "Office HTML Script" vulnerability.
12686| [CVE-2000-0331] Buffer overflow in Microsoft command processor (CMD.EXE) for Windows NT and Windows 2000 allows a local user to cause a denial of service via a long environment variable, aka the "Malformed Environment Variable" vulnerability.
12687| [CVE-2000-0277] Microsoft Excel 97 and 2000 does not warn the user when executing Excel Macro Language (XLM) macros in external text files, which could allow an attacker to execute a macro virus, aka the "XLM Text Macro" vulnerability.
12688| [CVE-2013-2557] The sandbox protection mechanism in Microsoft Internet Explorer 9 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, as demonstrated against Adobe Flash Player by VUPEN during a Pwn2Own competition at CanSecWest 2013.
12689| [CVE-2013-2556] Unspecified vulnerability in Microsoft Windows 7 allows attackers to bypass the ASLR protection mechanism via unknown vectors, as demonstrated against Adobe Flash Player by VUPEN during a Pwn2Own competition at CanSecWest 2013.
12690| [CVE-2013-2554] Unspecified vulnerability in Microsoft Windows 7 allows attackers to bypass the ASLR and DEP protection mechanisms via unknown vectors, as demonstrated against Firefox by VUPEN during a Pwn2Own competition at CanSecWest 2013, a different vulnerability than CVE-2013-0787.
12691| [CVE-2013-2553] Unspecified vulnerability in the kernel in Microsoft Windows 7 allows local users to gain privileges via unknown vectors, as demonstrated by Nils and Jon of MWR Labs during a Pwn2Own competition at CanSecWest 2013, a different vulnerability than CVE-2013-0912.
12692| [CVE-2013-2552] Unspecified vulnerability in Microsoft Internet Explorer 10 on Windows 8 allows remote attackers to bypass the sandbox protection mechanism by leveraging access to a Medium integrity process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013.
12693| [CVE-2013-2551] Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1308 and CVE-2013-1309.
12694| [CVE-2013-1347] Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly allocated or (2) is deleted, as exploited in the wild in May 2013.
12695| [CVE-2013-1305] HTTP.sys in Microsoft Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (infinite loop) via a crafted HTTP header, aka "HTTP.sys Denial of Service Vulnerability."
12696| [CVE-2013-1290] Microsoft SharePoint Server 2013, in certain configurations involving legacy My Sites, does not properly establish default access controls for a SharePoint list, which allows remote authenticated users to bypass intended restrictions on reading list items via a direct request for a list's location, aka "Incorrect Access Rights Information Disclosure Vulnerability."
12697| [CVE-2013-1289] Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1, Groove Server 2010 SP1, SharePoint Foundation 2010 SP1, and Office Web Apps 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted string, aka "HTML Sanitization Vulnerability."
12698| [CVE-2013-1284] Race condition in the kernel in Microsoft Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Kernel Race Condition Vulnerability."
12699| [CVE-2013-0096] Writer in Microsoft Windows Essentials 2011 and 2012 allows remote attackers to bypass proxy settings and overwrite arbitrary files via crafted URL parameters, aka "Windows Essentials Improper URI Handling Vulnerability."
12700| [CVE-2013-0086] Microsoft OneNote 2010 SP1 does not properly determine buffer sizes during memory allocation, which allows remote attackers to obtain sensitive information via a crafted OneNote file, aka "Buffer Size Validation Vulnerability."
12701| [CVE-2013-0085] Buffer overflow in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to cause a denial of service (W3WP process crash and site outage) via a crafted URL, aka "Buffer Overflow Vulnerability."
12702| [CVE-2013-0084] Directory traversal vulnerability in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to bypass intended read restrictions for content, and hijack user accounts, via a crafted URL, aka "SharePoint Directory Traversal Vulnerability."
12703| [CVE-2013-0083] Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via crafted content, leading to administrative command execution, aka "SharePoint XSS Vulnerability."
12704| [CVE-2013-0080] Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allow remote attackers to bypass intended read restrictions for content, and hijack user accounts, via a crafted URL, aka "Callback Function Vulnerability."
12705| [CVE-2013-0079] Microsoft Visio Viewer 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Visio file that triggers incorrect memory allocation, aka "Visio Viewer Tree Object Type Confusion Vulnerability."
12706| [CVE-2013-0005] The WCF Replace function in the Open Data (aka OData) protocol implementation in Microsoft .NET Framework 3.5, 3.5 SP1, 3.5.1, and 4, and the Management OData IIS Extension on Windows Server 2012, allows remote attackers to cause a denial of service (resource consumption and daemon restart) via crafted values in HTTP requests, aka "Replace Denial of Service Vulnerability."
12707| [CVE-2012-4969] Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site, as exploited in the wild in September 2012.
12708| [CVE-2012-4792] Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object, and exploited in the wild in December 2012.
12709| [CVE-2012-3456] Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in Calligra 2.4.3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ODF style in an ODF document. NOTE: this is the same vulnerability as CVE-2012-3455, but it was SPLIT by the CNA even though Calligra and KOffice share the same codebase.
12710| [CVE-2012-3455] Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in KOffice 2.3.3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ODF style in an ODF document. NOTE: this is the same vulnerability as CVE-2012-3456, but it was SPLIT by the CNA even though Calligra and KOffice share the same codebase.
12711| [CVE-2012-2290] The client in EMC NetWorker Module for Microsoft Applications (NMM) 2.2.1, 2.3 before build 122, and 2.4 before build 375 allows remote attackers to execute arbitrary code by sending a crafted message over a TCP communication channel.
12712| [CVE-2012-2284] The (1) install and (2) upgrade processes in EMC NetWorker Module for Microsoft Applications (NMM) 2.2.1, 2.3 before build 122, and 2.4 before build 375, when Exchange Server is used, allow local users to read cleartext administrator credentials via unspecified vectors.
12713| [CVE-2012-1945] Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allow local users to obtain sensitive information via an HTML document that loads a shortcut (aka .lnk) file for display within an IFRAME element, as demonstrated by a network share implemented by (1) Microsoft Windows or (2) Samba.
12714| [CVE-2012-1894] Microsoft Office for Mac 2011 uses world-writable permissions for the "Applications/Microsoft Office 2011/" directory and certain other directories, which allows local users to gain privileges by placing a Trojan horse executable file in one of these directories, aka "Office for Mac Improper Folder Permissions Vulnerability."
12715| [CVE-2012-1892] Cross-site scripting (XSS) vulnerability in Microsoft Visual Studio Team Foundation Server 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "XSS Vulnerability."
12716| [CVE-2012-1891] Heap-based buffer overflow in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2 and Windows Data Access Components (WDAC) 6.0 allows remote attackers to execute arbitrary code via crafted XML data that triggers access to an uninitialized object in memory, aka "ADO Cachesize Heap Overflow RCE Vulnerability."
12717| [CVE-2012-1888] Buffer overflow in Microsoft Visio 2010 SP1 and Visio Viewer 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Visio file, aka "Visio DXF File Format Buffer Overflow Vulnerability."
12718| [CVE-2012-1876] Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by attempting to access a nonexistent object, leading to a heap-based buffer overflow, aka "Col Element Remote Code Execution Vulnerability," as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012.
12719| [CVE-2012-1861] Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 Gold and SP1, SharePoint Foundation 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "SharePoint Script in Username Vulnerability."
12720| [CVE-2012-1859] Cross-site scripting (XSS) vulnerability in scriptresx.ashx in Microsoft SharePoint Server 2010 Gold and SP1, SharePoint Foundation 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "XSS scriptresx.ashx Vulnerability."
12721| [CVE-2012-1857] Cross-site scripting (XSS) vulnerability in the Enterprise Portal component in Microsoft Dynamics AX 2012 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Dynamics AX Enterprise Portal XSS Vulnerability."
12722| [CVE-2012-1849] Untrusted search path vulnerability in Microsoft Lync 2010, 2010 Attendee, and 2010 Attendant allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .ocsmeet file, aka "Lync Insecure Library Loading Vulnerability."
12723| [CVE-2012-1545] Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, allows remote attackers to bypass Protected Mode or cause a denial of service (memory corruption) by leveraging access to a Low integrity process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012.
12724| [CVE-2012-1436] The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \2D\6C\68 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.
12725| [CVE-2012-1435] The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \50\4B\4C\49\54\45 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.
12726| [CVE-2012-1434] The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \19\04\00\10 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.
12727| [CVE-2012-1433] The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \4a\46\49\46 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.
12728| [CVE-2012-0447] Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize data for image/vnd.microsoft.icon images, which allows remote attackers to obtain potentially sensitive information by reading a PNG image that was created through conversion from an ICO image.
12729| [CVE-2012-0147] Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 does not properly configure the default web site, which allows remote attackers to obtain sensitive information via a crafted HTTPS request, aka "Unfiltered Access to UAG Default Website Vulnerability."
12730| [CVE-2012-0146] Open redirect vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka "UAG Blind HTTP Redirect Vulnerability."
12731| [CVE-2012-0145] Cross-site scripting (XSS) vulnerability in wizardlist.aspx in Microsoft Office SharePoint Server 2010 Gold and SP1 and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in wizardlist.aspx Vulnerability."
12732| [CVE-2012-0144] Cross-site scripting (XSS) vulnerability in themeweb.aspx in Microsoft Office SharePoint Server 2010 Gold and SP1 and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in themeweb.aspx Vulnerability."
12733| [CVE-2012-0138] Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0019, CVE-2012-0020, CVE-2012-0136, and CVE-2012-0137.
12734| [CVE-2012-0137] Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0019, CVE-2012-0020, CVE-2012-0136, and CVE-2012-0138.
12735| [CVE-2012-0136] Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0019, CVE-2012-0020, CVE-2012-0137, and CVE-2012-0138.
12736| [CVE-2012-0020] Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0019, CVE-2012-0136, CVE-2012-0137, and CVE-2012-0138.
12737| [CVE-2012-0019] Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0020, CVE-2012-0136, CVE-2012-0137, and CVE-2012-0138.
12738| [CVE-2012-0018] Microsoft Visio Viewer 2010 Gold and SP1 does not properly validate attributes in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "VSD File Format Memory Corruption Vulnerability."
12739| [CVE-2012-0017] Cross-site scripting (XSS) vulnerability in inplview.aspx in Microsoft SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in inplview.aspx Vulnerability."
12740| [CVE-2011-4695] Unspecified vulnerability in Microsoft Windows 7 SP1, when Java is installed, allows local users to bypass Internet Explorer sandbox restrictions and gain privileges via unknown vectors, as demonstrated by the White Phosphorus wp_ie_sandbox_escape module for Immunity CANVAS. NOTE: as of 20111207, this disclosure has no actionable information. However, because the module author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.
12741| [CVE-2011-2012] Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 does not properly validate session cookies, which allows remote attackers to cause a denial of service (IIS outage) via unspecified network traffic, aka "Null Session Cookie Crash."
12742| [CVE-2011-2010] The Microsoft Office Input Method Editor (IME) for Simplified Chinese in Microsoft Pinyin IME 2010, Office Pinyin SimpleFast Style 2010, and Office Pinyin New Experience Style 2010 does not properly restrict access to configuration options, which allows local users to gain privileges via the Microsoft Pinyin (aka MSPY) IME toolbar, aka "Pinyin IME Elevation Vulnerability."
12743| [CVE-2011-1969] Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 provides the MicrosoftClient.jar file containing a signed Java applet, which allows remote attackers to execute arbitrary code on client machines via unspecified vectors, aka "Poisoned Cup of Code Execution Vulnerability."
12744| [CVE-2011-1897] Cross-site scripting (XSS) vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Default Reflected XSS Vulnerability."
12745| [CVE-2011-1896] Cross-site scripting (XSS) vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "ExcelTable Reflected XSS Vulnerability."
12746| [CVE-2011-1895] CRLF injection vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary HTTP headers, and conduct HTTP response splitting attacks and cross-site scripting (XSS) attacks, via unspecified vectors, aka "ExcelTable Response Splitting XSS Vulnerability."
12747| [CVE-2011-1891] Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in a request to a script, aka "Contact Details Reflected XSS Vulnerability."
12748| [CVE-2011-1890] Cross-site scripting (XSS) vulnerability in EditForm.aspx in Microsoft Office SharePoint Server 2010 and SharePoint Foundation 2010 allows remote attackers to inject arbitrary web script or HTML via a post, aka "Editform Script Injection Vulnerability."
12749| [CVE-2011-1889] The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute arbitrary code via vectors involving unspecified requests, aka "TMG Firewall Client Memory Corruption Vulnerability."
12750| [CVE-2011-1417] Integer overflow in QuickLook, as used in Apple Mac OS X before 10.6.7 and MobileSafari in Apple iOS before 4.2.7 and 4.3.x before 4.3.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a Microsoft Office document with a crafted size field in the OfficeArtMetafileHeader, related to OfficeArtBlip, as demonstrated on the iPhone by Charlie Miller and Dion Blazakis during a Pwn2Own competition at CanSecWest 2011.
12751| [CVE-2011-1347] Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to bypass Protected Mode and create arbitrary files by leveraging access to a Low integrity process, as demonstrated by Stephen Fewer as the third of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011.
12752| [CVE-2011-1346] Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors, as demonstrated by Stephen Fewer as the second of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011.
12753| [CVE-2011-1345] Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, as demonstrated by Stephen Fewer as the first of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011, aka "Object Management Memory Corruption Vulnerability."
12754| [CVE-2011-1265] The Bluetooth Stack 2.1 in Microsoft Windows Vista SP1 and SP2 and Windows 7 Gold and SP1 does not prevent access to objects in memory that (1) were not properly initialized or (2) have been deleted, which allows remote attackers to execute arbitrary code via crafted Bluetooth packets, aka "Bluetooth Stack Vulnerability."
12755| [CVE-2011-0653] Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2010 Gold and SP1, and SharePoint Foundation 2010, allows remote attackers to inject arbitrary web script or HTML via the URI, aka "XSS in SharePoint Calendar Vulnerability."
12756| [CVE-2011-0647] The irccd.exe service in EMC Replication Manager Client before 5.3 and NetWorker Module for Microsoft Applications 2.1.x and 2.2.x allows remote attackers to execute arbitrary commands via the RunProgram function to TCP port 6542.
12757| [CVE-2011-0627] Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content, as possibly exploited in the wild in May 2011 by a Microsoft Office document with an embedded .swf file.
12758| [CVE-2011-0037] Microsoft Malware Protection Engine before 1.1.6603.0, as used in Microsoft Malicious Software Removal Tool (MSRT), Windows Defender, Security Essentials, Forefront Client Security, Forefront Endpoint Protection 2010, and Windows Live OneCare, allows local users to gain privileges via a crafted value of an unspecified user registry key.
12759| [CVE-2011-0027] Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, does not properly validate memory allocation for internal data structures, which allows remote attackers to execute arbitrary code, possibly via a large CacheSize property that triggers an integer wrap and a buffer overflow, aka "ADO Record Memory Vulnerability." NOTE: this might be a duplicate of CVE-2010-1117 or CVE-2010-1118.
12760| [CVE-2011-0026] Integer signedness error in the SQLConnectW function in an ODBC API (odbc32.dll) in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, allows remote attackers to execute arbitrary code via a long string in the Data Source Name (DSN) and a crafted szDSN argument, which bypasses a signed comparison and leads to a buffer overflow, aka "DSN Overflow Vulnerability."
12761| [CVE-2010-4643] Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Truevision TGA (TARGA) file in an ODF or Microsoft Office document.
12762| [CVE-2010-4253] Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file in an ODF or Microsoft Office document, as demonstrated by a PowerPoint (aka PPT) document.
12763| [CVE-2010-4121] ** DISPUTED ** The TCP-to-ODBC gateway in IBM Tivoli Provisioning Manager for OS Deployment 7.1.1.3 does not require authentication for SQL statements, which allows remote attackers to modify, create, or read database records via a session on TCP port 2020. NOTE: the vendor disputes this issue, stating that the "default Microsoft Access database is not password protected because it is intended to be used for evaluation purposes only."
12764| [CVE-2010-3967] Untrusted search path vulnerability in Microsoft Windows Movie Maker (WMM) 2.6 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a Movie Maker (MSWMM) file, aka "Insecure Library Loading Vulnerability."
12765| [CVE-2010-3962] Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token sequences and the clip attribute, aka an "invalid flag reference" issue or "Uninitialized Memory Corruption Vulnerability," as exploited in the wild in November 2010.
12766| [CVE-2010-3936] Cross-site scripting (XSS) vulnerability in Signurl.asp in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "XSS in Signurl.asp Vulnerability."
12767| [CVE-2010-3889] Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the wild in July 2010 by the Stuxnet worm, and identified by Microsoft researchers and other researchers.
12768| [CVE-2010-3888] Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the wild in July 2010 by the Stuxnet worm, and identified by Kaspersky Lab researchers and other researchers.
12769| [CVE-2010-3497] Symantec Norton AntiVirus 2011 does not properly interact with the processing of hcp:// URLs by the Microsoft Help and Support Center, which makes it easier for remote attackers to execute arbitrary code via malware that is correctly detected by this product, but with a detection approach that occurs too late to stop the code execution. NOTE: the researcher indicates that a vendor response was received, stating that this issue "falls into the work of our Firewall and not our AV (per our methodology of layers of defense)."
12770| [CVE-2010-3454] Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted typography information in a Microsoft Word .DOC file that triggers an out-of-bounds write.
12771| [CVE-2010-3453] The WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle an unspecified number of list levels in user-defined list styles in WW8 data in a Microsoft Word document, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted .DOC file that triggers an out-of-bounds write.
12772| [CVE-2010-3141] Untrusted search path vulnerability in Microsoft PowerPoint 2010 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse pptimpconv.dll that is located in the same folder as a .odp, .pot, .potm, .potx, .ppa, .pps, .ppsm, .ppsx, .ppt, .pptm, .pptx, .pwz, .sldm, or .sldx file.
12773| [CVE-2010-2743] The kernel-mode drivers in Microsoft Windows XP SP3 do not properly perform indexing of a function-pointer table during the loading of keyboard layouts from disk, which allows local users to gain privileges via a crafted application, as demonstrated in the wild in July 2010 by the Stuxnet worm, aka "Win32k Keyboard Layout Vulnerability." NOTE: this might be a duplicate of CVE-2010-3888 or CVE-2010-3889.
12774| [CVE-2010-2734] Cross-site scripting (XSS) vulnerability in the mobile portal in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "XSS Issue on UAG Mobile Portal Website in Forefront Unified Access Gateway Vulnerability."
12775| [CVE-2010-2733] Cross-site scripting (XSS) vulnerability in the Web Monitor in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "UAG XSS Allows EOP Vulnerability."
12776| [CVE-2010-2732] Open redirect vulnerability in the web interface in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka "UAG Redirection Spoofing Vulnerability."
12777| [CVE-2010-2564] Buffer overflow in Microsoft Windows Movie Maker (WMM) 2.1, 2.6, and 6.0 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted project file, aka "Movie Maker Memory Corruption Vulnerability."
12778| [CVE-2010-1184] The Microsoft wireless keyboard uses XOR encryption with a key derived from the MAC address, which makes it easier for remote attackers to obtain keystroke information and inject arbitrary commands via a nearby wireless device, as demonstrated by Keykeriki 2.
12779| [CVE-2010-1118] Unspecified vulnerability in Internet Explorer 8 on Microsoft Windows 7 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to a use-after-free issue, as demonstrated by Peter Vreugdenhil during a Pwn2Own competition at CanSecWest 2010.
12780| [CVE-2010-1117] Heap-based buffer overflow in Internet Explorer 8 on Microsoft Windows 7 allows remote attackers to discover the base address of a Windows .dll file, and possibly have unspecified other impact, via unknown vectors, as demonstrated by Peter Vreugdenhil during a Pwn2Own competition at CanSecWest 2010.
12781| [CVE-2010-0806] Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object, as exploited in the wild in March 2010, aka "Uninitialized Memory Corruption Vulnerability."
12782| [CVE-2010-0716] _layouts/Upload.aspx in the Documents module in Microsoft SharePoint before 2010 uses URLs with the same hostname and port number for a web site's primary files and individual users' uploaded files (aka attachments), which allows remote authenticated users to leverage same-origin relationships and conduct cross-site scripting (XSS) attacks by uploading TXT files, a related issue to CVE-2008-5026. NOTE: the vendor disputes the significance of this issue, because cross-domain isolation can be implemented when needed.
12783| [CVE-2009-3555] The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.
12784| [CVE-2008-5750] Argument injection vulnerability in Microsoft Internet Explorer 8 beta 2 on Windows XP SP3 allows remote attackers to execute arbitrary commands via the --renderer-path option in a chromehtml: URI.
12785| [CVE-2008-5556] ** DISPUTED ** The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 does not recognize attack patterns designed to operate against web pages that are encoded with utf-7, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting crafted utf-7 content. NOTE: the vendor reportedly disputes this issue, stating "Behaviour is by design."
12786| [CVE-2008-5555] Microsoft Internet Explorer 8.0 Beta 2 relies on the XDomainRequestAllowed HTTP header to authorize data exchange between domains, which allows remote attackers to bypass the product's XSS Filter protection mechanism, and conduct XSS and cross-domain attacks, by injecting this header after a CRLF sequence, related to "XDomainRequest Allowed Injection (XAI)." NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
12787| [CVE-2008-5554] The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 does not properly handle some HTTP headers that appear after a CRLF sequence in a URI, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS or redirection attacks, as demonstrated by the (1) Location and (2) Set-Cookie HTTP headers. NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
12788| [CVE-2008-5553] The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 disables itself upon encountering a certain X-XSS-Protection HTTP header, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting this header after a CRLF sequence. NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
12789| [CVE-2008-5552] The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks via a CRLF sequence in conjunction with a crafted Content-Type header, as demonstrated by a header with a utf-7 charset value. NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
12790| [CVE-2008-5551] The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting data at two different positions within an HTML document, related to STYLE elements and the CSS expression property, aka a "double injection."
12791| [CVE-2008-5180] Microsoft Communicator, and Communicator in Microsoft Office 2010 beta, allows remote attackers to cause a denial of service (memory consumption) via a large number of SIP INVITE requests, which trigger the creation of many sessions.
12792| [CVE-2008-4211] Integer signedness error in (1) QuickLook in Apple Mac OS X 10.5.5 and (2) Office Viewer in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted Microsoft Excel file that triggers an out-of-bounds memory access, related to "handling of columns."
12793| [CVE-2007-5351] Unspecified vulnerability in Server Message Block Version 2 (SMBv2) signing support in Microsoft Windows Vista allows remote attackers to force signature re-computation and execute arbitrary code via a crafted SMBv2 packet, aka "SMBv2 Signing Vulnerability."
12794| [CVE-2007-2729] Comodo Firewall Pro 2.4.18.184 and Comodo Personal Firewall 2.3.6.81, and probably older Comodo Firewall versions, do not properly test for equivalence of process identifiers for certain Microsoft Windows API functions in the NT kernel 5.0 and greater, which allows local users to call these functions, and bypass firewall rules or gain privileges, via a modified identifier that is one, two, or three greater than the canonical identifier.
12795| [CVE-2007-1534] DFSR.exe in Windows Meeting Space in Microsoft Windows Vista remains available for remote connections on TCP port 5722 for 2 minutes after Windows Meeting Space is closed, which allows remote attackers to have an unknown impact by connecting to this port during the time window.
12796| [CVE-2007-0341] Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.1 and earlier, when Microsoft Internet Explorer 6 is used, allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in a CSS style in the convcharset parameter to the top-level URI, a different vulnerability than CVE-2005-0992.
12797| [CVE-2006-5559] The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the second argument is a BSTR, which allows remote attackers to cause a denial of service (Internet Explorer crash) and possibly execute arbitrary code via certain strings in the second and third arguments.
12798| [CVE-2006-4686] Buffer overflow in the Extensible Stylesheet Language Transformations (XSLT) processing in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 allows remote attackers to execute arbitrary code via a crafted Web page.
12799| [CVE-2006-4685] The XMLHTTP ActiveX control in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 does not properly handle HTTP server-side redirects, which allows remote user-assisted attackers to access content from other domains.
12800| [CVE-2006-1359] Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer.
12801| [CVE-2006-0761] Buffer overflow in BlackBerry Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server 2.2 and 4.0 before SP3 Hotfix 4 for IBM Lotus Domino, 3.6 before SP7 and 5.0 before SP3 Hotfix 3 for Microsoft Exchangem, and 4.0 for Novell GroupWise before SP3 Hotfix 1 might allow user-assisted remote attackers to execute arbitrary code on the server via a crafted Microsoft Word document that is opened on a wireless device.
12802| [CVE-2006-0753] Memory leak in Microsoft Internet Explorer 6 for Windows XP Service Pack 2 allows remote attackers to cause a denial of service (memory consumption) via JavaScript that uses setInterval to repeatedly call a function to set the value of window.status.
12803| [CVE-2006-0544] urlmon.dll in Microsoft Internet Explorer 7.0 beta 2 (aka 7.0.5296.0) allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a BGSOUND element with its SRC attribute set to "file://" followed by a large number of "-" (dash of hyphen) characters.
12804| [CVE-2006-0003] Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and distributed in Microsoft Data Access Components (MDAC) 2.7 and 2.8, allows remote attackers to execute arbitrary code via unknown attack vectors.
12805| [CVE-2005-1929] Multiple heap-based buffer overflows in (1) isaNVWRequest.dll and (2) relay.dll in Trend Micro ServerProtect Management Console 5.58 and earlier, as used in Control Manager 2.5 and 3.0 and Damage Cleanup Server 1.1, allow remote attackers to execute arbitrary code via "wrapped" length values in Chunked transfer requests. NOTE: the original report suggests that the relay.dll issue is related to a problem in which a Microsoft Foundation Classes (MFC) static library returns invalid values under heavy load. As such, this might not be a vulnerability in Trend Micro's product.
12806| [CVE-2005-0852] Microsoft Windows XP SP1 allows local users to cause a denial of service (system crash) via an empty datagram to a raw IP over IP socket (IP protocol 4), as originally demonstrated using code in Python 2.3.
12807| [CVE-2004-1322] Cisco Unity 2.x, 3.x, and 4.x, when integrated with Microsoft Exchange, has several hard coded usernames and passwords, which allows remote attackers to gain unauthorized access and change configuration settings or read outgoing or incoming e-mail messages.
12808| [CVE-2003-1306] Microsoft URLScan 2.5, with the RemoveServerHeader option enabled, allows remote attackers to obtain sensitive information (server name and version) via an HTTP request that generates certain errors such as 400 "Bad Request," which leak the Server header in the response.
12809| [CVE-2003-0903] Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request.
12810| [CVE-2003-0353] Buffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary code via a long response to a broadcast request to UDP port 1434.
12811| [CVE-2002-1918] Buffer overflow in Microsoft Active Data Objects (ADO) in Microsoft MDAC 2.5 through 2.7 allows remote attackers to have unknown impact with unknown attack vectors. NOTE: due to the lack of details available regarding this issue, perhaps it should be REJECTED.
12812| [CVE-2002-1142] Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.
12813| [CVE-2002-1015] RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to execute arbitrary script in the Local computer zone by inserting the script into the skin.ini file of an RJS archive, then referencing skin.ini from a web page after it has been extracted, which is parsed as HTML by Internet Explorer or other Microsoft-based web readers.
12814| [CVE-2002-0697] Microsoft Metadirectory Services (MMS) 2.2 allows remote attackers to bypass authentication and modify sensitive data by using an LDAP client to directly connect to MMS and bypass the checks for MMS credentials.
12815| [CVE-2002-0057] XMLHTTP control in Microsoft XML Core Services 2.6 and later does not properly handle IE Security Zone settings, which allows remote attackers to read arbitrary files by specifying a local file as an XML Data Source.
12816| [CVE-2001-1218] Microsoft Internet Explorer for Unix 5.0SP1 allows local users to possibly cause a denial of service (crash) in CDE or the X server on Solaris 2.6 by rapidly scrolling Chinese characters or maximizing the window.
12817| [CVE-2000-0563] The URLConnection function in MacOS Runtime Java (MRJ) 2.1 and earlier and the Microsoft virtual machine (VM) for MacOS allows a malicious web site operator to connect to arbitrary hosts using a HTTP redirection, in violation of the Java security model.
12818| [CVE-1999-1097] Microsoft NetMeeting 2.1 allows one client to read the contents of another client's clipboard via a CTRL-C in the chat box when the box is empty.
12819|
12820| SecurityFocus - https://www.securityfocus.com/bid/:
12821| [83154] Microsoft Windows 2000 Server CVE-2004-0540 Remote Security Vulnerability
12822| [45297] Microsoft Exchange Server 2007 Infinite Loop Remote Denial of Service Vulnerability
12823| [43419] Microsoft Excel 2002 Memory Corruption Vulnerability
12824| [43189] Microsoft Visual C++ 2008 Redistributable Package DLL Loading Arbitrary Code Execution Vulnerability
12825| [42742] Microsoft PowerPoint 2007 Multiple DLL Loading Arbitrary Code Execution Vulnerability
12826| [42695] Microsoft Groove 2007 'mso.dll' DLL Loading Arbitrary Code Execution Vulnerability
12827| [42681] Microsoft Visio 2003 'mfc71enu.dll' DLL Loading Arbitrary Code Execution Vulnerability
12828| [41843] Microsoft Outlook Web Access for Exchange Server 2003 Cross Site Request Forgery Vulnerability
12829| [39776] Microsoft SharePoint Server 2007 '_layouts/help.aspx' Cross Site Scripting Vulnerability
12830| [37196] RETIRED: Microsoft December 2009 Advance Notification Multiple Vulnerabilities
12831| [36940] RETIRED: Microsoft November 2009 Advance Notification Multiple Vulnerabilities
12832| [36633] RETIRED: Microsoft October 2009 Advance Notification Multiple Vulnerabilities
12833| [36239] RETIRED: Microsoft September 2009 Advance Notification Multiple Vulnerabilities
12834| [35974] RETIRED: Microsoft August 2009 Advance Notification Multiple Vulnerabilities
12835| [35617] RETIRED: Microsoft July 2009 Advance Notification Multiple Vulnerabilities
12836| [35213] RETIRED: Microsoft June 2009 Advance Notification Multiple Vulnerabilities
12837| [34867] RETIRED: Microsoft May 2009 Advance Notification Multiple Vulnerabilities
12838| [34532] Microsoft IAG 2007 ActiveX Control Multiple Stack Based Buffer Overflow Vulnerabilities
12839| [34469] Microsoft Word 2000 WordPerfect Converter Remote Code Execution Vulnerability
12840| [34450] RETIRED: Microsoft April 2009 Advance Notification Multiple Vulnerabilities
12841| [34005] RETIRED: Microsoft March 2009 Advance Notification Multiple Vulnerabilities
12842| [33639] RETIRED: Microsoft February 2009 Advance Notification Multiple Vulnerabilities
12843| [33170] RETIRED: Microsoft January 2009 Advance Notification Multiple Vulnerabilities
12844| [32632] RETIRED: Microsoft December 2008 Advance Notification Multiple Vulnerabilities
12845| [32153] Retired: Microsoft November 2008 Advance Notification Multiple Vulnerabilities
12846| [31667] Retired: Microsoft October 2008 Advance Notification Multiple Vulnerabilities
12847| [31129] RETIRED: Microsoft SQL Server 2000 'sqlvdir.dll' ActiveX Buffer Overflow Vulnerability
12848| [31014] RETIRED: Microsoft September 2008 Advance Notification Multiple Vulnerabilities
12849| [30593] RETIRED: Microsoft August 2008 Advance Notification Multiple Vulnerabilities
12850| [30075] RETIRED: Microsoft July 2008 Advance Notification Multiple Vulnerabilities
12851| [29576] RETIRED: Microsoft June 2008 Advance Notification Multiple Vulnerabilities
12852| [29108] RETIRED: Microsoft May 2008 Advance Notification Multiple Vulnerabilities
12853| [28598] RETIRED: Microsoft April 2008 Advance Notification Multiple Vulnerabilities
12854| [28124] Retired: Microsoft March 2008 Advance Notification Multiple Vulnerabilities
12855| [27674] RETIRED: Microsoft February 2008 Advance Notification Multiple Vulnerabilities
12856| [27119] RETIRED: Microsoft January 2008 Advance Notification Multiple Vulnerabilities
12857| [26739] RETIRED: Microsoft December 2007 Advance Notification Multiple Vulnerabilities
12858| [26414] Microsoft Forms 2.0 ActiveX Control Memory Access Violation Denial of Service Vulnerabilities
12859| [26380] Retired: Microsoft November 2007 Advance Notification Multiple Vulnerabilities
12860| [25991] RETIRED: Microsoft Office 2000 and XP Unspecified Word Document Handling DoS Vulnerability
12861| [25922] RETIRED: Microsoft October 2007 Advance Notification Multiple Vulnerabilities
12862| [25573] RETIRED: Microsoft September 2007 Advance Notification Multiple Vulnerabilities
12863| [25247] Retired: Microsoft August 2007 Advance Notification Multiple Vulnerabilities
12864| [24771] Retired: Microsoft July 2007 Advance Notification Multiple Vulnerabilities
12865| [24366] RETIRED: Microsoft June 2007 Advance Notification Multiple Vulnerabilities
12866| [24118] Microsoft Office 2000 UA OUACTRL.OCX ActiveX Control Buffer Overflow Vulnerability
12867| [23800] RETIRED: Microsoft May 2007 Advance Notification Multiple Vulnerabilities
12868| [23380] Microsoft Word 2007 WWLib.DLL Unspecified Document File Buffer Overflow Vulnerability
12869| [23335] RETIRED: Microsoft April 2007 Advance Notification Multiple Vulnerabilities
12870| [22716] Microsoft Office 2003 Denial of Service Vulnerability
12871| [22567] Microsoft Word 2000/2002 Document Stream Remote Code Execution Vulnerability
12872| [22328] RETIRED: Microsoft Word 2003 Unspecified Code Execution Vulnerability
12873| [22225] Microsoft Word 2000 Malformed Function Code Execution Vulnerability
12874| [21611] Microsoft Project Server 2003 PDSRequest.ASP XML Request Information Disclosure Vulnerability
12875| [21495] Microsoft Windows 2000 Remote Installation Service Remote Code Execution Vulnerability
12876| [20843] Microsoft Visual Studio 2005 WMI Object Broker Remote Code Execution Vulnerability
12877| [19636] Microsoft Windows 2000 Multiple COM Object Instantiation Code Execution Vulnerabilities
12878| [19388] Microsoft Windows 2000 Kernel Local Privilege Escalation Vulnerability
12879| [17134] Microsoft Commerce Server 2002 Authentication Bypass Vulnerability
12880| [16634] Microsoft PowerPoint 2000 Remote Information Disclosure Vulnerability
12881| [14772] Microsoft Exchange Server 2003 Exchange Information Store Denial Of Service Vulnerability
12882| [14093] Microsoft Update Rollup 1 for Windows 2000 SP4 Released - Multiple Vulnerabilities Fixed
12883| [13564] Microsoft SQL Server 2000 Multiple Vulnerabilities
12884| [13008] Microsoft Windows Server 2003 SMB Redirector Local Denial Of Service Vulnerability
12885| [12972] Microsoft Windows Server 2003 Service Pack 1 Released - Multiple Vulnerabilities Fixed
12886| [12913] Microsoft Outlook 2002 Connector For IBM Lotus Domino Policy Bypass Vulnerability
12887| [12824] Microsoft InfoPath 2003 Insecure Information Storage Vulnerability
12888| [12641] Microsoft Windows 2000 Group Policy Bypass Vulnerability
12889| [12141] Microsoft FrontPage 2000 Internet Publishing Service Provider DAV File Upload Vulnerability
12890| [11820] Microsoft Windows 2000 Resource Kit W3Who.DLL Multiple Remote Vulnerabilities
12891| [11446] Microsoft Outlook 2003 Security Policy Bypass Vulnerability
12892| [11387] Microsoft Windows 2003 Services Default SACL Access Right Weakness
12893| [10901] Microsoft Windows 2000/XP CRL File Failed Integrity Check Denial Of Service Vulnerability
12894| [10693] Microsoft Windows 2000 Media Player Control Media Preview Script Execution Vulnerability
12895| [10484] Microsoft ISA Server 2000 FTP Bounce Filtering Vulnerability
12896| [10480] Microsoft ISA Server 2000 Site And Content Rule Bypass Vulnerability
12897| [10440] Microsoft Windows 2000 Domain Expired Account Security Policy Violation Weakness
12898| [10369] Microsoft Outlook 2003 Media File Script Execution Vulnerability
12899| [10307] Microsoft Outlook 2003 Predictable File Location Weakness
12900| [10114] Microsoft Windows 2000 Domain Controller LDAP Denial Of Service Vulnerability
12901| [9409] Microsoft Exchange Server 2003 Outlook Web Access Random Mailbox Access Vulnerability
12902| [9408] Microsoft ISA Server 2000 H.323 Filter Remote Buffer Overflow Vulnerability
12903| [9118] Microsoft Exchange Server 2003 Outlook Web Access Lowered Security Settings Weakness
12904| [8833] Microsoft Windows 2000 TroubleShooter ActiveX Control Buffer Overflow Vulnerability
12905| [8522] Multiple Microsoft Windows 2003 Stack Protection Implementation Weaknesses
12906| [8397] Microsoft Windows 2000 Subnet Bandwidth Manager RSVP Server Authority Hijacking Vulnerability
12907| [8104] Microsoft Windows 2000 Unauthorized RPC Connection Weakness
12908| [8098] Microsoft Windows 2000 Terminal Services Named Pipe System Account Access Vulnerability
12909| [8093] Microsoft Windows 2000 Active Directory Forest Origin Validation Vulnerability
12910| [8090] Microsoft Windows 2000 ShellExecute() Buffer Overflow Vulnerability
12911| [8089] Microsoft Windows 2000 Unspecified Cryptnet.DLL Memory Leakage Vulnerability
12912| [8086] Microsoft Windows 2000 Port Name Buffers Potential Buffer Overflow Vulnerability
12913| [8085] Microsoft Windows 2000 ModifyDN Request Denial of Service Vulnerability
12914| [8083] Microsoft Windows 2000 Domain Controller Spoofing Vulnerability
12915| [8081] Microsoft Windows 2000 USBH_IoctlGetNodeConnectionDriverKeyName Information Disclosure Vulnerability
12916| [8063] Microsoft Commerce Server 2002 Weak Registry Key Permissions Weakness
12917| [8045] Microsoft Windows 2000 SP4 Released - Multiple Vulnerabilities Fixed
12918| [7930] Microsoft Windows 2000 Active Directory Remote Stack Overflow Vulnerability
12919| [7788] Microsoft Windows 2000/XP/2003 IPV6 ICMP Flood Denial Of Service Vulnerability
12920| [7469] Microsoft BizTalk Server 2002 HTTP Receiver Buffer Overflow Vulnerability
12921| [7360] Microsoft Windows 2000/XP Registry Editor Custom Permissions Weakness
12922| [7102] Microsoft Windows 2000 Help Facility .CNT File :Link Buffer Overflow Vulnerability
12923| [6769] Microsoft Windows 2000 RPC Service Privilege Escalation Vulnerability
12924| [6766] Microsoft Windows 2000 NetBIOS Continuation Packets Kernel Memory Leak Vulnerability
12925| [6667] Microsoft Outlook 2002 V1 Exchange Server Security Certificate Information Leakage Vulnerability
12926| [6319] Microsoft Outlook 2002 Email Header Processing Denial of Service Vulnerability
12927| [6030] Microsoft Windows 2000 SNMP Printer Query Denial of Service Vulnerability
12928| [5972] Microsoft Windows 2000/XP Full Event Log Administrative Alert Weakness
12929| [5922] Microsoft Content Management Server 2001 Cross-Site Scripting Vulnerability
12930| [5480] Microsoft Windows 2000 Network Connection Manager Privilege Elevation Vulnerability
12931| [5422] Microsoft Content Management Server 2001 SQL Injection Vulnerability
12932| [5421] Microsoft Content Management Server 2001 Arbitrary Upload Location Vulnerability
12933| [5420] Microsoft Content Management Server 2001 User Authentication Buffer Overflow Vulnerability
12934| [5415] Microsoft Windows 2000 Insecure Default File Permissions Vulnerability
12935| [5413] Microsoft Exchange 2000 Post Authorization License Exhaustion Denial Of Service Vulnerability
12936| [5412] Microsoft Exchange 2000 Multiple MSRPC Denial Of Service Vulnerabilities
12937| [5312] Microsoft SQL Server 2000 Resolution Service Denial of Service Vulnerability
12938| [5311] Microsoft SQL Server 2000 Resolution Service Stack Overflow Vulnerability
12939| [5310] Microsoft SQL Server 2000 Resolution Service Heap Overflow Vulnerability
12940| [5309] Microsoft SQL Server 2000 sp_MScopyscript SQL Injection Vulnerability
12941| [5307] Microsoft SQL Server 2000 Database Consistency Checkers Buffer Overflow Vulnerability
12942| [5253] Microsoft Windows 2000 Narrator Password Disclosure Vulnerability
12943| [5205] Microsoft SQL Server 2000 Incorrect Registry Key Permissions Vulnerability
12944| [5111] Microsoft Commerce Server 2000 OWC Package Installer Local Command Execution Vulnerability
12945| [5014] Microsoft SQL Server 2000 Password Encrypt Procedure Buffer Overflow Vulnerability
12946| [4881] Microsoft Exchange 2000 Malformed Mail Attribute DoS Vulnerability
12947| [4853] Microsoft Commerce Server 2000 Profile Service Buffer Overflow Vulnerability
12948| [4852] Microsoft Windows 2000 Remote Access Service Buffer Overflow Vulnerability
12949| [4847] Microsoft SQL Server 2000 Bulk Insert Procedure Buffer Overflow Vulnerability
12950| [4797] Microsoft MSDE/SQL Server 2000 Desktop Engine Default Configuration Vulnerability
12951| [4683] Microsoft Windows 2000 / NT Path Precedence Vulnerability
12952| [4532] Microsoft Windows 2000 Lanman Denial of Service Vulnerability
12953| [4438] Microsoft Windows 2000 Group Policy Evasion Vulnerability
12954| [4426] Microsoft Windows 2000 / NT / XP MUP UNC Request Buffer Overflow Vulnerability
12955| [4287] Microsoft Windows 2000 / NT 4.0 Process Handle Local Privilege Elevation Vulnerability
12956| [4256] Microsoft Windows 2000 Password Policy Bypass Vulnerability
12957| [4157] Microsoft Commerce Server 2000 ISAPI Buffer Overflow Vulnerability
12958| [4095] Microsoft Windows 2000 Server Terminal Services Failure To Lock Terminal Vulnerability
12959| [3652] Microsoft Windows 2000 Internet Key Exchange DoS Vulnerability
12960| [3481] Microsoft Windows 2000/XP GDI Denial of Service Vulnerability
12961| [3479] Microsoft Windows 2000 NTFS With Macintosh Client Directory Permission Vulnerability
12962| [3445] Microsoft Windows 2000/NT Terminal Server Service RDP DoS Vulnerability
12963| [3339] Microsoft Index Server 2.0 File Information and Path Disclosure Vulnerability
12964| [3305] Norton AntiVirus for Microsoft Exchange 2000 Information Disclosure Vulnerability
12965| [3291] Microsoft Windows 2000 RunAs Service Denial of Services Vulnerability
12966| [3215] Microsoft Windows 2000 IrDA Buffer Overflow Denial of Service Vulnerability
12967| [3185] Microsoft Windows 2000 RunAs Service Named Pipe Hijacking Vulnerability
12968| [3184] Microsoft Windows 2000 RunAs User Credentials Exposure Vulnerability
12969| [3146] Microsoft Windows 2000 System File Replacement Vulnerability
12970| [3115] Microsoft Windows NT and 2000 Command Prompt Reboot Vulnerability
12971| [3063] Microsoft Windows 2000 Unauthorized Password Change Vulnerability
12972| [3033] Microsoft Windows 2000 Task Manager Process Termination Vulnerability
12973| [2988] Microsoft Windows 2000 SMTP Improper Authentication Vulnerability
12974| [2929] Microsoft Windows 2000 LDAP SSL Password Modification Vulnerability
12975| [2849] Microsoft Windows 2000 Telnet Privilege Escalation Vulnerability
12976| [2846] Microsoft Windows 2000 Telnet System Call DoS Vulnerability
12977| [2844] Microsoft Windows 2000 Telnet Service DoS Vulnerability
12978| [2843] Microsoft Windows 2000 Telnet Multiple Sessions DoS Vulnerability
12979| [2838] Microsoft Windows 2000 Telnet Username DoS Vulnerability
12980| [2460] Microsoft Windows 2000 Event Viewer Buffer Overflow Vulnerability
12981| [2441] Microsoft Exchange 2000 / IIS 5.0 Multiple Invalid URL Request DoS Vulnerability
12982| [2394] Microsoft Windows 2000 Domain Controller DoS Vulnerability
12983| [2341] Microsoft Windows 2000 Network DDE Escalated Privileges Vulnerability
12984| [2326] Microsoft Windows 2000 RDP DoS Vulnerability
12985| [2133] Microsoft Windows 2000 Directory Services Restore Mode Blank Password Vulnerability
12986| [2066] Microsoft Windows NT 4.0 / 2000 SNMP Registry Key Modification Vulnerability
12987| [2018] Microsoft Windows 2000 Telnet Session Timeout DoS Vulnerability
12988| [2007] Microsoft Windows 2000 DNS Memory Leak Vulnerability
12989| [1973] Microsoft Windows 2000 Domain Account Lockout Bypass Vulnerability
12990| [1958] Microsoft Exchange 2000 Server EUSR_EXSTOREEVENT Account Vulnerability
12991| [1933] Microsoft Indexing Services for Windows 2000 File Verification Vulnerability
12992| [1899] Microsoft Windows 2000 ActiveX Control Buffer Overflow Vulnerability
12993| [1811] Microsoft Site Server 2.0 with IIS 4.0 Malicious File Upload Vulnerability
12994| [1758] Microsoft Windows 2000 Unattended Install OEMPreinstall Vulnerability
12995| [1753] Microsoft Windows NT 4.0 / 2000 Spoofed LPC Request Vulnerability
12996| [1748] Microsoft Windows NT 4.0 / 2000 Predictable LPC Message Identifier Multiple Vulnerabilities
12997| [1745] Microsoft Windows NT 4.0 / 2000 LPC Zone Memory Depletion DoS Vulnerability
12998| [1729] Microsoft Windows 2000 Simplified Chinese IME Vulnerability
12999| [1695] Microsoft Proxy 2.0 FTP Permissions Bypass Vulnerability
13000| [1692] Microsoft Proxy 2.0 Internal Network Access Vulnerability
13001| [1683] Microsoft Windows 2000 telnet.exe NTLM Authentication Vulnerability
13002| [1673] Microsoft Windows 2000 Malformed RPC Packet DoS Vulnerability
13003| [1651] Microsoft Windows 2000 Still Image Service Privilege Escalation Vulnerability
13004| [1632] Microsoft Windows 98 / NT 4.0 / 2000 File Extension Validation Vulnerability
13005| [1620] Microsoft Windows 9x / NT 4.0 / 2000 NetBIOS Cache Corruption Vulnerability
13006| [1613] Microsoft Windows 2000 Local Security Policy Corruption Vulnerability
13007| [1566] Microsoft Word 97 / 2000 Mail Merge Code Execution Vulnerability
13008| [1561] Microsoft Word / Excel / Powerpoint 2000 Object Tag Buffer Overflow Vulnerability
13009| [1535] Microsoft Windows 2000 Named Pipes Predictability Vulnerability
13010| [1507] Microsoft Windows NT 4.0 / 2000 Unspecified Executable Path Vulnerability
13011| [1451] Microsoft Excel 97 / 2000 Register.ID Vulnerability
13012| [1435] Microsoft FrontPage 2000 Server Extensions Denial Of Service Vulnerability
13013| [1415] Microsoft Windows 2000 Remote CPU-overload Vulnerability
13014| [1414] Microsoft Windows 2000 Telnet Server DoS Vulnerability
13015| [1399] Microsoft Internet Explorer 5.01 and Excel/Powerpoint 2000 ActiveX Object Execution Vulnerability
13016| [1398] Microsoft Internet Explorer 5.01 and Access 2000 / 97 VBA Code Execution Vulnerability
13017| [1350] Microsoft Windows 2000 Windows Station Access Vulnerability
13018| [1304] Microsoft Windows NT 4.0 / 2000 SMB Write Request DoS Vulnerability
13019| [1301] Microsoft Windows NT 4.0 / 2000 Ignored SMB Response DoS Vulnerability
13020| [1295] Microsoft Windows 2000 Default 40-bit Encrypted Protected Store Vulnerability
13021| [1198] Microsoft Windows 2000 Default SYSKEY Configuration Vulnerability
13022| [1197] Microsoft Office 2000 UA Control Vulnerability
13023| [990] Microsoft Windows 2000 Install Unprotected ADMIN$ Share Vulnerability
13024| [945] Microsoft SMS 2.0 Default Permissions Vulnerability
13025| [539] Microsoft Windows 2000 EFS Vulnerability
13026| [180] Microsoft Windows April Fools 2001 Vulnerability
13027| [71487] Microsoft December 2014 Advance Notification Multiple Vulnerabilities
13028| [70966] RETIRED: Microsoft November 2014 Advance Notification Multiple Vulnerabilities
13029| [70367] RETIRED: Microsoft October 2014 Advance Notification Multiple Vulnerabilities
13030| [69636] RETIRED: Microsoft September 2014 Advance Notification Multiple Vulnerabilities
13031| [69108] Microsoft August 2014 Advance Notification Multiple Vulnerabilities
13032| [68367] Microsoft July 2014 Advance Notification Multiple Vulnerabilities
13033| [67905] Microsoft June 2014 Advance Notification Multiple Vulnerabilities
13034| [67298] Microsoft May 2014 Advance Notification Multiple Vulnerabilities
13035| [66639] RETIRED: Microsoft April 2014 Advance Notification Multiple Vulnerabilities
13036| [66016] Microsoft March 2014 Notification Multiple Vulnerabilities
13037| [65426] Microsoft February 2014 Notification Multiple Vulnerabilities
13038| [64757] RETIRED: Microsoft January 2014 Advance Notification Multiple Vulnerabilities
13039| [64083] RETIRED: Microsoft December 2013 Advance Notification Multiple Vulnerabilities
13040| [63604] RETIRED: Microsoft November 2013 Advance Notification Multiple Vulnerabilities
13041| [62797] RETIRED: Microsoft October 2013 Advance Notification Multiple Vulnerabilities
13042| [62228] RETIRED: Microsoft September 2013 Advance Notification Multiple Vulnerabilities
13043| [62181] Microsoft Office Pinyin IME 2010 CVE-2013-3859 Local Privilege Escalation Vulnerability
13044| [61686] Microsoft August 2013 Advance Notification Multiple Vulnerabilities
13045| [60960] RETIRED: Microsoft July 2013 Advance Notification Multiple Vulnerabilities
13046| [60394] Microsoft June 2013 Advance Notification Multiple Vulnerabilities
13047| [59785] RETIRED: Microsoft May 2013 Advance Notification Multiple Vulnerabilities
13048| [58881] RETIRED: Microsoft April 2013 Advance Notification Multiple Vulnerabilities
13049| [58380] RETIRED: Microsoft March 2013 Advance Notification Multiple Vulnerabilities
13050| [57846] RETIRED: Microsoft February 2013 Advance Notification Multiple Vulnerabilities
13051| [57137] RETIRED: Microsoft January 2013 Advance Notification Multiple Vulnerabilities
13052| [56838] RETIRED: Microsoft December 2012 Advance Notification Multiple Vulnerabilities
13053| [56450] RETIRED: Microsoft November 2012 Advance Notification Multiple Vulnerabilities
13054| [56304] Microsoft Office Excel 2010 Memory Corruption Denial of Service Vulnerability
13055| [55794] RETIRED: Microsoft October 2012 Advance Notification Multiple Vulnerabilities
13056| [55472] RETIRED: Microsoft September 2012 Advance Notification Multiple Vulnerabilities
13057| [54944] RETIRED: Microsoft August 2012 Advance Notification Multiple Vulnerabilities
13058| [54318] RETIRED: Microsoft July 2012 Advance Notification Multiple Vulnerabilities
13059| [53862] RETIRED: Microsoft June 2012 Advance Notification Multiple Vulnerabilities
13060| [53372] RETIRED: Microsoft May 2012 Advance Notification Multiple Vulnerabilities
13061| [52910] RETIRED: Microsoft April 2012 Advance Notification Multiple Vulnerabilities
13062| [52366] RETIRED: Microsoft March 2012 Advance Notification Multiple Vulnerabilities
13063| [51944] RETIRED: Microsoft February 2012 Advance Notification Multiple Vulnerabilities
13064| [51289] RETIRED: Microsoft January 2012 Advance Notification Multiple Vulnerabilities
13065| [50980] RETIRED: Microsoft December 2011 Advance Notification Multiple Vulnerabilities
13066| [50513] RETIRED: Microsoft November 2011 Advance Notification Multiple Vulnerabilities
13067| [49994] RETIRED: Microsoft October 2011 Advance Notification Multiple Vulnerabilities
13068| [49515] RETIRED: Microsoft September 2011 Advance Notification Multiple Vulnerabilities
13069| [49017] RETIRED: Microsoft August 2011 Advance Notification Multiple Vulnerabilities
13070| [48616] RETIRED: Microsoft July 2011 Advance Notification Multiple Vulnerabilities
13071| [48235] Microsoft Lync Server 2010 'ReachJoin.aspx' Remote Command Injection Vulnerability
13072| [48193] RETIRED: Microsoft June 2011 Advance Notification Multiple Vulnerabilities
13073| [47725] RETIRED: Microsoft May 2011 Advance Notification Multiple Vulnerabilities
13074| [47255] RETIRED: Microsoft April 2011 Advance Notification Multiple Vulnerabilities
13075| [46675] RETIRED: Microsoft March 2011 Advance Notification Multiple Vulnerabilities
13076| [46132] RETIRED: Microsoft February 2011 Advance Notification Multiple Vulnerabilities
13077| [45696] RETIRED: Microsoft January 2011 Advance Notification Multiple Vulnerabilities
13078| [45307] RETIRED: Microsoft December 2010 Advance Notification Multiple Vulnerabilities
13079| [44649] RETIRED: Microsoft November 2010 Advance Notification Multiple Vulnerabilities
13080| [43831] RETIRED: Microsoft October 2010 Advance Notification Multiple Vulnerabilities
13081| [43115] RETIRED: Microsoft September 2010 Advance Notification Multiple Vulnerabilities
13082| [42234] RETIRED: Microsoft August 2010 Advance Notification Multiple Vulnerabilities
13083| [41474] RETIRED: Microsoft July 2010 Advance Notification Multiple Vulnerabilities
13084| [40548] RETIRED: Microsoft June 2010 Advance Notification Multiple Vulnerabilities
13085| [39961] RETIRED: Microsoft May 2010 Advance Notification Multiple Vulnerabilities
13086| [39313] RETIRED: Microsoft April 2010 Advance Notification Multiple Vulnerabilities
13087| [38540] RETIRED: Microsoft March 2010 Advance Notification Multiple Vulnerabilities
13088| [38096] RETIRED: Microsoft February 2010 Advance Notification Multiple Vulnerabilities
13089| [37887] RETIRED: Microsoft January 2010 Advance Notification Multiple Vulnerabilities
13090| [37664] RETIRED: Microsoft January 2010 Advance Notification Multiple Vulnerabilities
13091| [32642] Microsoft Word RTF Malformed Control Word Variant 2 Remote Code Execution Vulnerability
13092|
13093| IBM X-Force - https://exchange.xforce.ibmcloud.com:
13094| [82417] Microsoft Windows Knowledge Base Article 2801261 update is not installed
13095| [82415] Microsoft Windows Knowledge Base Article 2807986 update is not installed
13096| [82410] Microsoft Windows Knowledge Base Article 2809289 update is not installed
13097| [81859] Microsoft Windows Knowledge Base Article 2802968 update is not installed
13098| [81857] Microsoft Windows Knowledge Base Article 2809279 update is not installed
13099| [81668] Microsoft Windows Knowledge Base Article 2800277 update is not installed
13100| [77323] Microsoft Windows Knowledge Base Article 2706045 update is not installed
13101| [75949] Microsoft Windows Knowledge Base Article 2707960 update is not installed
13102| [75942] Microsoft Windows Knowledge Base Article 2706726 update is not installed
13103| [75934] Microsoft Windows Knowledge Base Article 2709162 update is not installed
13104| [75926] Microsoft Windows Knowledge Base Article 2709100 update is not installed
13105| [75905] Microsoft Windows Knowledge Base Article 2707956 update is not installed
13106| [71991] Microsoft Windows Knowledge Base Article 2607664 update is not installed
13107| [71542] Microsoft Windows Knowledge Base Article 2607702 update is not installed
13108| [70945] Microsoft Windows Knowledge Base Article 2603381 update is not installed
13109| [70150] Microsoft Windows Knowledge Base Article 2607670 update is not installed
13110| [67755] Microsoft Windows Knowledge Base Article 2503665 update is not installed
13111| [67749] Microsoft Windows Knowledge Base Article 2507938 update is not installed
13112| [66845] Microsoft Windows Knowledge Base Article 2506014 update is not installed
13113| [66844] Microsoft Windows Knowledge Base Article 2501584 update is not installed
13114| [66448] Microsoft Windows Knowledge Base Article 2508272 update is not installed
13115| [66442] Microsoft Windows Knowledge Base Article 2509553 update is not installed
13116| [66440] Microsoft Windows Knowledge Base Article 2508429 update is not installed
13117| [66438] Microsoft Windows Knowledge Base Article 2507618 update is not installed
13118| [66430] Microsoft Windows Knowledge Base Article 2503658 update is not installed
13119| [66425] Microsoft Windows Knowledge Base Article 2506223 update is not installed
13120| [65570] Microsoft Windows Knowledge Base Article 2500212 update is not installed
13121| [65568] Microsoft Windows Knowledge Base Article 2508062 update is not installed
13122| [63840] Microsoft Visual C++ 2008 Redistributable Package dynamic-linked library (DLL) code execution
13123| [63780] Microsoft PowerPoint 2007 dynamic-linked library (rpawinet.dll) code execution
13124| [63775] Microsoft Visio 2003 dynamic-linked library (mfc71enu.dll) code execution
13125| [63586] Microsoft Windows Knowledge Base Article 2207559 update is not installed
13126| [63573] Microsoft Windows Knowledge Base Article 2407132 update is not installed
13127| [62797] Microsoft Windows Knowledge Base Article 2305420 update is not installed
13128| [62149] Microsoft Windows Knowledge Base Article 2207566 update is not installed
13129| [62133] Microsoft Windows Knowledge Base Article 2405882 update is not installed
13130| [53980] Microsoft Windows 2000 License Logging Server buffer overflow
13131| [53601] Microsoft Office 2008 for Mac user ID 502 security bypass
13132| [50973] Microsoft Windows Server 2003 and Vista win32k.sys denial of service
13133| [50759] Microsoft Windows 2000 Active Directory LDAP code execution
13134| [48595] Microsoft Word 2007 Email as PDF information disclosure
13135| [46102] Microsoft Windows 2003 SP2 is not installed on the system
13136| [46101] Microsoft Windows 2003 SP1 is not installed on the system
13137| [45186] Microsoft SQL Server 2000 SQLVDIRLib.SQLVDirControl ActiveX control buffer overflow
13138| [37200] Microsoft SQL Server 2000 Service Pack 1 update is not installed
13139| [37198] Microsoft SQL Server 2000 Service Pack 3 update is not installed
13140| [34634] Microsoft Windows Server 2003 Active Directory information disclosure
13141| [34599] Microsoft Windows Server 2003 terminal server security bypass
13142| [34473] Microsoft Office 2000 ActiveX control buffer overflow
13143| [33713] Microsoft Word 2007 multiple unspecified denial of service
13144| [33712] Microsoft Word 2007 wwlib.dll buffer overflow
13145| [32631] Microsoft SQL Server 2000 Service Pack 2 update is not installed
13146| [31821] Microsoft Windows time zone update for year 2007
13147| [31196] Microsoft Office 2003 Brazilian Grammar Checker buffer overflow
13148| [30905] Microsoft Project Server 2003 pdsrequest.asp information disclosure
13149| [29546] Microsoft Windows 2000/2003 user logoff initiated
13150| [29545] Microsoft Windows 2000/2003 system time changed
13151| [29544] Microsoft Windows 2000/2003 system security access removed
13152| [29543] Microsoft Windows 2000/2003 security access granted
13153| [29542] Microsoft Windows 2000/2003 SAM notification package loaded
13154| [29541] Microsoft Windows 2000/2003 primary security token issued
13155| [29540] Microsoft Windows 2000/2003 user password reset successful
13156| [29539] Microsoft Windows 2000/2003 object indirectly accessed
13157| [29538] Microsoft Windows 2000/2003 object handle duplicated
13158| [29537] Microsoft Windows 2000/2003 logon with explicit credentials success
13159| [29536] Microsoft Windows 2000/2003 logon attempt using explicit credentials unsuccessful
13160| [29535] Microsoft Windows 2000/2003 IPSEC policy agent failed
13161| [29534] Microsoft Windows 2000/2003 IPSEC policy agent disabled
13162| [29533] Microsoft Windows 2000/2003 IPSEC policy agent changed
13163| [29532] Microsoft Windows 2000/2003 IKE security association established
13164| [29531] Microsoft Windows 2000/2003 IKE quick mode association ended
13165| [29530] Microsoft Windows 2000/2003 IKE main mode association ended
13166| [29529] Microsoft Windows 2000/2003 IKE association negotiation failed
13167| [29528] Microsoft Windows 2000/2003 IKE association peer authentication failed
13168| [29527] Microsoft Windows 2000/2003 IKE association failed invalid proposal
13169| [29526] Microsoft Windows 2000/2003 IKE association failed authentication parameters
13170| [29525] Microsoft Windows 2000/2003 DPAPI master key backup attempted
13171| [29524] Microsoft Windows 2000/2003 DPAPI key recovery attempted
13172| [29523] Microsoft Windows 2000/2003 DPAPI auditable data unprotected
13173| [29522] Microsoft Windows 2000/2003 administrative group security descriptor set
13174| [29521] Microsoft Windows 2000/2003 account name changed
13175| [29507] Microsoft Office 2003 unspecified PowerPoint NULL pointer dereference denial of service
13176| [28512] Microsoft Internet Explorer multiple Windows 2000 COM object denial of service
13177| [28005] Microsoft Windows 2000 Management Console (MMC) resource file cross-site scripting
13178| [26118] Microsoft Office 2003 mailto: information disclosure
13179| [25330] Microsoft Commerce Server 2002 authfiles/login.asp authentication bypass
13180| [24474] Microsoft Windows 2000 LDAP client accepts untrusted CA
13181| [24473] Microsoft Windows 2000 event ID 565 not logged
13182| [24472] Microsoft Windows 2000 Event ID 1704 records incorrect group policy settings
13183| [24407] Microsoft Windows 2000 SECEDIT command fails to set ACLs correctly
13184| [24405] Microsoft Windows 2000 UPN credentials with trailing dot group policy bypass
13185| [24403] Microsoft Windows 2000 WideCharToMultiByte() incorrect Japanese character conversion
13186| [24402] Microsoft Windows 2000 Terminal Service client IP not logged
13187| [24400] Microsoft Windows 2000 domain authentication can be bypassed by a local administrator
13188| [23066] Microsoft Windows XP and 2000 Server MSRPC memory allocation denial of service
13189| [22318] Microsoft SQL Server 2000 Service Pack 4 update is not installed
13190| [22183] Microsoft Exchange Server 2003 public folder denial of service
13191| [21345] Microsoft Windows 2000 Update Rollup 1 for Service Pack 4 has not been installed
13192| [21315] Microsoft Outlook 2002 connector for Domino bypass restrictions
13193| [19969] Multiple Microsoft Windows Server 2003 Edition printer driver denial of service
13194| [19965] Multiple Microsoft Windows Server 2003 Editions SMB redirector denial of service
13195| [19727] Microsoft Windows 2000 GDI32.DLL denial of service
13196| [19629] Microsoft Exchange Server 2003 folder denial of service
13197| [17826] Microsoft Outlook 2003 CID security bypass
13198| [17624] Microsoft Windows XP and Windows Server 2003 Compressed Folders buffer overflow
13199| [17621] Microsoft Windows 2003 SMTP service code execution
13200| [17560] Microsoft Windows 2000 and XP GDI library denial of service
13201| [17521] Microsoft Windows 2000 Service Pack 4 is not installed
13202| [16913] Microsoft Windows 2003 users with Synchronize directory service data privilege
13203| [16912] Microsoft Windows 2003 groups with Synchronize directory service data privilege
13204| [16909] Microsoft Windows 2003 groups with Remove computer from docking station privilege
13205| [16907] Microsoft Windows 2003 users with Create global objects privilege
13206| [16905] Microsoft Windows 2003 users or groups with Create global objects privilege
13207| [16851] Microsoft Windows 2003 and XP WinKey and U key denial of service
13208| [16704] Microsoft Windows 2000 Media Player control code execution
13209| [16582] Microsoft Windows Server 2003 kernel CPU denial of service
13210| [16572] Microsoft Windows 2003 Users with Impersonate a client after authentication privilege
13211| [16570] Microsoft Windows 2003 Users with Create global objects privilege
13212| [16564] Microsoft Windows 2003 Groups with Create global objects privilege
13213| [16562] Microsoft Windows 2003 Groups with "
13214| [16522] Microsoft Windows 2003 Impersonate a client after authentication privilege
13215| [16521] Microsoft Windows 2003 Deny Logon Through Terminal Services privilege
13216| [16520] Microsoft Windows 2003 Create global objects privilege
13217| [16276] Microsoft Windows 2000 Advanced Server fully qualified domain name security bypass
13218| [16173] Microsoft Outlook 2003 OLE object bypass restricted security zone
13219| [16119] Microsoft Outlook 2000 URL spoofing
13220| [16104] Microsoft Outlook 2003 predictable file location could allow code execution
13221| [16095] Microsoft Windows XP and Windows Server 2003 HCP URL code execution
13222| [15704] Microsoft Windows XP and Windows Server 2003 HCP URL code execution
13223| [15700] Microsoft Windows 2000 Domain Controller LSASS LDAP message denial of service
13224| [15632] Microsoft Windows 2000 Utility Manger allows privilege escalation
13225| [15414] Microsoft Outlook 2002 mailto URL allows execution of code
13226| [15263] Microsoft Windows XP and 2000 Server kernel allows elevated privileges
13227| [15057] Microsoft Windows XP and Windows Server 2003 smbmount Linux client denial of service
13228| [15038] Microsoft Windows 2000 Server Windows Media Services denial of service
13229| [15037] Microsoft Windows Server 2003 WINS /GS flag denial of service
13230| [14178] Microsoft ISA Exchange Server 2003 MS04-002 patch is not installed
13231| [14167] Microsoft ISA Server 2000 H.323 filter buffer overflow
13232| [13426] Microsoft Windows 2000 and XP RPC race condition
13233| [13423] Microsoft Windows 2000 Local Troubleshooter ActiveX control buffer overflow
13234| [13407] Microsoft Windows 2000 Server mqsvc.exe MQLocateBegin packet buffer overflow
13235| [13385] Microsoft Windows Server 2003 "
13236| [13211] Microsoft Windows 2000 and XP URG memory leak
13237| [13171] Microsoft Windows Server 2003 can allow attacker to bypass mechanism used to detect buffer overflows
13238| [13131] Microsoft Windows 2000 Message Queue Manager buffer overflow
13239| [12684] Microsoft Exchange Server OWA Outlook 2003 denial of service
13240| [12652] Microsoft Windows 2000 and NT 4.0 Server IIS ISAPI nsiislog.dll extension POST request buffer overflow
13241| [12620] Microsoft Windows 2000 Server SMTP FILETIME denial of service
13242| [12543] Microsoft Windows 2000 Accessibility Utility Manager could allow an attacker to gain privileges
13243| [12493] Microsoft Windows Shell32.dll 2000 ShellExecute function buffer overflow
13244| [12489] Microsoft Windows 2000 Server Active Directory buffer overflow
13245| [12128] Microsoft Windows 2000 and Windows NT MS03-019 patch is not installed
13246| [12092] Microsoft Windows 2000 and NT 4.0 Server IIS ISAPI nsiislog.dll extension buffer overflow
13247| [12048] Microsoft Windows 2000 and Windows Server 2003 LAN Manager hash creation enabled
13248| [11901] Microsoft BizTalk Server 2002 SQL injection
13249| [11900] Microsoft BizTalk Server 2002 HTTP Receiver function buffer overflow
13250| [11816] Microsoft Windows 2000 Terminal Services MSGINA.DLL insecure access permissions
13251| [11696] Microsoft Windows 2000 Terminal Services man-in-the-middle attack
13252| [11617] Microsoft Windows 2000 MS03-007 patch is not installed on the system
13253| [11546] Microsoft Windows 2000 Windows Help Facility .cnt file buffer overflow
13254| [11329] Microsoft Windows NT and 2000 cmd.exe CD path name buffer overflow
13255| [11274] Microsoft Windows 2000 NetBIOS continuation packets denial of service
13256| [11273] Microsoft Windows 2000 RPC service could allow an attacker to gain elevated privileges
13257| [11216] Microsoft Windows NT and 2000 command prompt denial of service
13258| [11141] Microsoft Windows 2000 Terminal Services MSGINA.DLL denial of service
13259| [11133] Microsoft Outlook 2002 using V1 Exchange Server Security certificates transmits plaintext emails
13260| [10843] Microsoft Windows 2000 and XP SMB signing group policy modification
13261| [10431] Microsoft Windows 2000 SNMP LANMAN Extension memory leak denial of service
13262| [10400] Microsoft Windows 2000 RPC TCP port 135 denial of service
13263| [10377] Microsoft Windows XP and 2000 administrative alerts fail when security event log is full
13264| [10199] Microsoft Windows 2000/XP PPTP packet buffer overflow
13265| [10195] Microsoft FrontPage Server Extensions (FPSE) 2002 SmartHTML Interpreter buffer overflow
13266| [10194] Microsoft FrontPage Server Extensions (FPSE) 2000 SmartHTML Interpreter denial of service
13267| [9946] Microsoft Windows 2000 Terminal Services session screensaver fails to lock the console
13268| [9856] Microsoft Windows 2000 NCM handler routine could allow elevated privileges
13269| [9779] Microsoft Windows 2000 weak system partition permissions
13270| [9752] Microsoft Windows 2000 Service Pack 3 is not installed
13271| [9746] Microsoft Windows 2000 HTML Help item parameter buffer overflow
13272| [9625] Microsoft Windows 2000 Narrator allows login information to be audible
13273| [9154] Microsoft Data Engine (MSDE) and Microsoft SQL Server 2000 Desktop Engine have a default blank "
13274| [8867] Microsoft Windows 2000 LanMan denial of service
13275| [8813] Microsoft Windows 2000 Terminal Services allows attacker to bypass group policy settings
13276| [8759] Microsoft Windows 2000 could allow an attacker to block the application of Group Policy settings
13277| [8752] Microsoft Windows NT, 2000, and XP MUP buffer overflow
13278| [8739] Microsoft Windows 2000 DCOM memory leak
13279| [8708] Microsoft Outlook 2000 and 2002 executes embedded script in object tag when replying or forwarding HTML mail
13280| [8402] Microsoft Windows 2000 allows an attacker to bypass password policy
13281| [8307] Microsoft Windows 2000, Windows XP, and Exchange 2000 SMTP data transfer command denial of service
13282| [8304] Microsoft Windows 2000 and Exchange 5.5 SMTP service unauthorized mail privileges
13283| [8254] Microsoft Commerce Server 2000 AuthFilter ISAPI filter buffer overflow
13284| [8199] Microsoft Windows 2000 Terminal Services unlocked client
13285| [8094] Microsoft Windows 2000 and Interix 2.2 Telnet protocol option buffer overflow
13286| [8092] Microsoft Exchange 2000 System Attendant sets incorrect registry permissions
13287| [8043] Microsoft Windows NT, 2000, and XP using NTFS could allow files to be hidden
13288| [8037] Microsoft Windows 2000 empty TCP packet denial of service
13289| [8023] Microsoft Windows NT and Windows 2000 SIDs could allow an attacker to gain elevated privileges in another domain
13290| [7919] Microsoft IIS 4.0 and Norton Internet Security 2001 default permissions could allow an attacker to modify log files
13291| [7667] Microsoft Windows 2000 IKE UDP packet flood denial of service
13292| [7566] Microsoft IIS 2.0 and 3.0 upgraded to Microsoft IIS 4.0 fails to remove the ism.dll file
13293| [7538] Microsoft Windows 2000 and XP Terminal services allow an attacker to spoof IP addresses
13294| [7533] Microsoft Windows 2000 RunAs service denial of service
13295| [7532] Microsoft Windows 2000 RunAs service allows local attacker to bypass pipe authentication
13296| [7531] Microsoft Windows 2000 RunAs service reveals sensitive information
13297| [7528] Microsoft Windows NT and Windows 2000 malformed RPC request denial of service
13298| [7409] Microsoft Windows 2000 and Windows XP GDI denial of service
13299| [7302] Microsoft Windows NT and 2000 Terminal Server malformed RDP packet series denial of service
13300| [7008] Microsoft Windows 2000 IrDA device denial of service
13301| [6977] Microsoft Windows NT and 2000 NNTP memory leak denial of service
13302| [6931] Microsoft Windows 2000 without Service Pack 2
13303| [6919] Microsoft Windows 2000 Task Manager does not terminate malicious files with the same name as a system process
13304| [6912] Microsoft Windows NT and 2000 Terminal Server RDP memory leak denial of service
13305| [6876] Microsoft Windows 2000 could allow an attacker to change network passwords
13306| [6803] Microsoft Windows 2000 SMTP service allows mail relaying
13307| [6745] Microsoft Windows 2000 LDAP function could allow domain user password change
13308| [6669] Microsoft Windows 2000 Telnet system call denial of service
13309| [6668] Microsoft Windows 2000 Telnet handle leak denial of service
13310| [6667] Microsoft Windows 2000 Telnet multiple idle sessions denial of service
13311| [6666] Microsoft Windows 2000 Telnet username denial of service
13312| [6665] Microsoft Windows 2000 Telnet service weak domain authentication
13313| [6664] Microsoft Windows 2000 Telnet service predictable pipe names could allow elevation of privileges
13314| [6652] Microsoft Exchange 2000 OWA script execution
13315| [6590] Microsoft Windows 2000 debug registers allow attacker to gain elevated privileges
13316| [6506] Microsoft Windows 2000 Server Kerberos denial of service
13317| [6443] Microsoft Windows 2000 catalog file could remove installed hotfixes
13318| [6160] Microsoft Windows 2000 event viewer buffer overflow
13319| [6136] Microsoft Windows 2000 domain controller denial of service
13320| [6035] Microsoft Windows 2000 Server RDP denial of service
13321| [5973] Microsoft Windows 2000 EFS allows local user to recover sensitive data
13322| [5936] Microsoft Windows 2000 Server Directory Service Restore Mode allows user to login with blank password
13323| [5800] Microsoft Windows 2000 Index Service ActiveX controls allow unauthorized access to file information
13324| [5623] Microsoft Windows NT and 2000 Phone Book service buffer overflow
13325| [5598] Microsoft Windows 2000 Telnet daemon could allow a denial of service
13326| [5585] Microsoft Windows 2000 brute force attack
13327| [5502] Microsoft Windows 2000 Indexing Services ixsso.query
13328| [5467] Microsoft Windows 2000 System Monitor ActiveX control buffer overflow
13329| [5399] Microsoft Windows NT and 2000 Network Monitor buffer overflow
13330| [5301] Microsoft Windows 2000 Simplified Chinese IME State Recognition
13331| [5263] Microsoft Office 2000 executes .dll without users knowledge
13332| [5242] Microsoft Windows 2000 Telnet client NTLM authentication weakness
13333| [5222] Microsoft Windows 2000 malformed RPC packet denial of service
13334| [5203] Microsoft Windows 2000 still image service
13335| [5171] Microsoft Windows 2000 Local Security Policy corruption
13336| [5080] Microsoft Office 2000 HTML object tag buffer overflow
13337| [5033] Microsoft Windows 2000 without Service Pack 1
13338| [5031] Microsoft Windows 2000 Service Control Manager named pipe could allow a unauthorized user to gain privileges
13339| [5015] Microsoft Windows NT and 2000 executable path
13340| [4887] Microsoft Windows 2000 Kerberos ticket renewed
13341| [4886] Microsoft Windows 2000 logon session reconnected
13342| [4885] Microsoft Windows 2000 logon session disconnected
13343| [4882] Microsoft Windows 2000 Kerberos pre-authentication failed
13344| [4873] Microsoft Windows 2000 user account mapped for logon
13345| [4872] Microsoft Windows 2000 account logon failed
13346| [4871] Microsoft Windows 2000 account used for logon
13347| [4855] Microsoft Windows 2000 group type change
13348| [4842] Microsoft Internet Explorer and Microsoft Powerpoint 2000 ActiveX object execution
13349| [4841] Microsoft Internet Explorer and Microsoft Access 2000 VBA code execution
13350| [4823] Microsoft Windows 2000 Telnet server binary stream denial of service
13351| [4819] Microsoft Windows 2000 default SYSKEY configuration
13352| [4787] Microsoft Windows 2000 user account locked out
13353| [4786] Microsoft Windows 2000 computer account created
13354| [4785] Microsoft Windows 2000 computer account changed
13355| [4784] Microsoft Windows 2000 computer account deleted
13356| [4714] Microsoft Windows 2000 "
13357| [4589] Microsoft Windows 2000 protected store can be compromised by brute force attack
13358| [4278] Microsoft Windows 2000 unattended install does not secure All Users profile
13359| [4138] Microsoft Windows 2000 system file integrity feature is disabled
13360| [4086] Microsoft Windows 2000 may not start Jaz drives correctly
13361| [4085] Microsoft Windows 2000 non-Gregorial calendar error
13362| [4084] Microsoft Windows 2000 may prevent Adobe FrameMaker files from being saved in some formats
13363| [4083] Microsoft Windows 2000 Terminal Services may damage Office files saved as HTML
13364| [4082] Microsoft Windows 2000 and Iomega parallel port drives display error
13365| [4080] Microsoft Windows 2000 AOL image support
13366| [4079] Microsoft Windows 2000 High Encryption Pack
13367| [3854] Microsoft Office 2000 security setting
13368| [1376] Microsoft Proxy 2.0 denial of service
13369| [86256] Microsoft Windows Knowledge Base Article 2876063 update is not installed
13370| [86097] Microsoft Windows Knowledge Base Article 2859537 update is not installed
13371| [86091] Microsoft Windows Knowledge Base Article 2868623 update is not installed
13372| [86089] Microsoft Windows Knowledge Base Article 2862772 update is not installed
13373| [86075] Microsoft Windows Knowledge Base Article 2850869 update is not installed
13374| [86073] Microsoft Windows Knowledge Base Article 2873872 update is not installed
13375| [86070] Microsoft Windows Knowledge Base Article 2849568 update is not installed
13376| [85245] Microsoft Windows Knowledge Base Article 2848295 update is not installed
13377| [85244] Microsoft Windows Knowledge Base Article 2847927 update is not installed
13378| [85243] Microsoft Windows Knowledge Base Article 2861561 update is not installed
13379| [85236] Microsoft Windows Knowledge Base Article 2850851 update is not installed
13380| [85227] Microsoft Windows Knowledge Base Article 2847883 update is not installed
13381| [85223] Microsoft Windows Knowledge Base Article 2846071 update is not installed
13382| [85205] Microsoft Windows Knowledge Base Article 2845187 update is not installed
13383| [84621] Microsoft Windows Knowledge Base Article 2845690 update is not installed
13384| [84619] Microsoft Windows Knowledge Base Article 2839894 update is not installed
13385| [84617] Microsoft Windows Knowledge Base Article 2839571 update is not installed
13386| [84615] Microsoft Windows Knowledge Base Article 2839229 update is not installed
13387| [84613] Microsoft Windows Knowledge Base Article 2838727 update is not installed
13388| [84156] Microsoft Windows Knowledge Base Article 2847204 update is not installed
13389| [83912] Microsoft Windows Knowledge Base Article 2829254 update is not installed
13390| [83910] Microsoft Windows Knowledge Base Article 2829530 update is not installed
13391| [83898] Microsoft Windows Knowledge Base Article 2830397 update is not installed
13392| [83886] Microsoft Windows Knowledge Base Article 2830399 update is not installed
13393| [83884] Microsoft Windows Knowledge Base Article 2834692 update is not installed
13394| [83882] Microsoft Windows Knowledge Base Article 2834695 update is not installed
13395| [83880] Microsoft Windows Knowledge Base Article 2836440 update is not installed
13396| [83876] Microsoft Windows Knowledge Base Article 2840221 update is not installed
13397| [83192] Microsoft Windows Knowledge Base Article 2817183 update is not installed
13398| [83100] Microsoft Windows Knowledge Base Article 2830914 update is not installed
13399| [83098] Microsoft Windows Knowledge Base Article 2829996 update is not installed
13400| [83093] Microsoft Windows Knowledge Base Article 2828223 update is not installed
13401| [83091] Microsoft Windows Knowledge Base Article 2813170 update is not installed
13402| [83088] Microsoft Windows Knowledge Base Article 2827663 update is not installed
13403| [83086] Microsoft Windows Knowledge Base Article 2823482 update is not installed
13404| [83084] Microsoft Windows Knowledge Base Article 2821818 update is not installed
13405| [83082] Microsoft Windows Knowledge Base Article 2820917 update is not installed
13406| [82600] Microsoft Windows Knowledge Base Article 2813707 update is not installed
13407| [82424] Microsoft Windows Knowledge Base Article 2814124 update is not installed
13408| [82422] Microsoft Windows Knowledge Base Article 2780176 update is not installed
13409| [82401] Microsoft Windows Knowledge Base Article 2813682 update is not installed
13410| [82399] Microsoft Windows Knowledge Base Article 2816264 update is not installed
13411| [81683] Microsoft Windows Knowledge Base Article 2780091 update is not installed
13412| [81681] Microsoft Windows Knowledge Base Article 2784242 update is not installed
13413| [81680] Microsoft Windows Knowledge Base Article 2790113 update is not installed
13414| [81678] Microsoft Windows Knowledge Base Article 2790655 update is not installed
13415| [81676] Microsoft Windows Knowledge Base Article 2790978 update is not installed
13416| [81674] Microsoft Windows Knowledge Base Article 2797052 update is not installed
13417| [81672] Microsoft Windows Knowledge Base Article 2799494 update is not installed
13418| [81666] Microsoft Windows Knowledge Base Article 2778344 update is not installed
13419| [81634] Microsoft Windows Knowledge Base Article 2792100 update is not installed
13420| [81339] Microsoft Windows Knowledge Base Article 2799329 update is not installed
13421| [80875] Microsoft Windows Knowledge Base Article 2756145 update is not installed
13422| [80872] Microsoft Windows Knowledge Base Article 2769324 update is not installed
13423| [80867] Microsoft Windows Knowledge Base Article 2769327 update is not installed
13424| [80865] Microsoft Windows Knowledge Base Article 2769369 update is not installed
13425| [80863] Microsoft Windows Knowledge Base Article 2778930 update is not installed
13426| [80861] Microsoft Windows Knowledge Base Article 2785220 update is not installed
13427| [80365] Microsoft Windows Knowledge Base Article 2761465 update is not installed
13428| [80360] Microsoft Windows Knowledge Base Article 2765809 update is not installed
13429| [80358] Microsoft Windows Knowledge Base Article 2770660 update is not installed
13430| [80356] Microsoft Windows Knowledge Base Article 2780642 update is not installed
13431| [80352] Microsoft Windows Knowledge Base Article 2783534 update is not installed
13432| [80349] Microsoft Windows Knowledge Base Article 2784126 update is not installed
13433| [79693] Microsoft Windows Knowledge Base Article 2745030 update is not installed
13434| [79687] Microsoft Windows Knowledge Base Article 2761451 update is not installed
13435| [79683] Microsoft Windows Knowledge Base Article 2761226 update is not installed
13436| [79679] Microsoft Windows Knowledge Base Article 2758857 update is not installed
13437| [79677] Microsoft Windows Knowledge Base Article 2727528 update is not installed
13438| [78864] Microsoft Windows Knowledge Base Article 2754670 update is not installed
13439| [78862] Microsoft Windows Knowledge Base Article 2743555 update is not installed
13440| [78858] Microsoft Windows Knowledge Base Article 2754849 update is not installed
13441| [78856] Microsoft Windows Knowledge Base Article 2724197 update is not installed
13442| [78853] Microsoft Windows Knowledge Base Article 2741517 update is not installed
13443| [78851] Microsoft Windows Knowledge Base Article 2742319 update is not installed
13444| [78848] Microsoft Windows Knowledge Base Article 2742321 update is not installed
13445| [78760] Microsoft Windows Knowledge Base Article 2744842 update is not installed
13446| [78077] Microsoft Windows Knowledge Base Article 2741528 update is not installed
13447| [78075] Microsoft Windows Knowledge Base Article 2720184 update is not installed
13448| [78071] Microsoft Windows Knowledge Base Article 2748552 update is not installed
13449| [77512] Microsoft Windows Knowledge Base Article 2740358 update is not installed
13450| [77362] Microsoft Windows Knowledge Base Article 2733918 update is not installed
13451| [77360] Microsoft Windows Knowledge Base Article 2733829 update is not installed
13452| [77357] Microsoft Windows Knowledge Base Article 2733594 update is not installed
13453| [77352] Microsoft Windows Knowledge Base Article 2731879 update is not installed
13454| [77350] Microsoft Windows Knowledge Base Article 2731847 update is not installed
13455| [77348] Microsoft Windows Knowledge Base Article 2723135 update is not installed
13456| [77346] Microsoft Windows Knowledge Base Article 2722913 update is not installed
13457| [77342] Microsoft Windows Knowledge Base Article 2720573 update is not installed
13458| [77325] Microsoft Windows Knowledge Base Article 2719584 update is not installed
13459| [76808] Microsoft Windows Knowledge Base Article 2721015 update is not installed
13460| [76725] Microsoft Windows Knowledge Base Article 2722479 update is not installed
13461| [76724] Microsoft Windows Knowledge Base Article 2719177 update is not installed
13462| [76721] Microsoft Windows Knowledge Base Article 2718523 update is not installed
13463| [76718] Microsoft Windows Knowledge Base Article 2698365 update is not installed
13464| [76711] Microsoft Windows Knowledge Base Article 2695502 update is not installed
13465| [76704] Microsoft Windows Knowledge Base Article 2691442 update is not installed
13466| [76702] Microsoft Windows Knowledge Base Article 2655992 update is not installed
13467| [75963] Microsoft Windows Knowledge Base Article 2699988 update is not installed
13468| [75939] Microsoft Windows Knowledge Base Article 2685939 update is not installed
13469| [75928] Microsoft Windows Knowledge Base Article 2711167 update is not installed
13470| [75136] Microsoft Windows Knowledge Base Article 2693777 update is not installed
13471| [75132] Microsoft Windows Knowledge Base Article 2690533 update is not installed
13472| [75130] Microsoft Windows Knowledge Base Article 2688338 update is not installed
13473| [75127] Microsoft Windows Knowledge Base Article 2681578 update is not installed
13474| [75123] Microsoft Windows Knowledge Base Article 2680352 update is not installed
13475| [75116] Microsoft Windows Knowledge Base Article 2597981 update is not installed
13476| [74556] Microsoft Windows Knowledge Base Article 2639185 update is not installed
13477| [74384] Microsoft Windows Knowledge Base Article 2675157 update is not installed
13478| [74378] Microsoft Windows Knowledge Base Article 2671605 update is not installed
13479| [74373] Microsoft Windows Knowledge Base Article 2664258 update is not installed
13480| [74369] Microsoft Windows Knowledge Base Article 2663860 update is not installed
13481| [73543] Microsoft Windows Knowledge Base Article 2671387 update is not installed
13482| [73540] Microsoft Windows Knowledge Base Article 2665364 update is not installed
13483| [73538] Microsoft Windows Knowledge Base Article 2651019 update is not installed
13484| [73536] Microsoft Windows Knowledge Base Article 2651018 update is not installed
13485| [73533] Microsoft Windows Knowledge Base Article 2647170 update is not installed
13486| [73530] Microsoft Windows Knowledge Base Article 2641653 update is not installed
13487| [72887] Microsoft Windows Knowledge Base Article 2663841 update is not installed
13488| [72873] Microsoft Windows Knowledge Base Article 2663830 update is not installed
13489| [72867] Microsoft Windows Knowledge Base Article 2663510 update is not installed
13490| [72857] Microsoft Windows Knowledge Base Article 2661637 update is not installed
13491| [72855] Microsoft Windows Knowledge Base Article 2660465 update is not installed
13492| [72853] Microsoft Windows Knowledge Base Article 2653956 update is not installed
13493| [72851] Microsoft Windows Knowledge Base Article 2654428 update is not installed
13494| [72849] Microsoft Windows Knowledge Base Article 2651026 update is not installed
13495| [72846] Microsoft Windows Knowledge Base Article 2647516 update is not installed
13496| [72841] Microsoft Windows Knowledge Base Article 2645640 update is not installed
13497| [72838] Microsoft Windows Knowledge Base Article 2643719 update is not installed
13498| [72029] Microsoft Windows Knowledge Base Article 2638420 update is not installed
13499| [72003] Microsoft Windows Knowledge Base Article 2646524 update is not installed
13500| [71998] Microsoft Windows Knowledge Base Article 2644615 update is not installed
13501| [71995] Microsoft Windows Knowledge Base Article 2643584 update is not installed
13502| [71994] Microsoft Windows Knowledge Base Article 2636391 update is not installed
13503| [71565] Microsoft Windows Knowledge Base Article 2648048 update is not installed
13504| [71562] Microsoft Windows Knowledge Base Article 2640241 update is not installed
13505| [71560] Microsoft Windows Knowledge Base Article 2640045 update is not installed
13506| [71558] Microsoft Windows Knowledge Base Article 2639417 update is not installed
13507| [71557] Microsoft Windows Knowledge Base Article 2639142 update is not installed
13508| [71554] Microsoft Windows Knowledge Base Article 2633171 update is not installed
13509| [71552] Microsoft Windows Knowledge Base Article 2624667 update is not installed
13510| [71550] Microsoft Windows Knowledge Base Article 2620712 update is not installed
13511| [71548] Microsoft Windows Knowledge Base Article 2618451 update is not installed
13512| [71546] Microsoft Windows Knowledge Base Article 2618444 update is not installed
13513| [71538] Microsoft Windows Knowledge Base Article 2590602 update is not installed
13514| [70951] Microsoft Windows Knowledge Base Article 2630837 update is not installed
13515| [70949] Microsoft Windows Knowledge Base Article 2620704 update is not installed
13516| [70947] Microsoft Windows Knowledge Base Article 2617657 update is not installed
13517| [70943] Microsoft Windows Knowledge Base Article 2588516 update is not installed
13518| [70152] Microsoft Windows Knowledge Base Article 2623699 update is not installed
13519| [70140] Microsoft Windows Knowledge Base Article 2652016 update is not installed
13520| [70130] Microsoft Windows Knowledge Base Article 2586448 update is not installed
13521| [70115] Microsoft Windows Knowledge Base Article 2567053 update is not installed
13522| [69501] Microsoft Windows Knowledge Base Article 2587634 update is not installed
13523| [69498] Microsoft Windows Knowledge Base Article 2587505 update is not installed
13524| [69492] Microsoft Windows Knowledge Base Article 2571621 update is not installed
13525| [69490] Microsoft Windows Knowledge Base Article 2570947 update is not installed
13526| [68840] Microsoft Windows Knowledge Base Article 2451858 update is not installed
13527| [68833] Microsoft Windows Knowledge Base Article 2567943 update is not installed
13528| [68831] Microsoft Windows Knowledge Base Article 2570222 update is not installed
13529| [68829] Microsoft Windows Knowledge Base Article 2567951 update is not installed
13530| [68827] Microsoft Windows Knowledge Base Article 2578230 update is not installed
13531| [68825] Microsoft Windows Knowledge Base Article 2546250 update is not installed
13532| [68823] Microsoft Windows Knowledge Base Article 2559049 update is not installed
13533| [68816] Microsoft Windows Knowledge Base Article 2556532 update is not installed
13534| [68814] Microsoft Windows Knowledge Base Article 2560656 update is not installed
13535| [68812] Microsoft Windows Knowledge Base Article 2560978 update is not installed
13536| [68809] Microsoft Windows Knowledge Base Article 2562485 update is not installed
13537| [68806] Microsoft Windows Knowledge Base Article 2566454 update is not installed
13538| [68804] Microsoft Windows Knowledge Base Article 2563894 update is not installed
13539| [68801] Microsoft Windows Knowledge Base Article 2567680 update is not installed
13540| [68315] Microsoft Windows Knowledge Base Article 2555917 update is not installed
13541| [68299] Microsoft Windows Knowledge Base Article 2566220 update is not installed
13542| [68283] Microsoft Windows Knowledge Base Article 2560847 update is not installed
13543| [67955] Microsoft Windows Knowledge Base Article 2530548 update is not installed
13544| [67943] Microsoft Windows Knowledge Base Article 2544521 update is not installed
13545| [67762] Microsoft Windows Knowledge Base Article 2543893 update is not installed
13546| [67759] Microsoft Windows Knowledge Base Article 2544893 update is not installed
13547| [67757] Microsoft Windows Knowledge Base Article 2476490 update is not installed
13548| [67753] Microsoft Windows Knowledge Base Article 2514842 update is not installed
13549| [67751] Microsoft Windows Knowledge Base Article 2518295 update is not installed
13550| [67737] Microsoft Windows Knowledge Base Article 2520426 update is not installed
13551| [67733] Microsoft Windows Knowledge Base Article 2525694 update is not installed
13552| [67731] Microsoft Windows Knowledge Base Article 2525835 update is not installed
13553| [67728] Microsoft Windows Knowledge Base Article 2535512 update is not installed
13554| [67725] Microsoft Windows Knowledge Base Article 2536275 update is not installed
13555| [67722] Microsoft Windows Knowledge Base Article 2536276 update is not installed
13556| [67718] Microsoft Windows Knowledge Base Article 2537146 update is not installed
13557| [67709] Microsoft Windows Knowledge Base Article 2538814 update is not installed
13558| [67302] Microsoft Windows Knowledge Base Article 2545814 update is not installed
13559| [67101] Microsoft Windows Knowledge Base Article 2524426 update is not installed
13560| [66446] Microsoft Windows Knowledge Base Article 2514666 update is not installed
13561| [66444] Microsoft Windows Knowledge Base Article 2511455 update is not installed
13562| [66436] Microsoft Windows Knowledge Base Article 2497640 update is not installed
13563| [66432] Microsoft Windows Knowledge Base Article 2527308 update is not installed
13564| [66428] Microsoft Windows Knowledge Base Article 2489979 update is not installed
13565| [66423] Microsoft Windows kernel-mode driver (win32k.sys) variant 29 privilege escalation
13566| [66422] Microsoft Windows kernel-mode driver (win32k.sys) variant 28 privilege escalation
13567| [66421] Microsoft Windows kernel-mode driver (win32k.sys) variant 27 privilege escalation
13568| [66420] Microsoft Windows kernel-mode driver (win32k.sys) variant 26 privilege escalation
13569| [66419] Microsoft Windows kernel-mode driver (win32k.sys) variant 25 privilege escalation
13570| [66418] Microsoft Windows kernel-mode driver (win32k.sys) variant 24 privilege escalation
13571| [66417] Microsoft Windows kernel-mode driver (win32k.sys) variant 23 privilege escalation
13572| [66416] Microsoft Windows kernel-mode driver (win32k.sys) variant 22 privilege escalation
13573| [66415] Microsoft Windows kernel-mode driver (win32k.sys) variant 21 privilege escalation
13574| [66414] Microsoft Windows kernel-mode driver (win32k.sys) variant 20 privilege escalation
13575| [66396] Microsoft Windows kernel-mode driver (win32k.sys) variant 2 privilege escalation
13576| [66394] Microsoft Windows Knowledge Base Article 2485663 update is not installed
13577| [65588] Microsoft Windows Knowledge Base Article 2489279 update is not installed
13578| [65581] Microsoft Windows Knowledge Base Article 2510030 update is not installed
13579| [65580] Microsoft Windows Knowledge Base Article 2489283 update is not installed
13580| [65575] Microsoft Windows Knowledge Base Article 2489293 update is not installed
13581| [65573] Microsoft Windows Knowledge Base Article 2494047 update is not installed
13582| [64973] Microsoft Windows Knowledge Base Article 2478960 update is not installed
13583| [64971] Microsoft Windows Knowledge Base Article 2479628 update is not installed
13584| [64927] Microsoft Windows Knowledge Base Article 2393802 update is not installed
13585| [64925] Microsoft Windows Knowledge Base Article 2451879 update is not installed
13586| [64920] Microsoft Windows Knowledge Base Article 2475792 update is not installed
13587| [64918] Microsoft Windows Knowledge Base Article 2476687 update is not installed
13588| [64916] Microsoft Windows Knowledge Base Article 2478953 update is not installed
13589| [64914] Microsoft Windows Knowledge Base Article 2482017 update is not installed
13590| [64910] Microsoft Windows Knowledge Base Article 2483185 update is not installed
13591| [64909] Microsoft Windows Knowledge Base Article 2484015 update is not installed
13592| [64907] Microsoft Windows Knowledge Base Article 2485376 update is not installed
13593| [64905] Microsoft Windows Knowledge Base Article 2489256 update is not installed
13594| [64902] Microsoft Windows Knowledge Base Article 2496930 update is not installed
13595| [64342] Microsoft Windows Knowledge Base Article 2451910 update is not installed
13596| [64339] Microsoft Windows Knowledge Base Article 2478935 update is not installed
13597| [63584] Microsoft Windows Knowledge Base Article 2424434 update is not installed
13598| [63582] Microsoft Windows Knowledge Base Article 2423089 update is not installed
13599| [63580] Microsoft Windows Knowledge Base Article 2436673 update is not installed
13600| [63571] Microsoft Windows Knowledge Base Article 2440591 update is not installed
13601| [63569] Microsoft Windows Knowledge Base Article 2385678 update is not installed
13602| [63566] Microsoft Windows Knowledge Base Article 2442962 update is not installed
13603| [63564] Microsoft Windows Knowledge Base Article 2345316 update is not installed
13604| [63562] Microsoft Windows Knowledge Base Article 2296199 update is not installed
13605| [63558] Microsoft Windows Knowledge Base Article 2416400 update is not installed
13606| [63550] Microsoft Windows Knowledge Base Article 2447961 update is not installed
13607| [63548] Microsoft Windows Knowledge Base Article 2443105 update is not installed
13608| [63546] Microsoft Windows Knowledge Base Article 2455005 update is not installed
13609| [63544] Microsoft Windows Knowledge Base Article 2292970 update is not installed
13610| [62805] Microsoft Windows Knowledge Base Article 2316074 update is not installed
13611| [62793] Microsoft Windows Knowledge Base Article 2293386 update is not installed
13612| [62789] Microsoft Windows Knowledge Base Article 2423930 update is not installed
13613| [62170] Microsoft Windows Knowledge Base Article 2296011 update is not installed
13614| [62166] Microsoft Windows Knowledge Base Article 2294255 update is not installed
13615| [62163] Microsoft Windows Knowledge Base Article 2281679 update is not installed
13616| [62154] Microsoft Windows Knowledge Base Article 2279986 update is not installed
13617| [62147] Microsoft Windows Knowledge Base Article 2160841 update is not installed
13618| [62134] Microsoft Windows Knowledge Base Article 2412048 update is not installed
13619| [62129] Microsoft Windows Knowledge Base Article 2387149 update is not installed
13620| [62126] Microsoft Windows Knowledge Base Article 2378111 update is not installed
13621| [62123] Microsoft Windows Knowledge Base Article 2360937 update is not installed
13622| [62118] Microsoft Windows Knowledge Base Article 2293211 update is not installed
13623| [62104] Microsoft Windows Knowledge Base Article 2360131 update is not installed
13624| [62098] Microsoft Windows Knowledge Base Article 2293194 update is not installed
13625| [62069] Microsoft Windows Knowledge Base Article 2418042 update is not installed
13626| [61519] Microsoft Windows Knowledge Base Article 2121546 update is not installed
13627| [61517] Microsoft Windows Knowledge Base Article 2259922 update is not installed
13628| [61514] Microsoft Windows Knowledge Base Article 2267960 update is not installed
13629| [61510] Microsoft Windows Knowledge Base Article 2315011 update is not installed
13630| [61507] Microsoft Windows Knowledge Base Article 2320113 update is not installed
13631| [61504] Microsoft Windows Knowledge Base Article 2347290 update is not installed
13632| [60736] Microsoft Windows Knowledge Base Article 2265906 update is not installed
13633| [60734] Microsoft Windows Knowledge Base Article 2269638 update is not installed
13634| [60728] Microsoft Windows Knowledge Base Article 2269707 update is not installed
13635| [60724] Microsoft Windows Knowledge Base Article 2286198 update is not installed
13636| [60713] Microsoft Windows Knowledge Base Article 2183461 update is not installed
13637| [60698] Microsoft Windows Knowledge Base Article 2160329 update is not installed
13638| [60686] Microsoft Windows Knowledge Base Article 2115168 update is not installed
13639| [60684] Microsoft Windows Knowledge Base Article 2079403 update is not installed
13640| [60680] Microsoft Windows Knowledge Base Article 2264072 update is not installed
13641| [59901] Microsoft Windows Knowledge Base Article 2229593 update is not installed
13642| [59898] Microsoft Windows Knowledge Base Article 2229593 update is not installed
13643| [58913] Microsoft Windows Knowledge Base Article 2027452 update is not installed
13644| [58891] Microsoft Windows Knowledge Base Article 2028554 update is not installed
13645| [17004] Microsoft Windows XP Service Pack 2 is not installed on the system
13646| [9187] Microsoft Passport SDK 2.1 Component Configuration Document (CCD) permission
13647| [9146] Microsoft Passport SDK 2.1 events reporting disabled
13648| [9068] Microsoft Passport SDK 2.1 registry default permission exposure
13649| [9067] Microsoft Passport SDK 2.1 default test site exposure
13650| [9066] Microsoft Passport SDK 2.1 Adventure Works Sample Site exposure
13651| [9065] Microsoft Passport SDK 2.1 Adventure Works Sample Site global.asa file default permission exposure
13652| [9064] Microsoft Passport SDK 2.1 default time window exposure
13653| [1271] Microsoft IIS version 2 installed
13654| [621] Microsoft IIS 3.0 script source revealed by appending 2E to requests
13655|
13656| Exploit-DB - https://www.exploit-db.com:
13657| [30756] Microsoft Forms 2.0 ActiveX Control 2.0 Memory Access Violation Denial of Service Vulnerabilities
13658| [30749] Microsoft Office 2003 Web Component Memory Access Violation Denial of Service Vulnerability
13659| [30636] Microsoft Windows 2000/2003 Recursive DNS Spoofing Vulnerability (2)
13660| [30635] Microsoft Windows 2000/2003 Recursive DNS Spoofing Vulnerability (1)
13661| [30281] Microsoft .Net Framework <= 2.0 - Multiple Null Byte Injection Vulnerabilities
13662| [29664] Microsoft Office Publisher 2007 - Remote Denial of Service (DoS) Vulnerability
13663| [29660] Microsoft Office 2003 - Denial of Service (DoS) Vulnerability
13664| [29630] Microsoft Windows 2003/XP ReadDirectoryChangesW Information Disclosure Vulnerability
13665| [29524] Microsoft Word 2000 - Malformed Function Code Execution Vulnerability
13666| [28420] Microsoft Windows 2000 Multiple COM Object Instantiation Code Execution Vulnerabilities
13667| [28357] Microsoft Windows Explorer 2000/2003/XP Drag and Drop Remote Code Execution Vulnerability
13668| [28227] Microsoft Windows 2000/XP Registry Access Local Denial of Service Vulnerability
13669| [28226] Microsoft PowerPoint 2003 PPT File Closure Memory Corruption
13670| [28225] Microsoft PowerPoint 2003 powerpnt.exe Unspecified Issue
13671| [28224] Microsoft PowerPoint 2003 mso.dll PPT Processing Unspecified Code Execution
13672| [28198] Microsoft Office 2000/2002 Property Code Execution Vulnerability
13673| [28189] Microsoft Excel 2000-2004 Style Handling and Repair Remote Code Execution Vulnerability
13674| [28087] Microsoft Office 2003 Embedded Shockwave Flash Object Security Bypass Weakness
13675| [28005] Microsoft Exchange Server 2000/2003 Outlook Web Access Script Injection Vulnerability
13676| [26690] Microsoft Windows 2000/2003/XP CreateRemoteThread Local Denial of Service Vulnerability
13677| [26517] Microsoft Office PowerPoint 2007 - Crash PoC
13678| [26341] Microsoft Windows 2000/2003/XP MSDTC TIP Denial of Service Vulnerability
13679| [26222] Microsoft Windows 2000/2003/XP Keyboard Event Privilege Escalation Weakness
13680| [25384] Microsoft Windows 2000/XP Internet Protocol Validation Remote Code Execution Vulnerability (2)
13681| [25383] Microsoft Windows 2000/XP Internet Protocol Validation Remote Code Execution Vulnerability (1)
13682| [25231] Microsoft Windows 2000/2003/XP Graphical Device Interface Library Denial of Service Vulnerability
13683| [25085] Microsoft Office XP 2000/2002 HTML Link Processing Remote Buffer Overflow Vulnerability
13684| [25084] Microsoft Outlook 2003 Web Access Login Form Remote URI Redirection Vulnerability
13685| [25050] Microsoft Windows 2000/2003/XP winhlp32 Phrase Heap Overflow Vulnerability
13686| [25049] Microsoft Windows 2000/2003/XP winhlp32 Phrase Integer Overflow Vulnerability
13687| [24686] Microsoft Outlook 2003 Security Policy Bypass Vulnerability
13688| [24277] Microsoft Windows 2000/NT 4 POSIX Subsystem Buffer Overflow Local Privilege Escalation Vulnerability
13689| [24114] Microsoft Outlook 2003Mail Client E-mail Address Verification Weakness
13690| [24101] Microsoft Outlook 2003 Predictable File Location Weakness
13691| [23989] Microsoft Windows 2000/NT 4 Local Descriptor Table Local Privilege Escalation Vulnerability
13692| [23796] Microsoft Outlook 2002 Mailto Parameter Quoting Zone Bypass Vulnerability
13693| [23019] Microsoft Windows 2000 Subnet Bandwidth Manager RSVP Server Authority Hijacking Vulnerability
13694| [22919] Microsoft ISA Server 2000 Cross-Site Scripting Vulnerabilities
13695| [22883] Microsoft Windows 2000 CreateFile API Named Pipe Privilege Escalation Vulnerability (2)
13696| [22882] Microsoft Windows 2000 CreateFile API Named Pipe Privilege Escalation Vulnerability (1)
13697| [22837] Microsoft Windows 2000/NT 4 Media Services NSIISlog.DLL Remote Buffer Overflow
13698| [22782] Microsoft Windows 2000 Active Directory Remote Stack Overflow Vulnerability
13699| [22591] Microsoft Office Excel 2007 - WriteAV Crash PoC
13700| [22555] Microsoft BizTalk Server 2000/2002 DTA RawCustomSearchField.asp SQL Injection
13701| [22554] Microsoft BizTalk Server 2000/2002 DTA rawdocdata.asp SQL Injection Vulnerability
13702| [22553] Microsoft BizTalk Server 2002 HTTP Receiver Buffer Overflow Vulnerability
13703| [22528] Microsoft Windows 2000 RegEdit.EXE Registry Key Value Buffer Overflow Vulnerability
13704| [22354] Microsoft Windows 2000 Help Facility .CNT File :Link Buffer Overflow Vulnerability
13705| [21920] Microsoft Content Management Server 2001 Cross-Site Scripting Vulnerability
13706| [21718] Microsoft SQL 2000/7.0 Agent Jobs Privilege Elevation Vulnerability
13707| [21693] Microsoft SQL Server 2000 User Authentication Remote Buffer Overflow Vulnerability
13708| [21652] Microsoft SQL Server 2000 Resolution Service Heap Overflow Vulnerability
13709| [21651] Microsoft SQL Server 2000 sp_MScopyscript SQL Injection Vulnerability
13710| [21650] Microsoft SQL Server 2000 Database Consistency Checkers Buffer Overflow Vulnerability
13711| [21549] Microsoft SQL Server 2000 Password Encrypt Procedure Buffer Overflow Vulnerability
13712| [21541] Microsoft SQL Server 2000 SQLXML Script Injection Vulnerability
13713| [21540] Microsoft SQL Server 2000 SQLXML Buffer Overflow Vulnerability
13714| [21389] Microsoft Windows 2000 Lanman Denial of Service Vulnerability (2)
13715| [21388] Microsoft Windows 2000 Lanman Denial of Service Vulnerability (1)
13716| [21344] Microsoft Windows 2000 / NT 4.0 Process Handle Local Privilege Elevation Vulnerability
13717| [21258] Microsoft Windows 2000/NT 4 NTFS File Hiding Vulnerability
13718| [21246] Microsoft Windows 2000/NT 4 TCP Stack DoS Vulnerability (2)
13719| [21245] Microsoft Windows 2000/NT 4 TCP Stack DoS Vulnerability (1)
13720| [21172] Microsoft Windows 2000 Internet Key Exchange DoS Vulnerability (2)
13721| [21171] Microsoft Windows 2000 Internet Key Exchange DoS Vulnerability (1)
13722| [21131] Microsoft Windows 2000/XP GDI Denial of Service Vulnerability
13723| [21123] Microsoft Windows 2000/NT Terminal Server Service RDP DoS Vulnerability
13724| [21113] Microsoft Index Server 2.0 File Information and Path Disclosure Vulnerability
13725| [21099] Microsoft Windows 2000 RunAs Service Denial of Services Vulnerability
13726| [21069] Microsoft Windows 2000 RunAs Service Named Pipe Hijacking Vulnerability
13727| [20907] Microsoft Windows 2000 Telnet Username DoS Vulnerability
13728| [20802] Microsoft IIS 2.0/3.0 Long URL Denial of Service Vulnerability
13729| [20763] Microsoft ISA Server 2000 Web Proxy DoS Vulnerability
13730| [20571] Microsoft Outlook 2000 0/98 0/Express 5.5 Concealed Attachment Vulnerability
13731| [20481] Microsoft IIS 2.0/3.0 Appended Dot Script Source Disclosure Vulnerability
13732| [20399] Microsoft Indexing Services for Windows 2000 File Verification Vulnerability
13733| [20335] Microsoft Indexing Services for Windows 2000/NT 4.0 .htw Cross-Site Scripting Vulnerability
13734| [20305] Microsoft Site Server 2.0 with IIS 4.0 - File Upload Vulnerability
13735| [20265] Microsoft Windows NT 4.0 / 2000 Spoofed LPC Request Vulnerability
13736| [20257] Microsoft Windows NT 4.0 / 2000 Predictable LPC Message Identifier Multiple Vulnerabilities
13737| [20255] Microsoft Windows NT 4.0 / 2000 LPC Zone Memory Depletion DoS Vulnerability
13738| [20222] Microsoft Windows 2000 telnet.exe NTLM Authentication Vulnerability
13739| [20209] Microsoft Windows 2000 Still Image Service Privilege Escalation Vulnerability
13740| [20133] Microsoft Windows 2000 Named Pipes Predictability Vulnerability
13741| [20122] Microsoft Office SharePoint Server 2007 Remote Code Execution
13742| [20096] Microsoft IIS 2.0/3.0/4.0/5.0/5.1 Internal IP Address Disclosure Vulnerability
13743| [20048] Microsoft Windows 2000 Remote CPU-overload Vulnerability
13744| [20047] Microsoft Windows 2000 Telnet Server DoS Vulnerability
13745| [19830] Microsoft Index Server 2.0 '%20' ASP Source Disclosure Vulnerability
13746| [19742] microsoft iis 3.0/4.0,microsoft index server 2.0 - Directory Traversal
13747| [19734] Microsoft Virtual Machine 2000 Series/3000 Series getSystemResource Vulnerability
13748| [19731] microsoft index server 2.0/indexing services for windows 2000 - Directory Traversal
13749| [19728] Microsoft Systems Management Server 2.0 Default Permissions Vulnerability
13750| [19425] Microsoft Data Access Components (MDAC) <= 2.1,Microsoft IIS 3.0/4.0,Microsoft Index Server 2.0,Microsoft Site Server Commerce Edition 3.0 i386 MDAC RDS Vulnerability (2)
13751| [19424] Microsoft Data Access Components (MDAC) <= 2.1,Microsoft IIS 3.0/4.0,Microsoft Index Server 2.0,Microsoft Site Server Commerce Edition 3.0 i386 MDAC RDS Vulnerability (1)
13752| [19376] Microsoft IIS 2.0/3.0/4.0 ISAPI GetExtensionVersion() Vulnerability
13753| [19143] "Microsoft Windows ""April Fools 2001"" Vulnerability"
13754| [19118] Microsoft IIS 3.0/4.0,Microsoft Personal Web Server 2.0/3.0/4.0 ASP Alternate Data Streams Vulnerability
13755| [18334] Microsoft Office 2003 Home/Pro 0day
13756| [18087] MS11-021 Microsoft Office 2007 Excel .xlb Buffer Overflow
13757| [18078] Microsoft Excel 2003 11.8335.8333 Use After Free
13758| [18067] Microsoft Excel 2007 SP2 Buffer Overwrite Exploit
13759| [17305] "Microsoft Windows Vista/Server 2008 ""nsiproxy.sys"" Local Kernel DoS Exploit"
13760| [14971] MOAUB #11 - Microsoft Office Word 2007 sprmCMajority Buffer Overflow
13761| [14782] Microsoft Office PowerPoint 2007 DLL Hijacking Exploit (rpawinet.dll)
13762| [14746] Microsoft Office Groove 2007 DLL Hijacking Exploit (mso.dll)
13763| [14744] Microsoft Visio 2003 DLL Hijacking Exploit (mfc71enu.dll)
13764| [12450] Microsoft SharePoint Server 2007 XSS Vulnerability
13765| [10068] Microsoft Windows 2000-2008 Embedded OpenType Font Engine Remote Code Execution
13766| [4121] Microsoft Excel 2000/2003 Sheet Name Vulnerability PoC
13767| [3973] Microsoft Office 2000 (OUACTRL.OCX 1.0.1.9) - Remote DoS Exploit
13768| [3690] microsoft office word 2007 - Multiple Vulnerabilities
13769| [3260] Microsoft Word 2000 Unspecified Code Execution Exploit (0day)
13770| [2523] Microsoft Office 2003 PPT Local Buffer Overflow PoC
13771| [2091] Microsoft PowerPoint 2003 SP2 Local Code Execution Exploit (french)
13772| [2001] Microsoft Word 2000/2003 Unchecked Boundary Condition Vulnerability
13773| [1999] Microsoft Word 2000/2003 Hlink Local Buffer Overflow Exploit PoC
13774| [1988] Microsoft Excel 2003 Hlink Local Buffer Overflow Exploit (italian)
13775| [1986] Microsoft Excel 2000/2003 Hlink Local Buffer Overflow Exploit (french)
13776| [1958] Microsoft Excel 2003 Hlink Stack/SEH Buffer Overflow Exploit
13777| [28238] Microsoft SharePoint 2013 (Cloud) - Persistent Exception Handling Vulnerability MS13-067
13778| [23034] Microsoft URLScan 2.5/ RSA Security SecurID 5.0 Configuration Enumeration Weakness
13779| [22850] Microsoft Office OneNote 2010 Crash PoC
13780| [22679] Microsoft Visio 2010 Crash PoC
13781| [22655] Microsoft Publisher 2013 Crash PoC
13782| [22621] Microsoft Netmeeting 2.1/3.0.1 4.4.3385 CALLTO URL Buffer Overflow Vulnerability
13783| [22330] Microsoft Office Excel 2010 Crash PoC
13784| [22310] Microsoft Office Publisher 2010 Crash PoC
13785| [22237] Microsoft Office Picture Manager 2010 Crash PoC
13786| [22215] Microsoft Office Word 2010 Crash PoC
13787| [19451] Microsoft Windows 98 a/98 b/98SE,Solaris 2.6 IRDP Vulnerability
13788| [19440] Microsoft Windows NT 4.0/SP 1/SP 2/Sp 3/SP 4/SP 5 Malformed Dialer Entry Vulnerability
13789| [19372] Microsoft Windows NT 4.0/SP 1/SP 2/SP 3/SP 4/SP 5 Null Session Admin Name Vulnerability
13790| [17164] Microsoft Reader <= 2.1.1.3143 NULL Byte Write
13791| [17163] Microsoft Reader <= 2.1.1.3143 Array Overflow
13792| [17162] Microsoft Reader <= 2.1.1.3143 Integer Overflow
13793| [17161] Microsoft Reader <= 2.1.1.3143 Heap Overflow
13794| [17160] Microsoft Reader <= 2.1.1.3143 Integer Overflow
13795| [14731] Microsoft Windows Movie Maker <= 2.6.4038.0 DLL Hijacking Exploit (hhctrl.ocx)
13796| [14723] Microsoft Power Point 2010 DLL Hijacking Exploit (pptimpconv.dll)
13797|
13798| OpenVAS (Nessus) - http://www.openvas.org:
13799| [902250] Microsoft Word 2003 'MSO.dll' Null Pointer Dereference Vulnerability
13800| [900125] Microsoft SQL Server 2000 sqlvdir.dll ActiveX Buffer Overflow Vulnerability
13801| [801597] Microsoft Office Excel 2003 Invalid Object Type Remote Code Execution Vulnerability
13802| [801596] Microsoft Excel 2007 Office Drawing Layer Remote Code Execution Vulnerability
13803| [801594] Microsoft PowerPoint 2007 OfficeArt Atom Remote Code Execution Vulnerability
13804| [800687] Microsoft Windows Server 2003 OpenType Font Engine DoS Vulnerability
13805| [800577] Microsoft Windows Server 2003 win32k.sys DoS Vulnerability
13806| [800343] Microsoft Word 2007 Sensitive Information Disclosure Vulnerability
13807| [103254] Microsoft SharePoint Server 2007 '_layouts/help.aspx' Cross Site Scripting Vulnerability
13808| [11992] Vulnerability in Microsoft ISA Server 2000 H.323 Filter(816458)
13809| [902931] Microsoft Office Remote Code Execution Vulnerabilities - 2720184 (Mac OS X)
13810| [902678] Microsoft Silverlight Code Execution Vulnerabilities - 2681578 (Mac OS X)
13811| [901210] Microsoft Office Privilege Elevation Vulnerability - 2721015 (Mac OS X)
13812|
13813| SecurityTracker - https://www.securitytracker.com:
13814| [1015347] Microsoft Windows 2000 Kernel APC Queue Bug Lets Local Users Gain Elevated Privileges
13815| [1013454] Microsoft Office InfoPath 2003 May Disclose System and Authentication Information to Remote Users
13816| [1013284] Microsoft Windows 2000 and XP Group Policy Can Be Bypassed By Microsoft Office Applications and By Flash Drives
13817| [1010687] Microsoft Windows 2000/NT POSIX Subsystem Buffer Overflow Lets Local Users Gain Elevated Privileges
13818| [1010352] Microsoft Windows 2000 Domains With Eight Characters May Let Remote Users With Expired Passwords Login
13819| [1010189] Microsoft Outlook 2003 Scripting Restrictions Can Be Bypassed By Remote Users
13820| [1010125] Microsoft Outlook 2003 Lets Remote Users Send E-mail to Cause the Recipient's Client to Contact a Remote Server
13821| [1009767] Microsoft Windows 2000 Domain Controller LDAP Flaw May Let Remote Users Restart the Authentication Service
13822| [1008324] Microsoft Exchange 2003 With Outlook Web Access and Windows SharePoint Services May Grant Incorrect E-mail Account Access to Remote Authenticated Users
13823| [1007905] Microsoft Windows Server 2003 Shell Folders Can Be Referenced Using Directory Traversal Characters
13824| [1007238] Microsoft Outlook Web Access Can Be Crashed By Remote Authenticated Users With an Outlook 2003 Client
13825| [1007152] Microsoft Windows 2000 Accessibility Utility Manager Lets Local Users Gain Elevated Privileges
13826| [1007099] Microsoft Windows 2000 ShellExecute() Buffer Overflow May Let Users Execute Arbitrary Code
13827| [1007093] Microsoft Active Directory Stack Overflow in 'Lsaas.exe' Lets Remote Users Crash the Windows 2000 Server
13828| [1006959] Microsoft Windows Server 2003 Drivers May Leak Information From Memory Via Ethernet Packets Containing TCP Streams
13829| [1006580] Microsoft Windows 2003 'win2k.sys' Printing Bug Lets Users Crash the System
13830| [1006534] Microsoft Proxy Service in Proxy Server 2.0 Has Unspecified Flaw That Lets Remote Users Stop Traffic
13831| [1006286] Microsoft Windows 2000/XP PostMessage() API Flaw May Let Local Users Grab Passwords from Local Dialog Boxes
13832| [1006280] Protegrity Secure.Data for Microsoft SQL Server 2000 Contains Buffer Oveflows That Let Remote Users Execute Arbitrary Code
13833| [1005254] Microsoft NT, 2000, and XP Operating Systems May Execute a 16-bit Application Even When The File Has No Execute Permissions
13834| [1005068] Microsoft NTFS Filesystem in Windows NT and Windows 2000 Has Auditing Hole That Lets Local Users Access Files Without the File Access Being Audited
13835| [1004587] Microsoft SQL Server 2000 Buffer Overflow in OpenDataSource() Function May Let Remote Users Gain SYSTEM Privileges on the Server
13836| [1004528] Microsoft SQLXML Component of Microsoft SQL Server 2000 Contains an Input Validation Flaw in an XML SQL Tag That Allows Cross-Site Scripting Attacks
13837| [1004527] Microsoft SQLXML Component of Microsoft SQL Server 2000 Contains a Buffer Overflow That Lets Remote Users Take Full Control of the System
13838| [1004407] Microsoft Exchange 2000 Flaw in Processing a Certain Malformed SMTP Command Allows Remote Users to Deny Service to the Server
13839| [1004357] Microsoft Windows Debugging Facility for Windows NT4 and 2000 Has Authentication Hole That Lets Local Users Execute Arbitrary Code with SYSTEM Privileges
13840| [1004083] Microsoft Windows 2000 'microsoft-ds' Service Flaw Allows Remote Users to Create Denial of Service Conditions By Sending Malformed Packets
13841| [1004022] Microsoft Windows 2000 Group Policy Object Enforcement Can Be Circumvented if User License Limits are Exceeded
13842| [1003975] Microsoft Windows NT, 2000, and XP Kernel Buffer Overflow in Processing Multiple UNC Provider (MUP) Requests May Let Local Users Obtain System Level Privileges
13843| [1003949] Microsoft Windows 2000 DCOM Implementation Flaw May Disclose Memory Contents to Remote Users
13844| [1003816] Microsoft Windows 2000 Automatic Log Off Policy Fails to Expire Sessions in Progress
13845| [1003688] Microsoft Exchange Server 2000 Command Processing Bug Lets Remote Users Cause the SMTP Service to Crash
13846| [1003687] Microsoft Windows 2000 and Windows XP SMTP Service Command Processing Bug Lets Remote Users Cause the SMTP Service to Crash
13847| [1003634] Microsoft XML Core Services in SQL Server 2000 Lets Remote Scripts Access and Send Local Files
13848| [1003629] Microsoft Commerce Server 2000 AuthFilter Buffer Overflow Lets Remote Users Execute Arbitrary Code on the Server With LocalSystem Privileges to Gain Full Control of the Server
13849| [1003472] Microsoft Telnet Server for Windows 2000 and for Interix Has a Buffer Overflow That May Let Remote Users Execute Code on the Server with System Level Privileges
13850| [1003469] Microsoft Exchange 2000 Server Allows Remote Users to View and Possibly Modify Registry Settings
13851| [1003402] Microsoft Windows NT 4.0 and Windows 2000 Domain Controllers May Give Elevated Privileges to Remote Users Who Are Valid Administrators on Other Trusted Domains
13852| [1002922] Microsoft Windows 2000 Internet Key Exchange (IKE) Service Can Be Crashed By Remote Users
13853| [1002754] Terminal Services on Microsoft Windows 2000 and XP Allow Remote Users to Log Bogus IP Addresses Instead of the User's Genuine Address
13854| [1002731] Microsoft Windows 2000 RunAs Service May Disclose Authentication Credentials to Local Users
13855| [1002730] Microsoft Windows 2000 RunAs Utility May Disclose Sensitive Information to Local Users
13856| [1002729] Microsoft Windows 2000 RunAs Service Allows Local Users to Disable the Service
13857| [1002356] Microsoft Outlook 2000 Animated Assistant Prevents the Screen Saver from Activating, Allowing Physically Local Users to Access the System
13858| [1002206] Microsoft Internet Security and Acceleration (ISA) Server 2000 Can Be Disrupted By Remote Users Due to Memory Leaks and Also Allows Cross-Site Scripting Attacks
13859| [1002106] Microsoft Windows 2000 and Windows NT 4.0 RPC Input Validation Failure Lets Remote Users Destabilize the Operating System
13860| [1002099] Microsoft Windows 2000 Telnet Service Can Be Crashed By Remote Users
13861| [1002098] Windows Terminal Services in Microsoft Windows 2000 and NT 4.0 Can Be Crashed By Remote Users Due to a Memory Leak
13862| [1001993] Microsoft Windows 2000, Linux 2.4, NetBSD, FreeBSD, and OpenBSD May Let Remote Users Affect TCP Performance
13863| [1001931] Microsoft Windows 2000 SMTP Service May Allow Unauthorized Remote Users to Relay E-mail via the Service
13864| [1001832] Microsoft Windows 2000 LDAP Server Lets Remote Users Gain Administrator Access to the Domain Controller When Configured to Support LDAP over SSL
13865| [1001701] Microsoft Windows 2000 Telnet Server Allows Local Users to Gain System-Level Privileges and Lets Remote Users Crash the Server
13866| [1001605] Microsoft Windows 2000 Allows Local Users to Elevate Privileges
13867| [1001565] Microsoft IIS Web Server on Windows 2000 Allows Remote Users to Cause the Server to Consume All Available Memory Due to Memory Leak in WebDAV Lock Method
13868| [1001513] Microsoft Windows 2000 Indexing Service Allows Remote Users to View Include Programming Files
13869| [1001501] Microsoft Windows 2000 Domain Controllers Can Be Effectively Halted By Remote Users
13870| [1001464] Microsoft Internet Information Server IIS 5.0 for Windows 2000 Lets Remote Users Execute Arbitrary Code on the Server and Gain Control of the Server
13871| [1001240] Microsoft FTP Client for Windows 2000 Still Vulnerable to Executing Arbitrary Code in Limited Situations
13872| [1001088] Microsoft Internet Explorer with Services for Unix 2.0 Can Create Malicious Files on the User's Host
13873|
13874| OSVDB - http://www.osvdb.org:
13875| [90257] Microsoft Windows Server 2003 ICACLS.EXE Permission Inheritance Weakness
13876| [86790] Microsoft Virtual PC 2007 Crafted x86 Instruction Sequence Handling Local DoS
13877| [86061] Microsoft Windows Server 2008 R1 CSRSS ReadConsole / CloseHandle Local DoS
13878| [79442] Microsoft Windows Server 2008 DNS Server Service Cache Update Policy Deleted Domain Name Resolving Weakness
13879| [72670] Microsoft Windows Server 2003 ActiveDirectory BROWSER ELECTION Remote Overflow
13880| [68554] Microsoft Windows Server 2008 Shared Cluster Disks Addition Default Permission Weakness
13881| [62251] Microsoft Windows Server 2008 Hyper-V Crafted Instruction Sequence DoS
13882| [60329] Microsoft Windows 2000 NetBIOS Continuation Packet Remote DoS
13883| [59733] Microsoft Windows 2000 Terminal Services Screensaver Screen Minimization Locking Weakness
13884| [59731] Microsoft Windows 2000 DCOM Client Alter Context Request Remote Information Disclosure
13885| [59730] Microsoft Windows 2000 Terminal Services Disconnect Feature Local Privilege Escalation
13886| [59514] Microsoft Windows 2000 Task Manager Uppercase Process Name Termination Weakness
13887| [59509] Microsoft Windows 2000 Encrypted File System Cleartext Backup File Local Disclosure
13888| [59346] Microsoft Windows 2000 Crafted TCP/UDP Traffic CPU Consumption Remote DoS
13889| [55836] Microsoft ISA Server 2006 Radius OTP Security Bypass
13890| [53663] Microsoft Office Word 2000 WordPerfect 6.x Converter Document Handling Stack Corruption
13891| [50589] Microsoft SQL Server 2000 sp_replwritetovarbin() Stored Procedure Overflow
13892| [37629] Microsoft Windows 2000 RPC Authentication Unspecified Information Disclosure
13893| [37628] Microsoft Windows 2000 RPC Authentication Crafted Request Remote DoS
13894| [36034] Microsoft Office 2000 Controllo ActiveX (OUACTRL.OCX) HelpPopup Method Overflow
13895| [34489] Microsoft Office 2003 Malformed WMF File Handling DoS
13896| [34488] Microsoft Excel 2003 XLS Handling Corrupt Format DoS
13897| [31251] Microsoft Office 2003 Brazilian Portuguese Grammar Checker Arbitrary Code Execution
13898| [29529] Microsoft Windows 2000 creator.dll ActiveX COM Object Memory Corruption
13899| [29528] Microsoft Windows 2000 msdxm.ocx ActiveX COM Object Memory Corruption
13900| [29527] Microsoft Windows 2000 myinfo.dll ActiveX COM Object Memory Corruption
13901| [29526] Microsoft Windows 2000 ciodm.dll ActiveX COM Object Memory Corruption
13902| [28539] Microsoft Word 2000 Unspecified Code Execution
13903| [24121] Microsoft Commerce Server 2002 authfiles/login.asp Authentication Bypass
13904| [24081] Microsoft Outlook 2003 Unspecified Malformed Word Attachment DoS
13905| [23484] Microsoft SQLServer 2000 sp_addalias Procedure Privileged Alias Creation
13906| [23234] Microsoft SQLServer 2000 Unspecified Invalid Client Buffer DoS
13907| [23231] Microsoft SQL Server 2000 SQL Profiler Multiple Method DoS
13908| [23205] Microsoft SQLServer 2000 Crafted Sort Command User Mode Scheduler (UMS) Bypass DoS
13909| [23203] Microsoft SQL Server 2000 Database Name Transact-SQL Statement Privilege Escalation
13910| [23202] Microsoft SQLServer 2000 sysmembers Virtual Table Query Overflow
13911| [23201] Microsoft SQL Server 2000 Dynamic Transact-SQL Statement Disclosure
13912| [23200] Microsoft SQLServer 2000 Encrypted Stored Procedure Dynamic Query Disclosure
13913| [21907] Microsoft Office InfoPath 2003 Mshtml.dll Form Handling DoS
13914| [21598] Microsoft Windows 2000 NetBIOS Port Malformed TCP Packet Parsing Remote DoS
13915| [20256] Microsoft Windows 2000 NTFS Volume Macintosh Client Directory Permission Modification
13916| [20222] Microsoft Windows 2000 runas.exe Named Pipe Spoofing Information Disclosure
13917| [20221] Microsoft Windows 2000 runas.exe Named Pipe Single Thread DoS
13918| [20220] Microsoft Windows 2000 runas.exe Cleartext Authentication Information Disclosure
13919| [20002] Microsoft Windows 2000 CHKDSK Fix Mode File ACL Failure
13920| [20001] Microsoft Windows 2000 Terminal Service Client Connection IP Logging Failure
13921| [20000] Microsoft Windows 2000 Domain Administrator Computer Lock Bypass
13922| [19999] Microsoft Windows 2000 FQDN Domain Login Password Expiry Bypass
13923| [19998] Microsoft Windows 2000 UPN Credentialed Login Group Policy Failure
13924| [19997] Microsoft Windows 2000 WideCharToMultiByte Function String Termination Issue
13925| [19996] Microsoft Windows 2000 Event ID 1704 Group Policy Failure
13926| [19995] Microsoft Windows 2000 SECEDIT Long Folder ACL Set Issue
13927| [19994] Microsoft Windows 2000 audit directory service access 565 Event Logging Failure
13928| [19993] Microsoft Windows 2000 LDAPS CA Trust Issue
13929| [19264] Microsoft Exchange Server 2003 Crafted IMAP4 Folder Listing Request DoS
13930| [17031] Microsoft ISA Server 2000 SecureNAT Traffic Saturation DoS
13931| [15343] Microsoft Windows Server 2003 Malformed HTTP Cookie Header CGI DoS
13932| [15341] Microsoft Windows Server 2003 SMB Redirector Processing DoS
13933| [15340] Microsoft Windows Server 2003 Terminal Service Client Print DoS
13934| [15338] Microsoft Windows Server 2003 Terminal Session Close DoS
13935| [15337] Microsoft Windows Server 2003 CreateProcessWithLogonW() Function Process Disclosure
13936| [15336] Microsoft Windows Server 2003 Shutdown.exe Shut Down Failure
13937| [15335] Microsoft Windows Server 2003 MIT Kerberos Realm Authentication Group Policy Failure
13938| [15334] Microsoft Windows Server 2003 Shared Folder Permission Weakness
13939| [15333] Microsoft Windows Server 2003 EFS File Copy LDAP Connection DoS
13940| [15332] Microsoft Windows Server 2003 Citrix Metaframe Encryption Policy Failure
13941| [15331] Microsoft Windows Server 2003 Home Folder Path Permission Inheritance Failure
13942| [14617] Microsoft Exchange Server 2003 Folder Handling DoS
13943| [14430] Microsoft Commerce Server 2000 Profile Service Affected API Overflow
13944| [13996] Microsoft Windows 2000 IKE Malformed Packet Saturation Remote DoS
13945| [13762] Microsoft 2000 Domain Controller Directory Service Restore Mode Blank Password
13946| [13761] Microsoft Exchange 2000 Malformed URL Request DoS
13947| [13475] Microsoft Windows 2000 Telnet Service Predictable Named Pipe Arbitrary Command Execution Variant
13948| [13474] Microsoft Windows 2000 Telnet Service Predictable Named Pipe Arbitrary Command Execution
13949| [13441] Microsoft Windows 2000 Security Interface Change Password Option Account Enumeration
13950| [13437] Microsoft Windows 2000 Debug Register Local Privilege Escalation
13951| [13424] Microsoft Windows 2000 Current Password Change Policy Bypass
13952| [13423] Microsoft Windows 2000 Terminal Server SYSVOL Share Connection Saturation Restriction Bypass
13953| [13415] Microsoft Windows 2000 System Root Folder Search Path Permission Weakness
13954| [13410] Microsoft Windows 2000 Accessibility Utility Manager Arbitrary Code Execution
13955| [11958] Microsoft Outlook 2003 Image Rendering Security Policy Bypass
13956| [11945] Microsoft Outlook 2002 IFRAME Tag Embedded URL
13957| [11944] Microsoft Outlook 2002 HREF Tag Embedded JavaScript Execution
13958| [11750] Microsoft Windows 2000 Message Queue Manager Queue Registration Request Overflow DoS
13959| [11712] Microsoft ISA Server 2000 H.323 Filter Overflow
13960| [10633] Microsoft Windows 2000 Protected Store Weak Encryption Default
13961| [9386] Microsoft Windows 2000 msinfo32.exe msinfo_file Variable Overflow
13962| [8243] Microsoft SMS Port 2702 DoS
13963| [7202] Microsoft PowerPoint 2000 File Loader Overflow
13964| [7179] Microsoft Windows 2000 Event Viewer Snap-in Overflow
13965| [6971] Microsoft ISA Server 2000 ICMP Rule Bypass During Startup
13966| [6970] Microsoft ISA Server 2000 Web Publishing Unencrypted Credentials Disclosure
13967| [6969] Microsoft ISA Server 2000 Invalid DNS Request DoS
13968| [6968] Microsoft ISA Server 2000 FTP Port Scan Bounce Weakness
13969| [6967] Microsoft ISA Server 2000 UDP Packet Winsock DoS
13970| [6965] Microsoft ISA Server 2000 SSL Packet DoS
13971| [6964] Microsoft ISA Server 2000 DNS Intrusion Detection Filter DoS
13972| [6515] Microsoft Windows 2000 Domain Expired Account Authentication
13973| [5179] Microsoft Windows 2000 microsoft-ds DoS
13974| [5171] Microsoft Word 2002 Mail Merge Tool Execute Arbitrary Script
13975| [4779] Microsoft Desktop Engine (MSDE) 2000 Stored Procedure SQL Injection
13976| [4778] Microsoft SQL Server 2000 Stored Procedure SQL Injection
13977| [4777] Microsoft Desktop Engine (MSDE) 2000 Database Consistency Checkers (DBCCs) Overflow
13978| [4776] Microsoft SQL Server 2000 Database Consistency Checkers (DBCCs) 2000 Overflow
13979| [4170] Microsoft Windows 2000 Server Media Services TCP Packet Handling Remote DoS
13980| [4168] Microsoft Outlook 2002 mailto URI Script Injection
13981| [3490] Microsoft Exchange 2003 OWA Mailbox Access Information Disclosure
13982| [2705] Microsoft Windows 2000 Windows Troubleshooter ActiveX Overflow
13983| [2655] Microsoft Windows Server 2003 Shell Folders Arbitrary File Access
13984| [2540] Microsoft Windows 2003 Server Buffer Overflow Protection Mechanism Bypass
13985| [2244] Microsoft Windows 2000 ShellExecute() API Let
13986| [2237] Microsoft Windows 2000 Active Directory Lsass.exe Overflow
13987| [1949] Symantec Norton Anti-Virus for Microsoft Exchange 2000 INBOX Path Information Disclosure
13988| [1764] Microsoft Windows 2000 Domain Controller DoS
13989| [1758] Microsoft Windows 2000 Network DDE Escalated Privileges
13990| [1755] Microsoft Windows 2000 RDP Malformed Packet Handling Remote DoS
13991| [1672] Microsoft Windows 2000 Telnet Session Timeout DoS
13992| [1633] Microsoft Windows 2000 System Monitor ActiveX LogFileName Parameter Validation Overflow
13993| [1621] Microsoft Indexing Services for Windows 2000 .htw XSS
13994| [1591] Microsoft Windows 2000 OEMPreinstall Installation Permission Weakness
13995| [1578] Microsoft Windows 2000 Simplified Chinese IME Local Privilege Escalation
13996| [1500] Microsoft Word / Excel / Powerpoint 2000 Object Tag Buffer Overflow
13997| [1437] Microsoft Windows 2000 Telnet Server Binary Zero Parsing Remote DoS
13998| [1399] Microsoft Windows 2000 Windows Station Access
13999| [1328] Microsoft Office 2000 UA Control ActiveX (Ouactrl.ocx) Show Me Function Remote Code Execution
14000| [1297] Microsoft Windows 2000 Active Directory Object Attribute
14001| [1292] Microsoft Windows NT 4.0 / 2000 cmd.exe Buffer Overflow
14002| [773] Microsoft Windows 2000 Group Policy File Lock DoS
14003| [515] Microsoft Windows 2000 LDAP Server Arbitrary User Password Modification
14004| [454] Microsoft Windows 2000 NTLM Domain Account Lockout Policy Bypass
14005| [403] Microsoft Windows 2000 Still Image Service WM_USER Message Local Overflow
14006| [398] Microsoft Windows 2000 Malformed RPC Traffic Local Security Policy Corruption DoS
14007| [307] Microsoft FrontPage 2000 Server Extensions shtml.exe Path Disclosure
14008| [69085] Microsoft Office 2010 RTF File Handling pFragments Buffer Overflow Arbitrary Code Execution
14009|_
14010Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
14011Device type: general purpose
14012Running (JUST GUESSING): Microsoft Windows 2012 (88%)
14013OS CPE: cpe:/o:microsoft:windows_server_2012
14014Aggressive OS guesses: Microsoft Windows Server 2012 (88%), Microsoft Windows Server 2012 or Windows Server 2012 R2 (88%), Microsoft Windows Server 2012 R2 (88%)
14015No exact OS matches for host (test conditions non-ideal).
14016Uptime guess: 15.005 days (since Fri Sep 27 09:10:44 2019)
14017Network Distance: 11 hops
14018TCP Sequence Prediction: Difficulty=262 (Good luck!)
14019IP ID Sequence Generation: Busy server or unknown class
14020Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
14021
14022TRACEROUTE (using port 443/tcp)
14023HOP RTT ADDRESS
140241 40.19 ms 10.243.204.1
140252 40.28 ms vlan102.as02.qc1.ca.m247.com (176.113.74.17)
140263 40.31 ms irb-0.agg1.qc1.ca.m247.com (37.120.128.168)
140274 40.28 ms te-1-5-2-0.bb1.fra2.de.m247.com (82.102.29.44)
140285 40.30 ms motl-b1-link.telia.net (62.115.183.72)
140296 40.46 ms toro-b1-link.telia.net (62.115.134.48)
140307 40.50 ms chi-b21-link.telia.net (62.115.118.230)
140318 40.50 ms hurricane-ic-350465-chi-b21.c.telia.net (62.115.181.206)
140329 59.22 ms 216.66.76.146
1403310 59.30 ms 216.111.200.58
1403411 103.94 ms a67-209-250-173.cust.mi.winntel.net (67.209.250.173)
14035
14036NSE: Script Post-scanning.
14037Initiating NSE at 09:18
14038Completed NSE at 09:18, 0.00s elapsed
14039Initiating NSE at 09:18
14040Completed NSE at 09:18, 0.00s elapsed
14041Read data files from: /usr/bin/../share/nmap
14042OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
14043Nmap done: 1 IP address (1 host up) scanned in 126.58 seconds
14044 Raw packets sent: 108 (9.896KB) | Rcvd: 879 (569.088KB)
14045######################################################################################################################################
14046Version: 1.11.13-static
14047OpenSSL 1.0.2-chacha (1.0.2g-dev)
14048
14049Connected to 67.209.250.173
14050
14051Testing SSL server 67.209.250.173 on port 443 using SNI name 67.209.250.173
14052
14053 TLS Fallback SCSV:
14054Server does not support TLS Fallback SCSV
14055
14056 TLS renegotiation:
14057Secure session renegotiation supported
14058
14059 TLS Compression:
14060Compression disabled
14061
14062 Heartbleed:
14063TLS 1.2 not vulnerable to heartbleed
14064TLS 1.1 not vulnerable to heartbleed
14065TLS 1.0 not vulnerable to heartbleed
14066
14067 Supported Server Cipher(s):
14068Preferred TLSv1.2 256 bits ECDHE-RSA-AES256-SHA384 Curve P-256 DHE 256
14069Accepted TLSv1.2 128 bits ECDHE-RSA-AES128-SHA256 Curve P-256 DHE 256
14070Accepted TLSv1.2 256 bits ECDHE-RSA-AES256-SHA Curve P-256 DHE 256
14071Accepted TLSv1.2 128 bits ECDHE-RSA-AES128-SHA Curve P-256 DHE 256
14072Accepted TLSv1.2 256 bits DHE-RSA-AES256-GCM-SHA384 DHE 1024 bits
14073Accepted TLSv1.2 128 bits DHE-RSA-AES128-GCM-SHA256 DHE 1024 bits
14074Accepted TLSv1.2 256 bits DHE-RSA-AES256-SHA DHE 1024 bits
14075Accepted TLSv1.2 128 bits DHE-RSA-AES128-SHA DHE 1024 bits
14076Accepted TLSv1.2 256 bits AES256-GCM-SHA384
14077Accepted TLSv1.2 128 bits AES128-GCM-SHA256
14078Accepted TLSv1.2 256 bits AES256-SHA256
14079Accepted TLSv1.2 128 bits AES128-SHA256
14080Accepted TLSv1.2 256 bits AES256-SHA
14081Accepted TLSv1.2 128 bits AES128-SHA
14082Accepted TLSv1.2 112 bits DES-CBC3-SHA
14083Accepted TLSv1.2 128 bits RC4-SHA
14084Accepted TLSv1.2 128 bits RC4-MD5
14085Preferred TLSv1.1 256 bits ECDHE-RSA-AES256-SHA Curve P-256 DHE 256
14086Accepted TLSv1.1 128 bits ECDHE-RSA-AES128-SHA Curve P-256 DHE 256
14087Accepted TLSv1.1 256 bits DHE-RSA-AES256-SHA DHE 1024 bits
14088Accepted TLSv1.1 128 bits DHE-RSA-AES128-SHA DHE 1024 bits
14089Accepted TLSv1.1 256 bits AES256-SHA
14090Accepted TLSv1.1 128 bits AES128-SHA
14091Accepted TLSv1.1 112 bits DES-CBC3-SHA
14092Accepted TLSv1.1 128 bits RC4-SHA
14093Accepted TLSv1.1 128 bits RC4-MD5
14094Preferred TLSv1.0 256 bits ECDHE-RSA-AES256-SHA Curve P-256 DHE 256
14095Accepted TLSv1.0 128 bits ECDHE-RSA-AES128-SHA Curve P-256 DHE 256
14096Accepted TLSv1.0 256 bits DHE-RSA-AES256-SHA DHE 1024 bits
14097Accepted TLSv1.0 128 bits DHE-RSA-AES128-SHA DHE 1024 bits
14098Accepted TLSv1.0 256 bits AES256-SHA
14099Accepted TLSv1.0 128 bits AES128-SHA
14100Accepted TLSv1.0 112 bits DES-CBC3-SHA
14101Accepted TLSv1.0 128 bits RC4-SHA
14102Accepted TLSv1.0 128 bits RC4-MD5
14103Preferred SSLv3 112 bits DES-CBC3-SHA
14104Accepted SSLv3 128 bits RC4-SHA
14105Accepted SSLv3 128 bits RC4-MD5
14106
14107 SSL Certificate:
14108Signature Algorithm: sha256WithRSAEncryption
14109RSA Key Strength: 2048
14110
14111Subject: www.grandlodgemi.org
14112Altnames: DNS:www.grandlodgemi.org, DNS:grandlodgemi.org, DNS:www.sharethesecret.org, DNS:michiganchildid.org, DNS:mds.grandlodgemi.org, DNS:qr.grandlodgemi.org, DNS:data.michiganmasons.org, DNS:sharethesecret.org, DNS:contacts.michiganmasons.org, DNS:search.grandlodgemi.org, DNS:www.michiganchildid.org, DNS:www.michiganmasons.org, DNS:michiganmasons.org
14113Issuer: Starfield Secure Certificate Authority - G2
14114
14115Not valid before: Dec 20 10:28:44 2018 GMT
14116Not valid after: Feb 18 20:52:40 2021 GMT
14117#######################################################################################################################################
14118Starting Nmap 7.80 ( https://nmap.org ) at 2019-10-12 09:20 EDT
14119NSE: Loaded 47 scripts for scanning.
14120NSE: Script Pre-scanning.
14121Initiating NSE at 09:20
14122Completed NSE at 09:20, 0.00s elapsed
14123Initiating NSE at 09:20
14124Completed NSE at 09:20, 0.00s elapsed
14125Initiating Ping Scan at 09:20
14126Scanning 67.209.250.173 [4 ports]
14127Completed Ping Scan at 09:20, 0.13s elapsed (1 total hosts)
14128Initiating Parallel DNS resolution of 1 host. at 09:20
14129Completed Parallel DNS resolution of 1 host. at 09:20, 0.02s elapsed
14130Initiating SYN Stealth Scan at 09:20
14131Scanning a67-209-250-173.cust.mi.winntel.net (67.209.250.173) [65535 ports]
14132Discovered open port 80/tcp on 67.209.250.173
14133Discovered open port 443/tcp on 67.209.250.173
14134SYN Stealth Scan Timing: About 16.18% done; ETC: 09:23 (0:02:41 remaining)
14135SYN Stealth Scan Timing: About 44.04% done; ETC: 09:23 (0:01:18 remaining)
14136Completed SYN Stealth Scan at 09:22, 108.23s elapsed (65535 total ports)
14137Initiating Service scan at 09:22
14138Scanning 2 services on a67-209-250-173.cust.mi.winntel.net (67.209.250.173)
14139Completed Service scan at 09:22, 12.47s elapsed (2 services on 1 host)
14140Initiating OS detection (try #1) against a67-209-250-173.cust.mi.winntel.net (67.209.250.173)
14141Retrying OS detection (try #2) against a67-209-250-173.cust.mi.winntel.net (67.209.250.173)
14142Initiating Traceroute at 09:22
14143Completed Traceroute at 09:22, 0.06s elapsed
14144Initiating Parallel DNS resolution of 2 hosts. at 09:22
14145Completed Parallel DNS resolution of 2 hosts. at 09:22, 0.00s elapsed
14146NSE: Script scanning 67.209.250.173.
14147Initiating NSE at 09:22
14148Completed NSE at 09:23, 22.76s elapsed
14149Initiating NSE at 09:23
14150Completed NSE at 09:23, 0.92s elapsed
14151Nmap scan report for a67-209-250-173.cust.mi.winntel.net (67.209.250.173)
14152Host is up (0.041s latency).
14153Not shown: 65529 filtered ports
14154PORT STATE SERVICE VERSION
1415525/tcp closed smtp
1415680/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
14157|_http-server-header: Microsoft-HTTPAPI/2.0
14158| vulscan: VulDB - https://vuldb.com:
14159| [141625] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 DirectX memory corruption
14160| [141624] Microsoft Windows 7 SP1/Server 2008 R2 SP1 Graphics Component information disclosure
14161| [139966] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Kernel information disclosure
14162| [139923] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Graphics Component information disclosure
14163| [139905] Microsoft Windows Server 2008 SP2 DHCP Server memory corruption
14164| [137573] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
14165| [137567] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
14166| [137566] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
14167| [137565] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
14168| [137564] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
14169| [136343] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
14170| [136342] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
14171| [136341] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
14172| [136316] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
14173| [136315] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
14174| [136313] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
14175| [136311] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
14176| [136309] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
14177| [136302] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
14178| [136298] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
14179| [136297] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Win32k memory corruption
14180| [131683] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Win32k memory corruption
14181| [131642] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Active Directory privilege escalation
14182| [127822] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2012 Kernel information disclosure
14183| [125103] Microsoft Windows Server 2008 SP2 Graphics Component information disclosure
14184| [123853] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Kernel Memory information disclosure
14185| [122858] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 LNK memory corruption
14186| [122833] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI+ memory corruption
14187| [121109] Microsoft Wireless Display Adapter V2 2.0.8350/2.0.8365/2.0.8372 privilege escalation
14188| [120449] Microsoft Forefront Unified Access Gateway 2000 InitParams.aspx Parameter Server-Side Request Forgery
14189| [119469] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Kernel privilege escalation
14190| [116015] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1 memory corruption
14191| [114563] Microsoft Office 2007 SP3/2010 SP2/2013/2013 RT SP1 memory corruption
14192| [114528] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI privilege escalation
14193| [114524] Microsoft ASP.NET Core 2.0 denial of service
14194| [114523] Microsoft ASP.NET Core 2.0 Kestrel Web Application privilege escalation
14195| [113257] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2012 Kernel information disclosure
14196| [113256] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2012 Kernel information disclosure
14197| [113255] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2012 Kernel information disclosure
14198| [113247] Microsoft Windows 7 SP1/Server 2008 R2 SP1 EOT Font Engine information disclosure
14199| [113246] Microsoft Windows 7 SP1/Server 2008 R2 SP1 EOT Font Engine information disclosure
14200| [113245] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2012 EOT Font Engine information disclosure
14201| [113244] Microsoft Windows 7 SP1/Server 2008 R2 SP1 EOT Font Engine information disclosure
14202| [113235] Microsoft Outlook 2007 SP3/2010 SP2/2013 SP1/2016 privilege escalation
14203| [113234] Microsoft Office 2007 SP2/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
14204| [113216] Microsoft Outlook 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
14205| [112285] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
14206| [112284] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
14207| [112283] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
14208| [112282] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
14209| [111578] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
14210| [111577] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
14211| [111576] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
14212| [111575] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
14213| [111574] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
14214| [111573] Microsoft Office 2007/2010/2013/2016 Equation Editor memory corruption
14215| [111572] Microsoft Office 2007/2010/2013/2016 Equation Editor memory corruption
14216| [111570] Microsoft Office 2007/2010/2013/2016 Equation Editor memory corruption
14217| [111568] Microsoft Excel 2007/2010/2013/2016 memory corruption
14218| [111566] Microsoft Word 2007/2010/2013/2016 memory corruption
14219| [111565] Microsoft Word 2007/2010/2013 Email Message memory corruption
14220| [111563] Microsoft Outlook 2007/2010/2013/2016 Email Message privilege escalation
14221| [111347] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Color Management Icm32.dll information disclosure
14222| [109388] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2016 memory corruption
14223| [109387] Microsoft ASP.NET Core 2.0 privilege escalation
14224| [109386] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
14225| [109385] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 Security Feature Macro privilege escalation
14226| [109381] Microsoft Office/Word 2007 SP3/2010 SP2 memory corruption
14227| [107703] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
14228| [106530] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
14229| [106528] Microsoft PowerPoint 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
14230| [106515] Microsoft Publisher 2007 SP3/2010 SP2 memory corruption
14231| [106497] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Uniscribe memory corruption
14232| [106476] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
14233| [106475] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
14234| [105051] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Font Library privilege escalation
14235| [105032] Microsoft Internet Explorer 9/10 on Server 2008/Server 2012 memory corruption
14236| [102513] Microsoft Windows Server 2003 SP2/XP SP3 OLE olecnv32.dll privilege escalation
14237| [102512] Microsoft Windows Server 2003 SP2/XP SP3 rpc privilege escalation
14238| [102511] Microsoft Windows Server 2003 SP2/XP SP3 RDP EsteemAudit privilege escalation
14239| [102447] Microsoft PowerPoint/SharePoint Server 2007 SP3 privilege escalation
14240| [102444] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 privilege escalation
14241| [102442] Microsoft Outlook 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 Bypass privilege escalation
14242| [102441] Microsoft Outlook 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
14243| [102401] Microsoft Windows 7 SP1/Server 2008 R2 SP1 GDI USP10!NextCharInLiga Uniscribe Font information disclosure
14244| [101491] Microsoft Windows up to XP SP3/Server 2003 SP2 Remote Desktop Protocol gpkcsp.dll memory corruption
14245| [101017] Microsoft Office 2007 SP3/2010 SP2/2016 memory corruption
14246| [101012] Microsoft Office 2007 SP3/2010 SP2/2011/2013 SP1/2016 memory corruption
14247| [101011] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 ActiveX Object Memory memory corruption
14248| [100854] Microsoft Windows Server 2003 SP2 RRAS ERRATICGOPHER memory corruption
14249| [99904] Microsoft Windows Server 2003 SP2/XP SP3 SmartCard Authentication RDP Packet EsteemAudit privilege escalation
14250| [99698] Microsoft OneNote 2007 SP3/2010 SP2 DLL Loader privilege escalation
14251| [99684] Microsoft Excel 2007 SP3/2010 SP2 Memory information disclosure
14252| [99654] Microsoft Outlook 2007 SP3/2010 SP2/2011/2013 SP1/2016 Email Message privilege escalation
14253| [99653] Microsoft Outlook 2007 SP3/2010 SP2/2011/2013 SP1/2016 Email Message privilege escalation
14254| [99533] Microsoft Office 2007/2010/2013/2016 RTF Document Necurs Dridex memory corruption
14255| [98561] Microsoft IIS 6.0 on Windows Server 2003 WebDAV ScStoragePathFromUrl Long Header memory corruption
14256| [98092] Microsoft SharePoint Server 2007 SP3 memory corruption
14257| [98088] Microsoft SharePoint Server 2007 SP3 memory corruption
14258| [98087] Microsoft Office 2007 SP3/2010 SP2 memory corruption
14259| [98086] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
14260| [98085] Microsoft Excel 2007 SP3 memory corruption
14261| [98084] Microsoft Word 2007 SP3/2010 SP2/2011 memory corruption
14262| [98083] Microsoft Word 2007 SP3/2010 SP2/2011 memory corruption
14263| [98078] Microsoft Word/Excel 2007 SP3 memory corruption
14264| [98072] Microsoft Office 2007 SP3/2010 SP2/Word Viewer Graphics Component privilege escalation
14265| [98071] Microsoft Office 2007 SP3/2010 SP2/Word Viewer GDI+ information disclosure
14266| [98070] Microsoft Office 2007 SP3/2010 SP2/Word Viewer GDI+ information disclosure
14267| [94450] Microsoft Office 2007 SP3/2010 SP2/2011 memory corruption
14268| [94449] Microsoft Office 2007 SP3/2010 SP2/2011/2013 SP1 information disclosure
14269| [94448] Microsoft Office 2007 SP3/2010 SP2/2011/2013 SP1 information disclosure
14270| [94445] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1 information disclosure
14271| [94441] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 privilege escalation
14272| [94440] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
14273| [94439] Microsoft Office 2007 SP3/2011 privilege escalation
14274| [94438] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 privilege escalation
14275| [93542] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1 memory corruption
14276| [93541] Microsoft Office 2007 SP3 denial of service
14277| [93539] Microsoft Office 2007/2010 SP2/2011 memory corruption
14278| [93538] Microsoft Office 2007/2010 SP2/2011/2013 SP1 memory corruption
14279| [93537] Microsoft Office 2007/2010 SP2/2011 memory corruption
14280| [93396] Microsoft Office 2007/2010/2011 memory corruption
14281| [93395] Microsoft Office 2007/2010/2011 memory corruption
14282| [93394] Microsoft Office 2007/2010 memory corruption
14283| [92596] Microsoft Windows 7 SP1/Server 2008 R2/Server 2008 SP2/Vista SP2 Internet Messaging API File information disclosure
14284| [91554] Microsoft Exchange 2007/2010/2013/2016 Email information disclosure
14285| [91553] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
14286| [91552] Microsoft Office 2007/2010/2013/2013 RT/2016 spoofing
14287| [91551] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
14288| [91549] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
14289| [91548] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
14290| [91546] Microsoft Office 2007/2010/2013/2013 RT memory corruption
14291| [91545] Microsoft Office 2007/2010 memory corruption
14292| [91544] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
14293| [91542] Microsoft Office 2007/2010/2013/2013 RT/2016 information disclosure
14294| [90707] Microsoft OneNote 2007/2010/2013/2013 RT/2016 information disclosure
14295| [90706] Microsoft Office 2007/2010/2013/2013 RT Graphics memory corruption
14296| [90705] Microsoft Office 2007/2010/2011 memory corruption
14297| [90703] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
14298| [89039] Microsoft Office 2007 SP3/2010 SP2/2011/2013 RT SP1/2013 SP1 memory corruption
14299| [89034] Microsoft Windows Server 2008/Vista SP2 JScript/VBScript memory corruption
14300| [87960] Microsoft Windows Server 2008 R2/Server 2012/Server 2012 R2 Active Directory denial of service
14301| [87955] Microsoft Exchange 2007/2010/2013/2016 Oracle Outside In Libraries privilege escalation
14302| [87954] Microsoft Exchange 2007/2010/2013/2016 Oracle Outside In Libraries privilege escalation
14303| [87953] Microsoft Exchange 2007/2010/2013/2016 Oracle Outside In Libraries privilege escalation
14304| [87939] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 OLE DLL memory corruption
14305| [87938] Microsoft Office 2007 SP3/2010 SP2/2011 information disclosure
14306| [87937] Microsoft Office 2007 SP3/2010 SP2/2011 memory corruption
14307| [87935] Microsoft Windows Server 2008 R2 SP1/Server 2008 SP2/Vista SP2 VBScript/JScript memory corruption
14308| [87934] Microsoft Windows Server 2008 R2 SP1/Server 2008 SP2/Vista SP2 VBScript/JScript memory corruption
14309| [87933] Microsoft Windows Server 2008 R2 SP1/Server 2008 SP2/Vista SP2 VBScript/JScript memory corruption
14310| [87147] Microsoft Office 2007/2010 memory corruption
14311| [87145] Microsoft Windows Server 2008/Vista SP2 JScript/VBScript memory corruption
14312| [87144] Microsoft Windows Server 2008/Vista SP2 JScript/VBScript memory corruption
14313| [82228] Microsoft Excel 2007 SP3/2010 SP2 Office Document memory corruption
14314| [82225] Microsoft Word 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1 Office Document memory corruption
14315| [82224] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 Office Document memory corruption
14316| [81273] Microsoft Office 2007/2010/2013/2016 memory corruption
14317| [81272] Microsoft Office 2007/2010/2013 memory corruption
14318| [81265] Microsoft Windows Server 2008/Vista SP2 Library Loader memory corruption
14319| [80872] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
14320| [80871] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
14321| [80869] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
14322| [79506] Microsoft Windows 7/Server 2008/Server 2008 R2/Vista Library Loader memory corruption
14323| [79505] Microsoft Office 2007 memory corruption
14324| [79504] Microsoft Office 2007/2010/2013/2016 memory corruption
14325| [79503] Microsoft Office 2007/2010/2013 memory corruption
14326| [79502] Microsoft Office 2007/2010/2011 memory corruption
14327| [79501] Microsoft Office 2007/2010 memory corruption
14328| [79499] Microsoft Windows 7/Server 2008 R2 Uniscribe memory corruption
14329| [79493] Microsoft Windows Server 2008/Vista Graphics memory corruption
14330| [79190] Microsoft Word 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 Office Document memory corruption
14331| [79189] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 Office Document memory corruption
14332| [79187] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2016 Sandbox privilege escalation
14333| [79167] Microsoft Windows 7/Server 2008/Server 2008 R2/Vista Journal memory corruption
14334| [78372] Microsoft Visio 2007 SP3/2010 SP2 UML Data memory corruption
14335| [78371] Microsoft SharePoint Server 2007 SP3/2010 SP2 InfoPath Forms Services XXE information disclosure
14336| [77646] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1 EPS Image memory corruption
14337| [77629] Microsoft Excel 2007 SP3/2010 SP2/2011/2016 Office Document memory corruption
14338| [77627] Microsoft Excel 2007 SP3/2010 SP2 Office Document memory corruption
14339| [77626] Microsoft Excel 2007 SP3/2010 SP2/2011/2016 Office Document memory corruption
14340| [77617] Microsoft Office 2007 SP3/2010 SP2 OpenType Font memory corruption
14341| [77252] Microsoft Office 2007 SP3/2010 SP2 Office Graphics Library Font memory corruption
14342| [77038] Microsoft Windows Server 2008 SP2 UDDI Services cross site scripting
14343| [76497] Microsoft PowerPoint 2007 SP3/2010 SP2/2013 SP1 Office Document memory corruption
14344| [76491] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1 Office Document memory corruption
14345| [76467] Microsoft Word 2007 SP3/2010 SP2/2011/2013 RT SP1/2013 SP1 Office Document memory corruption
14346| [76466] Microsoft Word 2007 SP3/2010 SP2/2011/2013 RT SP1/2013 SP1 Office Document memory corruption
14347| [76464] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1 Office Document memory corruption
14348| [76463] Microsoft Excel 2007 SP3/2010 SP2/2011/2013 RT SP1/2013 SP1 Office Document memory corruption
14349| [76449] Microsoft Windows 8/8.1/Server 2008/Server 2012/Server 2012 R2 Hyper-V memory corruption
14350| [76440] Microsoft SQL Server 2008/2008 R2/2012/2014 Virtual Function Uninitialized Memory memory corruption
14351| [76439] Microsoft SQL Server 2008/2008 R2/2012/2014 Uninitialized Memory memory corruption
14352| [76438] Microsoft SQL Server 2008/2008 R2/2012/2014 Pointer Casting privilege escalation
14353| [75783] Microsoft Windows Server 2008/Server 2012 Active Directory Federation Services cross site scripting
14354| [75338] Microsoft SharePoint 2007/2010/2013 Content privilege escalation
14355| [75337] Microsoft Office 2007 SP3/2010 SP2/2011/2013 RT SP1/2013 SP1 memory corruption
14356| [75336] Microsoft Office 2007 SP3/2010 SP2/2011/2013 RT SP1/2013 SP1 memory corruption
14357| [74845] Microsoft Office 2007/2010/2013 Document Use-After-Free memory corruption
14358| [74844] Microsoft Office 2007/2010 Document Use-After-Free memory corruption
14359| [74837] Microsoft Office 2007/2010/2011/2013 RTF Document Use-After-Free privilege escalation
14360| [73979] Microsoft Exchange Server 2003 CU7/2003 SP1 Meeting privilege escalation
14361| [73978] Microsoft Exchange Server 2003 CU7/2003 SP1 cross site scripting
14362| [73977] Microsoft Exchange Server 2003 CU7/2003 SP1 cross site scripting
14363| [73976] Microsoft Exchange Server 2003 CU7/2003 SP1 cross site scripting
14364| [73975] Microsoft Exchange Server 2003 CU7/2003 SP1 cross site scripting
14365| [73964] Microsoft SharePoint 2007/2010/2013 cross site scripting
14366| [69158] Microsoft Office 2007/2010/2013 Use-After-Free memory corruption
14367| [69157] Microsoft Office 2007/2010/2013 OneTableDocumentStream memory corruption
14368| [68416] Microsoft Exchange 2007/2010/2013 Outlook Web Access Token spoofing
14369| [68409] Microsoft Office 2007/2010/2013 Use-After-Free memory corruption
14370| [68408] Microsoft Excel 2007/2010/2013 memory corruption
14371| [68407] Microsoft Excel 2007/2010 memory corruption
14372| [68405] Microsoft Word 2007/2010 Index Use-After-Free memory corruption
14373| [68195] Microsoft Windows 7/Server 2003/Server 2008/Vista Input Method Editor Sandbox privilege escalation
14374| [68189] Microsoft Windows Server 2003 SP2 TCP/IP Stack Stack-Based memory corruption
14375| [68188] Microsoft Word 2007 File memory corruption
14376| [68187] Microsoft Word 2007 File memory corruption
14377| [68186] Microsoft Word 2007 File memory corruption
14378| [67829] Microsoft Office 2007/2010/2011 Object memory corruption
14379| [67825] Microsoft .NET Framework 2.0/3.5/3.5.1 ASLR privilege escalation
14380| [71337] Microsoft Office 2000/2004/XP memory corruption
14381| [67355] Microsoft OneNote 2007 File Processing privilege escalation
14382| [67354] Microsoft SQL Server 2008 R2 SP2/2008 SP3/2012 SP1/2014 SQL Master Data Services cross site scripting
14383| [67353] Microsoft SQL Server 2008 R2 SP2/2008 SP3/2012 SP1/2014 T-SQL Query Stack-Based memory corruption
14384| [67018] Microsoft Windows Server 2008/Server 2012/Server 2012 R2 Service Bus AMQP Message denial of service
14385| [13545] Microsoft Word 2007 Embedded Font memory corruption
14386| [13397] Microsoft Windows 2000/Server 2003/XP DHCP Response DHCP ACK spoofing
14387| [13462] Microsoft Visual Studio 2002/2003/2005/2010 Debug Interface msdia.dll PDB File memory corruption
14388| [13229] Microsoft Office 2007/2010/2013 Common Control Library MSCOMCTL.OCX privilege escalation
14389| [13227] Microsoft Office 2007/2010/2013 Chinese Grammar Checker Library privilege escalation
14390| [13226] Microsoft SharePoint Server 2007/2010/2013 Page memory corruption
14391| [13225] Microsoft SharePoint Server 2007/2010/2013 cross site scripting
14392| [13224] Microsoft SharePoint Server 2007/2010/2013 Page memory corruption
14393| [12859] Microsoft Word 2003 Office Document Stack-Based memory corruption
14394| [12852] Microsoft Publisher 2003/2007 Publisher File pubconv.dll memory corruption
14395| [12845] Microsoft Word 2003 Office File Stack-Based memory corruption
14396| [12844] Microsoft Word 2007/2010 Office File memory corruption
14397| [12843] Microsoft Office 2007/2010/2011/2013 XML Parser Nested Entities Memory Consumption denial of service
14398| [12687] Microsoft Word/Office/Outlook 2003/2007/2010/2013 RTF Document memory corruption
14399| [12530] Microsoft Windows Server 2003/Server 2008/Server 2012/Vista/XP Security Account Manager Lockout privilege escalation
14400| [12266] Microsoft .NET Framework 2.0 SP2/3.5.1 ASLR Bypass privilege escalation
14401| [12070] Apple Pages 2.0/2.0.1/2.0.2/5.0/5.0.1 on Mac Microsoft Word Document memory corruption
14402| [11950] Microsoft Office Compability Pack/Word 2007 SP3 File memory corruption
14403| [11949] Microsoft Word Viewer/Office Compatibility Pack/Word 2003 SP3/2007 SP3 File memory corruption
14404| [11494] Microsoft .NET Framework 2.0 SP2/3.5.1/4/4.5/4.5.1 MAC Authentication privilege escalation
14405| [11448] Microsoft Office 2007/2010 Address Space Layout Randomization privilege escalation
14406| [11148] Microsoft Office 2003/2007 WordPerfect Document epsimp32.flt memory corruption
14407| [11146] Microsoft Office 2003/2007 epsimp32.flt memory corruption
14408| [11230] Microsoft Word 2003 DOC Document Embedded Image denial of service
14409| [11081] Microsoft Windows Server 2008/Vista TIFF Image memory corruption
14410| [10648] Microsoft Word 2007 Word File memory corruption
14411| [10647] Microsoft Word 2003 Word File memory corruption
14412| [10643] Microsoft SharePoint Server 2007/2010/2013 Input Sanitizer memory corruption
14413| [10642] Microsoft SharePoint Server 2007/2010 Content Display in Frames privilege escalation
14414| [10247] Microsoft SharePoint Server 2007/2010/2013 Online Cloud cross site scripting
14415| [10245] Microsoft Office 2003/2007/2010 Word File memory corruption
14416| [10244] Microsoft Office 2003 SP3 Word File memory corruption
14417| [10243] Microsoft Office 2003/2007 Word File memory corruption
14418| [10242] Microsoft Office 2007 Word File memory corruption
14419| [10241] Microsoft Office 2007 Word File memory corruption
14420| [10240] Microsoft Office 2003/2007/2010 Word File memory corruption
14421| [10239] Microsoft Office 2003/2007 Word File memory corruption
14422| [10238] Microsoft Excel 2003/2007 XML External Entity Data information disclosure
14423| [10237] Microsoft Excel 2003/2007/2010 XML External Entity Data information disclosure
14424| [10236] Microsoft Word/Office 2003/2007 XML External Entity Data information disclosure
14425| [10234] Microsoft Word/Sharepoint 2003 SP3/2007 SP3/2010 SP1 Office File memory corruption
14426| [10232] Microsoft Word/Sharepoint 2003 SP3/2007 SP3/2010 SP1 Office File memory corruption
14427| [10231] Microsoft Word/Sharepoint 2003 SP3/2007 SP3/2010 SP1 Office File memory corruption
14428| [10230] Microsoft Word/Sharepoint 2003 SP3/2007 SP3/2010 SP1 Office File memory corruption
14429| [10229] Microsoft Access 2007/2010/2013 Access File ACCDB File memory corruption
14430| [10228] Microsoft Access 2007/2010/2013 Access File ACCDB File memory corruption
14431| [10227] Microsoft Access 2007/2010/2013 Access File ACCDB File memory corruption
14432| [10192] Microsoft Windows 7/2000/Server 2003 SP2/Vista/XP SP3 Windows Theme File privilege escalation
14433| [10191] Microsoft Windows Server 2003/XP OLE Object privilege escalation
14434| [10190] Microsoft Windows 7/8/Server 2008/Vista Active Directory denial of service
14435| [10189] Microsoft Outlook 2007/2010 S/MIME privilege escalation
14436| [9941] Microsoft Windows Server 2003/XP Unicode Scripts Processor USP10.DLL Uniscribe Font memory corruption
14437| [9929] Microsoft Windows Server 2008/Server 2012 Active Directory Federation Services Unspecified Account information disclosure
14438| [9715] Microsoft PowerPoint 2007 DirectShow Runtime quartz.dll GetMaxSampleSize denial of service
14439| [9397] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 Array privilege escalation
14440| [9394] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 on 64-bit Array memory corruption
14441| [9393] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 Permission privilege escalation
14442| [8738] Microsoft Visio 2003 SP3/2007 SP3/2010 SP1 XML Parser File information disclosure
14443| [8737] Microsoft Word 2003 SP3 Shape Data Parser File memory corruption
14444| [8736] Microsoft Publisher 2003 SP3 PUB File memory corruption
14445| [8735] Microsoft Publisher 2003 SP3/2007 SP3/2010 SP1 PUB File memory corruption
14446| [8734] Microsoft Publisher 2003 SP3 PUB File memory corruption
14447| [8733] Microsoft Publisher 2003 SP3 PUB File memory corruption
14448| [8732] Microsoft Publisher 2003 SP3 PUB File memory corruption
14449| [8731] Microsoft Publisher 2003 SP3 PUB File memory corruption
14450| [8730] Microsoft Publisher 2003 SP3 PUB File memory corruption
14451| [8729] Microsoft Publisher 2003 SP3 PUB File memory corruption
14452| [8728] Microsoft Publisher 2003 SP3 PUB File memory corruption
14453| [8727] Microsoft Publisher 2003 SP3 PUB File memory corruption
14454| [8726] Microsoft Publisher 2003 PUB File Eingabe memory corruption
14455| [8723] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 XML File spoofing
14456| [7643] Microsoft Windows Server 2008 R2/Server 2012 NFS Server NULL Pointer Dereference denial of service
14457| [7642] Microsoft Exchange 2007/2010 Outlook Web Access vspdx.dll) privilege escalation
14458| [7641] Microsoft Windows Server 2003/Server 2008/Vista/XP DirectShow Quartz.dll memory corruption
14459| [8589] Microsoft System Center Operations Manager 2007 R2/2007 SP1 ViewTypeManager.aspx cross site scripting
14460| [7252] Microsoft System Center Operations Manager 2007 ExecuteTask.aspx cross site scripting
14461| [7251] Microsoft System Center Operations Manager 2007 cross site scripting
14462| [7248] Microsoft Windows 7/Server 2008 R2 Print Spooler privilege escalation
14463| [7121] Microsoft Exchange 2007/2010 RSS Feed denial of service
14464| [7118] Microsoft Windows Server 2008 R2/Server 2012 IP-HTTPS unknown vulnerability
14465| [62914] Microsoft Office 2003 SP3/2007 SP3/2008/2010 SP1/2011 Spreadsheet Use-After-Free memory corruption
14466| [7058] Microsoft Windows 7/Server 2008 R2 DHCPv6 Message denial of service
14467| [6935] Microsoft Office Excel 2003/2007/2010 Input Sanitizer File Stack-based memory corruption
14468| [6934] Microsoft Office Excel 2003/2007/2010 Input Sanitizer memory corruption
14469| [6933] Microsoft Office Excel 2003/2007/2010 SerAuxErrBar File memory corruption
14470| [6929] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 Web Proxy Setting Auto-Discovery memory corruption
14471| [6927] Microsoft .NET Framework 2.0 SP2/3.5.1 Trusted Code Function information disclosure
14472| [6918] Microsoft Excel 2007 SP2 Input Sanitizer File memory corruption
14473| [6830] Microsoft Word 2007/2010 File memory corruption
14474| [6819] Microsoft Excel 2007 File memory corruption
14475| [6627] Microsoft Windows 7/Server 2008 R2 Kerberos denial of service
14476| [6626] Microsoft SharePoint/Lync/Infopath 2007/2010 HTML Sanitization cross site scripting
14477| [6621] Microsoft Word 2007 PAPX memory corruption
14478| [62239] Microsoft Systems Management Server 2003 Configuration Manager Reflected cross site scripting
14479| [5945] Microsoft Office 2007/2010 Computer Graphics Metafile memory corruption
14480| [5939] Microsoft Windows 7/Server 2003/Server 2008 R2/Vista/XP Print Spooler Service memory corruption
14481| [5938] Microsoft Windows 7/Server 2003/Server 2008 R2/Vista/XP Remote Administration Protocol netapi32.dll RAP Request denial of service
14482| [5933] Microsoft SQL Server 2000/2005/2008/2008 R2 Common Controls TabStrip ActiveX MSCOMCTL.OCX memory corruption
14483| [5932] Microsoft Office 2003/2007/2010 Common Controls TabStrip ActiveX MSCOMCTL.OCX memory corruption
14484| [5654] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP information disclosure
14485| [5653] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP win32k.sys memory corruption
14486| [5652] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP win32k.sys memory corruption
14487| [5650] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP memory corruption
14488| [5649] Microsoft Office 2003/2007/2010 libraries memory corruption
14489| [5645] Microsoft SharePoint 2007/2010/3.0 Reflected cross site scripting
14490| [5643] Microsoft SharePoint 2007/2010 information disclosure
14491| [5642] Microsoft SharePoint 2007 cross site request forgery
14492| [5553] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP OpenType Font atmfd.dll denial of service
14493| [5524] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP memory corruption
14494| [5518] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 memory corruption
14495| [5362] Microsoft Office 2003/2007 GDI+ memory corruption
14496| [5291] Microsoft Visual Studio 2008 Incremental Linker link.exe ConvertRgImgSymToRgImgSymEx memory corruption
14497| [5268] Microsoft Office 2008 on Mac RTF Pfragment File memory corruption
14498| [5080] Microsoft SQL Server 2005/2008/2008R2 CREATE DATABASE sql injection
14499| [5050] Microsoft Office 2007 WPS Converter Heap-based memory corruption
14500| [5049] Microsoft SQL Server 2000/2005/2008 MSCOMCTL.OCX privilege escalation
14501| [5048] Microsoft Office 2003/2007/2010 MSCOMCTL.OCX privilege escalation
14502| [5046] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Windows Authenticode Signature Verification WinVerifyTrust Signature privilege escalation
14503| [4803] Microsoft Windows Server 2003/Server 2008 DNS Server Domain Resource Record Query Parser denial of service
14504| [4802] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Remote Desktop Protocol denial of service
14505| [4798] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Remote Desktop Service memory corruption
14506| [60205] Microsoft .NET Framework 2.0 SP2/3.5.1 Heap-based memory corruption
14507| [4642] Microsoft .NET Framework 2.0 SP2/3.5.1/4 XAML Browser Application memory corruption
14508| [60065] Microsoft Windows 2000 mod_sql unknown vulnerability
14509| [4535] Microsoft Windows Server 2003/XP Object Packager packager.exe privilege escalation
14510| [4534] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Line21 DirectShow Filter Quartz.dll/Qdvd.dll Media File memory corruption
14511| [4533] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Multimedia Library winmm.dll MIDI File memory corruption
14512| [4507] Microsoft .NET Framework 2.0 SP2/3.5 SP1/3.5.1/4.0 Forms Authentication privilege escalation
14513| [59666] Microsoft Publisher 2003/2007 "Publisher memory corruption
14514| [4482] Microsoft Word 2007/2010/2011 Document Parser memory corruption
14515| [4480] Microsoft Excel 2003 memory corruption
14516| [4478] Microsoft Windows Server 2003/XP OLE Objects Memory Management memory corruption
14517| [4477] Microsoft PowerPoint 2007 SP2/2008 OfficeArt Use-After-Free memory corruption
14518| [4474] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Active Directory Query memory corruption
14519| [4473] Microsoft PowerPoint 2007 SP2/2010 DLL-Loader memory corruption
14520| [4471] Microsoft Office 2003/2007 Publisher Out-of-Bounds memory corruption
14521| [4470] Microsoft Office 2003 SP3 memory corruption
14522| [4453] Microsoft Excel 2003 Record Parser memory corruption
14523| [4446] Microsoft Office 2007/2008 OfficeArt Record Parser memory corruption
14524| [4445] Microsoft Office 2007/2010/2011 Word Document Parser memory corruption
14525| [4438] Microsoft Windows 7/Server 2008/Vista TCP/IP Reference Counter denial of service
14526| [5358] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP TrueType Font Handling memory corruption
14527| [59005] Microsoft Host Integration Server 2004 denial of service
14528| [58492] Microsoft SharePoint Server 2007 Spreadsheet memory corruption
14529| [58491] Microsoft Office 2004/2007/2008/2010/2011 Spreadsheet memory corruption
14530| [58490] Microsoft Office Compatibility Pack 2007 Spreadsheet memory corruption
14531| [58489] Microsoft Office 2004/2007/2008/2010/2011 Spreadsheet memory corruption
14532| [58488] Microsoft Office 2007/2010 memory corruption
14533| [4412] Microsoft Office 2003/2007 Library Loader unknown vulnerability
14534| [4411] Microsoft Excel 2003 memory corruption
14535| [4409] Microsoft Windows Server 2003/Server 2008 WINS unknown vulnerability
14536| [58240] Microsoft Visio 2003/2007 memory corruption
14537| [58237] Microsoft Visio 2003/2007/2010 memory corruption
14538| [4396] Microsoft Windows 7/Server 2008/Vista TCP/IP Stack denial of service
14539| [4393] Microsoft Windows Server 2008 DNS Service memory corruption
14540| [4391] Microsoft .NET Framework 2.0 SP2/3.5.1/4 Socket Restriction privilege escalation
14541| [4390] Microsoft Windows Server 2008 Remote Desktop Web Access cross site scripting
14542| [4388] Microsoft Windows 7/Server 2008/Vista File Metadata Parser denial of service
14543| [57691] Microsoft SQL Server 2008 Web Service information disclosure
14544| [57690] Microsoft Excel 2002/2003 Spreadsheet memory corruption
14545| [57689] Microsoft Excel 2002 Spreadsheet memory corruption
14546| [57688] Microsoft Excel 2002 Spreadsheet memory corruption
14547| [57687] Microsoft Excel 2002/2003/2007 Spreadsheet memory corruption
14548| [57686] Microsoft Excel 2002 Spreadsheet memory corruption
14549| [57685] Microsoft Excel 2002/2003/2007 Array Access memory corruption
14550| [57684] Microsoft Excel 2002/2003/2007/2010 Spreadsheet memory corruption
14551| [4369] Microsoft Excel 2002/2003/2007 memory corruption
14552| [4367] Microsoft Windows Server 2008 Hyper-V VMBus denial of service
14553| [4362] Microsoft Windows 7/Server 2008/Vista denial of service
14554| [57420] Microsoft PowerPoint 2002/2003 memory corruption
14555| [4349] Microsoft Office 2004/2007/2008 Presentation File Parser memory corruption
14556| [4348] Microsoft PowerPoint 2002/2003/2007 memory corruption
14557| [57077] Microsoft Excel 2002 Uninitialized Memory memory corruption
14558| [57078] Microsoft Office 2003/2007/Xp docx unknown vulnerability
14559| [57079] Microsoft PowerPoint 2002/2003/2007/2010 memory corruption
14560| [57076] Microsoft Excel 2002/2003 memory corruption
14561| [57075] Microsoft Excel 2002/2003 memory corruption
14562| [57074] Microsoft Excel 2002 memory corruption
14563| [57073] Microsoft Excel 2002/2003/2007/2010 memory corruption
14564| [4334] Microsoft .NET Framework 2.0 SP2/3.5 SP1/3.5.1/4.0 JIT Compiler memory corruption
14565| [4332] Microsoft PowerPoint 2007/2010 memory corruption
14566| [4301] Microsoft Windows Server 2003 SMB Browser Heap-based denial of service
14567| [56475] Microsoft Office 2004/2008 memory corruption
14568| [56414] Microsoft Visio 2002/2003/2007 ELEMENTS.DLL memory corruption
14569| [56413] Microsoft Visio 2002/2003/2007 Exception ORMELEMS.DLL memory corruption
14570| [4298] Microsoft Windows 7/Server 2008 JScript/VBScript Engine information disclosure
14571| [4297] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP OpenType Compact Font Format Driver privilege escalation
14572| [4296] Microsoft Windows Server 2003/XP LSASS Authentication Request unknown vulnerability
14573| [4295] Microsoft Windows 7/Server 2008 Kerberos weak authentication
14574| [4294] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Driver win32k.sys unknown vulnerability
14575| [4293] Microsoft Windows Server 2003/XP Kerberos CRC32 Checksum privilege escalation
14576| [4292] Microsoft Windows Server 2003/XP CSRSS Logoff privilege escalation
14577| [4289] Microsoft Excel 2007 Shape Data Parser memory corruption
14578| [4286] Microsoft PowerPoint 2002 SP3/2003 SP3/2004/2007 SP2/2008 OfficeArt Container Parser memory corruption
14579| [4279] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP MHTML cross site scripting
14580| [56176] Microsoft Windows 7/Server 2003/XP fxscover.exe CDrawPoly::Serialize memory corruption
14581| [55772] Microsoft Publisher 2002 pubconv.dll memory corruption
14582| [55771] Microsoft Publisher 2002/2003/2010 memory corruption
14583| [55765] Microsoft Office 2003/Xp Integer memory corruption
14584| [55764] Microsoft Office 2003/Xp memory corruption
14585| [55750] Microsoft Publisher 2002/2003 pubconv.dll memory corruption
14586| [55749] Microsoft Publisher 2002/2003/2007/2010 pubconv.dll memory corruption
14587| [55748] Microsoft Publisher 2002/2003/2007 pubconv.dll memory corruption
14588| [4230] Microsoft Exchange 2007 on 64-bit RPC store.exe MAPI Request denial of service
14589| [4229] Microsoft SharePoint 2007 Document Conversion Launcher Service Eingabeung\xC3\xBCltigkeit
14590| [4228] Microsoft Windows Server 2008 Hyper-V VMBus denial of service
14591| [4224] Microsoft Windows 7/Server 2008/Vista Consent User Interface privilege escalation
14592| [4231] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Driver win32k.sys GreEnableEUDC denial of service
14593| [55420] Microsoft Office 2007/2010 memory corruption
14594| [55419] Microsoft Office 2004/2008/2011/Xp memory corruption
14595| [55412] Microsoft PowerPoint Viewer 2007 memory corruption
14596| [55411] Microsoft PowerPoint 2002/2003 memory corruption
14597| [4204] Microsoft Windows Server 2008 Color Control Panel Eingabeung\xC3\xBCltigkeit
14598| [54995] Microsoft Office 2004/2008 memory corruption
14599| [54994] Microsoft Office 2004/2008 Out-of-Bounds memory corruption
14600| [54993] Microsoft Office Compatibility Pack 2007 memory corruption
14601| [54992] Microsoft Excel 2002 memory corruption
14602| [54991] Microsoft Office 2004 Future memory corruption
14603| [54990] Microsoft Office 2004 memory corruption
14604| [54989] Microsoft Office 2004/2008 memory corruption
14605| [54988] Microsoft Excel 2002 memory corruption
14606| [54987] Microsoft Excel 2002 memory corruption
14607| [54986] Microsoft Excel 2002/2003 memory corruption
14608| [54985] Microsoft Office Compatibility Pack 2003/2004/2007/2008 memory corruption
14609| [54984] Microsoft Office 2004/2008 memory corruption
14610| [54983] Microsoft Excel 2002 Integer memory corruption
14611| [54980] Microsoft Word 2002/2003 memory corruption
14612| [54979] Microsoft Word 2002 memory corruption
14613| [54978] Microsoft Word 2002 memory corruption
14614| [54977] Microsoft Word 2002 Heap-based memory corruption
14615| [54976] Microsoft Word 2002 memory corruption
14616| [54975] Microsoft Word 2002 memory corruption
14617| [54974] Microsoft Word 2002 memory corruption
14618| [54973] Microsoft Word 2002 memory corruption
14619| [54972] Microsoft Word 2002 memory corruption
14620| [54971] Microsoft Word 2002 memory corruption
14621| [4197] Microsoft SharePoint 2007/3.0 cross site scripting
14622| [4196] Microsoft Word 2002/2003/2007/2010 Stack-based memory corruption
14623| [4194] Microsoft Windows 7/Server 2008/Vista SChannel Client Certificate Request denial of service
14624| [54774] Microsoft Word 2003 word_crash_11.8326.8324_poc.doc denial of service
14625| [54757] Microsoft SharePoint Server 2007 HTML Sanitization SafeHTML cross site scripting
14626| [4186] Microsoft Outlook 2002/2003/2007 Content Parser Heap-based memory corruption
14627| [54584] Microsoft Visual C++ 2005 AtlTraceTool8.exe unknown vulnerability
14628| [54554] Microsoft Groove 2007 mso.dll memory corruption
14629| [4187] Microsoft Windows 7/Server 2008/Vista TCP/IP Stack Ipv4SetEchoRequestCreate denial of service
14630| [54322] Microsoft Word 2002/2003 memory corruption
14631| [54321] Microsoft Office Compatibility Pack 2007 memory corruption
14632| [54320] Microsoft Office Compatibility Pack 2007 memory corruption
14633| [54319] Microsoft Office Compatibility Pack 2007 memory corruption
14634| [54318] Microsoft .NET Framework 2.0 SP1/2.0 SP2/3.5/3.5 SP1/3.5.1 Interfaces memory corruption
14635| [4165] Microsoft Windows 7/Server 2008/Vista TCP/IP Stack denial of service
14636| [4162] Microsoft Windows 7/Server 2008/Vista Kernel memory corruption
14637| [4159] Microsoft Excel 2002/2003 SXDB PivotTable Cache Data Record memory corruption
14638| [4149] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Shell Shortcut Parser memory corruption
14639| [54083] Microsoft Access 2003 ActiveX Control ACCWIZ.dll memory corruption
14640| [4146] Microsoft Outlook 2002/2003/2007 SMB Attachment PR_ATTACH_METHOD memory corruption
14641| [4145] Microsoft Access 2003/2007 ActiveX ACCWIZ.dll memory corruption
14642| [54617] Microsoft Outlook Web Access up to 2007 cross site request forgery
14643| [4151] Microsoft Windows Server 2008/Vista NtUserCheckAccessForIntegrityLevel memory corruption
14644| [53591] Microsoft Windows Server 2003 GetServerName cross site scripting
14645| [53505] Microsoft Excel 2002/2007 memory corruption
14646| [53501] Microsoft Excel 2002 memory corruption
14647| [53500] Microsoft Excel 2002 memory corruption
14648| [53499] Microsoft Excel 2002 memory corruption
14649| [53495] Microsoft Excel 2002/2003/2007 memory corruption
14650| [53494] Microsoft Excel 2002 Stack-based memory corruption
14651| [53504] Microsoft Excel 2002 memory corruption
14652| [53503] Microsoft Excel 2002 Stack-Based memory corruption
14653| [53502] Microsoft Excel 2002 Heap-based memory corruption
14654| [53498] Microsoft Excel 2002 Stack-based memory corruption
14655| [53497] Microsoft Excel 2002 memory corruption
14656| [53496] Microsoft Excel 2002 memory corruption
14657| [53493] Microsoft Excel 2002/2003/2007 memory corruption
14658| [4133] Microsoft Office 2003/2007/Xp COM Object Instantiator memory corruption
14659| [53366] Microsoft ASP.NET 2.0 cross site scripting
14660| [53385] Microsoft Exchange Server 2007 Outlook Web Access cross site scripting
14661| [53164] Microsoft Office 2003/2007/Xp ActiveX Control VBE6.DLL memory corruption
14662| [53054] Microsoft VISIO 2002/2003/2007 VISIODWG.DLL memory corruption
14663| [4125] Microsoft SharePoint 2007/3.0 help.aspx cross site scripting
14664| [52777] Microsoft Publisher 2002/2003/2007 memory corruption
14665| [52773] Microsoft Visio 2002/2003/2007 memory corruption
14666| [52772] Microsoft Visio 2002/2003/2007 memory corruption
14667| [4107] Microsoft Windows 7/Server 2008 Kernel denial of service
14668| [4103] Microsoft Windows Server 2003 Media Services Stack-based memory corruption
14669| [52543] Microsoft Virtual PC 2007 unknown vulnerability
14670| [52148] Microsoft Office 2004/2007/2008 Uninitialized Memory memory corruption
14671| [52147] Microsoft Office 2004/2007/2008 Spreadsheet Uninitialized Memory memory corruption
14672| [52146] Microsoft Office 2004/2007/2008 Spreadsheet Heap-based memory corruption
14673| [52145] Microsoft Office 2004/2007/2008 Spreadsheet Heap-based memory corruption
14674| [52144] Microsoft Office 2004/2007/2008 Spreadsheet memory corruption
14675| [52143] Microsoft Office 2004/2007/2008 Spreadsheet memory corruption
14676| [4090] Microsoft Excel 2002/2003/2007 memory corruption
14677| [52036] Microsoft Windows 2000 MsgBox memory corruption
14678| [51995] Microsoft SharePoint Server up to 2006 cross site scripting
14679| [51810] Microsoft Office 2004/Xp MSO.DLL memory corruption
14680| [51802] Microsoft PowerPoint 2003 Stack-based memory corruption
14681| [51801] Microsoft PowerPoint 2003 Stack-based memory corruption
14682| [51800] Microsoft PowerPoint 2002/2003 Use-After-Free memory corruption
14683| [51799] Microsoft PowerPoint 2002/2003 memory corruption
14684| [51798] Microsoft PowerPoint 2002/2003 Heap-based memory corruption
14685| [4082] Microsoft PowerPoint 2002 SP3 memory corruption
14686| [54550] Microsoft PowerPoint 2007 rpawinet.dll memory corruption
14687| [54556] Microsoft Visio 2003 mfc71enu.dll unknown vulnerability
14688| [51497] Microsoft Windows Live Messenger 2009 ActiveX Control msnmsgr.exe denial of service
14689| [51133] Microsoft Windows 2000 SP4/Server 2003 SP2/SP3/XP SP2 memory corruption
14690| [51074] Microsoft Office 2002/2003 Integer memory corruption
14691| [4069] Microsoft Project 2003/2007 Project Memory Validator memory corruption
14692| [50794] Microsoft Office 2004/2008 Spreadsheet memory corruption
14693| [50793] Microsoft Office 2004/2008 Spreadsheet memory corruption
14694| [50792] Microsoft Office 2004/2008 Spreadsheet memory corruption
14695| [50791] Microsoft Office 2004/2008 Spreadsheet memory corruption
14696| [50790] Microsoft Office 2004/2008 Spreadsheet Heap-based memory corruption
14697| [50788] Microsoft Office 2004/2008 Spreadsheet memory corruption
14698| [50787] Microsoft Office 2004/2008 Spreadsheet memory corruption
14699| [50786] Microsoft Windows 2000 llssrv.exe memory corruption
14700| [50789] Microsoft Office 2004/2008 Spreadsheet memory corruption
14701| [4056] Microsoft Word 2002/2003 File Information Block Parser Stack-based memory corruption
14702| [50660] Microsoft SharePoint Server 2007 unknown vulnerability
14703| [50443] Microsoft PowerPoint 2007 Integer memory corruption
14704| [50432] Microsoft .NET Framework 2.0/2.0 SP1/2.0 SP2/3.5/3.5 SP1 memory corruption
14705| [49866] Microsoft Windows Server 2003 memory corruption
14706| [4031] Microsoft Windows Server 2008/Vista SMB Processor EducatedScholar memory corruption
14707| [4030] Microsoft Windows Server 2008/Vista Wireless LAN AutoConfig Service Heap-based memory corruption
14708| [4029] Microsoft Windows 2000/XP TCP/IP Window Size denial of service
14709| [49745] Microsoft Windows Server 2003 denial of service
14710| [49395] Microsoft Office 2000/2003/XP Office Web Components Heap-based memory corruption
14711| [49394] Microsoft Windows Server 2003 memory corruption
14712| [49389] Microsoft Office 2000/2003/XP Office Web Components memory corruption
14713| [49390] Microsoft Office 2000/2003/XP Office Web Components memory corruption
14714| [49198] Microsoft Visual Studio 2005 information disclosure
14715| [49047] Microsoft Virtual Server 2005 privilege escalation
14716| [49046] Microsoft Windows Server 2003 quartz.dll memory corruption
14717| [49045] Microsoft Windows Server 2003 quartz.dll memory corruption
14718| [49044] Microsoft ISA Server 2006 privilege escalation
14719| [3999] Microsoft Office 2007 Pointer memory corruption
14720| [4000] Microsoft Office 2003/Sp3/Xp Web Components memory corruption
14721| [48894] Microsoft Windows Server 2003 msvidctl.dll memory corruption
14722| [48572] Microsoft PowerPoint 2002 FL21WIN.DLL memory corruption
14723| [48517] Microsoft Windows 2000 Memory Leak memory corruption
14724| [48516] Microsoft Windows Server 2008 unknown vulnerability
14725| [48512] Microsoft Windows Server 2008 unknown vulnerability
14726| [48515] Microsoft Office Word Viewer 2003 memory corruption
14727| [48514] Microsoft Office Word Viewer 2003 Stack-based memory corruption
14728| [48554] Microsoft Excel 2000/2003/2007 memory corruption
14729| [48157] Microsoft PowerPoint 2002 Sound memory corruption
14730| [48156] Microsoft PowerPoint 2000 Stack-based memory corruption
14731| [48154] Microsoft PowerPoint 2002 Sound PP7X32.DLL memory corruption
14732| [48152] Microsoft PowerPoint 2002 PP4X32.DLL memory corruption
14733| [48150] Microsoft PowerPoint 2002 Sound memory corruption
14734| [48147] Microsoft PowerPoint 2002 Sound memory corruption
14735| [48146] Microsoft PowerPoint 2002 Integer memory corruption
14736| [48155] Microsoft PowerPoint 2002 Notes Container Heap-based memory corruption
14737| [48153] Microsoft PowerPoint 2002 Sound memory corruption
14738| [48151] Microsoft PowerPoint 2002 Stack-based memory corruption
14739| [48149] Microsoft PowerPoint 2002 memory corruption
14740| [48148] Microsoft PowerPoint 2002 Sound memory corruption
14741| [3974] Microsoft PowerPoint 2000/2002/2003 Sound Data Stack-based memory corruption
14742| [3973] Microsoft PowerPoint 2000/2002/2003 Notes Container Stack-based memory corruption
14743| [3972] Microsoft PowerPoint 2000/2002/2003 BuildList memory corruption
14744| [3971] Microsoft PowerPoint 2000/2002/2003 Object Stack-based memory corruption
14745| [3970] Microsoft PowerPoint 2000/2002/2003 Paragraph Stack-based memory corruption
14746| [3969] Microsoft PowerPoint 2000/2002/2003 Atom Stack-based memory corruption
14747| [47719] Microsoft Windows 2000 Stack-based memory corruption
14748| [47720] Microsoft Internet Security And Acceleration Server 2006 Forms Authentication cookieauth.dll cross site scripting
14749| [47716] Microsoft Office Converter Pack 2003 WPFT632.CNV memory corruption
14750| [47715] Microsoft Windows 2000 Wordpad memory corruption
14751| [47718] Microsoft Excel 2000/2002/2003/2007 Spreadsheet memory corruption
14752| [3960] Microsoft Windows 2000/Server 2003/XP DirectShow MJPEG memory corruption
14753| [3952] Microsoft ISA Server 2004/2006 denial of service
14754| [3946] Microsoft PowerPoint 2000/2002/2003/2004 memory corruption
14755| [47091] Microsoft Windows Server 2008 unknown vulnerability
14756| [47090] Microsoft Windows Server 2008 unknown vulnerability
14757| [3939] Microsoft Windows 2000 DNS spoofing
14758| [3938] Microsoft Windows 2000 SSL weak authentication
14759| [3937] Microsoft Windows 2000 memory corruption
14760| [3932] Microsoft Excel 2000/2002/2003/2004/2007 Object Reference memory corruption
14761| [46620] Microsoft Windows Live Messenger 2009 msnmsgr.exe denial of service
14762| [46455] Microsoft Exchange Server 2007 denial of service
14763| [46454] Microsoft Exchange Server 2007 memory corruption
14764| [46453] Microsoft Visio 2002/2003/2007 memory corruption
14765| [46452] Microsoft Visio 2002/2003/2007 memory corruption
14766| [46451] Microsoft Visio 2002/2003/2007 memory corruption
14767| [46327] Microsoft Word 2007 information disclosure
14768| [45758] Microsoft Money 2006 ActiveX Control prtstb06.dll denial of service
14769| [45381] Microsoft Windows Server 2008/Vista SP1 Explorer memory corruption
14770| [45380] Microsoft Windows Server 2008/Vista SP1 Search memory corruption
14771| [45379] Microsoft Office SharePoint Server 2007 denial of service
14772| [3896] Microsoft SQL Server up to 2005 sp_replwritetovarbin memory corruption
14773| [3892] Microsoft Excel 2000/2002/2003 Formula memory corruption
14774| [3891] Microsoft Excel 2000/2002/2003 memory corruption
14775| [3890] Microsoft Excel 2000/2002/2003 NAME Index memory corruption
14776| [3889] Microsoft Word 2000/2002/2003/2007 Table Property Stack-based memory corruption
14777| [3888] Microsoft Word 2000/2002/2003/2007 RTF Stylesheet memory corruption
14778| [3887] Microsoft Word 2000/2002/2003/2007 memory corruption
14779| [3886] Microsoft Word 2000/2002/2003/2007 ControlWord Heap-based memory corruption
14780| [3885] Microsoft Word 2000/2002/2003/2007 memory corruption
14781| [3884] Microsoft Word 2000/2002/2003/2007 memory corruption
14782| [3883] Microsoft Word 2000/2002/2003/2007 RTF Heap-based memory corruption
14783| [3882] Microsoft Word 2000/2002/2003/2007 LFO memory corruption
14784| [3880] Microsoft Visual Basic up to 2003 ActiveX Control Mschrt20.ocx memory corruption
14785| [3879] Microsoft Visual Basic up to 2003 ActiveX Control mscomct2.ocx memory corruption
14786| [3878] Microsoft Visual Basic up to 2003 ActiveX Control mshflxgd.ocx memory corruption
14787| [3877] Microsoft Visual Basic up to 2003 ActiveX Control msflxgrd.ocx memory corruption
14788| [3876] Microsoft Visual Basic up to 2003 ActiveX Control msdatgrd.ocx memory corruption
14789| [45197] Microsoft Windows 2000 nskey.dll memory corruption
14790| [45063] Microsoft Windows Server 2003 Active Directory unknown vulnerability
14791| [45040] Microsoft .NET Framework 2.0.50727 Code Access Security unknown vulnerability
14792| [44855] DjVu Activex Control For Microsoft Office 2000 3.0 ActiveX Control DjVu_ActiveX_MSOffice.dll memory corruption
14793| [44665] Microsoft Peachtree Accounting 2004 ActiveX Control PAWWeb11.ocx unknown vulnerability
14794| [44589] Microsoft Exchange Server 2003 Outlook Web Access unknown vulnerability
14795| [3845] Microsoft Windows 2000 SP4 Active Directory memory corruption
14796| [44533] Microsoft Windows 2000 mqsvc.exe memory corruption
14797| [3844] Microsoft Excel 2003 REPT memory corruption
14798| [3843] Microsoft Excel up to 2007 BIFF File Heap-based memory corruption
14799| [3842] Microsoft Excel 2003 VBA Performance Cache Stack-based memory corruption
14800| [44405] Microsoft Digital Image 2006 ActiveX Control PipPPush.DLL unknown vulnerability
14801| [44047] Microsoft SQL Server 2000 ActiveX Control SQLVDIRLib.SQLVDirControl memory corruption
14802| [43981] Microsoft Organization Chart 2.00 orgchart.exe memory corruption
14803| [43957] Microsoft Office 2003/2007/Xp gdiplus.dll memory corruption
14804| [43956] Microsoft Office 2003/2007/Xp gdiplus.dll memory corruption
14805| [43955] Microsoft Office 2003/2007/Xp gdiplus.dll memory corruption
14806| [43952] Microsoft Office 2003/2007/Xp URI memory corruption
14807| [43676] Microsoft Windows 2000/Server 2003/Vista/XP memory corruption
14808| [43675] Microsoft Windows 2000/Server 2003/Vista/XP of memory corruption
14809| [43662] Microsoft PowerPoint Viewer 2000 SP3/2002 SP3/2003 SP2/2007 SP1 memory corruption
14810| [43661] Microsoft PowerPoint Viewer 2003 memory corruption
14811| [43660] Microsoft PowerPoint Viewer 2003 Integer memory corruption
14812| [43657] Microsoft Office 2000/2003/Xp memory corruption
14813| [43654] Microsoft SharePoint Server 2007 memory corruption
14814| [43653] Microsoft Office 2000/2002/2004/2008 memory corruption
14815| [43652] Microsoft Office 2000/2002/2003/2004/2008 memory corruption
14816| [3797] Microsoft Windows Server 2008/Vista IPsec Policy Designfehler
14817| [3796] Microsoft Office 2000 WPG memory corruption
14818| [3795] Microsoft Office 2000/2003/Xp BMP Image BMPIMP32.FLT memory corruption
14819| [3794] Microsoft Office 2000/2003/Xp PICT bits_per_pixel memory corruption
14820| [3793] Microsoft Office 2000/2003/Xp PICT memory corruption
14821| [3792] Microsoft Office 2000 EPS File memory corruption
14822| [3783] Microsoft Word 2002 memory corruption
14823| [43103] Microsoft Exchange Srv 2007 Sp1 Outlook Web Access cross site scripting
14824| [43102] Microsoft Windows 2000 SP4/Server 2003 SP2/Server 2008 DNS Cache privilege escalation
14825| [3778] Microsoft Exchange 2003/2007 Outlook Web Access cross site scripting
14826| [3777] Microsoft Windows Server 2008/Vista SP1 Explorer memory corruption
14827| [43087] Microsoft Office Snapshot Viewer ActiveX up to Office 2003 Snapshot Viewer ActiveX Control snapview.ocx memory corruption
14828| [43096] Microsoft Publisher 2003/2007 Crypto API unknown vulnerability
14829| [42816] Microsoft Word 2000/2003 memory corruption
14830| [42732] Microsoft Windows Server 2003/Vista/XP denial of service
14831| [42731] Microsoft Windows Server 2003 denial of service
14832| [3732] Microsoft Windows 2000/Server 2003 WINS memory corruption
14833| [3701] Microsoft Word 2003 CSS Heap-based memory corruption
14834| [3700] Microsoft Word 2003 RTF Document Heap-based memory corruption
14835| [42065] Microsoft SharePoint Server 2.0 Rich Text Editor cross site scripting
14836| [41881] Microsoft Office 2003/2007/2007 Sp1/Xp memory corruption
14837| [41880] Microsoft Project 2000/2002/2003 memory corruption
14838| [41879] Microsoft Windows 2000/Server 2003/Vista Stack-based memory corruption
14839| [41878] Microsoft Windows 2000/Server 2003/Vista spoofing
14840| [41877] Microsoft Windows Server 2003 vbscript.dll memory corruption
14841| [3671] Microsoft Visio 2002/2003/2003 Sp3/2007/2007 Sp1 memory corruption
14842| [3670] Microsoft Visio 2002/2003/2003 Sp3/2007/2007 Sp1 Object memory corruption
14843| [41455] Microsoft Office 2000/2003/2004/Xp memory corruption
14844| [41454] Microsoft Excel 2000/2002/2003/2007 memory corruption
14845| [41453] Microsoft Excel 2000/2002/2003 memory corruption
14846| [41452] Microsoft Excel 2000/2002/2003/2007 memory corruption
14847| [41451] Microsoft Excel 2000/2002/2003 memory corruption
14848| [41450] Microsoft Excel 2000 memory corruption
14849| [41449] Microsoft Excel 2000/2002/2003 memory corruption
14850| [41448] Microsoft Office 2000/Xp Office Web Components memory corruption
14851| [3648] Microsoft Excel 2003 memory corruption
14852| [3647] Microsoft Outlook up to 2007 mailto URI memory corruption
14853| [41003] Microsoft Office 2000/2003/2004/Xp memory corruption
14854| [41002] Microsoft Office 2000/2003/Xp memory corruption
14855| [41001] Microsoft Works 2005/8.0 wkcvqd01.dll memory corruption
14856| [41000] Microsoft Works 2005/8.0 memory corruption
14857| [40998] Microsoft Publisher 2000/2002/2003 memory corruption
14858| [40994] Microsoft Works 2005/8.0 wkcvqd01.dll memory corruption
14859| [40987] Microsoft Windows 2000 denial of service
14860| [40736] Microsoft ActiveX 2.0 ActiveX Control privilege escalation
14861| [3552] Microsoft Excel 2000/2002/2003 File memory corruption
14862| [40242] Microsoft Publisher 2000/2002/2003/2007 Crash denial of service
14863| [40020] Microsoft Office 2007 ZIP Container unknown vulnerability
14864| [39769] Microsoft Windows 2000 cryptgenrandom weak encryption
14865| [39749] Microsoft Windows 2000 msjet40.dll memory corruption
14866| [39655] Microsoft Windows Server 2003 spoofing
14867| [39324] Microsoft Windows Mobile 2005 SMS unknown vulnerability
14868| [3373] Microsoft Word 2000/2002 memory corruption
14869| [38999] Microsoft Windows Server 2003 explorer.exe denial of service
14870| [38899] Microsoft ISA Server 2004 information disclosure
14871| [38728] Microsoft SQL Server 2005 Enterprise Manager sqldmo.dll memory corruption
14872| [38326] Microsoft Windows 2000 attemptwrite memory corruption
14873| [3241] Microsoft Excel 2000/2003/2004/XP SP3 rtWnDesk memory corruption
14874| [3223] Microsoft Windows Server 2003/XP URI privilege escalation
14875| [3212] Microsoft DirectX February 2006 RLE Compression Targa Files Heap-based memory corruption
14876| [37739] Microsoft Excel 2000/2002/2003/2004/2007 memory corruption
14877| [37738] Microsoft Office 2002/2003 memory corruption
14878| [3176] Microsoft Excel 2000/2002/2003/2007 File Attribute memory corruption
14879| [3175] Microsoft Excel 2000/2002/2003/2007 Active Worksheet memory corruption
14880| [3174] Microsoft Excel 2000/2002/2003/2007 Version Information memory corruption
14881| [3172] Microsoft Office Publisher 2007 Pointer memory corruption
14882| [37566] Microsoft Excel 2003 unknown vulnerability
14883| [37526] Microsoft Windows 2000/Server 2003 denial of service
14884| [37248] Microsoft Visio 2002 Packaging memory corruption
14885| [37251] Microsoft Windows 2000 memory corruption
14886| [3119] Microsoft Visio 2002 Object memory corruption
14887| [3118] Microsoft Visio 2002 Data memory corruption
14888| [37093] Microsoft Windows Server 2003 Error Message unknown vulnerability
14889| [37010] Microsoft Office 2000 ActiveX Control ouactrl.ocx memory corruption
14890| [36628] Microsoft Word 2000/2002/2003/2004 winword.exe memory corruption
14891| [36616] Microsoft Works 2004/2005/2006 memory corruption
14892| [36621] Microsoft Exchange Server 2000 Integer denial of service
14893| [36620] Microsoft Exchange Server 2000 Outlook Web Access cross site scripting
14894| [36619] Microsoft Exchange Server 2000/2003/2007 MIME Email memory corruption
14895| [36618] Microsoft Exchange Server 2000 NULL Pointer Dereference denial of service
14896| [36617] Microsoft Excel 2000/2002/2003/2004 memory corruption
14897| [36623] Microsoft BizTalk Server 2004 ActiveX Control capicom.dll memory corruption
14898| [3067] Microsoft Office 2000/2003/2004/2007/Xp Drawing Object memory corruption
14899| [3065] Microsoft Excel 2000/2002/2003/2007 Filter Stack-based memory corruption
14900| [3064] Microsoft Excel 2000/2002/2003/2004/2007 set Font memory corruption
14901| [3063] Microsoft Excel 2000/2002/2003/2007 BIFF Record Stack-based memory corruption
14902| [3012] Microsoft Windows 2000/Server 2003 DNS Service Stack-based memory corruption
14903| [36039] Microsoft Content Management Server 2001 memory corruption
14904| [36052] Microsoft Windows 2000 Heap-based memory corruption
14905| [36051] Microsoft Word 2007 file798-1.doc memory corruption
14906| [36050] Microsoft Word 2007 file789-1.doc memory corruption
14907| [36040] Microsoft Content Management Server 2001 cross site scripting
14908| [3004] Microsoft Windows up to 2003/XP URL Parser memory corruption
14909| [36041] Microsoft .NET Framework 2.0.50727.42 cross site scripting
14910| [36002] Microsoft Windows 2000/XP denial of service
14911| [2990] Microsoft Windows 2000/Vista/XP Animated Cursor Stack-based memory corruption
14912| [36515] Microsoft Windows 2000/Server 2003/XP memory corruption
14913| [35846] Microsoft Windows 2000/Server 2003 Default Configuration information disclosure
14914| [35373] Microsoft Excel 2003 denial of service
14915| [35372] Microsoft Office 2003 denial of service
14916| [35206] Microsoft Windows Server 2003/XP Crash denial of service
14917| [35161] Microsoft ISA Server 2004 unknown vulnerability
14918| [35236] Microsoft Publisher 2007 memory corruption
14919| [2939] Microsoft Word 2000 memory corruption
14920| [34994] Microsoft Windows 2000 OLE Dialog memory corruption
14921| [34993] Microsoft Office 2000/2003/Xp memory corruption
14922| [35001] Microsoft Office 2000/2003/2004/Xp memory corruption
14923| [35000] Microsoft Word 2000/2002/2003 memory corruption
14924| [2933] Microsoft Windows 2000 SP4/Server 2003 SP1/XP SP2 OLE Dialog Stack-based memory corruption
14925| [2894] Microsoft Office 2000/2003/2004/Xp Undefined String Format String
14926| [2884] Microsoft Word 2000/2002/2003 memory corruption
14927| [34321] Microsoft Office 2000/2003/2004/Xp Spreadsheet Heap-based memory corruption
14928| [34320] Microsoft Office 2000/2003/2004/Xp memory corruption
14929| [34319] Microsoft Office 2000/2003/2004/Xp memory corruption
14930| [34318] Microsoft Office 2000/2003/2004/Xp memory corruption
14931| [34322] Microsoft Office 2000/2003/Xp memory corruption
14932| [2811] Microsoft Windows 2000/Server 2003/XP VML Vector Markup Language Integer memory corruption
14933| [2810] Microsoft Outlook 2000/2002/2003 Office Saved Search OSS File memory corruption
14934| [2809] Microsoft Outlook 2000/2002/2003 Header denial of service
14935| [2808] Microsoft Outlook 2000/2002/2003 Meeting VEVENT memory corruption
14936| [2807] Microsoft Excel 2000/2002/2003 XLS File memory corruption
14937| [34126] Microsoft Office 2003 memory corruption
14938| [34122] Microsoft Office Web Components 2000 memory corruption
14939| [2789] Microsoft Windows 2000/XP RPC Request NetrWkstaUserEnum denial of service
14940| [2765] Microsoft Project Server 2003 pdsrequest.asp weak authentication
14941| [33851] Microsoft Word 2000/2002/2003 12122006-djtest.doc memory corruption
14942| [2739] Microsoft Windows 2000 Remote Installation Service Fehlende Authentifizierung
14943| [2738] Microsoft Windows 2000/Server 2003/XP SNMP memory corruption
14944| [2737] Microsoft Windows Server 2003/XP Manifest denial of service
14945| [33766] Microsoft Word 2000/2002/2003 memory corruption
14946| [2718] Microsoft Word 2000/2002/2003 DOC Document memory corruption
14947| [2717] Microsoft Windows 2000 Print Spooler Memory Consumption denial of service
14948| [2689] Microsoft Windows up to 2000 SP4 Active Directory denial of service
14949| [2688] Microsoft Windows 2000/Server 2003/XP Client Service for Netware denial of service
14950| [2687] Microsoft Windows 2000/Server 2003/XP Agent ActiveX ACF File Heap-based memory corruption
14951| [2686] Microsoft Windows 2000/Server 2003/XP Client Service for Netware memory corruption
14952| [2684] Microsoft Windows 2000/XP Workstation Service Stack-based memory corruption
14953| [2659] Microsoft Windows 2000/XP GDI Crash memory corruption
14954| [2655] Microsoft Windows 2000/Server 2003/XP XML Core Services memory corruption
14955| [33067] Microsoft Visual Studio .net 2005 ActiveX Control wmiscriptutils.dll memory corruption
14956| [2610] Microsoft PowerPoint 2003 PPT Document NULL Pointer Dereference denial of service
14957| [32693] Microsoft Word 2004 memory corruption
14958| [32686] Microsoft Office 2000/2001/2003/2004 Integer memory corruption
14959| [32690] Microsoft Office 2000/2003/2004/Xp memory corruption
14960| [32676] Microsoft Office 2000/2001/2003/2004 memory corruption
14961| [32675] Microsoft Office 2000/2003/2004/Xp memory corruption
14962| [32694] Microsoft Windows 2000 memory corruption
14963| [32689] Microsoft Excel 2000/2002/2003/2004/XP memory corruption
14964| [32688] Microsoft Excel 2000/2002/2003/2004/XP memory corruption
14965| [32687] Microsoft Word 2000/2002 memory corruption
14966| [32685] Microsoft Office 2000/2001/2003/2004 memory corruption
14967| [2601] Microsoft Windows Server 2003/XP IPv6 Stack denial of service
14968| [2600] Microsoft Windows Server 2003/XP IPv6 Stack TCP denial of service
14969| [2599] Microsoft Windows Server 2003/XP IPv6 Stack ICMP denial of service
14970| [2598] Microsoft Windows Server 2003/XP Object Packager privilege escalation
14971| [2597] Microsoft Office 2003/Xp Smart-Tag Parser memory corruption
14972| [2596] Microsoft Office 2000/2003/2004/Xp Value Read memory corruption
14973| [2595] Microsoft Office 2000/2001/2003/2004 Diagram Value memory corruption
14974| [2594] Microsoft Office 2000/2001/2003/2004 Document memory corruption
14975| [2593] Microsoft ASP.NET 2.0 cross site scripting
14976| [141652] Microsoft Windows up to Server 2019 Common Log File System Driver information disclosure
14977| [141639] Microsoft SharePoint Foundation 2013 SP1 cross site request forgery
14978| [141637] Microsoft Windows up to Server 2019 AppX Deployment Server privilege escalation
14979| [141636] Microsoft ASP.NET Core 2.1/2.2/3.0 Project Template privilege escalation
14980| [141635] Microsoft .NET Core 2.1/2.2 denial of service
14981| [141633] Microsoft Excel up to 2019 memory corruption
14982| [141631] Microsoft Windows up to Server 2019 SMB Client Driver information disclosure
14983| [141630] Microsoft Windows up to Server 2019 denial of service
14984| [141629] Microsoft Windows up to Server 2019 Update Delivery Optimization privilege escalation
14985| [141627] Microsoft Windows up to Server 2019 GDI information disclosure
14986| [141626] Microsoft Windows up to Server 2019 Win32k memory corruption
14987| [141621] Microsoft Windows up to Server 2019 Kernel information disclosure
14988| [141620] Microsoft Windows up to Server 2019 Active Directory Federation Services cross site scripting
14989| [141619] Microsoft Windows up to Server 2019 ALPC privilege escalation
14990| [141618] Microsoft Windows up to Server 2019 hdAudio.sys privilege escalation
14991| [141617] Microsoft Windows up to Server 2019 Store Installer privilege escalation
14992| [141616] Microsoft Windows up to Server 2019 ALPC privilege escalation
14993| [141615] Microsoft Windows up to Server 2019 Winlogon privilege escalation
14994| [141614] Microsoft Windows up to Server 2019 Compatibility Appraiser privilege escalation
14995| [141611] Microsoft Office up to 2019 Security Feature privilege escalation
14996| [141610] Microsoft Excel up to 2019 information disclosure
14997| [141609] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
14998| [141608] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site request forgery
14999| [141607] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016/2019 privilege escalation
15000| [141606] Microsoft Windows up to Server 2019 Win32k memory corruption
15001| [141605] Microsoft Windows up to Server 2019 Hyper-V information disclosure
15002| [141604] Microsoft Windows up to Server 2019 AppX Deployment Server privilege escalation
15003| [141603] Microsoft Windows up to Server 2019 GDI information disclosure
15004| [141602] Microsoft Windows up to Server 2019 DirectWrite information disclosure
15005| [141601] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15006| [141600] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15007| [141599] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15008| [141598] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15009| [141597] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15010| [141596] Microsoft Windows up to Server 2019 DirectWrite information disclosure
15011| [141595] Microsoft Windows up to Server 2019 DirectWrite information disclosure
15012| [141594] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15013| [141593] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15014| [141592] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15015| [141591] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15016| [141590] Microsoft Windows up to Server 2019 Text Service Framework command injection
15017| [141589] Microsoft Exchange Server 2016 CU12/2016 CU13/2019 CU1/2019 CU2 denial of service
15018| [141583] Microsoft Lync Server 2013 Conference directory traversal
15019| [141581] Microsoft Windows up to Server 2016 Hyper-V denial of service
15020| [141580] Microsoft Windows up to Server 2019 Transaction Manager information disclosure
15021| [141579] Microsoft Windows up to Server 2016 DirectX information disclosure
15022| [141577] Microsoft Windows up to Server 2019 Common Log File System Driver privilege escalation
15023| [141575] Microsoft Windows up to Server 2019 lnk File privilege escalation
15024| [141564] Microsoft SharePoint Enterprise Server 2010 SP1/2013 SP1/2016/2019 Markup Application Package privilege escalation
15025| [141561] Microsoft Windows up to Server 2019 Remote Desktop privilege escalation
15026| [141560] Microsoft Windows up to Server 2019 Remote Desktop privilege escalation
15027| [139972] Microsoft Windows up to Server 2019 HTTP2 HTTP.sys denial of service
15028| [139971] Microsoft Windows up to Server 2019 HTTP2 HTTP.sys denial of service
15029| [139970] Microsoft Windows up to Server 2019 HTTP2 HTTP.sys denial of service
15030| [139969] Microsoft Windows up to Server 2019 HTTP2 HTTP.sys denial of service
15031| [139968] Microsoft Windows up to Server 2019 HTTP2 HTTP.sys denial of service
15032| [139965] Microsoft Windows up to Server 2019 Kernel information disclosure
15033| [139963] Microsoft Windows up to Server 2019 Remote Desktop Protocol information disclosure
15034| [139962] Microsoft Windows up to Server 2019 Remote Desktop Protocol denial of service
15035| [139960] Microsoft Windows up to Server 2019 DHCP Server denial of service
15036| [139958] Microsoft Windows up to Server 2019 DHCP Server denial of service
15037| [139957] Microsoft SharePoint Server 2013 SP1/2016/2019 cross site scripting
15038| [139956] Microsoft SharePoint 2010 SP2/2013 SP1/2016/2019 Session Object information disclosure
15039| [139955] Microsoft Windows up to Server 2019 SyncController.dll privilege escalation
15040| [139949] Microsoft Windows up to Server 2019 XmlLite Runtime XmlLite.dll denial of service
15041| [139946] Microsoft Windows up to Server 2019 Core Shell COM Server Registrar COM Call privilege escalation
15042| [139942] Microsoft Windows up to Server 2019 rpcss.dll memory corruption
15043| [139941] Microsoft Windows up to Server 2019 DirectX memory corruption
15044| [139937] Microsoft Windows up to Server 2019 Azure Active Directory information disclosure
15045| [139936] Microsoft Windows up to Server 2019 SymCrypt information disclosure
15046| [139935] Microsoft Windows 10 1809/10 1903/Server 1903/Server 2019 NTFS privilege escalation
15047| [139934] Microsoft Windows 7 SP1/Server 2018 R2 SP1/Server 2018 SP2 Win32k memory corruption
15048| [139933] Microsoft Windows up to Server 2019 p2pimsvc privilege escalation
15049| [139932] Microsoft Windows up to Server 2019 Kernel memory corruption
15050| [139931] Microsoft Windows up to Server 2019 File Signature Security Feature CAB File privilege escalation
15051| [139930] Microsoft Windows up to Server 2019 ALPC privilege escalation
15052| [139928] Microsoft Windows up to Server 2019 Kernel memory corruption
15053| [139927] Microsoft Windows up to Server 2019 Graphics Component information disclosure
15054| [139926] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15055| [139925] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15056| [139924] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15057| [139922] Microsoft Windows up to Server 2019 Graphics Component information disclosure
15058| [139921] Microsoft Windows up to Server 2019 Graphics Component information disclosure
15059| [139920] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15060| [139919] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15061| [139918] Microsoft Windows up to Server 2019 Graphics Component information disclosure
15062| [139917] Microsoft Windows up to Server 2019 Graphics Component information disclosure
15063| [139916] Microsoft Windows up to Server 2019 XML Core Services MSXML Parser privilege escalation
15064| [139914] Microsoft Windows up to Server 2019 Hyper-V Network Switch denial of service
15065| [139913] Microsoft Windows up to Server 2019 Hyper-V Network Switch denial of service
15066| [139912] Microsoft Windows 10 1809/10 1903/Server 1903/Server 2019 Hyper-V Network Switch denial of service
15067| [139911] Microsoft Windows up to Server 2019 denial of service
15068| [139910] Microsoft Windows up to Server 2019 Hyper-V Network Switch denial of service
15069| [139909] Microsoft Windows up to Server 2019 Hyper-V Network Switch denial of service
15070| [139908] Microsoft Windows up to Server 2019 Bluetooth weak encryption
15071| [139907] Microsoft Windows up to Server 2019 Remote Desktop Service privilege escalation
15072| [139906] Microsoft Windows up to Server 2019 Remote Desktop Service privilege escalation
15073| [139902] Microsoft Word up to 2019 memory corruption
15074| [139901] Microsoft Outlook up to 2019 memory corruption
15075| [139895] Microsoft Windows up to Server 2019 lnk File privilege escalation
15076| [139894] Microsoft Windows up to Server 2019 VBScript Engine memory corruption
15077| [139893] Microsoft Windows up to Server 2019 Remote Desktop Service privilege escalation
15078| [139892] Microsoft Windows up to Server 2019 Remote Desktop Service privilege escalation
15079| [139891] Microsoft Windows up to Server 2019 Font Library memory corruption
15080| [139890] Microsoft Windows up to Server 2019 Font Library memory corruption
15081| [139889] Microsoft Windows up to Server 2019 Font Library memory corruption
15082| [139888] Microsoft Windows up to Server 2019 Font Library memory corruption
15083| [139887] Microsoft Windows up to Server 2019 Font Library memory corruption
15084| [139886] Microsoft Windows up to Server 2019 Font Library memory corruption
15085| [139880] Microsoft Windows up to Server 2019 Hyper-V memory corruption
15086| [139879] Microsoft Windows up to Server 2019 DHCP Client memory corruption
15087| [139878] Microsoft Windows up to Server 2019 Hyper-V Network Switch memory corruption
15088| [139877] Microsoft Outlook up to 2019 memory corruption
15089| [139876] Microsoft Windows up to Server 2019 Remote Desktop Service privilege escalation
15090| [139875] Microsoft Windows up to Server 2019 Remote Desktop Service privilege escalation
15091| [137590] Microsoft ASP.NET Core 2.1/2.2 Open Redirect
15092| [137589] Microsoft Exchange Server 2013 CU23/2016 CU12/2016 CU13/2019 CU1/2019 CU2 cross site scripting
15093| [137588] Microsoft Exchange Server 2010 SP3/2013 CU23/2016 CU12/2016 CU13 Web Services privilege escalation
15094| [137587] Microsoft SharePoint Server 2013 SP1/2016/2019 cross site scripting
15095| [137586] Microsoft Windows up to Server 2019 AppX Deployment Service privilege escalation
15096| [137585] Microsoft Windows up to Server 2019 AppX Deployment Service privilege escalation
15097| [137584] Microsoft Windows up to Server 2019 DirectWrite memory corruption
15098| [137583] Microsoft Windows up to Server 2019 DirectWrite memory corruption
15099| [137581] Microsoft Windows up to Server 2019 DirectWrite memory corruption
15100| [137580] Microsoft Windows up to Server 2019 DirectWrite memory corruption
15101| [137579] Microsoft Windows up to Server 2019 DirectWrite memory corruption
15102| [137578] Microsoft Windows up to Server 2019 DirectWrite memory corruption
15103| [137577] Microsoft Windows up to Server 2019 DirectWrite memory corruption
15104| [137576] Microsoft Windows up to Server 2019 DirectWrite memory corruption
15105| [137575] Microsoft Windows up to Server 2019 DirectWrite memory corruption
15106| [137574] Microsoft Windows up to Server 2019 DirectWrite memory corruption
15107| [137568] Microsoft Windows up to Server 2019 Remote Desktop Protocol information disclosure
15108| [137563] Microsoft Windows up to Server 2019 DirectWrite information disclosure
15109| [137562] Microsoft Windows up to Server 2019 Win32k information disclosure
15110| [137561] Microsoft Windows up to Server 2019 GDI information disclosure
15111| [137560] Microsoft Windows up to Server 2019 GDI information disclosure
15112| [137559] Microsoft Windows up to Server 2019 DirectWrite information disclosure
15113| [137555] Microsoft Windows up to Server 2019 Audio Service privilege escalation
15114| [137554] Microsoft Windows up to Server 2019 Audio Service privilege escalation
15115| [137553] Microsoft Windows up to Server 2019 Audio Service privilege escalation
15116| [137549] Microsoft Windows up to Server 2016 DLL privilege escalation
15117| [137544] Microsoft Windows up to Server 2019 Kernel information disclosure
15118| [137543] Microsoft Windows up to Server 2019 Kernel information disclosure
15119| [137542] Microsoft SQL Server 2014 SP2/2016 SP1/2017 privilege escalation
15120| [137541] Microsoft Windows up to Server 2019 memory corruption
15121| [137540] Microsoft Windows up to Server 2019 Error Reporting privilege escalation
15122| [137539] Microsoft Windows up to Server 2016 DirectX memory corruption
15123| [137538] Microsoft Windows Server 1803/Server 1903/Server 2016/Server 2019 ADFS Security Feature privilege escalation
15124| [137537] Microsoft Windows up to Server 2019 Hyper-V denial of service
15125| [137535] Microsoft Windows up to Server 2019 Remote Desktop Service privilege escalation
15126| [137533] Microsoft Windows up to Server 2019 SymCrypt denial of service
15127| [137527] Microsoft Windows up to Server 2019 GDI+ memory corruption
15128| [137512] Microsoft Windows up to Server 2019 DHCP memory corruption
15129| [136414] Microsoft Azure DevOps Server 2019 cross site request forgery
15130| [136349] Microsoft Windows up to Server 2019 Event Viewer eventvwr.msc XML External Entity
15131| [136348] Microsoft Windows up to Server 2019 Task Scheduler privilege escalation
15132| [136347] Microsoft Windows up to Server 2019 AppXSVC privilege escalation
15133| [136345] Microsoft Windows up to Server 2019 Windows Shell privilege escalation
15134| [136344] Microsoft Windows up to Server 2019 GDI information disclosure
15135| [136340] Microsoft Windows up to Server 2019 GDI information disclosure
15136| [136337] Microsoft Windows up to Server 2019 Comctl32.dll memory corruption
15137| [136336] Microsoft Windows up to Server 2019 Kernel privilege escalation
15138| [136335] Microsoft Windows up to Server 2019 NTLM Downgrade weak authentication
15139| [136334] Microsoft Windows up to Server 2019 Kernel information disclosure
15140| [136333] Microsoft SharePoint Server 2010 SP2/2013 SP1/2016/2019 cross site scripting
15141| [136330] Microsoft SharePoint Server 2010 SP2/2013 SP1/2016/2019 cross site scripting
15142| [136329] Microsoft SharePoint Server 2016/2019 cross site scripting
15143| [136328] Microsoft SharePoint Server 2010 SP2/2013 SP1/2016/2019 cross site scripting
15144| [136327] Microsoft Lync Server 2010/2013 denial of service
15145| [136326] Microsoft Windows up to Server 2019 Audio Service privilege escalation
15146| [136325] Microsoft Windows up to Server 2019 Audio Service privilege escalation
15147| [136324] Microsoft Windows up to Server 2019 Audio Service privilege escalation
15148| [136323] Microsoft Windows up to Server 2019 denial of service
15149| [136321] Microsoft Windows 10 1809/10 1903/Server 1903/Server 2019 Audio Service privilege escalation
15150| [136320] Microsoft Windows up to Server 2019 Audio Service privilege escalation
15151| [136319] Microsoft Windows up to Server 2019 Security Credentials information disclosure
15152| [136318] Microsoft Windows up to Server 2019 DirectX privilege escalation
15153| [136317] Microsoft Windows up to Server 2019 Win32k memory corruption
15154| [136314] Microsoft Windows up to Server 2019 Win32k memory corruption
15155| [136312] Microsoft Windows up to Server 2019 GDI information disclosure
15156| [136310] Microsoft Windows up to Server 2019 GDI information disclosure
15157| [136308] Microsoft Windows up to Server 2019 Audio Service privilege escalation
15158| [136306] Microsoft Windows up to Server 2019 Storage Service privilege escalation
15159| [136305] Microsoft Windows up to Server 2019 User Profile Service privilege escalation
15160| [136304] Microsoft Windows up to Server 2019 Common Log File System Driver privilege escalation
15161| [136303] Microsoft Windows up to Server 2019 Storage Service privilege escalation
15162| [136301] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15163| [136299] Microsoft Windows up to Server 2019 Local Security Authority Subsystem Service Reboot denial of service
15164| [136296] Microsoft Windows up to Server 2019 Common Log File System Driver memory corruption
15165| [136295] Microsoft Windows up to Server 2019 ALPC privilege escalation
15166| [136293] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15167| [136292] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15168| [136291] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15169| [136290] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15170| [136289] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15171| [136288] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15172| [136287] Microsoft Windows up to Server 2019 Hyper-V denial of service
15173| [136286] Microsoft Windows up to Server 2019 Hyper-V denial of service
15174| [136285] Microsoft Windows up to Server 2019 Hyper-V denial of service
15175| [136284] Microsoft Windows up to Server 2019 Kernel memory corruption
15176| [136276] Microsoft Windows up to Server 2019 Hyper-V memory corruption
15177| [136275] Microsoft Windows 10/10 1607/10 1703/10 1709/Server 2016 Hyper-V memory corruption
15178| [136274] Microsoft Windows up to Server 2019 ActiveX memory corruption
15179| [136273] Microsoft Windows up to Server 2019 Hyper-V memory corruption
15180| [134750] Microsoft ASP.NET Core 2.1/2.2 denial of service
15181| [134745] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
15182| [134744] Microsoft Windows up to Server 2019 GDI information disclosure
15183| [134743] Microsoft SharePoint Server 2013 SP1/2016 cross site scripting
15184| [134742] Microsoft SharePoint Enterprise Server 2016/2019 cross site scripting
15185| [134741] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
15186| [134740] Microsoft SharePoint Enterprise Server 2013 SP1/2016 privilege escalation
15187| [134739] Microsoft SharePoint Foundation 2010 SP2/2013 SP2 cross site scripting
15188| [134738] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
15189| [134737] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
15190| [134736] Microsoft Office 2010 SP2 Access Connectivity Engine memory corruption
15191| [134735] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
15192| [134734] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
15193| [134733] Microsoft Windows up to Server 2019 Unified Write Filter privilege escalation
15194| [134731] Microsoft Windows up to Server 2019 Symlink privilege escalation
15195| [134729] Microsoft Windows up to Server 2019 Storage Service privilege escalation
15196| [134725] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15197| [134724] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15198| [134723] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15199| [134722] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15200| [134721] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15201| [134720] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15202| [134719] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15203| [134718] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15204| [134717] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15205| [134716] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15206| [134715] Microsoft Windows up to Server 2019 Win32k memory corruption
15207| [134714] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15208| [134713] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15209| [134712] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15210| [134710] Microsoft Windows up to Server 2019 GDI information disclosure
15211| [134709] Microsoft Windows up to Server 2019 Kernel privilege escalation
15212| [134706] Microsoft Windows up to Server 2019 Error Reporting privilege escalation
15213| [134701] Microsoft Windows up to Server 2019 Windows Defender Application Control privilege escalation
15214| [134700] Microsoft Windows up to Server 2019 Diagnostic Hub privilege escalation
15215| [134699] Microsoft Windows up to Server 2019 NDIS ndis.sys memory corruption
15216| [134698] Microsoft Windows up to Server 2019 OLE memory corruption
15217| [134684] Microsoft Windows up to Server 2019 DHCP Server memory corruption
15218| [134678] Microsoft Windows up to Server 2019 GDI+ memory corruption
15219| [133236] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15220| [133234] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15221| [133232] Microsoft Azure DevOps Server 2019 cross site scripting
15222| [133229] Microsoft Azure DevOps Server 2019 cross site scripting
15223| [133224] Microsoft Exchange Server 2013 CU22/2016 CU11/2016 CU12/2019/2019 CU1 Outlook Web Access privilege escalation
15224| [133223] Microsoft Azure DevOps Server 2019 Content Security Policy privilege escalation
15225| [133222] Microsoft Windows up to Server 2019 Remote Registry Service memory corruption
15226| [133221] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15227| [133220] Microsoft Windows up to Server 2019 GDI Memory information disclosure
15228| [133219] Microsoft Windows up to Server 2019 Win32k Memory information disclosure
15229| [133218] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15230| [133217] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15231| [133216] Microsoft Windows up to Server 2019 Kernel Memory information disclosure
15232| [133215] Microsoft Windows up to Server 2019 VBScript Engine memory corruption
15233| [133214] Microsoft Windows up to Server 2019 AppX Deployment Service privilege escalation
15234| [133213] Microsoft Windows up to Server 2019 Kernel Memory information disclosure
15235| [133212] Microsoft Windows up to Server 2019 Terminal Services Memory information disclosure
15236| [133211] Microsoft Windows up to Server 2019 Task Scheduler information disclosure
15237| [133209] Microsoft Windows up to Server 2019 LUAFV Driver luafv.sys privilege escalation
15238| [133206] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016/2019 cross site scripting
15239| [133205] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site scripting
15240| [133204] Microsoft Office/Excel up to 2019 memory corruption
15241| [133203] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
15242| [133202] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
15243| [133201] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
15244| [133200] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
15245| [133199] Microsoft Office 2010 SP2 Access Connectivity Engine memory corruption
15246| [133198] Microsoft Exchange Server up to 2019 CU1 Outlook Web Access cross site scripting
15247| [133197] Microsoft ASP.NET Core 2.2 Request denial of service
15248| [133196] Microsoft Windows up to Server 2019 Win32k information disclosure
15249| [133195] Microsoft Windows up to Server 2019 LUAFV Driver luafv.sys privilege escalation
15250| [133194] Microsoft Windows up to Server 2019 GDI Memory information disclosure
15251| [133193] Microsoft Windows up to Server 2019 LUAFV Driver luafv.sys privilege escalation
15252| [133192] Microsoft Windows up to Server 2019 OLE Automation privilege escalation
15253| [133189] Microsoft Windows up to Server 2019 CSRSS memory corruption
15254| [133188] Microsoft Windows up to Server 2019 LUAFV Driver luafv.sys privilege escalation
15255| [133187] Microsoft Windows up to Server 2019 LUAFV Driver luafv.sys privilege escalation
15256| [133186] Microsoft Windows up to Server 2019 TCP/IP Stack Fragmented IP Packet information disclosure
15257| [133185] Microsoft Windows up to Server 2019 Win32k memory corruption
15258| [133183] Microsoft Windows up to Server 2019 Win32k memory corruption
15259| [133182] Microsoft Windows up to Server 2019 Win32k memory corruption
15260| [133181] Microsoft Office/Excel/PowerPoint up to 2019 URL Document Code Execution
15261| [133180] Microsoft Windows up to Server 2019 MS XML Code Execution
15262| [133179] Microsoft Windows up to Server 2019 MS XML Code Execution
15263| [133177] Microsoft Windows up to Server 2019 Device Guard luafv.sys privilege escalation
15264| [133174] Microsoft Windows up to Server 2019 GDI+ privilege escalation
15265| [133173] Microsoft Windows up to Server 2019 IOleCvt Interface privilege escalation
15266| [133166] Microsoft Windows up to Server 2019 MS XML Code Execution
15267| [133165] Microsoft Windows up to Server 2019 MS XML Code Execution
15268| [133164] Microsoft Windows up to Server 2019 MS XML Code Execution
15269| [133163] Microsoft Windows up to Server 2019 MS XML Code Execution
15270| [133162] Microsoft Windows up to Server 2019 MS XML Code Execution
15271| [131687] Microsoft Team Foundation Server 2017 Update 3.1/2018 Update 3.2/2018 Updated 1.2 cross site scripting
15272| [131685] Microsoft Windows up to Server 2019 SMB information disclosure
15273| [131684] Microsoft Visual Studio 2017 Version 15.9 C++ Redistributable Installer privilege escalation
15274| [131681] Microsoft Windows up to Server 2019 Win32k memory corruption
15275| [131679] Microsoft Windows up to Server 2019 Kernel information disclosure
15276| [131675] Microsoft SharePoint 2013 SP1/2016 cross site scripting
15277| [131674] Microsoft Windows up to Server 2019 Win32k information disclosure
15278| [131673] Microsoft Windows up to Server 2019 Kernel information disclosure
15279| [131672] Microsoft Windows up to Server 2019 GDI information disclosure
15280| [131671] Microsoft Windows up to Server 2019 VBScript Engine memory corruption
15281| [131668] Microsoft Windows up to Server 2019 AppX Deployment Server privilege escalation
15282| [131667] Microsoft Windows up to Server 2019 Comctl32.dll memory corruption
15283| [131663] Microsoft Windows up to Server 2019 Print Spooler information disclosure
15284| [131658] Microsoft Windows up to Server 2019 information disclosure
15285| [131657] Microsoft Windows up to Server 2019 denial of service
15286| [131656] Microsoft Office 2010 SP2 Connectivity Engine memory corruption
15287| [131653] Microsoft Windows up to Server 2019 SMB information disclosure
15288| [131652] Microsoft Windows up to Server 2019 SMB information disclosure
15289| [131651] Microsoft Windows up to Server 2019 Kernel information disclosure
15290| [131650] Microsoft Windows 10 1803/10 1809/Server 1803/Server 2019 Hyper-V denial of service
15291| [131649] Microsoft Windows up to Server 2019 Kernel memory corruption
15292| [131648] Microsoft Windows up to Server 2019 Hyper-V denial of service
15293| [131644] Microsoft Windows up to Server 2019 Hyper-V denial of service
15294| [131638] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15295| [131632] Microsoft Windows 10 1803/10 1809/Server 1803/Server 2019 DHCP Client memory corruption
15296| [131631] Microsoft Windows 10 1803/10 1809/Server 1803/Server 2019 DHCP Client memory corruption
15297| [131630] Microsoft Windows 10 1803/10 1809/Server 1803/Server 2019 DHCP Client memory corruption
15298| [131629] Microsoft Windows up to Server 2019 Deployment Services TFTP Server memory corruption
15299| [131628] Microsoft Windows up to Server 2019 ActiveX memory corruption
15300| [131619] Microsoft Windows up to Server 2019 MS XML privilege escalation
15301| [131334] Microsoft Team Foundation Server 2018 Update 3.2 cross site scripting
15302| [131333] Microsoft Team Foundation Server 2018 Update 3.2 cross site scripting
15303| [131328] Microsoft Windows up to Server 2016 Kernel information disclosure
15304| [130832] Microsoft 2013 SP1 spoofing
15305| [130828] Microsoft Exchange Server 2010 SP3/2013 CU22/2016 CU12/2019 CU1 EWS privilege escalation
15306| [130826] Microsoft Office 2010 SP2 Connectivity Engine memory corruption
15307| [130825] Microsoft Office up to 2019 Connectivity Engine memory corruption
15308| [130824] Microsoft Office up to 2019 Connectivity Engine memory corruption
15309| [130823] Microsoft Office up to 2019 Connectivity Engine privilege escalation
15310| [130822] Microsoft Office up to 2019 Connectivity Engine privilege escalation
15311| [130821] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
15312| [130820] Microsoft Windows up to Server 2012 R2 GDI information disclosure
15313| [130818] Microsoft Windows up to Server 2019 GDI information disclosure
15314| [130817] Microsoft Windows up to Server 2019 Storage Service privilege escalation
15315| [130814] Microsoft Windows up to Server 2019 privilege escalation
15316| [130809] Microsoft Windows up to Server 2019 Defender Firewall Security privilege escalation
15317| [130808] Microsoft Windows up to Server 2019 information disclosure
15318| [130807] Microsoft Windows up to Server 2019 Hyper-V information disclosure
15319| [130806] Microsoft Windows up to Server 2019 SMB privilege escalation
15320| [130805] Microsoft Windows up to Server 2019 Device Guard privilege escalation
15321| [130804] Microsoft Windows up to Server 2019 Device Guard privilege escalation
15322| [130803] Microsoft Windows up to Server 2019 SMB privilege escalation
15323| [130802] Microsoft Windows up to Server 2019 Win32k information disclosure
15324| [130801] Microsoft Windows up to Server 2019 Device Guard privilege escalation
15325| [130800] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15326| [130799] Microsoft Windows up to Server 2016 Win32k memory corruption
15327| [130798] Microsoft Windows up to Server 2019 GDI information disclosure
15328| [130797] Microsoft Windows up to Server 2019 GDI information disclosure
15329| [130796] Microsoft Windows up to Server 2019 GDI information disclosure
15330| [130793] Microsoft Windows up to Server 2019 GDI information disclosure
15331| [130792] Microsoft Windows up to Server 2019 HID information disclosure
15332| [130791] Microsoft Windows up to Server 2019 HID information disclosure
15333| [130790] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15334| [130789] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15335| [130788] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15336| [130787] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15337| [130786] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15338| [130784] Microsoft Windows up to Server 2019 GDI+ memory corruption
15339| [130782] Microsoft Windows up to Server 2019 DHCP Server memory corruption
15340| [130781] Microsoft Windows up to Server 2019 GDI+ memory corruption
15341| [129847] Microsoft Team Foundation Server 2017 Update 3.1/2018 Update 1.2/2018 Update 3.2 information disclosure
15342| [129846] Microsoft Team Foundation Server 2018 Update 3.2 cross site scripting
15343| [129845] Microsoft Skype for Business 2015 CU 8 Request cross site scripting
15344| [128765] Microsoft Visual Studio 2017 Version 15.9 C++ Construct privilege escalation
15345| [128764] Microsoft Exchange Server 2010 SP3/2013 CU21/2016 CU10/2016 CU11/2019 PowerShell API information disclosure
15346| [128761] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
15347| [128760] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
15348| [128759] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
15349| [128758] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
15350| [128757] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
15351| [128756] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
15352| [128755] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
15353| [128754] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
15354| [128753] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
15355| [128752] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
15356| [128751] Microsoft Windows up to Server 2019 Data Sharing Service privilege escalation
15357| [128750] Microsoft Windows up to Server 2019 Runtime privilege escalation
15358| [128749] Microsoft Windows up to Server 2019 Kernel information disclosure
15359| [128747] Microsoft ASP.NET Core 2.1 Web Request denial of service
15360| [128746] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site scripting
15361| [128745] Microsoft Office up to 2019 Word Macro information disclosure
15362| [128742] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site scripting
15363| [128741] Microsoft SharePoint Enterprise Server 2016 cross site scripting
15364| [128740] Microsoft SharePoint Enterprise Server 2013 SP1 cross site scripting
15365| [128739] Microsoft Windows up to Server 2019 Kernel information disclosure
15366| [128738] Microsoft Windows up to Server 2019 Subsystem for Linux information disclosure
15367| [128737] Microsoft Windows up to Server 2019 COM Desktop Broker privilege escalation
15368| [128736] Microsoft Windows up to Server 2019 Kernel information disclosure
15369| [128735] Microsoft ASP.NET Core 2.1/2.2 Web Request denial of service
15370| [128733] Microsoft Windows up to Server 2019 Authentication Request privilege escalation
15371| [128729] Microsoft Visual Studio 2010 SP1/2012 Update 5 vscontent File information disclosure
15372| [128728] Microsoft Windows up to Server 2019 Kernel information disclosure
15373| [128727] Microsoft Windows up to Server 2019 Data Sharing Service privilege escalation
15374| [128726] Microsoft Windows up to Server 2019 Data Sharing Service privilege escalation
15375| [128725] Microsoft Windows up to Server 2019 Data Sharing Service privilege escalation
15376| [128718] Microsoft Windows up to Server 2019 Hyper-V memory corruption
15377| [128717] Microsoft Windows 10 1803/10 1809/Server 1803/Server 2019 Hyper-V memory corruption
15378| [127925] Microsoft SharePoint Enterprise Server 2016 Web Request cross site scripting
15379| [127882] Microsoft Dynamics NAV 2016/2017 Web Request cross site scripting
15380| [127881] Microsoft Windows 10 1809/Server 2019 Object denial of service
15381| [127880] Microsoft Windows up to Server 2019 Win32k Object memory corruption
15382| [127828] Microsoft Windows up to Server 2019 Win32k memory corruption
15383| [127827] Microsoft Windows 10 1809/Server 2019 DirectX information disclosure
15384| [127826] Microsoft Windows 10 1803/10 1809/Server 1803/Server 2019 Win32k ASLR privilege escalation
15385| [127825] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016 privilege escalation
15386| [127824] Microsoft Excel up to 2019 Out-of-Bounds memory corruption
15387| [127823] Microsoft Windows up to Server 2012 R2 Kernel information disclosure
15388| [127821] Microsoft Windows up to Server 2019 Connected User Experiences and Telemetry Service denial of service
15389| [127820] Microsoft Windows up to Server 2019 Kernel memory corruption
15390| [127819] Microsoft Exchange Server 2016 CU10/2016 CU11 Profile Data privilege escalation
15391| [127817] Microsoft Excel up to 2019 information disclosure
15392| [127816] Microsoft Windows up to Server 2019 GDI information disclosure
15393| [127815] Microsoft Windows up to Server 2019 GDI information disclosure
15394| [127814] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016 Search cross site request forgery
15395| [127812] Microsoft Windows up to Server 2019 Remote Procedure Call information disclosure
15396| [127806] Microsoft Outlook up to 2019 memory corruption
15397| [127805] Microsoft Excel up to 2019 memory corruption
15398| [127804] Microsoft Excel up to 2019 memory corruption
15399| [127803] Microsoft Windows up to Server 2019 Text-To-Speech memory corruption
15400| [127801] Microsoft Windows up to Server 2019 DNS Server privilege escalation
15401| [126938] Microsoft Team Foundation Server 2018 Update 1.1/2018 Update 3 Code Execution
15402| [126755] Microsoft .NET Core 2.1 privilege escalation
15403| [126754] Microsoft Skype for Business/Lync Server 2013 SP1/2016 Emoji denial of service
15404| [126750] Microsoft Windows up to Server 2019 ALPC privilege escalation
15405| [126749] Microsoft Exchange Server 2010/2013/2016/2019 privilege escalation
15406| [126747] Microsoft SharePoint Enterprise Server 2013 SP1 Folder information disclosure
15407| [126746] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
15408| [126745] Microsoft Project 2010 SP2/2013 SP1/2016 memory corruption
15409| [126744] Microsoft Office up to 2019 Word memory corruption
15410| [126743] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site scripting
15411| [126742] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site scripting
15412| [126739] Microsoft Windows up to Server 2012 R2 Win32k information disclosure
15413| [126737] Microsoft Windows up to Server 2012 R2 DirectX information disclosure
15414| [126736] Microsoft Windows up to Server 2019 Win32k memory corruption
15415| [126735] Microsoft Windows up to Server 2019 DirectX privilege escalation
15416| [126733] Microsoft Windows 10 1803/10 1809/Server 1803/Server 2019 DirectX memory corruption
15417| [126730] Microsoft Windows up to Server 2019 Active Directory Federation Services cross site scripting
15418| [126728] Microsoft Office/SharePoint 2010 SP2 Word memory corruption
15419| [126727] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
15420| [126726] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
15421| [126725] Microsoft Windows up to Server 2019 DirectX memory corruption
15422| [126722] Microsoft Windows up to Server 2019 PowerShell privilege escalation
15423| [126718] Microsoft Windows up to Server 2016 Search memory corruption
15424| [126717] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016/2019 memory corruption
15425| [126716] Microsoft Office up to 2019 Excel memory corruption
15426| [126714] Microsoft Windows up to Server 2019 PowerShell unknown vulnerability
15427| [126713] Microsoft Windows up to Server 2019 VBScript Engine memory corruption
15428| [126712] Microsoft Windows up to Server 2016 Graphics Component memory corruption
15429| [126711] Microsoft Windows up to Server 2019 Deployment Services TFTP Server memory corruption
15430| [125123] Microsoft Windows up to Server 2019 Codecs Library information disclosure
15431| [125122] Microsoft Windows up to Server 2016 TCP/IP information disclosure
15432| [125121] Microsoft Windows up to Server 2019 DirectX memory corruption
15433| [125120] Microsoft Windows up to Server 2019 Windows Media Player information disclosure
15434| [125119] Microsoft Windows up to Server 2019 Windows Media Player information disclosure
15435| [125116] Microsoft Exchange Server 2013 CU21/2016 CU10 privilege escalation
15436| [125115] Microsoft Windows up to Server 2019 Theme API privilege escalation
15437| [125114] Microsoft Windows up to Server 2019 Windows Shell privilege escalation
15438| [125113] Microsoft Windows up to Server 2019 Kernel memory corruption
15439| [125111] Microsoft Windows up to Server 2019 Device Guard Code Integrity Policy privilege escalation
15440| [125110] Microsoft Windows up to Server 2019 DNS Global Blocklist privilege escalation
15441| [125109] Microsoft Windows up to Server 2019 NTFS privilege escalation
15442| [125108] Microsoft Windows up to Server 2019 Filter Manager memory corruption
15443| [125107] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
15444| [125106] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
15445| [125105] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
15446| [125104] Microsoft SharePoint Enterprise Server 2016 cross site scripting
15447| [125102] Microsoft Office/Word 2010 SP2/2013 RT SP1/2013 SP1/2016/2019 Protected View memory corruption
15448| [125100] Microsoft Office/PowerPoint 2010 SP2/2013 RT SP1/2013 SP1/2016/2019 Protected View memory corruption
15449| [125099] Microsoft Office/Excel up to 2019 Protected View memory corruption
15450| [125098] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
15451| [125097] Microsoft Windows up to Server 2019 DirectX Graphics memory corruption
15452| [125096] Microsoft Windows up to Server 2019 Win32k memory corruption
15453| [125095] Microsoft Exchange Server 2013 CU21/2016 CU10 Outlook Web Access cross site scripting
15454| [125093] Microsoft Windows up to Server 2019 Hyper-V memory corruption
15455| [125092] Microsoft Windows up to Server 2019 Hyper-V memory corruption
15456| [125091] Microsoft Windows up to Server 2019 MS XML privilege escalation
15457| [124371] Microsoft Exchange Server up to 2010 SP3 Outlook Web Access /owa/auth/logon.aspx Parameter Server-Side Request Forgery
15458| [124217] Microsoft Windows Server 2012/Server 2016 Active Directory Federation Services /adfs/ls Server-Side Request Forgery
15459| [123995] Microsoft Lync 2011 on Mac Security Feature Messages Download privilege escalation
15460| [123881] Microsoft Windows up to Server 2016 Sandbox privilege escalation
15461| [123874] Microsoft Windows up to Server 2016 Kernel information disclosure
15462| [123872] Microsoft Windows 8.1/10/RT 8.1/Server 2012/Server 2012 R2 SMB information disclosure
15463| [123868] Microsoft Windows up to Server 2016 Hyper-V denial of service
15464| [123864] Microsoft Windows up to Server 2016 Hyper-V information disclosure
15465| [123862] Microsoft SharePoint Enterprise Server 2010 SP2/2013 RT SP1/2013 SP1/2016 cross site scripting
15466| [123861] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R information disclosure
15467| [123860] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
15468| [123859] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016 cross site scripting
15469| [123851] Microsoft Windows up to Server 2016 ALPC privilege escalation
15470| [123849] Microsoft Windows up to Server 2016 SMB denial of service
15471| [123846] Microsoft Office 2016 on Win/Mac memory corruption
15472| [123844] Microsoft Word 2013 RT SP1/2013 SP1/2016 PDF File memory corruption
15473| [123843] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
15474| [123842] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
15475| [123830] Microsoft Windows up to Server 2016 Hyper-V memory corruption
15476| [123828] Microsoft Windows up to Server 2016 Win32k Graphics privilege escalation
15477| [123827] Microsoft Windows up to Server 2016 Image memory corruption
15478| [123825] Microsoft Windows up to Server 2016 MSXML Parser privilege escalation
15479| [123823] Microsoft Windows up to Server 2016 Hyper-V privilege escalation
15480| [122887] Microsoft Office 2016 on Mac AutoUpdate memory corruption
15481| [122886] Microsoft Windows up to Server 2016 DirectX Graphics memory corruption
15482| [122885] Microsoft Windows up to Server 2016 DirectX Graphics memory corruption
15483| [122884] Microsoft Windows up to Server 2016 Win32k memory corruption
15484| [122883] Microsoft Windows up to Server 2016 DirectX Graphics memory corruption
15485| [122875] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R information disclosure
15486| [122874] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
15487| [122873] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R information disclosure
15488| [122871] Microsoft PowerPoint 2010 SP2 memory corruption
15489| [122870] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
15490| [122861] Microsoft Windows up to Server 2016 Microsoft COM for Windows privilege escalation
15491| [122850] Microsoft Visual Studio 2015 Update 3/2017/2017 Version 15.8 Diagnostic Hub privilege escalation
15492| [122849] Microsoft Windows up to Server 2016 Diagnostic Hub privilege escalation
15493| [122848] Microsoft Windows Security Feature 2FA weak authentication
15494| [122834] Microsoft Windows up to Server 2016 LNK memory corruption
15495| [122825] Microsoft Windows up to Server 2016 Graphics memory corruption
15496| [122823] Microsoft SQL Server 2016 SP1/2016 SP2/2017 memory corruption
15497| [121208] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R Attachment privilege escalation
15498| [121118] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
15499| [121116] Microsoft Windows up to Server 2016 Sandbox privilege escalation
15500| [121114] Microsoft Access 2013 SP1/2016/2016 C2R memory corruption
15501| [121111] Microsoft Windows up to Server 2016 Kernel memory corruption
15502| [121110] Microsoft Windows up to Server 2016 Wordpad privilege escalation
15503| [121107] Microsoft Windows up to Server 2016 DNSAPI DNSAPI.dll denial of service
15504| [121106] Microsoft SharePoint Enterprise Server 2013 SP1/2016 privilege escalation
15505| [121105] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
15506| [121098] Microsoft Office 2016/2016 C2R memory corruption
15507| [121092] Microsoft Windows up to Server 2016 FTP Server denial of service
15508| [121090] Microsoft Visual Studio up to 2017 Version 15.8 Preview privilege escalation
15509| [119479] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
15510| [119477] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016 information disclosure
15511| [119476] Microsoft Publisher 2010 SP2 OLE Object PUB File privilege escalation
15512| [119475] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016 Attachment privilege escalation
15513| [119474] Microsoft Windows up to Server 2016 GDI information disclosure
15514| [119470] Microsoft Windows up to Server 2016 HTTP HTTP.sys denial of service
15515| [119468] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
15516| [119467] Microsoft Windows up to Server 2016 Hypervisor privilege escalation
15517| [119465] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
15518| [119464] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
15519| [119463] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
15520| [119461] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
15521| [119460] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
15522| [119459] Microsoft Windows up to Server 2016 memory corruption
15523| [119457] Microsoft Windows up to Server 2016 Desktop Bridge privilege escalation
15524| [119456] Microsoft Windows up to Server 2016 Kernel information disclosure
15525| [119455] Microsoft Windows up to Server 2016 denial of service
15526| [119454] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
15527| [119452] Microsoft Windows up to Server 2016 HIDParser memory corruption
15528| [119448] Microsoft Windows up to Server 2016 Code Integrity Module denial of service
15529| [119447] Microsoft Windows up to Server 2016 NTFS privilege escalation
15530| [119441] Microsoft Windows up to Server 2016 Media Foundation memory corruption
15531| [119437] Microsoft Windows up to Server 2016 HTTP Protocol Stack Http.sys memory corruption
15532| [119436] Microsoft Windows up to Server 2016 memory corruption
15533| [119431] Microsoft Windows up to Server 2016 DNSAPI DNSAPI.dll DNS Response privilege escalation
15534| [118120] Microsoft Office 2016 on Mac XML Data Code Execution
15535| [117561] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1 Web Request cross site scripting
15536| [117560] Microsoft Exchange Server up to 2016 CU9 Code Execution memory corruption
15537| [117559] Microsoft Exchange Server 2016 CU8/2016 CU9 Outlook Web Access Web Request cross site scripting
15538| [117558] Microsoft Windows up to Server 2016 Code Execution memory corruption
15539| [117507] Microsoft Infopath 2013 SP1 memory corruption
15540| [117505] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R information disclosure
15541| [117504] Microsoft Office 2010 SP2 information disclosure
15542| [117503] Microsoft Exchange Server 2013 CU19/2013 CU20/2016 CU8/2016 CU9 Outlook Web Access cross site scripting
15543| [117502] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016 cross site scripting
15544| [117501] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
15545| [117500] Microsoft Exchange Server 2016 CU8/2016 CU9 Outlook Web Access cross site scripting
15546| [117499] Microsoft Exchange Server up to 2016 CU9 information disclosure
15547| [117498] Microsoft Office 2016 C2R Security Feature privilege escalation
15548| [117497] Microsoft SharePoint Enterprise Server 2010/2013 SP1/2016 cross site scripting
15549| [117480] Microsoft Windows up to Server 2016 COM Serialized privilege escalation
15550| [117473] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
15551| [117472] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
15552| [117471] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
15553| [117470] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
15554| [117469] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
15555| [117468] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
15556| [117444] Microsoft Windows up to Server 2016 Hyper-V vSMB memory corruption
15557| [117443] Microsoft Windows up to Server 2016 Hyper-V memory corruption
15558| [117442] Microsoft Windows up to Server 2016 VBScript Engine memory corruption
15559| [116132] Microsoft Office 2016 Memory information disclosure
15560| [116051] Microsoft SharePoint Enterprise Server 2016 cross site scripting
15561| [116050] Microsoft SharePoint Enterprise Server 2010 SP2/2013/2016 cross site scripting
15562| [116049] Microsoft SharePoint Enterprise Server 2013/2016 privilege escalation
15563| [116048] Microsoft Windows up to Server 2016 DirectX Graphics Kernel Subsystem memory corruption
15564| [116047] Microsoft Windows up to Server 2016 OpenType Font Driver atmfd.dll memory corruption
15565| [116046] Microsoft SharePoint Enterprise Server 2013/2016 Share cross site scripting
15566| [116045] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
15567| [116039] Microsoft Windows up to Server 2016 Remote Desktop Protocol denial of service
15568| [116031] Microsoft Windows up to Server 2016 Kernel ASLR information disclosure
15569| [116030] Microsoft Windows up to Server 2016 SNMP Service denial of service
15570| [116026] Microsoft Windows up to Server 2016 Kernel information disclosure
15571| [116024] Microsoft Windows up to Server 2016 HTTP.sys denial of service
15572| [116023] Microsoft Office up to 2016 C2R information disclosure
15573| [116022] Microsoft Excel 2010 SP2 memory corruption
15574| [116020] Microsoft Windows 10 1607/10 1703/10 1709/Server 1709/Server 2016 Active Directory privilege escalation
15575| [116019] Microsoft Windows up to Server 2016 Kernel information disclosure
15576| [116018] Microsoft Office 2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
15577| [116017] Microsoft Excel up to 2016 C2R memory corruption
15578| [116016] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 Graphics memory corruption
15579| [116014] Microsoft Office 2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
15580| [116013] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1 memory corruption
15581| [116008] Microsoft Windows up to Server 2016 Graphics memory corruption
15582| [116007] Microsoft Windows up to Server 2016 Graphics memory corruption
15583| [116006] Microsoft Windows up to Server 2016 Graphics memory corruption
15584| [116005] Microsoft Windows up to Server 2016 Graphics memory corruption
15585| [116004] Microsoft Windows up to Server 2016 Graphics memory corruption
15586| [116003] Microsoft Windows up to Server 2016 VBScript Engine memory corruption
15587| [115994] Microsoft Windows up to Server 2016 Malware Protection Engine memory corruption
15588| [115804] Microsoft Windows up to Server 2016 Malware Protection Engine privilege escalation
15589| [114579] Microsoft Exchange Server up to 2017 CU8 Outlook Web Access information disclosure
15590| [114574] Microsoft SharePoint Enterprise Server 2016 privilege escalation
15591| [114573] Microsoft SharePoint Enterprise Server 2016 cross site scripting
15592| [114571] Microsoft Exchange Server 2016 CU7/2016 CU8 Outlook Web Access information disclosure
15593| [114570] Microsoft Exchange Server 2010 SP3/2013 CU18/2013 CU19/2016 CU7/2016 CU8 Outlook Web Access Fake privilege escalation
15594| [114565] Microsoft Windows 10 1607/10 1703/10 1709/Server 1709/Server 2016 Kernel information disclosure
15595| [114564] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
15596| [114562] Microsoft SharePoint Enterprise Server 2016 cross site scripting
15597| [114560] Microsoft SharePoint Enterprise Server 2016 cross site scripting
15598| [114559] Microsoft SharePoint Enterprise Server 2016 cross site scripting
15599| [114558] Microsoft SharePoint Enterprise Server 2016 cross site scripting
15600| [114557] Microsoft SharePoint Enterprise Server 2016 cross site scripting
15601| [114556] Microsoft SharePoint Enterprise Server 2016 cross site scripting
15602| [114555] Microsoft SharePoint Enterprise Server 2016 cross site scripting
15603| [114554] Microsoft SharePoint Enterprise Server 2016 cross site scripting
15604| [114553] Microsoft SharePoint Enterprise Server 2016 cross site scripting
15605| [114552] Microsoft SharePoint Enterprise Server 2016 cross site scripting
15606| [114551] Microsoft Excel up to 2016 C2R Security Feature privilege escalation
15607| [114549] Microsoft Access 2010 SP2/2013 SP1/2016 memory corruption
15608| [114548] Microsoft Windows up to Server 2016 CNG Security Feature cng.sys privilege escalation
15609| [114547] Microsoft Windows up to Server 2016 Kernel information disclosure
15610| [114546] Microsoft Windows up to Server 2016 Kernel information disclosure
15611| [114545] Microsoft Windows up to Server 2016 Kernel information disclosure
15612| [114544] Microsoft Windows up to Server 2016 Kernel information disclosure
15613| [114543] Microsoft Windows up to Server 2016 Kernel information disclosure
15614| [114542] Microsoft Windows up to Server 2016 Kernel information disclosure
15615| [114541] Microsoft Windows up to Server 2016 Kernel information disclosure
15616| [114540] Microsoft Windows up to Server 2016 Kernel information disclosure
15617| [114536] Microsoft Windows up to Server 2016 CredSSP privilege escalation
15618| [114535] Microsoft Windows up to Server 2016 Hyper-V denial of service
15619| [114531] Microsoft Windows up to Server 2016 Windows Installer privilege escalation
15620| [114530] Microsoft Windows up to Server 2016 GDI privilege escalation
15621| [114529] Microsoft Windows up to Server 2016 GDI privilege escalation
15622| [114527] Microsoft Windows up to Server 2016 Kernel information disclosure
15623| [114526] Microsoft Windows up to Server 2016 Kernel information disclosure
15624| [114525] Microsoft Windows up to Server 2016 Kernel information disclosure
15625| [114522] Microsoft Windows 10 1607/10 1703/Server 2016 Desktop Bridge privilege escalation
15626| [114521] Microsoft Windows up to Server 2016 Video Control privilege escalation
15627| [114520] Microsoft Windows 10/Server 1709/Server 2016 Desktop Bridge privilege escalation
15628| [114518] Microsoft Windows up to Server 2016 Remote Assistance information disclosure
15629| [114517] Microsoft Windows 10/Server 1709/Server 2016 Desktop Bridge VFS privilege escalation
15630| [114516] Microsoft Windows up to Server 2016 Windows Shell privilege escalation
15631| [113835] Microsoft Identity Manager 2016 SP1 cross site scripting
15632| [113264] Microsoft Windows 8.1/RT 8.1/Server 2012 R2 SMBv2/SMBv3 denial of service
15633| [113260] Microsoft Windows up to Server 2016 Kernel memory corruption
15634| [113259] Microsoft Windows 10/Server 1709/Server 2016 NTFS privilege escalation
15635| [113254] Microsoft Windows up to Server 2016 Kernel information disclosure
15636| [113253] Microsoft Windows 10/Server 1709/Server 2016 Kernel memory corruption
15637| [113252] Microsoft Windows up to Server 2016 Kernel memory corruption
15638| [113250] Microsoft Windows 10/Server 1709/Server 2016 Kernel memory corruption
15639| [113249] Microsoft Windows up to Server 2016 Kernel memory corruption
15640| [113248] Microsoft Windows up to Server 2016 Kernel information disclosure
15641| [113243] Microsoft Windows 10/Server 2016 MultiPoint Management privilege escalation
15642| [113242] Microsoft Windows up to Server 2016 Common Log File System Driver memory corruption
15643| [113241] Microsoft Windows up to Server 2016 Common Log File System Driver memory corruption
15644| [113240] Microsoft Windows 10/Server 1709/Server 2016 AppContainer privilege escalation
15645| [113237] Microsoft SharePoint Enterprise Server 2016 cross site scripting
15646| [113236] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
15647| [113233] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 Uninitialized Memory information disclosure
15648| [113232] Microsoft Excel 2016 memory corruption
15649| [113230] Microsoft Windows up to Server 2016 Scripting Engine information disclosure
15650| [113229] Microsoft Windows up to Server 2016 StructuredQuery memory corruption
15651| [111580] Microsoft Office 2016 on Mac Email Attachment spoofing
15652| [111571] Microsoft SharePoint Enterprise Server 2013/2016 Access cross site scripting
15653| [111567] Microsoft Office 2010/2013/2016 memory corruption
15654| [111564] Microsoft Word 2016 memory corruption
15655| [111562] Microsoft SharePoint Server 2010/2013/2016 Web Request cross site scripting
15656| [111561] Microsoft SharePoint Server 2010/2013/2016 Web Request cross site scripting
15657| [128730] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
15658| [111358] Microsoft Windows up to Server 2016 IPsec denial of service
15659| [110553] Microsoft Office 2016 C2R information disclosure
15660| [110552] Microsoft SharePoint Enterprise Server 2016 Web Request privilege escalation
15661| [110551] Microsoft Excel 2016 C2R memory corruption
15662| [110550] Microsoft PowerPoint 2013 RT SP1/2013 SP1/2016 information disclosure
15663| [110549] Microsoft Exchange Server 2016 CU6/2016 CU7 Outlook Web Access privilege escalation
15664| [110547] Microsoft Windows up to Server 2016 its:// Protocol information disclosure
15665| [110531] Microsoft Windows 10/Server 2016 Device Guard privilege escalation
15666| [110522] Microsoft Windows up to Server 2016 RRAS privilege escalation
15667| [110350] Microsoft Windows up to Server 2016 Malware Protection Engine memory corruption
15668| [110318] Microsoft Windows up to Server 2016 Malware Protection Engine memory corruption
15669| [109391] Microsoft SharePoint Enterprise Server 2016 Project Server cross site request forgery
15670| [109389] Microsoft Excel 2016 Click-to-Run memory corruption
15671| [109360] Microsoft Windows up to Server 2016 Windows Search denial of service
15672| [107759] Microsoft Windows up to Server 2016 SMB denial of service
15673| [107757] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
15674| [107756] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
15675| [107753] Microsoft Windows 10/Server 2016 SMB privilege escalation
15676| [107744] Microsoft Windows up to Server 2016 DNSAPI DNSAPI.dll DNS Response privilege escalation
15677| [107741] Microsoft Outlook 2016 Secure Connection Mail information disclosure
15678| [107740] Microsoft Windows up to Server 2016 Graphics memory corruption
15679| [107739] Microsoft Windows up to Server 2016 Graphics memory corruption
15680| [107738] Microsoft Windows up to Server 2016 Search information disclosure
15681| [107734] Microsoft Windows 10/Server 2016 SMB privilege escalation
15682| [107732] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016 Bypass privilege escalation
15683| [107730] Microsoft Windows up to Server 2016 Search Remote memory corruption
15684| [107729] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
15685| [107728] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
15686| [107727] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
15687| [107724] Microsoft Windows up to Server 2016 Text Services Framework memory corruption
15688| [107723] Microsoft Windows up to Server 2016 SMB information disclosure
15689| [107698] Microsoft Office 2016 memory corruption
15690| [107593] InFocus Mondopad 2.2.08 Excel Spreadsheet Microsoft Office Document Credentials information disclosure
15691| [106544] Microsoft Exchange Server 2016 Outlook Web Access cross site scripting
15692| [106531] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
15693| [106529] Microsoft PowerPoint 2016 memory corruption
15694| [106523] Microsoft Windows up to Server 2016 PDF Library memory corruption
15695| [106518] Microsoft Edge on Win10/Server 2016 memory corruption
15696| [106516] Microsoft Windows up to Server 2016 PDF Library memory corruption
15697| [106498] Microsoft Windows up to Server 2016 Shell privilege escalation
15698| [106496] Microsoft Windows up to Server 2016 Uniscribe information disclosure
15699| [106495] Microsoft Windows up to Server 2012 R2 Uniscribe memory corruption
15700| [106492] Microsoft Windows Server 2012/Server 2012 R2/Server 2016 DHCP Service memory corruption
15701| [106489] Microsoft Windows up to Server 2016 Graphics Win32k win32k!fsc_CalcGrayRow memory corruption
15702| [106474] Microsoft Office 2016 memory corruption
15703| [106473] Microsoft SharePoint Server 2013 SP1 cross site scripting
15704| [106472] Microsoft Windows up to Server 2016 Bluetooth Driver Object BlueBorne spoofing
15705| [106470] Microsoft Excel 2011 on Mac memory corruption
15706| [106455] Microsoft Exchange Server 2013/2016 information disclosure
15707| [106454] Microsoft Windows up to Server 2016 Windows NetBT Session Services race condition memory corruption
15708| [105048] Microsoft Edge on Win10/Server 2016 Scripting Engine memory corruption
15709| [105047] Microsoft Edge on Win10/Server 2016 Scripting Engine EntryCall memory corruption
15710| [105046] Microsoft Edge on Win10/Server 2016 Javascript Engine memory corruption
15711| [105040] Microsoft Edge on Win10/Server 2016 Scripting Engine memory corruption
15712| [105038] Microsoft Edge on Win10/Server 2016 Javascript Engine Out-of-Bounds memory corruption
15713| [105037] Microsoft Edge on Win10/Server 2016 Javascript Engine PreVisitCatch memory corruption
15714| [105035] Microsoft SharePoint Server 2010 SP2 cross site scripting
15715| [105033] Microsoft Edge 38.14393.1066.0 on Win10/Server 2016 Use-After-Free information disclosure
15716| [105029] Microsoft Edge on Win10/Server 2016 Javascript Engine ProcessLinkFailedAsmJsModule memory corruption
15717| [105027] Microsoft Edge on Win10/Server 2016 _SelectValueInternal information disclosure
15718| [105024] Microsoft Edge on Win10/Server 2016 Javascript Engine memory corruption
15719| [105023] Microsoft Edge on Win10/Server 2016 Javascript Engine memory corruption
15720| [105017] Microsoft Windows up to Server 2016 Error Reporting information disclosure
15721| [105013] Microsoft Windows 10 1607/10 1703/Server 2016 Hyper-V denial of service
15722| [105011] Microsoft Windows up to Server 2016 Windows Search memory corruption
15723| [105010] Microsoft Windows up to Server 2016 Win32k memory corruption
15724| [105009] Microsoft Windows up to Server 2016 Input Method Editor memory corruption
15725| [105008] Microsoft SQL Server 2012/2014/2016 Analysis Services information disclosure
15726| [104990] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
15727| [104989] Microsoft Windows up to Server 2016 NetBIOS denial of service
15728| [104584] Microsoft Outlook up to 2016 C2R Document File privilege escalation
15729| [104583] Microsoft Outlook up to 2016 C2R Email memory corruption
15730| [104582] Microsoft Outlook up to 2016 C2R Object memory corruption
15731| [103468] Microsoft Exchange Server 2010 SP3/2013 CU16/2013 SP3/2016 CU5 Open Redirect
15732| [103446] Microsoft Windows up to Server 2016 Search Object privilege escalation
15733| [103445] Microsoft Windows up to Server 2016 Wordpad privilege escalation
15734| [103444] Microsoft Windows up to Server 2016 Explorer denial of service
15735| [103442] Microsoft Windows 10/Server 2016 HoloLens WiFi Packet privilege escalation
15736| [103441] Microsoft Windows up to Server 2016 Object HTTP.sys information disclosure
15737| [103431] Microsoft Windows up to Server 2016 PowerShell PSObject Object privilege escalation
15738| [103429] Microsoft Windows up to Server 2016 Kerberos weak authentication
15739| [103426] Microsoft Exchange Server 2010 SP3/2013 CU16/2013 SP3/2016 CU5 OWA Request cross site scripting
15740| [103425] Microsoft Exchange Server 2010 SP3/2013 CU16/2013 SP3/2016 CU5 OWA Request cross site scripting
15741| [103420] Microsoft Windows up to Server 2016 Kerberos Bypass privilege escalation
15742| [103417] Microsoft Windows up to Server 2016 Windows Shell privilege escalation
15743| [102544] Microsoft Edge on Win10/Server 2016 Fetch API information disclosure
15744| [102543] Microsoft Edge on Win10/Server 2016 Javascript XML DOM Object information disclosure
15745| [102463] Microsoft Project Server 2013 SP1 cross site scripting
15746| [102460] Microsoft Outlook 2016 on Mac HTML spoofing
15747| [102448] Microsoft SharePoint Enterprise Server 2016 Reflected cross site scripting
15748| [102446] Microsoft Office up to 2016 privilege escalation
15749| [102445] Microsoft Office 2010 SP2/2011/2013 RT SP1/2013 SP1/2016 privilege escalation
15750| [102443] Microsoft Office up to 2016 privilege escalation
15751| [102412] Microsoft Windows up to Server 2016 PDF information disclosure
15752| [102397] Microsoft Outlook 2010 SP1/2013 SP1/2016 DLL Loader privilege escalation
15753| [102396] Microsoft Office 2013 SP1/2016 DLL Loader privilege escalation
15754| [102386] Microsoft Windows up to Server 2012 R2 Uniscribe privilege escalation
15755| [102385] Microsoft Windows up to Server 2016 Font Library privilege escalation
15756| [102376] Microsoft Windows up to Server 2016 CAB File privilege escalation
15757| [102375] Microsoft Windows up to Server 2016 PDF Parser privilege escalation
15758| [102374] Microsoft Windows up to Server 2016 PDF Parser privilege escalation
15759| [102373] Microsoft Windows up to Server 2016 Uniscribe Font USP10!MergeLigRecords memory corruption
15760| [101817] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
15761| [101816] Microsoft Windows up to Server 2016 Malware Protection Engine setCaller memory corruption
15762| [101815] Microsoft Windows up to Server 2016 Malware Protection Engine Use-After-Free memory corruption
15763| [101814] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
15764| [101813] Microsoft Windows up to Server 2016 Malware Protection Engine memory corruption
15765| [101812] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
15766| [101811] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
15767| [101810] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
15768| [101028] Microsoft Windows 10/Server 2016 Hyper-V vSMB privilege escalation
15769| [101020] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
15770| [101019] Microsoft Skype for Business 2016 memory corruption
15771| [101018] Microsoft SharePoint 2010 SP2/2013 SP1/2016 memory corruption
15772| [101016] Microsoft PowerPoint 2011 on Mac memory corruption
15773| [101015] Microsoft PowerPoint 2011 on Mac memory corruption
15774| [101014] Microsoft Office 2010 SP2/2016 memory corruption
15775| [101013] Microsoft Office 2010 SP2/2016 memory corruption
15776| [101002] Microsoft Windows up to Server 2016 SMBv1 Server memory corruption
15777| [101001] Microsoft Windows up to Server 2016 SMBv1 Server memory corruption
15778| [101000] Microsoft Windows up to Server 2016 SMBv1 Server memory corruption
15779| [100999] Microsoft Windows up to Server 2016 SMBv1 Server memory corruption
15780| [100918] Microsoft Windows 8/8.1/10/Server 2012/Server 2016 Malware Protection Service Type Confusion privilege escalation
15781| [99697] Microsoft SharePoint Server 2010 SP1/2010 SP2 Excel Services cross site scripting
15782| [99683] Microsoft Windows 10 1607/10 1703/Server 2012 R2/Server 2016 Active Directory Lockout privilege escalation
15783| [99682] Microsoft Outlook 2011 on Mac HTML Tag Validator spoofing
15784| [99681] Microsoft Windows up to Server 2016 OLE Integrity-Level Check privilege escalation
15785| [99667] Microsoft Windows 10/Server 2016 Active Directory Service Unresponsive denial of service
15786| [98272] Microsoft Windows up to 10/Server 2016 Local Session privilege escalation
15787| [98096] Microsoft Exchange 2013 SP1 privilege escalation
15788| [98095] Microsoft Lync for Mac 2011 Certificate Validation weak authentication
15789| [98094] Microsoft SharePoint Server 2013 SP1 cross site scripting
15790| [98093] Microsoft SharePoint Server/Office Web Apps 2010 SP2 memory corruption
15791| [98091] Microsoft SharePoint Server/Office Web Apps 2010 SP2 memory corruption
15792| [98090] Microsoft SharePoint Server 2010 SP2/2013 SP1 information disclosure
15793| [98089] Microsoft Office Web Apps 2013 SP1 memory corruption
15794| [98082] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 denial of service
15795| [98081] Microsoft Excel up to 2016 information disclosure
15796| [98080] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
15797| [98079] Microsoft Word 2016 memory corruption
15798| [98076] Microsoft Lync/Skype for Business 2010/2013/2016 Graphics Component privilege escalation
15799| [98075] Microsoft Lync/Skype for Business 2010/2013/2016 GDI+ information disclosure
15800| [98074] Microsoft Lync/Skype for Business 2010/2013/2016 GDI+ information disclosure
15801| [98073] Microsoft Office 2010 SP2/Word Viewer Graphics Component information disclosure
15802| [98069] Microsoft Windows up to Server 2012 R2 Color Management memory corruption
15803| [98056] Microsoft Windows up to Server 2016 DNS Query information disclosure
15804| [98054] Microsoft Windows up to Server 2016 SMBv2/SMBv3 NULL Pointer Dereference memory corruption
15805| [98017] Microsoft Windows up to Server 2016 PDF memory corruption
15806| [98015] Microsoft Windows 10/Server 2016 Hyper-V denial of service
15807| [98013] Microsoft Windows 10/Server 2016 Hyper-V vSMB memory corruption
15808| [98007] Microsoft Windows 10/Server 2016 Hyper-V Network Switch denial of service
15809| [98006] Microsoft Windows 10/Server 2016 Hyper-V vSMB memory corruption
15810| [96521] Microsoft Windows 8.1/10/Server 2012/Server 2016 SMB Response mrxsmb20.sys denial of service
15811| [95781] Microsoft PowerPoint 2016 Java Embedded Object privilege escalation
15812| [95125] Microsoft Word/SharePoint Enterprise Server 2016 Document privilege escalation
15813| [94451] Microsoft Office 2011 memory corruption
15814| [94447] Microsoft Office 2010 SP2 memory corruption
15815| [94446] Microsoft Office 2016 memory corruption
15816| [94444] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 OLE DLL Loader memory corruption
15817| [94443] Microsoft Office up to 2016 information disclosure
15818| [94442] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 privilege escalation
15819| [93964] Microsoft Windows 7 Excel Starter 2010 XXE information disclosure
15820| [93543] Microsoft SQL Server 2016 FILESTREAM Path privilege escalation
15821| [93540] Microsoft Excel 2010 SP2/2011/2016 memory corruption
15822| [93416] Microsoft SQL Server 2014 SP2/2016/up to 2012 SP3 Server Agent atxcore.dll privilege escalation
15823| [93415] Microsoft SQL Server 2016 MDS API cross site scripting
15824| [93414] Microsoft SQL Server up to 2012 SP3 RDBMS Engine privilege escalation
15825| [93413] Microsoft SQL Server 2016/up to 2014 SP2 RDBMS Engine privilege escalation
15826| [93412] Microsoft SQL Server 2016 RDBMS Engine privilege escalation
15827| [93393] Microsoft Office up to 2016 memory corruption
15828| [93392] Microsoft Office up to 2016 memory corruption
15829| [93391] Microsoft Office up to 2016 memory corruption
15830| [93389] Microsoft Windows up to Server 2016 Media Foundation memory corruption
15831| [93388] Microsoft Windows up to Server 2016 Animation Manager Stylesheets memory corruption
15832| [92587] Microsoft Windows 8.1/10/RT 8.1/Server 2012/Server 2012 R2 Transaction Manager privilege escalation
15833| [92584] Microsoft Office up to 2016 memory corruption
15834| [91571] Microsoft Windows 8.1/10/RT 8.1/Server 2012/Server 2012 R2 PDF Library information disclosure
15835| [91570] Microsoft Windows 8.1/10/RT 8.1/Server 2012/Server 2012 R2 PDF Library information disclosure
15836| [91556] Microsoft Exchange 2016 Meeting Invation cross site scripting
15837| [91555] Microsoft Exchange 2013/2016 Link spoofing
15838| [91550] Microsoft Office 2016 memory corruption
15839| [91547] Microsoft Office 2010 memory corruption
15840| [91543] Microsoft Office up to 2016 memory corruption
15841| [91541] Microsoft Office 2013/2016 APP-V ASLR privilege escalation
15842| [90711] Microsoft Windows 8.1/10/RT 8.1/Server 2012/Server 2012 R2 PDF privilege escalation
15843| [90710] Microsoft Windows 8.1/RT 8.1/Server 2012/Server 2012 R2 Netlogon privilege escalation
15844| [90704] Microsoft Office 2013/2013 RT/2016 memory corruption
15845| [89043] Microsoft Office up to 2016 memory corruption
15846| [89041] Microsoft Office up to 2016 memory corruption
15847| [89040] Microsoft Office 2010 SP2/2011/2013 RT SP1/2013 SP1/2016 memory corruption
15848| [89038] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 Security Feature privilege escalation
15849| [89037] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
15850| [87961] Microsoft Windows up to Server 2012 R2 Search denial of service
15851| [87959] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 PDF information disclosure
15852| [87958] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 PDF memory corruption
15853| [87957] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 PDF information disclosure
15854| [87956] Microsoft Exchange 2013/2016 Oracle Outside In Libraries information disclosure
15855| [87944] Microsoft Windows Server 2012/Server 2012 R2 Virtual PCI Memory information disclosure
15856| [87940] Microsoft Windows Server 2012/Server 2012 R2 DNS Server Use-After-Free memory corruption
15857| [87936] Microsoft Office up to 2016 memory corruption
15858| [87166] Microsoft Windows up to Server 2012 R2 DirectX Graphics Kernel Subsystem privilege escalation
15859| [87156] Microsoft Windows 8.1/10/RT 8.1/Server 2012 R2 Shell memory corruption
15860| [87149] Microsoft Office up to 2016 memory corruption
15861| [87148] Microsoft Office 2010 Graphics memory corruption
15862| [87146] Microsoft Office 2011/2013/2013 RT/2016 memory corruption
15863| [82229] Microsoft Excel 2010 SP2 Office Document memory corruption
15864| [82223] Microsoft Windows 8.1/10/Server 2012 R2 Hyper-V Memory information disclosure
15865| [82222] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 Memory information disclosure
15866| [82221] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 Hyper-V privilege escalation
15867| [81274] Microsoft Office up to 2016 memory corruption
15868| [81270] Microsoft Windows 8.1/10/RT 8.1/Server 2012/Server 2012 R2 PDF Library memory corruption
15869| [81269] Microsoft Windows up to Server 2012 R2 Media Parser memory corruption
15870| [81268] Microsoft Windows up to Server 2012 R2 Media Parser memory corruption
15871| [80886] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
15872| [80885] Microsoft Windows 7 SP1/8.1/10/Server 2012/Server 2012 R2 RDP memory corruption
15873| [80878] Microsoft Windows Server 2012 R2 Active Directory Federation Service denial of service
15874| [80874] Microsoft Windows 7 SP1/8.1/10/Server 2012/Server 2012 R2 RDP privilege escalation
15875| [80870] Microsoft Office up to 2016 memory corruption
15876| [80868] Microsoft Office up to 2016 memory corruption
15877| [80867] Microsoft Office up to 2016 memory corruption
15878| [80865] Microsoft Windows 8.1/RT 8.1/Server 2012/Server 2012 R2 DLL Loader memory corruption
15879| [80860] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 Reader memory corruption
15880| [80859] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 PDF Library memory corruption
15881| [80231] Microsoft Excel up to 2016 Office Document memory corruption
15882| [80229] Microsoft Exchange Server 2013 CU 10/2013 CU 11/2013 SP1/2016 Outlook Web Access cross site scripting
15883| [80228] Microsoft Exchange Server 2016 Outlook Web Access cross site scripting
15884| [80227] Microsoft Exchange Server 2013 CU 10/2013 SP1/2016 Outlook Web Access cross site scripting
15885| [80226] Microsoft Exchange Server 2016 Outlook Web Access cross site scripting
15886| [80218] Microsoft Office up to 2016 ASLR privilege escalation
15887| [80217] Microsoft SharePoint Foundation 2013 SP1 Access Control Policy cross site scripting
15888| [80216] Microsoft Office up to 2016 Office Document memory corruption
15889| [80206] Microsoft SharePoint Foundation 2013 SP1 Access Control Policy cross site scripting
15890| [128763] Microsoft Exchange Server 2016 CU10/2016 CU11/2019 memory corruption
15891| [79508] Microsoft Windows up to Server 2012 R2 Library Loader memory corruption
15892| [79500] Microsoft Office 2010/2011/2016 memory corruption
15893| [79183] Microsoft Windows up to Server 2012 R2 IPsec denial of service
15894| [79173] Microsoft Windows up to Server 2012 R2 Graphics information disclosure
15895| [79117] Microsoft Outlook 2011/2016 on Mac HTML spoofing
15896| [78375] Microsoft SharePoint Server/SharePoint Foundation 2013 SP1 cross site scripting
15897| [77645] Microsoft Exchange Server 2013 CU8/2013 CU9 Outlook Web Access cross site scripting
15898| [77644] Microsoft Exchange Server 2013 CU8/2013 CU9 Outlook Web Access cross site scripting
15899| [77638] Microsoft Lync Server 2013 cross site scripting
15900| [77628] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
15901| [77612] Microsoft Exchange Server 2013 CU8/2013 CU9 Outlook Web Access Stack-Based information disclosure
15902| [77050] Microsoft Office up to 2016 memory corruption
15903| [77037] Microsoft Windows Server 2012/Server 2012 R2 System Center Operations Manager cross site scripting
15904| [76461] Microsoft Windows up to Server 2012 R2 Domain-Controller Communication Credentials information disclosure
15905| [76460] Microsoft Windows 7 SP1/8/Server 2012 RDP Server Service memory corruption
15906| [76448] Microsoft Windows 8.1/Server 2012 R2 Hyper-V memory corruption
15907| [75793] Microsoft Exchange Server 2013 CU8 cross site scripting
15908| [75792] Microsoft Exchange Server 2013 SP1 CU8 cross site request forgery
15909| [75791] Microsoft Office 2013 SP1 Office Document Uninitialized Memory memory corruption
15910| [75787] Microsoft Exchange Server 2013 SP1 CU8 Same Origin Policy privilege escalation
15911| [75786] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1 Office Document memory corruption
15912| [66976] Microsoft Access 2010 VBA Datatype denial of service
15913| [74848] Microsoft SharePoint Foundation/SharePoint Server 2013 SP1 cross site scripting
15914| [74842] Microsoft Windows 8.1/Server 2012 R2 Hyper-V denial of service
15915| [74836] Microsoft Project Server 2010 SP2/2013 SP1 cross site scripting
15916| [74835] Microsoft Office 2011 on Mac Use-After-Free cross site scripting
15917| [74834] Microsoft Windows Server 2012 R2 Active Directory Federation Services 3.0 privilege escalation
15918| [74833] Microsoft Windows 7 SP1/8/8.1/Server 2012/Server 2012 R2 HTTP Request HTTP.sys privilege escalation
15919| [74393] Microsoft SharePoint Server 2013 Foundation cross site scripting
15920| [73967] Microsoft Office up to 2013 SP1 Office File memory corruption
15921| [73966] Microsoft Office up to 2013 SP1 RTF File memory corruption
15922| [73965] Microsoft Office up to 2013 SP1 Use-After-Free memory corruption
15923| [73961] Microsoft Windows 7 SP1/8/8.1/Server 2012/Server 2012 R2 Remote Desktop Protocol Object Management denial of service
15924| [69162] Microsoft System Center Virtual Machine Manager 2012 privilege escalation
15925| [69160] Microsoft Windows up to Server 2012 Process privilege escalation
15926| [69156] Microsoft Office 2010 Object memory corruption
15927| [68593] Microsoft Windows up to Server 2012 Network Location Awareness Service privilege escalation
15928| [68417] Microsoft Exchange 2013 Outlook Web Access Token spoofing
15929| [68191] Microsoft SharePoint 2010 cross site scripting
15930| [67828] Microsoft ASP.NET MVC 2/3/4/5/5.1 System.Web.Mvc.dll cross site scripting
15931| [67518] Microsoft Lync 2013 denial of service
15932| [67517] Microsoft Lync 2013 Script Reflected cross site scripting
15933| [67516] Microsoft Lync 2010/2013 denial of service
15934| [67362] Microsoft Windows up to Server 2012 R2 Remote Procedure Call privilege escalation
15935| [67360] Microsoft SharePoint 2013 App Permission Management cross site scripting
15936| [13549] Microsoft Windows 7/8/8.1/Server 2012 Remote Desktop Protocol weak encryption
15937| [13547] Microsoft Lync 2010/2013 Meeting cross site scripting
15938| [13228] Microsoft Office 2013 Document privilege escalation
15939| [68577] Microsoft ASP.NET 2014.3.1209 Telerik UI RadAsyncUpload directory traversal
15940| [12267] Microsoft Forefront Security for Exchange Server 2010 Mail memory corruption
15941| [12263] Microsoft Windows up to Server 2012 Direct2D 2D Geometric Figure memory corruption
15942| [12238] Microsoft Windows 8/RT/Server 2012 IPv6 denial of service
15943| [12185] Microsoft .NET Framework 2/4 HMAC weak authentication
15944| [12183] Microsoft .NET Framework 2/4 DTD denial of service
15945| [11673] Microsoft Windows Live Movie Maker 2011 WAV File denial of service
15946| [11468] Microsoft Exchange 2010/2013 cross site scripting
15947| [11466] Microsoft Office 2013 File Response information disclosure
15948| [11457] Microsoft SharePoint Server/Office Web Apps 2010 SP1/2010 SP2/2013 W3WP Service Account privilege escalation
15949| [11150] Microsoft Windows 8/Server 2012 Hyper-V Data Structure Value Crash privilege escalation
15950| [11004] Microsoft Windows Server 2012 R2 RDP Restricted Admin Mode weak authentication
15951| [10250] Microsoft SharePoint Server up to 2013 W3WP Process denial of service
15952| [10249] Microsoft SharePoint 2010/2003/2007/2.0/3.0 Workflow memory corruption
15953| [10248] Microsoft SharePoint Server up to 2013 cross site scripting
15954| [9943] Microsoft Windows Server 2012 NAT Driver ICMP Packet denial of service
15955| [8739] Microsoft Windows Essentials up to 2012 Windows Writer Eingabe information disclosure
15956| [8725] Microsoft Lync 2010/2013 Use-After-Free memory corruption
15957| [8722] Microsoft Windows 8/RT/Server 2012 HTTP.sys denial of service
15958| [8206] Microsoft SharePoint Server 2010 SP1 HTML Sanitization Component cross site scripting
15959| [8203] Microsoft Windows up to 2012 AD LDAP Query denial of service
15960| [8200] Microsoft SharePoint Server 2013 ACL information disclosure
15961| [7971] Microsoft Office for Mac 2011 up to 14.3.1 on Mac HTML5 Mail Message Parser File information disclosure
15962| [7969] Microsoft OneNote 2010 SP1 ONE File information disclosure
15963| [7968] Microsoft SharePoint Server 2010 SP1 Input Validator Eingabe Crash denial of service
15964| [7967] Microsoft SharePoint Server 2010 SP1 User Account Eingabe Crash information disclosure
15965| [7966] Microsoft SharePoint Server 2010 SP1 Eingabe Crash cross site scripting
15966| [7965] Microsoft SharePoint Server 2010 SP1 User Account Callback URL privilege escalation
15967| [7964] Microsoft Visio 2010 Tree Object Type File memory corruption
15968| [7343] Microsoft Lync 2012 HTTP Format String
15969| [7258] Microsoft Windows up to 8/Server 2012 SSL/TLS race condition
15970| [7230] Microsoft Excel 2010 SP1 on 32-bit XLS File Formatting Information Crash denial of service
15971| [6831] Microsoft Office Picture Manager 2010 File memory corruption
15972| [62720] EMC NetWorker Module for Microsoft Applications up to 2.2.0 memory corruption
15973| [6624] Microsoft SQL Server up to 2012 Report Manager cross site scripting
15974| [62238] Microsoft Visual Studio Team Foundation Server 2010 cross site scripting
15975| [5946] Microsoft Visio/Visio Viewer up to 2010 SP1 File memory corruption
15976| [5644] Microsoft SharePoint 2010 scriptesx.ashx cross site scripting
15977| [5641] Microsoft SharePoint 2010 cross site scripting
15978| [60943] Microsoft Dynamics AX 2012 Enterprise Portal cross site scripting
15979| [12311] Microsoft Lync 2010 Search race condition
15980| [60570] Microsoft Forefront Unified Access Gateway 2010 information disclosure
15981| [60569] Microsoft Forefront Unified Access Gateway 2010 spoofing
15982| [60208] Microsoft Visio Viewer 2010 memory corruption
15983| [60207] Microsoft Visio Viewer 2010 memory corruption
15984| [60206] Microsoft Visio Viewer 2010 memory corruption
15985| [4640] Microsoft SharePoint 2010 inplview.aspx cross site scripting
15986| [4636] Microsoft SharePoint 2010 wizardlist.aspx cross site scripting
15987| [4635] Microsoft SharePoint 2010 themeweb.aspx cross site scripting
15988| [59008] Microsoft Forefront Unified Access Gateway 2010 Crash denial of service
15989| [58995] Microsoft Forefront Unified Access Gateway 2010 memory corruption
15990| [58994] Microsoft Forefront Unified Access Gateway 2010 Reflected cross site scripting
15991| [58993] Microsoft Forefront Unified Access Gateway 2010 Reflected cross site scripting
15992| [4424] Microsoft Host Integration Server up to 2010 denial of service
15993| [4420] Microsoft Forefront Unified Access Gateway 2010 memory corruption
15994| [58487] Microsoft SharePoint Foundation 2010 cross site scripting
15995| [58486] Microsoft SharePoint Foundation 2010 Reflected cross site scripting
15996| [58485] Microsoft SharePoint Foundation 2010 EditForm.aspx cross site scripting
15997| [4414] Microsoft SharePoint 2010 cross site scripting
15998| [4413] Microsoft SharePoint 2010/2007/3.0 XML/XLS unknown vulnerability
15999| [91971] Microsoft Skype 2.2.x/5.2.x/5.3.x denial of service
16000| [57693] Microsoft Forefront Threat Management Gateway 2010 NSPLookupServiceNext memory corruption
16001| [56028] Microsoft Data Access Components 2.8 memory corruption
16002| [55777] Microsoft Windows Movie Maker 2.6 memory corruption
16003| [55424] Microsoft Forefront Unified Access Gateway 2010 Signurl.asp cross site scripting
16004| [55415] Microsoft Forefront Unified Access Gateway 2010 cross site scripting
16005| [55414] Microsoft Forefront Unified Access Gateway 2010 cross site scripting
16006| [55413] Microsoft Forefront Unified Access Gateway 2010 spoofing
16007| [54341] Microsoft Windows Movie Maker 2.1 memory corruption
16008| [54549] Microsoft PowerPoint 2010 pptimpconv.dll memory corruption
16009| [4009] Microsoft NET Framework 2.x/3.x denial of service
16010| [45681] Microsoft Internet Explorer 8 Beta 2 privilege escalation
16011| [45449] Microsoft Internet Explorer 8 Beta 2 XSS Filter cross site scripting
16012| [45448] Microsoft Internet Explorer 8 Beta 2 XSS Filter cross site scripting
16013| [45446] Microsoft Internet Explorer 8 Beta 2 XSS Filter cross site scripting
16014| [2927] Microsoft Data Access Components 2.x ADODB.Connection ActiveX Control memory corruption
16015| [32692] Microsoft XML Core Services up to 2.6 memory corruption
16016| [32691] Microsoft XML Core Services up to 2.6 memory corruption
16017|
16018| MITRE CVE - https://cve.mitre.org:
16019| [CVE-2013-3661] The EPATHOBJ::bFlatten function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not check whether linked-list traversal is continually accessing the same list member, which allows local users to cause a denial of service (infinite traversal) via vectors that trigger a crafted PATHRECORD chain.
16020| [CVE-2013-3660] The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 does not properly initialize a pointer for the next object in a certain list, which allows local users to obtain write access to the PATHRECORD chain, and consequently gain privileges, by triggering excessive consumption of paged memory and then making many FlattenPath function calls, aka "Win32k Read AV Vulnerability."
16021| [CVE-2013-3174] DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 allows remote attackers to execute arbitrary code via a crafted GIF file, aka "DirectShow Arbitrary Memory Overwrite Vulnerability."
16022| [CVE-2013-3173] Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Win32k Buffer Overwrite Vulnerability."
16023| [CVE-2013-3172] Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to cause a denial of service (system hang) via a crafted application that leverages improper handling of objects in memory, aka "Win32k Buffer Overflow Vulnerability."
16024| [CVE-2013-3171] The serialization functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly check the permissions of delegate objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a partial-trust relationship, aka "Delegate Serialization Vulnerability."
16025| [CVE-2013-3167] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Information Disclosure Vulnerability."
16026| [CVE-2013-3154] The signature-update functionality in Windows Defender on Microsoft Windows 7 and Windows Server 2008 R2 relies on an incorrect pathname, which allows local users to gain privileges via a Trojan horse application in the %SYSTEMDRIVE% top-level directory, aka "Microsoft Windows 7 Defender Improper Pathname Vulnerability."
16027| [CVE-2013-3138] Integer overflow in the TCP/IP kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (system hang) via crafted TCP packets, aka "TCP/IP Integer Overflow Vulnerability."
16028| [CVE-2013-3136] The kernel in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, and Windows 8 on 32-bit platforms does not properly handle unspecified page-fault system calls, which allows local users to obtain sensitive information from kernel memory via a crafted application, aka "Kernel Information Disclosure Vulnerability."
16029| [CVE-2013-3134] The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 on 64-bit platforms does not properly allocate arrays of structures, which allows remote attackers to execute arbitrary code via a crafted .NET Framework application that changes array data, aka "Array Allocation Vulnerability."
16030| [CVE-2013-3133] Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "Anonymous Method Injection Vulnerability."
16031| [CVE-2013-3132] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "Delegate Reflection Bypass Vulnerability."
16032| [CVE-2013-3131] Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5, and Silverlight 5 before 5.1.20513.0, does not properly prevent changes to data in multidimensional arrays of structures, which allows remote attackers to execute arbitrary code via (1) a crafted .NET Framework application or (2) a crafted Silverlight application, aka "Array Access Violation Vulnerability."
16033| [CVE-2013-1345] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Vulnerability."
16034| [CVE-2013-1340] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Dereference Vulnerability."
16035| [CVE-2013-1339] The Print Spooler in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly manage memory during deletion of printer connections, which allows remote authenticated users to execute arbitrary code via a crafted request, aka "Print Spooler Vulnerability."
16036| [CVE-2013-1336] The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check signatures, which allows remote attackers to make undetected changes to signed XML documents via unspecified vectors that preserve signature validity, aka "XML Digital Signature Spoofing Vulnerability."
16037| [CVE-2013-1335] Microsoft Word 2003 SP3 and Word Viewer allow remote attackers to execute arbitrary code via crafted shape data in a Word document, aka "Word Shape Corruption Vulnerability."
16038| [CVE-2013-1334] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Window Handle Vulnerability."
16039| [CVE-2013-1332] dxgkrnl.sys (aka the DirectX graphics kernel subsystem) in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "DirectX Graphics Kernel Subsystem Double Fetch Vulnerability."
16040| [CVE-2013-1331] Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Office document, leading to improper memory allocation, aka "Office Buffer Overflow Vulnerability."
16041| [CVE-2013-1329] Integer signedness error in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers a buffer underflow, aka "Publisher Buffer Underflow Vulnerability."
16042| [CVE-2013-1328] Microsoft Publisher 2003 SP3, 2007 SP3, and 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers incorrect pointer handling, aka "Publisher Pointer Handling Vulnerability."
16043| [CVE-2013-1327] Integer signedness error in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers an improper memory allocation, aka "Publisher Signed Integer Vulnerability."
16044| [CVE-2013-1323] Microsoft Publisher 2003 SP3 does not properly handle NULL values for unspecified data items, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Incorrect NULL Value Handling Vulnerability."
16045| [CVE-2013-1322] Microsoft Publisher 2003 SP3 does not properly check table range data, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Invalid Range Check Vulnerability."
16046| [CVE-2013-1321] Microsoft Publisher 2003 SP3 does not properly check the data type of an unspecified return value, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Return Value Validation Vulnerability."
16047| [CVE-2013-1320] Buffer overflow in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Buffer Overflow Vulnerability."
16048| [CVE-2013-1319] Microsoft Publisher 2003 SP3 does not properly check the return value of an unspecified method, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Return Value Handling Vulnerability."
16049| [CVE-2013-1318] Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers access to an invalid pointer, aka "Publisher Corrupt Interface Pointer Vulnerability."
16050| [CVE-2013-1317] Integer overflow in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers an improper allocation-size calculation, aka "Publisher Integer Overflow Vulnerability."
16051| [CVE-2013-1316] Microsoft Publisher 2003 SP3 does not properly validate the size of an unspecified array, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Negative Value Allocation Vulnerability."
16052| [CVE-2013-1302] Microsoft Communicator 2007 R2, Lync 2010, Lync 2010 Attendee, and Lync Server 2013 do not properly handle objects in memory, which allows remote attackers to execute arbitrary code via an invitation that triggers access to a deleted object, aka "Lync RCE Vulnerability."
16053| [CVE-2013-1301] Microsoft Visio 2003 SP3 2007 SP3, and 2010 SP1 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, aka "XML External Entities Resolution Vulnerability."
16054| [CVE-2013-1300] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Memory Allocation Vulnerability."
16055| [CVE-2013-1295] The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "CSRSS Memory Corruption Vulnerability."
16056| [CVE-2013-1294] Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Kernel Race Condition Vulnerability."
16057| [CVE-2013-1293] The NTFS kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via a crafted application that leverages improper handling of objects in memory, aka "NTFS NULL Pointer Dereference Vulnerability."
16058| [CVE-2013-1292] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Win32k Race Condition Vulnerability."
16059| [CVE-2013-1291] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 Gold and SP1, and Windows 8 allows local users to cause a denial of service (reboot) via a crafted OpenType font, aka "OpenType Font Parsing Vulnerability" or "Win32k Font Parsing Vulnerability."
16060| [CVE-2013-1287] The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Windows USB Descriptor Vulnerability," a different vulnerability than CVE-2013-1285 and CVE-2013-1286.
16061| [CVE-2013-1286] The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Windows USB Descriptor Vulnerability," a different vulnerability than CVE-2013-1285 and CVE-2013-1287.
16062| [CVE-2013-1285] The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Windows USB Descriptor Vulnerability," a different vulnerability than CVE-2013-1286 and CVE-2013-1287.
16063| [CVE-2013-1283] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Win32k Race Condition Vulnerability."
16064| [CVE-2013-1281] The NFS server in Microsoft Windows Server 2008 R2 and R2 SP1 and Server 2012 allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via an attempted renaming of a file or folder located on a read-only share, aka "NULL Dereference Vulnerability."
16065| [CVE-2013-1280] The kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Reference Count Vulnerability."
16066| [CVE-2013-1279] Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages incorrect handling of objects in memory, aka "Kernel Race Condition Vulnerability," a different vulnerability than CVE-2013-1278.
16067| [CVE-2013-1278] Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages incorrect handling of objects in memory, aka "Kernel Race Condition Vulnerability," a different vulnerability than CVE-2013-1279.
16068| [CVE-2013-1277] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
16069| [CVE-2013-1276] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
16070| [CVE-2013-1275] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
16071| [CVE-2013-1274] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
16072| [CVE-2013-1273] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
16073| [CVE-2013-1272] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
16074| [CVE-2013-1271] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
16075| [CVE-2013-1270] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
16076| [CVE-2013-1269] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
16077| [CVE-2013-1268] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
16078| [CVE-2013-1267] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
16079| [CVE-2013-1266] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
16080| [CVE-2013-1265] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
16081| [CVE-2013-1264] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
16082| [CVE-2013-1263] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
16083| [CVE-2013-1262] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
16084| [CVE-2013-1261] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
16085| [CVE-2013-1260] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
16086| [CVE-2013-1259] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
16087| [CVE-2013-1258] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
16088| [CVE-2013-1257] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
16089| [CVE-2013-1256] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
16090| [CVE-2013-1255] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
16091| [CVE-2013-1254] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
16092| [CVE-2013-1253] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
16093| [CVE-2013-1252] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
16094| [CVE-2013-1251] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
16095| [CVE-2013-1250] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
16096| [CVE-2013-1249] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
16097| [CVE-2013-1248] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
16098| [CVE-2013-0095] Outlook in Microsoft Office for Mac 2008 before 12.3.6 and Office for Mac 2011 before 14.3.2 allows remote attackers to trigger access to a remote URL and consequently confirm the rendering of an HTML e-mail message by including unspecified HTML5 elements and leveraging the installation of a WebKit browser on the victim's machine, aka "Unintended Content Loading Vulnerability."
16099| [CVE-2013-0077] Quartz.dll in DirectShow in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows remote attackers to execute arbitrary code via crafted media content in (1) a media file, (2) a media stream, or (3) a Microsoft Office document, aka "Media Decompression Vulnerability."
16100| [CVE-2013-0076] The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Reference Count Vulnerability."
16101| [CVE-2013-0075] The TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (reboot) via a crafted packet that terminates a TCP connection, aka "TCP FIN WAIT Vulnerability."
16102| [CVE-2013-0073] The Windows Forms (aka WinForms) component in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly restrict the privileges of a callback function during object creation, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "WinForms Callback Elevation Vulnerability."
16103| [CVE-2013-0013] The SSL provider component in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle encrypted packets, which allows man-in-the-middle attackers to conduct SSLv2 downgrade attacks against (1) SSLv3 sessions or (2) TLS sessions by intercepting handshakes and injecting content, aka "Microsoft SSL Version 3 and TLS Protocol Security Feature Bypass Vulnerability."
16104| [CVE-2013-0011] The Print Spooler in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted print job, aka "Windows Print Spooler Components Vulnerability."
16105| [CVE-2013-0010] Cross-site scripting (XSS) vulnerability in Microsoft System Center Operations Manager 2007 SP1 and R2 allows remote attackers to inject arbitrary web script or HTML via crafted input, aka "System Center Operations Manager Web Console XSS Vulnerability," a different vulnerability than CVE-2013-0009.
16106| [CVE-2013-0009] Cross-site scripting (XSS) vulnerability in Microsoft System Center Operations Manager 2007 SP1 and R2 allows remote attackers to inject arbitrary web script or HTML via crafted input, aka "System Center Operations Manager Web Console XSS Vulnerability," a different vulnerability than CVE-2013-0010.
16107| [CVE-2013-0008] win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle window broadcast messages, which allows local users to gain privileges via a crafted application, aka "Win32k Improper Message Handling Vulnerability."
16108| [CVE-2013-0004] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate the permissions of objects in memory, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "Double Construction Vulnerability."
16109| [CVE-2013-0003] Buffer overflow in a System.DirectoryServices.Protocols (S.DS.P) namespace method in Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a missing array-size check during a memory copy operation, aka "S.DS.P Buffer Overflow Vulnerability."
16110| [CVE-2013-0002] Buffer overflow in the Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages improper counting of objects during a memory copy operation, aka "WinForms Buffer Overflow Vulnerability."
16111| [CVE-2013-0001] The Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 4, and 4.5 does not properly initialize memory arrays, which allows remote attackers to obtain sensitive information via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a pointer to an unmanaged memory location, aka "System Drawing Information Disclosure Vulnerability."
16112| [CVE-2012-5672] Microsoft Excel Viewer (aka Xlview.exe) and Excel in Microsoft Office 2007 (aka Office 12) allow remote attackers to cause a denial of service (read access violation and application crash) via a crafted spreadsheet file, as demonstrated by a .xls file with battery voltage data.
16113| [CVE-2012-4791] Microsoft Exchange Server 2007 SP3 and 2010 SP1 and SP2 allows remote authenticated users to cause a denial of service (Information Store service hang) by subscribing to a crafted RSS feed, aka "RSS Feed May Cause Exchange DoS Vulnerability."
16114| [CVE-2012-4786] The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allow remote attackers to execute arbitrary code via a crafted TrueType Font (TTF) file, aka "TrueType Font Parsing Vulnerability."
16115| [CVE-2012-4776] The Web Proxy Auto-Discovery (WPAD) functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not validate configuration data that is returned during acquisition of proxy settings, which allows remote attackers to execute arbitrary JavaScript code by providing crafted data during execution of (1) an XAML browser application (aka XBAP) or (2) a .NET Framework application, aka "Web Proxy Auto-Discovery Vulnerability."
16116| [CVE-2012-4774] Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allow remote attackers to execute arbitrary code via a crafted (1) file name or (2) subfolder name that triggers use of unallocated memory as the destination of a copy operation, aka "Windows Filename Parsing Vulnerability."
16117| [CVE-2012-2897] The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT, as used by Google Chrome before 22.0.1229.79 and other programs, do not properly handle objects in memory, which allows remote attackers to execute arbitrary code via a crafted TrueType font file, aka "Windows Font Parsing Vulnerability" or "TrueType Font Parsing Vulnerability."
16118| [CVE-2012-2556] The OpenType Font (OTF) driver in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to execute arbitrary code via a crafted OpenType font file, aka "OpenType Font Parsing Vulnerability."
16119| [CVE-2012-2553] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application, aka "Win32k Use After Free Vulnerability."
16120| [CVE-2012-2552] Cross-site scripting (XSS) vulnerability in the SQL Server Report Manager in Microsoft SQL Server 2000 Reporting Services SP2 and SQL Server 2005 SP4, 2008 SP2 and SP3, 2008 R2 SP1, and 2012 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "Reflected XSS Vulnerability."
16121| [CVE-2012-2551] The server in Kerberos in Microsoft Windows Server 2008 R2 and R2 SP1, and Windows 7 Gold and SP1, allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via a crafted session request, aka "Kerberos NULL Dereference Vulnerability."
16122| [CVE-2012-2543] Stack-based buffer overflow in Microsoft Excel 2007 SP2 and SP3 and 2010 SP1
16123| [CVE-2012-2539] Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1
16124| [CVE-2012-2536] Cross-site scripting (XSS) vulnerability in Microsoft Systems Management Server 2003 SP3 and System Center Configuration Manager 2007 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Reflected XSS Vulnerability."
16125| [CVE-2012-2530] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application, aka "Win32k Use After Free Vulnerability."
16126| [CVE-2012-2529] Integer overflow in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Windows Kernel Integer Overflow Vulnerability."
16127| [CVE-2012-2528] Use-after-free vulnerability in Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1
16128| [CVE-2012-2527] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application, aka "Win32k Use After Free Vulnerability."
16129| [CVE-2012-2524] Microsoft Office 2007 SP2 and SP3 and 2010 SP1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Computer Graphics Metafile (CGM) file, aka "CGM File Format Memory Corruption Vulnerability."
16130| [CVE-2012-2520] Cross-site scripting (XSS) vulnerability in Microsoft InfoPath 2007 SP2 and SP3 and 2010 SP1, Communicator 2007 R2, Lync 2010 and 2010 Attendee, SharePoint Server 2007 SP2 and SP3 and 2010 SP1, Groove Server 2010 SP1, Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010 SP1, and Office Web Apps 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted string, aka "HTML Sanitization Vulnerability."
16131| [CVE-2012-2519] Untrusted search path vulnerability in Entity Framework in ADO.NET in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, and 4 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .NET application, aka ".NET Framework Insecure Library Loading Vulnerability."
16132| [CVE-2012-1896] Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly consider trust levels during construction of output data, which allows remote attackers to obtain sensitive information via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka "Code Access Security Info Disclosure Vulnerability."
16133| [CVE-2012-1895] The reflection implementation in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4 does not properly enforce object permissions, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka "Reflection Bypass Vulnerability."
16134| [CVE-2012-1893] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate callback parameters during creation of a hook procedure, which allows local users to gain privileges via a crafted application, aka "Win32k Incorrect Type Handling Vulnerability."
16135| [CVE-2012-1890] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle keyboard-layout files, which allows local users to gain privileges via a crafted application, aka "Keyboard Layout Vulnerability."
16136| [CVE-2012-1887] Use-after-free vulnerability in Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 SP1, and Office 2008 and 2011 for Mac, allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel SST Invalid Length Use After Free Vulnerability."
16137| [CVE-2012-1886] Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 SP1
16138| [CVE-2012-1885] Heap-based buffer overflow in Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 SP1
16139| [CVE-2012-1870] The CBC mode in the TLS protocol, as used in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and other products, allows remote web servers to obtain plaintext data by triggering multiple requests to a third-party HTTPS server and sniffing the network during the resulting HTTPS session, aka "TLS Protocol Vulnerability."
16140| [CVE-2012-1867] Integer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted TrueType font file that triggers incorrect memory allocation, aka "Font Resource Refcount Integer Overflow Vulnerability."
16141| [CVE-2012-1866] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle user-mode input passed to kernel mode for driver objects, which allows local users to gain privileges via a crafted application, aka "Clipboard Format Atom Name Handling Vulnerability."
16142| [CVE-2012-1865] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle user-mode input passed to kernel mode for driver objects, which allows local users to gain privileges via a crafted application, aka "String Atom Class Name Handling Vulnerability," a different vulnerability than CVE-2012-1864.
16143| [CVE-2012-1864] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle user-mode input passed to kernel mode for driver objects, which allows local users to gain privileges via a crafted application, aka "String Atom Class Name Handling Vulnerability," a different vulnerability than CVE-2012-1865.
16144| [CVE-2012-1863] Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2007 SP2 and SP3 Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "SharePoint Reflected List Parameter Vulnerability."
16145| [CVE-2012-1862] Open redirect vulnerability in Microsoft Office SharePoint Server 2007 SP2 and SP3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka "SharePoint URL Redirection Vulnerability."
16146| [CVE-2012-1860] Microsoft Office SharePoint Server 2007 SP2 and SP3, SharePoint Server 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 do not properly check permissions for search scopes, which allows remote authenticated users to obtain sensitive information or cause a denial of service (data modification) by changing a parameter in a search-scope URL, aka "SharePoint Search Scope Vulnerability."
16147| [CVE-2012-1858] The toStaticHTML API (aka the SafeHTML component) in Microsoft Internet Explorer 8 and 9, Communicator 2007 R2, and Lync 2010 and 2010 Attendee does not properly handle event attributes and script, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted HTML document, aka "HTML Sanitization Vulnerability."
16148| [CVE-2012-1856] The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Server 2000 SP4, SQL Server 2005 SP4, SQL Server 2008 SP2, SP3, R2, R2 SP1, and R2 SP2, Commerce Server 2002 SP4, Commerce Server 2007 SP2, Commerce Server 2009 Gold and R2, Host Integration Server 2004 SP1, Visual FoxPro 8.0 SP1, Visual FoxPro 9.0 SP2, and Visual Basic 6.0 Runtime allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption, aka "MSCOMCTL.OCX RCE Vulnerability."
16149| [CVE-2012-1855] Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly handle function pointers, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka ".NET Framework Memory Access Vulnerability."
16150| [CVE-2012-1854] Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1
16151| [CVE-2012-1851] Format string vulnerability in the Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted response, aka "Print Spooler Service Format String Vulnerability."
16152| [CVE-2012-1850] The Remote Administration Protocol (RAP) implementation in the LanmanWorkstation service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle RAP responses, which allows remote attackers to cause a denial of service (service hang) via crafted RAP packets, aka "Remote Administration Protocol Denial of Service Vulnerability."
16153| [CVE-2012-1848] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly handle user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Scrollbar Calculation Vulnerability."
16154| [CVE-2012-1847] Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1
16155| [CVE-2012-1537] Heap-based buffer overflow in DirectPlay in DirectX 9.0 through 11.1 in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 allows remote attackers to execute arbitrary code via a crafted Office document, aka "DirectPlay Heap Overflow Vulnerability."
16156| [CVE-2012-1528] Integer overflow in Windows Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 allows local users to gain privileges via a crafted briefcase, aka "Windows Briefcase Integer Overflow Vulnerability."
16157| [CVE-2012-1527] Integer underflow in Windows Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 allows local users to gain privileges via a crafted briefcase, aka "Windows Briefcase Integer Underflow Vulnerability."
16158| [CVE-2012-1459] The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, nProtect Anti-Virus 2011-01-17.01, Panda Antivirus 10.0.2.7, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field corresponding to that entire entry, plus part of the header of the next entry. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
16159| [CVE-2012-1457] The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field that exceeds the total TAR file size. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
16160| [CVE-2012-1453] The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Trend Micro AntiVirus 9.120.0.1004, McAfee Gateway (formerly Webwasher) 2010.1C, Emsisoft Anti-Malware 5.1.0.1, CA eTrust Vet Antivirus 36.1.8511, Antiy Labs AVL SDK 2.0.3.7, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Rising Antivirus 22.83.00.03, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via a CAB file with a modified coffFiles field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.
16161| [CVE-2012-1443] The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Command Antivirus 5.2.11.5, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Emsisoft Anti-Malware 5.1.0.1, PC Tools AntiVirus 7.0.3.5, F-Prot Antivirus 4.6.2.117, VirusBuster 13.6.151.0, Fortinet Antivirus 4.2.254.0, Antiy Labs AVL SDK 2.0.3.7, K7 AntiVirus 9.77.3565, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Jiangmin Antivirus 13.0.900, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Sophos Anti-Virus 4.61.0, NOD32 Antivirus 5795, Avira AntiVir 7.11.1.163, Norman Antivirus 6.06.12, McAfee Anti-Virus Scanning Engine 5.400.0.1158, Panda Antivirus 10.0.2.7, McAfee Gateway (formerly Webwasher) 2010.1C, Trend Micro AntiVirus 9.120.0.1004, Comodo Antivirus 7424, Bitdefender 7.2, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, nProtect Anti-Virus 2011-01-17.01, AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, avast! Antivirus 4.8.1351.0 and 5.0.677.0, and VBA32 3.12.14.2 allows user-assisted remote attackers to bypass malware detection via a RAR file with an initial MZ character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different RAR parser implementations.
16162| [CVE-2012-1420] The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Panda Antivirus 10.0.2.7, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial \7fELF character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
16163| [CVE-2012-1194] The resolver in the DNS Server service in Microsoft Windows Server 2008 before R2 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack.
16164| [CVE-2012-0185] Heap-based buffer overflow in Microsoft Excel 2007 SP2 and SP3 and 2010 Gold and SP1, Excel Viewer, and Office Compatibility Pack SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet that triggers incorrect handling of memory during opening, aka "Excel MergeCells Record Heap Overflow Vulnerability."
16165| [CVE-2012-0184] Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1
16166| [CVE-2012-0183] Microsoft Word 2003 SP3 and 2007 SP2 and SP3, Office 2008 and 2011 for Mac, and Office Compatibility Pack SP2 and SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, aka "RTF Mismatch Vulnerability."
16167| [CVE-2012-0182] Microsoft Word 2007 SP2 and SP3 does not properly handle memory during the parsing of Word documents, which allows remote attackers to execute arbitrary code via a crafted document, aka "Word PAPX Section Corruption Vulnerability."
16168| [CVE-2012-0181] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly manage Keyboard Layout files, which allows local users to gain privileges via a crafted application, aka "Keyboard Layout File Vulnerability."
16169| [CVE-2012-0180] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly handle user-mode input passed to kernel mode for (1) windows and (2) messages, which allows local users to gain privileges via a crafted application, aka "Windows and Messages Vulnerability."
16170| [CVE-2012-0179] Double free vulnerability in tcpip.sys in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that binds an IPv6 address to a local interface, aka "TCP/IP Double Free Vulnerability."
16171| [CVE-2012-0178] Race condition in partmgr.sys in Windows Partition Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that makes multiple simultaneous Plug and Play (PnP) Configuration Manager function calls, aka "Plug and Play (PnP) Configuration Manager Vulnerability."
16172| [CVE-2012-0177] Heap-based buffer overflow in the Office Works File Converter in Microsoft Office 2007 SP2, Works 9, and Works 6-9 File Converter allows remote attackers to execute arbitrary code via a crafted Works (aka .wps) file, aka "Office WPS Converter Heap Overflow Vulnerability."
16173| [CVE-2012-0175] The Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted name for a (1) file or (2) directory, aka "Command Injection Vulnerability."
16174| [CVE-2012-0174] Windows Firewall in tcpip.sys in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly enforce firewall rules for outbound broadcast packets, which allows remote attackers to obtain potentially sensitive information by observing broadcast traffic on a local network, aka "Windows Firewall Bypass Vulnerability."
16175| [CVE-2012-0173] The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process packets in memory, which allows remote attackers to execute arbitrary code by sending crafted RDP packets triggering access to an object that (1) was not properly initialized or (2) is deleted, aka "Remote Desktop Protocol Vulnerability," a different vulnerability than CVE-2012-0002.
16176| [CVE-2012-0167] Heap-based buffer overflow in the Office GDI+ library in Microsoft Office 2003 SP3 and 2007 SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted EMF image in an Office document, aka "GDI+ Heap Overflow Vulnerability."
16177| [CVE-2012-0165] GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2 and Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1 does not properly validate record types in EMF images, which allows remote attackers to execute arbitrary code via a crafted image, aka "GDI+ Record Type Vulnerability."
16178| [CVE-2012-0163] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate function parameters, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka ".NET Framework Parameter Validation Vulnerability."
16179| [CVE-2012-0161] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly handle an unspecified exception during use of partially trusted assemblies to serialize input data, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka ".NET Framework Serialization Vulnerability."
16180| [CVE-2012-0160] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly serialize input data, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka ".NET Framework Serialization Vulnerability."
16181| [CVE-2012-0159] Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview
16182| [CVE-2012-0158] The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1
16183| [CVE-2012-0157] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle window messaging, which allows local users to gain privileges via a crafted application that calls the PostMessage function, aka "PostMessage Function Vulnerability."
16184| [CVE-2012-0156] DirectWrite in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly render Unicode characters, which allows remote attackers to cause a denial of service (application hang) via a (1) instant message or (2) web site, aka "DirectWrite Application Denial of Service Vulnerability."
16185| [CVE-2012-0154] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers keyboard layout errors, aka "Keyboard Layout Use After Free Vulnerability."
16186| [CVE-2012-0152] The Remote Desktop Protocol (RDP) service in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (application hang) via a series of crafted packets, aka "Terminal Server Denial of Service Vulnerability."
16187| [CVE-2012-0151] The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to execute arbitrary code via a modified file with additional content, aka "WinVerifyTrust Signature Validation Vulnerability."
16188| [CVE-2012-0150] Buffer overflow in msvcrt.dll in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted media file, aka "Msvcrt.dll Buffer Overflow Vulnerability."
16189| [CVE-2012-0149] afd.sys in the Ancillary Function Driver in Microsoft Windows Server 2003 SP2 does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."
16190| [CVE-2012-0148] afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 on 64-bit platforms does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "AfdPoll Elevation of Privilege Vulnerability."
16191| [CVE-2012-0143] Microsoft Excel 2003 SP3 and Office 2008 for Mac do not properly handle memory during the opening of files, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Memory Corruption Using Various Modified Bytes Vulnerability."
16192| [CVE-2012-0142] Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1
16193| [CVE-2012-0141] Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1
16194| [CVE-2012-0015] Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly calculate the length of an unspecified buffer, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka ".NET Framework Heap Corruption Vulnerability."
16195| [CVE-2012-0014] Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.1.10111, does not properly restrict access to memory associated with unmanaged objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4) a crafted Silverlight application, aka ".NET Framework Unmanaged Objects Vulnerability."
16196| [CVE-2012-0013] Incomplete blacklist vulnerability in the Windows Packager configuration in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted ClickOnce application in a Microsoft Office document, related to .application files, aka "Assembly Execution Vulnerability."
16197| [CVE-2012-0009] Untrusted search path vulnerability in the Windows Object Packager configuration in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a Trojan horse executable file in the current working directory, as demonstrated by a directory that contains a file with an embedded packaged object, aka "Object Packager Insecure Executable Launching Vulnerability."
16198| [CVE-2012-0008] Untrusted search path vulnerability in Microsoft Visual Studio 2008 SP1, 2010, and 2010 SP1 allows local users to gain privileges via a Trojan horse add-in in an unspecified directory, aka "Visual Studio Add-In Vulnerability."
16199| [CVE-2012-0006] The DNS server in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 does not properly handle objects in memory during record lookup, which allows remote attackers to cause a denial of service (daemon restart) via a crafted query, aka "DNS Denial of Service Vulnerability."
16200| [CVE-2012-0005] The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2, when a Chinese, Japanese, or Korean system locale is used, can access uninitialized memory during the processing of Unicode characters, which allows local users to gain privileges via a crafted application, aka "CSRSS Elevation of Privilege Vulnerability."
16201| [CVE-2012-0004] Unspecified vulnerability in DirectShow in DirectX in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted media file, related to Quartz.dll, Qdvd.dll, closed captioning, and the Line21 DirectShow filter, aka "DirectShow Remote Code Execution Vulnerability."
16202| [CVE-2012-0003] Unspecified vulnerability in winmm.dll in Windows Multimedia Library in Windows Media Player (WMP) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows remote attackers to execute arbitrary code via a crafted MIDI file, aka "MIDI Remote Code Execution Vulnerability."
16203| [CVE-2012-0002] The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process packets in memory, which allows remote attackers to execute arbitrary code by sending crafted RDP packets triggering access to an object that (1) was not properly initialized or (2) is deleted, aka "Remote Desktop Protocol Vulnerability."
16204| [CVE-2012-0001] The kernel in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly load structured exception handling tables, which allows context-dependent attackers to bypass the SafeSEH security feature by leveraging a Visual C++ .NET 2003 application, aka "Windows Kernel SafeSEH Bypass Vulnerability."
16205| [CVE-2011-5046] The Graphics Device Interface (GDI) in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted data, as demonstrated by a large height attribute of an IFRAME element rendered by Safari, aka "GDI Access Violation Vulnerability."
16206| [CVE-2011-4434] Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 do not properly enforce AppLocker rules, which allows local users to bypass intended access restrictions via a (1) macro or (2) scripting feature in an application, as demonstrated by Microsoft Office applications and the SANDBOX_INERT and LOAD_IGNORE_CODE_AUTHZ_LEVEL flags.
16207| [CVE-2011-3417] The Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0, when sliding expiry is enabled, does not properly handle cached content, which allows remote attackers to obtain access to arbitrary user accounts via a crafted URL, aka "ASP.NET Forms Authentication Ticket Caching Vulnerability."
16208| [CVE-2011-3416] The Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 allows remote authenticated users to obtain access to arbitrary user accounts via a crafted username, aka "ASP.Net Forms Authentication Bypass Vulnerability."
16209| [CVE-2011-3415] Open redirect vulnerability in the Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted return URL, aka "Insecure Redirect in .NET Form Authentication Vulnerability."
16210| [CVE-2011-3414] The CaseInsensitiveHashProvider.getHashCode function in the HashTable implementation in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters, aka "Collisions in HashTable May Cause DoS Vulnerability."
16211| [CVE-2011-3413] Microsoft PowerPoint 2007 SP2
16212| [CVE-2011-3412] Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, allows remote attackers to execute arbitrary code via a crafted Publisher file that leverages incorrect memory handling, aka "Publisher Memory Corruption Vulnerability."
16213| [CVE-2011-3411] Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that leverages incorrect handling of values in memory, aka "Publisher Invalid Pointer Vulnerability."
16214| [CVE-2011-3410] Array index error in Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, allows remote attackers to execute arbitrary code via a crafted Publisher file that leverages incorrect handling of values in memory, aka "Publisher Out-of-bounds Array Index Vulnerability."
16215| [CVE-2011-3408] Csrsrv.dll in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly check permissions for sending inter-process device-event messages from low-integrity processes to high-integrity processes, which allows local users to gain privileges via a crafted application, aka "CSRSS Local Privilege Elevation Vulnerability."
16216| [CVE-2011-3406] Buffer overflow in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote authenticated users to execute arbitrary code via a crafted query that leverages incorrect memory initialization, aka "Active Directory Buffer Overflow Vulnerability."
16217| [CVE-2011-3403] Microsoft Excel 2003 SP3 and Office 2004 for Mac do not properly handle objects in memory, which allows remote attackers to execute arbitrary code via a crafted Excel spreadsheet, aka "Record Memory Corruption Vulnerability."
16218| [CVE-2011-3402] Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via crafted font data in a Word document or web page, as exploited in the wild in November 2011 by Duqu, aka "TrueType Font Parsing Vulnerability."
16219| [CVE-2011-3400] Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 do not properly handle OLE objects in memory, which allows remote attackers to execute arbitrary code via a crafted object in a file, aka "OLE Property Vulnerability."
16220| [CVE-2011-3397] The Microsoft Time component in DATIME.DLL in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted web site that leverages an unspecified "binary behavior" in Internet Explorer, aka "Microsoft Time Remote Code Execution Vulnerability."
16221| [CVE-2011-3396] Untrusted search path vulnerability in Microsoft PowerPoint 2007 SP2 and 2010 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "PowerPoint Insecure Library Loading Vulnerability."
16222| [CVE-2011-2019] Untrusted search path vulnerability in Microsoft Internet Explorer 9 on Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains an HTML file, aka "Internet Explorer Insecure Library Loading Vulnerability."
16223| [CVE-2011-2018] The kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, and Windows 7 Gold and SP1 does not properly initialize objects, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Exception Handler Vulnerability."
16224| [CVE-2011-2016] Untrusted search path vulnerability in Windows Mail and Windows Meeting Space in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .eml or .wcinv file, aka "Windows Mail Insecure Library Loading Vulnerability."
16225| [CVE-2011-2014] The LDAP over SSL (aka LDAPS) implementation in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not examine Certificate Revocation Lists (CRLs), which allows remote authenticated users to bypass intended certificate restrictions and access Active Directory resources by leveraging a revoked X.509 certificate for a domain account, aka "LDAPS Authentication Bypass Vulnerability."
16226| [CVE-2011-2013] Integer overflow in the TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code by sending a sequence of crafted UDP packets to a closed port, aka "Reference Counter Overflow Vulnerability."
16227| [CVE-2011-2011] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, aka "Win32k Use After Free Vulnerability."
16228| [CVE-2011-2008] Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service outage) via crafted TCP or UDP traffic, aka "Access of Unallocated Memory DoS Vulnerability."
16229| [CVE-2011-2007] Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service outage) via crafted TCP or UDP traffic, aka "Endless Loop DoS in snabase.exe Vulnerability."
16230| [CVE-2011-2005] afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."
16231| [CVE-2011-2004] Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (reboot) via a crafted TrueType font file, aka "TrueType Font Parsing Vulnerability," a different vulnerability than CVE-2011-3402.
16232| [CVE-2011-2003] Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted .fon file, aka "Font Library File Buffer Overrun Vulnerability."
16233| [CVE-2011-2002] win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle TrueType fonts, which allows local users to cause a denial of service (system hang) via a crafted font file, aka "Win32k TrueType Font Type Translation Vulnerability."
16234| [CVE-2011-1991] Multiple untrusted search path vulnerabilities in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allow local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .doc, .rtf, or .txt file, related to (1) deskpan.dll in the Display Panning CPL Extension, (2) EAPHost Authenticator Service, (3) Folder Redirection, (4) HyperTerminal, (5) the Japanese Input Method Editor (IME), and (6) Microsoft Management Console (MMC), aka "Windows Components Insecure Library Loading Vulnerability."
16235| [CVE-2011-1990] Microsoft Excel 2007 SP2
16236| [CVE-2011-1989] Microsoft Excel 2003 SP3 and 2007 SP2
16237| [CVE-2011-1988] Microsoft Excel 2003 SP3 and 2007 SP2
16238| [CVE-2011-1987] Array index error in Microsoft Excel 2003 SP3 and 2007 SP2
16239| [CVE-2011-1986] Use-after-free vulnerability in Microsoft Excel 2003 SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Use after Free WriteAV Vulnerability."
16240| [CVE-2011-1985] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via a crafted application, aka "Win32k Null Pointer De-reference Vulnerability."
16241| [CVE-2011-1984] WINS in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 allows local users to gain privileges by sending crafted packets over the loopback interface, aka "WINS Local Elevation of Privilege Vulnerability."
16242| [CVE-2011-1983] Use-after-free vulnerability in Microsoft Office 2007 SP2 and SP3, Office 2010 Gold and SP1, and Office for Mac 2011 allows remote attackers to execute arbitrary code via a crafted Word document, aka "Word Use After Free Vulnerability."
16243| [CVE-2011-1982] Microsoft Office 2007 SP2, and 2010 Gold and SP1, does not initialize an unspecified object pointer during the opening of Word documents, which allows remote attackers to execute arbitrary code via a crafted document, aka "Office Uninitialized Object Pointer Vulnerability."
16244| [CVE-2011-1980] Untrusted search path vulnerability in Microsoft Office 2003 SP3 and 2007 SP2 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .doc, .ppt, or .xls file, aka "Office Component Insecure Library Loading Vulnerability."
16245| [CVE-2011-1979] Microsoft Visio 2003 SP3 and 2007 SP2 does not properly validate objects in memory during Visio file parsing, which allows remote attackers to execute arbitrary code via a crafted file, aka "Move Around the Block RCE Vulnerability."
16246| [CVE-2011-1978] Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4 does not properly validate the System.Net.Sockets trust level, which allows remote attackers to obtain sensitive information or trigger arbitrary outbound network traffic via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Socket Restriction Bypass Vulnerability."
16247| [CVE-2011-1976] Cross-site scripting (XSS) vulnerability in the Report Viewer Control in Microsoft Visual Studio 2005 SP1 and Report Viewer 2005 SP1 allows remote attackers to inject arbitrary web script or HTML via a parameter in a data source, aka "Report Viewer Controls XSS Vulnerability."
16248| [CVE-2011-1975] Untrusted search path vulnerability in the Data Access Tracing component in Windows Data Access Components (Windows DAC) 6.0 in Microsoft Windows 7 Gold and SP1 and Windows Server 2008 R2 and R2 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains an Excel .xlsx file, aka "Data Access Components Insecure Library Loading Vulnerability."
16249| [CVE-2011-1974] NDISTAPI.sys in the NDISTAPI driver in Remote Access Service (RAS) in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "NDISTAPI Elevation of Privilege Vulnerability."
16250| [CVE-2011-1972] Microsoft Visio 2003 SP3, 2007 SP2, and 2010 Gold and SP1 does not properly validate objects in memory during Visio file parsing, which allows remote attackers to execute arbitrary code via a crafted file, aka "pStream Release RCE Vulnerability."
16251| [CVE-2011-1971] The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly parse file metadata, which allows local users to cause a denial of service (reboot) via a crafted file, aka "Windows Kernel Metadata Parsing DOS Vulnerability."
16252| [CVE-2011-1970] The DNS server in Microsoft Windows Server 2003 SP2 and Windows Server 2008 SP2, R2, and R2 SP1 does not properly initialize memory, which allows remote attackers to cause a denial of service (service outage) via a query for a nonexistent domain, aka "DNS Uninitialized Memory Corruption Vulnerability."
16253| [CVE-2011-1968] The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 does not properly process packets in memory, which allows remote attackers to cause a denial of service (reboot) by sending crafted RDP packets triggering access to an object that (1) was not properly initialized or (2) is deleted, as exploited in the wild in 2011, aka "Remote Desktop Protocol Vulnerability."
16254| [CVE-2011-1967] Winsrv.dll in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly check permissions for sending inter-process device-event messages from low-integrity processes to high-integrity processes, which allows local users to gain privileges via a crafted application, aka "CSRSS Vulnerability."
16255| [CVE-2011-1966] The DNS server in Microsoft Windows Server 2008 SP2, R2, and R2 SP1 does not properly handle NAPTR queries that trigger recursive processing, which allows remote attackers to execute arbitrary code via a crafted query, aka "DNS NAPTR Query Vulnerability."
16256| [CVE-2011-1965] Tcpip.sys in the TCP/IP stack in Microsoft Windows 7 Gold and SP1 and Windows Server 2008 R2 and R2 SP1 does not properly implement URL-based QoS, which allows remote attackers to cause a denial of service (reboot) via a crafted URL to a web server, aka "TCP/IP QOS Denial of Service Vulnerability."
16257| [CVE-2011-1894] The MHTML protocol handler in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle a MIME format in a request for embedded content in an HTML document, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted EMBED element in a web page that is visited in Internet Explorer, aka "MHTML Mime-Formatted Request Vulnerability."
16258| [CVE-2011-1893] Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2010, Windows SharePoint Services 2.0 and 3.0 SP2, and SharePoint Foundation 2010 allows remote attackers to inject arbitrary web script or HTML via the URI, aka "SharePoint XSS Vulnerability."
16259| [CVE-2011-1892] Microsoft Office Groove 2007 SP2, SharePoint Workspace 2010 Gold and SP1, Office Forms Server 2007 SP2, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Office Groove Data Bridge Server 2007 SP2, Office Groove Management Server 2007 SP2, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, and Office Web Apps 2010 Gold and SP1 do not properly handle Web Parts containing XML classes referencing external entities, which allows remote authenticated users to read arbitrary files via a crafted XML and XSL file, aka "SharePoint Remote File Disclosure Vulnerability."
16260| [CVE-2011-1888] win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Null Pointer De-reference Vulnerability."
16261| [CVE-2011-1887] win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Null Pointer De-reference Vulnerability."
16262| [CVE-2011-1885] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Null Pointer De-reference Vulnerability."
16263| [CVE-2011-1884] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
16264| [CVE-2011-1883] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
16265| [CVE-2011-1882] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
16266| [CVE-2011-1881] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Null Pointer De-reference Vulnerability."
16267| [CVE-2011-1880] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Null Pointer De-reference Vulnerability."
16268| [CVE-2011-1879] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
16269| [CVE-2011-1878] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
16270| [CVE-2011-1877] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, aka "Win32k Use After Free Vulnerability."
16271| [CVE-2011-1876] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
16272| [CVE-2011-1875] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
16273| [CVE-2011-1874] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
16274| [CVE-2011-1873] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 on 64-bit platforms does not properly validate pointers during the parsing of OpenType (aka OTF) fonts, which allows remote attackers to execute arbitrary code via a crafted font file, aka "Win32k OTF Validation Vulnerability."
16275| [CVE-2011-1872] Hyper-V in Microsoft Windows Server 2008 Gold, SP2, R2, and R2 SP1 allows guest OS users to cause a denial of service (host OS infinite loop) via malformed machine instructions in a VMBus packet, aka "VMBus Persistent DoS Vulnerability."
16276| [CVE-2011-1871] Tcpip.sys in the TCP/IP stack in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (reboot) via a series of crafted ICMP messages, aka "ICMP Denial of Service Vulnerability."
16277| [CVE-2011-1870] Integer overflow in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP SrvWriteConsoleOutputString Vulnerability."
16278| [CVE-2011-1869] The Distributed File System (DFS) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote DFS servers to cause a denial of service (system hang) via a crafted referral response, aka "DFS Referral Response Vulnerability."
16279| [CVE-2011-1868] The Distributed File System (DFS) implementation in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate fields in DFS responses, which allows remote DFS servers to execute arbitrary code via a crafted response, aka "DFS Memory Corruption Vulnerability."
16280| [CVE-2011-1508] Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, does not properly manage memory allocations for function pointers, which allows user-assisted remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Function Pointer Overwrite Vulnerability."
16281| [CVE-2011-1284] Integer overflow in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP SrvWriteConsoleOutput Vulnerability."
16282| [CVE-2011-1283] The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2 does not ensure that an unspecified array index has a non-negative value before performing read and write operations, which allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP SrvSetConsoleNumberOfCommand Vulnerability."
16283| [CVE-2011-1282] The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly initialize memory and consequently uses a NULL pointer in an unspecified function call, which allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP SrvSetConsoleLocalEUDC Vulnerability."
16284| [CVE-2011-1281] The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly restrict the number of console objects for a process, which allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP AllocConsole Vulnerability."
16285| [CVE-2011-1280] The XML Editor in Microsoft InfoPath 2007 SP2 and 2010
16286| [CVE-2011-1279] Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel Out of Bounds WriteAV Vulnerability."
16287| [CVE-2011-1278] Microsoft Excel 2002 SP3 and Office 2004 for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel WriteAV Vulnerability."
16288| [CVE-2011-1277] Microsoft Excel 2002 SP3, Office 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel Memory Corruption Vulnerability."
16289| [CVE-2011-1276] Buffer overflow in Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2
16290| [CVE-2011-1275] Microsoft Excel 2002 SP3
16291| [CVE-2011-1274] Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2
16292| [CVE-2011-1273] Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010
16293| [CVE-2011-1272] Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2
16294| [CVE-2011-1270] Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "Presentation Buffer Overrun RCE Vulnerability."
16295| [CVE-2011-1269] Microsoft PowerPoint 2002 SP3, 2003 SP3, and 2007 SP2
16296| [CVE-2011-1268] The SMB client in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote SMB servers to execute arbitrary code via a crafted (1) SMBv1 or (2) SMBv2 response, aka "SMB Response Parsing Vulnerability."
16297| [CVE-2011-1267] The SMB server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (system hang) via a crafted (1) SMBv1 or (2) SMBv2 request, aka "SMB Request Parsing Vulnerability."
16298| [CVE-2011-1264] Cross-site scripting (XSS) vulnerability in Active Directory Certificate Services Web Enrollment in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, R2, and R2 SP1 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "Active Directory Certificate Services Vulnerability."
16299| [CVE-2011-1263] Cross-site scripting (XSS) vulnerability in the logon page in Remote Desktop Web Access (RD Web Access) in Microsoft Windows Server 2008 R2 and R2 SP1 allows remote attackers to inject arbitrary web script or HTML via the URI, aka "Remote Desktop Web Access Vulnerability."
16300| [CVE-2011-1253] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.0.60831, does not properly restrict inheritance, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4) a crafted Silverlight application, aka ".NET Framework Class Inheritance Vulnerability."
16301| [CVE-2011-1252] Cross-site scripting (XSS) vulnerability in the SafeHTML function in the toStaticHTML API in Microsoft Internet Explorer 7 and 8, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified strings, aka "toStaticHTML Information Disclosure Vulnerability" or "HTML Sanitization Vulnerability."
16302| [CVE-2011-1249] The Ancillary Function Driver (AFD) in afd.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."
16303| [CVE-2011-1248] WINS in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, R2, and R2 SP1 does not properly handle socket send exceptions, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted packets, related to unintended stack-frame values and buffer passing, aka "WINS Service Failed Response Vulnerability."
16304| [CVE-2011-1247] Untrusted search path vulnerability in the Microsoft Active Accessibility component in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "Active Accessibility Insecure Library Loading Vulnerability."
16305| [CVE-2011-1242] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
16306| [CVE-2011-1241] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
16307| [CVE-2011-1240] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
16308| [CVE-2011-1239] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
16309| [CVE-2011-1238] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
16310| [CVE-2011-1237] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
16311| [CVE-2011-1236] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
16312| [CVE-2011-1235] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
16313| [CVE-2011-1234] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
16314| [CVE-2011-1233] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
16315| [CVE-2011-1232] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
16316| [CVE-2011-1231] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
16317| [CVE-2011-1230] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
16318| [CVE-2011-1229] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
16319| [CVE-2011-1228] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
16320| [CVE-2011-1227] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
16321| [CVE-2011-1226] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
16322| [CVE-2011-1225] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
16323| [CVE-2011-0980] Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse Office Art objects, which allows remote attackers to execute arbitrary code via vectors related to a function pointer, aka "Excel Dangling Pointer Vulnerability."
16324| [CVE-2011-0979] Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010
16325| [CVE-2011-0978] Stack-based buffer overflow in Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2
16326| [CVE-2011-0977] Use-after-free vulnerability in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via malformed shape data in the Office drawing file format, aka "Microsoft Office Graphic Object Dereferencing Vulnerability."
16327| [CVE-2011-0976] Microsoft PowerPoint 2002 SP3, 2003 SP3, and 2007 SP2
16328| [CVE-2011-0677] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
16329| [CVE-2011-0676] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
16330| [CVE-2011-0675] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
16331| [CVE-2011-0674] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
16332| [CVE-2011-0672] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
16333| [CVE-2011-0671] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
16334| [CVE-2011-0670] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
16335| [CVE-2011-0667] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
16336| [CVE-2011-0666] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
16337| [CVE-2011-0665] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
16338| [CVE-2011-0664] Microsoft .NET Framework 2.0 SP1 and SP2, 3.5 Gold and SP1, 3.5.1, and 4.0, and Silverlight 4 before 4.0.60531.0, does not properly validate arguments to unspecified networking API functions, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4) a crafted Silverlight application, aka ".NET Framework Array Offset Vulnerability."
16339| [CVE-2011-0662] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
16340| [CVE-2011-0661] The SMB Server service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate fields in SMB requests, which allows remote attackers to execute arbitrary code via a malformed request in a (1) SMBv1 or (2) SMBv2 packet, aka "SMB Transaction Parsing Vulnerability."
16341| [CVE-2011-0660] The SMB client in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote SMB servers to execute arbitrary code via a crafted (1) SMBv1 or (2) SMBv2 response, aka "SMB Client Response Parsing Vulnerability."
16342| [CVE-2011-0658] Integer underflow in the OLE Automation protocol implementation in VBScript.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted WMF file, aka "OLE Automation Underflow Vulnerability."
16343| [CVE-2011-0657] DNSAPI.dll in the DNS client in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process DNS queries, which allows remote attackers to execute arbitrary code via (1) a crafted LLMNR broadcast query or (2) a crafted application, aka "DNS Query Vulnerability."
16344| [CVE-2011-0656] Microsoft PowerPoint 2002 SP3, 2003 SP3, 2007 SP2, and 2010
16345| [CVE-2011-0655] Microsoft PowerPoint 2007 SP2 and 2010
16346| [CVE-2011-0654] Integer underflow in the BowserWriteErrorLogEntry function in the Common Internet File System (CIFS) browser service in Mrxsmb.sys or bowser.sys in Active Directory in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via a malformed BROWSER ELECTION message, leading to a heap-based buffer overflow, aka "Browser Pool Corruption Vulnerability." NOTE: some of these details are obtained from third party information.
16347| [CVE-2011-0107] Untrusted search path vulnerability in Microsoft Office XP SP3, Office 2003 SP3, and Office 2007 SP2 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .docx file, aka "Office Component Insecure Library Loading Vulnerability."
16348| [CVE-2011-0105] Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac obtain a certain length value from an uninitialized memory location, which allows remote attackers to trigger a buffer overflow and execute arbitrary code via a crafted Excel file, aka "Excel Data Initialization Vulnerability."
16349| [CVE-2011-0104] Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HLink record in an Excel file, aka "Excel Buffer Overwrite Vulnerability."
16350| [CVE-2011-0103] Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted record information in an Excel file, aka "Excel Memory Corruption Vulnerability."
16351| [CVE-2011-0101] Microsoft Excel 2002 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted RealTimeData record, related to a stTopic field, doubly-byte characters, and an incorrect pointer calculation, aka "Excel Record Parsing WriteAV Vulnerability."
16352| [CVE-2011-0098] Integer signedness error in Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010
16353| [CVE-2011-0097] Integer underflow in Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010
16354| [CVE-2011-0096] The MHTML protocol handler in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle a MIME format in a request for content blocks in a document, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site that is visited in Internet Explorer, aka "MHTML Mime-Formatted Request Vulnerability."
16355| [CVE-2011-0093] ELEMENTS.DLL in Microsoft Visio 2002 SP2, 2003 SP3, and 2007 SP2 does not properly parse structures during the opening of a Visio file, which allows remote attackers to execute arbitrary code via a file containing a malformed structure, aka "Visio Data Type Memory Corruption Vulnerability."
16356| [CVE-2011-0092] The LZW stream decompression functionality in ORMELEMS.DLL in Microsoft Visio 2002 SP2, 2003 SP3, and 2007 SP2 allows remote attackers to execute arbitrary code via a Visio file with a malformed VisioDocument stream that triggers an exception handler that accesses an object that has not been fully initialized, which triggers memory corruption, aka "Visio Object Memory Corruption Vulnerability."
16357| [CVE-2011-0091] Kerberos in Microsoft Windows Server 2008 R2 and Windows 7 does not prevent a session from changing from strong encryption to DES encryption, which allows man-in-the-middle attackers to spoof network traffic and obtain sensitive information via a DES downgrade, aka "Kerberos Spoofing Vulnerability."
16358| [CVE-2011-0090] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Vulnerability."
16359| [CVE-2011-0089] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Window Class Improper Pointer Validation Vulnerability."
16360| [CVE-2011-0088] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Window Class Pointer Confusion Vulnerability."
16361| [CVE-2011-0087] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Insufficient User Input Validation Vulnerability."
16362| [CVE-2011-0086] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Improper User Input Validation Vulnerability."
16363| [CVE-2011-0043] Kerberos in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 supports weak hashing algorithms, which allows local users to gain privileges by operating a service that sends crafted service tickets, as demonstrated by the CRC32 algorithm, aka "Kerberos Unkeyed Checksum Vulnerability."
16364| [CVE-2011-0042] SBE.dll in the Stream Buffer Engine in Windows Media Player and Windows Media Center in Microsoft Windows XP SP2 and SP3, Windows XP Media Center Edition 2005 SP3, Windows Vista SP1 and SP2, Windows 7 Gold and SP1, and Windows Media Center TV Pack for Windows Vista does not properly parse Digital Video Recording (.dvr-ms) files, which allows remote attackers to execute arbitrary code via a crafted file, aka "DVR-MS Vulnerability."
16365| [CVE-2011-0041] Integer overflow in gdiplus.dll in GDI+ in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold and SP2, and Office XP SP3 allows remote attackers to execute arbitrary code via a crafted EMF image, aka "GDI+ Integer Overflow Vulnerability."
16366| [CVE-2011-0040] The server in Microsoft Active Directory on Windows Server 2003 SP2 does not properly handle an update request for a service principal name (SPN), which allows remote attackers to cause a denial of service (authentication downgrade or outage) via a crafted request that triggers name collisions, aka "Active Directory SPN Validation Vulnerability."
16367| [CVE-2011-0039] The Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly process authentication requests, which allows local users to gain privileges via a request with a crafted length, aka "LSASS Length Validation Vulnerability."
16368| [CVE-2011-0034] Stack-based buffer overflow in the OpenType Compact Font Format (aka OTF or CFF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via crafted parameter values in an OpenType font, aka "OpenType Font Stack Overflow Vulnerability."
16369| [CVE-2011-0033] The OpenType Compact Font Format (CFF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate parameter values in OpenType fonts, which allows remote attackers to execute arbitrary code via a crafted font, aka "OpenType Font Encoded Character Vulnerability."
16370| [CVE-2011-0032] Untrusted search path vulnerability in DirectShow in Microsoft Windows Vista SP1 and SP2, Windows 7 Gold and SP1, Windows Server 2008 R2 and R2 SP1, and Windows Media Center TV Pack for Windows Vista allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a Digital Video Recording (.dvr-ms), Windows Recorded TV Show (.wtv), or .mpg file, aka "DirectShow Insecure Library Loading Vulnerability."
16371| [CVE-2011-0031] The (1) JScript 5.8 and (2) VBScript 5.8 scripting engines in Microsoft Windows Server 2008 R2 and Windows 7 do not properly load decoded scripts obtained from web pages, which allows remote attackers to trigger memory corruption and consequently obtain sensitive information via a crafted web site, aka "Scripting Engines Information Disclosure Vulnerability."
16372| [CVE-2011-0030] The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly kill processes after a logout, which allows local users to obtain sensitive information or gain privileges via a crafted application that continues to execute throughout the logout of one user and the login session of the next user, aka "CSRSS Elevation of Privilege Vulnerability," a different vulnerability than CVE-2010-0023.
16373| [CVE-2011-0028] WordPad in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly parse fields in Word documents, which allows remote attackers to execute arbitrary code via a crafted .doc file, aka "WordPad Converter Parsing Vulnerability."
16374| [CVE-2010-5082] Untrusted search path vulnerability in colorcpl.exe 6.0.6000.16386 in the Color Control Panel in Microsoft Windows Server 2008 SP2, R2, and R2 SP1 allows local users to gain privileges via a Trojan horse sti.dll file in the current working directory, as demonstrated by a directory that contains a .camp, .cdmp, .gmmp, .icc, or .icm file, aka "Color Control Panel Insecure Library Loading Vulnerability."
16375| [CVE-2010-4701] Heap-based buffer overflow in the CDrawPoly::Serialize function in fxscover.exe in Microsoft Windows Fax Services Cover Page Editor 5.2 r2 in Windows XP Professional SP3, Server 2003 R2 Enterprise Edition SP2, and Windows 7 Professional allows remote attackers to execute arbitrary code via a long record in a Fax Cover Page (.cov) file. NOTE: some of these details are obtained from third party information.
16376| [CVE-2010-4669] The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Microsoft Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, and Windows 7 allows remote attackers to cause a denial of service (CPU consumption and system hang) by sending many Router Advertisement (RA) messages with different source addresses, as demonstrated by the flood_router6 program in the thc-ipv6 package.
16377| [CVE-2010-4562] Microsoft Windows 2008, 7, Vista, 2003, 2000, and XP, when using IPv6, allows remote attackers to determine whether a host is sniffing the network by sending an ICMPv6 Echo Request to a multicast address and determining whether an Echo Reply is sent, as demonstrated by thcping. NOTE: due to a typo, some sources map CVE-2010-4562 to a ProFTPd mod_sql vulnerability, but that issue is covered by CVE-2010-4652.
16378| [CVE-2010-4398] Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges, and bypass the User Account Control (UAC) feature, via a crafted REG_BINARY value for a SystemDefaultEUDCFont registry key, aka "Driver Improper Interaction with Windows Kernel Vulnerability."
16379| [CVE-2010-4182] Untrusted search path vulnerability in the Data Access Objects (DAO) library (dao360.dll) in Microsoft Windows XP Professional SP3, Windows Server 2003 R2 Enterprise Edition SP3, Windows Vista Business SP1, and Windows 7 Professional allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse msjet49.dll that is located in the same folder as a file that is processed by dao360.dll. NOTE: the provenance of this information is unknown
16380| [CVE-2010-3974] fxscover.exe in the Fax Cover Page Editor in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly parse FAX cover pages, which allows remote attackers to execute arbitrary code via a crafted .cov file, aka "Fax Cover Page Editor Memory Corruption Vulnerability."
16381| [CVE-2010-3970] Stack-based buffer overflow in the CreateSizedDIBSECTION function in shimgvw.dll in the Windows Shell graphics processor (aka graphics rendering engine) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted .MIC or unspecified Office document containing a thumbnail bitmap with a negative biClrUsed value, as reported by Moti and Xu Hao, aka "Windows Shell Graphics Processing Overrun Vulnerability."
16382| [CVE-2010-3966] Untrusted search path vulnerability in Microsoft Windows Server 2008 R2 and Windows 7, when BranchCache is supported, allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains an EML file, an RSS file, or a WPOST file, aka "BranchCache Insecure Library Loading Vulnerability."
16383| [CVE-2010-3965] Untrusted search path vulnerability in Windows Media Encoder 9 on Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a Windows Media Profile (PRX) file, aka "Insecure Library Loading Vulnerability."
16384| [CVE-2010-3964] Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Office SharePoint Server 2007 SP2, when the Document Conversions Load Balancer Service is enabled, allows remote attackers to execute arbitrary code via a crafted SOAP request to TCP port 8082, aka "Malformed Request Code Execution Vulnerability."
16385| [CVE-2010-3963] Buffer overflow in the Routing and Remote Access NDProxy component in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, related to the Routing and Remote Access service (RRAS) and improper copying from user mode to the kernel, aka "Kernel NDProxy Buffer Overflow Vulnerability."
16386| [CVE-2010-3961] The Consent User Interface (UI) in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly handle an unspecified registry-key value, which allows local users with SeImpersonatePrivilege rights to gain privileges via a crafted application, aka "Consent UI Impersonation Vulnerability."
16387| [CVE-2010-3960] Hyper-V in Microsoft Windows Server 2008 Gold, SP2, and R2 allows guest OS users to cause a denial of service (host OS hang) by sending a crafted encapsulated packet over the VMBus, aka "Hyper-V VMBus Vulnerability."
16388| [CVE-2010-3959] The OpenType Font (OTF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a crafted CMAP table in an OpenType font, aka "OpenType CMAP Table Vulnerability."
16389| [CVE-2010-3958] The x86 JIT compiler in Microsoft .NET Framework 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 does not properly compile function calls, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka ".NET Framework Stack Corruption Vulnerability."
16390| [CVE-2010-3957] Double free vulnerability in the OpenType Font (OTF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a crafted OpenType font, aka "OpenType Font Double Free Vulnerability."
16391| [CVE-2010-3956] The OpenType Font (OTF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly perform array indexing, which allows local users to gain privileges via a crafted OpenType font, aka "OpenType Font Index Vulnerability."
16392| [CVE-2010-3955] pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3 does not properly perform array indexing, which allows remote attackers to execute arbitrary code via a crafted Publisher file that uses an old file format, aka "Array Indexing Memory Corruption Vulnerability."
16393| [CVE-2010-3954] Microsoft Publisher 2002 SP3, 2003 SP3, and 2010 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Publisher file, aka "Microsoft Publisher Memory Corruption Vulnerability."
16394| [CVE-2010-3946] Integer overflow in the PICT image converter in the graphics filters in Microsoft Office XP SP3, Office 2003 SP3, and Office Converter Pack allows remote attackers to execute arbitrary code via a crafted PICT image in an Office document, aka "PICT Image Converter Integer Overflow Vulnerability."
16395| [CVE-2010-3945] Buffer overflow in the CGM image converter in the graphics filters in Microsoft Office XP SP3, Office 2003 SP3, and Office Converter Pack allows remote attackers to execute arbitrary code via a crafted CGM image in an Office document, aka "CGM Image Converter Buffer Overrun Vulnerability."
16396| [CVE-2010-3944] win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Vulnerability."
16397| [CVE-2010-3943] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly link driver objects, which allows local users to gain privileges via a crafted application that triggers linked-list corruption, aka "Win32k Cursor Linking Vulnerability."
16398| [CVE-2010-3942] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly allocate memory for copies from user mode, which allows local users to gain privileges via a crafted application, aka "Win32k WriteAV Vulnerability."
16399| [CVE-2010-3941] Double free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold and SP2, and Windows 7 allows local users to gain privileges via a crafted application, aka "Win32k Double Free Vulnerability."
16400| [CVE-2010-3940] Double free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a crafted application, aka "Win32k PFE Pointer Double Free Vulnerability."
16401| [CVE-2010-3939] Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via vectors related to improper memory allocation for copies from user mode, aka "Win32k Buffer Overflow Vulnerability."
16402| [CVE-2010-3937] Microsoft Exchange Server 2007 SP2 on the x64 platform allows remote authenticated users to cause a denial of service (infinite loop and MSExchangeIS outage) via a crafted RPC request, aka "Exchange Server Infinite Loop Vulnerability."
16403| [CVE-2010-3338] The Windows Task Scheduler in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly determine the security context of scheduled tasks, which allows local users to gain privileges via a crafted application, aka "Task Scheduler Vulnerability." NOTE: this might overlap CVE-2010-3888.
16404| [CVE-2010-3337] Untrusted search path vulnerability in Microsoft Office 2007 SP2 and 2010 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "Insecure Library Loading Vulnerability." NOTE: this might overlap CVE-2010-3141 and CVE-2010-3142.
16405| [CVE-2010-3336] Microsoft Office XP SP3, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "MSO Large SPID Read AV Vulnerability."
16406| [CVE-2010-3335] Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "Drawing Exception Handling Vulnerability."
16407| [CVE-2010-3334] Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via an Office document containing an Office Art Drawing record with crafted msofbtSp records and unspecified flags, which triggers memory corruption, aka "Office Art Drawing Records Vulnerability."
16408| [CVE-2010-3333] Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via crafted RTF data, aka "RTF Stack Buffer Overflow Vulnerability."
16409| [CVE-2010-3332] Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Services (IIS), provides detailed error codes during decryption attempts, which allows remote attackers to decrypt and modify encrypted View State (aka __VIEWSTATE) form data, and possibly forge cookies or read application files, via a padding oracle attack, aka "ASP.NET Padding Oracle Vulnerability."
16410| [CVE-2010-3324] The toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, Office SharePoint Server 2007 SP2, Groove Server 2010, and Office Web Apps, allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism and conduct XSS attacks via a crafted use of the Cascading Style Sheets (CSS) @import rule, aka "HTML Sanitization Vulnerability," a different vulnerability than CVE-2010-1257.
16411| [CVE-2010-3243] Cross-site scripting (XSS) vulnerability in the toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2 and Office SharePoint Server 2007 SP2, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "HTML Sanitization Vulnerability."
16412| [CVE-2010-3242] Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Ghost Record Type Parsing Vulnerability."
16413| [CVE-2010-3241] Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate binary file-format information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Out-of-Bounds Memory Write in Parsing Vulnerability."
16414| [CVE-2010-3240] Microsoft Excel 2002 SP3 and 2007 SP2
16415| [CVE-2010-3239] Microsoft Excel 2002 SP3 does not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Extra Out of Boundary Record Parsing Vulnerability."
16416| [CVE-2010-3238] Microsoft Excel 2002 SP3 and 2003 SP3, and Office 2004 for Mac, does not properly validate binary file-format information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Negative Future Function Vulnerability."
16417| [CVE-2010-3237] Microsoft Excel 2002 SP3 and Office 2004 for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Merge Cell Record Pointer Vulnerability."
16418| [CVE-2010-3236] Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Out Of Bounds Array Vulnerability."
16419| [CVE-2010-3235] Microsoft Excel 2002 SP3 does not properly validate formula information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Formula Biff Record Vulnerability."
16420| [CVE-2010-3234] Microsoft Excel 2002 SP3 does not properly validate formula information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Formula Substream Memory Corruption Vulnerability."
16421| [CVE-2010-3233] Microsoft Excel 2002 SP3 and 2003 SP3 does not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted .wk3 (aka Lotus 1-2-3 workbook) file, aka "Lotus 1-2-3 Workbook Parsing Vulnerability."
16422| [CVE-2010-3232] Microsoft Excel 2003 SP3 and 2007 SP2
16423| [CVE-2010-3231] Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Excel Record Parsing Memory Corruption Vulnerability."
16424| [CVE-2010-3230] Integer overflow in Microsoft Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel document with crafted record information, aka "Excel Record Parsing Integer Overflow Vulnerability."
16425| [CVE-2010-3229] The Secure Channel (aka SChannel) security package in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when IIS 7.x is used, does not properly process client certificates during SSL and TLS handshakes, which allows remote attackers to cause a denial of service (LSASS outage and reboot) via a crafted packet, aka "TLSv1 Denial of Service Vulnerability."
16426| [CVE-2010-3227] Stack-based buffer overflow in the UpdateFrameTitleForDocument method in the CFrameWnd class in mfc42.dll in the Microsoft Foundation Class (MFC) Library in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows context-dependent attackers to execute arbitrary code via a long window title that this library attempts to create at the request of an application, as demonstrated by the Trident PowerZip 7.2 Build 4010 application, aka "Windows MFC Document Title Updating Buffer Overflow Vulnerability."
16427| [CVE-2010-3223] The user interface in Microsoft Cluster Service (MSCS) in Microsoft Windows Server 2008 R2 does not properly set administrative-share permissions for new cluster disks that are shared as part of a failover cluster, which allows remote attackers to read or modify data on these disks via requests to the associated share, aka "Permissions on New Cluster Disks Vulnerability."
16428| [CVE-2010-3222] Stack-based buffer overflow in the Remote Procedure Call Subsystem (RPCSS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted LPC message that requests an LRPC connection from an LPC server to a client, aka "LPC Message Buffer Overrun Vulnerability."
16429| [CVE-2010-3221] Microsoft Word 2002 SP3 and 2003 SP3, Office 2004 for Mac, and Word Viewer do not properly handle a malformed record during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Parsing Vulnerability."
16430| [CVE-2010-3220] Unspecified vulnerability in Microsoft Word 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Word document that triggers memory corruption, aka "Word Parsing Vulnerability."
16431| [CVE-2010-3219] Array index vulnerability in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via a crafted Word document that triggers memory corruption, aka "Word Index Parsing Vulnerability."
16432| [CVE-2010-3218] Heap-based buffer overflow in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via malformed records in a Word document, aka "Word Heap Overflow Vulnerability."
16433| [CVE-2010-3217] Double free vulnerability in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via a Word document with crafted List Format Override (LFO) records, aka "Word Pointer Vulnerability."
16434| [CVE-2010-3216] Microsoft Word 2002 SP3 and Office 2004 for Mac allow remote attackers to execute arbitrary code via a crafted Word document containing bookmarks that trigger use of an invalid pointer and memory corruption, aka "Word Bookmarks Vulnerability."
16435| [CVE-2010-3215] Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly handle unspecified return values during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Return Value Vulnerability."
16436| [CVE-2010-3214] Stack-based buffer overflow in Microsoft Word 2002 SP3, 2003 SP3, 2007 SP2, and 2010
16437| [CVE-2010-3213] Cross-site request forgery (CSRF) vulnerability in Microsoft Outlook Web Access (owa/ev.owa) 2007 through SP2 allows remote attackers to hijack the authentication of e-mail users for requests that perform Outlook requests, as demonstrated by setting the auto-forward rule.
16438| [CVE-2010-3200] MSO.dll in Microsoft Word 2003 SP3 11.8326.11.8324 allows remote attackers to cause a denial of service (NULL pointer dereference and multiple-instance application crash) via a crafted buffer in a Word document, as demonstrated by word_crash_11.8326.8324_poc.doc.
16439| [CVE-2010-3190] Untrusted search path vulnerability in the Microsoft Foundation Class (MFC) Library in Microsoft Visual Studio .NET 2003 SP1
16440| [CVE-2010-3148] Untrusted search path vulnerability in Microsoft Visio 2003 SP3 allows local users to gain privileges via a Trojan horse mfc71enu.dll file in the current working directory, as demonstrated by a directory that contains a .vsd, .vdx, .vst, or .vtx file, aka "Microsoft Visio Insecure Library Loading Vulnerability."
16441| [CVE-2010-3147] Untrusted search path vulnerability in wab.exe 6.00.2900.5512 in Windows Address Book in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a Trojan horse wab32res.dll file in the current working directory, as demonstrated by a directory that contains a Windows Address Book (WAB), VCF (aka vCard), or P7C file, aka "Insecure Library Loading Vulnerability." NOTE: the codebase for this product may overlap the codebase for the product referenced in CVE-2010-3143.
16442| [CVE-2010-3146] Multiple untrusted search path vulnerabilities in Microsoft Groove 2007 SP2 allow local users to gain privileges via a Trojan horse (1) mso.dll or (2) GroovePerfmon.dll file in the current working directory, as demonstrated by a directory that contains a Groove vCard (.vcg) or Groove Tool Archive (.gta) file, aka "Microsoft Groove Insecure Library Loading Vulnerability."
16443| [CVE-2010-3144] Untrusted search path vulnerability in the Internet Connection Signup Wizard in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a Trojan horse smmscrpt.dll file in the current working directory, as demonstrated by a directory that contains an ISP or INS file, aka "Internet Connection Signup Wizard Insecure Library Loading Vulnerability."
16444| [CVE-2010-3142] Untrusted search path vulnerability in Microsoft Office PowerPoint 2007 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse rpawinet.dll that is located in the same folder as a .odp, .pothtml, .potm, .potx, .ppa, .ppam, .pps, .ppt, .ppthtml, .pptm, .pptxml, .pwz, .sldm, .sldx, and .thmx file.
16445| [CVE-2010-2750] Array index error in Microsoft Word 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Word document that triggers memory corruption, aka "Word Index Vulnerability."
16446| [CVE-2010-2748] Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly check an unspecified boundary during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Boundary Check Vulnerability."
16447| [CVE-2010-2747] Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly handle an uninitialized pointer during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Uninitialized Pointer Vulnerability."
16448| [CVE-2010-2746] Heap-based buffer overflow in Comctl32.dll (aka the common control library) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when a third-party SVG viewer is used, allows remote attackers to execute arbitrary code via a crafted HTML document that triggers unspecified messages from this viewer, aka "Comctl32 Heap Overflow Vulnerability."
16449| [CVE-2010-2744] The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly manage a window class, which allows local users to gain privileges by creating a window, then using (1) the SetWindowLongPtr function to modify the popup menu structure, or (2) the SwitchWndProc function with a switch window information pointer, which is not re-initialized when a WM_NCCREATE message is processed, aka "Win32k Window Class Vulnerability."
16450| [CVE-2010-2742] The Netlogon RPC Service in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, and R2, when the domain controller role is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via a crafted RPC packet, aka "Netlogon RPC Null dereference DOS Vulnerability."
16451| [CVE-2010-2741] The OpenType Font (OTF) format driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 performs an incorrect integer calculation during font processing, which allows local users to gain privileges via a crafted application, aka "OpenType Font Validation Vulnerability."
16452| [CVE-2010-2740] The OpenType Font (OTF) format driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly perform memory allocation during font parsing, which allows local users to gain privileges via a crafted application, aka "OpenType Font Parsing Vulnerability."
16453| [CVE-2010-2739] Buffer overflow in the CreateDIBPalette function in win32k.sys in Microsoft Windows XP SP3, Server 2003 R2 Enterprise SP2, Vista Business SP1, Windows 7, and Server 2008 SP2 allows local users to cause a denial of service (crash) and possibly execute arbitrary code by performing a clipboard operation (GetClipboardData API function) with a crafted bitmap with a palette that contains a large number of colors.
16454| [CVE-2010-2738] The Uniscribe (aka new Unicode Script Processor) implementation in USP10.DLL in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2, and Microsoft Office XP SP3, 2003 SP3, and 2007 SP2, does not properly validate tables associated with malformed OpenType fonts, which allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) Office document, aka "Uniscribe Font Parsing Engine Memory Corruption Vulnerability."
16455| [CVE-2010-2729] The Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when printer sharing is enabled, does not properly validate spooler access permissions, which allows remote attackers to create files in a system directory, and consequently execute arbitrary code, by sending a crafted print request over RPC, as exploited in the wild in September 2010, aka "Print Spooler Service Impersonation Vulnerability."
16456| [CVE-2010-2728] Heap-based buffer overflow in Microsoft Outlook 2002 SP3, 2003 SP3, and 2007 SP2, when Online Mode for an Exchange Server is enabled, allows remote attackers to execute arbitrary code via a crafted e-mail message, aka "Heap Based Buffer Overflow in Outlook Vulnerability."
16457| [CVE-2010-2573] Integer underflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3, PowerPoint Viewer SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint Integer Underflow Causes Heap Corruption Vulnerability."
16458| [CVE-2010-2572] Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95 document, aka "PowerPoint Parsing Buffer Overflow Vulnerability."
16459| [CVE-2010-2571] Array index error in pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher 97 file, aka "Memory Corruption Due To Invalid Index Into Array in Pubconv.dll Vulnerability."
16460| [CVE-2010-2570] Heap-based buffer overflow in pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3, 2003 SP3, 2007 SP2, and 2010 allows remote attackers to execute arbitrary code via a crafted Publisher file that uses an old file format, aka "Heap Overrun in pubconv.dll Vulnerability."
16461| [CVE-2010-2569] pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3, 2003 SP3, and 2007 SP2 does not properly handle an unspecified size field in certain older file formats, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted Publisher file, aka "Size Value Heap Corruption in pubconv.dll Vulnerability."
16462| [CVE-2010-2568] Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code via a crafted (1) .LNK or (2) .PIF shortcut file, which is not properly handled during icon display in Windows Explorer, as demonstrated in the wild in July 2010, and originally reported for malware that leverages CVE-2010-2772 in Siemens WinCC SCADA systems.
16463| [CVE-2010-2567] The RPC client implementation in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly allocate memory during the parsing of responses, which allows remote RPC servers and man-in-the-middle attackers to execute arbitrary code via a malformed response, aka "RPC Memory Corruption Vulnerability."
16464| [CVE-2010-2566] The Secure Channel (aka SChannel) security package in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, does not properly validate certificate request messages from TLS and SSL servers, which allows remote servers to execute arbitrary code via a crafted SSL response, aka "SChannel Malformed Certificate Request Remote Code Execution Vulnerability."
16465| [CVE-2010-2563] The Word 97 text converter in the WordPad Text Converters in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly parse malformed structures in Word 97 documents, which allows remote attackers to execute arbitrary code via a crafted document containing an unspecified value that is used in a loop counter, aka "WordPad Word 97 Text Converter Memory Corruption Vulnerability."
16466| [CVE-2010-2562] Microsoft Office Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Excel file, aka "Excel Memory Corruption Vulnerability."
16467| [CVE-2010-2555] The Tracing Feature for Services in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly determine the length of strings in the registry, which allows local users to gain privileges or cause a denial of service (memory corruption) via vectors involving a long string, aka "Tracing Memory Corruption Vulnerability."
16468| [CVE-2010-2554] The Tracing Feature for Services in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 has incorrect ACLs on its registry keys, which allows local users to gain privileges via vectors involving a named pipe and impersonation, aka "Tracing Registry Key ACL Vulnerability."
16469| [CVE-2010-2552] Stack consumption vulnerability in the SMB Server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to cause a denial of service (system hang) via a malformed SMBv2 compounded request, aka "SMB Stack Exhaustion Vulnerability."
16470| [CVE-2010-2551] The SMB Server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate an internal variable in an SMB packet, which allows remote attackers to cause a denial of service (system hang) via a crafted (1) SMBv1 or (2) SMBv2 packet, aka "SMB Variable Validation Vulnerability."
16471| [CVE-2010-2550] The SMB Server in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate fields in an SMB request, which allows remote attackers to execute arbitrary code via a crafted SMB packet, aka "SMB Pool Overflow Vulnerability."
16472| [CVE-2010-2549] Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2 and Server 2008 Gold and SP2 allows local users to gain privileges or cause a denial of service (system crash) by using a large number of calls to the NtUserCheckAccessForIntegrityLevel function to trigger a failure in the LockProcessByClientId function, leading to deletion of an in-use process object, aka "Win32k Reference Count Vulnerability."
16473| [CVE-2010-2265] Cross-site scripting (XSS) vulnerability in the GetServerName function in sysinfo/commonFunc.js in Microsoft Windows Help and Support Center for Windows XP and Windows Server 2003 allows remote attackers to inject arbitrary web script or HTML via the svr parameter to sysinfo/sysinfomain.htm. NOTE: this can be leveraged with CVE-2010-1885 to execute arbitrary commands without user interaction.
16474| [CVE-2010-2091] Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7 on Windows Server 2003 is used, does not properly handle the id parameter in a Folder IPF.Note action to the default URI, which might allow remote attackers to obtain sensitive information or conduct cross-site scripting (XSS) attacks via an invalid value.
16475| [CVE-2010-2084] Microsoft ASP.NET 2.0 does not prevent setting the InnerHtml property on a control that inherits from HtmlContainerControl, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to an attribute.
16476| [CVE-2010-1903] Microsoft Office Word 2002 SP3 and 2003 SP3, and Office Word Viewer, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed record in a Word file, aka "Word HTML Linked Objects Memory Corruption Vulnerability."
16477| [CVE-2010-1902] Buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2
16478| [CVE-2010-1901] Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2
16479| [CVE-2010-1900] Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2
16480| [CVE-2010-1898] The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP1, 2.0 SP2, 3.5, 3.5 SP1, and 3.5.1, and Microsoft Silverlight 2 and 3 before 3.0.50611.0 on Windows and before 3.0.41130.0 on Mac OS X, does not properly handle interfaces and delegations to virtual methods, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft Silverlight and Microsoft .NET Framework CLR Virtual Method Delegate Vulnerability."
16481| [CVE-2010-1897] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly validate pseudo-handle values in callback parameters during window creation, which allows local users to gain privileges via a crafted application, aka "Win32k Window Creation Vulnerability."
16482| [CVE-2010-1896] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2 do not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Win32k User Input Validation Vulnerability."
16483| [CVE-2010-1895] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, do not properly perform memory allocation before copying user-mode data to kernel mode, which allows local users to gain privileges via a crafted application, aka "Win32k Pool Overflow Vulnerability."
16484| [CVE-2010-1894] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, do not properly handle unspecified exceptions, which allows local users to gain privileges via a crafted application, aka "Win32k Exception Handling Vulnerability."
16485| [CVE-2010-1893] Integer overflow in the TCP/IP stack in Microsoft Windows Vista SP1, Windows Server 2008 Gold and R2, and Windows 7 allows local users to gain privileges via a buffer of user-mode data that is copied to kernel mode, aka "Integer Overflow in Windows Networking Vulnerability."
16486| [CVE-2010-1892] The TCP/IP stack in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly handle malformed IPv6 packets, which allows remote attackers to cause a denial of service (system hang) via multiple crafted packets, aka "IPv6 Memory Corruption Vulnerability."
16487| [CVE-2010-1891] The Client/Server Runtime Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2, when a Chinese, Japanese, or Korean locale is enabled, does not properly allocate memory for transactions, which allows local users to gain privileges via a crafted application, aka "CSRSS Local Elevation of Privilege Vulnerability."
16488| [CVE-2010-1890] The kernel in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate ACLs on kernel objects, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Improper Validation Vulnerability."
16489| [CVE-2010-1889] Double free vulnerability in the kernel in Microsoft Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2, allows local users to gain privileges via a crafted application, related to object initialization during error handling, aka "Windows Kernel Double Free Vulnerability."
16490| [CVE-2010-1887] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly validate an unspecified system-call argument, which allows local users to cause a denial of service (system hang) via a crafted application, aka "Win32k Bounds Checking Vulnerability."
16491| [CVE-2010-1886] Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2, and Windows 7 allow local users to gain privileges by leveraging access to a process with NetworkService credentials, as demonstrated by TAPI Server, SQL Server, and IIS processes, and related to the Windows Service Isolation feature. NOTE: the vendor states that privilege escalation from NetworkService to LocalSystem does not cross a "security boundary."
16492| [CVE-2010-1885] The MPC::HexToNum function in helpctr.exe in Microsoft Windows Help and Support Center in Windows XP and Windows Server 2003 does not properly handle malformed escape sequences, which allows remote attackers to bypass the trusted documents whitelist (fromHCP option) and execute arbitrary commands via a crafted hcp:// URL, aka "Help Center URL Validation Vulnerability."
16493| [CVE-2010-1883] Integer overflow in the Embedded OpenType (EOT) Font Engine in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to execute arbitrary code via a crafted table in an embedded font, aka "Embedded OpenType Font Integer Overflow Vulnerability."
16494| [CVE-2010-1882] Multiple buffer overflows in the MPEG Layer-3 Audio Codec for Microsoft DirectShow in l3codecx.ax in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allow remote attackers to execute arbitrary code via an MPEG Layer-3 audio stream in (1) a crafted media file or (2) crafted streaming content, aka "MPEG Layer-3 Audio Decoder Buffer Overflow Vulnerability."
16495| [CVE-2010-1881] The FieldList ActiveX control in the Microsoft Access Wizard Controls in ACCWIZ.dll in Microsoft Office Access 2003 SP3 does not properly interact with the memory-access approach used by Internet Explorer and Office during instantiation, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via an HTML document that references this control along with crafted persistent storage data, aka "ACCWIZ.dll Uninitialized Variable Vulnerability."
16496| [CVE-2010-1880] Unspecified vulnerability in Quartz.dll for DirectShow on Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1, and Server 2008 allows remote attackers to execute arbitrary code via a media file with crafted compression data, aka "MJPEG Media Decompression Vulnerability."
16497| [CVE-2010-1735] The SfnLOGONNOTIFY function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service (system crash) via a 0x4c value in the second argument (aka the Msg argument) of a PostMessage function call for the DDEMLEvent window.
16498| [CVE-2010-1734] The SfnINSTRING function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service (system crash) via a 0x18d value in the second argument (aka the Msg argument) of a PostMessage function call for the DDEMLEvent window.
16499| [CVE-2010-1690] The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 does not verify that transaction IDs of responses match transaction IDs of queries, which makes it easier for man-in-the-middle attackers to spoof DNS responses, a different vulnerability than CVE-2010-0024 and CVE-2010-0025.
16500| [CVE-2010-1689] The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 uses predictable transaction IDs that are formed by incrementing a previous ID by 1, which makes it easier for man-in-the-middle attackers to spoof DNS responses, a different vulnerability than CVE-2010-0024 and CVE-2010-0025.
16501| [CVE-2010-1263] Windows Shell and WordPad in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7
16502| [CVE-2010-1257] Cross-site scripting (XSS) vulnerability in the toStaticHTML API, as used in Microsoft Office InfoPath 2003 SP3, 2007 SP1, and 2007 SP2
16503| [CVE-2010-1255] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 Gold and SP2, Windows 7, and Server 2008 R2 allows local users to execute arbitrary code via vectors related to "glyph outline information" and TrueType fonts, aka "Win32k TrueType Font Parsing Vulnerability."
16504| [CVE-2010-1253] Microsoft Office Excel 2002 SP3, 2007 SP1, and SP2
16505| [CVE-2010-1252] Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Excel file, aka "Excel String Variable Vulnerability."
16506| [CVE-2010-1251] Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Excel file, aka "Excel Record Stack Corruption Vulnerability."
16507| [CVE-2010-1250] Heap-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with malformed (1) EDG (0x88) and (2) Publisher (0x89) records, aka "Excel EDG Memory Corruption Vulnerability."
16508| [CVE-2010-1249] Buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed ExternName (0x23) record, aka "Excel Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0823 and CVE-2010-1247.
16509| [CVE-2010-1248] Buffer overflow in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed HFPicture (0x866) record, aka "Excel HFPicture Memory Corruption Vulnerability."
16510| [CVE-2010-1247] Unspecified vulnerability in Microsoft Office Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel file with a malformed RTD (0x813) record that triggers heap corruption, aka "Excel Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0823 and CVE-2010-1249.
16511| [CVE-2010-1246] Stack-based buffer overflow in Microsoft Office Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel file with a malformed RTD (0x813) record, aka "Excel RTD Memory Corruption Vulnerability."
16512| [CVE-2010-1245] Unspecified vulnerability in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed SxView (0xB0) record, aka "Excel Record Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0824 and CVE-2010-0821.
16513| [CVE-2010-1225] The memory-management implementation in the Virtual Machine Monitor (aka VMM or hypervisor) in Microsoft Virtual PC 2007 Gold and SP1, Virtual Server 2005 Gold and R2 SP1, and Windows Virtual PC does not properly restrict access from the guest OS to memory locations in the VMM work area, which allows context-dependent attackers to bypass certain anti-exploitation protection mechanisms on the guest OS via crafted input to a vulnerable application. NOTE: the vendor reportedly found that only systems with an otherwise vulnerable application are affected, because "the memory areas accessible from the guest cannot be leveraged to achieve either remote code execution or elevation of privilege and ... no data from the host is exposed to the guest OS."
16514| [CVE-2010-1175] Microsoft Internet Explorer 7.0 on Windows XP and Windows Server 2003 allows remote attackers to have an unspecified impact via a certain XML document that references a crafted web site in the SRC attribute of an image element, related to a "0day Vulnerability."
16515| [CVE-2010-0917] Stack-based buffer overflow in VBScript in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, might allow user-assisted remote attackers to execute arbitrary code via a long string in the fourth argument (aka helpfile argument) to the MsgBox function, leading to code execution when the F1 key is pressed, a different vulnerability than CVE-2010-0483.
16516| [CVE-2010-0824] Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed WOPT (0x80B) record, aka "Excel Record Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0821 and CVE-2010-1245.
16517| [CVE-2010-0823] Unspecified vulnerability in Microsoft Office Excel 2002 SP3, 2003 SP3, 2007 SP1 and SP2
16518| [CVE-2010-0822] Stack-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a crafted OBJ (0x5D) record, aka "Excel Object Stack Overflow Vulnerability."
16519| [CVE-2010-0821] Unspecified vulnerability in Microsoft Office Excel 2002 SP3, 2003 SP3, 2007 SP1 and SP2
16520| [CVE-2010-0820] Heap-based buffer overflow in the Local Security Authority Subsystem Service (LSASS), as used in Active Directory in Microsoft Windows Server 2003 SP2 and Windows Server 2008 Gold, SP2, and R2
16521| [CVE-2010-0819] Unspecified vulnerability in the Windows OpenType Compact Font Format (CFF) driver in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users to execute arbitrary code via unknown vectors related to improper validation when copying data from user mode to kernel mode, aka "OpenType CFF Font Driver Memory Corruption Vulnerability."
16522| [CVE-2010-0818] The MPEG-4 codec in the Windows Media codecs in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 does not properly handle crafted media content with MPEG-4 video encoding, which allows remote attackers to execute arbitrary code via a file in an unspecified "supported format," aka "MPEG-4 Codec Vulnerability."
16523| [CVE-2010-0817] Cross-site scripting (XSS) vulnerability in _layouts/help.aspx in Microsoft SharePoint Server 2007 12.0.0.6421 and possibly earlier, and SharePoint Services 3.0 SP1 and SP2, versions, allows remote attackers to inject arbitrary web script or HTML via the cid0 parameter.
16524| [CVE-2010-0815] VBE6.DLL in Microsoft Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Visual Basic for Applications (VBA), and VBA SDK 6.3 through 6.5 does not properly search for ActiveX controls that are embedded in documents, which allows remote attackers to execute arbitrary code via a crafted document, aka "VBE6.DLL Stack Memory Corruption Vulnerability."
16525| [CVE-2010-0814] The Microsoft Access Wizard Controls in ACCWIZ.dll in Microsoft Office Access 2003 SP3 and 2007 SP1 and SP2 do not properly interact with the memory-allocation approach used by Internet Explorer during instantiation, which allows remote attackers to execute arbitrary code via a web site that references multiple ActiveX controls, as demonstrated by the ImexGrid and FieldList controls, aka "Access ActiveX Control Vulnerability."
16526| [CVE-2010-0812] Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to bypass intended IPv4 source-address restrictions via a mismatched IPv6 source address in a tunneled ISATAP packet, aka "ISATAP IPv6 Source Address Spoofing Vulnerability."
16527| [CVE-2010-0811] Multiple unspecified vulnerabilities in the Microsoft Internet Explorer 8 Developer Tools ActiveX control in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allow remote attackers to execute arbitrary code via unknown vectors that "corrupt the system state," aka "Microsoft Internet Explorer 8 Developer Tools Vulnerability."
16528| [CVE-2010-0810] The kernel in Microsoft Windows Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2, does not properly handle unspecified exceptions, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Exception Handler Vulnerability."
16529| [CVE-2010-0719] An unspecified API in Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, and Windows 7 does not validate arguments, which allows local users to cause a denial of service (system crash) via a crafted application.
16530| [CVE-2010-0487] The Authenticode Signature verification functionality in cabview.dll in Cabinet File Viewer Shell Extension 5.1, 6.0, and 6.1 in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly use unspecified fields in a file digest, which allows remote attackers to execute arbitrary code via a modified cabinet (aka .CAB) file that incorrectly appears to have a valid signature, aka "Cabview Corruption Validation Vulnerability."
16531| [CVE-2010-0486] The WinVerifyTrust function in Authenticode Signature Verification 5.1, 6.0, and 6.1 in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly use unspecified fields in a file digest, which allows user-assisted remote attackers to execute arbitrary code via a modified (1) Portable Executable (PE) or (2) cabinet (aka .CAB) file that incorrectly appears to have a valid signature, aka "WinVerifyTrust Signature Validation Vulnerability."
16532| [CVE-2010-0485] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 Gold and SP2, Windows 7, and Server 2008 R2 "do not properly validate all callback parameters when creating a new window," which allows local users to execute arbitrary code, aka "Win32k Window Creation Vulnerability."
16533| [CVE-2010-0484] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 "do not properly validate changes in certain kernel objects," which allows local users to execute arbitrary code via vectors related to Device Contexts (DC) and the GetDCEx function, aka "Win32k Improper Data Validation Vulnerability."
16534| [CVE-2010-0483] vbscript.dll in VBScript 5.1, 5.6, 5.7, and 5.8 in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, allows user-assisted remote attackers to execute arbitrary code by referencing a (1) local pathname, (2) UNC share pathname, or (3) WebDAV server with a crafted .hlp file in the fourth argument (aka helpfile argument) to the MsgBox function, leading to code execution involving winhlp32.exe when the F1 key is pressed, aka "VBScript Help Keypress Vulnerability."
16535| [CVE-2010-0482] The kernel in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate relocation sections of image files, which allows local users to cause a denial of service (reboot) via a crafted file, aka "Windows Kernel Malformed Image Vulnerability."
16536| [CVE-2010-0481] The kernel in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly translate a registry key's virtual path to its real path, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Virtual Path Parsing Vulnerability."
16537| [CVE-2010-0480] Multiple stack-based buffer overflows in the MPEG Layer-3 audio codecs in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to execute arbitrary code via a crafted AVI file, aka "MPEG Layer-3 Audio Decoder Stack Overflow Vulnerability."
16538| [CVE-2010-0479] Buffer overflow in Microsoft Office Publisher 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Microsoft Office Publisher File Conversion TextBox Processing Buffer Overflow Vulnerability."
16539| [CVE-2010-0478] Stack-based buffer overflow in nsum.exe in the Windows Media Unicast Service in Media Services for Microsoft Windows 2000 Server SP4 allows remote attackers to execute arbitrary code via crafted packets associated with transport information, aka "Media Services Stack-based Buffer Overflow Vulnerability."
16540| [CVE-2010-0477] The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly handle (1) SMBv1 and (2) SMBv2 response packets, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted packet that causes the client to read the entirety of the response, and then improperly interact with the Winsock Kernel (WSK), aka "SMB Client Message Size Vulnerability."
16541| [CVE-2010-0476] The SMB client in Microsoft Windows Server 2003 SP2, Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2 allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and reboot) via a crafted SMB transaction response that uses (1) SMBv1 or (2) SMBv2, aka "SMB Client Response Parsing Vulnerability."
16542| [CVE-2010-0278] A certain ActiveX control in msgsc.14.0.8089.726.dll in Microsoft Windows Live Messenger 2009 build 14.0.8089.726 on Windows Vista and Windows 7 allows remote attackers to cause a denial of service (msnmsgr.exe crash) by calling the ViewProfile method with a crafted argument during an MSN Messenger session.
16543| [CVE-2010-0270] The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate fields in SMB transaction responses, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and reboot) via a crafted (1) SMBv1 or (2) SMBv2 response, aka "SMB Client Transaction Vulnerability."
16544| [CVE-2010-0269] The SMB client in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly allocate memory for SMB responses, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted (1) SMBv1 or (2) SMBv2 response, aka "SMB Client Memory Allocation Vulnerability."
16545| [CVE-2010-0268] Unspecified vulnerability in the Windows Media Player ActiveX control in Windows Media Player (WMP) 9 on Microsoft Windows 2000 SP4 and XP SP2 and SP3 allows remote attackers to execute arbitrary code via crafted media content, aka "Media Player Remote Code Execution Vulnerability."
16546| [CVE-2010-0266] Microsoft Office Outlook 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 does not properly verify e-mail attachments with a PR_ATTACH_METHOD property value of ATTACH_BY_REFERENCE, which allows user-assisted remote attackers to execute arbitrary code via a crafted message, aka "Microsoft Outlook SMB Attachment Vulnerability."
16547| [CVE-2010-0265] Buffer overflow in Microsoft Windows Movie Maker 2.1, 2.6, and 6.0, and Microsoft Producer 2003, allows remote attackers to execute arbitrary code via a crafted project (.MSWMM) file, aka "Movie Maker and Producer Buffer Overflow Vulnerability."
16548| [CVE-2010-0264] Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Microsoft Office Excel DbOrParamQry Record Parsing Vulnerability."
16549| [CVE-2010-0263] Microsoft Office Excel 2007 SP1 and SP2
16550| [CVE-2010-0262] Microsoft Office Excel 2007 SP1 and SP2 and Office 2004 for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet that triggers access of an uninitialized stack variable, aka "Microsoft Office Excel FNGROUPNAME Record Uninitialized Memory Vulnerability."
16551| [CVE-2010-0261] Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2 and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted spreadsheet in which "a MDXSET record is broken up into several records," aka "Microsoft Office Excel MDXSET Record Heap Overflow Vulnerability."
16552| [CVE-2010-0260] Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2
16553| [CVE-2010-0258] Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
16554| [CVE-2010-0257] Microsoft Office Excel 2002 SP3 does not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Microsoft Office Excel Record Memory Corruption Vulnerability."
16555| [CVE-2010-0256] Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 and SP2 does not properly calculate unspecified indexes associated with Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Visio Index Calculation Memory Corruption Vulnerability."
16556| [CVE-2010-0254] Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 and SP2 does not properly validate attributes in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Visio Attribute Validation Memory Corruption Vulnerability."
16557| [CVE-2010-0252] The Microsoft Data Analyzer ActiveX control (aka the Office Excel ActiveX control for Data Analysis) in max3activex.dll in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to execute arbitrary code via a crafted web page that corrupts the "system state," aka "Microsoft Data Analyzer ActiveX Control Vulnerability."
16558| [CVE-2010-0250] Heap-based buffer overflow in DirectShow in Microsoft DirectX, as used in the AVI Filter on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2, and in Quartz on Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, allows remote attackers to execute arbitrary code via an AVI file with a crafted length field in an unspecified video stream, which is not properly handled by the RLE video decompressor, aka "DirectShow Heap Overflow Vulnerability."
16559| [CVE-2010-0249] Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4
16560| [CVE-2010-0243] Buffer overflow in MSO.DLL in Microsoft Office XP SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Office document, aka "MSO.DLL Buffer Overflow."
16561| [CVE-2010-0242] The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows remote attackers to cause a denial of service (system hang) via crafted packets with malformed TCP selective acknowledgement (SACK) values, aka "TCP/IP Selective Acknowledgement Vulnerability."
16562| [CVE-2010-0241] The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when IPv6 is enabled, does not properly perform bounds checking on ICMPv6 Route Information packets, which allows remote attackers to execute arbitrary code via crafted packets, aka "ICMPv6 Route Information Vulnerability."
16563| [CVE-2010-0240] The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when a custom network driver is used, does not properly handle local fragmentation of Encapsulating Security Payload (ESP) over UDP packets, which allows remote attackers to execute arbitrary code via crafted packets, aka "Header MDL Fragmentation Vulnerability."
16564| [CVE-2010-0239] The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when IPv6 is enabled, does not properly perform bounds checking on ICMPv6 Router Advertisement packets, which allows remote attackers to execute arbitrary code via crafted packets, aka "ICMPv6 Router Advertisement Vulnerability."
16565| [CVE-2010-0238] Unspecified vulnerability in registry-key validation in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Registry Key Vulnerability."
16566| [CVE-2010-0237] The kernel in Microsoft Windows 2000 SP4 and XP SP2 and SP3 allows local users to gain privileges by creating a symbolic link from an untrusted registry hive to a trusted registry hive, aka "Windows Kernel Symbolic Link Creation Vulnerability."
16567| [CVE-2010-0236] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold does not properly allocate memory for the destination key associated with a symbolic-link registry key, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Allocation Vulnerability."
16568| [CVE-2010-0235] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold does not perform the expected validation before creating a symbolic link, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Symbolic Link Value Vulnerability."
16569| [CVE-2010-0234] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not properly validate a registry-key argument to an unspecified system call, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Null Pointer Vulnerability."
16570| [CVE-2010-0233] Double free vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows local users to gain privileges via a crafted application, aka "Windows Kernel Double Free Vulnerability."
16571| [CVE-2010-0232] The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges by crafting a VDM_TIB data structure in the Thread Environment Block (TEB), and then calling the NtVdmControl function to start the Windows Virtual DOS Machine (aka NTVDM) subsystem, leading to improperly handled exceptions involving the #GP trap handler (nt!KiTrap0D), aka "Windows Kernel Exception Handler Vulnerability."
16572| [CVE-2010-0231] The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not use a sufficient source of entropy, which allows remote attackers to obtain access to files and other SMB resources via a large number of authentication requests, related to server-generated challenges, certain "duplicate values," and spoofing of an authentication token, aka "SMB NTLM Authentication Lack of Entropy Vulnerability."
16573| [CVE-2010-0035] The Key Distribution Center (KDC) in Kerberos in Microsoft Windows 2000 SP4, Server 2003 SP2, and Server 2008 Gold and SP2, when a trust relationship with a non-Windows Kerberos realm exists, allows remote authenticated users to cause a denial of service (NULL pointer dereference and domain controller outage) via a crafted Ticket Granting Ticket (TGT) renewal request, aka "Kerberos Null Pointer Dereference Vulnerability."
16574| [CVE-2010-0034] Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "Office PowerPoint Viewer TextCharsAtom Record Stack Overflow Vulnerability."
16575| [CVE-2010-0033] Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint Viewer TextBytesAtom Record Stack Overflow Vulnerability."
16576| [CVE-2010-0032] Use-after-free vulnerability in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "OEPlaceholderAtom Use After Free Vulnerability."
16577| [CVE-2010-0031] Array index error in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3, and PowerPoint in Office 2004 for Mac, allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint OEPlaceholderAtom 'placementId' Invalid Array Indexing Vulnerability."
16578| [CVE-2010-0030] Heap-based buffer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint LinkedSlideAtom Heap Overflow Vulnerability."
16579| [CVE-2010-0029] Buffer overflow in Microsoft Office PowerPoint 2002 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint File Path Handling Buffer Overflow Vulnerability."
16580| [CVE-2010-0028] Integer overflow in Microsoft Paint in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted JPEG (.JPG) file, aka "MS Paint Integer Overflow Vulnerability."
16581| [CVE-2010-0027] The URL validation functionality in Microsoft Internet Explorer 5.01, 6, 6 SP1, 7 and 8, and the ShellExecute API function in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."
16582| [CVE-2010-0026] The Hyper-V server implementation in Microsoft Windows Server 2008 Gold, SP2, and R2 on the x64 platform allows guest OS users to cause a denial of service (host OS hang) via a crafted application that executes a malformed series of machine instructions, aka "Hyper-V Instruction Set Validation Vulnerability."
16583| [CVE-2010-0025] The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2000 SP3, does not properly allocate memory for SMTP command replies, which allows remote attackers to read fragments of e-mail messages by sending a series of invalid commands and then sending a STARTTLS command, aka "SMTP Memory Allocation Vulnerability."
16584| [CVE-2010-0024] The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2003 SP2, does not properly parse MX records, which allows remote DNS servers to cause a denial of service (service outage) via a crafted response to a DNS MX record query, aka "SMTP Server MX Record Vulnerability."
16585| [CVE-2010-0023] The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly kill processes after a logout, which allows local users to obtain sensitive information or gain privileges via a crafted application that continues to execute throughout the logout of one user and the login session of the next user, aka "CSRSS Local Privilege Elevation Vulnerability."
16586| [CVE-2010-0022] The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate the share and servername fields in SMB packets, which allows remote attackers to cause a denial of service (system hang) via a crafted packet, aka "SMB Null Pointer Vulnerability."
16587| [CVE-2010-0021] Multiple race conditions in the SMB implementation in the Server service in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allow remote attackers to cause a denial of service (system hang) via a crafted (1) SMBv1 or (2) SMBv2 Negotiate packet, aka "SMB Memory Corruption Vulnerability."
16588| [CVE-2010-0020] The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate request fields, which allows remote authenticated users to execute arbitrary code via a malformed request, aka "SMB Pathname Overflow Vulnerability."
16589| [CVE-2010-0018] Integer overflow in the Embedded OpenType (EOT) Font Engine (t2embed.dll) in Microsoft Windows 2000 SP4
16590| [CVE-2010-0017] Race condition in the SMB client implementation in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code, and in the SMB client implementation in Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows local users to gain privileges, via a crafted SMB Negotiate response, aka "SMB Client Race Condition Vulnerability."
16591| [CVE-2010-0016] The SMB client implementation in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly validate response fields, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted response, aka "SMB Client Pool Corruption Vulnerability."
16592| [CVE-2009-4313] ir32_32.dll 3.24.15.3 in the Indeo32 codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to cause a denial of service (heap corruption) or execute arbitrary code via malformed data in a stream in a media file, as demonstrated by an AVI file.
16593| [CVE-2009-4312] Unspecified vulnerability in the Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via crafted media content, as reported to Microsoft by Dave Lenoe of Adobe.
16594| [CVE-2009-4311] Unspecified vulnerability in the Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via crafted media content, as reported to Microsoft by Paul Byrne of NGS Software. NOTE: this might overlap CVE-2008-3615.
16595| [CVE-2009-4310] Stack-based buffer overflow in the Intel Indeo41 codec for Windows Media Player in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via crafted compressed video data in an IV41 stream in a media file, leading to many loop iterations, as demonstrated by data in an AVI file.
16596| [CVE-2009-4309] Heap-based buffer overflow in the Intel Indeo41 codec for Windows Media Player in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a large size value in a movi record in an IV41 stream in a media file, as demonstrated by an AVI file.
16597| [CVE-2009-4210] The Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted media content.
16598| [CVE-2009-3830] The download functionality in Team Services in Microsoft Office SharePoint Server 2007 12.0.0.4518 and 12.0.0.6219 allows remote attackers to read ASP.NET source code via pathnames in the SourceUrl and Source parameters to _layouts/download.aspx.
16599| [CVE-2009-3678] Integer overflow in cdd.dll in the Canonical Display Driver (CDD) in Microsoft Windows Server 2008 R2 and Windows 7 on 64-bit platforms, when the Windows Aero theme is installed, allows context-dependent attackers to cause a denial of service (reboot) or possibly execute arbitrary code via a crafted image file that triggers incorrect data parsing after user-mode data is copied to kernel mode, as demonstrated using "Browse with Irfanview" and certain actions on a folder containing a large number of thumbnail images in Resample mode, possibly related to the ATI graphics driver or win32k.sys, aka "Canonical Display Driver Integer Overflow Vulnerability."
16600| [CVE-2009-3677] The Internet Authentication Service (IAS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly verify the credentials in an MS-CHAP v2 Protected Extensible Authentication Protocol (PEAP) authentication request, which allows remote attackers to access network resources via a malformed request, aka "MS-CHAP Authentication Bypass Vulnerability."
16601| [CVE-2009-3676] The SMB client in the kernel in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle attackers to cause a denial of service (infinite loop and system hang) via a (1) SMBv1 or (2) SMBv2 response packet that contains (a) an incorrect length value in a NetBIOS header or (b) an additional length field at the end of this response packet, aka "SMB Client Incomplete Response Vulnerability."
16602| [CVE-2009-3675] LSASS.exe in the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote authenticated users to cause a denial of service (CPU consumption) via a malformed ISAKMP request over IPsec, aka "Local Security Authority Subsystem Service Resource Exhaustion Vulnerability."
16603| [CVE-2009-3450] Multiple cross-site scripting (XSS) vulnerabilities in WebCoreModule.ashx in RADactive I-Load before 2008.2.5.0 allow remote attackers to inject arbitrary web script or HTML via parameters with names beginning with __ (underscore underscore) sequences, which are incompatible with an XSS protection mechanism provided by Microsoft ASP.NET.
16604| [CVE-2009-3135] Stack-based buffer overflow in Microsoft Office Word 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, Open XML File Format Converter for Mac, Office Word Viewer 2003 SP3, and Office Word Viewer allow remote attackers to execute arbitrary code via a Word document with a malformed File Information Block (FIB) structure, aka "Microsoft Office Word File Information Memory Corruption Vulnerability."
16605| [CVE-2009-3134] Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
16606| [CVE-2009-3133] Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a spreadsheet containing a malformed object that triggers memory corruption, related to "loading Excel records," aka "Excel Document Parsing Memory Corruption Vulnerability."
16607| [CVE-2009-3132] Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
16608| [CVE-2009-3131] Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
16609| [CVE-2009-3130] Heap-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via a spreadsheet containing a malformed Binary File Format (aka BIFF) record that triggers memory corruption, aka "Excel Document Parsing Heap Overflow Vulnerability."
16610| [CVE-2009-3129] Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
16611| [CVE-2009-3128] Microsoft Office Excel 2002 SP3 and 2003 SP3, and Office Excel Viewer 2003 SP3, does not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a spreadsheet with a malformed record object, aka "Excel SxView Memory Corruption Vulnerability."
16612| [CVE-2009-3127] Microsoft Office Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, Open XML File Format Converter for Mac, and Office Excel Viewer 2003 SP3 do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Cache Memory Corruption Vulnerability."
16613| [CVE-2009-3126] Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted PNG image file, aka "GDI+ PNG Integer Overflow Vulnerability."
16614| [CVE-2009-3103] Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via an & (ampersand) character in a Process ID High header field in a NEGOTIATE PROTOCOL REQUEST packet, which triggers an attempted dereference of an out-of-bounds memory location, aka "SMBv2 Negotiation Vulnerability." NOTE: some of these details are obtained from third party information.
16615| [CVE-2009-3020] win32k.sys in Microsoft Windows Server 2003 SP2 allows remote attackers to cause a denial of service (system crash) by referencing a crafted .eot file in the src descriptor of an @font-face Cascading Style Sheets (CSS) rule in an HTML document, possibly related to the Embedded OpenType (EOT) Font Engine, a different vulnerability than CVE-2006-0010, CVE-2009-0231, and CVE-2009-0232. NOTE: some of these details are obtained from third party information.
16616| [CVE-2009-2653] ** DISPUTED ** The NtUserConsoleControl function in win32k.sys in Microsoft Windows XP SP2 and SP3, and Server 2003 before SP1, allows local administrators to bypass unspecified "security software" and gain privileges via a crafted call that triggers an overwrite of an arbitrary memory location. NOTE: the vendor disputes the significance of this report, stating that 'the Administrator to SYSTEM "escalation" is not a security boundary we defend.'
16617| [CVE-2009-2532] Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC do not properly process the command value in an SMB Multi-Protocol Negotiate Request packet, which allows remote attackers to execute arbitrary code via a crafted SMBv2 packet to the Server service, aka "SMBv2 Command Value Vulnerability."
16618| [CVE-2009-2526] Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 do not properly validate fields in SMBv2 packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted packet to the Server service, aka "SMBv2 Infinite Loop Vulnerability."
16619| [CVE-2009-2524] Integer underflow in the NTLM authentication feature in the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to cause a denial of service (reboot) via a malformed packet, aka "Local Security Authority Subsystem Service Integer Overflow Vulnerability."
16620| [CVE-2009-2523] The License Logging Server (llssrv.exe) in Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrary code via an RPC message containing a string without a null terminator, which triggers a heap-based buffer overflow in the LlsrLicenseRequestW method, aka "License Logging Server Heap Overflow Vulnerability."
16621| [CVE-2009-2519] The DHTML Editing Component ActiveX control in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly format HTML markup, which allows remote attackers to execute arbitrary code via a crafted web site that triggers "system state" corruption, aka "DHTML Editing Component ActiveX Control Vulnerability."
16622| [CVE-2009-2517] The kernel in Microsoft Windows Server 2003 SP2 does not properly handle unspecified exceptions when an error condition occurs, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Exception Handler Vulnerability."
16623| [CVE-2009-2516] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly validate data sent from user mode, which allows local users to gain privileges via a crafted PE .exe file that triggers a NULL pointer dereference during chain traversal, aka "Windows Kernel NULL Pointer Dereference Vulnerability."
16624| [CVE-2009-2515] Integer underflow in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows local users to gain privileges via a crafted application that triggers an incorrect truncation of a 64-bit integer to a 32-bit integer, aka "Windows Kernel Integer Underflow Vulnerability."
16625| [CVE-2009-2514] win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not correctly parse font code during construction of a directory-entry table, which allows remote attackers to execute arbitrary code via a crafted Embedded OpenType (EOT) font, aka "Win32k EOT Parsing Vulnerability."
16626| [CVE-2009-2513] The Graphics Device Interface (GDI) in win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Insufficient Data Validation Vulnerability."
16627| [CVE-2009-2511] Integer overflow in the CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows man-in-the-middle attackers to spoof arbitrary SSL servers and other entities via an X.509 certificate that has a malformed ASN.1 Object Identifier (OID) and was issued by a legitimate Certification Authority, aka "Integer Overflow in X.509 Object Identifiers Vulnerability."
16628| [CVE-2009-2510] The CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, as used by Internet Explorer and other applications, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, aka "Null Truncation in X.509 Common Name Vulnerability," a related issue to CVE-2009-2408.
16629| [CVE-2009-2509] Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly validate headers in HTTP requests, which allows remote authenticated users to execute arbitrary code via a crafted request to an IIS web server, aka "Remote Code Execution in ADFS Vulnerability."
16630| [CVE-2009-2508] The single sign-on implementation in Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly remove credentials at the end of a network session, which allows physically proximate attackers to obtain the credentials of a previous user of the same web browser by using data from the browser's cache, aka "Single Sign On Spoofing in ADFS Vulnerability."
16631| [CVE-2009-2507] A certain ActiveX control in the Indexing Service in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly process URLs, which allows remote attackers to execute arbitrary programs via unspecified vectors that cause a "vulnerable binary" to load and run, aka "Memory Corruption in Indexing Service Vulnerability."
16632| [CVE-2009-2506] Integer overflow in the text converters in Microsoft Office Word 2002 SP3 and 2003 SP3
16633| [CVE-2009-2505] The Internet Authentication Service (IAS) in Microsoft Windows Vista SP2 and Server 2008 SP2 does not properly validate MS-CHAP v2 Protected Extensible Authentication Protocol (PEAP) authentication requests, which allows remote attackers to execute arbitrary code via crafted structures in a malformed request, aka "Internet Authentication Service Memory Corruption Vulnerability."
16634| [CVE-2009-2504] Multiple integer overflows in unspecified APIs in GDI+ in Microsoft .NET Framework 1.1 SP1, .NET Framework 2.0 SP1 and SP2, Windows XP SP2 and SP3, Windows Server 2003 SP2, Vista Gold and SP1, Server 2008 Gold, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allow remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "GDI+ .NET API Vulnerability."
16635| [CVE-2009-2503] GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 does not properly allocate an unspecified buffer, which allows remote attackers to execute arbitrary code via a crafted TIFF image file that triggers memory corruption, aka "GDI+ TIFF Memory Corruption Vulnerability."
16636| [CVE-2009-2502] Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted TIFF image file, aka "GDI+ TIFF Buffer Overflow Vulnerability."
16637| [CVE-2009-2501] Heap-based buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted PNG image file, aka "GDI+ PNG Heap Overflow Vulnerability."
16638| [CVE-2009-2500] Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted WMF image file, aka "GDI+ WMF Integer Overflow Vulnerability."
16639| [CVE-2009-2498] Microsoft Windows Media Format Runtime 9.0, 9.5, and 11 and Windows Media Services 9.1 and 2008 do not properly parse malformed headers in Advanced Systems Format (ASF) files, which allows remote attackers to execute arbitrary code via a crafted (1) .asf, (2) .wmv, or (3) .wma file, aka "Windows Media Header Parsing Invalid Free Vulnerability."
16640| [CVE-2009-2497] The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0, 2.0 SP1, 2.0 SP2, 3.5, and 3.5 SP1, and Silverlight 2, does not properly handle interfaces, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted Silverlight application, (3) a crafted ASP.NET application, or (4) a crafted .NET Framework application, aka "Microsoft Silverlight and Microsoft .NET Framework CLR Vulnerability."
16641| [CVE-2009-2496] Heap-based buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 SP1, and Office Small Business Accounting 2006 allows remote attackers to execute arbitrary code via unspecified parameters to unknown methods, aka "Office Web Components Heap Corruption Vulnerability."
16642| [CVE-2009-2495] The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1 does not properly enforce string termination, which allows remote attackers to obtain sensitive information via a crafted HTML document with an ATL (1) component or (2) control that triggers a buffer over-read, related to ATL headers and buffer allocation, aka "ATL Null String Vulnerability."
16643| [CVE-2009-2494] The Active Template Library (ATL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via vectors related to erroneous free operations after reading a variant from a stream and deleting this variant, aka "ATL Object Type Mismatch Vulnerability."
16644| [CVE-2009-2493] The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1
16645| [CVE-2009-1930] The Telnet service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote Telnet servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user, aka "Telnet Credential Reflection Vulnerability," a related issue to CVE-2000-0834.
16646| [CVE-2009-1929] Heap-based buffer overflow in the Microsoft Terminal Services Client ActiveX control running RDP 6.1 on Windows XP SP2, Vista SP1 or SP2, or Server 2008 Gold or SP2
16647| [CVE-2009-1928] Stack consumption vulnerability in the LDAP service in Active Directory on Microsoft Windows 2000 SP4, Server 2003 SP2, and Server 2008 Gold and SP2
16648| [CVE-2009-1926] Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to cause a denial of service (TCP outage) via a series of TCP sessions that have pending data and a (1) small or (2) zero receive window size, and remain in the FIN-WAIT-1 or FIN-WAIT-2 state indefinitely, aka "TCP/IP Orphaned Connections Vulnerability."
16649| [CVE-2009-1925] The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 does not properly manage state information, which allows remote attackers to execute arbitrary code by sending packets to a listening service, and thereby triggering misinterpretation of an unspecified field as a function pointer, aka "TCP/IP Timestamps Code Execution Vulnerability."
16650| [CVE-2009-1924] Integer overflow in the Windows Internet Name Service (WINS) component for Microsoft Windows 2000 SP4 allows remote WINS replication partners to execute arbitrary code via crafted data structures in a packet, aka "WINS Integer Overflow Vulnerability."
16651| [CVE-2009-1923] Heap-based buffer overflow in the Windows Internet Name Service (WINS) component for Microsoft Windows 2000 SP4 and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted WINS replication packet that triggers an incorrect buffer-length calculation, aka "WINS Heap Overflow Vulnerability."
16652| [CVE-2009-1922] The Message Queuing (aka MSMQ) service for Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP2, and Vista Gold does not properly validate unspecified IOCTL request data from user mode before passing this data to kernel mode, which allows local users to gain privileges via a crafted request, aka "MSMQ Null Pointer Vulnerability."
16653| [CVE-2009-1546] Integer overflow in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windows allows remote attackers to execute arbitrary code on a Windows 2000 SP4 system via a crafted AVI file, or cause a denial of service on a Windows XP SP2 or SP3, Server 2003 SP2, Vista Gold, SP1, or SP2, or Server 2008 Gold or SP2 system via a crafted AVI file, aka "AVI Integer Overflow Vulnerability."
16654| [CVE-2009-1545] Unspecified vulnerability in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a malformed header in a crafted AVI file, aka "Malformed AVI Header Vulnerability."
16655| [CVE-2009-1544] Double free vulnerability in the Workstation service in Microsoft Windows allows remote authenticated users to gain privileges via a crafted RPC message to a Windows XP SP2 or SP3 or Server 2003 SP2 system, or cause a denial of service via a crafted RPC message to a Vista Gold, SP1, or SP2 or Server 2008 Gold or SP2 system, aka "Workstation Service Memory Corruption Vulnerability."
16656| [CVE-2009-1542] The Virtual Machine Monitor (VMM) in Microsoft Virtual PC 2004 SP1, 2007, and 2007 SP1, and Microsoft Virtual Server 2005 R2 SP1, does not enforce CPU privilege-level requirements for all machine instructions, which allows guest OS users to execute arbitrary kernel-mode code and gain privileges within the guest OS via a crafted application, aka "Virtual PC and Virtual Server Privileged Instruction Decoding Vulnerability."
16657| [CVE-2009-1539] The QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 does not properly validate unspecified size fields in QuickTime media files, which allows remote attackers to execute arbitrary code via a crafted file, aka "DirectX Size Validation Vulnerability."
16658| [CVE-2009-1538] The QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 performs updates to pointers without properly validating unspecified data values, which allows remote attackers to execute arbitrary code via a crafted QuickTime media file, aka "DirectX Pointer Validation Vulnerability."
16659| [CVE-2009-1537] Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted QuickTime media file, as exploited in the wild in May 2009, aka "DirectX NULL Byte Overwrite Vulnerability."
16660| [CVE-2009-1536] ASP.NET in Microsoft .NET Framework 2.0 SP1 and SP2 and 3.5 Gold and SP1, when ASP 2.0 is used in integrated mode on IIS 7.0, does not properly manage request scheduling, which allows remote attackers to cause a denial of service (daemon outage) via a series of crafted HTTP requests, aka "Remote Unauthenticated Denial of Service in ASP.NET Vulnerability."
16661| [CVE-2009-1534] Buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2000 Web Components SP3, Office XP Web Components SP3, BizTalk Server 2002, and Visual Studio .NET 2003 SP1 allows remote attackers to execute arbitrary code via crafted property values, aka "Office Web Components Buffer Overflow Vulnerability."
16662| [CVE-2009-1533] Buffer overflow in the Works for Windows document converters in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, Office 2007 SP1, and Works 8.5 and 9 allows remote attackers to execute arbitrary code via a crafted Works .wps file that triggers memory corruption, aka "File Converter Buffer Overflow Vulnerability."
16663| [CVE-2009-1491] McAfee GroupShield for Microsoft Exchange on Exchange Server 2000, and possibly other anti-virus or anti-spam products from McAfee or other vendors, does not scan X- headers for malicious content, which allows remote attackers to bypass virus detection via a crafted message, as demonstrated by a message with an X-Testing header and no message body.
16664| [CVE-2009-1216] Multiple unspecified vulnerabilities in (1) unlzh.c and (2) unpack.c in the gzip libraries in Microsoft Windows Server 2008, Windows Services for UNIX 3.0 and 3.5, and the Subsystem for UNIX-based Applications (SUA)
16665| [CVE-2009-1141] Microsoft Internet Explorer 6 for Windows XP SP2 and SP3 and Server 2003 SP2 allows remote attackers to execute arbitrary code via unspecified DHTML function calls related to a tr element and the "insertion, deletion and attributes of a table cell," which trigger memory corruption when the window is destroyed, aka "DHTML Object Memory Corruption Vulnerability."
16666| [CVE-2009-1139] Memory leak in the LDAP service in Active Directory on Microsoft Windows 2000 SP4 and Server 2003 SP2, and Active Directory Application Mode (ADAM) on Windows XP SP2 and SP3 and Server 2003 SP2, allows remote attackers to cause a denial of service (memory consumption and service outage) via (1) LDAP or (2) LDAPS requests with unspecified OID filters, aka "Active Directory Memory Leak Vulnerability."
16667| [CVE-2009-1138] The LDAP service in Active Directory on Microsoft Windows 2000 SP4 does not properly free memory for LDAP and LDAPS requests, which allows remote attackers to execute arbitrary code via a request that uses hexadecimal encoding, whose associated memory is not released, related to a "DN AttributeValue," aka "Active Directory Invalid Free Vulnerability." NOTE: this issue is probably a memory leak.
16668| [CVE-2009-1137] Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0223, CVE-2009-0226, and CVE-2009-0227.
16669| [CVE-2009-1136] The Microsoft Office Web Components Spreadsheet ActiveX control (aka OWC10 or OWC11), as distributed in Office XP SP3 and Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 Gold and SP1, and Office Small Business Accounting 2006, when used in Internet Explorer, allows remote attackers to execute arbitrary code via a crafted call to the msDataSourceObject method, as exploited in the wild in July and August 2009, aka "Office Web Components HTML Script Vulnerability."
16670| [CVE-2009-1135] Microsoft Internet Security and Acceleration (ISA) Server 2006 Gold and SP1, when Radius OTP is enabled, uses the HTTP-Basic authentication method, which allows remote attackers to gain the privileges of an arbitrary account, and access published web pages, via vectors involving attempted access to a network resource behind the ISA Server, aka "Radius OTP Bypass Vulnerability."
16671| [CVE-2009-1134] Excel in 2007 Microsoft Office System SP1 and SP2
16672| [CVE-2009-1133] Heap-based buffer overflow in Microsoft Remote Desktop Connection (formerly Terminal Services Client) running RDP 5.0 through 6.1 on Windows, and Remote Desktop Connection Client for Mac 2.0, allows remote attackers to execute arbitrary code via unspecified parameters, aka "Remote Desktop Connection Heap Overflow Vulnerability."
16673| [CVE-2009-1132] Heap-based buffer overflow in the Wireless LAN AutoConfig Service (aka Wlansvc) in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a malformed wireless frame, aka "Wireless Frame Parsing Remote Code Execution Vulnerability."
16674| [CVE-2009-1131] Multiple stack-based buffer overflows in Microsoft Office PowerPoint 2000 SP3 allow remote attackers to execute arbitrary code via a large amount of data associated with unspecified atoms in a PowerPoint file that triggers memory corruption, aka "Data Out of Bounds Vulnerability."
16675| [CVE-2009-1130] Heap-based buffer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a crafted structure in a Notes container in a PowerPoint file that causes PowerPoint to read more data than was allocated when creating a C++ object, leading to an overwrite of a function pointer, aka "Heap Corruption Vulnerability."
16676| [CVE-2009-1129] Multiple stack-based buffer overflows in the PowerPoint 95 importer (PP7X32.DLL) in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allow remote attackers to execute arbitrary code via an inconsistent record length in sound data in a file that uses a PowerPoint 95 (PPT95) native file format, aka "PP7 Memory Corruption Vulnerability," a different vulnerability than CVE-2009-1128.
16677| [CVE-2009-1128] Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 95 native file format, leading to memory corruption, aka "PP7 Memory Corruption Vulnerability," a different vulnerability than CVE-2009-1129.
16678| [CVE-2009-1127] win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not correctly validate an argument to an unspecified system call, which allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, aka "Win32k NULL Pointer Dereferencing Vulnerability."
16679| [CVE-2009-1126] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly validate the user-mode input associated with the editing of an unspecified desktop parameter, which allows local users to gain privileges via a crafted application, aka "Windows Desktop Parameter Edit Vulnerability."
16680| [CVE-2009-1125] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate an argument to an unspecified system call, which allows local users to gain privileges via a crafted application, aka "Windows Driver Class Registration Vulnerability."
16681| [CVE-2009-1124] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate user-mode pointers in unspecified error conditions, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Pointer Validation Vulnerability."
16682| [CVE-2009-1123] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Desktop Vulnerability."
16683| [CVE-2009-1122] The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote attackers to bypass authentication, and possibly read or create files, via a crafted HTTP request, aka "IIS 5.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1535.
16684| [CVE-2009-1043] Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors triggered by clicking on a link, as demonstrated by Nils during a PWN2OWN competition at CanSecWest 2009.
16685| [CVE-2009-1011] Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on reliable researcher claims that this issue is for multiple integer overflows in a function that parses an optional data stream within a Microsoft Office file, leading to a heap-based buffer overflow.
16686| [CVE-2009-0901] The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold, and Visual C++ 2005 SP1 and 2008 Gold and SP1
16687| [CVE-2009-0568] The RPC Marshalling Engine (aka NDR) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly maintain its internal state, which allows remote attackers to overwrite arbitrary memory locations via a crafted RPC message that triggers incorrect pointer reading, related to "IDL interfaces containing a non-conformant varying array" and FC_SMVARRAY, FC_LGVARRAY, FC_VARIABLE_REPEAT, and FC_VARIABLE_OFFSET, aka "RPC Marshalling Engine Vulnerability."
16688| [CVE-2009-0566] Microsoft Office Publisher 2007 SP1 does not properly calculate object handler data for Publisher files, which allows remote attackers to execute arbitrary code via a crafted file in a legacy format that triggers memory corruption, aka "Pointer Dereference Vulnerability."
16689| [CVE-2009-0565] Buffer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, and 2007 SP1 and SP2
16690| [CVE-2009-0563] Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
16691| [CVE-2009-0562] The Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 SP1, and Office Small Business Accounting 2006 does not properly allocate memory, which allows remote attackers to execute arbitrary code via unspecified vectors that trigger "system state" corruption, aka "Office Web Components Memory Allocation Vulnerability."
16692| [CVE-2009-0561] Integer overflow in Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac
16693| [CVE-2009-0560] Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac
16694| [CVE-2009-0559] Stack-based buffer overflow in Excel in Microsoft Office 2000 SP3 and Office XP SP3 allows remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "String Copy Stack-Based Overrun Vulnerability."
16695| [CVE-2009-0558] Array index error in Excel in Microsoft Office 2000 SP3 and Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac, allows remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Array Indexing Memory Corruption Vulnerability."
16696| [CVE-2009-0557] Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac
16697| [CVE-2009-0556] Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an an invalid index value that triggers memory corruption, as exploited in the wild in April 2009 by Exploit:Win32/Apptom.gen, aka "Memory Corruption Vulnerability."
16698| [CVE-2009-0554] Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka "Uninitialized Memory Corruption Vulnerability."
16699| [CVE-2009-0553] Microsoft Internet Explorer 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka "Uninitialized Memory Corruption Vulnerability."
16700| [CVE-2009-0552] Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 on Windows XP SP2 and SP3, and 6 on Windows Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka "Uninitialized Memory Corruption Vulnerability."
16701| [CVE-2009-0551] Microsoft Internet Explorer 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 does not properly handle transition errors in a request for one HTTP document followed by a request for a second HTTP document, which allows remote attackers to execute arbitrary code via vectors involving (1) multiple crafted pages on a web site or (2) a web page with crafted inline content such as banner advertisements, aka "Page Transition Memory Corruption Vulnerability."
16702| [CVE-2009-0550] Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008
16703| [CVE-2009-0549] Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac
16704| [CVE-2009-0320] Microsoft Windows XP, Server 2003 and 2008, and Vista exposes I/O activity measurements of all processes, which allows local users to obtain sensitive information, as demonstrated by reading the I/O Other Bytes column in Task Manager (aka taskmgr.exe) to estimate the number of characters that a different user entered at a runas.exe password prompt, related to a "benchmarking attack."
16705| [CVE-2009-0239] Cross-site scripting (XSS) vulnerability in Windows Search 4.0 for Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted file that appears in a preview in a search result, aka "Script Execution in Windows Search Vulnerability."
16706| [CVE-2009-0238] Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1
16707| [CVE-2009-0235] Stack-based buffer overflow in the Word 97 text converter in WordPad in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted Word 97 file that triggers memory corruption, related to use of inconsistent integer data sizes for an unspecified length field, aka "WordPad Word 97 Text Converter Stack Overflow Vulnerability."
16708| [CVE-2009-0234] The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008 does not properly cache crafted DNS responses, which makes it easier for remote attackers to predict transaction IDs and poison caches by sending many crafted DNS queries that trigger "unnecessary lookups," aka "DNS Server Response Validation Vulnerability."
16709| [CVE-2009-0233] The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not reuse cached DNS responses in all applicable situations, which makes it easier for remote attackers to predict transaction IDs and poison caches by simultaneously sending crafted DNS queries and responses, aka "DNS Server Query Validation Vulnerability."
16710| [CVE-2009-0232] Integer overflow in the Embedded OpenType (EOT) Font Engine in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted name table, aka "Embedded OpenType Font Integer Overflow Vulnerability."
16711| [CVE-2009-0231] The Embedded OpenType (EOT) Font Engine (T2EMBED.DLL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted name table in a data record that triggers an integer truncation and a heap-based buffer overflow, aka "Embedded OpenType Font Heap Overflow Vulnerability."
16712| [CVE-2009-0230] The Windows Print Spooler in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows remote authenticated users to gain privileges via a crafted RPC message that triggers loading of a DLL file from an arbitrary directory, aka "Print Spooler Load Library Vulnerability."
16713| [CVE-2009-0229] The Windows Printing Service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows local users to read arbitrary files via a crafted separator page, aka "Print Spooler Read File Vulnerability."
16714| [CVE-2009-0228] Stack-based buffer overflow in the EnumeratePrintShares function in Windows Print Spooler Service (win32spl.dll) in Microsoft Windows 2000 SP4 allows remote printer servers to execute arbitrary code via a a crafted ShareName in a response to an RPC request, related to "printing data structures," aka "Buffer Overflow in Print Spooler Vulnerability."
16715| [CVE-2009-0227] Stack-based buffer overflow in the PowerPoint 4.2 conversion filter (PP4X32.DLL) in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via a large number of structures in sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0223, CVE-2009-0226, and CVE-2009-1137.
16716| [CVE-2009-0226] Stack-based buffer overflow in the PowerPoint 4.2 conversion filter in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via a long string in sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0223, CVE-2009-0227, and CVE-2009-1137.
16717| [CVE-2009-0225] Microsoft Office PowerPoint 2002 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 95 native file format, leading to improper "array indexing" and memory corruption, aka "PP7 Memory Corruption Vulnerability."
16718| [CVE-2009-0224] Microsoft Office PowerPoint 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
16719| [CVE-2009-0223] Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0226, CVE-2009-0227, and CVE-2009-1137.
16720| [CVE-2009-0222] Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 4.0 native file format, leading to a "pointer overwrite" and memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0223, CVE-2009-0226, CVE-2009-0227, and CVE-2009-1137.
16721| [CVE-2009-0221] Integer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a PowerPoint file containing a crafted record type for "collaboration information for different slides" that contains a field that specifies a large number of records, which triggers an under-allocated buffer and a heap-based buffer overflow, aka "Integer Overflow Vulnerability."
16722| [CVE-2009-0220] Multiple stack-based buffer overflows in the PowerPoint 4.0 importer (PP4X32.DLL) in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allow remote attackers to execute arbitrary code via crafted formatting data for paragraphs in a file that uses a PowerPoint 4.0 native file format, related to (1) an incorrect calculation from a record header, or (2) an interget that is used to specify the number of bytes to copy, aka "Legacy File Format Vulnerability."
16723| [CVE-2009-0202] Array index error in FL21WIN.DLL in the PowerPoint Freelance Windows 2.1 Translator in Microsoft PowerPoint 2000 and 2002 allows remote attackers to execute arbitrary code via a Freelance file with unspecified "layout information" that triggers a heap-based buffer overflow.
16724| [CVE-2009-0102] Microsoft Project 2000 SR1 and 2002 SP1, and Office Project 2003 SP3, does not properly handle memory allocation for Project files, which allows remote attackers to execute arbitrary code via a malformed file, aka "Project Memory Validation Vulnerability."
16725| [CVE-2009-0100] Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1
16726| [CVE-2009-0099] The Electronic Messaging System Microsoft Data Base (EMSMDB32) provider in Microsoft Exchange 2000 Server SP3 and Exchange Server 2003 SP2, as used in Exchange System Attendant, allows remote attackers to cause a denial of service (application outage) via a malformed MAPI command, aka "Literal Processing Vulnerability."
16727| [CVE-2009-0098] Microsoft Exchange 2000 Server SP3, Exchange Server 2003 SP2, and Exchange Server 2007 SP1 do not properly interpret Transport Neutral Encapsulation (TNEF) properties, which allows remote attackers to execute arbitrary code via a crafted TNEF message, aka "Memory Corruption Vulnerability."
16728| [CVE-2009-0097] Microsoft Office Visio 2002 SP2 and 2003 SP3 does not properly validate memory allocation for Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Memory Corruption Vulnerability."
16729| [CVE-2009-0096] Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 does not properly perform memory copy operations for object data, which allows remote attackers to execute arbitrary code via a crafted Visio document, aka "Memory Corruption Vulnerability."
16730| [CVE-2009-0095] Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 does not properly validate object data in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Memory Validation Vulnerability."
16731| [CVE-2009-0094] The WINS server in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 does not restrict registration of the (1) "wpad" and (2) "isatap" NetBIOS names, which allows remote authenticated users to hijack the Web Proxy Auto-Discovery (WPAD) and Intra-Site Automatic Tunnel Addressing Protocol (ISATAP) features, and conduct man-in-the-middle attacks by spoofing a proxy server or ISATAP route, by registering one of these names in the WINS database, aka "WPAD WINS Server Registration Vulnerability," a related issue to CVE-2007-1692.
16732| [CVE-2009-0093] Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not restrict registration of the "wpad" hostname, which allows remote authenticated users to hijack the Web Proxy Auto-Discovery (WPAD) feature, and conduct man-in-the-middle attacks by spoofing a proxy server, via a Dynamic Update request for this hostname, aka "DNS Server Vulnerability in WPAD Registration Vulnerability," a related issue to CVE-2007-1692.
16733| [CVE-2009-0091] Microsoft .NET Framework 2.0, 2.0 SP1, and 3.5 does not properly enforce a certain type-equality constraint in .NET verifiable code, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft .NET Framework Type Verification Vulnerability."
16734| [CVE-2009-0090] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, and 2.0 SP1 does not properly validate .NET verifiable code, which allows remote attackers to obtain unintended access to stack memory, and execute arbitrary code, via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft .NET Framework Pointer Verification Vulnerability."
16735| [CVE-2009-0089] Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Vista Gold allows remote web servers to impersonate arbitrary https web sites by using DNS spoofing to "forward a connection" to a different https web site that has a valid certificate matching its own domain name, but not a certificate matching the domain name of the host requested by the user, aka "Windows HTTP Services Certificate Name Mismatch Vulnerability."
16736| [CVE-2009-0088] The WordPerfect 6.x Converter (WPFT632.CNV, 1998.1.27.0) in Microsoft Office Word 2000 SP3 and Microsoft Office Converter Pack does not properly validate the length of an unspecified string, which allows remote attackers to execute arbitrary code via a crafted WordPerfect 6.x file, related to an unspecified counter and control structures on the stack, aka "Word 2000 WordPerfect 6.x Converter Stack Corruption Vulnerability."
16737| [CVE-2009-0087] Unspecified vulnerability in the Word 6 text converter in WordPad in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2
16738| [CVE-2009-0086] Integer underflow in Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote HTTP servers to execute arbitrary code via crafted parameter values in a response, related to error handling, aka "Windows HTTP Services Integer Underflow Vulnerability."
16739| [CVE-2009-0085] The Secure Channel (aka SChannel) authentication component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008, when certificate authentication is used, does not properly validate the client's key exchange data in Transport Layer Security (TLS) handshake messages, which allows remote attackers to spoof authentication by crafting a TLS packet based on knowledge of the certificate but not the private key, aka "SChannel Spoofing Vulnerability."
16740| [CVE-2009-0083] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 does not properly handle invalid pointers, which allows local users to gain privileges via an application that triggers use of a crafted pointer, aka "Windows Kernel Invalid Pointer Vulnerability."
16741| [CVE-2009-0082] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate handles, which allows local users to gain privileges via a crafted application that triggers unspecified "actions," aka "Windows Kernel Handle Validation Vulnerability."
16742| [CVE-2009-0081] The graphics device interface (GDI) implementation in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate input received from user mode, which allows remote attackers to execute arbitrary code via a crafted (1) Windows Metafile (aka WMF) or (2) Enhanced Metafile (aka EMF) image file, aka "Windows Kernel Input Validation Vulnerability."
16743| [CVE-2009-0079] The RPCSS service in Microsoft Windows XP SP2 and SP3 and Server 2003 SP1 and SP2 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by accessing the resources of one of the processes, aka "Windows RPCSS Service Isolation Vulnerability."
16744| [CVE-2009-0078] The Windows Management Instrumentation (WMI) provider in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by accessing the resources of one of the processes, aka "Windows WMI Service Isolation Vulnerability."
16745| [CVE-2008-7217] Microsoft Office 2008 for Mac, when running on Macintosh systems that restrict Office access to administrators, does not enforce this restriction for user ID 502, which allows local users with that ID to bypass intended security policy and access Office programs, related to permissions and ownership for certain directories.
16746| [CVE-2008-6819] win32k.sys in Microsoft Windows Server 2003 and Vista allows local users to cause a denial of service (system crash) via vectors related to CreateWindow, TranslateMessage, and DispatchMessage, possibly a race condition between threads, a different vulnerability than CVE-2008-1084. NOTE: some of these details are obtained from third party information.
16747| [CVE-2008-6219] nsrexecd.exe in multiple EMC Networker products including EMC NetWorker Server, Storage Node, and Client 7.3.x and 7.4, 7.4.1, 7.4.2, Client and Storage Node for Open VMS 7.3.2 ECO6 and earlier, Module for Microsoft Exchange 5.1 and earlier, Module for Microsoft Applications 2.0 and earlier, Module for Meditech 2.0 and earlier, and PowerSnap 2.4 SP1 and earlier does not properly control the allocation of memory, which allows remote attackers to cause a denial of service (memory exhaustion) via multiple crafted RPC requests.
16748| [CVE-2008-6063] Microsoft Word 2007, when the "Save as PDF" add-on is enabled, places an absolute pathname in the Subject field during an "Email as PDF" operation, which allows remote attackers to obtain sensitive information such as the sender's account name and a Temporary Internet Files subdirectory name.
16749| [CVE-2008-5912] An unspecified function in the JavaScript implementation in Microsoft Internet Explorer creates and exposes a "temporary footprint" when there is a current login to a web site, which makes it easier for remote attackers to trick a user into acting upon a spoofed pop-up message, aka an "in-session phishing attack." NOTE: as of 20090116, the only disclosure is a vague pre-advisory with no actionable information. However, because it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.
16750| [CVE-2008-5823] An ActiveX control in prtstb06.dll in Microsoft Money 2006, when used with WScript in Windows Script Host (WSH) on Windows Vista, allows remote attackers to cause a denial of service (access violation and application crash) via a zero value for the Startup property.
16751| [CVE-2008-5416] Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier
16752| [CVE-2008-5232] Buffer overflow in the CallHTMLHelp method in the Microsoft Windows Media Services ActiveX control in nskey.dll 4.1.00.3917 in Windows Media Services on Microsoft Windows NT and 2000, and Avaya Media and Message Application servers, allows remote attackers to execute arbitrary code via a long argument. NOTE: the provenance of this information is unknown
16753| [CVE-2008-5112] The LDAP server in Active Directory in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 responds differently to a failed bind attempt depending on whether the user account exists and is permitted to login, which allows remote attackers to enumerate valid usernames via a series of LDAP bind requests, as demonstrated by ldapuserenum.
16754| [CVE-2008-5100] The strong name (SN) implementation in Microsoft .NET Framework 2.0.50727 relies on the digital signature Public Key Token embedded in the pathname of a DLL file instead of the digital signature of this file itself, which makes it easier for attackers to bypass Global Assembly Cache (GAC) and Code Access Security (CAS) protection mechanisms, aka MSRC ticket MSRC8566gs.
16755| [CVE-2008-5044] Race condition in Microsoft Windows Server 2003 and Vista allows local users to cause a denial of service (crash or hang) via a multi-threaded application that makes many calls to UnhookWindowsHookEx while certain other desktop activity is occurring.
16756| [CVE-2008-4844] Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via DSO bindings involving (1) an XML Island, (2) XML DSOs, or (3) Tabular Data Control (TDC) in a crafted HTML or XML document, as demonstrated by nested SPAN or MARQUEE elements, and exploited in the wild in December 2008.
16757| [CVE-2008-4841] The WordPad Text Converter for Word 97 files in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf Word 97 file that triggers memory corruption, as exploited in the wild in December 2008. NOTE: As of 20081210, it is unclear whether this vulnerability is related to a WordPad issue disclosed on 20080925 with a 2008-crash.doc.rar example, but there are insufficient details to be sure.
16758| [CVE-2008-4837] Stack-based buffer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
16759| [CVE-2008-4835] SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside the SMB packets" in an NT Trans2 request, related to "insufficiently validating the buffer size," aka "SMB Validation Remote Code Execution Vulnerability."
16760| [CVE-2008-4834] Buffer overflow in SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside the SMB packets" in an NT Trans request, aka "SMB Buffer Overflow Remote Code Execution Vulnerability."
16761| [CVE-2008-4493] Microsoft PicturePusher ActiveX control (PipPPush.DLL 7.00.0709), as used in Microsoft Digital Image 2006 Starter Edition, allows remote attackers to force the upload of arbitrary files by using the AddString and Post methods and a modified PostURL to construct an HTTP POST request. NOTE: this issue might only be exploitable in limited environments or non-default browser settings.
16762| [CVE-2008-4295] Microsoft Windows Mobile 6.0 on HTC Wiza 200 and HTC MDA 8125 devices does not properly handle the first attempt to establish a Bluetooth connection to a peer with a long name, which allows remote attackers to cause a denial of service (device reboot) by configuring a Bluetooth device with a long hci name and (1) connecting directly to the Windows Mobile system or (2) waiting for the Windows Mobile system to scan for nearby devices.
16763| [CVE-2008-4269] The search-ms protocol handler in Windows Explorer in Microsoft Windows Vista Gold and SP1 and Server 2008 uses untrusted parameter data obtained from incorrect parsing, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "Windows Search Parsing Vulnerability."
16764| [CVE-2008-4268] The Windows Search component in Microsoft Windows Vista Gold and SP1 and Server 2008 does not properly free memory during a save operation for a Windows Search file, which allows remote attackers to execute arbitrary code via a crafted saved-search file, aka "Windows Saved Search Vulnerability."
16765| [CVE-2008-4266] Array index vulnerability in Microsoft Office Excel 2000 SP3, 2002 SP3, and 2003 SP3
16766| [CVE-2008-4265] Microsoft Office Excel 2000 SP3 allows remote attackers to execute arbitrary code via a crafted Excel spreadsheet that contains a malformed object, which triggers memory corruption during the loading of records from this spreadsheet, aka "File Format Parsing Vulnerability."
16767| [CVE-2008-4264] Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
16768| [CVE-2008-4261] Stack-based buffer overflow in Microsoft Internet Explorer 5.01 SP4, 6 SP1 on Windows 2000, and 6 on Windows XP and Server 2003 does not properly handle extraneous data associated with an object embedded in a web page, which allows remote attackers to execute arbitrary code via crafted HTML tags that trigger memory corruption, aka "HTML Rendering Memory Corruption Vulnerability."
16769| [CVE-2008-4256] The Charts ActiveX control in Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the "system state," aka "Charts Control Memory Corruption Vulnerability."
16770| [CVE-2008-4255] Heap-based buffer overflow in mscomct2.ocx (aka Windows Common ActiveX control or Microsoft Animation ActiveX control) in Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2, and Office Project 2003 SP3 and 2007 Gold and SP1 allows remote attackers to execute arbitrary code via an AVI file with a crafted stream length, which triggers an "allocation error" and memory corruption, aka "Windows Common AVI Parsing Overflow Vulnerability."
16771| [CVE-2008-4253] The FlexGrid ActiveX control in Microsoft Visual Basic 6.0, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2, Office FrontPage 2002 SP3, and Office Project 2003 SP3 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the "system state," aka "FlexGrid Control Memory Corruption Vulnerability."
16772| [CVE-2008-4250] The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by Gimmiv.A in October 2008, aka "Server Service Vulnerability."
16773| [CVE-2008-4114] srv.sys in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via an SMB WRITE_ANDX packet with an offset that is inconsistent with the packet size, related to "insufficiently validating the buffer size," as demonstrated by a request to the \PIPE\lsarpc named pipe, aka "SMB Validation Denial of Service Vulnerability."
16774| [CVE-2008-4110] Buffer overflow in the SQLVDIRLib.SQLVDirControl ActiveX control in Tools\Binn\sqlvdir.dll in Microsoft SQL Server 2000 (aka SQL Server 8.0) allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a long URL in the second argument to the Connect method. NOTE: this issue is not a vulnerability in many environments, since the control is not marked as safe for scripting and would not execute with default Internet Explorer settings.
16775| [CVE-2008-4038] Buffer underflow in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via a Server Message Block (SMB) request that contains a filename with a crafted length, aka "SMB Buffer Underflow Vulnerability."
16776| [CVE-2008-4037] Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote SMB servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user, as demonstrated by backrush, aka "SMB Credential Reflection Vulnerability." NOTE: some reliable sources report that this vulnerability exists because of an insufficient fix for CVE-2000-0834.
16777| [CVE-2008-4036] Integer overflow in Memory Manager in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows local users to gain privileges via a crafted application that triggers an erroneous decrement of a variable, related to validation of parameters for Virtual Address Descriptors (VADs) and a "memory allocation mapping error," aka "Virtual Address Descriptor Elevation of Privilege Vulnerability."
16778| [CVE-2008-4032] Microsoft Office SharePoint Server 2007 Gold and SP1 and Microsoft Search Server 2008 do not properly perform authentication and authorization for administrative functions, which allows remote attackers to cause a denial of service (server load), obtain sensitive information, and "create scripts that would run in the context of the site" via requests to administrative URIs, aka "Access Control Vulnerability."
16779| [CVE-2008-4031] Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
16780| [CVE-2008-4030] Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
16781| [CVE-2008-4028] Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
16782| [CVE-2008-4027] Double free vulnerability in Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
16783| [CVE-2008-4026] Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
16784| [CVE-2008-4025] Integer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
16785| [CVE-2008-4024] Microsoft Office Word 2000 SP3 and 2002 SP3 and Office 2004 for Mac allow remote attackers to execute arbitrary code via a Word document with a crafted lcbPlcfBkfSdt field in the File Information Block (FIB), which bypasses an initialization step and triggers an "arbitrary free," aka "Word Memory Corruption Vulnerability."
16786| [CVE-2008-4023] Active Directory in Microsoft Windows 2000 SP4 does not properly allocate memory for (1) LDAP and (2) LDAPS requests, which allows remote attackers to execute arbitrary code via a crafted request, aka "Active Directory Overflow Vulnerability."
16787| [CVE-2008-4019] Integer overflow in the REPT function in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1
16788| [CVE-2008-3956] orgchart.exe in Microsoft Organization Chart 2.00 allows user-assisted attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted .opx file.
16789| [CVE-2008-3704] Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions before 6.0.84.18, in Microsoft Visual Studio 6.0, Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 allows remote attackers to execute arbitrary code via a long Mask parameter, related to not "validating property values with boundary checks," as exploited in the wild in August 2008, aka "Masked Edit Control Memory Corruption Vulnerability."
16790| [CVE-2008-3648] nslookup.exe in Microsoft Windows XP SP2 allows user-assisted remote attackers to execute arbitrary code, as demonstrated by an attempted DNS zone transfer, and as exploited in the wild in August 2008.
16791| [CVE-2008-3636] Integer overflow in the IopfCompleteRequest API in the kernel in Microsoft Windows 2000, XP, Server 2003, and Vista allows context-dependent attackers to gain privileges. NOTE: this issue was originally reported for GEARAspiWDM.sys 2.0.7.5 in Gear Software CD DVD Filter driver before 4.001.7, as used in other products including Apple iTunes and multiple Symantec and Norton products, which allows local users to gain privileges via repeated IoAttachDevice IOCTL calls to \\.\GEARAspiWDMDevice in this GEARAspiWDM.sys. However, the root cause is the integer overflow in the API call itself.
16792| [CVE-2008-3479] Heap-based buffer overflow in the Microsoft Message Queuing (MSMQ) service (mqsvc.exe) in Microsoft Windows 2000 SP4 allows remote attackers to read memory contents and execute arbitrary code via a crafted RPC call, related to improper processing of parameters to string APIs, aka "Message Queuing Service Remote Code Execution Vulnerability."
16793| [CVE-2008-3477] Microsoft Excel 2000 SP3, 2002 SP3, and 2003 SP2 and SP3 does not properly validate data in the VBA Performance Cache when processing an Office document with an embedded object, which allows remote attackers to execute arbitrary code via an Excel file containing a crafted value, leading to heap-based buffer overflows, integer overflows, array index errors, and memory corruption, aka "Calendar Object Validation Vulnerability."
16794| [CVE-2008-3471] Stack-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1
16795| [CVE-2008-3466] Microsoft Host Integration Server (HIS) 2000, 2004, and 2006 does not limit RPC access to administrative functions, which allows remote attackers to bypass authentication and execute arbitrary programs via a crafted SNA RPC message using opcode 1 or 6 to call the CreateProcess function, aka "HIS Command Execution Vulnerability."
16796| [CVE-2008-3465] Heap-based buffer overflow in an API in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows context-dependent attackers to cause a denial of service or execute arbitrary code via a WMF file with a malformed file-size parameter, which would not be properly handled by a third-party application that uses this API for a copy operation, aka "GDI Heap Overflow Vulnerability."
16797| [CVE-2008-3464] afd.sys in the Ancillary Function Driver (AFD) component in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP1 and SP2 does not properly validate input sent from user mode to the kernel, which allows local users to gain privileges via a crafted application, as demonstrated using crafted pointers and lengths that bypass intended ProbeForRead and ProbeForWrite restrictions, aka "AFD Kernel Overwrite Vulnerability."
16798| [CVE-2008-3460] WPGIMP32.FLT in Microsoft Office 2000 SP3, XP SP3, and 2003 SP2
16799| [CVE-2008-3068] Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times and IP addresses of recipients, and port-scan results, via a crafted certificate with an Authority Information Access (AIA) extension.
16800| [CVE-2008-3021] Microsoft Office 2000 SP3, XP SP3, and 2003 SP2
16801| [CVE-2008-3020] Microsoft Office 2000 SP3 and XP SP3
16802| [CVE-2008-3019] Microsoft Office 2000 SP3, XP SP3, and 2003 SP2
16803| [CVE-2008-3018] Microsoft Office 2000 SP3, XP SP3, and 2003 SP2
16804| [CVE-2008-3015] Integer overflow in gdiplus.dll in GDI+ in Microsoft Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a BMP image file with a malformed BitMapInfoHeader that triggers a buffer overflow, aka "GDI+ BMP Integer Overflow Vulnerability."
16805| [CVE-2008-3014] Buffer overflow in gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a malformed WMF image file that triggers improper memory allocation, aka "GDI+ WMF Buffer Overrun Vulnerability."
16806| [CVE-2008-3013] gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a malformed GIF image file containing many extension markers for graphic control extensions and subsequent unknown labels, aka "GDI+ GIF Parsing Vulnerability."
16807| [CVE-2008-3012] gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 does not properly perform memory allocation, which allows remote attackers to execute arbitrary code via a malformed EMF image file, aka "GDI+ EMF Memory Corruption Vulnerability."
16808| [CVE-2008-3009] Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1, 9, and 2008 do not properly use the Service Principal Name (SPN) identifier when validating replies to authentication requests, which allows remote servers to execute arbitrary code via vectors that employ NTLM credential reflection, aka "SPN Vulnerability."
16809| [CVE-2008-3007] Argument injection vulnerability in a URI handler in Microsoft Office XP SP3, 2003 SP2 and SP3, 2007 Office System Gold and SP1, and Office OneNote 2007 Gold and SP1 allow remote attackers to execute arbitrary code via a crafted onenote:// URL, aka "Uniform Resource Locator Validation Error Vulnerability."
16810| [CVE-2008-3006] Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1
16811| [CVE-2008-3005] Array index vulnerability in Microsoft Office Excel 2000 SP3 and 2002 SP3, and Office 2004 and 2008 for Mac allows remote attackers to execute arbitrary code via an Excel file with a crafted array index for a FORMAT record, aka the "Excel Index Array Vulnerability."
16812| [CVE-2008-3004] Microsoft Office Excel 2000 SP3, 2002 SP3, and 2003 SP2 and SP3
16813| [CVE-2008-3003] Microsoft Office Excel 2007 Gold and SP1 does not properly delete the PWD (password) string from connections.xml when a .xlsx file is configured not to save the remote data session password, which allows local users to obtain sensitive information and obtain access to a remote data source, aka the "Excel Credential Caching Vulnerability."
16814| [CVE-2008-2752] Microsoft Word 2000 9.0.2812 and 2003 11.8106.8172 does not properly handle unordered lists, which allows user-assisted remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .doc file. NOTE: some of these details are obtained from third party information.
16815| [CVE-2008-2540] Apple Safari on Mac OS X, and before 3.1.2 on Windows, does not prompt the user before downloading an object that has an unrecognized content type, which allows remote attackers to place malware into the (1) Desktop directory on Windows or (2) Downloads directory on Mac OS X, and subsequently allows remote attackers to execute arbitrary code on Windows by leveraging an untrusted search path vulnerability in (a) Internet Explorer 7 on Windows XP or (b) the SearchPath function in Windows XP, Vista, and Server 2003 and 2008, aka a "Carpet Bomb" and a "Blended Threat Elevation of Privilege Vulnerability," a different issue than CVE-2008-1032. NOTE: Apple considers this a vulnerability only because the Microsoft products can load application libraries from the desktop and, as of 20080619, has not covered the issue in an advisory for Mac OS X.
16816| [CVE-2008-2463] The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snapshot Viewer and Microsoft Office Access 2000 through 2003, allows remote attackers to download arbitrary files to a client machine via a crafted HTML document or e-mail message, probably involving use of the SnapshotPath and CompressedPath properties and the PrintSnapshot method. NOTE: this can be leveraged for code execution by writing to a Startup folder.
16817| [CVE-2008-2252] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate parameters sent from user mode to the kernel, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Corruption Vulnerability."
16818| [CVE-2008-2251] Double free vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows local users to gain privileges via a crafted application that makes system calls within multiple threads, aka "Windows Kernel Unhandled Exception Vulnerability." NOTE: according to Microsoft, this is not a duplicate of CVE-2008-4510.
16819| [CVE-2008-2250] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate window properties sent from a parent window to a child window during creation of a new window, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Window Creation Vulnerability."
16820| [CVE-2008-2249] Integer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via a malformed header in a crafted WMF file, which triggers a buffer overflow, aka "GDI Integer Overflow Vulnerability."
16821| [CVE-2008-2246] Microsoft Windows Vista through SP1 and Server 2008 do not properly import the default IPsec policy from a Windows Server 2003 domain to a Windows Server 2008 domain, which prevents IPsec rules from being enforced and allows remote attackers to bypass intended access restrictions.
16822| [CVE-2008-2245] Heap-based buffer overflow in the InternalOpenColorProfile function in mscms.dll in Microsoft Windows Image Color Management System (MSCMS) in the Image Color Management (ICM) component on Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted image file.
16823| [CVE-2008-2244] Microsoft Office Word 2002 SP3 allows remote attackers to execute arbitrary code via a .doc file that contains malformed data, as exploited in the wild in July 2008, and as demonstrated by attachement.doc.
16824| [CVE-2008-1898] A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and 2007, allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via an invalid WksPictureInterface property value, which triggers an improper function call.
16825| [CVE-2008-1888] Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 2.0 allows remote attackers to inject arbitrary web script or HTML via the Picture Source (aka picture object source) field in the Rich Text Editor.
16826| [CVE-2008-1547] Open redirect vulnerability in exchweb/bin/redir.asp in Microsoft Outlook Web Access (OWA) for Exchange Server 2003 SP2 (aka build 6.5.7638) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the URL parameter.
16827| [CVE-2008-1457] The Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate per-user subscriptions, which allows remote authenticated users to execute arbitrary code via a crafted event subscription request.
16828| [CVE-2008-1456] Array index vulnerability in the Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote authenticated users to execute arbitrary code via a crafted event subscription request that is used to access an array of function pointers.
16829| [CVE-2008-1455] A "memory calculation error" in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, 2003 SP2, and 2007 through SP1
16830| [CVE-2008-1454] Unspecified vulnerability in Microsoft DNS in Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008 allows remote attackers to conduct cache poisoning attacks via unknown vectors related to accepting "records from a response that is outside the remote server's authority," aka "DNS Cache Poisoning Vulnerability," a different vulnerability than CVE-2008-1447.
16831| [CVE-2008-1451] The WINS service on Microsoft Windows 2000 SP4, and Server 2003 SP1 and SP2, does not properly validate data structures in WINS network packets, which allows local users to gain privileges via a crafted packet, aka "Memory Overwrite Vulnerability."
16832| [CVE-2008-1446] Integer overflow in the Internet Printing Protocol (IPP) ISAPI extension in Microsoft Internet Information Services (IIS) 5.0 through 7.0 on Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to execute arbitrary code via an HTTP POST request that triggers an outbound IPP connection from a web server to a machine operated by the attacker, aka "Integer Overflow in IPP Service Vulnerability."
16833| [CVE-2008-1445] Active Directory on Microsoft Windows 2000 Server SP4, XP Professional SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to cause a denial of service (system hang or reboot) via a crafted LDAP request.
16834| [CVE-2008-1444] Stack-based buffer overflow in Microsoft DirectX 7.0 and 8.1 on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a Synchronized Accessible Media Interchange (SAMI) file with crafted parameters for a Class Name variable, aka the "SAMI Format Parsing Vulnerability."
16835| [CVE-2008-1441] Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to cause a denial of service (system hang) via a series of Pragmatic General Multicast (PGM) packets with invalid fragment options, aka the "PGM Malformed Fragment Vulnerability."
16836| [CVE-2008-1440] Microsoft Windows XP SP2 and SP3, and Server 2003 SP1 and SP2, does not properly validate the option length field in Pragmatic General Multicast (PGM) packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted PGM packet, aka the "PGM Invalid Length Vulnerability."
16837| [CVE-2008-1436] Microsoft Windows XP Professional SP2, Vista, and Server 2003 and 2008 does not properly assign activities to the (1) NetworkService and (2) LocalService accounts, which might allow context-dependent attackers to gain privileges by using one service process to capture a resource from a second service process that has a LocalSystem privilege-escalation ability, related to improper management of the SeImpersonatePrivilege user right, as originally reported for Internet Information Services (IIS), aka Token Kidnapping.
16838| [CVE-2008-1435] Windows Explorer in Microsoft Windows Vista up to SP1, and Server 2008, allows user-assisted remote attackers to execute arbitrary code via crafted saved-search (.search-ms) files that are not properly handled when saving, aka "Windows Saved Search Vulnerability."
16839| [CVE-2008-1434] Use-after-free vulnerability in Microsoft Word in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 Office System SP1 and earlier allows remote attackers to execute arbitrary code via an HTML document with a large number of Cascading Style Sheets (CSS) selectors, related to a "memory handling error" that triggers memory corruption.
16840| [CVE-2008-1092] Buffer overflow in msjet40.dll before 4.0.9505.0 in Microsoft Jet Database Engine allows remote attackers to execute arbitrary code via a crafted Word file, as exploited in the wild in March 2008. NOTE: as of 20080513, Microsoft has stated that this is the same issue as CVE-2007-6026.
16841| [CVE-2008-1091] Unspecified vulnerability in Microsoft Word in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 Office System SP1 and earlier allows remote attackers to execute arbitrary code via a Rich Text Format (.rtf) file with a malformed string that triggers a "memory calculation error" and a heap-based buffer overflow, aka "Object Parsing Vulnerability."
16842| [CVE-2008-1090] Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows user-assisted remote attackers to execute arbitrary code via a crafted .DXF file, aka "Visio Memory Validation Vulnerability."
16843| [CVE-2008-1089] Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows user-assisted remote attackers to execute arbitrary code via a Visio file containing crafted object header data, aka "Visio Object Header Vulnerability."
16844| [CVE-2008-1088] Microsoft Project 2000 Service Release 1, 2002 SP1, and 2003 SP2 allows user-assisted remote attackers to execute arbitrary code via a crafted Project file, related to improper validation of "memory resource allocations."
16845| [CVE-2008-1087] Stack-based buffer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to execute arbitrary code via an EMF image file with crafted filename parameters, aka "GDI Stack Overflow Vulnerability."
16846| [CVE-2008-1086] The HxTocCtrl ActiveX control (hxvz.dll), as used in Microsoft Internet Explorer 5.01 SP4 and 6 SP1, in Windows XP SP2, Server 2003 SP1 and SP2, Vista SP1, and Server 2008, allows remote attackers to execute arbitrary code via malformed arguments, which triggers memory corruption.
16847| [CVE-2008-1084] Unspecified vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, through Vista SP1, and Server 2008 allows local users to execute arbitrary code via unknown vectors related to improper input validation. NOTE: it was later reported that one affected function is NtUserFnOUTSTRING in win32k.sys.
16848| [CVE-2008-1083] Heap-based buffer overflow in the CreateDIBPatternBrushPt function in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to execute arbitrary code via an EMF or WMF image file with a malformed header that triggers an integer overflow, aka "GDI Heap Overflow Vulnerability."
16849| [CVE-2008-0121] A "memory calculation error" in Microsoft PowerPoint Viewer 2003 allows remote attackers to execute arbitrary code via a PowerPoint file with an invalid picture index that triggers memory corruption, aka "Memory Calculation Vulnerability."
16850| [CVE-2008-0120] Integer overflow in Microsoft PowerPoint Viewer 2003 allows remote attackers to execute arbitrary code via a PowerPoint file with a malformed picture index that triggers memory corruption, related to handling of CString objects, aka "Memory Allocation Vulnerability."
16851| [CVE-2008-0119] Unspecified vulnerability in Microsoft Publisher in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 SP1 and earlier allows remote attackers to execute arbitrary code via a Publisher file with crafted object header data that triggers memory corruption, aka "Publisher Object Handler Validation Vulnerability."
16852| [CVE-2008-0118] Unspecified vulnerability in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, Excel Viewer 2003 up to SP3, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption from an "allocation error," aka "Microsoft Office Memory Corruption Vulnerability."
16853| [CVE-2008-0117] Unspecified vulnerability in Microsoft Excel 2000 SP3 and 2002 SP2, and Office 2004 and 2008 for Mac, allows user-assisted remote attackers to execute arbitrary code via crafted conditional formatting values, aka "Excel Conditional Formatting Vulnerability."
16854| [CVE-2008-0116] Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, Compatibility Pack, and Office 2004 and 2008 for Mac allows user-assisted remote attackers to execute arbitrary code via malformed tags in rich text, aka "Excel Rich Text Validation Vulnerability."
16855| [CVE-2008-0115] Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2007, Viewer 2003, Compatibility Pack, and Office for Mac 2004 allows user-assisted remote attackers to execute arbitrary code via malformed formulas, aka "Excel Formula Parsing Vulnerability."
16856| [CVE-2008-0114] Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office for Mac 2004 allows user-assisted remote attackers to execute arbitrary code via crafted Style records that trigger memory corruption.
16857| [CVE-2008-0113] Unspecified vulnerability in Microsoft Office Excel Viewer 2003 up to SP3 allows user-assisted remote attackers to execute arbitrary code via an Excel document with malformed cell comments that trigger memory corruption from an "allocation error," aka "Microsoft Office Cell Parsing Memory Corruption Vulnerability."
16858| [CVE-2008-0112] Unspecified vulnerability in Microsoft Excel 2000 SP3, and Office for Mac 2004 and 2008 allows user-assisted remote attackers to execute arbitrary code via a crafted .SLK file that is not properly handled when importing the file, aka "Excel File Import Vulnerability."
16859| [CVE-2008-0111] Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2007, Viewer 2003, Compatibility Pack, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted data validation records, aka "Excel Data Validation Record Vulnerability."
16860| [CVE-2008-0110] Unspecified vulnerability in Microsoft Outlook in Office 2000 SP3, XP SP3, 2003 SP2 and Sp3, and Office System allows user-assisted remote attackers to execute arbitrary code via a crafted mailto URI.
16861| [CVE-2008-0109] Word in Microsoft Office 2000 SP3, XP SP3, Office 2003 SP2, and Office Word Viewer 2003 allows remote attackers to execute arbitrary code via crafted fields within the File Information Block (FIB) of a Word file, which triggers length calculation errors and memory corruption.
16862| [CVE-2008-0108] Stack-based buffer overflow in wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted field lengths, aka "Microsoft Works File Converter Field Length Vulnerability."
16863| [CVE-2008-0106] Buffer overflow in Microsoft SQL Server 2005 SP1 and SP2, and 2005 Express Edition SP1 and SP2, allows remote authenticated users to execute arbitrary code via a crafted insert statement.
16864| [CVE-2008-0105] Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section header index table information, aka "Microsoft Works File Converter Index Table Vulnerability."
16865| [CVE-2008-0104] Unspecified vulnerability in Microsoft Office Publisher 2000, 2002, and 2003 SP2 allows remote attackers to execute arbitrary code via a crafted .pub file, aka "Publisher Memory Corruption Vulnerability."
16866| [CVE-2008-0103] Unspecified vulnerability in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Office document that contains a malformed object, related to a "memory handling error," aka "Microsoft Office Execution Jump Vulnerability."
16867| [CVE-2008-0102] Unspecified vulnerability in Microsoft Office Publisher 2000, 2002, and 2003 SP2 allows remote attackers to execute arbitrary code via a crafted .pub file, related to invalid "memory values," aka "Publisher Invalid Memory Reference Vulnerability."
16868| [CVE-2008-0088] Unspecified vulnerability in Active Directory on Microsoft Windows 2000 and Windows Server 2003, and Active Directory Application Mode (ADAM) on XP and Server 2003, allows remote attackers to cause a denial of service (hang and restart) via a crafted LDAP request.
16869| [CVE-2008-0087] The DNS client in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, and Vista uses predictable DNS transaction IDs, which allows remote attackers to spoof DNS responses.
16870| [CVE-2008-0086] Buffer overflow in the convert function in Microsoft SQL Server 2000 SP4, 2000 Desktop Engine (MSDE 2000) SP4, and 2000 Desktop Engine (WMSDE) allows remote authenticated users to execute arbitrary code via a crafted SQL expression.
16871| [CVE-2008-0083] The (1) VBScript (VBScript.dll) and (2) JScript (JScript.dll) scripting engines 5.1 and 5.6, as used in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2, do not properly decode script, which allows remote attackers to execute arbitrary code via unknown vectors.
16872| [CVE-2008-0081] Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted macros, aka "Macro Validation Vulnerability," a different vulnerability than CVE-2007-3490.
16873| [CVE-2008-0080] Heap-based buffer overflow in the WebDAV Mini-Redirector in Microsoft Windows XP SP2, Server 2003 SP1 and SP2, and Vista allows remote attackers to execute arbitrary code via a crafted WebDAV response.
16874| [CVE-2008-0020] Unspecified vulnerability in the Load method in the IPersistStreamInit interface in the Active Template Library (ATL), as used in the Microsoft Video ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via unknown vectors that trigger memory corruption, aka "ATL Header Memcopy Vulnerability," a different vulnerability than CVE-2008-0015.
16875| [CVE-2008-0015] Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted web page, as exploited in the wild in July 2009, aka "Microsoft Video ActiveX Control Vulnerability."
16876| [CVE-2008-0011] Microsoft DirectX 8.1 through 9.0c, and DirectX on Microsoft XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008, does not properly perform MJPEG error checking, which allows remote attackers to execute arbitrary code via a crafted MJPEG stream in a (1) AVI or (2) ASF file, aka the "MJPEG Decoder Vulnerability."
16877| [CVE-2007-6753] Untrusted search path vulnerability in Shell32.dll in Microsoft Windows 2000, Windows XP, Windows Vista, Windows Server 2008, and Windows 7, when using an environment configured with a string such as %APPDATA% or %PROGRAMFILES% in a certain way, allows local users to gain privileges via a Trojan horse DLL under the current working directory, as demonstrated by iTunes and Safari.
16878| [CVE-2007-6357] Stack-based buffer overflow in Microsoft Office Access allows remote, user-assisted attackers to execute arbitrary code via a crafted Microsoft Access Database (.mdb) file. NOTE: due to the lack of details as of 20071210, it is not clear whether this issue is the same as CVE-2007-6026 or CVE-2005-0944.
16879| [CVE-2007-6329] Microsoft Office 2007 12.0.6015.5000 and MSO 12.0.6017.5000 do not sign the metadata of Office Open XML (OOXML) documents, which makes it easier for remote attackers to modify Dublin Core metadata fields, as demonstrated by the (1) LastModifiedBy and (2) creator fields in docProps/core.xml in the OOXML ZIP container.
16880| [CVE-2007-6043] The CryptGenRandom function in Microsoft Windows 2000 generates predictable values, which makes it easier for context-dependent attackers to reduce the effectiveness of cryptographic mechanisms, as demonstrated by attacks on (1) forward security and (2) backward security, related to use of eight instances of the RC4 cipher, and possibly a related issue to CVE-2007-3898.
16881| [CVE-2007-6026] Stack-based buffer overflow in Microsoft msjet40.dll 4.0.8618.0 (aka Microsoft Jet Engine), as used by Access 2003 in Microsoft Office 2003 SP3, allows user-assisted attackers to execute arbitrary code via a crafted MDB file database file containing a column structure with a modified column count. NOTE: this might be the same issue as CVE-2005-0944.
16882| [CVE-2007-5587] Buffer overflow in Macrovision SafeDisc secdrv.sys before 4.3.86.0, as shipped in Microsoft Windows XP SP2, XP Professional x64 and x64 SP2, Server 2003 SP1 and SP2, and Server 2003 x64 and x64 SP2 allows local users to overwrite arbitrary memory locations and gain privileges via a crafted argument to a METHOD_NEITHER IOCTL, as originally discovered in the wild.
16883| [CVE-2007-5352] Unspecified vulnerability in Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows local users to gain privileges via a crafted local procedure call (LPC) request.
16884| [CVE-2007-5348] Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via an image file with crafted gradient sizes in gradient fill input, which triggers a heap-based buffer overflow related to GdiPlus.dll and VGX.DLL, aka "GDI+ VML Buffer Overrun Vulnerability."
16885| [CVE-2007-4991] The SOCKS4 Proxy in Microsoft Internet Security and Acceleration (ISA) Server 2004 SP1 and SP2 allows remote attackers to obtain potentially sensitive information (the destination IP address of another user's session) via an empty packet.
16886| [CVE-2007-4916] Heap-based buffer overflow in the FileFind::FindFile method in (1) MFC42.dll, (2) MFC42u.dll, (3) MFC71.dll, and (4) MFC71u.dll in Microsoft Foundation Class (MFC) Library 8.0, as used by the ListFiles method in hpqutil.dll 2.0.0.138 in Hewlett-Packard (HP) All-in-One and Photo & Imaging Gallery 1.1 and probably other products, allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long first argument.
16887| [CVE-2007-4814] Buffer overflow in the SQLServer ActiveX control in the Distributed Management Objects OLE DLL (sqldmo.dll) 2000.085.2004.00 in Microsoft SQL Server Enterprise Manager 8.05.2004 allows remote attackers to execute arbitrary code via a long second argument to the Start method.
16888| [CVE-2007-3930] Interpretation conflict between Microsoft Internet Explorer and DocuWiki before 2007-06-26b allows remote attackers to inject arbitrary JavaScript and conduct cross-site scripting (XSS) attacks when spellchecking UTF-8 encoded messages via the spell_utf8test function in lib/exe/spellcheck.php, which triggers HTML document identification and script execution by Internet Explorer even though the Content-Type header is text/plain.
16889| [CVE-2007-3924] Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Netscape installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a -chrome argument to the navigatorurl URI, which are inserted into the command line that is created when invoking netscape.exe, a related issue to CVE-2007-3670. NOTE: there has been debate about whether the issue is in Internet Explorer or Netscape. As of 20070713, it is CVE's opinion that IE appears to not properly delimit the URL argument when invoking Netscape
16890| [CVE-2007-3899] Unspecified vulnerability in Microsoft Word 2000 SP3, Word 2002 SP3, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a malformed string in a Word file, aka "Word Memory Corruption Vulnerability."
16891| [CVE-2007-3898] The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS servers, which allows remote attackers to spoof DNS replies, poison the DNS cache, and facilitate further attack vectors.
16892| [CVE-2007-3896] The URL handling in Shell32.dll in the Windows shell in Microsoft Windows XP and Server 2003, with Internet Explorer 7 installed, allows remote attackers to execute arbitrary programs via invalid "%" sequences in a mailto: or other URI handler, as demonstrated using mIRC, Outlook, Firefox, Adobe Reader, Skype, and other applications. NOTE: this issue might be related to other issues involving URL handlers in Windows systems, such as CVE-2007-3845. There also might be separate but closely related issues in the applications that are invoked by the handlers.
16893| [CVE-2007-3890] Microsoft Excel in Office 2000 SP3, Office XP SP3, Office 2003 SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via a Workspace with a certain index value that triggers memory corruption.
16894| [CVE-2007-3670] Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Firefox installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a (1) FirefoxURL or (2) FirefoxHTML URI, which are inserted into the command line that is created when invoking firefox.exe. NOTE: it has been debated as to whether the issue is in Internet Explorer or Firefox. As of 20070711, it is CVE's opinion that IE appears to be failing to properly delimit the URL argument when invoking Firefox, and this issue could arise with other protocol handlers in IE as well. However, Mozilla has stated that it will address the issue with a "defense in depth" fix that will "prevent IE from sending Firefox malicious data."
16895| [CVE-2007-3490] Unspecified vulnerability in Microsoft Excel 2003 SP2 allows remote attackers to have an unknown impact via unspecified vectors, possibly related to the sheet name, as demonstrated by 2670.xls.
16896| [CVE-2007-3300] Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070619 allow remote attackers to bypass scanning via a crafted header in a (1) LHA or (2) RAR archive.
16897| [CVE-2007-3040] Stack-based buffer overflow in agentdpv.dll 2.0.0.3425 in Microsoft Agent on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a crafted URL to the Agent (Agent.Control) ActiveX control, which triggers an overflow within the Agent Service (agentsrv.exe) process, a different issue than CVE-2007-1205.
16898| [CVE-2007-3039] Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Windows 2000 Professional SP4, and Windows XP SP2 allows attackers to execute arbitrary code via a long string in an opnum 0x06 RPC call to port 2103. NOTE: this is remotely exploitable on Windows 2000 Server.
16899| [CVE-2007-3036] Unspecified vulnerability in the (1) Windows Services for UNIX 3.0 and 3.5, and (2) Subsystem for UNIX-based Applications in Microsoft Windows 2000, XP, Server 2003, and Vista allows local users to gain privileges via unspecified vectors related to "certain setuid binary files."
16900| [CVE-2007-3034] Integer overflow in the AttemptWrite function in Graphics Rendering Engine (GDI) on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted metafile (image) with a large record length value, which triggers a heap-based buffer overflow.
16901| [CVE-2007-3030] Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, and 2003 Viewer allows user-assisted remote attackers to execute arbitrary code via a malformed Excel file involving the "denoting [of] the start of a Workspace designation", which results in memory corruption, aka the "Workbook Memory Corruption Vulnerability".
16902| [CVE-2007-3029] Unspecified vulnerability in Microsoft Excel 2002 SP3 and 2003 SP2 allows user-assisted remote attackers to execute arbitrary code via a malformed Excel file containing multiple active worksheets, which results in memory corruption.
16903| [CVE-2007-3028] The LDAP service in Windows Active Directory in Microsoft Windows 2000 Server SP4 does not properly check "the number of convertible attributes", which allows remote attackers to cause a denial of service (service unavailability) via a crafted LDAP request, related to "client sent LDAP request logic," aka "Windows Active Directory Denial of Service Vulnerability". NOTE: this is probably a different issue than CVE-2007-0040.
16904| [CVE-2007-2999] Microsoft Windows Server 2003, when time restrictions are in effect for user accounts, generates different error messages for failed login attempts with a valid user name than for those with an invalid user name, which allows context-dependent attackers to determine valid Active Directory account names.
16905| [CVE-2007-2967] Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070522 allow remote attackers to cause a denial of service (file scanning infinite loop) via certain crafted (1) ARJ archives or (2) FSG packed files.
16906| [CVE-2007-2966] Buffer overflow in the LHA decompresion component in F-Secure anti-virus products for Microsoft Windows and Linux before 20070529 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted LHA archive, related to an integer wrap, a similar issue to CVE-2006-4335.
16907| [CVE-2007-2903] Buffer overflow in the HelpPopup method in the Microsoft Office 2000 Controllo UA di Microsoft Office ActiveX control (OUACTRL.OCX) 1.0.1.9 allows remote attackers to cause a denial of service (probably winhlp32.exe crash) via a long first argument. NOTE: it is not clear whether this issue crosses privilege boundaries.
16908| [CVE-2007-2593] The Terminal Server in Microsoft Windows 2003 Server, when using TLS, allows remote attackers to bypass SSL and self-signed certificate requirements, downgrade the server security, and possibly conduct man-in-the-middle attacks via unspecified vectors, as demonstrated using the Remote Desktop Protocol (RDP) 6.0 client. NOTE: a third party claims that the vendor may have fixed this in approximately 2006.
16909| [CVE-2007-2581] Multiple cross-site scripting (XSS) vulnerabilities in Microsoft Windows SharePoint Services 3.0 for Windows Server 2003 and Office SharePoint Server 2007 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (query string) in "every main page," as demonstrated by default.aspx.
16910| [CVE-2007-2374] Unspecified vulnerability in Microsoft Windows 2000, XP, and Server 2003 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors. NOTE: this information is based upon a vague pre-advisory with no actionable information. However, the advisory is from a reliable source.
16911| [CVE-2007-2228] rpcrt4.dll (aka the RPC runtime library) in Microsoft Windows XP SP2, XP Professional x64 Edition, Server 2003 SP1 and SP2, Server 2003 x64 Edition and x64 Edition SP2, and Vista and Vista x64 Edition allows remote attackers to cause a denial of service (RPCSS service stop and system restart) via an RPC request that uses NTLMSSP PACKET authentication with a zero-valued verification trailer signature, which triggers an invalid dereference. NOTE: this also affects Windows 2000 SP4, although the impact is an information leak.
16912| [CVE-2007-2224] Object linking and embedding (OLE) Automation, as used in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Office 2004 for Mac, and Visual Basic 6.0 allows remote attackers to execute arbitrary code via the substringData method on a TextNode object, which causes an integer overflow that leads to a buffer overflow.
16913| [CVE-2007-2221] Unspecified vulnerability in the mdsauth.dll COM object in Microsoft Windows Media Server in the Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4
16914| [CVE-2007-2219] Unspecified vulnerability in the Win32 API on Microsoft Windows 2000, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via certain parameters to an unspecified function.
16915| [CVE-2007-2218] Unspecified vulnerability in the Windows Schannel Security Package for Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2, allows remote servers to execute arbitrary code or cause a denial of service via crafted digital signatures that are processed during an SSL handshake.
16916| [CVE-2007-2217] Kodak Image Viewer in Microsoft Windows 2000 SP4, and in some cases XP SP2 and Server 2003 SP1 and SP2, allows remote attackers to execute arbitrary code via crafted image files that trigger memory corruption, as demonstrated by a certain .tif (TIFF) file.
16917| [CVE-2007-1911] Multiple unspecified vulnerabilities in Microsoft Word 2007 allow remote attackers to cause a denial of service (CPU consumption) via crafted documents, as demonstrated by (1) file798-1.doc and (2) file613-1.doc, possibly related to a buffer overflow.
16918| [CVE-2007-1910] Buffer overflow in wwlib.dll in Microsoft Word 2007 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted document, as demonstrated by file789-1.doc.
16919| [CVE-2007-1765] Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malformed ANI file, which results in memory corruption when processing cursors, animated cursors, and icons, a similar issue to CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this issue might be a duplicate of CVE-2007-0038
16920| [CVE-2007-1756] Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, and Office Excel 2007 does not properly validate version information, which allows user-assisted remote attackers to execute arbitrary code via a crafted Excel file, aka "Calculation Error Vulnerability".
16921| [CVE-2007-1754] PUBCONV.DLL in Microsoft Office Publisher 2007 does not properly clear memory when transferring data from disk to memory, which allows user-assisted remote attackers to execute arbitrary code via a malformed .pub page via a certain negative value, which bypasses a sanitization procedure that initializes critical pointers to NULL, aka the "Publisher Invalid Memory Reference Vulnerability".
16922| [CVE-2007-1748] Stack-based buffer overflow in the RPC interface in the Domain Name System (DNS) Server Service in Microsoft Windows 2000 Server SP 4, Server 2003 SP 1, and Server 2003 SP 2 allows remote attackers to execute arbitrary code via a long zone name containing character constants represented by escape sequences.
16923| [CVE-2007-1747] Unspecified vulnerability in MSO.dll in Microsoft Office 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and 2007 allows user-assisted remote attackers to execute arbitrary code via a malformed drawing object, which triggers memory corruption.
16924| [CVE-2007-1645] Buffer overflow in FutureSoft TFTP Server 2000 on Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrary code via a long request on UDP port 69. NOTE: this issue might overlap CVE-2006-4781 or CVE-2005-1812.
16925| [CVE-2007-1537] \Device\NdisTapi (NDISTAPI.sys) in Microsoft Windows XP SP2 and 2003 SP1 uses weak permissions, which allows local users to write to the device and cause a denial of service, as demonstrated by using an IRQL to acquire a spinlock on paged memory via the NdisTapiDispatch function.
16926| [CVE-2007-1512] Stack-based buffer overflow in the AfxOleSetEditMenu function in the MFC component in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 Gold and SP1, and Visual Studio .NET 2002 Gold and SP1, and 2003 Gold and SP1 allows user-assisted remote attackers to have an unknown impact (probably crash) via an RTF file with a malformed OLE object, which results in writing two 0x00 characters past the end of szBuffer, aka the "MFC42u.dll Off-by-Two Overflow." NOTE: this issue is due to an incomplete patch (MS07-012) for CVE-2007-0025.
16927| [CVE-2007-1347] Microsoft Windows Explorer on Windows 2000 SP4 FR and XP SP2 FR, and possibly other versions and platforms, allows remote attackers to cause a denial of service (memory corruption and crash) via an Office file with crafted document summary information, which causes an error in Ole32.dll.
16928| [CVE-2007-1239] Microsoft Excel 2003 does not properly parse .XLS files, which allows remote attackers to cause a denial of service (application crash) via a file with a (1) corrupted XML format or a (2) corrupted XLS format, which triggers a NULL pointer dereference.
16929| [CVE-2007-1238] Microsoft Office 2003 allows user-assisted remote attackers to cause a denial of service (application crash) by attempting to insert a corrupted WMF file.
16930| [CVE-2007-1215] Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4
16931| [CVE-2007-1214] Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, and 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a crafted AutoFilter filter record in an Excel BIFF8 format XLS file, which triggers memory corruption.
16932| [CVE-2007-1213] The TrueType Fonts rasterizer in Microsoft Windows 2000 SP4 allows local users to gain privileges via crafted TrueType fonts, which result in an uninitialized function pointer.
16933| [CVE-2007-1212] Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4
16934| [CVE-2007-1211] Unspecified kernel GDI functions in Microsoft Windows 2000 SP4
16935| [CVE-2007-1205] Unspecified vulnerability in Microsoft Agent (msagent\agentsvr.exe) in Windows 2000 SP4, XP SP2, and Server 2003, 2003 SP1, and 2003 SP2 allows remote attackers to execute arbitrary code via crafted URLs, which result in memory corruption.
16936| [CVE-2007-1203] Unspecified vulnerability in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, 2004 for Mac, and 2007 allows user-assisted remote attackers to execute arbitrary code via a crafted set font value in an Excel file, which results in memory corruption.
16937| [CVE-2007-1202] Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006 does not properly parse certain rich text "property strings of certain control words," which allows user-assisted remote attackers to trigger heap corruption and execute arbitrary code, aka the "Word RTF Parsing Vulnerability."
16938| [CVE-2007-1201] Unspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user-assisted remote attackers to execute arbitrary code via vectors related to DataSource that trigger memory corruption, aka "Office Web Components DataSource Vulnerability."
16939| [CVE-2007-1117] Unspecified vulnerability in Publisher 2007 in Microsoft Office 2007 allows remote attackers to execute arbitrary code via unspecified vectors, related to a "file format vulnerability." NOTE: this information is based upon a vague pre-advisory with no actionable information. However, the advisory is from a reliable source.
16940| [CVE-2007-1090] Microsoft Windows Explorer on Windows XP and 2003 allows remote user-assisted attackers to cause a denial of service (crash) via a malformed WMF file, which triggers the crash when the user browses the folder.
16941| [CVE-2007-1083] Buffer overflow in the Configuration Checker (ConfigChk) ActiveX control in VSCnfChk.dll 2.0.0.2 for Verisign Managed PKI Service, Secure Messaging for Microsoft Exchange, and Go Secure! allows remote attackers to execute arbitrary code via long arguments to the VerCompare method.
16942| [CVE-2007-0948] Heap-based buffer overflow in Microsoft Virtual PC 2004 and PC for Mac 7.1 and 7, and Virtual Server 2005 and 2005 R2, allows local guest OS administrators to execute arbitrary code on the host OS via unspecified vectors related to "interaction and initialization of components."
16943| [CVE-2007-0947] Use-after-free vulnerability in Microsoft Internet Explorer 7 on Windows XP SP2, Windows Server 2003 SP1 or SP2, or Windows Vista allows remote attackers to execute arbitrary code via crafted HTML objects, resulting in accessing deallocated memory of CMarkup objects, aka the second of two "HTML Objects Memory Corruption Vulnerabilities" and a different issue than CVE-2007-0946.
16944| [CVE-2007-0946] Unspecified vulnerability in Microsoft Internet Explorer 7 on Windows XP SP2, Windows Server 2003 SP1 or SP2, or Windows Vista allows remote attackers to execute arbitrary code via crafted HTML objects, which results in memory corruption, aka the first of two "HTML Objects Memory Corruption Vulnerabilities" and a different issue than CVE-2007-0947.
16945| [CVE-2007-0945] Microsoft Internet Explorer 6 SP1 on Windows 2000 SP4
16946| [CVE-2007-0944] Unspecified vulnerability in the CTableCol::OnPropertyChange method in Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4
16947| [CVE-2007-0942] Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4
16948| [CVE-2007-0940] Unspecified vulnerability in the Cryptographic API Component Object Model Certificates ActiveX control (CAPICOM.dll) in Microsoft CAPICOM and BizTalk Server 2004 SP1 and SP2 allows remote attackers to execute arbitrary code via unspecified vectors, aka the "CAPICOM.Certificates Vulnerability."
16949| [CVE-2007-0939] Cross-site scripting (XSS) vulnerability in Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving HTML redirection queries, aka "Cross-site Scripting and Spoofing Vulnerability."
16950| [CVE-2007-0938] Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 does not properly handle certain characters in a crafted HTTP GET request, which allows remote attackers to execute arbitrary code, aka the "CMS Memory Corruption Vulnerability."
16951| [CVE-2007-0936] Multiple unspecified vulnerabilities in Microsoft Visio 2002 allow remote user-assisted attackers to execute arbitrary code via a Visio (.VSD, VSS, .VST) file with a crafted packed object that triggers memory corruption, aka "Visio Document Packaging Vulnerability."
16952| [CVE-2007-0934] Unspecified vulnerability in Microsoft Visio 2002 allows remote user-assisted attackers to execute arbitrary code via a Visio (.VSD, VSS, .VST) file with a crafted version number that triggers memory corruption.
16953| [CVE-2007-0913] Unspecified vulnerability in Microsoft Powerpoint allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as exploited by Trojan.PPDropper.G. NOTE: as of 20070213, it is not clear whether this is the same issue as CVE-2006-5296, CVE-2006-4694, CVE-2006-3876, CVE-2006-3877, or older issues.
16954| [CVE-2007-0870] Unspecified vulnerability in Microsoft Word 2000 allows remote attackers to cause a denial of service (crash) via unknown vectors, a different vulnerability than CVE-2006-5994, CVE-2006-6456, CVE-2006-6561, and CVE-2007-0515, a variant of Exploit-MS06-027.
16955| [CVE-2007-0843] The ReadDirectoryChangesW API function on Microsoft Windows 2000, XP, Server 2003, and Vista does not check permissions for child objects, which allows local users to bypass permissions by opening a directory with LIST (READ) access and using ReadDirectoryChangesW to monitor changes of files that do not have LIST permissions, which can be leveraged to determine filenames, access times, and other sensitive information.
16956| [CVE-2007-0811] Microsoft Internet Explorer 6.0 SP1 on Windows 2000, and 6.0 SP2 on Windows XP, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an HTML document containing a certain JavaScript for loop with an empty loop body, possibly involving getElementById.
16957| [CVE-2007-0671] Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.
16958| [CVE-2007-0612] Multiple ActiveX controls in Microsoft Windows 2000, XP, 2003, and Vista allows remote attackers to cause a denial of service (Internet Explorer crash) by accessing the bgColor, fgColor, linkColor, alinkColor, vlinkColor, or defaultCharset properties in the (1) giffile, (2) htmlfile, (3) jpegfile, (4) mhtmlfile, (5) ODCfile, (6) pjpegfile, (7) pngfile, (8) xbmfile, (9) xmlfile, (10) xslfile, or (11) wdfile objects in (a) mshtml.dll
16959| [CVE-2007-0515] Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of service on Word 2003, via unknown attack vectors that trigger memory corruption, as exploited by Trojan.Mdropper.W and later by Trojan.Mdropper.X, a different issue than CVE-2006-6456, CVE-2006-5994, and CVE-2006-6561.
16960| [CVE-2007-0351] Microsoft Windows XP and Windows Server 2003 do not properly handle user logoff, which might allow local users to gain the privileges of a previous system user, possibly related to user profile unload failure. NOTE: it is not clear whether this is an issue in Windows itself, or an interaction with another product. The issue might involve ZoneAlarm not being able to terminate processes when it cannot prompt the user.
16961| [CVE-2007-0221] Integer overflow in the IMAP (IMAP4) support in Microsoft Exchange Server 2000 SP3 allows remote attackers to cause a denial of service (service hang) via crafted literals in an IMAP command, aka the "IMAP Literal Processing Vulnerability."
16962| [CVE-2007-0220] Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2000 SP3, and 2003 SP1 and SP2 allows remote attackers to execute arbitrary scripts, spoof content, or obtain sensitive information via certain UTF-encoded, script-based e-mail attachments, involving an "incorrectly handled UTF character set label".
16963| [CVE-2007-0216] wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section length headers, aka "Microsoft Works File Converter Input Validation Vulnerability."
16964| [CVE-2007-0215] Stack-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, and 2003 Viewer allows user-assisted remote attackers to execute arbitrary code via a .XLS BIFF file with a malformed Named Graph record, which results in memory corruption.
16965| [CVE-2007-0214] The HTML Help ActiveX control (Hhctrl.ocx) in Microsoft Windows 2000 SP3, XP SP2 and Professional, 2003 SP1 allows remote attackers to execute arbitrary code via unspecified functions, related to uninitialized parameters.
16966| [CVE-2007-0213] Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 does not properly decode certain MIME encoded e-mails, which allows remote attackers to execute arbitrary code via a crafted base64-encoded MIME e-mail message.
16967| [CVE-2007-0211] The hardware detection functionality in the Windows Shell in Microsoft Windows XP SP2 and Professional, and Server 2003 SP1 allows local users to gain privileges via an unvalidated parameter to a function related to the "detection and registration of new hardware."
16968| [CVE-2007-0209] Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a Word file with a malformed drawing object, which leads to memory corruption.
16969| [CVE-2007-0208] Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac does not correctly check the properties of certain documents and warn the user of macro content, which allows user-assisted remote attackers to execute arbitrary code.
16970| [CVE-2007-0069] Unspecified vulnerability in the kernel in Microsoft Windows XP SP2, Server 2003, and Vista allows remote attackers to cause a denial of service (CPU consumption) and possibly execute arbitrary code via crafted (1) IGMPv3 and (2) MLDv2 packets that trigger memory corruption, aka "Windows Kernel TCP/IP/IGMPv3 and MLDv2 Vulnerability."
16971| [CVE-2007-0066] The kernel in Microsoft Windows 2000 SP4, XP SP2, and Server 2003, when ICMP Router Discovery Protocol (RDP) is enabled, allows remote attackers to cause a denial of service via fragmented router advertisement ICMP packets that trigger an out-of-bounds read, aka "Windows Kernel TCP/IP/ICMP Vulnerability."
16972| [CVE-2007-0065] Heap-based buffer overflow in Object Linking and Embedding (OLE) Automation in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, Office 2004 for Mac, and Visual basic 6.0 SP6 allows remote attackers to execute arbitrary code via a crafted script request.
16973| [CVE-2007-0064] Heap-based buffer overflow in Windows Media Format Runtime 7.1, 9, 9.5, 9.5 x64 Edition, 11, and Windows Media Services 9.1 for Microsoft Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via a crafted Advanced Systems Format (ASF) file.
16974| [CVE-2007-0043] The Just In Time (JIT) Compiler service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer," probably a buffer overflow, aka ".NET JIT Compiler Vulnerability".
16975| [CVE-2007-0042] Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to access configuration files and obtain sensitive information, and possibly bypass security mechanisms that try to constrain the final substring of a string, via %00 characters, related to use of %00 as a string terminator within POSIX functions but a data character within .NET strings, aka "Null Byte Termination Vulnerability."
16976| [CVE-2007-0041] The PE Loader service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer" and unvalidated message lengths, probably a buffer overflow.
16977| [CVE-2007-0040] The LDAP service in Windows Active Directory in Microsoft Windows 2000 Server SP4, Server 2003 SP1 and SP2, Server 2003 x64 Edition and SP2, and Server 2003 for Itanium-based Systems SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted LDAP request with an unspecified number of "convertible attributes."
16978| [CVE-2007-0039] The Exchange Collaboration Data Objects (EXCDO) functionality in Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 allows remote attackers to cause a denial of service (crash) via an Internet Calendar (iCal) file containing multiple X-MICROSOFT-CDO-MODPROPS (MODPROPS) properties in which the second MODPROPS is longer than the first, which triggers a NULL pointer dereference and an unhandled exception.
16979| [CVE-2007-0038] Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a large length value in the second (or later) anih block of a RIFF .ANI, cur, or .ico file, which results in memory corruption when processing cursors, animated cursors, and icons, a variant of CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this might be a duplicate of CVE-2007-1765
16980| [CVE-2007-0035] Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006 does not properly handle data in a certain array, which allows user-assisted remote attackers to execute arbitrary code, aka the "Word Array Overflow Vulnerability."
16981| [CVE-2007-0034] Buffer overflow in the Advanced Search (Finder.exe) feature of Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted Outlook Saved Searches (OSS) file that triggers memory corruption, aka "Microsoft Outlook Advanced Find Vulnerability."
16982| [CVE-2007-0033] Microsoft Outlook 2002 and 2003 allows user-assisted remote attackers to execute arbitrary code via a malformed VEVENT record in an .iCal meeting request or ICS file.
16983| [CVE-2007-0031] Heap-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via a BIFF8 spreadsheet with a PALETTE record that contains a large number of entries.
16984| [CVE-2007-0030] Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via an Excel file with an out-of-range Column field in certain BIFF8 record types, which references arbitrary memory.
16985| [CVE-2007-0029] Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via a malformed string, aka "Excel Malformed String Vulnerability."
16986| [CVE-2007-0028] Microsoft Excel 2000, 2002, 2003, Viewer 2003, Office 2004 for Mac, and Office v.X for Mac does not properly handle certain opcodes, which allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file, which results in an "Improper Memory Access Vulnerability." NOTE: an early disclosure of this issue used CVE-2006-3432, but only CVE-2007-0028 should be used.
16987| [CVE-2007-0027] Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via malformed IMDATA records that trigger memory corruption.
16988| [CVE-2007-0026] The OLE Dialog component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption.
16989| [CVE-2007-0025] The MFC component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 and Visual Studio .NET 2000, 2002 SP1, 2003, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption. NOTE: this might be due to a stack-based buffer overflow in the AfxOleSetEditMenu function in MFC42u.dll.
16990| [CVE-2007-0024] Integer overflow in the Vector Markup Language (VML) implementation (vgx.dll) in Microsoft Internet Explorer 5.01, 6, and 7 on Windows 2000 SP4, XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted web page that contains unspecified integer properties that cause insufficient memory allocation and trigger a buffer overflow, aka the "VML Buffer Overrun Vulnerability."
16991| [CVE-2006-7210] Microsoft Windows 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (cpu consumption) via a PNG image with crafted (1) Width and (2) Height values in the IHDR block.
16992| [CVE-2006-7192] Microsoft ASP .NET Framework 2.0.50727.42 does not properly handle comment (/* */) enclosures, which allows remote attackers to bypass request filtering and conduct cross-site scripting (XSS) attacks, or cause a denial of service, as demonstrated via an xss:expression STYLE attribute in a closing XSS HTML tag.
16993| [CVE-2006-7027] Microsoft Internet Security and Acceleration (ISA) Server 2004 logs unusual ASCII characters in the Host header, including the tab, which allows remote attackers to manipulate portions of the log file and possibly leverage this for other attacks.
16994| [CVE-2006-6723] The Workstation service in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to cause a denial of service (memory consumption) via a large maxlen value in an NetrWkstaUserEnum RPC request.
16995| [CVE-2006-6696] Double free vulnerability in Microsoft Windows 2000, XP, 2003, and Vista allows local users to gain privileges by calling the MessageBox function with a MB_SERVICE_NOTIFICATION message with crafted data, which sends a HardError message to Client/Server Runtime Server Subsystem (CSRSS) process, which is not properly handled when invoking the UserHardError and GetHardErrorText functions in WINSRV.DLL.
16996| [CVE-2006-6617] projectserver/logon/pdsrequest.asp in Microsoft Project Server 2003 allows remote authenticated users to obtain the MSProjectUser password for a SQL database via a GetInitializationData request, which includes the information in the UserName and Password tags of the response.
16997| [CVE-2006-6561] Unspecified vulnerability in Microsoft Word 2000, 2002, and Word Viewer 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted DOC file that triggers memory corruption, as demonstrated via the 12122006-djtest.doc file, a different issue than CVE-2006-5994 and CVE-2006-6456.
16998| [CVE-2006-6456] Unspecified vulnerability in Microsoft Word 2000, 2002, and 2003 and Word Viewer 2003 allows remote attackers to execute code via unspecified vectors related to malformed data structures that trigger memory corruption, a different vulnerability than CVE-2006-5994.
16999| [CVE-2006-6296] The RpcGetPrinterData function in the Print Spooler (spoolsv.exe) service in Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 and earlier, allows remote attackers to cause a denial of service (memory consumption) via an RPC request that specifies a large 'offered' value (output buffer size), a variant of CVE-2005-3644.
17000| [CVE-2006-6134] Heap-based buffer overflow in the WMCheckURLScheme function in WMVCORE.DLL in Microsoft Windows Media Player (WMP) 10.00.00.4036 on Windows XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via a long HREF attribute, using an unrecognized protocol, in a REF element in an ASX PlayList file.
17001| [CVE-2006-6133] Stack-based buffer overflow in Visual Studio Crystal Reports for Microsoft Visual Studio .NET 2002 and 2002 SP1, .NET 2003 and 2003 SP1, and 2005 and 2005 SP1 (formerly Business Objects Crystal Reports XI Professional) allows user-assisted remote attackers to execute arbitrary code via a crafted RPT file.
17002| [CVE-2006-5994] Unspecified vulnerability in Microsoft Word 2000 and 2002, Office Word and Word Viewer 2003, Word 2004 and 2004 v. X for Mac, and Works 2004, 2005, and 2006 allows remote attackers to execute arbitrary code via a Word document with a malformed string that triggers memory corruption, a different vulnerability than CVE-2006-6456.
17003| [CVE-2006-5758] The Graphics Rendering Engine in Microsoft Windows 2000 through 2000 SP4 and Windows XP through SP2 maps GDI Kernel structures on a global shared memory section that is mapped with read-only permissions, but can be remapped by other processes as read-write, which allows local users to cause a denial of service (memory corruption and crash) and gain privileges by modifying the kernel structures.
17004| [CVE-2006-5586] The Graphics Rendering Engine in Microsoft Windows 2000 SP4 and XP SP2 allows local users to gain privileges via "invalid application window sizes" in layered application windows, aka the "GDI Invalid Window Size Elevation of Privilege Vulnerability."
17005| [CVE-2006-5585] The Client-Server Run-time Subsystem in Microsoft Windows XP SP2 and Server 2003 allows local users to gain privileges via a crafted file manifest within an application, aka "File Manifest Corruption Vulnerability."
17006| [CVE-2006-5584] The Remote Installation Service (RIS) in Microsoft Windows 2000 SP4 uses a TFTP server that allows anonymous access, which allows remote attackers to upload and overwrite arbitrary files to gain privileges on systems that use RIS.
17007| [CVE-2006-5583] Buffer overflow in the SNMP Service in Microsoft Windows 2000 SP4, XP SP2, Server 2003, Server 2003 SP1, and possibly other versions allows remote attackers to execute arbitrary code via a crafted SNMP packet, aka "SNMP Memory Corruption Vulnerability."
17008| [CVE-2006-5574] Unspecified vulnerability in the Brazilian Portuguese Grammar Checker in Microsoft Office 2003 and the Multilingual Interface for Office 2003, Project 2003, and Visio 2003 allows user-assisted remote attackers to execute arbitrary code via crafted text that is not properly parsed.
17009| [CVE-2006-5296] PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record length, which allows user-assisted attackers to cause a denial of service (NULL dereference and application crash) via a crafted PowerPoint (.PPT) file, as demonstrated by Nanika.ppt, and a different vulnerability than CVE-2006-3435, CVE-2006-3876, CVE-2006-3877, and CVE-2006-4694. NOTE: the impact of this issue was originally claimed to be arbitrary code execution, but later analysis demonstrated that this was erroneous.
17010| [CVE-2006-4854] ** REJECT ** Unspecified vulnerability in Microsoft Office 2000 (Chinese Edition) and Microsoft PowerPoint 2000 (Chinese Edition) allows user-assisted attackers to execute arbitrary code via a crafted PPT document, as exploited by malware such as Trojan.PPDropper.E. NOTE: on 20060919, Microsoft notified CVE that this is a duplicate of CVE-2006-0009.
17011| [CVE-2006-4704] Cross-zone scripting vulnerability in the WMI Object Broker (WMIScriptUtils.WMIObjectBroker2) ActiveX control (WmiScriptUtils.dll) in Microsoft Visual Studio 2005 allows remote attackers to bypass Internet zone restrictions and execute arbitrary code by instantiating dangerous objects, aka "WMI Object Broker Vulnerability."
17012| [CVE-2006-4702] Buffer overflow in the Windows Media Format Runtime in Microsoft Windows Media Player (WMP) 6.4 and Windows XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted Advanced Systems Format (ASF) file.
17013| [CVE-2006-4696] Unspecified vulnerability in the Server service in Microsoft Windows 2000 SP4, Server 2003 SP1 and earlier, and XP SP2 and earlier allows remote attackers to execute arbitrary code via a crafted packet, aka "SMB Rename Vulnerability."
17014| [CVE-2006-4695] Unspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user-assisted remote attackers to execute arbitrary code via a crafted URL, aka "Office Web Components URL Parsing Vulnerability."
17015| [CVE-2006-4694] Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office XP and Office 2003 allows user-assisted attackers to execute arbitrary code via a crafted record in a PPT file, as exploited by malware such as Exploit:Win32/Controlppt.W, Exploit:Win32/Controlppt.X, and Exploit-PPT.d/Trojan.PPDropper.F. NOTE: it has been reported that the attack vector involves SlideShowWindows.View.GotoNamedShow.
17016| [CVE-2006-4693] Unspecified vulnerability in Microsoft Word 2004 for Mac and v.X for Mac allows remote user-assisted attackers to execute arbitrary code via a crafted string in a Word file, a different issue than CVE-2006-3647 and CVE-2006-3651.
17017| [CVE-2006-4692] Argument injection vulnerability in the Windows Object Packager (packager.exe) in Microsoft Windows XP SP1 and SP2 and Server 2003 SP1 and earlier allows remote user-assisted attackers to execute arbitrary commands via a crafted file with a "/" (slash) character in the filename of the Command Line property, followed by a valid file extension, which causes the command before the slash to be executed, aka "Object Packager Dialogue Spoofing Vulnerability."
17018| [CVE-2006-4691] Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to execute arbitrary code via NetrJoinDomain2 RPC messages with a long hostname.
17019| [CVE-2006-4689] Unspecified vulnerability in the driver for the Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to cause a denial of service (hang and reboot) via has unknown attack vectors, aka "NetWare Driver Denial of Service Vulnerability."
17020| [CVE-2006-4688] Buffer overflow in Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via crafted messages, aka "Client Service for NetWare Memory Corruption Vulnerability."
17021| [CVE-2006-4534] Unspecified vulnerability in Microsoft Word 2000, 2002, and Office 2003 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors involving a crafted file resulting in a malformed stack, as exploited by malware with names including Trojan.Mdropper.Q, Mofei, and Femo.
17022| [CVE-2006-4495] Microsoft Internet Explorer allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Windows 2000 ActiveX COM Objects including (1) ciodm.dll, (2) myinfo.dll, (3) msdxm.ocx, and (4) creator.dll.
17023| [CVE-2006-4274] ** REJECT ** Unknown vulnerability in Microsoft PowerPoint allows user-assisted attackers to execute arbitrary code via a crafted PPT document, as exploited by malware such as TROJ_MDROPPER.BH. NOTE: on 20060822, it was determined that TROJ_MDROPPER.BH was exploiting CVE-2006-0009, so this is not a new vulnerability.
17024| [CVE-2006-4219] The Terminal Services COM object (tsuserex.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by instantiating it as an ActiveX object in Internet Explorer 6.0 SP1 on Microsoft Windows 2003 EE SP1 CN.
17025| [CVE-2006-4183] Heap-based buffer overflow in Microsoft DirectX SDK (February 2006) and probably earlier, including 9.0c End User Runtimes, allows context-dependent attackers to execute arbitrary code via a crafted Targa file with a run-length-encoding (RLE) compression that produces more data than expected when decoding.
17026| [CVE-2006-4071] Sign extension vulnerability in the createBrushIndirect function in the GDI library (gdi32.dll) in Microsoft Windows XP, Server 2003, and possibly other versions, allows user-assisted attackers to cause a denial of service (application crash) via a crafted WMF file.
17027| [CVE-2006-3992] Unspecified vulnerability in the Centrino (1) w22n50.sys, (2) w22n51.sys, (3) w29n50.sys, and (4) w29n51.sys Microsoft Windows drivers for Intel 2200BG and 2915ABG PRO/Wireless Network Connection before 10.5 with driver 9.0.4.16 allows remote attackers to execute arbitrary code via certain frames that trigger memory corruption.
17028| [CVE-2006-3942] The server driver (srv.sys) in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (system crash) via an SMB_COM_TRANSACTION SMB message that contains a string without null character termination, which leads to a NULL dereference in the ExecuteTransaction function, possibly related to an "SMB PIPE," aka the "Mailslot DOS" vulnerability. NOTE: the name "Mailslot DOS" was derived from incomplete initial research
17029| [CVE-2006-3897] Stack overflow in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a denial of service (application crash) by creating an NMSA.ASFSourceMediaDescription.1 ActiveX object with a long dispValue property.
17030| [CVE-2006-3880] ** DISPUTED ** Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Small Business Server 2003 allow remote attackers to cause a denial of service (IP stack hang) via a continuous stream of packets on TCP port 135 that have incorrect TCP header checksums and random numbers in certain TCP header fields, as demonstrated by the Achilles Windows Attack Tool. NOTE: the researcher reports that the Microsoft Security Response Center has stated "Our investigation which has included code review, review of the TCPDump, and attempts on reproing the issue on multiple fresh installs of various Windows Operating Systems have all resulted in non confirmation."
17031| [CVE-2006-3877] Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via an unspecified "crafted file," a different vulnerability than CVE-2006-3435, CVE-2006-4694, and CVE-2006-3876.
17032| [CVE-2006-3876] Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via a crafted Data record in a PPT file, a different vulnerability than CVE-2006-3435 and CVE-2006-4694.
17033| [CVE-2006-3875] Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, and Excel Viewer 2003 allows user-assisted attackers to execute arbitrary code via a crafted COLINFO record in an XLS file, a different vulnerability than CVE-2006-2387 and CVE-2006-3867.
17034| [CVE-2006-3873] Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP SP1, with versions the MS06-042 patch before 20060912, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL in a GZIP-encoded website that was the target of an HTTP redirect, due to an incomplete fix for CVE-2006-3869.
17035| [CVE-2006-3869] Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP SP1, with versions the MS06-042 patch before 20060824, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL on a website that uses HTTP 1.1 compression.
17036| [CVE-2006-3868] Unspecified vulnerability in Microsoft Office XP and 2003 allows remote user-assisted attackers to execute arbitrary code via a malformed Smart Tag.
17037| [CVE-2006-3867] Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, and Excel Viewer 2003 allows user-assisted attackers to execute arbitrary code via a crafted Lotus 1-2-3 file, a different vulnerability than CVE-2006-2387 and CVE-2006-3875.
17038| [CVE-2006-3864] Unspecified vulnerability in mso.dll in Microsoft Office 2000, XP, and 2003, and Microsoft PowerPoint 2000, XP, and 2003, allows remote user-assisted attackers to execute arbitrary code via a malformed record in a (1) .DOC, (2) .PPT, or (3) .XLS file that triggers memory corruption, related to an "array boundary condition" (possibly an array index overflow), a different vulnerability than CVE-2006-3434, CVE-2006-3650, and CVE-2006-3868.
17039| [CVE-2006-3841] Cross-site scripting (XSS) vulnerability in WebScarab before 20060718-1904, when used with Microsoft Internet Explorer 6 SP2 or Konqueror 3.5.3, allows remote attackers to inject arbitrary web script or HTML via the URL, which is not sanitized before being returned in an error message when WebScarab is not able to access the URL.
17040| [CVE-2006-3660] Unspecified vulnerability in Microsoft PowerPoint 2003 has unknown impact and user-assisted attack vectors related to powerpnt.exe. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3655, CVE-2006-3656, and CVE-2006-3590, although it is possible that they are all different.
17041| [CVE-2006-3656] Unspecified vulnerability in Microsoft PowerPoint 2003 allows user-assisted attackers to cause memory corruption via a crafted PowerPoint file, which triggers the corruption when the file is closed. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3655, CVE-2006-3660, and CVE-2006-3590, although it is possible that they are all different.
17042| [CVE-2006-3655] Unspecified vulnerability in mso.dll in Microsoft PowerPoint 2003 allows user-assisted attackers to execute arbitrary code via a crafted PowerPoint file. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3656, CVE-2006-3660, and CVE-2006-3590, although it is possible that they are all different.
17043| [CVE-2006-3652] Microsoft Internet Security and Acceleration (ISA) Server 2004 allows remote attackers to bypass file extension filters via a request with a trailing "#" character. NOTE: as of 20060715, this could not be reproduced by third parties.
17044| [CVE-2006-3651] Unspecified vulnerability in Microsoft Word 2000, 2002, and Office 2003 allows remote user-assisted attackers to execute arbitrary code via a crafted mail merge file, a different vulnerability than CVE-2006-3647 and CVE-2006-4693.
17045| [CVE-2006-3650] Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac do not properly parse the length of a chart record, which allows remote user-assisted attackers to execute arbitrary code via a Word document with an embedded malformed chart record that triggers an overwrite of pointer values with values from the document, a different vulnerability than CVE-2006-3434, CVE-2006-3864, and CVE-2006-3868.
17046| [CVE-2006-3649] Buffer overflow in Microsoft Visual Basic for Applications (VBA) SDK 6.0 through 6.4, as used by Microsoft Office 2000 SP3, Office XP SP3, Project 2000 SR1, Project 2002 SP1, Access 2000 Runtime SP3, Visio 2002 SP2, and Works Suite 2004 through 2006, allows user-assisted attackers to execute arbitrary code via unspecified document properties that are not verified when VBA is invoked to open documents.
17047| [CVE-2006-3648] Unspecified vulnerability in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 and 2003 SP1, allows remote attackers to execute arbitrary code via unspecified vectors involving unhandled exceptions, memory resident applications, and incorrectly "unloading chained exception."
17048| [CVE-2006-3647] Integer overflow in Microsoft Word 2000, 2002, 2003, 2004 for Mac, and v.X for Mac allows remote user-assisted attackers to execute arbitrary code via a crafted string in a Word document, which overflows a 16-bit integer length value, aka "Memmove Code Execution," a different vulnerability than CVE-2006-3651 and CVE-2006-4693.
17049| [CVE-2006-3643] Cross-site scripting (XSS) vulnerability in Internet Explorer 5.01 and 6 in Microsoft Windows 2000 SP4 permits access to local "HTML-embedded resource files" in the Microsoft Management Console (MMC) library, which allows remote authenticated users to execute arbitrary commands, aka "MMC Redirect Cross-Site Scripting Vulnerability."
17050| [CVE-2006-3590] mso.dll, as used by Microsoft PowerPoint 2000 through 2003, allows user-assisted attackers to execute arbitrary commands via a malformed shape container in a PPT file that leads to memory corruption, as exploited by Trojan.PPDropper.B, a different issue than CVE-2006-1540 and CVE-2006-3493.
17051| [CVE-2006-3510] The Remote Data Service Object (RDS.DataControl) in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a denial of service (crash) via a series of operations that result in an invalid length calculation when using SysAllocStringLen, then triggers a buffer over-read.
17052| [CVE-2006-3493] Buffer overflow in LsCreateLine function (mso_203) in mso.dll and mso9.dll, as used by Microsoft Word and possibly other products in Microsoft Office 2003, 2002, and 2000, allows remote user-assisted attackers to cause a denial of service (crash) via a crafted Word DOC or other Office file type. NOTE: this issue was originally reported to allow code execution, but on 20060710 Microsoft stated that code execution is not possible, and the original researcher agrees.
17053| [CVE-2006-3449] Unspecified vulnerability in Microsoft PowerPoint 2000 through 2003, possibly a buffer overflow, allows user-assisted remote attackers to execute arbitrary commands via a malformed record in the BIFF file format used in a PPT file, a different issue than CVE-2006-1540, aka "Microsoft PowerPoint Malformed Record Vulnerability."
17054| [CVE-2006-3448] Buffer overflow in the Step-by-Step Interactive Training in Microsoft Windows 2000 SP4, XP SP2 and Professional, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a long Syllabus string in crafted bookmark link files (cbo, cbl, or .cbm), a different issue than CVE-2005-1212.
17055| [CVE-2006-3445] Integer overflow in the ReadWideString function in agentdpv.dll in Microsoft Agent on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a large length value in an .ACF file, which results in a heap-based buffer overflow.
17056| [CVE-2006-3444] Unspecified vulnerability in the kernel in Microsoft Windows 2000 SP4, probably a buffer overflow, allows local users to obtain privileges via unspecified vectors involving an "unchecked buffer."
17057| [CVE-2006-3443] Untrusted search path vulnerability in Winlogon in Microsoft Windows 2000 SP4, when SafeDllSearchMode is disabled, allows local users to gain privileges via a malicious DLL in the UserProfile directory, aka "User Profile Elevation of Privilege Vulnerability."
17058| [CVE-2006-3441] Buffer overflow in the DNS Client service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted record response. NOTE: while MS06-041 implies that there is a single issue, there are multiple vectors, and likely multiple vulnerabilities, related to (1) a heap-based buffer overflow in a DNS server response to the client, (2) a DNS server response with malformed ATMA records, and (3) a length miscalculation in TXT, HINFO, X25, and ISDN records.
17059| [CVE-2006-3440] Buffer overflow in the Winsock API in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka "Winsock Hostname Vulnerability."
17060| [CVE-2006-3439] Buffer overflow in the Server Service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers, including anonymous users, to execute arbitrary code via a crafted RPC message, a different vulnerability than CVE-2006-1314.
17061| [CVE-2006-3436] Cross-site scripting (XSS) vulnerability in Microsoft .NET Framework 2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving "ASP.NET controls that set the AutoPostBack property to true".
17062| [CVE-2006-3435] PowerPoint in Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac does not properly parse the slide notes field in a document, which allows remote user-assisted attackers to execute arbitrary code via crafted data in this field, which triggers an erroneous object pointer calculation that uses data from within the document. NOTE: this issue is different than other PowerPoint vulnerabilities including CVE-2006-4694.
17063| [CVE-2006-3434] Unspecified vulnerability in Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac allows remote user-assisted attackers to execute arbitrary code via a crafted string that triggers memory corruption.
17064| [CVE-2006-3431] Buffer overflow in certain Asian language versions of Microsoft Excel might allow user-assisted attackers to execute arbitrary code via a crafted STYLE record in a spreadsheet that triggers the overflow when the user attempts to repair the document or selects the "Style" option, as demonstrated by nanika.xls. NOTE: Microsoft has confirmed to CVE via e-mail that this is different than the other Excel vulnerabilities announced before 20060707, including CVE-2006-3059 and CVE-2006-3086.
17065| [CVE-2006-3059] Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors. NOTE: this is a different vulnerability than CVE-2006-3086.
17066| [CVE-2006-2492] Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 20060519 for a zero-day attack.
17067| [CVE-2006-2389] Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via an Office file with a malformed property that triggers memory corruption related to record lengths, aka "Microsoft Office Property Vulnerability," a different vulnerability than CVE-2006-1316.
17068| [CVE-2006-2388] Microsoft Office Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via malformed cell comments, which lead to modification of "critical data offsets" during the rebuilding process.
17069| [CVE-2006-2387] Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, Excel Viewer 2003, and Microsoft Works Suite 2004 through 2006 allows user-assisted attackers to execute arbitrary code via a crafted DATETIME record in an XLS file, a different vulnerability than CVE-2006-3867 and CVE-2006-3875.
17070| [CVE-2006-2380] Microsoft Windows 2000 SP4 does not properly validate an RPC server during mutual authentication over SSL, which allows remote attackers to spoof an RPC server, aka the "RPC Mutual Authentication Vulnerability."
17071| [CVE-2006-2379] Buffer overflow in the TCP/IP Protocol driver in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via unknown vectors related to IP source routing.
17072| [CVE-2006-2378] Buffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and Sp2, Server 2003 SP1 and earlier, and Windows 98 and Me allows remote attackers to execute arbitrary code via a crafted ART image that causes heap corruption.
17073| [CVE-2006-2374] The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to cause a denial of service (hang) by calling the MrxSmbCscIoctlCloseForCopyChunk with the file handle of the shadow device, which results in a deadlock, aka the "SMB Invalid Handle Vulnerability."
17074| [CVE-2006-2373] The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to execute arbitrary code by calling the MrxSmbCscIoctlOpenForCopyChunk function with the METHOD_NEITHER method flag and an arbitrary address, possibly for kernel memory, aka the "SMB Driver Elevation of Privilege Vulnerability."
17075| [CVE-2006-2372] Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a crafted DHCP response.
17076| [CVE-2006-2371] Buffer overflow in the Remote Access Connection Manager service (RASMAN) service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," that lead to registry corruption and stack corruption, aka the "RASMAN Registry Corruption Vulnerability."
17077| [CVE-2006-2370] Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," aka the "RRAS Memory Corruption Vulnerability."
17078| [CVE-2006-2334] The RtlDosPathNameToNtPathName_U API function in NTDLL.DLL in Microsoft Windows 2000 SP4 and XP SP2 does not properly convert DOS style paths with trailing spaces into NT style paths, which allows context-dependent attackers to create files that cannot be accessed through the expected DOS path or prevent access to other similarly named files in the same directory, which prevents those files from being detected or disinfected by certain anti-virus and anti-spyware software.
17079| [CVE-2006-2094] Microsoft Internet Explorer before Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1, when Prompt is configured in Security Settings, uses modal dialogs to verify that a user wishes to run an ActiveX control or perform other risky actions, which allows user-assisted remote attackers to construct a race condition that tricks a user into clicking an object or pressing keys that are actually applied to a "Yes" approval for executing the control.
17080| [CVE-2006-2055] Argument injection vulnerability in Microsoft Outlook 2003 SP1 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via " (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft Outlook with an arbitrary filename as an attachment. NOTE: it is not clear whether this issue is implementation-specific or a problem in the Microsoft API.
17081| [CVE-2006-1654] Directory traversal vulnerability in the HP Color LaserJet 2500 Toolbox and Color LaserJet 4600 Toolbox on Microsoft Windows before 20060402 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request to TCP port 5225.
17082| [CVE-2006-1651] ** DISPUTED ** Microsoft ISA Server 2004 allows remote attackers to bypass certain filtering rules, including ones for (1) ICMP and (2) TCP, via IPv6 packets. NOTE: An established researcher has disputed this issue, saying that "Neither ISA Server 2004 nor Windows 2003 Basic Firewall support IPv6 filtering ... This is different network protocol."
17083| [CVE-2006-1540] MSO.DLL in Microsoft Office 2000, Office XP (2002), and Office 2003 allows user-assisted attackers to cause a denial of service and execute arbitrary code via multiple attack vectors, as originally demonstrated using a crafted document record with a malformed string, as demonstrated by replacing a certain "01 00 00 00" byte sequence with an "FF FF FF FF" byte sequence, possibly causing an invalid array index, in (1) an Excel .xls document, which triggers an access violation in ole32.dll
17084| [CVE-2006-1316] Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via an Office file with malformed string that triggers memory corruption related to record lengths, aka "Microsoft Office Parsing Vulnerability," a different vulnerability than CVE-2006-2389.
17085| [CVE-2006-1315] The Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to obtain sensitive information via crafted requests that leak information in SMB buffers, which are not properly initialized, aka "SMB Information Disclosure Vulnerability."
17086| [CVE-2006-1314] Heap-based buffer overflow in the Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to execute arbitrary code via crafted first-class Mailslot messages that triggers memory corruption and bypasses size restrictions on second-class Mailslot messages.
17087| [CVE-2006-1313] Microsoft JScript 5.1, 5.5, and 5.6 on Windows 2000 SP4, and 5.6 on Windows XP, Server 2003, Windows 98 and Windows Me, will "release objects early" in certain cases, which results in memory corruption and allows remote attackers to execute arbitrary code.
17088| [CVE-2006-1311] The RichEdit component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1
17089| [CVE-2006-1309] Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted LABEL record that triggers memory corruption.
17090| [CVE-2006-1308] Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted FNGROUPCOUNT value.
17091| [CVE-2006-1306] Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted BIFF record with an attacker-controlled array index that is used for a function pointer, aka "Malformed OBJECT record Vulnerability."
17092| [CVE-2006-1305] Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to cause a denial of service (memory exhaustion and interrupted mail recovery) via malformed e-mail header information, possibly related to (1) long subject lines or (2) large numbers of recipients in To or CC headers.
17093| [CVE-2006-1304] Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted COLINFO record, which triggers the overflow during a "data filling operation."
17094| [CVE-2006-1302] Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with certain crafted fields in a SELECTION record, which triggers memory corruption, aka "Malformed SELECTION record Vulnerability."
17095| [CVE-2006-1301] Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted SELECTION record that triggers memory corruption, a different vulnerability than CVE-2006-1302.
17096| [CVE-2006-1300] Microsoft .NET framework 2.0 (ASP.NET) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to bypass access restrictions via unspecified "URL paths" that can access Application Folder objects "explicitly by name."
17097| [CVE-2006-1257] The sample files in the authfiles directory in Microsoft Commerce Server 2002 before SP2 allow remote attackers to bypass authentication by logging in to authfiles/login.asp with a valid username and any password, then going to the main site twice.
17098| [CVE-2006-1193] Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2000 SP1 through SP3, when running Outlook Web Access (OWA), allows user-assisted remote attackers to inject arbitrary HTML or web script via unknown vectors related to "HTML parsing."
17099| [CVE-2006-1184] Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0, 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to cause a denial of service (crash) via a BuildContextW request with a large (1) UuidString or (2) GuidIn of a certain length, which causes an out-of-range memory access, aka the MSDTC Denial of Service Vulnerability. NOTE: this is a variant of CVE-2005-2119.
17100| [CVE-2006-0988] The default configuration of the DNS Server service on Windows Server 2003 and Windows 2000, and the Microsoft DNS Server service on Windows NT 4.0, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed source IP addresses.
17101| [CVE-2006-0935] Microsoft Word 2003 allows remote attackers to cause a denial of service (application crash) via a crafted file, as demonstrated by 101_filefuzz.
17102| [CVE-2006-0187] By design, Microsoft Visual Studio 2005 automatically executes code in the Load event of a user-defined control (UserControl1_Load function), which allows user-assisted attackers to execute arbitrary code by tricking the user into opening a malicious Visual Studio project file.
17103| [CVE-2006-0034] Heap-based buffer overflow in the CRpcIoManagerServer::BuildContext function in msdtcprx.dll for Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0 and Windows 2000 SP2 and SP3 allows remote attackers to execute arbitrary code via a long fifth argument to the BuildContextW or BuildContext opcode, which triggers a bug in the NdrAllocate function, aka the MSDTC Invalid Memory Access Vulnerability.
17104| [CVE-2006-0033] Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted PNG image that triggers memory corruption when it is parsed.
17105| [CVE-2006-0032] Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL, which is injected into an error message whose charset is set to UTF-7.
17106| [CVE-2006-0031] Stack-based buffer overflow in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed record with a modified length value, which leads to memory corruption.
17107| [CVE-2006-0030] Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed graphic, which leads to memory corruption.
17108| [CVE-2006-0029] Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed description, which leads to memory corruption.
17109| [CVE-2006-0028] Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via a BIFF parsing format file containing malformed BOOLERR records that lead to memory corruption, probably involving invalid pointers.
17110| [CVE-2006-0023] Microsoft Windows XP SP1 and SP2 before August 2004, and possibly other operating systems and versions, uses insecure default ACLs that allow the Authenticated Users group to gain privileges by modifying critical configuration information for the (1) Simple Service Discovery Protocol (SSDP), (2) Universal Plug and Play Device Host (UPnP), (3) NetBT, (4) SCardSvr, (5) DHCP, and (6) DnsCache services, aka "Permissive Windows Services DACLs." NOTE: the NetBT, SCardSvr, DHCP, DnsCache already require privileged access to exploit.
17111| [CVE-2006-0022] Unspecified vulnerability in Microsoft PowerPoint in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP1 and SP2, Office 2004 for Mac, and v. X for Mac allows user-assisted attackers to execute arbitrary code via a PowerPoint document with a malformed record, which triggers memory corruption.
17112| [CVE-2006-0021] Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang) via an IGMP packet with an invalid IP option, aka the "IGMP v3 DoS Vulnerability."
17113| [CVE-2006-0020] An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a crafted WMF file with a manipulated WMF header size, possibly involving an integer overflow, a different vulnerability than CVE-2005-4560, and aka "WMF Image Parsing Memory Corruption Vulnerability."
17114| [CVE-2006-0015] Cross-site scripting (XSS) vulnerability in _vti_bin/_vti_adm/fpadmdll.dll in Microsoft FrontPage Server Extensions 2002 and SharePoint Team Services allows remote attackers to inject arbitrary web script or HTML, then leverage the attack to execute arbitrary programs or create new accounts, via the (1) operation, (2) command, and (3) name parameters.
17115| [CVE-2006-0013] Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote authenticated users or Guests to execute arbitrary code via crafted RPC requests, a different vulnerability than CVE-2005-1207.
17116| [CVE-2006-0012] Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and "crafted files and directories," aka the "Windows Shell Vulnerability."
17117| [CVE-2006-0010] Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.
17118| [CVE-2006-0009] Buffer overflow in Microsoft Office 2000 SP3, XP SP3, and other versions and packages, allows user-assisted attackers to execute arbitrary code via a routing slip that is longer than specified by the provided length field, as exploited by malware such as TROJ_MDROPPER.BH and Trojan.PPDropper.E in attacks against PowerPoint.
17119| [CVE-2006-0008] The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program that displays the about box.
17120| [CVE-2006-0007] Buffer overflow in GIFIMP32.FLT, as used in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted GIF image that triggers memory corruption when it is parsed.
17121| [CVE-2006-0006] Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap (.BMP) file that specifies a size of 0 but contains additional data.
17122| [CVE-2006-0004] Microsoft PowerPoint 2000 in Office 2000 SP3 has an interaction with Internet Explorer that allows remote attackers to obtain sensitive information via a PowerPoint presentation that attempts to access objects in the Temporary Internet Files Folder (TIFF).
17123| [CVE-2006-0002] Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.
17124| [CVE-2006-0001] Stack-based buffer overflow in Microsoft Publisher 2000 through 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted PUB file, which causes an overflow when parsing fonts.
17125| [CVE-2005-4717] Microsoft Internet Explorer 6.0 on Windows NT 4.0 SP6a, Windows 2000 SP4, Windows XP SP1, Windows XP SP2, and Windows Server 2003 SP1 allows remote attackers to cause a denial of service (client crash) via a certain combination of a malformed HTML file and a CSS file that triggers a null dereference, probably related to rendering of a DIV element that contains a malformed IMG tag, as demonstrated by IEcrash.htm and IEcrash.rar.
17126| [CVE-2005-4269] mshtml.dll in Microsoft Windows XP, Server 2003, and Internet Explorer 6.0 SP1 allows attackers to cause a denial of service (access violation) by causing mshtml.dll to process button-focus events at the same time that a document is reloading, as seen in Microsoft Office InfoPath 2003 by repeatedly clicking the "Delete" button in a repeating section in a form. NOTE: the normal operation of InfoPath appears to involve a local user without any privilege boundaries, so this might not be a vulnerability in InfoPath. If no realistic scenarios exist for this problem in other products, then perhaps it should be excluded from CVE.
17127| [CVE-2005-4131] Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed range, which could lead to memory corruption involving an argument to the msvcrt.memmove function, aka "Brand new Microsoft Excel Vulnerability," as originally placed for sale on eBay as item number 7203336538.
17128| [CVE-2005-3981] ** DISPUTED ** NOTE: this issue has been disputed by third parties. Microsoft Windows XP, 2000, and 2003 allows local users to kill a writable process by using the CreateRemoteThread function with certain arguments on a process that has been opened using the OpenProcess function, possibly involving an invalid address for the start routine. NOTE: followup posts have disputed this issue, saying that if a user already has privileges to write to a process, then other functions could be called or the process could be terminated using PROCESS_TERMINATE.
17129| [CVE-2005-3945] The SynAttackProtect protection in Microsoft Windows 2003 before SP1 and Windows 2000 before SP4 with Update Roll-up uses a hash of predictable data, which allows remote attackers to cause a denial of service (CPU consumption) via a flood of SYN packets that produce identical hash values, which slows down the hash table lookups.
17130| [CVE-2005-3644] PNP_GetDeviceList (upnp_getdevicelist) in UPnP for Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 and earlier, allows remote attackers to cause a denial of service (memory consumption) via a DCE RPC request that specifies a large output buffer size, a variant of CVE-2006-6296, and a different vulnerability than CVE-2005-2120.
17131| [CVE-2005-3177] CHKDSK in Microsoft Windows 2000 before Update Rollup 1 for SP4, Windows XP, and Windows Server 2003, when running in fix mode, does not properly handle security descriptors if the master file table contains a large number of files or if the descriptors do not satisfy certain NTFS conventions, which could cause ACLs for some files to be reverted to less secure defaults, or cause security descriptors to be removed.
17132| [CVE-2005-3176] Microsoft Windows 2000 before Update Rollup 1 for SP4 does not record the IP address of a Windows Terminal Services client in a security log event if the client connects successfully, which could make it easier for attackers to escape detection.
17133| [CVE-2005-3175] Microsoft Windows 2000 before Update Rollup 1 for SP4 allows a local administrator to unlock a computer even if it has been locked by a domain administrator, which allows the local administrator to access the session as the domain administrator.
17134| [CVE-2005-3174] Microsoft Windows 2000 before Update Rollup 1 for SP4 allows users to log on to the domain, even when their password has expired, if the fully qualified domain name (FQDN) is 8 characters long.
17135| [CVE-2005-3173] Microsoft Windows 2000 before Update Rollup 1 for SP4 does not apply group policies if the user logs on using UPN credentials with a trailing dot, which prevents Windows 2000 from finding the correct domain controller and could allow the user to bypass intended restrictions.
17136| [CVE-2005-3172] The WideCharToMultiByte function in Microsoft Windows 2000 before Update Rollup 1 for SP4 does not properly convert strings with Japanese composite characters in the last character, which could prevent the string from being null terminated and lead to data corruption or enable buffer overflow attacks.
17137| [CVE-2005-3171] Microsoft Windows 2000 before Update Rollup 1 for SP4 records Event ID 1704 to indicate that Group Policy security settings were successfully updated, even when the processing fails such as when Ntuser.pol cannot be accessed, which could cause system administrators to believe that the system is compliant with the specified settings.
17138| [CVE-2005-3170] The LDAP client on Microsoft Windows 2000 before Update Rollup 1 for SP4 accepts certificates using LDAP Secure Sockets Layer (LDAPS) even when the Certificate Authority (CA) is not trusted, which could allow attackers to trick users into believing that they are accessing a trusted site.
17139| [CVE-2005-3169] Microsoft Windows 2000 before Update Rollup 1 for SP4, when the "audit directory service access" policy is enabled, does not record a 565 event message for File Delete Child operations on an Active Directory object in the security event log, which could allow attackers to conduct unauthorized activities without detection.
17140| [CVE-2005-3168] The SECEDIT command on Microsoft Windows 2000 before Update Rollup 1 for SP4, when using a security template to set Access Control Lists (ACLs) on folders, does not apply ACLs on folders that are listed after a long folder entry, which could result in less secure permissions than specified by the template.
17141| [CVE-2005-2122] Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to execute arbitrary commands via a shortcut (.lnk) file with long font properties that lead to a buffer overflow in the Client/Server Runtime Server Subsystem (CSRSS), a different vulnerability than CVE-2005-2118.
17142| [CVE-2005-2120] Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of "\" (backslash) characters in a registry key name, which triggers the overflow in a wsprintfW function call.
17143| [CVE-2005-2118] Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote user-assisted attackers to execute arbitrary commands via a crafted shortcut (.lnk) file with long font properties that lead to a buffer overflow when the user views the file's properties using Windows Explorer, a different vulnerability than CVE-2005-2122.
17144| [CVE-2005-2117] Web View in Windows Explorer on Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 does not properly handle certain HTML characters in preview fields, which allows remote user-assisted attackers to execute arbitrary code.
17145| [CVE-2005-1985] The Client Service for NetWare (CSNW) on Microsoft Windows 2000 SP4, XP SP1 and Sp2, and Server 2003 SP1 and earlier, allows remote attackers to execute arbitrary code due to an "unchecked buffer" when processing certain crafted network messages.
17146| [CVE-2005-1984] Buffer overflow in the Print Spooler service (Spoolsv.exe) for Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via a malicious message.
17147| [CVE-2005-1983] Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1 allows remote attackers to execute arbitrary code via a crafted packet, and local users to gain privileges via a malicious application, as exploited by the Zotob (aka Mytob) worm.
17148| [CVE-2005-1982] Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.
17149| [CVE-2005-1981] Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message.
17150| [CVE-2005-1907] The ISA Firewall service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (Wspsrv.exe crash) via a large amount of SecureNAT network traffic.
17151| [CVE-2005-1683] Buffer overflow in winword.exe 10.2627.6714 and earlier in Microsoft Word for the Macintosh, before SP3 for Word 2002, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted mcw file.
17152| [CVE-2005-1218] The Microsoft Windows kernel in Microsoft Windows 2000 Server, Windows XP, and Windows Server 2003 allows remote attackers to cause a denial of service (crash) via crafted Remote Desktop Protocol (RDP) requests.
17153| [CVE-2005-1216] Microsoft ISA Server 2000 allows remote attackers to connect to services utilizing the NetBIOS protocol via a NetBIOS connection with an ISA Server that uses the NetBIOS (all) predefined packet filter.
17154| [CVE-2005-1215] Microsoft ISA Server 2000 allows remote attackers to poison the ISA cache or bypass content restriction policies via a malformed HTTP request packet containing multiple Content-Length headers.
17155| [CVE-2005-1208] Integer overflow in Microsoft Windows 98, 2000, XP SP2 and earlier, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via a crafted compiled Help (.CHM) file with a large size field that triggers a heap-based buffer overflow, as demonstrated using a "ms-its:" URL in Internet Explorer.
17156| [CVE-2005-1207] Buffer overflow in the Web Client service in Microsoft Windows XP and Windows Server 2003 allows remote authenticated users to execute arbitrary code via a crafted WebDAV request containing special parameters.
17157| [CVE-2005-1206] Buffer overflow in the Server Message Block (SMB) functionality for Microsoft Windows 2000, XP SP1 and SP2, and Server 2003 and SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka the "Server Message Block Vulnerability."
17158| [CVE-2005-1205] The Telnet client for Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX allows remote attackers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.
17159| [CVE-2005-1052] Microsoft Outlook 2003 and Outlook Web Access (OWA) 2003 do not properly display comma separated addresses in the From field in an e-mail message, which could allow remote attackers to spoof e-mail addresses.
17160| [CVE-2005-0921] Microsoft Outlook 2002 Connector for IBM Lotus Domino 2.0 allows local users to save passwords and login credentials locally, even when password caching is disabled by a group policy.
17161| [CVE-2005-0820] Microsoft Office InfoPath 2003 SP1 includes sensitive information in the Manifest.xsf file in a custom .xsn form, which allows attackers to obtain printer and network information, obtain the database name, username, and password, or obtain the internal web server name.
17162| [CVE-2005-0738] Stack consumption vulnerability in Microsoft Exchange Server 2003 SP1 allows users to cause a denial of service (hang) by deleting or moving a folder with deeply nested subfolders, which causes Microsoft Exchange Information Store service (Store.exe) to hang as a result of a large number of recursive calls.
17163| [CVE-2005-0564] Stack-based buffer overflow in Microsoft Word 2000 and Word 2002, and Microsoft Works Suites 2000 through 2004, might allow remote attackers to execute arbitrary code via a .doc file with long font information.
17164| [CVE-2005-0558] Buffer overflow in Microsoft Word 2000, Word 2002, and Word 2003 allows remote attackers to execute arbitrary code via a crafted document.
17165| [CVE-2005-0551] Stack-based buffer overflow in WINSRV.DLL in the Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application that provides console window information with a long FaceName value.
17166| [CVE-2005-0550] Buffer overflow in Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to cause a denial of service (i.e., system crash) via a malformed request, aka "Object Management Vulnerability".
17167| [CVE-2005-0545] Microsoft Windows XP Pro SP2 and Windows 2000 Server SP4 running Active Directory allow local users to bypass group policies that restrict access to hidden drives by using the browse feature in Office 10 applications such as Word or Excel, or using a flash drive. NOTE: this issue has been disputed in a followup post.
17168| [CVE-2005-0063] The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.
17169| [CVE-2005-0061] The kernel of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via certain access requests.
17170| [CVE-2005-0060] Buffer overflow in the font processing component of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application.
17171| [CVE-2005-0059] Buffer overflow in the Message Queuing component of Microsoft Windows 2000 and Windows XP SP1 allows remote attackers to execute arbitrary code via a crafted message.
17172| [CVE-2005-0058] Buffer overflow in the Telephony Application Programming Interface (TAPI) for Microsoft Windows 98, Windows 98 SE, Windows ME, Windows 2000, Windows XP, and Windows Server 2003 allows attackers elevate privileges or execute arbitrary code via a crafted message.
17173| [CVE-2005-0048] Microsoft Windows XP SP2 and earlier, 2000 SP3 and SP4, Server 2003, and older operating systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IP packets with malformed options, aka the "IP Validation Vulnerability."
17174| [CVE-2004-2527] The local and remote desktop login screens in Microsoft Windows XP before SP2 and 2003 allow remote attackers to cause a denial of service (CPU and memory consumption) by repeatedly using the WinKey+"U" key combination, which causes multiple copies of Windows Utility Manager to be loaded more quickly than they can be closed when the copies detect that another instance is running.
17175| [CVE-2004-2482] Microsoft Outlook 2000 and 2003, when configured to use Microsoft Word 2000 or 2003 as the e-mail editor and when forwarding e-mail, does not properly handle an opening OBJECT tag that does not have a closing OBJECT tag, which causes Outlook to automatically download the URI in the data property of the OBJECT tag and might allow remote attackers to execute arbitrary code.
17176| [CVE-2004-2365] Memory leak in Microsoft Windows XP and Windows Server 2003 allows local users to cause a denial of service (memory exhaustion) by repeatedly creating and deleting directories using a non-standard tool such as smbmount.
17177| [CVE-2004-2339] ** DISPUTED ** Microsoft Windows 2000, XP, and possibly 2003 allows local users with the SeDebugPrivilege privilege to execute arbitrary code as kernel and read or write kernel memory via the NtSystemDebugControl function, which does not verify its pointer arguments. Note: this issue has been disputed, since Administrator privileges are typically required to exploit this issue, thus privilege boundaries are not crossed.
17178| [CVE-2004-1080] The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42, aka the "Association Context Vulnerability."
17179| [CVE-2004-0963] Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause a denial of service (application exception) and possibly execute arbitrary code in winword.exe via certain unexpected values in a .doc file, including (1) an offset that triggers an out-of-bounds memory access, (2) a certain value that causes a large memory copy as triggered by an integer conversion error, and other values.
17180| [CVE-2004-0897] The Indexing Service for Microsoft Windows XP and Server 2003 does not properly validate the length of a message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.
17181| [CVE-2004-0892] Microsoft Proxy Server 2.0 and Microsoft ISA Server 2000 (which is included in Small Business Server 2000 and Small Business Server 2003 Premium Edition) allows remote attackers to spoof trusted Internet content on a specially crafted webpage via spoofed reverse DNS lookup results.
17182| [CVE-2004-0846] Unknown vulnerability in Microsoft Excel 2000, 2002, 2001 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via a malicious file containing certain parameters that are not properly validated.
17183| [CVE-2004-0840] The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows Server 2003 64-bit Edition, and the Exchange Routing Engine component of Exchange Server 2003, allows remote attackers to execute arbitrary code via a malicious DNS response message containing length values that are not properly validated.
17184| [CVE-2004-0728] The Remote Control Client service in Microsoft's Systems Management Server (SMS) 2.50.2726.0 allows remote attackers to cause a denial of service (crash) via a data packet to TCP port 2702 that causes the server to read or write to an invalid memory address.
17185| [CVE-2004-0726] The Windows Media Player control in Microsoft Windows 2000 allows remote attackers to execute arbitrary script in the local computer zone via an ASX filename that contains javascript, which is executed in the local context in a preview panel.
17186| [CVE-2004-0575] Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit Edition allows remote attackers to execute arbitrary code via compressed (zipped) folders that involve an "unchecked buffer" and improper length validation.
17187| [CVE-2004-0574] The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an "unchecked buffer," leading to off-by-one and heap-based buffer overflows.
17188| [CVE-2004-0573] Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website.
17189| [CVE-2004-0540] Microsoft Windows 2000, when running in a domain whose Fully Qualified Domain Name (FQDN) is exactly 8 characters long, does not prevent users with expired passwords from logging on to the domain.
17190| [CVE-2004-0503] Microsoft Outlook 2003 allows remote attackers to bypass the default zone restrictions and execute script within media files via a Rich Text Format (RTF) message containing an OLE object for the Windows Media Player, which bypasses Media Player's setting to disallow scripting and may lead to unprompted installation of an executable when exploited in conjunction with predictable-file-location exposures such as CVE-2004-0502.
17191| [CVE-2004-0379] Multiple cross-site scripting (XSS) vulnerabilities in Microsoft SharePoint Portal Server 2001 allow remote attackers to process arbitrary web content and steal cookies via certain server scripts.
17192| [CVE-2004-0284] Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if "Do not save encrypted pages to disk" is disabled, via a web site or HTML e-mail that contains two null characters (%00) after the host name.
17193| [CVE-2004-0214] Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.
17194| [CVE-2004-0211] The kernel for Microsoft Windows Server 2003 does not reset certain values in CPU data structures, which allows local users to cause a denial of service (system crash) via a malicious program.
17195| [CVE-2004-0210] The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.
17196| [CVE-2004-0209] Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats that involve "an unchecked buffer."
17197| [CVE-2004-0208] The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions.
17198| [CVE-2004-0207] "Shatter" style vulnerability in the Window Management application programming interface (API) for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to gain privileges by using certain API functions to change properties of privileged programs using the SetWindowLong and SetWIndowLongPtr API functions.
17199| [CVE-2004-0206] Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow.
17200| [CVE-2004-0204] Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and other products, allows remote attackers to read and delete arbitrary files via ".." sequences in the dynamicimag argument to crystalimagehandler.aspx.
17201| [CVE-2004-0202] IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.
17202| [CVE-2004-0201] Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.
17203| [CVE-2004-0199] Help and Support Center in Microsoft Windows XP and Windows Server 2003 SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code, as demonstrated using certain hcp:// URLs that access the DVD Upgrade capability (dvdupgrd.htm).
17204| [CVE-2004-0124] The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability."
17205| [CVE-2004-0121] Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.
17206| [CVE-2004-0120] The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages.
17207| [CVE-2004-0116] An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field.
17208| [CVE-2003-1378] Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs via an HTML email with the CODEBASE parameter set to the program, a vulnerability similar to CAN-2002-0077.
17209| [CVE-2003-1106] The SMTP service in Microsoft Windows 2000 before SP4 allows remote attackers to cause a denial of service (crash or hang) via an e-mail message with a malformed time stamp in the FILETIME attribute.
17210| [CVE-2003-0908] The Utility Manager in Microsoft Windows 2000 executes winhlp32.exe with system privileges, which allows local users to execute arbitrary code via a "Shatter" style attack using a Windows message that accesses the context sensitive help button in the GUI, as demonstrated using the File Open dialog in the Help window, a different vulnerability than CVE-2004-0213.
17211| [CVE-2003-0906] Buffer overflow in the rendering for (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1 allows remote attackers to execute arbitrary code via a malformed WMF or EMF image.
17212| [CVE-2003-0904] Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reuse HTTP connections, which can cause OWA users to view mailboxes of other users when Kerberos has been disabled as an authentication method for IIS 6.0, e.g. when SharePoint Services 2.0 is installed.
17213| [CVE-2003-0839] Directory traversal vulnerability in the "Shell Folders" capability in Microsoft Windows Server 2003 allows remote attackers to read arbitrary files via .. (dot dot) sequences in a "shell:" link.
17214| [CVE-2003-0825] The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code.
17215| [CVE-2003-0824] Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.
17216| [CVE-2003-0822] Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to execute arbitrary code via a crafted chunked encoded request.
17217| [CVE-2003-0821] Microsoft Excel 97, 2000, and 2002 allows remote attackers to execute arbitrary code via a spreadsheet with a malicious XLM (Excel 4) macro that bypasses the macro security model.
17218| [CVE-2003-0820] Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.
17219| [CVE-2003-0819] Buffer overflow in the H.323 filter of Microsoft Internet Security and Acceleration Server 2000 allows remote attackers to execute arbitrary code in the Microsoft Firewall Service via certain H.323 traffic, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.
17220| [CVE-2003-0818] Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.
17221| [CVE-2003-0807] Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a crafted request.
17222| [CVE-2003-0806] Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1, when a member of a domain, allows remote attackers to execute arbitrary code.
17223| [CVE-2003-0719] Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets.
17224| [CVE-2003-0665] Buffer overflow in the ActiveX control for Microsoft Access Snapshot Viewer for Access 97, 2000, and 2002 allows remote attackers to execute arbitrary code via long parameters to the control.
17225| [CVE-2003-0664] Microsoft Word 2002, 2000, 97, and 98(J) does not properly check certain properties of a document, which allows attackers to bypass the macro security model and automatically execute arbitrary macros via a malicious document.
17226| [CVE-2003-0662] Buffer overflow in Troubleshooter ActiveX Control (Tshoot.ocx) in Microsoft Windows 2000 SP4 and earlier allows remote attackers to execute arbitrary code via an HTML document with a long argument to the RunQuery2 method.
17227| [CVE-2003-0660] The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to download and install ActiveX controls when the system is low on memory, which could allow remote attackers execute arbitrary code without user approval.
17228| [CVE-2003-0533] Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.
17229| [CVE-2003-0526] Cross-site scripting (XSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to inject arbitrary web script via a URL containing the script in the domain name portion, which is not properly cleansed in the default error pages (1) 500.htm for "500 Internal Server error" or (2) 404.htm for "404 Not Found."
17230| [CVE-2003-0506] Microsoft NetMeeting 3.01 2000 before SP4 allows remote attackers to cause a denial of service (shutdown of NetMeeting conference) via malformed packets, as demonstrated via the chat conversation.
17231| [CVE-2003-0505] Directory traversal vulnerability in Microsoft NetMeeting 3.01 2000 before SP4 allows remote attackers to read arbitrary files via "..\.." (dot dot) sequences in a file transfer request.
17232| [CVE-2003-0496] Microsoft SQL Server before Windows 2000 SP4 allows local users to gain privileges as the SQL Server user by calling the xp_fileexist extended stored procedure with a named pipe as an argument instead of a normal file.
17233| [CVE-2003-0352] Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message, as exploited by the Blaster/MSblast/LovSAN and Nachi/Welchia worms.
17234| [CVE-2003-0345] Buffer overflow in the SMB capability for Microsoft Windows XP, 2000, and NT allows remote attackers to cause a denial of service and possibly execute arbitrary code via an SMB packet that specifies a smaller buffer length than is required.
17235| [CVE-2003-0232] Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local Procedure Calls (LPC) port that leads to a buffer overflow.
17236| [CVE-2003-0231] Microsoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial of service (crash or hang) via a long request to a named pipe.
17237| [CVE-2003-0230] Microsoft SQL Server 7, 2000, and MSDE allows local users to gain privileges by hijacking a named pipe during the authentication of another user, aka the "Named Pipe Hijacking" vulnerability.
17238| [CVE-2003-0227] The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft Windows NT 4.0 and 2000, nsiislog.dll, allows remote attackers to cause a denial of service in Internet Information Server (IIS) and execute arbitrary code via a certain network request.
17239| [CVE-2003-0118] SQL injection vulnerability in the Document Tracking and Administration (DTA) website of Microsoft BizTalk Server 2000 and 2002 allows remote attackers to execute operating system commands via a request to (1) rawdocdata.asp or (2) RawCustomSearchField.asp containing an embedded SQL statement.
17240| [CVE-2003-0117] Buffer overflow in the HTTP receiver function (BizTalkHTTPReceive.dll ISAPI) of Microsoft BizTalk Server 2002 allows attackers to execute arbitrary code via a certain request to the HTTP receiver.
17241| [CVE-2003-0110] The Winsock Proxy service in Microsoft Proxy Server 2.0 and the Microsoft Firewall service in Internet Security and Acceleration (ISA) Server 2000 allow remote attackers to cause a denial of service (CPU consumption or packet storm) via a spoofed, malformed packet to UDP port 1745.
17242| [CVE-2003-0109] Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0.
17243| [CVE-2003-0011] Unknown vulnerability in the DNS intrusion detection application filter for Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (blocked traffic to DNS servers) via a certain type of incoming DNS request that is not properly handled.
17244| [CVE-2003-0007] Microsoft Outlook 2002 does not properly handle requests to encrypt email messages with V1 Exchange Server Security certificates, which causes Outlook to send the email in plaintext, aka "Flaw in how Outlook 2002 handles V1 Exchange Server Security Certificates could lead to Information Disclosure."
17245| [CVE-2003-0003] Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter information.
17246| [CVE-2003-0002] Cross-site scripting vulnerability (XSS) in ManualLogin.asp script for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary script via the REASONTXT parameter.
17247| [CVE-2002-2101] Microsoft Outlook 2002 allows remote attackers to execute arbitrary JavaScript code, even when scripting is disabled, via an "about:" or "javascript:" URI in the href attribute of an "a" tag.
17248| [CVE-2002-2100] Microsoft Outlook 2002 allows remote attackers to embed bypass the file download restrictions for attachments via an HTML email message that uses an IFRAME to reference malicious content.
17249| [CVE-2002-1984] Microsoft Internet Explorer 5.0.1 through 6.0 on Windows 2000 or Windows XP allows remote attackers to cause a denial of service (crash) via an OBJECT tag that contains a crafted CLASSID (CLSID) value of "CLSID:00022613-0000-0000-C000-000000000046".
17250| [CVE-2002-1981] Microsoft SQL Server 2000 through SQL Server 2000 SP2 allows the "public" role to execute the (1) sp_MSSetServerProperties or (2) sp_MSsetalertinfo stored procedures, which allows attackers to modify configuration including SQL server startup and alert settings.
17251| [CVE-2002-1933] The terminal services screensaver for Microsoft Windows 2000 does not automatically lock the terminal window if the window is minimized, which could allow local users to gain access to the terminal server window.
17252| [CVE-2002-1932] Microsoft Windows XP and Windows 2000, when configured to send administrative alerts and the "Do not overwrite events (clear log manually)" option is set, does not notify the administrator when the log reaches its maximum size, which allows local users and remote attackers to avoid detection.
17253| [CVE-2002-1876] Microsoft Exchange 2000 allows remote authenticated attackers to cause a denial of service via a large number of rapid requests, which consumes all of the licenses that are granted to Exchange by IIS.
17254| [CVE-2002-1873] Microsoft Exchange 2000, when used with Microsoft Remote Procedure Call (MSRPC), allows remote attackers to cause a denial of service (crash or memory consumption) via malformed MSRPC calls.
17255| [CVE-2002-1872] Microsoft SQL Server 6.0 through 2000, with SQL Authentication enabled, uses weak password encryption (XOR), which allows remote attackers to sniff and decrypt the password.
17256| [CVE-2002-1776] ** DISPUTED ** NOTE: this issue has been disputed by the vendor. Symantec Norton AntiVirus 2002 allows remote attackers to bypass virus protection via a Word Macro virus with a .nch or .dbx extension, which is automatically recognized and executed as a Microsoft Office document. NOTE: the vendor has disputed this issue, acknowledging that the initial scan is bypassed, but the Office plug-in would detect the virus before it is executed.
17257| [CVE-2002-1712] Microsoft Windows 2000 allows remote attackers to cause a denial of service (memory consumption) by sending a flood of empty TCP/IP packets with the ACK and FIN bits set to the NetBIOS port (TCP/139), as demonstrated by stream3.
17258| [CVE-2002-1256] The SMB signing capability in the Server Message Block (SMB) protocol in Microsoft Windows 2000 and Windows XP allows attackers to disable the digital signing settings in an SMB session to force the data to be sent unsigned, then inject data into the session without detection, e.g. by modifying group policy information sent from a domain controller.
17259| [CVE-2002-1255] Microsoft Outlook 2002 allows remote attackers to cause a denial of service (repeated failure) via an email message with a certain invalid header field that is accessed using POP3, IMAP, or WebDAV, aka "E-mail Header Processing Flaw Could Cause Outlook 2002 to Fail."
17260| [CVE-2002-1214] Buffer overflow in Microsoft PPTP Service on Windows XP and Windows 2000 allows remote attackers to cause a denial of service (hang) and possibly execute arbitrary code via a certain PPTP packet with malformed control data.
17261| [CVE-2002-1184] The system root folder of Microsoft Windows 2000 has default permissions of Everyone group with Full access (Everyone:F) and is in the search path when locating programs during login or application launch from the desktop, which could allow attackers to gain privileges as other users via Trojan horse programs.
17262| [CVE-2002-1145] The xp_runwebtask stored procedure in the Web Tasks component of Microsoft SQL Server 7.0 and 2000, Microsoft Data Engine (MSDE) 1.0, and Microsoft Desktop Engine (MSDE) 2000 can be executed by PUBLIC, which allows an attacker to gain privileges by updating a webtask that is owned by the database owner through the msdb.dbo.mswebtasks table, which does not have strong permissions.
17263| [CVE-2002-1141] An input validation error in the Sun Microsystems RPC library Services for Unix 3.0 Interix SD, as implemented on Microsoft Windows NT4, 2000, and XP, allows remote attackers to cause a denial of service via malformed fragmented RPC client packets, aka "Denial of service by sending an invalid RPC request."
17264| [CVE-2002-1140] The Sun Microsystems RPC library Services for Unix 3.0 Interix SD, as implemented on Microsoft Windows NT4, 2000, and XP, allows remote attackers to cause a denial of service (service hang) via malformed packet fragments, aka "Improper parameter size check leading to denial of service."
17265| [CVE-2002-1138] Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, writes output files for scheduled jobs under its own privileges instead of the entity that launched it, which allows attackers to overwrite system files, aka "Flaw in Output File Handling for Scheduled Jobs."
17266| [CVE-2002-1137] Buffer overflow in the Database Console Command (DBCC) that handles user inputs in Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, allows attackers to execute arbitrary code via a long SourceDB argument in a "non-SQL OLEDB data source" such as FoxPro, a variant of CAN-2002-0644.
17267| [CVE-2002-1123] Buffer overflow in the authentication function for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows remote attackers to execute arbitrary code via a long request to TCP port 1433, aka the "Hello" overflow.
17268| [CVE-2002-1117] Veritas Backup Exec 8.5 and earlier requires that the "RestrictAnonymous" registry key for Microsoft Exchange 2000 must be set to 0, which enables anonymous listing of the SAM database and shares.
17269| [CVE-2002-1056] Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary scripts via an email that the user forwards or replies to.
17270| [CVE-2002-0982] Microsoft SQL Server 2000 SP2, when configured as a distributor, allows attackers to execute arbitrary code via the @scriptfile parameter to the sp_MScopyscript stored procedure.
17271| [CVE-2002-0975] Buffer overflow in Microsoft DirectX Files Viewer ActiveX control (xweb.ocx) 2.0.6.15 and earlier allows remote attackers to execute arbitrary via a long File parameter.
17272| [CVE-2002-0863] Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka "Weak Encryption in RDP Protocol."
17273| [CVE-2002-0861] Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to bypass the "Allow paste operations via script" setting, even when it is disabled, via the (1) Copy method of the Cell object or (2) the Paste method of the Range object.
17274| [CVE-2002-0860] The LoadText method in the spreadsheet component in Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to read arbitrary files through Internet Explorer via a URL that redirects to the target file.
17275| [CVE-2002-0859] Buffer overflow in the OpenDataSource function of the Jet engine on Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code.
17276| [CVE-2002-0729] Microsoft SQL Server 2000 allows remote attackers to cause a denial of service via a malformed 0x08 packet that is missing a colon separator.
17277| [CVE-2002-0727] The Host function in Microsoft Office Web Components (OWC) 2000 and 2002 is exposed in components that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via the setTimeout method.
17278| [CVE-2002-0724] Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows attackers to cause a denial of service (crash) via a SMB_COM_TRANSACTION packet with a request for the (1) NetShareEnum, (2) NetServerEnum2, or (3) NetServerEnum3, aka "Unchecked Buffer in Network Share Provider Can Lead to Denial of Service".
17279| [CVE-2002-0721] Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could allow unprivileged users, and possibly remote attackers, to run stored procedures with administrator privileges via (1) xp_execresultset, (2) xp_printstatements, or (3) xp_displayparamstmt.
17280| [CVE-2002-0719] SQL injection vulnerability in the function that services for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary commands via an MCMS resource request for image files or other files.
17281| [CVE-2002-0718] Web authoring command in Microsoft Content Management Server (MCMS) 2001 allows attackers to authenticate and upload executable content, by modifying the upload location, aka "Program Execution via MCMS Authoring Function."
17282| [CVE-2002-0700] Buffer overflow in a system function that performs user authentication for Microsoft Content Management Server (MCMS) 2001 allows attackers to execute code in the Local System context by authenticating to a web page that calls the function, aka "Unchecked Buffer in MDAC Function Could Enable SQL Server Compromise."
17283| [CVE-2002-0699] Unknown vulnerability in the Certificate Enrollment ActiveX Control in Microsoft Windows 98, Windows 98 Second Edition, Windows Millennium, Windows NT 4.0, Windows 2000, and Windows XP allow remote attackers to delete digital certificates on a user's system via HTML.
17284| [CVE-2002-0695] Buffer overflow in the Transact-SQL (T-SQL) OpenRowSet component of Microsoft Data Access Components (MDAC) 2.5 through 2.7 for SQL Server 7.0 or 2000 allows remote attackers to execute arbitrary code via a query that calls the OpenRowSet command.
17285| [CVE-2002-0694] The HTML Help facility in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP uses the Local Computer Security Zone when opening .chm files from the Temporary Internet Files folder, which allows remote attackers to execute arbitrary code via HTML mail that references or inserts a malicious .chm file containing shortcuts that can be executed, aka "Code Execution via Compiled HTML Help File."
17286| [CVE-2002-0693] Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute code via (1) a long parameter to the Alink function, or (2) script containing a long argument to the showHelp function.
17287| [CVE-2002-0692] Buffer overflow in SmartHTML Interpreter (shtml.dll) in Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to cause a denial of service (CPU consumption) or run arbitrary code, respectively, via a certain type of web file request.
17288| [CVE-2002-0650] The keep-alive mechanism for Microsoft SQL Server 2000 allows remote attackers to cause a denial of service (bandwidth consumption) via a "ping" style packet to the Resolution Service (UDP port 1434) with a spoofed IP address of another SQL Server system, which causes the two servers to exchange packets in an infinite loop.
17289| [CVE-2002-0649] Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSDE) allow remote attackers to cause a denial of service or execute arbitrary code via UDP packets to port 1434 in which (1) a 0x04 byte that causes the SQL Monitor thread to generate a long registry key name, or (2) a 0x08 byte with a long string causes heap corruption, as exploited by the Slammer/Sapphire worm.
17290| [CVE-2002-0645] SQL injection vulnerability in stored procedures for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 may allow authenticated users to execute arbitrary commands.
17291| [CVE-2002-0644] Buffer overflow in several Database Consistency Checkers (DBCCs) for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows members of the db_owner and db_ddladmin roles to execute arbitrary code.
17292| [CVE-2002-0643] The installation of Microsoft Data Engine 1.0 (MSDE 1.0), and Microsoft SQL Server 2000 creates setup.iss files with insecure permissions and does not delete them after installation, which allows local users to obtain sensitive data, including weakly encrypted passwords, to gain privileges, aka "SQL Server Installation Process May Leave Passwords on System."
17293| [CVE-2002-0642] The registry key containing the SQL Server service account information in Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, has insecure permissions, which allows local users to gain privileges, aka "Incorrect Permission on SQL Server Service Account Registry Key."
17294| [CVE-2002-0641] Buffer overflow in bulk insert procedure of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows attackers with database administration privileges to execute arbitrary code via a long filename in the BULK INSERT query.
17295| [CVE-2002-0624] Buffer overflow in the password encryption function of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows remote attackers to gain control of the database and execute arbitrary code via SQL Server Authentication, aka "Unchecked Buffer in Password Encryption Procedure."
17296| [CVE-2002-0623] Buffer overflow in AuthFilter ISAPI filter on Microsoft Commerce Server 2000 and 2002 allows remote attackers to execute arbitrary code via long authentication data, aka "New Variant of the ISAPI Filter Buffer Overrun".
17297| [CVE-2002-0622] The Office Web Components (OWC) package installer for Microsoft Commerce Server 2000 allows remote attackers to execute commands by passing the commands as input to the OWC package installer, aka "OWC Package Command Execution".
17298| [CVE-2002-0621] Buffer overflow in the Office Web Components (OWC) package installer used by Microsoft Commerce Server 2000 allows remote attackers to cause the process to fail or run arbitrary code in the LocalSystem security context via certain input to the OWC package installer.
17299| [CVE-2002-0620] Buffer overflow in the Profile Service of Microsoft Commerce Server 2000 allows remote attackers to cause the server to fail or run arbitrary code in the LocalSystem security context via an input field using an affected API.
17300| [CVE-2002-0619] The Mail Merge Tool in Microsoft Word 2002 for Windows, when Microsoft Access is present on a system, allows remote attackers to execute Visual Basic (VBA) scripts within a mail merge document that is saved in HTML format, aka a "Variant of MS00-071, Word Mail Merge Vulnerability" (CVE-2000-0788).
17301| [CVE-2002-0618] The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code in the Local Computer zone by embedding HTML scripts within an Excel workbook that contains an XSL stylesheet, aka "Excel XSL Stylesheet Script Execution".
17302| [CVE-2002-0617] The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code by creating a hyperlink on a drawing shape in a source workbook that points to a destination workbook containing an autoexecute macro, aka "Hyperlinked Excel Workbook Macro Bypass."
17303| [CVE-2002-0616] The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code by attaching an inline macro to an object within an Excel workbook, aka the "Excel Inline Macros Vulnerability."
17304| [CVE-2002-0597] LANMAN service on Microsoft Windows 2000 allows remote attackers to cause a denial of service (CPU/memory exhaustion) via a stream of malformed data to microsoft-ds port 445.
17305| [CVE-2002-0444] Microsoft Windows 2000 running the Terminal Server 90-day trial version, and possibly other versions, does not apply group policies to incoming users when the number of connections to the SYSVOL share exceeds the maximum, e.g. with a maximum number of licenses, which can allow remote authenticated users to bypass group policies.
17306| [CVE-2002-0443] Microsoft Windows 2000 allows local users to bypass the policy that prohibits reusing old passwords by changing the current password before it expires, which does not enable the check for previous passwords.
17307| [CVE-2002-0373] The Windows Media Device Manager (WMDM) Service in Microsoft Windows Media Player 7.1 on Windows 2000 systems allows local users to obtain LocalSystem rights via a program that calls the WMDM service to connect to an invalid local storage device, aka "Privilege Elevation through Windows Media Device Manager Service".
17308| [CVE-2002-0371] Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote attackers to execute arbitrary code via a gopher:// URL that redirects the user to a real or simulated gopher server that sends a long response.
17309| [CVE-2002-0368] The Store Service in Microsoft Exchange 2000 allows remote attackers to cause a denial of service (CPU consumption) via a mail message with a malformed RFC message attribute, aka "Malformed Mail Attribute can Cause Exchange 2000 to Exhaust CPU Resources."
17310| [CVE-2002-0224] The MSDTC (Microsoft Distributed Transaction Service Coordinator) for Microsoft Windows 2000, Microsoft IIS 5.0 and SQL Server 6.5 through SQL 2000 0.0 allows remote attackers to cause a denial of service (crash or hang) via malformed (random) input.
17311| [CVE-2002-0187] Cross-site scripting vulnerability in the SQLXML component of Microsoft SQL Server 2000 allows an attacker to execute arbitrary script via the root parameter as part of an XML SQL query, aka "Script Injection via XML Tag."
17312| [CVE-2002-0186] Buffer overflow in the SQLXML ISAPI extension of Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code via data queries with a long content-type parameter, aka "Unchecked Buffer in SQLXML ISAPI Extension."
17313| [CVE-2002-0154] Buffer overflows in extended stored procedures for Microsoft SQL Server 7.0 and 2000 allow remote attackers to cause a denial of service or execute arbitrary code via a database query with certain long arguments.
17314| [CVE-2002-0152] Buffer overflow in various Microsoft applications for Macintosh allows remote attackers to cause a denial of service (crash) or execute arbitrary code by invoking the file:// directive with a large number of / characters, which affects Internet Explorer 5.1, Outlook Express 5.0 through 5.0.2, Entourage v. X and 2001, PowerPoint v. X, 2001, and 98, and Excel v. X and 2001 for Macintosh.
17315| [CVE-2002-0055] SMTP service in Microsoft Windows 2000, Windows XP Professional, and Exchange 2000 allows remote attackers to cause a denial of service via a command with a malformed data transfer (BDAT) request.
17316| [CVE-2002-0054] SMTP service in (1) Microsoft Windows 2000 and (2) Internet Mail Connector (IMC) in Exchange Server 5.5 does not properly handle responses to NTLM authentication, which allows remote attackers to perform mail relaying via an SMTP AUTH command using null session credentials.
17317| [CVE-2002-0050] Buffer overflow in AuthFilter ISAPI filter on Microsoft Commerce Server 2000 allows remote attackers to execute arbitrary code via long authentication data.
17318| [CVE-2002-0049] Microsoft Exchange Server 2000 System Attendant gives "Everyone" group privileges to the WinReg key, which could allow remote attackers to read or modify registry keys.
17319| [CVE-2002-0034] The Microsoft CONVERT.EXE program, when used on Windows 2000 and Windows XP systems, does not apply the default NTFS permissions when converting a FAT32 file system, which could cause the conversion to produce a file system with less secure permissions than expected.
17320| [CVE-2002-0018] In Microsoft Windows NT and Windows 2000, a trusting domain that receives authorization information from a trusted domain does not verify that the trusted domain is authoritative for all listed SIDs, which allows remote attackers to gain Domain Administrator privileges on the trusting domain by injecting SIDs from untrusted domains into the authorization data that comes from from the trusted domain.
17321| [CVE-2001-1533] ** DISPUTED * Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets. NOTE: the vendor disputes this issue, saying that it requires high bandwidth to exploit, and the server does not experience any instability. Therefore this "laws of physics" issue might not be included in CVE.
17322| [CVE-2001-1451] Memory leak in the SNMP LAN Manager (LANMAN) MIB extension for Microsoft Windows 2000 before SP3, when the Print Spooler is not running, allows remote attackers to cause a denial of service (memory consumption) via a large number of GET or GETNEXT requests.
17323| [CVE-2001-1319] Microsoft Exchange 5.5 2000 allows remote attackers to cause a denial of service (hang) via exceptional BER encodings for the LDAP filter type field, as demonstrated by the PROTOS LDAPv3 test suite.
17324| [CVE-2001-1099] The default configuration of Norton AntiVirus for Microsoft Exchange 2000 2.x allows remote attackers to identify the recipient's INBOX file path by sending an email with an attachment containing malicious content, which includes the path in the rejection notice.
17325| [CVE-2001-0986] SQLQHit.asp sample file in Microsoft Index Server 2.0 allows remote attackers to obtain sensitive information such as the physical path, file attributes, or portions of source code by directly calling sqlqhit.asp with a CiScope parameter set to (1) webinfo, (2) extended_fileinfo, (3) extended_webinfo, or (4) fileinfo.
17326| [CVE-2001-0718] Vulnerability in (1) Microsoft Excel 2002 and earlier and (2) Microsoft PowerPoint 2002 and earlier allows attackers to bypass macro restrictions and execute arbitrary commands by modifying the data stream in the document.
17327| [CVE-2001-0666] Outlook Web Access (OWA) in Microsoft Exchange 2000 allows an authenticated user to cause a denial of service (CPU consumption) via a malformed OWA request for a deeply nested folder within the user's mailbox.
17328| [CVE-2001-0658] Cross-site scripting (CSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause other clients to execute certain script or read cookies via malicious script in an invalid URL that is not properly quoted in an error message.
17329| [CVE-2001-0628] Microsoft Word 2000 does not check AutoRecovery (.asd) files for macros, which allows a local attacker to execute arbitrary macros with the user ID of the Word user.
17330| [CVE-2001-0547] Memory leak in the proxy service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows local attackers to cause a denial of service (resource exhaustion).
17331| [CVE-2001-0546] Memory leak in H.323 Gatekeeper Service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (resource exhaustion) via a large amount of malformed H.323 data.
17332| [CVE-2001-0542] Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow attackers with access to SQL Server to execute arbitrary code through the functions (1) raiserror, (2) formatmessage, or (3) xp_sprintf. NOTE: the C runtime format string vulnerability reported in MS01-060 is identified by CVE-2001-0879.
17333| [CVE-2001-0538] Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTML e-mail message or web page.
17334| [CVE-2001-0509] Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs.
17335| [CVE-2001-0505] Multiple memory leaks in Microsoft Services for Unix 2.0 allow remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed requests to (1) the Telnet service, or (2) the NFS service.
17336| [CVE-2001-0504] Vulnerability in authentication process for SMTP service in Microsoft Windows 2000 allows remote attackers to use incorrect credentials to gain privileges and conduct activites such as mail relaying.
17337| [CVE-2001-0501] Microsoft Word 2002 and earlier allows attackers to automatically execute macros without warning the user by embedding the macros in a manner that escapes detection by the security scanner.
17338| [CVE-2001-0351] Microsoft Windows 2000 telnet service allows a local user to make a certain system call that allows the user to terminate a Telnet session and cause a denial of service.
17339| [CVE-2001-0350] Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the second of two variants of this vulnerability.
17340| [CVE-2001-0349] Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the first of two variants of this vulnerability.
17341| [CVE-2001-0348] Microsoft Windows 2000 telnet service allows attackers to cause a denial of service (crash) via a long logon command that contains a backspace.
17342| [CVE-2001-0347] Information disclosure vulnerability in Microsoft Windows 2000 telnet service allows remote attackers to determine the existence of user accounts such as Guest, or log in to the server without specifying the domain name, via a malformed userid.
17343| [CVE-2001-0346] Handle leak in Microsoft Windows 2000 telnet service allows attackers to cause a denial of service by starting a large number of sessions and terminating them.
17344| [CVE-2001-0345] Microsoft Windows 2000 telnet service allows attackers to prevent idle Telnet sessions from timing out, causing a denial of service by creating a large number of idle sessions.
17345| [CVE-2001-0344] An SQL query method in Microsoft SQL Server 2000 Gold and 7.0 using Mixed Mode allows local database users to gain privileges by reusing a cached connection of the sa administrator account.
17346| [CVE-2001-0340] An interaction between the Outlook Web Access (OWA) service in Microsoft Exchange 2000 Server and Internet Explorer allows attackers to execute malicious script code against a user's mailbox via a message attachment that contains HTML code, which is executed automatically.
17347| [CVE-2001-0261] Microsoft Windows 2000 Encrypted File System does not properly destroy backups of files that are encrypted, which allows a local attacker to recover the text of encrypted files.
17348| [CVE-2001-0245] Microsoft Index Server 2.0 in Windows NT 4.0, and Indexing Service in Windows 2000, allows remote attackers to read server-side include files via a malformed search request, aka a new variant of the "Malformed Hit-Highlighting" vulnerability.
17349| [CVE-2001-0244] Buffer overflow in Microsoft Index Server 2.0 allows remote attackers to execute arbitrary commands via a long search parameter.
17350| [CVE-2001-0240] Microsoft Word before Word 2002 allows attackers to automatically execute macros without warning the user via a Rich Text Format (RTF) document that links to a template with the embedded macro.
17351| [CVE-2001-0239] Microsoft Internet Security and Acceleration (ISA) Server 2000 Web Proxy allows remote attackers to cause a denial of service via a long web request with a specific type.
17352| [CVE-2001-0237] Memory leak in Microsoft 2000 domain controller allows remote attackers to cause a denial of service by repeatedly connecting to the Kerberos service and then disconnecting without sending any data.
17353| [CVE-2001-0146] IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly sending a series of specially formatted URL's.
17354| [CVE-2001-0048] The "Configure Your Server" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to install malicious programs, aka the "Directory Service Restore Mode Password" vulnerability.
17355| [CVE-2001-0005] Buffer overflow in the parsing mechanism of the file loader in Microsoft PowerPoint 2000 allows attackers to execute arbitrary commands.
17356| [CVE-2001-0003] Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials and possibly obtain the password, aka the "Web Client NTLM Authentication" vulnerability.
17357| [CVE-2000-1218] The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query, which allows remote attackers to poison the DNS cache.
17358| [CVE-2000-1217] Microsoft Windows 2000 before Service Pack 2 (SP2), when running in a non-Windows 2000 domain and using NTLM authentication, and when credentials of an account are locally cached, allows local users to bypass account lockout policies and make an unlimited number of login attempts, aka the "Domain Account Lockout" vulnerability.
17359| [CVE-2000-1209] The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq Insight Manager, and (6) Visio 2000, which allows remote attackers to gain privileges, as exploited by worms such as Voyager Alpha Force and Spida.
17360| [CVE-2000-1139] The installation of Microsoft Exchange 2000 before Rev. A creates a user account with a known password, which could allow attackers to gain privileges, aka the "Exchange User Account" vulnerability.
17361| [CVE-2000-1088] The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
17362| [CVE-2000-1087] The xp_proxiedmetadata function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
17363| [CVE-2000-1086] The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
17364| [CVE-2000-1085] The xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
17365| [CVE-2000-1079] Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote attackers to modify dynamic NetBIOS name cache entries via a spoofed Browse Frame Request in a unicast or UDP broadcast datagram.
17366| [CVE-2000-0942] The CiWebHitsFile component in Microsoft Indexing Services for Windows 2000 allows remote attackers to conduct a cross site scripting (CSS) attack via a CiRestriction parameter in a .htw request, aka the "Indexing Services Cross Site Scripting" vulnerability.
17367| [CVE-2000-0854] When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as riched20.dll and msi.dll, which could allow an attacker to execute arbitrary commands by inserting a Trojan Horse DLL into the same directory as the document.
17368| [CVE-2000-0771] Microsoft Windows 2000 allows local users to cause a denial of service by corrupting the local security policy via malformed RPC traffic, aka the "Local Security Policy Corruption" vulnerability.
17369| [CVE-2000-0765] Buffer overflow in the HTML interpreter in Microsoft Office 2000 allows an attacker to execute arbitrary commands via a long embedded object tag, aka the "Microsoft Office HTML Object Tag" vulnerability.
17370| [CVE-2000-0756] Microsoft Outlook 2000 does not properly process long or malformed fields in vCard (.vcf) files, which allows attackers to cause a denial of service.
17371| [CVE-2000-0710] The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers determine the physical path of the server components by requesting an invalid URL whose name includes a standard DOS device name.
17372| [CVE-2000-0709] The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to cause a denial of service in some components by requesting a URL whose name includes a standard DOS device name.
17373| [CVE-2000-0637] Microsoft Excel 97 and 2000 allows an attacker to execute arbitrary commands by specifying a malicious .dll using the Register.ID function, aka the "Excel REGISTER.ID Function" vulnerability.
17374| [CVE-2000-0621] Microsoft Outlook 98 and 2000, and Outlook Express 4.0x and 5.0x, allow remote attackers to read files on the client's system via a malformed HTML message that stores files outside of the cache, aka the "Cache Bypass" vulnerability.
17375| [CVE-2000-0597] Microsoft Office 2000 (Excel and PowerPoint) and PowerPoint 97 are marked as safe for scripting, which allows remote attackers to force Internet Explorer or some email clients to save files to arbitrary locations via the Visual Basic for Applications (VBA) SaveAs function, aka the "Office HTML Script" vulnerability.
17376| [CVE-2000-0331] Buffer overflow in Microsoft command processor (CMD.EXE) for Windows NT and Windows 2000 allows a local user to cause a denial of service via a long environment variable, aka the "Malformed Environment Variable" vulnerability.
17377| [CVE-2000-0277] Microsoft Excel 97 and 2000 does not warn the user when executing Excel Macro Language (XLM) macros in external text files, which could allow an attacker to execute a macro virus, aka the "XLM Text Macro" vulnerability.
17378| [CVE-2013-2557] The sandbox protection mechanism in Microsoft Internet Explorer 9 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, as demonstrated against Adobe Flash Player by VUPEN during a Pwn2Own competition at CanSecWest 2013.
17379| [CVE-2013-2556] Unspecified vulnerability in Microsoft Windows 7 allows attackers to bypass the ASLR protection mechanism via unknown vectors, as demonstrated against Adobe Flash Player by VUPEN during a Pwn2Own competition at CanSecWest 2013.
17380| [CVE-2013-2554] Unspecified vulnerability in Microsoft Windows 7 allows attackers to bypass the ASLR and DEP protection mechanisms via unknown vectors, as demonstrated against Firefox by VUPEN during a Pwn2Own competition at CanSecWest 2013, a different vulnerability than CVE-2013-0787.
17381| [CVE-2013-2553] Unspecified vulnerability in the kernel in Microsoft Windows 7 allows local users to gain privileges via unknown vectors, as demonstrated by Nils and Jon of MWR Labs during a Pwn2Own competition at CanSecWest 2013, a different vulnerability than CVE-2013-0912.
17382| [CVE-2013-2552] Unspecified vulnerability in Microsoft Internet Explorer 10 on Windows 8 allows remote attackers to bypass the sandbox protection mechanism by leveraging access to a Medium integrity process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013.
17383| [CVE-2013-2551] Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1308 and CVE-2013-1309.
17384| [CVE-2013-1347] Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly allocated or (2) is deleted, as exploited in the wild in May 2013.
17385| [CVE-2013-1305] HTTP.sys in Microsoft Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (infinite loop) via a crafted HTTP header, aka "HTTP.sys Denial of Service Vulnerability."
17386| [CVE-2013-1290] Microsoft SharePoint Server 2013, in certain configurations involving legacy My Sites, does not properly establish default access controls for a SharePoint list, which allows remote authenticated users to bypass intended restrictions on reading list items via a direct request for a list's location, aka "Incorrect Access Rights Information Disclosure Vulnerability."
17387| [CVE-2013-1289] Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1, Groove Server 2010 SP1, SharePoint Foundation 2010 SP1, and Office Web Apps 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted string, aka "HTML Sanitization Vulnerability."
17388| [CVE-2013-1284] Race condition in the kernel in Microsoft Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Kernel Race Condition Vulnerability."
17389| [CVE-2013-0096] Writer in Microsoft Windows Essentials 2011 and 2012 allows remote attackers to bypass proxy settings and overwrite arbitrary files via crafted URL parameters, aka "Windows Essentials Improper URI Handling Vulnerability."
17390| [CVE-2013-0086] Microsoft OneNote 2010 SP1 does not properly determine buffer sizes during memory allocation, which allows remote attackers to obtain sensitive information via a crafted OneNote file, aka "Buffer Size Validation Vulnerability."
17391| [CVE-2013-0085] Buffer overflow in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to cause a denial of service (W3WP process crash and site outage) via a crafted URL, aka "Buffer Overflow Vulnerability."
17392| [CVE-2013-0084] Directory traversal vulnerability in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to bypass intended read restrictions for content, and hijack user accounts, via a crafted URL, aka "SharePoint Directory Traversal Vulnerability."
17393| [CVE-2013-0083] Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via crafted content, leading to administrative command execution, aka "SharePoint XSS Vulnerability."
17394| [CVE-2013-0080] Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allow remote attackers to bypass intended read restrictions for content, and hijack user accounts, via a crafted URL, aka "Callback Function Vulnerability."
17395| [CVE-2013-0079] Microsoft Visio Viewer 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Visio file that triggers incorrect memory allocation, aka "Visio Viewer Tree Object Type Confusion Vulnerability."
17396| [CVE-2013-0005] The WCF Replace function in the Open Data (aka OData) protocol implementation in Microsoft .NET Framework 3.5, 3.5 SP1, 3.5.1, and 4, and the Management OData IIS Extension on Windows Server 2012, allows remote attackers to cause a denial of service (resource consumption and daemon restart) via crafted values in HTTP requests, aka "Replace Denial of Service Vulnerability."
17397| [CVE-2012-4969] Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site, as exploited in the wild in September 2012.
17398| [CVE-2012-4792] Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object, and exploited in the wild in December 2012.
17399| [CVE-2012-3456] Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in Calligra 2.4.3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ODF style in an ODF document. NOTE: this is the same vulnerability as CVE-2012-3455, but it was SPLIT by the CNA even though Calligra and KOffice share the same codebase.
17400| [CVE-2012-3455] Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in KOffice 2.3.3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ODF style in an ODF document. NOTE: this is the same vulnerability as CVE-2012-3456, but it was SPLIT by the CNA even though Calligra and KOffice share the same codebase.
17401| [CVE-2012-2290] The client in EMC NetWorker Module for Microsoft Applications (NMM) 2.2.1, 2.3 before build 122, and 2.4 before build 375 allows remote attackers to execute arbitrary code by sending a crafted message over a TCP communication channel.
17402| [CVE-2012-2284] The (1) install and (2) upgrade processes in EMC NetWorker Module for Microsoft Applications (NMM) 2.2.1, 2.3 before build 122, and 2.4 before build 375, when Exchange Server is used, allow local users to read cleartext administrator credentials via unspecified vectors.
17403| [CVE-2012-1945] Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allow local users to obtain sensitive information via an HTML document that loads a shortcut (aka .lnk) file for display within an IFRAME element, as demonstrated by a network share implemented by (1) Microsoft Windows or (2) Samba.
17404| [CVE-2012-1894] Microsoft Office for Mac 2011 uses world-writable permissions for the "Applications/Microsoft Office 2011/" directory and certain other directories, which allows local users to gain privileges by placing a Trojan horse executable file in one of these directories, aka "Office for Mac Improper Folder Permissions Vulnerability."
17405| [CVE-2012-1892] Cross-site scripting (XSS) vulnerability in Microsoft Visual Studio Team Foundation Server 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "XSS Vulnerability."
17406| [CVE-2012-1891] Heap-based buffer overflow in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2 and Windows Data Access Components (WDAC) 6.0 allows remote attackers to execute arbitrary code via crafted XML data that triggers access to an uninitialized object in memory, aka "ADO Cachesize Heap Overflow RCE Vulnerability."
17407| [CVE-2012-1888] Buffer overflow in Microsoft Visio 2010 SP1 and Visio Viewer 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Visio file, aka "Visio DXF File Format Buffer Overflow Vulnerability."
17408| [CVE-2012-1876] Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by attempting to access a nonexistent object, leading to a heap-based buffer overflow, aka "Col Element Remote Code Execution Vulnerability," as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012.
17409| [CVE-2012-1861] Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 Gold and SP1, SharePoint Foundation 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "SharePoint Script in Username Vulnerability."
17410| [CVE-2012-1859] Cross-site scripting (XSS) vulnerability in scriptresx.ashx in Microsoft SharePoint Server 2010 Gold and SP1, SharePoint Foundation 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "XSS scriptresx.ashx Vulnerability."
17411| [CVE-2012-1857] Cross-site scripting (XSS) vulnerability in the Enterprise Portal component in Microsoft Dynamics AX 2012 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Dynamics AX Enterprise Portal XSS Vulnerability."
17412| [CVE-2012-1849] Untrusted search path vulnerability in Microsoft Lync 2010, 2010 Attendee, and 2010 Attendant allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .ocsmeet file, aka "Lync Insecure Library Loading Vulnerability."
17413| [CVE-2012-1545] Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, allows remote attackers to bypass Protected Mode or cause a denial of service (memory corruption) by leveraging access to a Low integrity process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012.
17414| [CVE-2012-1436] The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \2D\6C\68 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.
17415| [CVE-2012-1435] The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \50\4B\4C\49\54\45 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.
17416| [CVE-2012-1434] The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \19\04\00\10 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.
17417| [CVE-2012-1433] The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \4a\46\49\46 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.
17418| [CVE-2012-0447] Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize data for image/vnd.microsoft.icon images, which allows remote attackers to obtain potentially sensitive information by reading a PNG image that was created through conversion from an ICO image.
17419| [CVE-2012-0147] Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 does not properly configure the default web site, which allows remote attackers to obtain sensitive information via a crafted HTTPS request, aka "Unfiltered Access to UAG Default Website Vulnerability."
17420| [CVE-2012-0146] Open redirect vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka "UAG Blind HTTP Redirect Vulnerability."
17421| [CVE-2012-0145] Cross-site scripting (XSS) vulnerability in wizardlist.aspx in Microsoft Office SharePoint Server 2010 Gold and SP1 and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in wizardlist.aspx Vulnerability."
17422| [CVE-2012-0144] Cross-site scripting (XSS) vulnerability in themeweb.aspx in Microsoft Office SharePoint Server 2010 Gold and SP1 and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in themeweb.aspx Vulnerability."
17423| [CVE-2012-0138] Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0019, CVE-2012-0020, CVE-2012-0136, and CVE-2012-0137.
17424| [CVE-2012-0137] Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0019, CVE-2012-0020, CVE-2012-0136, and CVE-2012-0138.
17425| [CVE-2012-0136] Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0019, CVE-2012-0020, CVE-2012-0137, and CVE-2012-0138.
17426| [CVE-2012-0020] Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0019, CVE-2012-0136, CVE-2012-0137, and CVE-2012-0138.
17427| [CVE-2012-0019] Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0020, CVE-2012-0136, CVE-2012-0137, and CVE-2012-0138.
17428| [CVE-2012-0018] Microsoft Visio Viewer 2010 Gold and SP1 does not properly validate attributes in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "VSD File Format Memory Corruption Vulnerability."
17429| [CVE-2012-0017] Cross-site scripting (XSS) vulnerability in inplview.aspx in Microsoft SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in inplview.aspx Vulnerability."
17430| [CVE-2011-4695] Unspecified vulnerability in Microsoft Windows 7 SP1, when Java is installed, allows local users to bypass Internet Explorer sandbox restrictions and gain privileges via unknown vectors, as demonstrated by the White Phosphorus wp_ie_sandbox_escape module for Immunity CANVAS. NOTE: as of 20111207, this disclosure has no actionable information. However, because the module author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.
17431| [CVE-2011-2012] Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 does not properly validate session cookies, which allows remote attackers to cause a denial of service (IIS outage) via unspecified network traffic, aka "Null Session Cookie Crash."
17432| [CVE-2011-2010] The Microsoft Office Input Method Editor (IME) for Simplified Chinese in Microsoft Pinyin IME 2010, Office Pinyin SimpleFast Style 2010, and Office Pinyin New Experience Style 2010 does not properly restrict access to configuration options, which allows local users to gain privileges via the Microsoft Pinyin (aka MSPY) IME toolbar, aka "Pinyin IME Elevation Vulnerability."
17433| [CVE-2011-1969] Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 provides the MicrosoftClient.jar file containing a signed Java applet, which allows remote attackers to execute arbitrary code on client machines via unspecified vectors, aka "Poisoned Cup of Code Execution Vulnerability."
17434| [CVE-2011-1897] Cross-site scripting (XSS) vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Default Reflected XSS Vulnerability."
17435| [CVE-2011-1896] Cross-site scripting (XSS) vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "ExcelTable Reflected XSS Vulnerability."
17436| [CVE-2011-1895] CRLF injection vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary HTTP headers, and conduct HTTP response splitting attacks and cross-site scripting (XSS) attacks, via unspecified vectors, aka "ExcelTable Response Splitting XSS Vulnerability."
17437| [CVE-2011-1891] Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in a request to a script, aka "Contact Details Reflected XSS Vulnerability."
17438| [CVE-2011-1890] Cross-site scripting (XSS) vulnerability in EditForm.aspx in Microsoft Office SharePoint Server 2010 and SharePoint Foundation 2010 allows remote attackers to inject arbitrary web script or HTML via a post, aka "Editform Script Injection Vulnerability."
17439| [CVE-2011-1889] The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute arbitrary code via vectors involving unspecified requests, aka "TMG Firewall Client Memory Corruption Vulnerability."
17440| [CVE-2011-1417] Integer overflow in QuickLook, as used in Apple Mac OS X before 10.6.7 and MobileSafari in Apple iOS before 4.2.7 and 4.3.x before 4.3.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a Microsoft Office document with a crafted size field in the OfficeArtMetafileHeader, related to OfficeArtBlip, as demonstrated on the iPhone by Charlie Miller and Dion Blazakis during a Pwn2Own competition at CanSecWest 2011.
17441| [CVE-2011-1347] Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to bypass Protected Mode and create arbitrary files by leveraging access to a Low integrity process, as demonstrated by Stephen Fewer as the third of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011.
17442| [CVE-2011-1346] Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors, as demonstrated by Stephen Fewer as the second of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011.
17443| [CVE-2011-1345] Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, as demonstrated by Stephen Fewer as the first of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011, aka "Object Management Memory Corruption Vulnerability."
17444| [CVE-2011-1265] The Bluetooth Stack 2.1 in Microsoft Windows Vista SP1 and SP2 and Windows 7 Gold and SP1 does not prevent access to objects in memory that (1) were not properly initialized or (2) have been deleted, which allows remote attackers to execute arbitrary code via crafted Bluetooth packets, aka "Bluetooth Stack Vulnerability."
17445| [CVE-2011-0653] Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2010 Gold and SP1, and SharePoint Foundation 2010, allows remote attackers to inject arbitrary web script or HTML via the URI, aka "XSS in SharePoint Calendar Vulnerability."
17446| [CVE-2011-0647] The irccd.exe service in EMC Replication Manager Client before 5.3 and NetWorker Module for Microsoft Applications 2.1.x and 2.2.x allows remote attackers to execute arbitrary commands via the RunProgram function to TCP port 6542.
17447| [CVE-2011-0627] Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content, as possibly exploited in the wild in May 2011 by a Microsoft Office document with an embedded .swf file.
17448| [CVE-2011-0037] Microsoft Malware Protection Engine before 1.1.6603.0, as used in Microsoft Malicious Software Removal Tool (MSRT), Windows Defender, Security Essentials, Forefront Client Security, Forefront Endpoint Protection 2010, and Windows Live OneCare, allows local users to gain privileges via a crafted value of an unspecified user registry key.
17449| [CVE-2011-0027] Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, does not properly validate memory allocation for internal data structures, which allows remote attackers to execute arbitrary code, possibly via a large CacheSize property that triggers an integer wrap and a buffer overflow, aka "ADO Record Memory Vulnerability." NOTE: this might be a duplicate of CVE-2010-1117 or CVE-2010-1118.
17450| [CVE-2011-0026] Integer signedness error in the SQLConnectW function in an ODBC API (odbc32.dll) in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, allows remote attackers to execute arbitrary code via a long string in the Data Source Name (DSN) and a crafted szDSN argument, which bypasses a signed comparison and leads to a buffer overflow, aka "DSN Overflow Vulnerability."
17451| [CVE-2010-4643] Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Truevision TGA (TARGA) file in an ODF or Microsoft Office document.
17452| [CVE-2010-4253] Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file in an ODF or Microsoft Office document, as demonstrated by a PowerPoint (aka PPT) document.
17453| [CVE-2010-4121] ** DISPUTED ** The TCP-to-ODBC gateway in IBM Tivoli Provisioning Manager for OS Deployment 7.1.1.3 does not require authentication for SQL statements, which allows remote attackers to modify, create, or read database records via a session on TCP port 2020. NOTE: the vendor disputes this issue, stating that the "default Microsoft Access database is not password protected because it is intended to be used for evaluation purposes only."
17454| [CVE-2010-3967] Untrusted search path vulnerability in Microsoft Windows Movie Maker (WMM) 2.6 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a Movie Maker (MSWMM) file, aka "Insecure Library Loading Vulnerability."
17455| [CVE-2010-3962] Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token sequences and the clip attribute, aka an "invalid flag reference" issue or "Uninitialized Memory Corruption Vulnerability," as exploited in the wild in November 2010.
17456| [CVE-2010-3936] Cross-site scripting (XSS) vulnerability in Signurl.asp in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "XSS in Signurl.asp Vulnerability."
17457| [CVE-2010-3889] Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the wild in July 2010 by the Stuxnet worm, and identified by Microsoft researchers and other researchers.
17458| [CVE-2010-3888] Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the wild in July 2010 by the Stuxnet worm, and identified by Kaspersky Lab researchers and other researchers.
17459| [CVE-2010-3497] Symantec Norton AntiVirus 2011 does not properly interact with the processing of hcp:// URLs by the Microsoft Help and Support Center, which makes it easier for remote attackers to execute arbitrary code via malware that is correctly detected by this product, but with a detection approach that occurs too late to stop the code execution. NOTE: the researcher indicates that a vendor response was received, stating that this issue "falls into the work of our Firewall and not our AV (per our methodology of layers of defense)."
17460| [CVE-2010-3454] Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted typography information in a Microsoft Word .DOC file that triggers an out-of-bounds write.
17461| [CVE-2010-3453] The WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle an unspecified number of list levels in user-defined list styles in WW8 data in a Microsoft Word document, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted .DOC file that triggers an out-of-bounds write.
17462| [CVE-2010-3141] Untrusted search path vulnerability in Microsoft PowerPoint 2010 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse pptimpconv.dll that is located in the same folder as a .odp, .pot, .potm, .potx, .ppa, .pps, .ppsm, .ppsx, .ppt, .pptm, .pptx, .pwz, .sldm, or .sldx file.
17463| [CVE-2010-2743] The kernel-mode drivers in Microsoft Windows XP SP3 do not properly perform indexing of a function-pointer table during the loading of keyboard layouts from disk, which allows local users to gain privileges via a crafted application, as demonstrated in the wild in July 2010 by the Stuxnet worm, aka "Win32k Keyboard Layout Vulnerability." NOTE: this might be a duplicate of CVE-2010-3888 or CVE-2010-3889.
17464| [CVE-2010-2734] Cross-site scripting (XSS) vulnerability in the mobile portal in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "XSS Issue on UAG Mobile Portal Website in Forefront Unified Access Gateway Vulnerability."
17465| [CVE-2010-2733] Cross-site scripting (XSS) vulnerability in the Web Monitor in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "UAG XSS Allows EOP Vulnerability."
17466| [CVE-2010-2732] Open redirect vulnerability in the web interface in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka "UAG Redirection Spoofing Vulnerability."
17467| [CVE-2010-2564] Buffer overflow in Microsoft Windows Movie Maker (WMM) 2.1, 2.6, and 6.0 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted project file, aka "Movie Maker Memory Corruption Vulnerability."
17468| [CVE-2010-1184] The Microsoft wireless keyboard uses XOR encryption with a key derived from the MAC address, which makes it easier for remote attackers to obtain keystroke information and inject arbitrary commands via a nearby wireless device, as demonstrated by Keykeriki 2.
17469| [CVE-2010-1118] Unspecified vulnerability in Internet Explorer 8 on Microsoft Windows 7 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to a use-after-free issue, as demonstrated by Peter Vreugdenhil during a Pwn2Own competition at CanSecWest 2010.
17470| [CVE-2010-1117] Heap-based buffer overflow in Internet Explorer 8 on Microsoft Windows 7 allows remote attackers to discover the base address of a Windows .dll file, and possibly have unspecified other impact, via unknown vectors, as demonstrated by Peter Vreugdenhil during a Pwn2Own competition at CanSecWest 2010.
17471| [CVE-2010-0806] Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object, as exploited in the wild in March 2010, aka "Uninitialized Memory Corruption Vulnerability."
17472| [CVE-2010-0716] _layouts/Upload.aspx in the Documents module in Microsoft SharePoint before 2010 uses URLs with the same hostname and port number for a web site's primary files and individual users' uploaded files (aka attachments), which allows remote authenticated users to leverage same-origin relationships and conduct cross-site scripting (XSS) attacks by uploading TXT files, a related issue to CVE-2008-5026. NOTE: the vendor disputes the significance of this issue, because cross-domain isolation can be implemented when needed.
17473| [CVE-2009-3555] The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.
17474| [CVE-2008-5750] Argument injection vulnerability in Microsoft Internet Explorer 8 beta 2 on Windows XP SP3 allows remote attackers to execute arbitrary commands via the --renderer-path option in a chromehtml: URI.
17475| [CVE-2008-5556] ** DISPUTED ** The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 does not recognize attack patterns designed to operate against web pages that are encoded with utf-7, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting crafted utf-7 content. NOTE: the vendor reportedly disputes this issue, stating "Behaviour is by design."
17476| [CVE-2008-5555] Microsoft Internet Explorer 8.0 Beta 2 relies on the XDomainRequestAllowed HTTP header to authorize data exchange between domains, which allows remote attackers to bypass the product's XSS Filter protection mechanism, and conduct XSS and cross-domain attacks, by injecting this header after a CRLF sequence, related to "XDomainRequest Allowed Injection (XAI)." NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
17477| [CVE-2008-5554] The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 does not properly handle some HTTP headers that appear after a CRLF sequence in a URI, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS or redirection attacks, as demonstrated by the (1) Location and (2) Set-Cookie HTTP headers. NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
17478| [CVE-2008-5553] The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 disables itself upon encountering a certain X-XSS-Protection HTTP header, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting this header after a CRLF sequence. NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
17479| [CVE-2008-5552] The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks via a CRLF sequence in conjunction with a crafted Content-Type header, as demonstrated by a header with a utf-7 charset value. NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
17480| [CVE-2008-5551] The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting data at two different positions within an HTML document, related to STYLE elements and the CSS expression property, aka a "double injection."
17481| [CVE-2008-5180] Microsoft Communicator, and Communicator in Microsoft Office 2010 beta, allows remote attackers to cause a denial of service (memory consumption) via a large number of SIP INVITE requests, which trigger the creation of many sessions.
17482| [CVE-2008-4211] Integer signedness error in (1) QuickLook in Apple Mac OS X 10.5.5 and (2) Office Viewer in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted Microsoft Excel file that triggers an out-of-bounds memory access, related to "handling of columns."
17483| [CVE-2007-5351] Unspecified vulnerability in Server Message Block Version 2 (SMBv2) signing support in Microsoft Windows Vista allows remote attackers to force signature re-computation and execute arbitrary code via a crafted SMBv2 packet, aka "SMBv2 Signing Vulnerability."
17484| [CVE-2007-2729] Comodo Firewall Pro 2.4.18.184 and Comodo Personal Firewall 2.3.6.81, and probably older Comodo Firewall versions, do not properly test for equivalence of process identifiers for certain Microsoft Windows API functions in the NT kernel 5.0 and greater, which allows local users to call these functions, and bypass firewall rules or gain privileges, via a modified identifier that is one, two, or three greater than the canonical identifier.
17485| [CVE-2007-1534] DFSR.exe in Windows Meeting Space in Microsoft Windows Vista remains available for remote connections on TCP port 5722 for 2 minutes after Windows Meeting Space is closed, which allows remote attackers to have an unknown impact by connecting to this port during the time window.
17486| [CVE-2007-0341] Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.1 and earlier, when Microsoft Internet Explorer 6 is used, allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in a CSS style in the convcharset parameter to the top-level URI, a different vulnerability than CVE-2005-0992.
17487| [CVE-2006-5559] The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the second argument is a BSTR, which allows remote attackers to cause a denial of service (Internet Explorer crash) and possibly execute arbitrary code via certain strings in the second and third arguments.
17488| [CVE-2006-4686] Buffer overflow in the Extensible Stylesheet Language Transformations (XSLT) processing in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 allows remote attackers to execute arbitrary code via a crafted Web page.
17489| [CVE-2006-4685] The XMLHTTP ActiveX control in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 does not properly handle HTTP server-side redirects, which allows remote user-assisted attackers to access content from other domains.
17490| [CVE-2006-1359] Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer.
17491| [CVE-2006-0761] Buffer overflow in BlackBerry Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server 2.2 and 4.0 before SP3 Hotfix 4 for IBM Lotus Domino, 3.6 before SP7 and 5.0 before SP3 Hotfix 3 for Microsoft Exchangem, and 4.0 for Novell GroupWise before SP3 Hotfix 1 might allow user-assisted remote attackers to execute arbitrary code on the server via a crafted Microsoft Word document that is opened on a wireless device.
17492| [CVE-2006-0753] Memory leak in Microsoft Internet Explorer 6 for Windows XP Service Pack 2 allows remote attackers to cause a denial of service (memory consumption) via JavaScript that uses setInterval to repeatedly call a function to set the value of window.status.
17493| [CVE-2006-0544] urlmon.dll in Microsoft Internet Explorer 7.0 beta 2 (aka 7.0.5296.0) allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a BGSOUND element with its SRC attribute set to "file://" followed by a large number of "-" (dash of hyphen) characters.
17494| [CVE-2006-0003] Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and distributed in Microsoft Data Access Components (MDAC) 2.7 and 2.8, allows remote attackers to execute arbitrary code via unknown attack vectors.
17495| [CVE-2005-1929] Multiple heap-based buffer overflows in (1) isaNVWRequest.dll and (2) relay.dll in Trend Micro ServerProtect Management Console 5.58 and earlier, as used in Control Manager 2.5 and 3.0 and Damage Cleanup Server 1.1, allow remote attackers to execute arbitrary code via "wrapped" length values in Chunked transfer requests. NOTE: the original report suggests that the relay.dll issue is related to a problem in which a Microsoft Foundation Classes (MFC) static library returns invalid values under heavy load. As such, this might not be a vulnerability in Trend Micro's product.
17496| [CVE-2005-0852] Microsoft Windows XP SP1 allows local users to cause a denial of service (system crash) via an empty datagram to a raw IP over IP socket (IP protocol 4), as originally demonstrated using code in Python 2.3.
17497| [CVE-2004-1322] Cisco Unity 2.x, 3.x, and 4.x, when integrated with Microsoft Exchange, has several hard coded usernames and passwords, which allows remote attackers to gain unauthorized access and change configuration settings or read outgoing or incoming e-mail messages.
17498| [CVE-2003-1306] Microsoft URLScan 2.5, with the RemoveServerHeader option enabled, allows remote attackers to obtain sensitive information (server name and version) via an HTTP request that generates certain errors such as 400 "Bad Request," which leak the Server header in the response.
17499| [CVE-2003-0903] Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request.
17500| [CVE-2003-0353] Buffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary code via a long response to a broadcast request to UDP port 1434.
17501| [CVE-2002-1918] Buffer overflow in Microsoft Active Data Objects (ADO) in Microsoft MDAC 2.5 through 2.7 allows remote attackers to have unknown impact with unknown attack vectors. NOTE: due to the lack of details available regarding this issue, perhaps it should be REJECTED.
17502| [CVE-2002-1142] Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.
17503| [CVE-2002-1015] RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to execute arbitrary script in the Local computer zone by inserting the script into the skin.ini file of an RJS archive, then referencing skin.ini from a web page after it has been extracted, which is parsed as HTML by Internet Explorer or other Microsoft-based web readers.
17504| [CVE-2002-0697] Microsoft Metadirectory Services (MMS) 2.2 allows remote attackers to bypass authentication and modify sensitive data by using an LDAP client to directly connect to MMS and bypass the checks for MMS credentials.
17505| [CVE-2002-0057] XMLHTTP control in Microsoft XML Core Services 2.6 and later does not properly handle IE Security Zone settings, which allows remote attackers to read arbitrary files by specifying a local file as an XML Data Source.
17506| [CVE-2001-1218] Microsoft Internet Explorer for Unix 5.0SP1 allows local users to possibly cause a denial of service (crash) in CDE or the X server on Solaris 2.6 by rapidly scrolling Chinese characters or maximizing the window.
17507| [CVE-2000-0563] The URLConnection function in MacOS Runtime Java (MRJ) 2.1 and earlier and the Microsoft virtual machine (VM) for MacOS allows a malicious web site operator to connect to arbitrary hosts using a HTTP redirection, in violation of the Java security model.
17508| [CVE-1999-1097] Microsoft NetMeeting 2.1 allows one client to read the contents of another client's clipboard via a CTRL-C in the chat box when the box is empty.
17509|
17510| SecurityFocus - https://www.securityfocus.com/bid/:
17511| [83154] Microsoft Windows 2000 Server CVE-2004-0540 Remote Security Vulnerability
17512| [45297] Microsoft Exchange Server 2007 Infinite Loop Remote Denial of Service Vulnerability
17513| [43419] Microsoft Excel 2002 Memory Corruption Vulnerability
17514| [43189] Microsoft Visual C++ 2008 Redistributable Package DLL Loading Arbitrary Code Execution Vulnerability
17515| [42742] Microsoft PowerPoint 2007 Multiple DLL Loading Arbitrary Code Execution Vulnerability
17516| [42695] Microsoft Groove 2007 'mso.dll' DLL Loading Arbitrary Code Execution Vulnerability
17517| [42681] Microsoft Visio 2003 'mfc71enu.dll' DLL Loading Arbitrary Code Execution Vulnerability
17518| [41843] Microsoft Outlook Web Access for Exchange Server 2003 Cross Site Request Forgery Vulnerability
17519| [39776] Microsoft SharePoint Server 2007 '_layouts/help.aspx' Cross Site Scripting Vulnerability
17520| [37196] RETIRED: Microsoft December 2009 Advance Notification Multiple Vulnerabilities
17521| [36940] RETIRED: Microsoft November 2009 Advance Notification Multiple Vulnerabilities
17522| [36633] RETIRED: Microsoft October 2009 Advance Notification Multiple Vulnerabilities
17523| [36239] RETIRED: Microsoft September 2009 Advance Notification Multiple Vulnerabilities
17524| [35974] RETIRED: Microsoft August 2009 Advance Notification Multiple Vulnerabilities
17525| [35617] RETIRED: Microsoft July 2009 Advance Notification Multiple Vulnerabilities
17526| [35213] RETIRED: Microsoft June 2009 Advance Notification Multiple Vulnerabilities
17527| [34867] RETIRED: Microsoft May 2009 Advance Notification Multiple Vulnerabilities
17528| [34532] Microsoft IAG 2007 ActiveX Control Multiple Stack Based Buffer Overflow Vulnerabilities
17529| [34469] Microsoft Word 2000 WordPerfect Converter Remote Code Execution Vulnerability
17530| [34450] RETIRED: Microsoft April 2009 Advance Notification Multiple Vulnerabilities
17531| [34005] RETIRED: Microsoft March 2009 Advance Notification Multiple Vulnerabilities
17532| [33639] RETIRED: Microsoft February 2009 Advance Notification Multiple Vulnerabilities
17533| [33170] RETIRED: Microsoft January 2009 Advance Notification Multiple Vulnerabilities
17534| [32632] RETIRED: Microsoft December 2008 Advance Notification Multiple Vulnerabilities
17535| [32153] Retired: Microsoft November 2008 Advance Notification Multiple Vulnerabilities
17536| [31667] Retired: Microsoft October 2008 Advance Notification Multiple Vulnerabilities
17537| [31129] RETIRED: Microsoft SQL Server 2000 'sqlvdir.dll' ActiveX Buffer Overflow Vulnerability
17538| [31014] RETIRED: Microsoft September 2008 Advance Notification Multiple Vulnerabilities
17539| [30593] RETIRED: Microsoft August 2008 Advance Notification Multiple Vulnerabilities
17540| [30075] RETIRED: Microsoft July 2008 Advance Notification Multiple Vulnerabilities
17541| [29576] RETIRED: Microsoft June 2008 Advance Notification Multiple Vulnerabilities
17542| [29108] RETIRED: Microsoft May 2008 Advance Notification Multiple Vulnerabilities
17543| [28598] RETIRED: Microsoft April 2008 Advance Notification Multiple Vulnerabilities
17544| [28124] Retired: Microsoft March 2008 Advance Notification Multiple Vulnerabilities
17545| [27674] RETIRED: Microsoft February 2008 Advance Notification Multiple Vulnerabilities
17546| [27119] RETIRED: Microsoft January 2008 Advance Notification Multiple Vulnerabilities
17547| [26739] RETIRED: Microsoft December 2007 Advance Notification Multiple Vulnerabilities
17548| [26414] Microsoft Forms 2.0 ActiveX Control Memory Access Violation Denial of Service Vulnerabilities
17549| [26380] Retired: Microsoft November 2007 Advance Notification Multiple Vulnerabilities
17550| [25991] RETIRED: Microsoft Office 2000 and XP Unspecified Word Document Handling DoS Vulnerability
17551| [25922] RETIRED: Microsoft October 2007 Advance Notification Multiple Vulnerabilities
17552| [25573] RETIRED: Microsoft September 2007 Advance Notification Multiple Vulnerabilities
17553| [25247] Retired: Microsoft August 2007 Advance Notification Multiple Vulnerabilities
17554| [24771] Retired: Microsoft July 2007 Advance Notification Multiple Vulnerabilities
17555| [24366] RETIRED: Microsoft June 2007 Advance Notification Multiple Vulnerabilities
17556| [24118] Microsoft Office 2000 UA OUACTRL.OCX ActiveX Control Buffer Overflow Vulnerability
17557| [23800] RETIRED: Microsoft May 2007 Advance Notification Multiple Vulnerabilities
17558| [23380] Microsoft Word 2007 WWLib.DLL Unspecified Document File Buffer Overflow Vulnerability
17559| [23335] RETIRED: Microsoft April 2007 Advance Notification Multiple Vulnerabilities
17560| [22716] Microsoft Office 2003 Denial of Service Vulnerability
17561| [22567] Microsoft Word 2000/2002 Document Stream Remote Code Execution Vulnerability
17562| [22328] RETIRED: Microsoft Word 2003 Unspecified Code Execution Vulnerability
17563| [22225] Microsoft Word 2000 Malformed Function Code Execution Vulnerability
17564| [21611] Microsoft Project Server 2003 PDSRequest.ASP XML Request Information Disclosure Vulnerability
17565| [21495] Microsoft Windows 2000 Remote Installation Service Remote Code Execution Vulnerability
17566| [20843] Microsoft Visual Studio 2005 WMI Object Broker Remote Code Execution Vulnerability
17567| [19636] Microsoft Windows 2000 Multiple COM Object Instantiation Code Execution Vulnerabilities
17568| [19388] Microsoft Windows 2000 Kernel Local Privilege Escalation Vulnerability
17569| [17134] Microsoft Commerce Server 2002 Authentication Bypass Vulnerability
17570| [16634] Microsoft PowerPoint 2000 Remote Information Disclosure Vulnerability
17571| [14772] Microsoft Exchange Server 2003 Exchange Information Store Denial Of Service Vulnerability
17572| [14093] Microsoft Update Rollup 1 for Windows 2000 SP4 Released - Multiple Vulnerabilities Fixed
17573| [13564] Microsoft SQL Server 2000 Multiple Vulnerabilities
17574| [13008] Microsoft Windows Server 2003 SMB Redirector Local Denial Of Service Vulnerability
17575| [12972] Microsoft Windows Server 2003 Service Pack 1 Released - Multiple Vulnerabilities Fixed
17576| [12913] Microsoft Outlook 2002 Connector For IBM Lotus Domino Policy Bypass Vulnerability
17577| [12824] Microsoft InfoPath 2003 Insecure Information Storage Vulnerability
17578| [12641] Microsoft Windows 2000 Group Policy Bypass Vulnerability
17579| [12141] Microsoft FrontPage 2000 Internet Publishing Service Provider DAV File Upload Vulnerability
17580| [11820] Microsoft Windows 2000 Resource Kit W3Who.DLL Multiple Remote Vulnerabilities
17581| [11446] Microsoft Outlook 2003 Security Policy Bypass Vulnerability
17582| [11387] Microsoft Windows 2003 Services Default SACL Access Right Weakness
17583| [10901] Microsoft Windows 2000/XP CRL File Failed Integrity Check Denial Of Service Vulnerability
17584| [10693] Microsoft Windows 2000 Media Player Control Media Preview Script Execution Vulnerability
17585| [10484] Microsoft ISA Server 2000 FTP Bounce Filtering Vulnerability
17586| [10480] Microsoft ISA Server 2000 Site And Content Rule Bypass Vulnerability
17587| [10440] Microsoft Windows 2000 Domain Expired Account Security Policy Violation Weakness
17588| [10369] Microsoft Outlook 2003 Media File Script Execution Vulnerability
17589| [10307] Microsoft Outlook 2003 Predictable File Location Weakness
17590| [10114] Microsoft Windows 2000 Domain Controller LDAP Denial Of Service Vulnerability
17591| [9409] Microsoft Exchange Server 2003 Outlook Web Access Random Mailbox Access Vulnerability
17592| [9408] Microsoft ISA Server 2000 H.323 Filter Remote Buffer Overflow Vulnerability
17593| [9118] Microsoft Exchange Server 2003 Outlook Web Access Lowered Security Settings Weakness
17594| [8833] Microsoft Windows 2000 TroubleShooter ActiveX Control Buffer Overflow Vulnerability
17595| [8522] Multiple Microsoft Windows 2003 Stack Protection Implementation Weaknesses
17596| [8397] Microsoft Windows 2000 Subnet Bandwidth Manager RSVP Server Authority Hijacking Vulnerability
17597| [8104] Microsoft Windows 2000 Unauthorized RPC Connection Weakness
17598| [8098] Microsoft Windows 2000 Terminal Services Named Pipe System Account Access Vulnerability
17599| [8093] Microsoft Windows 2000 Active Directory Forest Origin Validation Vulnerability
17600| [8090] Microsoft Windows 2000 ShellExecute() Buffer Overflow Vulnerability
17601| [8089] Microsoft Windows 2000 Unspecified Cryptnet.DLL Memory Leakage Vulnerability
17602| [8086] Microsoft Windows 2000 Port Name Buffers Potential Buffer Overflow Vulnerability
17603| [8085] Microsoft Windows 2000 ModifyDN Request Denial of Service Vulnerability
17604| [8083] Microsoft Windows 2000 Domain Controller Spoofing Vulnerability
17605| [8081] Microsoft Windows 2000 USBH_IoctlGetNodeConnectionDriverKeyName Information Disclosure Vulnerability
17606| [8063] Microsoft Commerce Server 2002 Weak Registry Key Permissions Weakness
17607| [8045] Microsoft Windows 2000 SP4 Released - Multiple Vulnerabilities Fixed
17608| [7930] Microsoft Windows 2000 Active Directory Remote Stack Overflow Vulnerability
17609| [7788] Microsoft Windows 2000/XP/2003 IPV6 ICMP Flood Denial Of Service Vulnerability
17610| [7469] Microsoft BizTalk Server 2002 HTTP Receiver Buffer Overflow Vulnerability
17611| [7360] Microsoft Windows 2000/XP Registry Editor Custom Permissions Weakness
17612| [7102] Microsoft Windows 2000 Help Facility .CNT File :Link Buffer Overflow Vulnerability
17613| [6769] Microsoft Windows 2000 RPC Service Privilege Escalation Vulnerability
17614| [6766] Microsoft Windows 2000 NetBIOS Continuation Packets Kernel Memory Leak Vulnerability
17615| [6667] Microsoft Outlook 2002 V1 Exchange Server Security Certificate Information Leakage Vulnerability
17616| [6319] Microsoft Outlook 2002 Email Header Processing Denial of Service Vulnerability
17617| [6030] Microsoft Windows 2000 SNMP Printer Query Denial of Service Vulnerability
17618| [5972] Microsoft Windows 2000/XP Full Event Log Administrative Alert Weakness
17619| [5922] Microsoft Content Management Server 2001 Cross-Site Scripting Vulnerability
17620| [5480] Microsoft Windows 2000 Network Connection Manager Privilege Elevation Vulnerability
17621| [5422] Microsoft Content Management Server 2001 SQL Injection Vulnerability
17622| [5421] Microsoft Content Management Server 2001 Arbitrary Upload Location Vulnerability
17623| [5420] Microsoft Content Management Server 2001 User Authentication Buffer Overflow Vulnerability
17624| [5415] Microsoft Windows 2000 Insecure Default File Permissions Vulnerability
17625| [5413] Microsoft Exchange 2000 Post Authorization License Exhaustion Denial Of Service Vulnerability
17626| [5412] Microsoft Exchange 2000 Multiple MSRPC Denial Of Service Vulnerabilities
17627| [5312] Microsoft SQL Server 2000 Resolution Service Denial of Service Vulnerability
17628| [5311] Microsoft SQL Server 2000 Resolution Service Stack Overflow Vulnerability
17629| [5310] Microsoft SQL Server 2000 Resolution Service Heap Overflow Vulnerability
17630| [5309] Microsoft SQL Server 2000 sp_MScopyscript SQL Injection Vulnerability
17631| [5307] Microsoft SQL Server 2000 Database Consistency Checkers Buffer Overflow Vulnerability
17632| [5253] Microsoft Windows 2000 Narrator Password Disclosure Vulnerability
17633| [5205] Microsoft SQL Server 2000 Incorrect Registry Key Permissions Vulnerability
17634| [5111] Microsoft Commerce Server 2000 OWC Package Installer Local Command Execution Vulnerability
17635| [5014] Microsoft SQL Server 2000 Password Encrypt Procedure Buffer Overflow Vulnerability
17636| [4881] Microsoft Exchange 2000 Malformed Mail Attribute DoS Vulnerability
17637| [4853] Microsoft Commerce Server 2000 Profile Service Buffer Overflow Vulnerability
17638| [4852] Microsoft Windows 2000 Remote Access Service Buffer Overflow Vulnerability
17639| [4847] Microsoft SQL Server 2000 Bulk Insert Procedure Buffer Overflow Vulnerability
17640| [4797] Microsoft MSDE/SQL Server 2000 Desktop Engine Default Configuration Vulnerability
17641| [4683] Microsoft Windows 2000 / NT Path Precedence Vulnerability
17642| [4532] Microsoft Windows 2000 Lanman Denial of Service Vulnerability
17643| [4438] Microsoft Windows 2000 Group Policy Evasion Vulnerability
17644| [4426] Microsoft Windows 2000 / NT / XP MUP UNC Request Buffer Overflow Vulnerability
17645| [4287] Microsoft Windows 2000 / NT 4.0 Process Handle Local Privilege Elevation Vulnerability
17646| [4256] Microsoft Windows 2000 Password Policy Bypass Vulnerability
17647| [4157] Microsoft Commerce Server 2000 ISAPI Buffer Overflow Vulnerability
17648| [4095] Microsoft Windows 2000 Server Terminal Services Failure To Lock Terminal Vulnerability
17649| [3652] Microsoft Windows 2000 Internet Key Exchange DoS Vulnerability
17650| [3481] Microsoft Windows 2000/XP GDI Denial of Service Vulnerability
17651| [3479] Microsoft Windows 2000 NTFS With Macintosh Client Directory Permission Vulnerability
17652| [3445] Microsoft Windows 2000/NT Terminal Server Service RDP DoS Vulnerability
17653| [3339] Microsoft Index Server 2.0 File Information and Path Disclosure Vulnerability
17654| [3305] Norton AntiVirus for Microsoft Exchange 2000 Information Disclosure Vulnerability
17655| [3291] Microsoft Windows 2000 RunAs Service Denial of Services Vulnerability
17656| [3215] Microsoft Windows 2000 IrDA Buffer Overflow Denial of Service Vulnerability
17657| [3185] Microsoft Windows 2000 RunAs Service Named Pipe Hijacking Vulnerability
17658| [3184] Microsoft Windows 2000 RunAs User Credentials Exposure Vulnerability
17659| [3146] Microsoft Windows 2000 System File Replacement Vulnerability
17660| [3115] Microsoft Windows NT and 2000 Command Prompt Reboot Vulnerability
17661| [3063] Microsoft Windows 2000 Unauthorized Password Change Vulnerability
17662| [3033] Microsoft Windows 2000 Task Manager Process Termination Vulnerability
17663| [2988] Microsoft Windows 2000 SMTP Improper Authentication Vulnerability
17664| [2929] Microsoft Windows 2000 LDAP SSL Password Modification Vulnerability
17665| [2849] Microsoft Windows 2000 Telnet Privilege Escalation Vulnerability
17666| [2846] Microsoft Windows 2000 Telnet System Call DoS Vulnerability
17667| [2844] Microsoft Windows 2000 Telnet Service DoS Vulnerability
17668| [2843] Microsoft Windows 2000 Telnet Multiple Sessions DoS Vulnerability
17669| [2838] Microsoft Windows 2000 Telnet Username DoS Vulnerability
17670| [2460] Microsoft Windows 2000 Event Viewer Buffer Overflow Vulnerability
17671| [2441] Microsoft Exchange 2000 / IIS 5.0 Multiple Invalid URL Request DoS Vulnerability
17672| [2394] Microsoft Windows 2000 Domain Controller DoS Vulnerability
17673| [2341] Microsoft Windows 2000 Network DDE Escalated Privileges Vulnerability
17674| [2326] Microsoft Windows 2000 RDP DoS Vulnerability
17675| [2133] Microsoft Windows 2000 Directory Services Restore Mode Blank Password Vulnerability
17676| [2066] Microsoft Windows NT 4.0 / 2000 SNMP Registry Key Modification Vulnerability
17677| [2018] Microsoft Windows 2000 Telnet Session Timeout DoS Vulnerability
17678| [2007] Microsoft Windows 2000 DNS Memory Leak Vulnerability
17679| [1973] Microsoft Windows 2000 Domain Account Lockout Bypass Vulnerability
17680| [1958] Microsoft Exchange 2000 Server EUSR_EXSTOREEVENT Account Vulnerability
17681| [1933] Microsoft Indexing Services for Windows 2000 File Verification Vulnerability
17682| [1899] Microsoft Windows 2000 ActiveX Control Buffer Overflow Vulnerability
17683| [1811] Microsoft Site Server 2.0 with IIS 4.0 Malicious File Upload Vulnerability
17684| [1758] Microsoft Windows 2000 Unattended Install OEMPreinstall Vulnerability
17685| [1753] Microsoft Windows NT 4.0 / 2000 Spoofed LPC Request Vulnerability
17686| [1748] Microsoft Windows NT 4.0 / 2000 Predictable LPC Message Identifier Multiple Vulnerabilities
17687| [1745] Microsoft Windows NT 4.0 / 2000 LPC Zone Memory Depletion DoS Vulnerability
17688| [1729] Microsoft Windows 2000 Simplified Chinese IME Vulnerability
17689| [1695] Microsoft Proxy 2.0 FTP Permissions Bypass Vulnerability
17690| [1692] Microsoft Proxy 2.0 Internal Network Access Vulnerability
17691| [1683] Microsoft Windows 2000 telnet.exe NTLM Authentication Vulnerability
17692| [1673] Microsoft Windows 2000 Malformed RPC Packet DoS Vulnerability
17693| [1651] Microsoft Windows 2000 Still Image Service Privilege Escalation Vulnerability
17694| [1632] Microsoft Windows 98 / NT 4.0 / 2000 File Extension Validation Vulnerability
17695| [1620] Microsoft Windows 9x / NT 4.0 / 2000 NetBIOS Cache Corruption Vulnerability
17696| [1613] Microsoft Windows 2000 Local Security Policy Corruption Vulnerability
17697| [1566] Microsoft Word 97 / 2000 Mail Merge Code Execution Vulnerability
17698| [1561] Microsoft Word / Excel / Powerpoint 2000 Object Tag Buffer Overflow Vulnerability
17699| [1535] Microsoft Windows 2000 Named Pipes Predictability Vulnerability
17700| [1507] Microsoft Windows NT 4.0 / 2000 Unspecified Executable Path Vulnerability
17701| [1451] Microsoft Excel 97 / 2000 Register.ID Vulnerability
17702| [1435] Microsoft FrontPage 2000 Server Extensions Denial Of Service Vulnerability
17703| [1415] Microsoft Windows 2000 Remote CPU-overload Vulnerability
17704| [1414] Microsoft Windows 2000 Telnet Server DoS Vulnerability
17705| [1399] Microsoft Internet Explorer 5.01 and Excel/Powerpoint 2000 ActiveX Object Execution Vulnerability
17706| [1398] Microsoft Internet Explorer 5.01 and Access 2000 / 97 VBA Code Execution Vulnerability
17707| [1350] Microsoft Windows 2000 Windows Station Access Vulnerability
17708| [1304] Microsoft Windows NT 4.0 / 2000 SMB Write Request DoS Vulnerability
17709| [1301] Microsoft Windows NT 4.0 / 2000 Ignored SMB Response DoS Vulnerability
17710| [1295] Microsoft Windows 2000 Default 40-bit Encrypted Protected Store Vulnerability
17711| [1198] Microsoft Windows 2000 Default SYSKEY Configuration Vulnerability
17712| [1197] Microsoft Office 2000 UA Control Vulnerability
17713| [990] Microsoft Windows 2000 Install Unprotected ADMIN$ Share Vulnerability
17714| [945] Microsoft SMS 2.0 Default Permissions Vulnerability
17715| [539] Microsoft Windows 2000 EFS Vulnerability
17716| [180] Microsoft Windows April Fools 2001 Vulnerability
17717| [71487] Microsoft December 2014 Advance Notification Multiple Vulnerabilities
17718| [70966] RETIRED: Microsoft November 2014 Advance Notification Multiple Vulnerabilities
17719| [70367] RETIRED: Microsoft October 2014 Advance Notification Multiple Vulnerabilities
17720| [69636] RETIRED: Microsoft September 2014 Advance Notification Multiple Vulnerabilities
17721| [69108] Microsoft August 2014 Advance Notification Multiple Vulnerabilities
17722| [68367] Microsoft July 2014 Advance Notification Multiple Vulnerabilities
17723| [67905] Microsoft June 2014 Advance Notification Multiple Vulnerabilities
17724| [67298] Microsoft May 2014 Advance Notification Multiple Vulnerabilities
17725| [66639] RETIRED: Microsoft April 2014 Advance Notification Multiple Vulnerabilities
17726| [66016] Microsoft March 2014 Notification Multiple Vulnerabilities
17727| [65426] Microsoft February 2014 Notification Multiple Vulnerabilities
17728| [64757] RETIRED: Microsoft January 2014 Advance Notification Multiple Vulnerabilities
17729| [64083] RETIRED: Microsoft December 2013 Advance Notification Multiple Vulnerabilities
17730| [63604] RETIRED: Microsoft November 2013 Advance Notification Multiple Vulnerabilities
17731| [62797] RETIRED: Microsoft October 2013 Advance Notification Multiple Vulnerabilities
17732| [62228] RETIRED: Microsoft September 2013 Advance Notification Multiple Vulnerabilities
17733| [62181] Microsoft Office Pinyin IME 2010 CVE-2013-3859 Local Privilege Escalation Vulnerability
17734| [61686] Microsoft August 2013 Advance Notification Multiple Vulnerabilities
17735| [60960] RETIRED: Microsoft July 2013 Advance Notification Multiple Vulnerabilities
17736| [60394] Microsoft June 2013 Advance Notification Multiple Vulnerabilities
17737| [59785] RETIRED: Microsoft May 2013 Advance Notification Multiple Vulnerabilities
17738| [58881] RETIRED: Microsoft April 2013 Advance Notification Multiple Vulnerabilities
17739| [58380] RETIRED: Microsoft March 2013 Advance Notification Multiple Vulnerabilities
17740| [57846] RETIRED: Microsoft February 2013 Advance Notification Multiple Vulnerabilities
17741| [57137] RETIRED: Microsoft January 2013 Advance Notification Multiple Vulnerabilities
17742| [56838] RETIRED: Microsoft December 2012 Advance Notification Multiple Vulnerabilities
17743| [56450] RETIRED: Microsoft November 2012 Advance Notification Multiple Vulnerabilities
17744| [56304] Microsoft Office Excel 2010 Memory Corruption Denial of Service Vulnerability
17745| [55794] RETIRED: Microsoft October 2012 Advance Notification Multiple Vulnerabilities
17746| [55472] RETIRED: Microsoft September 2012 Advance Notification Multiple Vulnerabilities
17747| [54944] RETIRED: Microsoft August 2012 Advance Notification Multiple Vulnerabilities
17748| [54318] RETIRED: Microsoft July 2012 Advance Notification Multiple Vulnerabilities
17749| [53862] RETIRED: Microsoft June 2012 Advance Notification Multiple Vulnerabilities
17750| [53372] RETIRED: Microsoft May 2012 Advance Notification Multiple Vulnerabilities
17751| [52910] RETIRED: Microsoft April 2012 Advance Notification Multiple Vulnerabilities
17752| [52366] RETIRED: Microsoft March 2012 Advance Notification Multiple Vulnerabilities
17753| [51944] RETIRED: Microsoft February 2012 Advance Notification Multiple Vulnerabilities
17754| [51289] RETIRED: Microsoft January 2012 Advance Notification Multiple Vulnerabilities
17755| [50980] RETIRED: Microsoft December 2011 Advance Notification Multiple Vulnerabilities
17756| [50513] RETIRED: Microsoft November 2011 Advance Notification Multiple Vulnerabilities
17757| [49994] RETIRED: Microsoft October 2011 Advance Notification Multiple Vulnerabilities
17758| [49515] RETIRED: Microsoft September 2011 Advance Notification Multiple Vulnerabilities
17759| [49017] RETIRED: Microsoft August 2011 Advance Notification Multiple Vulnerabilities
17760| [48616] RETIRED: Microsoft July 2011 Advance Notification Multiple Vulnerabilities
17761| [48235] Microsoft Lync Server 2010 'ReachJoin.aspx' Remote Command Injection Vulnerability
17762| [48193] RETIRED: Microsoft June 2011 Advance Notification Multiple Vulnerabilities
17763| [47725] RETIRED: Microsoft May 2011 Advance Notification Multiple Vulnerabilities
17764| [47255] RETIRED: Microsoft April 2011 Advance Notification Multiple Vulnerabilities
17765| [46675] RETIRED: Microsoft March 2011 Advance Notification Multiple Vulnerabilities
17766| [46132] RETIRED: Microsoft February 2011 Advance Notification Multiple Vulnerabilities
17767| [45696] RETIRED: Microsoft January 2011 Advance Notification Multiple Vulnerabilities
17768| [45307] RETIRED: Microsoft December 2010 Advance Notification Multiple Vulnerabilities
17769| [44649] RETIRED: Microsoft November 2010 Advance Notification Multiple Vulnerabilities
17770| [43831] RETIRED: Microsoft October 2010 Advance Notification Multiple Vulnerabilities
17771| [43115] RETIRED: Microsoft September 2010 Advance Notification Multiple Vulnerabilities
17772| [42234] RETIRED: Microsoft August 2010 Advance Notification Multiple Vulnerabilities
17773| [41474] RETIRED: Microsoft July 2010 Advance Notification Multiple Vulnerabilities
17774| [40548] RETIRED: Microsoft June 2010 Advance Notification Multiple Vulnerabilities
17775| [39961] RETIRED: Microsoft May 2010 Advance Notification Multiple Vulnerabilities
17776| [39313] RETIRED: Microsoft April 2010 Advance Notification Multiple Vulnerabilities
17777| [38540] RETIRED: Microsoft March 2010 Advance Notification Multiple Vulnerabilities
17778| [38096] RETIRED: Microsoft February 2010 Advance Notification Multiple Vulnerabilities
17779| [37887] RETIRED: Microsoft January 2010 Advance Notification Multiple Vulnerabilities
17780| [37664] RETIRED: Microsoft January 2010 Advance Notification Multiple Vulnerabilities
17781| [32642] Microsoft Word RTF Malformed Control Word Variant 2 Remote Code Execution Vulnerability
17782|
17783| IBM X-Force - https://exchange.xforce.ibmcloud.com:
17784| [82417] Microsoft Windows Knowledge Base Article 2801261 update is not installed
17785| [82415] Microsoft Windows Knowledge Base Article 2807986 update is not installed
17786| [82410] Microsoft Windows Knowledge Base Article 2809289 update is not installed
17787| [81859] Microsoft Windows Knowledge Base Article 2802968 update is not installed
17788| [81857] Microsoft Windows Knowledge Base Article 2809279 update is not installed
17789| [81668] Microsoft Windows Knowledge Base Article 2800277 update is not installed
17790| [77323] Microsoft Windows Knowledge Base Article 2706045 update is not installed
17791| [75949] Microsoft Windows Knowledge Base Article 2707960 update is not installed
17792| [75942] Microsoft Windows Knowledge Base Article 2706726 update is not installed
17793| [75934] Microsoft Windows Knowledge Base Article 2709162 update is not installed
17794| [75926] Microsoft Windows Knowledge Base Article 2709100 update is not installed
17795| [75905] Microsoft Windows Knowledge Base Article 2707956 update is not installed
17796| [71991] Microsoft Windows Knowledge Base Article 2607664 update is not installed
17797| [71542] Microsoft Windows Knowledge Base Article 2607702 update is not installed
17798| [70945] Microsoft Windows Knowledge Base Article 2603381 update is not installed
17799| [70150] Microsoft Windows Knowledge Base Article 2607670 update is not installed
17800| [67755] Microsoft Windows Knowledge Base Article 2503665 update is not installed
17801| [67749] Microsoft Windows Knowledge Base Article 2507938 update is not installed
17802| [66845] Microsoft Windows Knowledge Base Article 2506014 update is not installed
17803| [66844] Microsoft Windows Knowledge Base Article 2501584 update is not installed
17804| [66448] Microsoft Windows Knowledge Base Article 2508272 update is not installed
17805| [66442] Microsoft Windows Knowledge Base Article 2509553 update is not installed
17806| [66440] Microsoft Windows Knowledge Base Article 2508429 update is not installed
17807| [66438] Microsoft Windows Knowledge Base Article 2507618 update is not installed
17808| [66430] Microsoft Windows Knowledge Base Article 2503658 update is not installed
17809| [66425] Microsoft Windows Knowledge Base Article 2506223 update is not installed
17810| [65570] Microsoft Windows Knowledge Base Article 2500212 update is not installed
17811| [65568] Microsoft Windows Knowledge Base Article 2508062 update is not installed
17812| [63840] Microsoft Visual C++ 2008 Redistributable Package dynamic-linked library (DLL) code execution
17813| [63780] Microsoft PowerPoint 2007 dynamic-linked library (rpawinet.dll) code execution
17814| [63775] Microsoft Visio 2003 dynamic-linked library (mfc71enu.dll) code execution
17815| [63586] Microsoft Windows Knowledge Base Article 2207559 update is not installed
17816| [63573] Microsoft Windows Knowledge Base Article 2407132 update is not installed
17817| [62797] Microsoft Windows Knowledge Base Article 2305420 update is not installed
17818| [62149] Microsoft Windows Knowledge Base Article 2207566 update is not installed
17819| [62133] Microsoft Windows Knowledge Base Article 2405882 update is not installed
17820| [53980] Microsoft Windows 2000 License Logging Server buffer overflow
17821| [53601] Microsoft Office 2008 for Mac user ID 502 security bypass
17822| [50973] Microsoft Windows Server 2003 and Vista win32k.sys denial of service
17823| [50759] Microsoft Windows 2000 Active Directory LDAP code execution
17824| [48595] Microsoft Word 2007 Email as PDF information disclosure
17825| [46102] Microsoft Windows 2003 SP2 is not installed on the system
17826| [46101] Microsoft Windows 2003 SP1 is not installed on the system
17827| [45186] Microsoft SQL Server 2000 SQLVDIRLib.SQLVDirControl ActiveX control buffer overflow
17828| [37200] Microsoft SQL Server 2000 Service Pack 1 update is not installed
17829| [37198] Microsoft SQL Server 2000 Service Pack 3 update is not installed
17830| [34634] Microsoft Windows Server 2003 Active Directory information disclosure
17831| [34599] Microsoft Windows Server 2003 terminal server security bypass
17832| [34473] Microsoft Office 2000 ActiveX control buffer overflow
17833| [33713] Microsoft Word 2007 multiple unspecified denial of service
17834| [33712] Microsoft Word 2007 wwlib.dll buffer overflow
17835| [32631] Microsoft SQL Server 2000 Service Pack 2 update is not installed
17836| [31821] Microsoft Windows time zone update for year 2007
17837| [31196] Microsoft Office 2003 Brazilian Grammar Checker buffer overflow
17838| [30905] Microsoft Project Server 2003 pdsrequest.asp information disclosure
17839| [29546] Microsoft Windows 2000/2003 user logoff initiated
17840| [29545] Microsoft Windows 2000/2003 system time changed
17841| [29544] Microsoft Windows 2000/2003 system security access removed
17842| [29543] Microsoft Windows 2000/2003 security access granted
17843| [29542] Microsoft Windows 2000/2003 SAM notification package loaded
17844| [29541] Microsoft Windows 2000/2003 primary security token issued
17845| [29540] Microsoft Windows 2000/2003 user password reset successful
17846| [29539] Microsoft Windows 2000/2003 object indirectly accessed
17847| [29538] Microsoft Windows 2000/2003 object handle duplicated
17848| [29537] Microsoft Windows 2000/2003 logon with explicit credentials success
17849| [29536] Microsoft Windows 2000/2003 logon attempt using explicit credentials unsuccessful
17850| [29535] Microsoft Windows 2000/2003 IPSEC policy agent failed
17851| [29534] Microsoft Windows 2000/2003 IPSEC policy agent disabled
17852| [29533] Microsoft Windows 2000/2003 IPSEC policy agent changed
17853| [29532] Microsoft Windows 2000/2003 IKE security association established
17854| [29531] Microsoft Windows 2000/2003 IKE quick mode association ended
17855| [29530] Microsoft Windows 2000/2003 IKE main mode association ended
17856| [29529] Microsoft Windows 2000/2003 IKE association negotiation failed
17857| [29528] Microsoft Windows 2000/2003 IKE association peer authentication failed
17858| [29527] Microsoft Windows 2000/2003 IKE association failed invalid proposal
17859| [29526] Microsoft Windows 2000/2003 IKE association failed authentication parameters
17860| [29525] Microsoft Windows 2000/2003 DPAPI master key backup attempted
17861| [29524] Microsoft Windows 2000/2003 DPAPI key recovery attempted
17862| [29523] Microsoft Windows 2000/2003 DPAPI auditable data unprotected
17863| [29522] Microsoft Windows 2000/2003 administrative group security descriptor set
17864| [29521] Microsoft Windows 2000/2003 account name changed
17865| [29507] Microsoft Office 2003 unspecified PowerPoint NULL pointer dereference denial of service
17866| [28512] Microsoft Internet Explorer multiple Windows 2000 COM object denial of service
17867| [28005] Microsoft Windows 2000 Management Console (MMC) resource file cross-site scripting
17868| [26118] Microsoft Office 2003 mailto: information disclosure
17869| [25330] Microsoft Commerce Server 2002 authfiles/login.asp authentication bypass
17870| [24474] Microsoft Windows 2000 LDAP client accepts untrusted CA
17871| [24473] Microsoft Windows 2000 event ID 565 not logged
17872| [24472] Microsoft Windows 2000 Event ID 1704 records incorrect group policy settings
17873| [24407] Microsoft Windows 2000 SECEDIT command fails to set ACLs correctly
17874| [24405] Microsoft Windows 2000 UPN credentials with trailing dot group policy bypass
17875| [24403] Microsoft Windows 2000 WideCharToMultiByte() incorrect Japanese character conversion
17876| [24402] Microsoft Windows 2000 Terminal Service client IP not logged
17877| [24400] Microsoft Windows 2000 domain authentication can be bypassed by a local administrator
17878| [23066] Microsoft Windows XP and 2000 Server MSRPC memory allocation denial of service
17879| [22318] Microsoft SQL Server 2000 Service Pack 4 update is not installed
17880| [22183] Microsoft Exchange Server 2003 public folder denial of service
17881| [21345] Microsoft Windows 2000 Update Rollup 1 for Service Pack 4 has not been installed
17882| [21315] Microsoft Outlook 2002 connector for Domino bypass restrictions
17883| [19969] Multiple Microsoft Windows Server 2003 Edition printer driver denial of service
17884| [19965] Multiple Microsoft Windows Server 2003 Editions SMB redirector denial of service
17885| [19727] Microsoft Windows 2000 GDI32.DLL denial of service
17886| [19629] Microsoft Exchange Server 2003 folder denial of service
17887| [17826] Microsoft Outlook 2003 CID security bypass
17888| [17624] Microsoft Windows XP and Windows Server 2003 Compressed Folders buffer overflow
17889| [17621] Microsoft Windows 2003 SMTP service code execution
17890| [17560] Microsoft Windows 2000 and XP GDI library denial of service
17891| [17521] Microsoft Windows 2000 Service Pack 4 is not installed
17892| [16913] Microsoft Windows 2003 users with Synchronize directory service data privilege
17893| [16912] Microsoft Windows 2003 groups with Synchronize directory service data privilege
17894| [16909] Microsoft Windows 2003 groups with Remove computer from docking station privilege
17895| [16907] Microsoft Windows 2003 users with Create global objects privilege
17896| [16905] Microsoft Windows 2003 users or groups with Create global objects privilege
17897| [16851] Microsoft Windows 2003 and XP WinKey and U key denial of service
17898| [16704] Microsoft Windows 2000 Media Player control code execution
17899| [16582] Microsoft Windows Server 2003 kernel CPU denial of service
17900| [16572] Microsoft Windows 2003 Users with Impersonate a client after authentication privilege
17901| [16570] Microsoft Windows 2003 Users with Create global objects privilege
17902| [16564] Microsoft Windows 2003 Groups with Create global objects privilege
17903| [16562] Microsoft Windows 2003 Groups with "
17904| [16522] Microsoft Windows 2003 Impersonate a client after authentication privilege
17905| [16521] Microsoft Windows 2003 Deny Logon Through Terminal Services privilege
17906| [16520] Microsoft Windows 2003 Create global objects privilege
17907| [16276] Microsoft Windows 2000 Advanced Server fully qualified domain name security bypass
17908| [16173] Microsoft Outlook 2003 OLE object bypass restricted security zone
17909| [16119] Microsoft Outlook 2000 URL spoofing
17910| [16104] Microsoft Outlook 2003 predictable file location could allow code execution
17911| [16095] Microsoft Windows XP and Windows Server 2003 HCP URL code execution
17912| [15704] Microsoft Windows XP and Windows Server 2003 HCP URL code execution
17913| [15700] Microsoft Windows 2000 Domain Controller LSASS LDAP message denial of service
17914| [15632] Microsoft Windows 2000 Utility Manger allows privilege escalation
17915| [15414] Microsoft Outlook 2002 mailto URL allows execution of code
17916| [15263] Microsoft Windows XP and 2000 Server kernel allows elevated privileges
17917| [15057] Microsoft Windows XP and Windows Server 2003 smbmount Linux client denial of service
17918| [15038] Microsoft Windows 2000 Server Windows Media Services denial of service
17919| [15037] Microsoft Windows Server 2003 WINS /GS flag denial of service
17920| [14178] Microsoft ISA Exchange Server 2003 MS04-002 patch is not installed
17921| [14167] Microsoft ISA Server 2000 H.323 filter buffer overflow
17922| [13426] Microsoft Windows 2000 and XP RPC race condition
17923| [13423] Microsoft Windows 2000 Local Troubleshooter ActiveX control buffer overflow
17924| [13407] Microsoft Windows 2000 Server mqsvc.exe MQLocateBegin packet buffer overflow
17925| [13385] Microsoft Windows Server 2003 "
17926| [13211] Microsoft Windows 2000 and XP URG memory leak
17927| [13171] Microsoft Windows Server 2003 can allow attacker to bypass mechanism used to detect buffer overflows
17928| [13131] Microsoft Windows 2000 Message Queue Manager buffer overflow
17929| [12684] Microsoft Exchange Server OWA Outlook 2003 denial of service
17930| [12652] Microsoft Windows 2000 and NT 4.0 Server IIS ISAPI nsiislog.dll extension POST request buffer overflow
17931| [12620] Microsoft Windows 2000 Server SMTP FILETIME denial of service
17932| [12543] Microsoft Windows 2000 Accessibility Utility Manager could allow an attacker to gain privileges
17933| [12493] Microsoft Windows Shell32.dll 2000 ShellExecute function buffer overflow
17934| [12489] Microsoft Windows 2000 Server Active Directory buffer overflow
17935| [12128] Microsoft Windows 2000 and Windows NT MS03-019 patch is not installed
17936| [12092] Microsoft Windows 2000 and NT 4.0 Server IIS ISAPI nsiislog.dll extension buffer overflow
17937| [12048] Microsoft Windows 2000 and Windows Server 2003 LAN Manager hash creation enabled
17938| [11901] Microsoft BizTalk Server 2002 SQL injection
17939| [11900] Microsoft BizTalk Server 2002 HTTP Receiver function buffer overflow
17940| [11816] Microsoft Windows 2000 Terminal Services MSGINA.DLL insecure access permissions
17941| [11696] Microsoft Windows 2000 Terminal Services man-in-the-middle attack
17942| [11617] Microsoft Windows 2000 MS03-007 patch is not installed on the system
17943| [11546] Microsoft Windows 2000 Windows Help Facility .cnt file buffer overflow
17944| [11329] Microsoft Windows NT and 2000 cmd.exe CD path name buffer overflow
17945| [11274] Microsoft Windows 2000 NetBIOS continuation packets denial of service
17946| [11273] Microsoft Windows 2000 RPC service could allow an attacker to gain elevated privileges
17947| [11216] Microsoft Windows NT and 2000 command prompt denial of service
17948| [11141] Microsoft Windows 2000 Terminal Services MSGINA.DLL denial of service
17949| [11133] Microsoft Outlook 2002 using V1 Exchange Server Security certificates transmits plaintext emails
17950| [10843] Microsoft Windows 2000 and XP SMB signing group policy modification
17951| [10431] Microsoft Windows 2000 SNMP LANMAN Extension memory leak denial of service
17952| [10400] Microsoft Windows 2000 RPC TCP port 135 denial of service
17953| [10377] Microsoft Windows XP and 2000 administrative alerts fail when security event log is full
17954| [10199] Microsoft Windows 2000/XP PPTP packet buffer overflow
17955| [10195] Microsoft FrontPage Server Extensions (FPSE) 2002 SmartHTML Interpreter buffer overflow
17956| [10194] Microsoft FrontPage Server Extensions (FPSE) 2000 SmartHTML Interpreter denial of service
17957| [9946] Microsoft Windows 2000 Terminal Services session screensaver fails to lock the console
17958| [9856] Microsoft Windows 2000 NCM handler routine could allow elevated privileges
17959| [9779] Microsoft Windows 2000 weak system partition permissions
17960| [9752] Microsoft Windows 2000 Service Pack 3 is not installed
17961| [9746] Microsoft Windows 2000 HTML Help item parameter buffer overflow
17962| [9625] Microsoft Windows 2000 Narrator allows login information to be audible
17963| [9154] Microsoft Data Engine (MSDE) and Microsoft SQL Server 2000 Desktop Engine have a default blank "
17964| [8867] Microsoft Windows 2000 LanMan denial of service
17965| [8813] Microsoft Windows 2000 Terminal Services allows attacker to bypass group policy settings
17966| [8759] Microsoft Windows 2000 could allow an attacker to block the application of Group Policy settings
17967| [8752] Microsoft Windows NT, 2000, and XP MUP buffer overflow
17968| [8739] Microsoft Windows 2000 DCOM memory leak
17969| [8708] Microsoft Outlook 2000 and 2002 executes embedded script in object tag when replying or forwarding HTML mail
17970| [8402] Microsoft Windows 2000 allows an attacker to bypass password policy
17971| [8307] Microsoft Windows 2000, Windows XP, and Exchange 2000 SMTP data transfer command denial of service
17972| [8304] Microsoft Windows 2000 and Exchange 5.5 SMTP service unauthorized mail privileges
17973| [8254] Microsoft Commerce Server 2000 AuthFilter ISAPI filter buffer overflow
17974| [8199] Microsoft Windows 2000 Terminal Services unlocked client
17975| [8094] Microsoft Windows 2000 and Interix 2.2 Telnet protocol option buffer overflow
17976| [8092] Microsoft Exchange 2000 System Attendant sets incorrect registry permissions
17977| [8043] Microsoft Windows NT, 2000, and XP using NTFS could allow files to be hidden
17978| [8037] Microsoft Windows 2000 empty TCP packet denial of service
17979| [8023] Microsoft Windows NT and Windows 2000 SIDs could allow an attacker to gain elevated privileges in another domain
17980| [7919] Microsoft IIS 4.0 and Norton Internet Security 2001 default permissions could allow an attacker to modify log files
17981| [7667] Microsoft Windows 2000 IKE UDP packet flood denial of service
17982| [7566] Microsoft IIS 2.0 and 3.0 upgraded to Microsoft IIS 4.0 fails to remove the ism.dll file
17983| [7538] Microsoft Windows 2000 and XP Terminal services allow an attacker to spoof IP addresses
17984| [7533] Microsoft Windows 2000 RunAs service denial of service
17985| [7532] Microsoft Windows 2000 RunAs service allows local attacker to bypass pipe authentication
17986| [7531] Microsoft Windows 2000 RunAs service reveals sensitive information
17987| [7528] Microsoft Windows NT and Windows 2000 malformed RPC request denial of service
17988| [7409] Microsoft Windows 2000 and Windows XP GDI denial of service
17989| [7302] Microsoft Windows NT and 2000 Terminal Server malformed RDP packet series denial of service
17990| [7008] Microsoft Windows 2000 IrDA device denial of service
17991| [6977] Microsoft Windows NT and 2000 NNTP memory leak denial of service
17992| [6931] Microsoft Windows 2000 without Service Pack 2
17993| [6919] Microsoft Windows 2000 Task Manager does not terminate malicious files with the same name as a system process
17994| [6912] Microsoft Windows NT and 2000 Terminal Server RDP memory leak denial of service
17995| [6876] Microsoft Windows 2000 could allow an attacker to change network passwords
17996| [6803] Microsoft Windows 2000 SMTP service allows mail relaying
17997| [6745] Microsoft Windows 2000 LDAP function could allow domain user password change
17998| [6669] Microsoft Windows 2000 Telnet system call denial of service
17999| [6668] Microsoft Windows 2000 Telnet handle leak denial of service
18000| [6667] Microsoft Windows 2000 Telnet multiple idle sessions denial of service
18001| [6666] Microsoft Windows 2000 Telnet username denial of service
18002| [6665] Microsoft Windows 2000 Telnet service weak domain authentication
18003| [6664] Microsoft Windows 2000 Telnet service predictable pipe names could allow elevation of privileges
18004| [6652] Microsoft Exchange 2000 OWA script execution
18005| [6590] Microsoft Windows 2000 debug registers allow attacker to gain elevated privileges
18006| [6506] Microsoft Windows 2000 Server Kerberos denial of service
18007| [6443] Microsoft Windows 2000 catalog file could remove installed hotfixes
18008| [6160] Microsoft Windows 2000 event viewer buffer overflow
18009| [6136] Microsoft Windows 2000 domain controller denial of service
18010| [6035] Microsoft Windows 2000 Server RDP denial of service
18011| [5973] Microsoft Windows 2000 EFS allows local user to recover sensitive data
18012| [5936] Microsoft Windows 2000 Server Directory Service Restore Mode allows user to login with blank password
18013| [5800] Microsoft Windows 2000 Index Service ActiveX controls allow unauthorized access to file information
18014| [5623] Microsoft Windows NT and 2000 Phone Book service buffer overflow
18015| [5598] Microsoft Windows 2000 Telnet daemon could allow a denial of service
18016| [5585] Microsoft Windows 2000 brute force attack
18017| [5502] Microsoft Windows 2000 Indexing Services ixsso.query
18018| [5467] Microsoft Windows 2000 System Monitor ActiveX control buffer overflow
18019| [5399] Microsoft Windows NT and 2000 Network Monitor buffer overflow
18020| [5301] Microsoft Windows 2000 Simplified Chinese IME State Recognition
18021| [5263] Microsoft Office 2000 executes .dll without users knowledge
18022| [5242] Microsoft Windows 2000 Telnet client NTLM authentication weakness
18023| [5222] Microsoft Windows 2000 malformed RPC packet denial of service
18024| [5203] Microsoft Windows 2000 still image service
18025| [5171] Microsoft Windows 2000 Local Security Policy corruption
18026| [5080] Microsoft Office 2000 HTML object tag buffer overflow
18027| [5033] Microsoft Windows 2000 without Service Pack 1
18028| [5031] Microsoft Windows 2000 Service Control Manager named pipe could allow a unauthorized user to gain privileges
18029| [5015] Microsoft Windows NT and 2000 executable path
18030| [4887] Microsoft Windows 2000 Kerberos ticket renewed
18031| [4886] Microsoft Windows 2000 logon session reconnected
18032| [4885] Microsoft Windows 2000 logon session disconnected
18033| [4882] Microsoft Windows 2000 Kerberos pre-authentication failed
18034| [4873] Microsoft Windows 2000 user account mapped for logon
18035| [4872] Microsoft Windows 2000 account logon failed
18036| [4871] Microsoft Windows 2000 account used for logon
18037| [4855] Microsoft Windows 2000 group type change
18038| [4842] Microsoft Internet Explorer and Microsoft Powerpoint 2000 ActiveX object execution
18039| [4841] Microsoft Internet Explorer and Microsoft Access 2000 VBA code execution
18040| [4823] Microsoft Windows 2000 Telnet server binary stream denial of service
18041| [4819] Microsoft Windows 2000 default SYSKEY configuration
18042| [4787] Microsoft Windows 2000 user account locked out
18043| [4786] Microsoft Windows 2000 computer account created
18044| [4785] Microsoft Windows 2000 computer account changed
18045| [4784] Microsoft Windows 2000 computer account deleted
18046| [4714] Microsoft Windows 2000 "
18047| [4589] Microsoft Windows 2000 protected store can be compromised by brute force attack
18048| [4278] Microsoft Windows 2000 unattended install does not secure All Users profile
18049| [4138] Microsoft Windows 2000 system file integrity feature is disabled
18050| [4086] Microsoft Windows 2000 may not start Jaz drives correctly
18051| [4085] Microsoft Windows 2000 non-Gregorial calendar error
18052| [4084] Microsoft Windows 2000 may prevent Adobe FrameMaker files from being saved in some formats
18053| [4083] Microsoft Windows 2000 Terminal Services may damage Office files saved as HTML
18054| [4082] Microsoft Windows 2000 and Iomega parallel port drives display error
18055| [4080] Microsoft Windows 2000 AOL image support
18056| [4079] Microsoft Windows 2000 High Encryption Pack
18057| [3854] Microsoft Office 2000 security setting
18058| [1376] Microsoft Proxy 2.0 denial of service
18059| [86256] Microsoft Windows Knowledge Base Article 2876063 update is not installed
18060| [86097] Microsoft Windows Knowledge Base Article 2859537 update is not installed
18061| [86091] Microsoft Windows Knowledge Base Article 2868623 update is not installed
18062| [86089] Microsoft Windows Knowledge Base Article 2862772 update is not installed
18063| [86075] Microsoft Windows Knowledge Base Article 2850869 update is not installed
18064| [86073] Microsoft Windows Knowledge Base Article 2873872 update is not installed
18065| [86070] Microsoft Windows Knowledge Base Article 2849568 update is not installed
18066| [85245] Microsoft Windows Knowledge Base Article 2848295 update is not installed
18067| [85244] Microsoft Windows Knowledge Base Article 2847927 update is not installed
18068| [85243] Microsoft Windows Knowledge Base Article 2861561 update is not installed
18069| [85236] Microsoft Windows Knowledge Base Article 2850851 update is not installed
18070| [85227] Microsoft Windows Knowledge Base Article 2847883 update is not installed
18071| [85223] Microsoft Windows Knowledge Base Article 2846071 update is not installed
18072| [85205] Microsoft Windows Knowledge Base Article 2845187 update is not installed
18073| [84621] Microsoft Windows Knowledge Base Article 2845690 update is not installed
18074| [84619] Microsoft Windows Knowledge Base Article 2839894 update is not installed
18075| [84617] Microsoft Windows Knowledge Base Article 2839571 update is not installed
18076| [84615] Microsoft Windows Knowledge Base Article 2839229 update is not installed
18077| [84613] Microsoft Windows Knowledge Base Article 2838727 update is not installed
18078| [84156] Microsoft Windows Knowledge Base Article 2847204 update is not installed
18079| [83912] Microsoft Windows Knowledge Base Article 2829254 update is not installed
18080| [83910] Microsoft Windows Knowledge Base Article 2829530 update is not installed
18081| [83898] Microsoft Windows Knowledge Base Article 2830397 update is not installed
18082| [83886] Microsoft Windows Knowledge Base Article 2830399 update is not installed
18083| [83884] Microsoft Windows Knowledge Base Article 2834692 update is not installed
18084| [83882] Microsoft Windows Knowledge Base Article 2834695 update is not installed
18085| [83880] Microsoft Windows Knowledge Base Article 2836440 update is not installed
18086| [83876] Microsoft Windows Knowledge Base Article 2840221 update is not installed
18087| [83192] Microsoft Windows Knowledge Base Article 2817183 update is not installed
18088| [83100] Microsoft Windows Knowledge Base Article 2830914 update is not installed
18089| [83098] Microsoft Windows Knowledge Base Article 2829996 update is not installed
18090| [83093] Microsoft Windows Knowledge Base Article 2828223 update is not installed
18091| [83091] Microsoft Windows Knowledge Base Article 2813170 update is not installed
18092| [83088] Microsoft Windows Knowledge Base Article 2827663 update is not installed
18093| [83086] Microsoft Windows Knowledge Base Article 2823482 update is not installed
18094| [83084] Microsoft Windows Knowledge Base Article 2821818 update is not installed
18095| [83082] Microsoft Windows Knowledge Base Article 2820917 update is not installed
18096| [82600] Microsoft Windows Knowledge Base Article 2813707 update is not installed
18097| [82424] Microsoft Windows Knowledge Base Article 2814124 update is not installed
18098| [82422] Microsoft Windows Knowledge Base Article 2780176 update is not installed
18099| [82401] Microsoft Windows Knowledge Base Article 2813682 update is not installed
18100| [82399] Microsoft Windows Knowledge Base Article 2816264 update is not installed
18101| [81683] Microsoft Windows Knowledge Base Article 2780091 update is not installed
18102| [81681] Microsoft Windows Knowledge Base Article 2784242 update is not installed
18103| [81680] Microsoft Windows Knowledge Base Article 2790113 update is not installed
18104| [81678] Microsoft Windows Knowledge Base Article 2790655 update is not installed
18105| [81676] Microsoft Windows Knowledge Base Article 2790978 update is not installed
18106| [81674] Microsoft Windows Knowledge Base Article 2797052 update is not installed
18107| [81672] Microsoft Windows Knowledge Base Article 2799494 update is not installed
18108| [81666] Microsoft Windows Knowledge Base Article 2778344 update is not installed
18109| [81634] Microsoft Windows Knowledge Base Article 2792100 update is not installed
18110| [81339] Microsoft Windows Knowledge Base Article 2799329 update is not installed
18111| [80875] Microsoft Windows Knowledge Base Article 2756145 update is not installed
18112| [80872] Microsoft Windows Knowledge Base Article 2769324 update is not installed
18113| [80867] Microsoft Windows Knowledge Base Article 2769327 update is not installed
18114| [80865] Microsoft Windows Knowledge Base Article 2769369 update is not installed
18115| [80863] Microsoft Windows Knowledge Base Article 2778930 update is not installed
18116| [80861] Microsoft Windows Knowledge Base Article 2785220 update is not installed
18117| [80365] Microsoft Windows Knowledge Base Article 2761465 update is not installed
18118| [80360] Microsoft Windows Knowledge Base Article 2765809 update is not installed
18119| [80358] Microsoft Windows Knowledge Base Article 2770660 update is not installed
18120| [80356] Microsoft Windows Knowledge Base Article 2780642 update is not installed
18121| [80352] Microsoft Windows Knowledge Base Article 2783534 update is not installed
18122| [80349] Microsoft Windows Knowledge Base Article 2784126 update is not installed
18123| [79693] Microsoft Windows Knowledge Base Article 2745030 update is not installed
18124| [79687] Microsoft Windows Knowledge Base Article 2761451 update is not installed
18125| [79683] Microsoft Windows Knowledge Base Article 2761226 update is not installed
18126| [79679] Microsoft Windows Knowledge Base Article 2758857 update is not installed
18127| [79677] Microsoft Windows Knowledge Base Article 2727528 update is not installed
18128| [78864] Microsoft Windows Knowledge Base Article 2754670 update is not installed
18129| [78862] Microsoft Windows Knowledge Base Article 2743555 update is not installed
18130| [78858] Microsoft Windows Knowledge Base Article 2754849 update is not installed
18131| [78856] Microsoft Windows Knowledge Base Article 2724197 update is not installed
18132| [78853] Microsoft Windows Knowledge Base Article 2741517 update is not installed
18133| [78851] Microsoft Windows Knowledge Base Article 2742319 update is not installed
18134| [78848] Microsoft Windows Knowledge Base Article 2742321 update is not installed
18135| [78760] Microsoft Windows Knowledge Base Article 2744842 update is not installed
18136| [78077] Microsoft Windows Knowledge Base Article 2741528 update is not installed
18137| [78075] Microsoft Windows Knowledge Base Article 2720184 update is not installed
18138| [78071] Microsoft Windows Knowledge Base Article 2748552 update is not installed
18139| [77512] Microsoft Windows Knowledge Base Article 2740358 update is not installed
18140| [77362] Microsoft Windows Knowledge Base Article 2733918 update is not installed
18141| [77360] Microsoft Windows Knowledge Base Article 2733829 update is not installed
18142| [77357] Microsoft Windows Knowledge Base Article 2733594 update is not installed
18143| [77352] Microsoft Windows Knowledge Base Article 2731879 update is not installed
18144| [77350] Microsoft Windows Knowledge Base Article 2731847 update is not installed
18145| [77348] Microsoft Windows Knowledge Base Article 2723135 update is not installed
18146| [77346] Microsoft Windows Knowledge Base Article 2722913 update is not installed
18147| [77342] Microsoft Windows Knowledge Base Article 2720573 update is not installed
18148| [77325] Microsoft Windows Knowledge Base Article 2719584 update is not installed
18149| [76808] Microsoft Windows Knowledge Base Article 2721015 update is not installed
18150| [76725] Microsoft Windows Knowledge Base Article 2722479 update is not installed
18151| [76724] Microsoft Windows Knowledge Base Article 2719177 update is not installed
18152| [76721] Microsoft Windows Knowledge Base Article 2718523 update is not installed
18153| [76718] Microsoft Windows Knowledge Base Article 2698365 update is not installed
18154| [76711] Microsoft Windows Knowledge Base Article 2695502 update is not installed
18155| [76704] Microsoft Windows Knowledge Base Article 2691442 update is not installed
18156| [76702] Microsoft Windows Knowledge Base Article 2655992 update is not installed
18157| [75963] Microsoft Windows Knowledge Base Article 2699988 update is not installed
18158| [75939] Microsoft Windows Knowledge Base Article 2685939 update is not installed
18159| [75928] Microsoft Windows Knowledge Base Article 2711167 update is not installed
18160| [75136] Microsoft Windows Knowledge Base Article 2693777 update is not installed
18161| [75132] Microsoft Windows Knowledge Base Article 2690533 update is not installed
18162| [75130] Microsoft Windows Knowledge Base Article 2688338 update is not installed
18163| [75127] Microsoft Windows Knowledge Base Article 2681578 update is not installed
18164| [75123] Microsoft Windows Knowledge Base Article 2680352 update is not installed
18165| [75116] Microsoft Windows Knowledge Base Article 2597981 update is not installed
18166| [74556] Microsoft Windows Knowledge Base Article 2639185 update is not installed
18167| [74384] Microsoft Windows Knowledge Base Article 2675157 update is not installed
18168| [74378] Microsoft Windows Knowledge Base Article 2671605 update is not installed
18169| [74373] Microsoft Windows Knowledge Base Article 2664258 update is not installed
18170| [74369] Microsoft Windows Knowledge Base Article 2663860 update is not installed
18171| [73543] Microsoft Windows Knowledge Base Article 2671387 update is not installed
18172| [73540] Microsoft Windows Knowledge Base Article 2665364 update is not installed
18173| [73538] Microsoft Windows Knowledge Base Article 2651019 update is not installed
18174| [73536] Microsoft Windows Knowledge Base Article 2651018 update is not installed
18175| [73533] Microsoft Windows Knowledge Base Article 2647170 update is not installed
18176| [73530] Microsoft Windows Knowledge Base Article 2641653 update is not installed
18177| [72887] Microsoft Windows Knowledge Base Article 2663841 update is not installed
18178| [72873] Microsoft Windows Knowledge Base Article 2663830 update is not installed
18179| [72867] Microsoft Windows Knowledge Base Article 2663510 update is not installed
18180| [72857] Microsoft Windows Knowledge Base Article 2661637 update is not installed
18181| [72855] Microsoft Windows Knowledge Base Article 2660465 update is not installed
18182| [72853] Microsoft Windows Knowledge Base Article 2653956 update is not installed
18183| [72851] Microsoft Windows Knowledge Base Article 2654428 update is not installed
18184| [72849] Microsoft Windows Knowledge Base Article 2651026 update is not installed
18185| [72846] Microsoft Windows Knowledge Base Article 2647516 update is not installed
18186| [72841] Microsoft Windows Knowledge Base Article 2645640 update is not installed
18187| [72838] Microsoft Windows Knowledge Base Article 2643719 update is not installed
18188| [72029] Microsoft Windows Knowledge Base Article 2638420 update is not installed
18189| [72003] Microsoft Windows Knowledge Base Article 2646524 update is not installed
18190| [71998] Microsoft Windows Knowledge Base Article 2644615 update is not installed
18191| [71995] Microsoft Windows Knowledge Base Article 2643584 update is not installed
18192| [71994] Microsoft Windows Knowledge Base Article 2636391 update is not installed
18193| [71565] Microsoft Windows Knowledge Base Article 2648048 update is not installed
18194| [71562] Microsoft Windows Knowledge Base Article 2640241 update is not installed
18195| [71560] Microsoft Windows Knowledge Base Article 2640045 update is not installed
18196| [71558] Microsoft Windows Knowledge Base Article 2639417 update is not installed
18197| [71557] Microsoft Windows Knowledge Base Article 2639142 update is not installed
18198| [71554] Microsoft Windows Knowledge Base Article 2633171 update is not installed
18199| [71552] Microsoft Windows Knowledge Base Article 2624667 update is not installed
18200| [71550] Microsoft Windows Knowledge Base Article 2620712 update is not installed
18201| [71548] Microsoft Windows Knowledge Base Article 2618451 update is not installed
18202| [71546] Microsoft Windows Knowledge Base Article 2618444 update is not installed
18203| [71538] Microsoft Windows Knowledge Base Article 2590602 update is not installed
18204| [70951] Microsoft Windows Knowledge Base Article 2630837 update is not installed
18205| [70949] Microsoft Windows Knowledge Base Article 2620704 update is not installed
18206| [70947] Microsoft Windows Knowledge Base Article 2617657 update is not installed
18207| [70943] Microsoft Windows Knowledge Base Article 2588516 update is not installed
18208| [70152] Microsoft Windows Knowledge Base Article 2623699 update is not installed
18209| [70140] Microsoft Windows Knowledge Base Article 2652016 update is not installed
18210| [70130] Microsoft Windows Knowledge Base Article 2586448 update is not installed
18211| [70115] Microsoft Windows Knowledge Base Article 2567053 update is not installed
18212| [69501] Microsoft Windows Knowledge Base Article 2587634 update is not installed
18213| [69498] Microsoft Windows Knowledge Base Article 2587505 update is not installed
18214| [69492] Microsoft Windows Knowledge Base Article 2571621 update is not installed
18215| [69490] Microsoft Windows Knowledge Base Article 2570947 update is not installed
18216| [68840] Microsoft Windows Knowledge Base Article 2451858 update is not installed
18217| [68833] Microsoft Windows Knowledge Base Article 2567943 update is not installed
18218| [68831] Microsoft Windows Knowledge Base Article 2570222 update is not installed
18219| [68829] Microsoft Windows Knowledge Base Article 2567951 update is not installed
18220| [68827] Microsoft Windows Knowledge Base Article 2578230 update is not installed
18221| [68825] Microsoft Windows Knowledge Base Article 2546250 update is not installed
18222| [68823] Microsoft Windows Knowledge Base Article 2559049 update is not installed
18223| [68816] Microsoft Windows Knowledge Base Article 2556532 update is not installed
18224| [68814] Microsoft Windows Knowledge Base Article 2560656 update is not installed
18225| [68812] Microsoft Windows Knowledge Base Article 2560978 update is not installed
18226| [68809] Microsoft Windows Knowledge Base Article 2562485 update is not installed
18227| [68806] Microsoft Windows Knowledge Base Article 2566454 update is not installed
18228| [68804] Microsoft Windows Knowledge Base Article 2563894 update is not installed
18229| [68801] Microsoft Windows Knowledge Base Article 2567680 update is not installed
18230| [68315] Microsoft Windows Knowledge Base Article 2555917 update is not installed
18231| [68299] Microsoft Windows Knowledge Base Article 2566220 update is not installed
18232| [68283] Microsoft Windows Knowledge Base Article 2560847 update is not installed
18233| [67955] Microsoft Windows Knowledge Base Article 2530548 update is not installed
18234| [67943] Microsoft Windows Knowledge Base Article 2544521 update is not installed
18235| [67762] Microsoft Windows Knowledge Base Article 2543893 update is not installed
18236| [67759] Microsoft Windows Knowledge Base Article 2544893 update is not installed
18237| [67757] Microsoft Windows Knowledge Base Article 2476490 update is not installed
18238| [67753] Microsoft Windows Knowledge Base Article 2514842 update is not installed
18239| [67751] Microsoft Windows Knowledge Base Article 2518295 update is not installed
18240| [67737] Microsoft Windows Knowledge Base Article 2520426 update is not installed
18241| [67733] Microsoft Windows Knowledge Base Article 2525694 update is not installed
18242| [67731] Microsoft Windows Knowledge Base Article 2525835 update is not installed
18243| [67728] Microsoft Windows Knowledge Base Article 2535512 update is not installed
18244| [67725] Microsoft Windows Knowledge Base Article 2536275 update is not installed
18245| [67722] Microsoft Windows Knowledge Base Article 2536276 update is not installed
18246| [67718] Microsoft Windows Knowledge Base Article 2537146 update is not installed
18247| [67709] Microsoft Windows Knowledge Base Article 2538814 update is not installed
18248| [67302] Microsoft Windows Knowledge Base Article 2545814 update is not installed
18249| [67101] Microsoft Windows Knowledge Base Article 2524426 update is not installed
18250| [66446] Microsoft Windows Knowledge Base Article 2514666 update is not installed
18251| [66444] Microsoft Windows Knowledge Base Article 2511455 update is not installed
18252| [66436] Microsoft Windows Knowledge Base Article 2497640 update is not installed
18253| [66432] Microsoft Windows Knowledge Base Article 2527308 update is not installed
18254| [66428] Microsoft Windows Knowledge Base Article 2489979 update is not installed
18255| [66423] Microsoft Windows kernel-mode driver (win32k.sys) variant 29 privilege escalation
18256| [66422] Microsoft Windows kernel-mode driver (win32k.sys) variant 28 privilege escalation
18257| [66421] Microsoft Windows kernel-mode driver (win32k.sys) variant 27 privilege escalation
18258| [66420] Microsoft Windows kernel-mode driver (win32k.sys) variant 26 privilege escalation
18259| [66419] Microsoft Windows kernel-mode driver (win32k.sys) variant 25 privilege escalation
18260| [66418] Microsoft Windows kernel-mode driver (win32k.sys) variant 24 privilege escalation
18261| [66417] Microsoft Windows kernel-mode driver (win32k.sys) variant 23 privilege escalation
18262| [66416] Microsoft Windows kernel-mode driver (win32k.sys) variant 22 privilege escalation
18263| [66415] Microsoft Windows kernel-mode driver (win32k.sys) variant 21 privilege escalation
18264| [66414] Microsoft Windows kernel-mode driver (win32k.sys) variant 20 privilege escalation
18265| [66396] Microsoft Windows kernel-mode driver (win32k.sys) variant 2 privilege escalation
18266| [66394] Microsoft Windows Knowledge Base Article 2485663 update is not installed
18267| [65588] Microsoft Windows Knowledge Base Article 2489279 update is not installed
18268| [65581] Microsoft Windows Knowledge Base Article 2510030 update is not installed
18269| [65580] Microsoft Windows Knowledge Base Article 2489283 update is not installed
18270| [65575] Microsoft Windows Knowledge Base Article 2489293 update is not installed
18271| [65573] Microsoft Windows Knowledge Base Article 2494047 update is not installed
18272| [64973] Microsoft Windows Knowledge Base Article 2478960 update is not installed
18273| [64971] Microsoft Windows Knowledge Base Article 2479628 update is not installed
18274| [64927] Microsoft Windows Knowledge Base Article 2393802 update is not installed
18275| [64925] Microsoft Windows Knowledge Base Article 2451879 update is not installed
18276| [64920] Microsoft Windows Knowledge Base Article 2475792 update is not installed
18277| [64918] Microsoft Windows Knowledge Base Article 2476687 update is not installed
18278| [64916] Microsoft Windows Knowledge Base Article 2478953 update is not installed
18279| [64914] Microsoft Windows Knowledge Base Article 2482017 update is not installed
18280| [64910] Microsoft Windows Knowledge Base Article 2483185 update is not installed
18281| [64909] Microsoft Windows Knowledge Base Article 2484015 update is not installed
18282| [64907] Microsoft Windows Knowledge Base Article 2485376 update is not installed
18283| [64905] Microsoft Windows Knowledge Base Article 2489256 update is not installed
18284| [64902] Microsoft Windows Knowledge Base Article 2496930 update is not installed
18285| [64342] Microsoft Windows Knowledge Base Article 2451910 update is not installed
18286| [64339] Microsoft Windows Knowledge Base Article 2478935 update is not installed
18287| [63584] Microsoft Windows Knowledge Base Article 2424434 update is not installed
18288| [63582] Microsoft Windows Knowledge Base Article 2423089 update is not installed
18289| [63580] Microsoft Windows Knowledge Base Article 2436673 update is not installed
18290| [63571] Microsoft Windows Knowledge Base Article 2440591 update is not installed
18291| [63569] Microsoft Windows Knowledge Base Article 2385678 update is not installed
18292| [63566] Microsoft Windows Knowledge Base Article 2442962 update is not installed
18293| [63564] Microsoft Windows Knowledge Base Article 2345316 update is not installed
18294| [63562] Microsoft Windows Knowledge Base Article 2296199 update is not installed
18295| [63558] Microsoft Windows Knowledge Base Article 2416400 update is not installed
18296| [63550] Microsoft Windows Knowledge Base Article 2447961 update is not installed
18297| [63548] Microsoft Windows Knowledge Base Article 2443105 update is not installed
18298| [63546] Microsoft Windows Knowledge Base Article 2455005 update is not installed
18299| [63544] Microsoft Windows Knowledge Base Article 2292970 update is not installed
18300| [62805] Microsoft Windows Knowledge Base Article 2316074 update is not installed
18301| [62793] Microsoft Windows Knowledge Base Article 2293386 update is not installed
18302| [62789] Microsoft Windows Knowledge Base Article 2423930 update is not installed
18303| [62170] Microsoft Windows Knowledge Base Article 2296011 update is not installed
18304| [62166] Microsoft Windows Knowledge Base Article 2294255 update is not installed
18305| [62163] Microsoft Windows Knowledge Base Article 2281679 update is not installed
18306| [62154] Microsoft Windows Knowledge Base Article 2279986 update is not installed
18307| [62147] Microsoft Windows Knowledge Base Article 2160841 update is not installed
18308| [62134] Microsoft Windows Knowledge Base Article 2412048 update is not installed
18309| [62129] Microsoft Windows Knowledge Base Article 2387149 update is not installed
18310| [62126] Microsoft Windows Knowledge Base Article 2378111 update is not installed
18311| [62123] Microsoft Windows Knowledge Base Article 2360937 update is not installed
18312| [62118] Microsoft Windows Knowledge Base Article 2293211 update is not installed
18313| [62104] Microsoft Windows Knowledge Base Article 2360131 update is not installed
18314| [62098] Microsoft Windows Knowledge Base Article 2293194 update is not installed
18315| [62069] Microsoft Windows Knowledge Base Article 2418042 update is not installed
18316| [61519] Microsoft Windows Knowledge Base Article 2121546 update is not installed
18317| [61517] Microsoft Windows Knowledge Base Article 2259922 update is not installed
18318| [61514] Microsoft Windows Knowledge Base Article 2267960 update is not installed
18319| [61510] Microsoft Windows Knowledge Base Article 2315011 update is not installed
18320| [61507] Microsoft Windows Knowledge Base Article 2320113 update is not installed
18321| [61504] Microsoft Windows Knowledge Base Article 2347290 update is not installed
18322| [60736] Microsoft Windows Knowledge Base Article 2265906 update is not installed
18323| [60734] Microsoft Windows Knowledge Base Article 2269638 update is not installed
18324| [60728] Microsoft Windows Knowledge Base Article 2269707 update is not installed
18325| [60724] Microsoft Windows Knowledge Base Article 2286198 update is not installed
18326| [60713] Microsoft Windows Knowledge Base Article 2183461 update is not installed
18327| [60698] Microsoft Windows Knowledge Base Article 2160329 update is not installed
18328| [60686] Microsoft Windows Knowledge Base Article 2115168 update is not installed
18329| [60684] Microsoft Windows Knowledge Base Article 2079403 update is not installed
18330| [60680] Microsoft Windows Knowledge Base Article 2264072 update is not installed
18331| [59901] Microsoft Windows Knowledge Base Article 2229593 update is not installed
18332| [59898] Microsoft Windows Knowledge Base Article 2229593 update is not installed
18333| [58913] Microsoft Windows Knowledge Base Article 2027452 update is not installed
18334| [58891] Microsoft Windows Knowledge Base Article 2028554 update is not installed
18335| [17004] Microsoft Windows XP Service Pack 2 is not installed on the system
18336| [9187] Microsoft Passport SDK 2.1 Component Configuration Document (CCD) permission
18337| [9146] Microsoft Passport SDK 2.1 events reporting disabled
18338| [9068] Microsoft Passport SDK 2.1 registry default permission exposure
18339| [9067] Microsoft Passport SDK 2.1 default test site exposure
18340| [9066] Microsoft Passport SDK 2.1 Adventure Works Sample Site exposure
18341| [9065] Microsoft Passport SDK 2.1 Adventure Works Sample Site global.asa file default permission exposure
18342| [9064] Microsoft Passport SDK 2.1 default time window exposure
18343| [1271] Microsoft IIS version 2 installed
18344| [621] Microsoft IIS 3.0 script source revealed by appending 2E to requests
18345|
18346| Exploit-DB - https://www.exploit-db.com:
18347| [30756] Microsoft Forms 2.0 ActiveX Control 2.0 Memory Access Violation Denial of Service Vulnerabilities
18348| [30749] Microsoft Office 2003 Web Component Memory Access Violation Denial of Service Vulnerability
18349| [30636] Microsoft Windows 2000/2003 Recursive DNS Spoofing Vulnerability (2)
18350| [30635] Microsoft Windows 2000/2003 Recursive DNS Spoofing Vulnerability (1)
18351| [30281] Microsoft .Net Framework <= 2.0 - Multiple Null Byte Injection Vulnerabilities
18352| [29664] Microsoft Office Publisher 2007 - Remote Denial of Service (DoS) Vulnerability
18353| [29660] Microsoft Office 2003 - Denial of Service (DoS) Vulnerability
18354| [29630] Microsoft Windows 2003/XP ReadDirectoryChangesW Information Disclosure Vulnerability
18355| [29524] Microsoft Word 2000 - Malformed Function Code Execution Vulnerability
18356| [28420] Microsoft Windows 2000 Multiple COM Object Instantiation Code Execution Vulnerabilities
18357| [28357] Microsoft Windows Explorer 2000/2003/XP Drag and Drop Remote Code Execution Vulnerability
18358| [28227] Microsoft Windows 2000/XP Registry Access Local Denial of Service Vulnerability
18359| [28226] Microsoft PowerPoint 2003 PPT File Closure Memory Corruption
18360| [28225] Microsoft PowerPoint 2003 powerpnt.exe Unspecified Issue
18361| [28224] Microsoft PowerPoint 2003 mso.dll PPT Processing Unspecified Code Execution
18362| [28198] Microsoft Office 2000/2002 Property Code Execution Vulnerability
18363| [28189] Microsoft Excel 2000-2004 Style Handling and Repair Remote Code Execution Vulnerability
18364| [28087] Microsoft Office 2003 Embedded Shockwave Flash Object Security Bypass Weakness
18365| [28005] Microsoft Exchange Server 2000/2003 Outlook Web Access Script Injection Vulnerability
18366| [26690] Microsoft Windows 2000/2003/XP CreateRemoteThread Local Denial of Service Vulnerability
18367| [26517] Microsoft Office PowerPoint 2007 - Crash PoC
18368| [26341] Microsoft Windows 2000/2003/XP MSDTC TIP Denial of Service Vulnerability
18369| [26222] Microsoft Windows 2000/2003/XP Keyboard Event Privilege Escalation Weakness
18370| [25384] Microsoft Windows 2000/XP Internet Protocol Validation Remote Code Execution Vulnerability (2)
18371| [25383] Microsoft Windows 2000/XP Internet Protocol Validation Remote Code Execution Vulnerability (1)
18372| [25231] Microsoft Windows 2000/2003/XP Graphical Device Interface Library Denial of Service Vulnerability
18373| [25085] Microsoft Office XP 2000/2002 HTML Link Processing Remote Buffer Overflow Vulnerability
18374| [25084] Microsoft Outlook 2003 Web Access Login Form Remote URI Redirection Vulnerability
18375| [25050] Microsoft Windows 2000/2003/XP winhlp32 Phrase Heap Overflow Vulnerability
18376| [25049] Microsoft Windows 2000/2003/XP winhlp32 Phrase Integer Overflow Vulnerability
18377| [24686] Microsoft Outlook 2003 Security Policy Bypass Vulnerability
18378| [24277] Microsoft Windows 2000/NT 4 POSIX Subsystem Buffer Overflow Local Privilege Escalation Vulnerability
18379| [24114] Microsoft Outlook 2003Mail Client E-mail Address Verification Weakness
18380| [24101] Microsoft Outlook 2003 Predictable File Location Weakness
18381| [23989] Microsoft Windows 2000/NT 4 Local Descriptor Table Local Privilege Escalation Vulnerability
18382| [23796] Microsoft Outlook 2002 Mailto Parameter Quoting Zone Bypass Vulnerability
18383| [23019] Microsoft Windows 2000 Subnet Bandwidth Manager RSVP Server Authority Hijacking Vulnerability
18384| [22919] Microsoft ISA Server 2000 Cross-Site Scripting Vulnerabilities
18385| [22883] Microsoft Windows 2000 CreateFile API Named Pipe Privilege Escalation Vulnerability (2)
18386| [22882] Microsoft Windows 2000 CreateFile API Named Pipe Privilege Escalation Vulnerability (1)
18387| [22837] Microsoft Windows 2000/NT 4 Media Services NSIISlog.DLL Remote Buffer Overflow
18388| [22782] Microsoft Windows 2000 Active Directory Remote Stack Overflow Vulnerability
18389| [22591] Microsoft Office Excel 2007 - WriteAV Crash PoC
18390| [22555] Microsoft BizTalk Server 2000/2002 DTA RawCustomSearchField.asp SQL Injection
18391| [22554] Microsoft BizTalk Server 2000/2002 DTA rawdocdata.asp SQL Injection Vulnerability
18392| [22553] Microsoft BizTalk Server 2002 HTTP Receiver Buffer Overflow Vulnerability
18393| [22528] Microsoft Windows 2000 RegEdit.EXE Registry Key Value Buffer Overflow Vulnerability
18394| [22354] Microsoft Windows 2000 Help Facility .CNT File :Link Buffer Overflow Vulnerability
18395| [21920] Microsoft Content Management Server 2001 Cross-Site Scripting Vulnerability
18396| [21718] Microsoft SQL 2000/7.0 Agent Jobs Privilege Elevation Vulnerability
18397| [21693] Microsoft SQL Server 2000 User Authentication Remote Buffer Overflow Vulnerability
18398| [21652] Microsoft SQL Server 2000 Resolution Service Heap Overflow Vulnerability
18399| [21651] Microsoft SQL Server 2000 sp_MScopyscript SQL Injection Vulnerability
18400| [21650] Microsoft SQL Server 2000 Database Consistency Checkers Buffer Overflow Vulnerability
18401| [21549] Microsoft SQL Server 2000 Password Encrypt Procedure Buffer Overflow Vulnerability
18402| [21541] Microsoft SQL Server 2000 SQLXML Script Injection Vulnerability
18403| [21540] Microsoft SQL Server 2000 SQLXML Buffer Overflow Vulnerability
18404| [21389] Microsoft Windows 2000 Lanman Denial of Service Vulnerability (2)
18405| [21388] Microsoft Windows 2000 Lanman Denial of Service Vulnerability (1)
18406| [21344] Microsoft Windows 2000 / NT 4.0 Process Handle Local Privilege Elevation Vulnerability
18407| [21258] Microsoft Windows 2000/NT 4 NTFS File Hiding Vulnerability
18408| [21246] Microsoft Windows 2000/NT 4 TCP Stack DoS Vulnerability (2)
18409| [21245] Microsoft Windows 2000/NT 4 TCP Stack DoS Vulnerability (1)
18410| [21172] Microsoft Windows 2000 Internet Key Exchange DoS Vulnerability (2)
18411| [21171] Microsoft Windows 2000 Internet Key Exchange DoS Vulnerability (1)
18412| [21131] Microsoft Windows 2000/XP GDI Denial of Service Vulnerability
18413| [21123] Microsoft Windows 2000/NT Terminal Server Service RDP DoS Vulnerability
18414| [21113] Microsoft Index Server 2.0 File Information and Path Disclosure Vulnerability
18415| [21099] Microsoft Windows 2000 RunAs Service Denial of Services Vulnerability
18416| [21069] Microsoft Windows 2000 RunAs Service Named Pipe Hijacking Vulnerability
18417| [20907] Microsoft Windows 2000 Telnet Username DoS Vulnerability
18418| [20802] Microsoft IIS 2.0/3.0 Long URL Denial of Service Vulnerability
18419| [20763] Microsoft ISA Server 2000 Web Proxy DoS Vulnerability
18420| [20571] Microsoft Outlook 2000 0/98 0/Express 5.5 Concealed Attachment Vulnerability
18421| [20481] Microsoft IIS 2.0/3.0 Appended Dot Script Source Disclosure Vulnerability
18422| [20399] Microsoft Indexing Services for Windows 2000 File Verification Vulnerability
18423| [20335] Microsoft Indexing Services for Windows 2000/NT 4.0 .htw Cross-Site Scripting Vulnerability
18424| [20305] Microsoft Site Server 2.0 with IIS 4.0 - File Upload Vulnerability
18425| [20265] Microsoft Windows NT 4.0 / 2000 Spoofed LPC Request Vulnerability
18426| [20257] Microsoft Windows NT 4.0 / 2000 Predictable LPC Message Identifier Multiple Vulnerabilities
18427| [20255] Microsoft Windows NT 4.0 / 2000 LPC Zone Memory Depletion DoS Vulnerability
18428| [20222] Microsoft Windows 2000 telnet.exe NTLM Authentication Vulnerability
18429| [20209] Microsoft Windows 2000 Still Image Service Privilege Escalation Vulnerability
18430| [20133] Microsoft Windows 2000 Named Pipes Predictability Vulnerability
18431| [20122] Microsoft Office SharePoint Server 2007 Remote Code Execution
18432| [20096] Microsoft IIS 2.0/3.0/4.0/5.0/5.1 Internal IP Address Disclosure Vulnerability
18433| [20048] Microsoft Windows 2000 Remote CPU-overload Vulnerability
18434| [20047] Microsoft Windows 2000 Telnet Server DoS Vulnerability
18435| [19830] Microsoft Index Server 2.0 '%20' ASP Source Disclosure Vulnerability
18436| [19742] microsoft iis 3.0/4.0,microsoft index server 2.0 - Directory Traversal
18437| [19734] Microsoft Virtual Machine 2000 Series/3000 Series getSystemResource Vulnerability
18438| [19731] microsoft index server 2.0/indexing services for windows 2000 - Directory Traversal
18439| [19728] Microsoft Systems Management Server 2.0 Default Permissions Vulnerability
18440| [19425] Microsoft Data Access Components (MDAC) <= 2.1,Microsoft IIS 3.0/4.0,Microsoft Index Server 2.0,Microsoft Site Server Commerce Edition 3.0 i386 MDAC RDS Vulnerability (2)
18441| [19424] Microsoft Data Access Components (MDAC) <= 2.1,Microsoft IIS 3.0/4.0,Microsoft Index Server 2.0,Microsoft Site Server Commerce Edition 3.0 i386 MDAC RDS Vulnerability (1)
18442| [19376] Microsoft IIS 2.0/3.0/4.0 ISAPI GetExtensionVersion() Vulnerability
18443| [19143] "Microsoft Windows ""April Fools 2001"" Vulnerability"
18444| [19118] Microsoft IIS 3.0/4.0,Microsoft Personal Web Server 2.0/3.0/4.0 ASP Alternate Data Streams Vulnerability
18445| [18334] Microsoft Office 2003 Home/Pro 0day
18446| [18087] MS11-021 Microsoft Office 2007 Excel .xlb Buffer Overflow
18447| [18078] Microsoft Excel 2003 11.8335.8333 Use After Free
18448| [18067] Microsoft Excel 2007 SP2 Buffer Overwrite Exploit
18449| [17305] "Microsoft Windows Vista/Server 2008 ""nsiproxy.sys"" Local Kernel DoS Exploit"
18450| [14971] MOAUB #11 - Microsoft Office Word 2007 sprmCMajority Buffer Overflow
18451| [14782] Microsoft Office PowerPoint 2007 DLL Hijacking Exploit (rpawinet.dll)
18452| [14746] Microsoft Office Groove 2007 DLL Hijacking Exploit (mso.dll)
18453| [14744] Microsoft Visio 2003 DLL Hijacking Exploit (mfc71enu.dll)
18454| [12450] Microsoft SharePoint Server 2007 XSS Vulnerability
18455| [10068] Microsoft Windows 2000-2008 Embedded OpenType Font Engine Remote Code Execution
18456| [4121] Microsoft Excel 2000/2003 Sheet Name Vulnerability PoC
18457| [3973] Microsoft Office 2000 (OUACTRL.OCX 1.0.1.9) - Remote DoS Exploit
18458| [3690] microsoft office word 2007 - Multiple Vulnerabilities
18459| [3260] Microsoft Word 2000 Unspecified Code Execution Exploit (0day)
18460| [2523] Microsoft Office 2003 PPT Local Buffer Overflow PoC
18461| [2091] Microsoft PowerPoint 2003 SP2 Local Code Execution Exploit (french)
18462| [2001] Microsoft Word 2000/2003 Unchecked Boundary Condition Vulnerability
18463| [1999] Microsoft Word 2000/2003 Hlink Local Buffer Overflow Exploit PoC
18464| [1988] Microsoft Excel 2003 Hlink Local Buffer Overflow Exploit (italian)
18465| [1986] Microsoft Excel 2000/2003 Hlink Local Buffer Overflow Exploit (french)
18466| [1958] Microsoft Excel 2003 Hlink Stack/SEH Buffer Overflow Exploit
18467| [28238] Microsoft SharePoint 2013 (Cloud) - Persistent Exception Handling Vulnerability MS13-067
18468| [23034] Microsoft URLScan 2.5/ RSA Security SecurID 5.0 Configuration Enumeration Weakness
18469| [22850] Microsoft Office OneNote 2010 Crash PoC
18470| [22679] Microsoft Visio 2010 Crash PoC
18471| [22655] Microsoft Publisher 2013 Crash PoC
18472| [22621] Microsoft Netmeeting 2.1/3.0.1 4.4.3385 CALLTO URL Buffer Overflow Vulnerability
18473| [22330] Microsoft Office Excel 2010 Crash PoC
18474| [22310] Microsoft Office Publisher 2010 Crash PoC
18475| [22237] Microsoft Office Picture Manager 2010 Crash PoC
18476| [22215] Microsoft Office Word 2010 Crash PoC
18477| [19451] Microsoft Windows 98 a/98 b/98SE,Solaris 2.6 IRDP Vulnerability
18478| [19440] Microsoft Windows NT 4.0/SP 1/SP 2/Sp 3/SP 4/SP 5 Malformed Dialer Entry Vulnerability
18479| [19372] Microsoft Windows NT 4.0/SP 1/SP 2/SP 3/SP 4/SP 5 Null Session Admin Name Vulnerability
18480| [17164] Microsoft Reader <= 2.1.1.3143 NULL Byte Write
18481| [17163] Microsoft Reader <= 2.1.1.3143 Array Overflow
18482| [17162] Microsoft Reader <= 2.1.1.3143 Integer Overflow
18483| [17161] Microsoft Reader <= 2.1.1.3143 Heap Overflow
18484| [17160] Microsoft Reader <= 2.1.1.3143 Integer Overflow
18485| [14731] Microsoft Windows Movie Maker <= 2.6.4038.0 DLL Hijacking Exploit (hhctrl.ocx)
18486| [14723] Microsoft Power Point 2010 DLL Hijacking Exploit (pptimpconv.dll)
18487|
18488| OpenVAS (Nessus) - http://www.openvas.org:
18489| [902250] Microsoft Word 2003 'MSO.dll' Null Pointer Dereference Vulnerability
18490| [900125] Microsoft SQL Server 2000 sqlvdir.dll ActiveX Buffer Overflow Vulnerability
18491| [801597] Microsoft Office Excel 2003 Invalid Object Type Remote Code Execution Vulnerability
18492| [801596] Microsoft Excel 2007 Office Drawing Layer Remote Code Execution Vulnerability
18493| [801594] Microsoft PowerPoint 2007 OfficeArt Atom Remote Code Execution Vulnerability
18494| [800687] Microsoft Windows Server 2003 OpenType Font Engine DoS Vulnerability
18495| [800577] Microsoft Windows Server 2003 win32k.sys DoS Vulnerability
18496| [800343] Microsoft Word 2007 Sensitive Information Disclosure Vulnerability
18497| [103254] Microsoft SharePoint Server 2007 '_layouts/help.aspx' Cross Site Scripting Vulnerability
18498| [11992] Vulnerability in Microsoft ISA Server 2000 H.323 Filter(816458)
18499| [902931] Microsoft Office Remote Code Execution Vulnerabilities - 2720184 (Mac OS X)
18500| [902678] Microsoft Silverlight Code Execution Vulnerabilities - 2681578 (Mac OS X)
18501| [901210] Microsoft Office Privilege Elevation Vulnerability - 2721015 (Mac OS X)
18502|
18503| SecurityTracker - https://www.securitytracker.com:
18504| [1015347] Microsoft Windows 2000 Kernel APC Queue Bug Lets Local Users Gain Elevated Privileges
18505| [1013454] Microsoft Office InfoPath 2003 May Disclose System and Authentication Information to Remote Users
18506| [1013284] Microsoft Windows 2000 and XP Group Policy Can Be Bypassed By Microsoft Office Applications and By Flash Drives
18507| [1010687] Microsoft Windows 2000/NT POSIX Subsystem Buffer Overflow Lets Local Users Gain Elevated Privileges
18508| [1010352] Microsoft Windows 2000 Domains With Eight Characters May Let Remote Users With Expired Passwords Login
18509| [1010189] Microsoft Outlook 2003 Scripting Restrictions Can Be Bypassed By Remote Users
18510| [1010125] Microsoft Outlook 2003 Lets Remote Users Send E-mail to Cause the Recipient's Client to Contact a Remote Server
18511| [1009767] Microsoft Windows 2000 Domain Controller LDAP Flaw May Let Remote Users Restart the Authentication Service
18512| [1008324] Microsoft Exchange 2003 With Outlook Web Access and Windows SharePoint Services May Grant Incorrect E-mail Account Access to Remote Authenticated Users
18513| [1007905] Microsoft Windows Server 2003 Shell Folders Can Be Referenced Using Directory Traversal Characters
18514| [1007238] Microsoft Outlook Web Access Can Be Crashed By Remote Authenticated Users With an Outlook 2003 Client
18515| [1007152] Microsoft Windows 2000 Accessibility Utility Manager Lets Local Users Gain Elevated Privileges
18516| [1007099] Microsoft Windows 2000 ShellExecute() Buffer Overflow May Let Users Execute Arbitrary Code
18517| [1007093] Microsoft Active Directory Stack Overflow in 'Lsaas.exe' Lets Remote Users Crash the Windows 2000 Server
18518| [1006959] Microsoft Windows Server 2003 Drivers May Leak Information From Memory Via Ethernet Packets Containing TCP Streams
18519| [1006580] Microsoft Windows 2003 'win2k.sys' Printing Bug Lets Users Crash the System
18520| [1006534] Microsoft Proxy Service in Proxy Server 2.0 Has Unspecified Flaw That Lets Remote Users Stop Traffic
18521| [1006286] Microsoft Windows 2000/XP PostMessage() API Flaw May Let Local Users Grab Passwords from Local Dialog Boxes
18522| [1006280] Protegrity Secure.Data for Microsoft SQL Server 2000 Contains Buffer Oveflows That Let Remote Users Execute Arbitrary Code
18523| [1005254] Microsoft NT, 2000, and XP Operating Systems May Execute a 16-bit Application Even When The File Has No Execute Permissions
18524| [1005068] Microsoft NTFS Filesystem in Windows NT and Windows 2000 Has Auditing Hole That Lets Local Users Access Files Without the File Access Being Audited
18525| [1004587] Microsoft SQL Server 2000 Buffer Overflow in OpenDataSource() Function May Let Remote Users Gain SYSTEM Privileges on the Server
18526| [1004528] Microsoft SQLXML Component of Microsoft SQL Server 2000 Contains an Input Validation Flaw in an XML SQL Tag That Allows Cross-Site Scripting Attacks
18527| [1004527] Microsoft SQLXML Component of Microsoft SQL Server 2000 Contains a Buffer Overflow That Lets Remote Users Take Full Control of the System
18528| [1004407] Microsoft Exchange 2000 Flaw in Processing a Certain Malformed SMTP Command Allows Remote Users to Deny Service to the Server
18529| [1004357] Microsoft Windows Debugging Facility for Windows NT4 and 2000 Has Authentication Hole That Lets Local Users Execute Arbitrary Code with SYSTEM Privileges
18530| [1004083] Microsoft Windows 2000 'microsoft-ds' Service Flaw Allows Remote Users to Create Denial of Service Conditions By Sending Malformed Packets
18531| [1004022] Microsoft Windows 2000 Group Policy Object Enforcement Can Be Circumvented if User License Limits are Exceeded
18532| [1003975] Microsoft Windows NT, 2000, and XP Kernel Buffer Overflow in Processing Multiple UNC Provider (MUP) Requests May Let Local Users Obtain System Level Privileges
18533| [1003949] Microsoft Windows 2000 DCOM Implementation Flaw May Disclose Memory Contents to Remote Users
18534| [1003816] Microsoft Windows 2000 Automatic Log Off Policy Fails to Expire Sessions in Progress
18535| [1003688] Microsoft Exchange Server 2000 Command Processing Bug Lets Remote Users Cause the SMTP Service to Crash
18536| [1003687] Microsoft Windows 2000 and Windows XP SMTP Service Command Processing Bug Lets Remote Users Cause the SMTP Service to Crash
18537| [1003634] Microsoft XML Core Services in SQL Server 2000 Lets Remote Scripts Access and Send Local Files
18538| [1003629] Microsoft Commerce Server 2000 AuthFilter Buffer Overflow Lets Remote Users Execute Arbitrary Code on the Server With LocalSystem Privileges to Gain Full Control of the Server
18539| [1003472] Microsoft Telnet Server for Windows 2000 and for Interix Has a Buffer Overflow That May Let Remote Users Execute Code on the Server with System Level Privileges
18540| [1003469] Microsoft Exchange 2000 Server Allows Remote Users to View and Possibly Modify Registry Settings
18541| [1003402] Microsoft Windows NT 4.0 and Windows 2000 Domain Controllers May Give Elevated Privileges to Remote Users Who Are Valid Administrators on Other Trusted Domains
18542| [1002922] Microsoft Windows 2000 Internet Key Exchange (IKE) Service Can Be Crashed By Remote Users
18543| [1002754] Terminal Services on Microsoft Windows 2000 and XP Allow Remote Users to Log Bogus IP Addresses Instead of the User's Genuine Address
18544| [1002731] Microsoft Windows 2000 RunAs Service May Disclose Authentication Credentials to Local Users
18545| [1002730] Microsoft Windows 2000 RunAs Utility May Disclose Sensitive Information to Local Users
18546| [1002729] Microsoft Windows 2000 RunAs Service Allows Local Users to Disable the Service
18547| [1002356] Microsoft Outlook 2000 Animated Assistant Prevents the Screen Saver from Activating, Allowing Physically Local Users to Access the System
18548| [1002206] Microsoft Internet Security and Acceleration (ISA) Server 2000 Can Be Disrupted By Remote Users Due to Memory Leaks and Also Allows Cross-Site Scripting Attacks
18549| [1002106] Microsoft Windows 2000 and Windows NT 4.0 RPC Input Validation Failure Lets Remote Users Destabilize the Operating System
18550| [1002099] Microsoft Windows 2000 Telnet Service Can Be Crashed By Remote Users
18551| [1002098] Windows Terminal Services in Microsoft Windows 2000 and NT 4.0 Can Be Crashed By Remote Users Due to a Memory Leak
18552| [1001993] Microsoft Windows 2000, Linux 2.4, NetBSD, FreeBSD, and OpenBSD May Let Remote Users Affect TCP Performance
18553| [1001931] Microsoft Windows 2000 SMTP Service May Allow Unauthorized Remote Users to Relay E-mail via the Service
18554| [1001832] Microsoft Windows 2000 LDAP Server Lets Remote Users Gain Administrator Access to the Domain Controller When Configured to Support LDAP over SSL
18555| [1001701] Microsoft Windows 2000 Telnet Server Allows Local Users to Gain System-Level Privileges and Lets Remote Users Crash the Server
18556| [1001605] Microsoft Windows 2000 Allows Local Users to Elevate Privileges
18557| [1001565] Microsoft IIS Web Server on Windows 2000 Allows Remote Users to Cause the Server to Consume All Available Memory Due to Memory Leak in WebDAV Lock Method
18558| [1001513] Microsoft Windows 2000 Indexing Service Allows Remote Users to View Include Programming Files
18559| [1001501] Microsoft Windows 2000 Domain Controllers Can Be Effectively Halted By Remote Users
18560| [1001464] Microsoft Internet Information Server IIS 5.0 for Windows 2000 Lets Remote Users Execute Arbitrary Code on the Server and Gain Control of the Server
18561| [1001240] Microsoft FTP Client for Windows 2000 Still Vulnerable to Executing Arbitrary Code in Limited Situations
18562| [1001088] Microsoft Internet Explorer with Services for Unix 2.0 Can Create Malicious Files on the User's Host
18563|
18564| OSVDB - http://www.osvdb.org:
18565| [90257] Microsoft Windows Server 2003 ICACLS.EXE Permission Inheritance Weakness
18566| [86790] Microsoft Virtual PC 2007 Crafted x86 Instruction Sequence Handling Local DoS
18567| [86061] Microsoft Windows Server 2008 R1 CSRSS ReadConsole / CloseHandle Local DoS
18568| [79442] Microsoft Windows Server 2008 DNS Server Service Cache Update Policy Deleted Domain Name Resolving Weakness
18569| [72670] Microsoft Windows Server 2003 ActiveDirectory BROWSER ELECTION Remote Overflow
18570| [68554] Microsoft Windows Server 2008 Shared Cluster Disks Addition Default Permission Weakness
18571| [62251] Microsoft Windows Server 2008 Hyper-V Crafted Instruction Sequence DoS
18572| [60329] Microsoft Windows 2000 NetBIOS Continuation Packet Remote DoS
18573| [59733] Microsoft Windows 2000 Terminal Services Screensaver Screen Minimization Locking Weakness
18574| [59731] Microsoft Windows 2000 DCOM Client Alter Context Request Remote Information Disclosure
18575| [59730] Microsoft Windows 2000 Terminal Services Disconnect Feature Local Privilege Escalation
18576| [59514] Microsoft Windows 2000 Task Manager Uppercase Process Name Termination Weakness
18577| [59509] Microsoft Windows 2000 Encrypted File System Cleartext Backup File Local Disclosure
18578| [59346] Microsoft Windows 2000 Crafted TCP/UDP Traffic CPU Consumption Remote DoS
18579| [55836] Microsoft ISA Server 2006 Radius OTP Security Bypass
18580| [53663] Microsoft Office Word 2000 WordPerfect 6.x Converter Document Handling Stack Corruption
18581| [50589] Microsoft SQL Server 2000 sp_replwritetovarbin() Stored Procedure Overflow
18582| [37629] Microsoft Windows 2000 RPC Authentication Unspecified Information Disclosure
18583| [37628] Microsoft Windows 2000 RPC Authentication Crafted Request Remote DoS
18584| [36034] Microsoft Office 2000 Controllo ActiveX (OUACTRL.OCX) HelpPopup Method Overflow
18585| [34489] Microsoft Office 2003 Malformed WMF File Handling DoS
18586| [34488] Microsoft Excel 2003 XLS Handling Corrupt Format DoS
18587| [31251] Microsoft Office 2003 Brazilian Portuguese Grammar Checker Arbitrary Code Execution
18588| [29529] Microsoft Windows 2000 creator.dll ActiveX COM Object Memory Corruption
18589| [29528] Microsoft Windows 2000 msdxm.ocx ActiveX COM Object Memory Corruption
18590| [29527] Microsoft Windows 2000 myinfo.dll ActiveX COM Object Memory Corruption
18591| [29526] Microsoft Windows 2000 ciodm.dll ActiveX COM Object Memory Corruption
18592| [28539] Microsoft Word 2000 Unspecified Code Execution
18593| [24121] Microsoft Commerce Server 2002 authfiles/login.asp Authentication Bypass
18594| [24081] Microsoft Outlook 2003 Unspecified Malformed Word Attachment DoS
18595| [23484] Microsoft SQLServer 2000 sp_addalias Procedure Privileged Alias Creation
18596| [23234] Microsoft SQLServer 2000 Unspecified Invalid Client Buffer DoS
18597| [23231] Microsoft SQL Server 2000 SQL Profiler Multiple Method DoS
18598| [23205] Microsoft SQLServer 2000 Crafted Sort Command User Mode Scheduler (UMS) Bypass DoS
18599| [23203] Microsoft SQL Server 2000 Database Name Transact-SQL Statement Privilege Escalation
18600| [23202] Microsoft SQLServer 2000 sysmembers Virtual Table Query Overflow
18601| [23201] Microsoft SQL Server 2000 Dynamic Transact-SQL Statement Disclosure
18602| [23200] Microsoft SQLServer 2000 Encrypted Stored Procedure Dynamic Query Disclosure
18603| [21907] Microsoft Office InfoPath 2003 Mshtml.dll Form Handling DoS
18604| [21598] Microsoft Windows 2000 NetBIOS Port Malformed TCP Packet Parsing Remote DoS
18605| [20256] Microsoft Windows 2000 NTFS Volume Macintosh Client Directory Permission Modification
18606| [20222] Microsoft Windows 2000 runas.exe Named Pipe Spoofing Information Disclosure
18607| [20221] Microsoft Windows 2000 runas.exe Named Pipe Single Thread DoS
18608| [20220] Microsoft Windows 2000 runas.exe Cleartext Authentication Information Disclosure
18609| [20002] Microsoft Windows 2000 CHKDSK Fix Mode File ACL Failure
18610| [20001] Microsoft Windows 2000 Terminal Service Client Connection IP Logging Failure
18611| [20000] Microsoft Windows 2000 Domain Administrator Computer Lock Bypass
18612| [19999] Microsoft Windows 2000 FQDN Domain Login Password Expiry Bypass
18613| [19998] Microsoft Windows 2000 UPN Credentialed Login Group Policy Failure
18614| [19997] Microsoft Windows 2000 WideCharToMultiByte Function String Termination Issue
18615| [19996] Microsoft Windows 2000 Event ID 1704 Group Policy Failure
18616| [19995] Microsoft Windows 2000 SECEDIT Long Folder ACL Set Issue
18617| [19994] Microsoft Windows 2000 audit directory service access 565 Event Logging Failure
18618| [19993] Microsoft Windows 2000 LDAPS CA Trust Issue
18619| [19264] Microsoft Exchange Server 2003 Crafted IMAP4 Folder Listing Request DoS
18620| [17031] Microsoft ISA Server 2000 SecureNAT Traffic Saturation DoS
18621| [15343] Microsoft Windows Server 2003 Malformed HTTP Cookie Header CGI DoS
18622| [15341] Microsoft Windows Server 2003 SMB Redirector Processing DoS
18623| [15340] Microsoft Windows Server 2003 Terminal Service Client Print DoS
18624| [15338] Microsoft Windows Server 2003 Terminal Session Close DoS
18625| [15337] Microsoft Windows Server 2003 CreateProcessWithLogonW() Function Process Disclosure
18626| [15336] Microsoft Windows Server 2003 Shutdown.exe Shut Down Failure
18627| [15335] Microsoft Windows Server 2003 MIT Kerberos Realm Authentication Group Policy Failure
18628| [15334] Microsoft Windows Server 2003 Shared Folder Permission Weakness
18629| [15333] Microsoft Windows Server 2003 EFS File Copy LDAP Connection DoS
18630| [15332] Microsoft Windows Server 2003 Citrix Metaframe Encryption Policy Failure
18631| [15331] Microsoft Windows Server 2003 Home Folder Path Permission Inheritance Failure
18632| [14617] Microsoft Exchange Server 2003 Folder Handling DoS
18633| [14430] Microsoft Commerce Server 2000 Profile Service Affected API Overflow
18634| [13996] Microsoft Windows 2000 IKE Malformed Packet Saturation Remote DoS
18635| [13762] Microsoft 2000 Domain Controller Directory Service Restore Mode Blank Password
18636| [13761] Microsoft Exchange 2000 Malformed URL Request DoS
18637| [13475] Microsoft Windows 2000 Telnet Service Predictable Named Pipe Arbitrary Command Execution Variant
18638| [13474] Microsoft Windows 2000 Telnet Service Predictable Named Pipe Arbitrary Command Execution
18639| [13441] Microsoft Windows 2000 Security Interface Change Password Option Account Enumeration
18640| [13437] Microsoft Windows 2000 Debug Register Local Privilege Escalation
18641| [13424] Microsoft Windows 2000 Current Password Change Policy Bypass
18642| [13423] Microsoft Windows 2000 Terminal Server SYSVOL Share Connection Saturation Restriction Bypass
18643| [13415] Microsoft Windows 2000 System Root Folder Search Path Permission Weakness
18644| [13410] Microsoft Windows 2000 Accessibility Utility Manager Arbitrary Code Execution
18645| [11958] Microsoft Outlook 2003 Image Rendering Security Policy Bypass
18646| [11945] Microsoft Outlook 2002 IFRAME Tag Embedded URL
18647| [11944] Microsoft Outlook 2002 HREF Tag Embedded JavaScript Execution
18648| [11750] Microsoft Windows 2000 Message Queue Manager Queue Registration Request Overflow DoS
18649| [11712] Microsoft ISA Server 2000 H.323 Filter Overflow
18650| [10633] Microsoft Windows 2000 Protected Store Weak Encryption Default
18651| [9386] Microsoft Windows 2000 msinfo32.exe msinfo_file Variable Overflow
18652| [8243] Microsoft SMS Port 2702 DoS
18653| [7202] Microsoft PowerPoint 2000 File Loader Overflow
18654| [7179] Microsoft Windows 2000 Event Viewer Snap-in Overflow
18655| [6971] Microsoft ISA Server 2000 ICMP Rule Bypass During Startup
18656| [6970] Microsoft ISA Server 2000 Web Publishing Unencrypted Credentials Disclosure
18657| [6969] Microsoft ISA Server 2000 Invalid DNS Request DoS
18658| [6968] Microsoft ISA Server 2000 FTP Port Scan Bounce Weakness
18659| [6967] Microsoft ISA Server 2000 UDP Packet Winsock DoS
18660| [6965] Microsoft ISA Server 2000 SSL Packet DoS
18661| [6964] Microsoft ISA Server 2000 DNS Intrusion Detection Filter DoS
18662| [6515] Microsoft Windows 2000 Domain Expired Account Authentication
18663| [5179] Microsoft Windows 2000 microsoft-ds DoS
18664| [5171] Microsoft Word 2002 Mail Merge Tool Execute Arbitrary Script
18665| [4779] Microsoft Desktop Engine (MSDE) 2000 Stored Procedure SQL Injection
18666| [4778] Microsoft SQL Server 2000 Stored Procedure SQL Injection
18667| [4777] Microsoft Desktop Engine (MSDE) 2000 Database Consistency Checkers (DBCCs) Overflow
18668| [4776] Microsoft SQL Server 2000 Database Consistency Checkers (DBCCs) 2000 Overflow
18669| [4170] Microsoft Windows 2000 Server Media Services TCP Packet Handling Remote DoS
18670| [4168] Microsoft Outlook 2002 mailto URI Script Injection
18671| [3490] Microsoft Exchange 2003 OWA Mailbox Access Information Disclosure
18672| [2705] Microsoft Windows 2000 Windows Troubleshooter ActiveX Overflow
18673| [2655] Microsoft Windows Server 2003 Shell Folders Arbitrary File Access
18674| [2540] Microsoft Windows 2003 Server Buffer Overflow Protection Mechanism Bypass
18675| [2244] Microsoft Windows 2000 ShellExecute() API Let
18676| [2237] Microsoft Windows 2000 Active Directory Lsass.exe Overflow
18677| [1949] Symantec Norton Anti-Virus for Microsoft Exchange 2000 INBOX Path Information Disclosure
18678| [1764] Microsoft Windows 2000 Domain Controller DoS
18679| [1758] Microsoft Windows 2000 Network DDE Escalated Privileges
18680| [1755] Microsoft Windows 2000 RDP Malformed Packet Handling Remote DoS
18681| [1672] Microsoft Windows 2000 Telnet Session Timeout DoS
18682| [1633] Microsoft Windows 2000 System Monitor ActiveX LogFileName Parameter Validation Overflow
18683| [1621] Microsoft Indexing Services for Windows 2000 .htw XSS
18684| [1591] Microsoft Windows 2000 OEMPreinstall Installation Permission Weakness
18685| [1578] Microsoft Windows 2000 Simplified Chinese IME Local Privilege Escalation
18686| [1500] Microsoft Word / Excel / Powerpoint 2000 Object Tag Buffer Overflow
18687| [1437] Microsoft Windows 2000 Telnet Server Binary Zero Parsing Remote DoS
18688| [1399] Microsoft Windows 2000 Windows Station Access
18689| [1328] Microsoft Office 2000 UA Control ActiveX (Ouactrl.ocx) Show Me Function Remote Code Execution
18690| [1297] Microsoft Windows 2000 Active Directory Object Attribute
18691| [1292] Microsoft Windows NT 4.0 / 2000 cmd.exe Buffer Overflow
18692| [773] Microsoft Windows 2000 Group Policy File Lock DoS
18693| [515] Microsoft Windows 2000 LDAP Server Arbitrary User Password Modification
18694| [454] Microsoft Windows 2000 NTLM Domain Account Lockout Policy Bypass
18695| [403] Microsoft Windows 2000 Still Image Service WM_USER Message Local Overflow
18696| [398] Microsoft Windows 2000 Malformed RPC Traffic Local Security Policy Corruption DoS
18697| [307] Microsoft FrontPage 2000 Server Extensions shtml.exe Path Disclosure
18698| [69085] Microsoft Office 2010 RTF File Handling pFragments Buffer Overflow Arbitrary Code Execution
18699|_
18700113/tcp closed ident
18701139/tcp closed netbios-ssn
18702443/tcp open ssl/http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
18703|_http-server-header: Microsoft-HTTPAPI/2.0
18704| vulscan: VulDB - https://vuldb.com:
18705| [141625] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 DirectX memory corruption
18706| [141624] Microsoft Windows 7 SP1/Server 2008 R2 SP1 Graphics Component information disclosure
18707| [139966] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Kernel information disclosure
18708| [139923] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Graphics Component information disclosure
18709| [139905] Microsoft Windows Server 2008 SP2 DHCP Server memory corruption
18710| [137573] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
18711| [137567] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
18712| [137566] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
18713| [137565] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
18714| [137564] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
18715| [136343] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
18716| [136342] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
18717| [136341] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
18718| [136316] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
18719| [136315] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
18720| [136313] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
18721| [136311] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
18722| [136309] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
18723| [136302] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
18724| [136298] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure
18725| [136297] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Win32k memory corruption
18726| [131683] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Win32k memory corruption
18727| [131642] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Active Directory privilege escalation
18728| [127822] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2012 Kernel information disclosure
18729| [125103] Microsoft Windows Server 2008 SP2 Graphics Component information disclosure
18730| [123853] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Kernel Memory information disclosure
18731| [122858] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 LNK memory corruption
18732| [122833] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI+ memory corruption
18733| [121109] Microsoft Wireless Display Adapter V2 2.0.8350/2.0.8365/2.0.8372 privilege escalation
18734| [120449] Microsoft Forefront Unified Access Gateway 2000 InitParams.aspx Parameter Server-Side Request Forgery
18735| [119469] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Kernel privilege escalation
18736| [116015] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1 memory corruption
18737| [114563] Microsoft Office 2007 SP3/2010 SP2/2013/2013 RT SP1 memory corruption
18738| [114528] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI privilege escalation
18739| [114524] Microsoft ASP.NET Core 2.0 denial of service
18740| [114523] Microsoft ASP.NET Core 2.0 Kestrel Web Application privilege escalation
18741| [113257] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2012 Kernel information disclosure
18742| [113256] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2012 Kernel information disclosure
18743| [113255] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2012 Kernel information disclosure
18744| [113247] Microsoft Windows 7 SP1/Server 2008 R2 SP1 EOT Font Engine information disclosure
18745| [113246] Microsoft Windows 7 SP1/Server 2008 R2 SP1 EOT Font Engine information disclosure
18746| [113245] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2012 EOT Font Engine information disclosure
18747| [113244] Microsoft Windows 7 SP1/Server 2008 R2 SP1 EOT Font Engine information disclosure
18748| [113235] Microsoft Outlook 2007 SP3/2010 SP2/2013 SP1/2016 privilege escalation
18749| [113234] Microsoft Office 2007 SP2/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
18750| [113216] Microsoft Outlook 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
18751| [112285] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
18752| [112284] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
18753| [112283] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
18754| [112282] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
18755| [111578] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
18756| [111577] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
18757| [111576] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
18758| [111575] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
18759| [111574] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
18760| [111573] Microsoft Office 2007/2010/2013/2016 Equation Editor memory corruption
18761| [111572] Microsoft Office 2007/2010/2013/2016 Equation Editor memory corruption
18762| [111570] Microsoft Office 2007/2010/2013/2016 Equation Editor memory corruption
18763| [111568] Microsoft Excel 2007/2010/2013/2016 memory corruption
18764| [111566] Microsoft Word 2007/2010/2013/2016 memory corruption
18765| [111565] Microsoft Word 2007/2010/2013 Email Message memory corruption
18766| [111563] Microsoft Outlook 2007/2010/2013/2016 Email Message privilege escalation
18767| [111347] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Color Management Icm32.dll information disclosure
18768| [109388] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2016 memory corruption
18769| [109387] Microsoft ASP.NET Core 2.0 privilege escalation
18770| [109386] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
18771| [109385] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 Security Feature Macro privilege escalation
18772| [109381] Microsoft Office/Word 2007 SP3/2010 SP2 memory corruption
18773| [107703] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
18774| [106530] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
18775| [106528] Microsoft PowerPoint 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
18776| [106515] Microsoft Publisher 2007 SP3/2010 SP2 memory corruption
18777| [106497] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Uniscribe memory corruption
18778| [106476] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
18779| [106475] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
18780| [105051] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Font Library privilege escalation
18781| [105032] Microsoft Internet Explorer 9/10 on Server 2008/Server 2012 memory corruption
18782| [102513] Microsoft Windows Server 2003 SP2/XP SP3 OLE olecnv32.dll privilege escalation
18783| [102512] Microsoft Windows Server 2003 SP2/XP SP3 rpc privilege escalation
18784| [102511] Microsoft Windows Server 2003 SP2/XP SP3 RDP EsteemAudit privilege escalation
18785| [102447] Microsoft PowerPoint/SharePoint Server 2007 SP3 privilege escalation
18786| [102444] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 privilege escalation
18787| [102442] Microsoft Outlook 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 Bypass privilege escalation
18788| [102441] Microsoft Outlook 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
18789| [102401] Microsoft Windows 7 SP1/Server 2008 R2 SP1 GDI USP10!NextCharInLiga Uniscribe Font information disclosure
18790| [101491] Microsoft Windows up to XP SP3/Server 2003 SP2 Remote Desktop Protocol gpkcsp.dll memory corruption
18791| [101017] Microsoft Office 2007 SP3/2010 SP2/2016 memory corruption
18792| [101012] Microsoft Office 2007 SP3/2010 SP2/2011/2013 SP1/2016 memory corruption
18793| [101011] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 ActiveX Object Memory memory corruption
18794| [100854] Microsoft Windows Server 2003 SP2 RRAS ERRATICGOPHER memory corruption
18795| [99904] Microsoft Windows Server 2003 SP2/XP SP3 SmartCard Authentication RDP Packet EsteemAudit privilege escalation
18796| [99698] Microsoft OneNote 2007 SP3/2010 SP2 DLL Loader privilege escalation
18797| [99684] Microsoft Excel 2007 SP3/2010 SP2 Memory information disclosure
18798| [99654] Microsoft Outlook 2007 SP3/2010 SP2/2011/2013 SP1/2016 Email Message privilege escalation
18799| [99653] Microsoft Outlook 2007 SP3/2010 SP2/2011/2013 SP1/2016 Email Message privilege escalation
18800| [99533] Microsoft Office 2007/2010/2013/2016 RTF Document Necurs Dridex memory corruption
18801| [98561] Microsoft IIS 6.0 on Windows Server 2003 WebDAV ScStoragePathFromUrl Long Header memory corruption
18802| [98092] Microsoft SharePoint Server 2007 SP3 memory corruption
18803| [98088] Microsoft SharePoint Server 2007 SP3 memory corruption
18804| [98087] Microsoft Office 2007 SP3/2010 SP2 memory corruption
18805| [98086] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
18806| [98085] Microsoft Excel 2007 SP3 memory corruption
18807| [98084] Microsoft Word 2007 SP3/2010 SP2/2011 memory corruption
18808| [98083] Microsoft Word 2007 SP3/2010 SP2/2011 memory corruption
18809| [98078] Microsoft Word/Excel 2007 SP3 memory corruption
18810| [98072] Microsoft Office 2007 SP3/2010 SP2/Word Viewer Graphics Component privilege escalation
18811| [98071] Microsoft Office 2007 SP3/2010 SP2/Word Viewer GDI+ information disclosure
18812| [98070] Microsoft Office 2007 SP3/2010 SP2/Word Viewer GDI+ information disclosure
18813| [94450] Microsoft Office 2007 SP3/2010 SP2/2011 memory corruption
18814| [94449] Microsoft Office 2007 SP3/2010 SP2/2011/2013 SP1 information disclosure
18815| [94448] Microsoft Office 2007 SP3/2010 SP2/2011/2013 SP1 information disclosure
18816| [94445] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1 information disclosure
18817| [94441] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 privilege escalation
18818| [94440] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
18819| [94439] Microsoft Office 2007 SP3/2011 privilege escalation
18820| [94438] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 privilege escalation
18821| [93542] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1 memory corruption
18822| [93541] Microsoft Office 2007 SP3 denial of service
18823| [93539] Microsoft Office 2007/2010 SP2/2011 memory corruption
18824| [93538] Microsoft Office 2007/2010 SP2/2011/2013 SP1 memory corruption
18825| [93537] Microsoft Office 2007/2010 SP2/2011 memory corruption
18826| [93396] Microsoft Office 2007/2010/2011 memory corruption
18827| [93395] Microsoft Office 2007/2010/2011 memory corruption
18828| [93394] Microsoft Office 2007/2010 memory corruption
18829| [92596] Microsoft Windows 7 SP1/Server 2008 R2/Server 2008 SP2/Vista SP2 Internet Messaging API File information disclosure
18830| [91554] Microsoft Exchange 2007/2010/2013/2016 Email information disclosure
18831| [91553] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
18832| [91552] Microsoft Office 2007/2010/2013/2013 RT/2016 spoofing
18833| [91551] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
18834| [91549] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
18835| [91548] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
18836| [91546] Microsoft Office 2007/2010/2013/2013 RT memory corruption
18837| [91545] Microsoft Office 2007/2010 memory corruption
18838| [91544] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
18839| [91542] Microsoft Office 2007/2010/2013/2013 RT/2016 information disclosure
18840| [90707] Microsoft OneNote 2007/2010/2013/2013 RT/2016 information disclosure
18841| [90706] Microsoft Office 2007/2010/2013/2013 RT Graphics memory corruption
18842| [90705] Microsoft Office 2007/2010/2011 memory corruption
18843| [90703] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
18844| [89039] Microsoft Office 2007 SP3/2010 SP2/2011/2013 RT SP1/2013 SP1 memory corruption
18845| [89034] Microsoft Windows Server 2008/Vista SP2 JScript/VBScript memory corruption
18846| [87960] Microsoft Windows Server 2008 R2/Server 2012/Server 2012 R2 Active Directory denial of service
18847| [87955] Microsoft Exchange 2007/2010/2013/2016 Oracle Outside In Libraries privilege escalation
18848| [87954] Microsoft Exchange 2007/2010/2013/2016 Oracle Outside In Libraries privilege escalation
18849| [87953] Microsoft Exchange 2007/2010/2013/2016 Oracle Outside In Libraries privilege escalation
18850| [87939] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 OLE DLL memory corruption
18851| [87938] Microsoft Office 2007 SP3/2010 SP2/2011 information disclosure
18852| [87937] Microsoft Office 2007 SP3/2010 SP2/2011 memory corruption
18853| [87935] Microsoft Windows Server 2008 R2 SP1/Server 2008 SP2/Vista SP2 VBScript/JScript memory corruption
18854| [87934] Microsoft Windows Server 2008 R2 SP1/Server 2008 SP2/Vista SP2 VBScript/JScript memory corruption
18855| [87933] Microsoft Windows Server 2008 R2 SP1/Server 2008 SP2/Vista SP2 VBScript/JScript memory corruption
18856| [87147] Microsoft Office 2007/2010 memory corruption
18857| [87145] Microsoft Windows Server 2008/Vista SP2 JScript/VBScript memory corruption
18858| [87144] Microsoft Windows Server 2008/Vista SP2 JScript/VBScript memory corruption
18859| [82228] Microsoft Excel 2007 SP3/2010 SP2 Office Document memory corruption
18860| [82225] Microsoft Word 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1 Office Document memory corruption
18861| [82224] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 Office Document memory corruption
18862| [81273] Microsoft Office 2007/2010/2013/2016 memory corruption
18863| [81272] Microsoft Office 2007/2010/2013 memory corruption
18864| [81265] Microsoft Windows Server 2008/Vista SP2 Library Loader memory corruption
18865| [80872] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
18866| [80871] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
18867| [80869] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
18868| [79506] Microsoft Windows 7/Server 2008/Server 2008 R2/Vista Library Loader memory corruption
18869| [79505] Microsoft Office 2007 memory corruption
18870| [79504] Microsoft Office 2007/2010/2013/2016 memory corruption
18871| [79503] Microsoft Office 2007/2010/2013 memory corruption
18872| [79502] Microsoft Office 2007/2010/2011 memory corruption
18873| [79501] Microsoft Office 2007/2010 memory corruption
18874| [79499] Microsoft Windows 7/Server 2008 R2 Uniscribe memory corruption
18875| [79493] Microsoft Windows Server 2008/Vista Graphics memory corruption
18876| [79190] Microsoft Word 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 Office Document memory corruption
18877| [79189] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1/2016 Office Document memory corruption
18878| [79187] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2016 Sandbox privilege escalation
18879| [79167] Microsoft Windows 7/Server 2008/Server 2008 R2/Vista Journal memory corruption
18880| [78372] Microsoft Visio 2007 SP3/2010 SP2 UML Data memory corruption
18881| [78371] Microsoft SharePoint Server 2007 SP3/2010 SP2 InfoPath Forms Services XXE information disclosure
18882| [77646] Microsoft Office 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1 EPS Image memory corruption
18883| [77629] Microsoft Excel 2007 SP3/2010 SP2/2011/2016 Office Document memory corruption
18884| [77627] Microsoft Excel 2007 SP3/2010 SP2 Office Document memory corruption
18885| [77626] Microsoft Excel 2007 SP3/2010 SP2/2011/2016 Office Document memory corruption
18886| [77617] Microsoft Office 2007 SP3/2010 SP2 OpenType Font memory corruption
18887| [77252] Microsoft Office 2007 SP3/2010 SP2 Office Graphics Library Font memory corruption
18888| [77038] Microsoft Windows Server 2008 SP2 UDDI Services cross site scripting
18889| [76497] Microsoft PowerPoint 2007 SP3/2010 SP2/2013 SP1 Office Document memory corruption
18890| [76491] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1 Office Document memory corruption
18891| [76467] Microsoft Word 2007 SP3/2010 SP2/2011/2013 RT SP1/2013 SP1 Office Document memory corruption
18892| [76466] Microsoft Word 2007 SP3/2010 SP2/2011/2013 RT SP1/2013 SP1 Office Document memory corruption
18893| [76464] Microsoft Excel 2007 SP3/2010 SP2/2013 RT SP1/2013 SP1 Office Document memory corruption
18894| [76463] Microsoft Excel 2007 SP3/2010 SP2/2011/2013 RT SP1/2013 SP1 Office Document memory corruption
18895| [76449] Microsoft Windows 8/8.1/Server 2008/Server 2012/Server 2012 R2 Hyper-V memory corruption
18896| [76440] Microsoft SQL Server 2008/2008 R2/2012/2014 Virtual Function Uninitialized Memory memory corruption
18897| [76439] Microsoft SQL Server 2008/2008 R2/2012/2014 Uninitialized Memory memory corruption
18898| [76438] Microsoft SQL Server 2008/2008 R2/2012/2014 Pointer Casting privilege escalation
18899| [75783] Microsoft Windows Server 2008/Server 2012 Active Directory Federation Services cross site scripting
18900| [75338] Microsoft SharePoint 2007/2010/2013 Content privilege escalation
18901| [75337] Microsoft Office 2007 SP3/2010 SP2/2011/2013 RT SP1/2013 SP1 memory corruption
18902| [75336] Microsoft Office 2007 SP3/2010 SP2/2011/2013 RT SP1/2013 SP1 memory corruption
18903| [74845] Microsoft Office 2007/2010/2013 Document Use-After-Free memory corruption
18904| [74844] Microsoft Office 2007/2010 Document Use-After-Free memory corruption
18905| [74837] Microsoft Office 2007/2010/2011/2013 RTF Document Use-After-Free privilege escalation
18906| [73979] Microsoft Exchange Server 2003 CU7/2003 SP1 Meeting privilege escalation
18907| [73978] Microsoft Exchange Server 2003 CU7/2003 SP1 cross site scripting
18908| [73977] Microsoft Exchange Server 2003 CU7/2003 SP1 cross site scripting
18909| [73976] Microsoft Exchange Server 2003 CU7/2003 SP1 cross site scripting
18910| [73975] Microsoft Exchange Server 2003 CU7/2003 SP1 cross site scripting
18911| [73964] Microsoft SharePoint 2007/2010/2013 cross site scripting
18912| [69158] Microsoft Office 2007/2010/2013 Use-After-Free memory corruption
18913| [69157] Microsoft Office 2007/2010/2013 OneTableDocumentStream memory corruption
18914| [68416] Microsoft Exchange 2007/2010/2013 Outlook Web Access Token spoofing
18915| [68409] Microsoft Office 2007/2010/2013 Use-After-Free memory corruption
18916| [68408] Microsoft Excel 2007/2010/2013 memory corruption
18917| [68407] Microsoft Excel 2007/2010 memory corruption
18918| [68405] Microsoft Word 2007/2010 Index Use-After-Free memory corruption
18919| [68195] Microsoft Windows 7/Server 2003/Server 2008/Vista Input Method Editor Sandbox privilege escalation
18920| [68189] Microsoft Windows Server 2003 SP2 TCP/IP Stack Stack-Based memory corruption
18921| [68188] Microsoft Word 2007 File memory corruption
18922| [68187] Microsoft Word 2007 File memory corruption
18923| [68186] Microsoft Word 2007 File memory corruption
18924| [67829] Microsoft Office 2007/2010/2011 Object memory corruption
18925| [67825] Microsoft .NET Framework 2.0/3.5/3.5.1 ASLR privilege escalation
18926| [71337] Microsoft Office 2000/2004/XP memory corruption
18927| [67355] Microsoft OneNote 2007 File Processing privilege escalation
18928| [67354] Microsoft SQL Server 2008 R2 SP2/2008 SP3/2012 SP1/2014 SQL Master Data Services cross site scripting
18929| [67353] Microsoft SQL Server 2008 R2 SP2/2008 SP3/2012 SP1/2014 T-SQL Query Stack-Based memory corruption
18930| [67018] Microsoft Windows Server 2008/Server 2012/Server 2012 R2 Service Bus AMQP Message denial of service
18931| [13545] Microsoft Word 2007 Embedded Font memory corruption
18932| [13397] Microsoft Windows 2000/Server 2003/XP DHCP Response DHCP ACK spoofing
18933| [13462] Microsoft Visual Studio 2002/2003/2005/2010 Debug Interface msdia.dll PDB File memory corruption
18934| [13229] Microsoft Office 2007/2010/2013 Common Control Library MSCOMCTL.OCX privilege escalation
18935| [13227] Microsoft Office 2007/2010/2013 Chinese Grammar Checker Library privilege escalation
18936| [13226] Microsoft SharePoint Server 2007/2010/2013 Page memory corruption
18937| [13225] Microsoft SharePoint Server 2007/2010/2013 cross site scripting
18938| [13224] Microsoft SharePoint Server 2007/2010/2013 Page memory corruption
18939| [12859] Microsoft Word 2003 Office Document Stack-Based memory corruption
18940| [12852] Microsoft Publisher 2003/2007 Publisher File pubconv.dll memory corruption
18941| [12845] Microsoft Word 2003 Office File Stack-Based memory corruption
18942| [12844] Microsoft Word 2007/2010 Office File memory corruption
18943| [12843] Microsoft Office 2007/2010/2011/2013 XML Parser Nested Entities Memory Consumption denial of service
18944| [12687] Microsoft Word/Office/Outlook 2003/2007/2010/2013 RTF Document memory corruption
18945| [12530] Microsoft Windows Server 2003/Server 2008/Server 2012/Vista/XP Security Account Manager Lockout privilege escalation
18946| [12266] Microsoft .NET Framework 2.0 SP2/3.5.1 ASLR Bypass privilege escalation
18947| [12070] Apple Pages 2.0/2.0.1/2.0.2/5.0/5.0.1 on Mac Microsoft Word Document memory corruption
18948| [11950] Microsoft Office Compability Pack/Word 2007 SP3 File memory corruption
18949| [11949] Microsoft Word Viewer/Office Compatibility Pack/Word 2003 SP3/2007 SP3 File memory corruption
18950| [11494] Microsoft .NET Framework 2.0 SP2/3.5.1/4/4.5/4.5.1 MAC Authentication privilege escalation
18951| [11448] Microsoft Office 2007/2010 Address Space Layout Randomization privilege escalation
18952| [11148] Microsoft Office 2003/2007 WordPerfect Document epsimp32.flt memory corruption
18953| [11146] Microsoft Office 2003/2007 epsimp32.flt memory corruption
18954| [11230] Microsoft Word 2003 DOC Document Embedded Image denial of service
18955| [11081] Microsoft Windows Server 2008/Vista TIFF Image memory corruption
18956| [10648] Microsoft Word 2007 Word File memory corruption
18957| [10647] Microsoft Word 2003 Word File memory corruption
18958| [10643] Microsoft SharePoint Server 2007/2010/2013 Input Sanitizer memory corruption
18959| [10642] Microsoft SharePoint Server 2007/2010 Content Display in Frames privilege escalation
18960| [10247] Microsoft SharePoint Server 2007/2010/2013 Online Cloud cross site scripting
18961| [10245] Microsoft Office 2003/2007/2010 Word File memory corruption
18962| [10244] Microsoft Office 2003 SP3 Word File memory corruption
18963| [10243] Microsoft Office 2003/2007 Word File memory corruption
18964| [10242] Microsoft Office 2007 Word File memory corruption
18965| [10241] Microsoft Office 2007 Word File memory corruption
18966| [10240] Microsoft Office 2003/2007/2010 Word File memory corruption
18967| [10239] Microsoft Office 2003/2007 Word File memory corruption
18968| [10238] Microsoft Excel 2003/2007 XML External Entity Data information disclosure
18969| [10237] Microsoft Excel 2003/2007/2010 XML External Entity Data information disclosure
18970| [10236] Microsoft Word/Office 2003/2007 XML External Entity Data information disclosure
18971| [10234] Microsoft Word/Sharepoint 2003 SP3/2007 SP3/2010 SP1 Office File memory corruption
18972| [10232] Microsoft Word/Sharepoint 2003 SP3/2007 SP3/2010 SP1 Office File memory corruption
18973| [10231] Microsoft Word/Sharepoint 2003 SP3/2007 SP3/2010 SP1 Office File memory corruption
18974| [10230] Microsoft Word/Sharepoint 2003 SP3/2007 SP3/2010 SP1 Office File memory corruption
18975| [10229] Microsoft Access 2007/2010/2013 Access File ACCDB File memory corruption
18976| [10228] Microsoft Access 2007/2010/2013 Access File ACCDB File memory corruption
18977| [10227] Microsoft Access 2007/2010/2013 Access File ACCDB File memory corruption
18978| [10192] Microsoft Windows 7/2000/Server 2003 SP2/Vista/XP SP3 Windows Theme File privilege escalation
18979| [10191] Microsoft Windows Server 2003/XP OLE Object privilege escalation
18980| [10190] Microsoft Windows 7/8/Server 2008/Vista Active Directory denial of service
18981| [10189] Microsoft Outlook 2007/2010 S/MIME privilege escalation
18982| [9941] Microsoft Windows Server 2003/XP Unicode Scripts Processor USP10.DLL Uniscribe Font memory corruption
18983| [9929] Microsoft Windows Server 2008/Server 2012 Active Directory Federation Services Unspecified Account information disclosure
18984| [9715] Microsoft PowerPoint 2007 DirectShow Runtime quartz.dll GetMaxSampleSize denial of service
18985| [9397] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 Array privilege escalation
18986| [9394] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 on 64-bit Array memory corruption
18987| [9393] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 Permission privilege escalation
18988| [8738] Microsoft Visio 2003 SP3/2007 SP3/2010 SP1 XML Parser File information disclosure
18989| [8737] Microsoft Word 2003 SP3 Shape Data Parser File memory corruption
18990| [8736] Microsoft Publisher 2003 SP3 PUB File memory corruption
18991| [8735] Microsoft Publisher 2003 SP3/2007 SP3/2010 SP1 PUB File memory corruption
18992| [8734] Microsoft Publisher 2003 SP3 PUB File memory corruption
18993| [8733] Microsoft Publisher 2003 SP3 PUB File memory corruption
18994| [8732] Microsoft Publisher 2003 SP3 PUB File memory corruption
18995| [8731] Microsoft Publisher 2003 SP3 PUB File memory corruption
18996| [8730] Microsoft Publisher 2003 SP3 PUB File memory corruption
18997| [8729] Microsoft Publisher 2003 SP3 PUB File memory corruption
18998| [8728] Microsoft Publisher 2003 SP3 PUB File memory corruption
18999| [8727] Microsoft Publisher 2003 SP3 PUB File memory corruption
19000| [8726] Microsoft Publisher 2003 PUB File Eingabe memory corruption
19001| [8723] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 XML File spoofing
19002| [7643] Microsoft Windows Server 2008 R2/Server 2012 NFS Server NULL Pointer Dereference denial of service
19003| [7642] Microsoft Exchange 2007/2010 Outlook Web Access vspdx.dll) privilege escalation
19004| [7641] Microsoft Windows Server 2003/Server 2008/Vista/XP DirectShow Quartz.dll memory corruption
19005| [8589] Microsoft System Center Operations Manager 2007 R2/2007 SP1 ViewTypeManager.aspx cross site scripting
19006| [7252] Microsoft System Center Operations Manager 2007 ExecuteTask.aspx cross site scripting
19007| [7251] Microsoft System Center Operations Manager 2007 cross site scripting
19008| [7248] Microsoft Windows 7/Server 2008 R2 Print Spooler privilege escalation
19009| [7121] Microsoft Exchange 2007/2010 RSS Feed denial of service
19010| [7118] Microsoft Windows Server 2008 R2/Server 2012 IP-HTTPS unknown vulnerability
19011| [62914] Microsoft Office 2003 SP3/2007 SP3/2008/2010 SP1/2011 Spreadsheet Use-After-Free memory corruption
19012| [7058] Microsoft Windows 7/Server 2008 R2 DHCPv6 Message denial of service
19013| [6935] Microsoft Office Excel 2003/2007/2010 Input Sanitizer File Stack-based memory corruption
19014| [6934] Microsoft Office Excel 2003/2007/2010 Input Sanitizer memory corruption
19015| [6933] Microsoft Office Excel 2003/2007/2010 SerAuxErrBar File memory corruption
19016| [6929] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 Web Proxy Setting Auto-Discovery memory corruption
19017| [6927] Microsoft .NET Framework 2.0 SP2/3.5.1 Trusted Code Function information disclosure
19018| [6918] Microsoft Excel 2007 SP2 Input Sanitizer File memory corruption
19019| [6830] Microsoft Word 2007/2010 File memory corruption
19020| [6819] Microsoft Excel 2007 File memory corruption
19021| [6627] Microsoft Windows 7/Server 2008 R2 Kerberos denial of service
19022| [6626] Microsoft SharePoint/Lync/Infopath 2007/2010 HTML Sanitization cross site scripting
19023| [6621] Microsoft Word 2007 PAPX memory corruption
19024| [62239] Microsoft Systems Management Server 2003 Configuration Manager Reflected cross site scripting
19025| [5945] Microsoft Office 2007/2010 Computer Graphics Metafile memory corruption
19026| [5939] Microsoft Windows 7/Server 2003/Server 2008 R2/Vista/XP Print Spooler Service memory corruption
19027| [5938] Microsoft Windows 7/Server 2003/Server 2008 R2/Vista/XP Remote Administration Protocol netapi32.dll RAP Request denial of service
19028| [5933] Microsoft SQL Server 2000/2005/2008/2008 R2 Common Controls TabStrip ActiveX MSCOMCTL.OCX memory corruption
19029| [5932] Microsoft Office 2003/2007/2010 Common Controls TabStrip ActiveX MSCOMCTL.OCX memory corruption
19030| [5654] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP information disclosure
19031| [5653] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP win32k.sys memory corruption
19032| [5652] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP win32k.sys memory corruption
19033| [5650] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP memory corruption
19034| [5649] Microsoft Office 2003/2007/2010 libraries memory corruption
19035| [5645] Microsoft SharePoint 2007/2010/3.0 Reflected cross site scripting
19036| [5643] Microsoft SharePoint 2007/2010 information disclosure
19037| [5642] Microsoft SharePoint 2007 cross site request forgery
19038| [5553] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP OpenType Font atmfd.dll denial of service
19039| [5524] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP memory corruption
19040| [5518] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 memory corruption
19041| [5362] Microsoft Office 2003/2007 GDI+ memory corruption
19042| [5291] Microsoft Visual Studio 2008 Incremental Linker link.exe ConvertRgImgSymToRgImgSymEx memory corruption
19043| [5268] Microsoft Office 2008 on Mac RTF Pfragment File memory corruption
19044| [5080] Microsoft SQL Server 2005/2008/2008R2 CREATE DATABASE sql injection
19045| [5050] Microsoft Office 2007 WPS Converter Heap-based memory corruption
19046| [5049] Microsoft SQL Server 2000/2005/2008 MSCOMCTL.OCX privilege escalation
19047| [5048] Microsoft Office 2003/2007/2010 MSCOMCTL.OCX privilege escalation
19048| [5046] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Windows Authenticode Signature Verification WinVerifyTrust Signature privilege escalation
19049| [4803] Microsoft Windows Server 2003/Server 2008 DNS Server Domain Resource Record Query Parser denial of service
19050| [4802] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Remote Desktop Protocol denial of service
19051| [4798] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Remote Desktop Service memory corruption
19052| [60205] Microsoft .NET Framework 2.0 SP2/3.5.1 Heap-based memory corruption
19053| [4642] Microsoft .NET Framework 2.0 SP2/3.5.1/4 XAML Browser Application memory corruption
19054| [60065] Microsoft Windows 2000 mod_sql unknown vulnerability
19055| [4535] Microsoft Windows Server 2003/XP Object Packager packager.exe privilege escalation
19056| [4534] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Line21 DirectShow Filter Quartz.dll/Qdvd.dll Media File memory corruption
19057| [4533] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Multimedia Library winmm.dll MIDI File memory corruption
19058| [4507] Microsoft .NET Framework 2.0 SP2/3.5 SP1/3.5.1/4.0 Forms Authentication privilege escalation
19059| [59666] Microsoft Publisher 2003/2007 "Publisher memory corruption
19060| [4482] Microsoft Word 2007/2010/2011 Document Parser memory corruption
19061| [4480] Microsoft Excel 2003 memory corruption
19062| [4478] Microsoft Windows Server 2003/XP OLE Objects Memory Management memory corruption
19063| [4477] Microsoft PowerPoint 2007 SP2/2008 OfficeArt Use-After-Free memory corruption
19064| [4474] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Active Directory Query memory corruption
19065| [4473] Microsoft PowerPoint 2007 SP2/2010 DLL-Loader memory corruption
19066| [4471] Microsoft Office 2003/2007 Publisher Out-of-Bounds memory corruption
19067| [4470] Microsoft Office 2003 SP3 memory corruption
19068| [4453] Microsoft Excel 2003 Record Parser memory corruption
19069| [4446] Microsoft Office 2007/2008 OfficeArt Record Parser memory corruption
19070| [4445] Microsoft Office 2007/2010/2011 Word Document Parser memory corruption
19071| [4438] Microsoft Windows 7/Server 2008/Vista TCP/IP Reference Counter denial of service
19072| [5358] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP TrueType Font Handling memory corruption
19073| [59005] Microsoft Host Integration Server 2004 denial of service
19074| [58492] Microsoft SharePoint Server 2007 Spreadsheet memory corruption
19075| [58491] Microsoft Office 2004/2007/2008/2010/2011 Spreadsheet memory corruption
19076| [58490] Microsoft Office Compatibility Pack 2007 Spreadsheet memory corruption
19077| [58489] Microsoft Office 2004/2007/2008/2010/2011 Spreadsheet memory corruption
19078| [58488] Microsoft Office 2007/2010 memory corruption
19079| [4412] Microsoft Office 2003/2007 Library Loader unknown vulnerability
19080| [4411] Microsoft Excel 2003 memory corruption
19081| [4409] Microsoft Windows Server 2003/Server 2008 WINS unknown vulnerability
19082| [58240] Microsoft Visio 2003/2007 memory corruption
19083| [58237] Microsoft Visio 2003/2007/2010 memory corruption
19084| [4396] Microsoft Windows 7/Server 2008/Vista TCP/IP Stack denial of service
19085| [4393] Microsoft Windows Server 2008 DNS Service memory corruption
19086| [4391] Microsoft .NET Framework 2.0 SP2/3.5.1/4 Socket Restriction privilege escalation
19087| [4390] Microsoft Windows Server 2008 Remote Desktop Web Access cross site scripting
19088| [4388] Microsoft Windows 7/Server 2008/Vista File Metadata Parser denial of service
19089| [57691] Microsoft SQL Server 2008 Web Service information disclosure
19090| [57690] Microsoft Excel 2002/2003 Spreadsheet memory corruption
19091| [57689] Microsoft Excel 2002 Spreadsheet memory corruption
19092| [57688] Microsoft Excel 2002 Spreadsheet memory corruption
19093| [57687] Microsoft Excel 2002/2003/2007 Spreadsheet memory corruption
19094| [57686] Microsoft Excel 2002 Spreadsheet memory corruption
19095| [57685] Microsoft Excel 2002/2003/2007 Array Access memory corruption
19096| [57684] Microsoft Excel 2002/2003/2007/2010 Spreadsheet memory corruption
19097| [4369] Microsoft Excel 2002/2003/2007 memory corruption
19098| [4367] Microsoft Windows Server 2008 Hyper-V VMBus denial of service
19099| [4362] Microsoft Windows 7/Server 2008/Vista denial of service
19100| [57420] Microsoft PowerPoint 2002/2003 memory corruption
19101| [4349] Microsoft Office 2004/2007/2008 Presentation File Parser memory corruption
19102| [4348] Microsoft PowerPoint 2002/2003/2007 memory corruption
19103| [57077] Microsoft Excel 2002 Uninitialized Memory memory corruption
19104| [57078] Microsoft Office 2003/2007/Xp docx unknown vulnerability
19105| [57079] Microsoft PowerPoint 2002/2003/2007/2010 memory corruption
19106| [57076] Microsoft Excel 2002/2003 memory corruption
19107| [57075] Microsoft Excel 2002/2003 memory corruption
19108| [57074] Microsoft Excel 2002 memory corruption
19109| [57073] Microsoft Excel 2002/2003/2007/2010 memory corruption
19110| [4334] Microsoft .NET Framework 2.0 SP2/3.5 SP1/3.5.1/4.0 JIT Compiler memory corruption
19111| [4332] Microsoft PowerPoint 2007/2010 memory corruption
19112| [4301] Microsoft Windows Server 2003 SMB Browser Heap-based denial of service
19113| [56475] Microsoft Office 2004/2008 memory corruption
19114| [56414] Microsoft Visio 2002/2003/2007 ELEMENTS.DLL memory corruption
19115| [56413] Microsoft Visio 2002/2003/2007 Exception ORMELEMS.DLL memory corruption
19116| [4298] Microsoft Windows 7/Server 2008 JScript/VBScript Engine information disclosure
19117| [4297] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP OpenType Compact Font Format Driver privilege escalation
19118| [4296] Microsoft Windows Server 2003/XP LSASS Authentication Request unknown vulnerability
19119| [4295] Microsoft Windows 7/Server 2008 Kerberos weak authentication
19120| [4294] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Driver win32k.sys unknown vulnerability
19121| [4293] Microsoft Windows Server 2003/XP Kerberos CRC32 Checksum privilege escalation
19122| [4292] Microsoft Windows Server 2003/XP CSRSS Logoff privilege escalation
19123| [4289] Microsoft Excel 2007 Shape Data Parser memory corruption
19124| [4286] Microsoft PowerPoint 2002 SP3/2003 SP3/2004/2007 SP2/2008 OfficeArt Container Parser memory corruption
19125| [4279] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP MHTML cross site scripting
19126| [56176] Microsoft Windows 7/Server 2003/XP fxscover.exe CDrawPoly::Serialize memory corruption
19127| [55772] Microsoft Publisher 2002 pubconv.dll memory corruption
19128| [55771] Microsoft Publisher 2002/2003/2010 memory corruption
19129| [55765] Microsoft Office 2003/Xp Integer memory corruption
19130| [55764] Microsoft Office 2003/Xp memory corruption
19131| [55750] Microsoft Publisher 2002/2003 pubconv.dll memory corruption
19132| [55749] Microsoft Publisher 2002/2003/2007/2010 pubconv.dll memory corruption
19133| [55748] Microsoft Publisher 2002/2003/2007 pubconv.dll memory corruption
19134| [4230] Microsoft Exchange 2007 on 64-bit RPC store.exe MAPI Request denial of service
19135| [4229] Microsoft SharePoint 2007 Document Conversion Launcher Service Eingabeung\xC3\xBCltigkeit
19136| [4228] Microsoft Windows Server 2008 Hyper-V VMBus denial of service
19137| [4224] Microsoft Windows 7/Server 2008/Vista Consent User Interface privilege escalation
19138| [4231] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Driver win32k.sys GreEnableEUDC denial of service
19139| [55420] Microsoft Office 2007/2010 memory corruption
19140| [55419] Microsoft Office 2004/2008/2011/Xp memory corruption
19141| [55412] Microsoft PowerPoint Viewer 2007 memory corruption
19142| [55411] Microsoft PowerPoint 2002/2003 memory corruption
19143| [4204] Microsoft Windows Server 2008 Color Control Panel Eingabeung\xC3\xBCltigkeit
19144| [54995] Microsoft Office 2004/2008 memory corruption
19145| [54994] Microsoft Office 2004/2008 Out-of-Bounds memory corruption
19146| [54993] Microsoft Office Compatibility Pack 2007 memory corruption
19147| [54992] Microsoft Excel 2002 memory corruption
19148| [54991] Microsoft Office 2004 Future memory corruption
19149| [54990] Microsoft Office 2004 memory corruption
19150| [54989] Microsoft Office 2004/2008 memory corruption
19151| [54988] Microsoft Excel 2002 memory corruption
19152| [54987] Microsoft Excel 2002 memory corruption
19153| [54986] Microsoft Excel 2002/2003 memory corruption
19154| [54985] Microsoft Office Compatibility Pack 2003/2004/2007/2008 memory corruption
19155| [54984] Microsoft Office 2004/2008 memory corruption
19156| [54983] Microsoft Excel 2002 Integer memory corruption
19157| [54980] Microsoft Word 2002/2003 memory corruption
19158| [54979] Microsoft Word 2002 memory corruption
19159| [54978] Microsoft Word 2002 memory corruption
19160| [54977] Microsoft Word 2002 Heap-based memory corruption
19161| [54976] Microsoft Word 2002 memory corruption
19162| [54975] Microsoft Word 2002 memory corruption
19163| [54974] Microsoft Word 2002 memory corruption
19164| [54973] Microsoft Word 2002 memory corruption
19165| [54972] Microsoft Word 2002 memory corruption
19166| [54971] Microsoft Word 2002 memory corruption
19167| [4197] Microsoft SharePoint 2007/3.0 cross site scripting
19168| [4196] Microsoft Word 2002/2003/2007/2010 Stack-based memory corruption
19169| [4194] Microsoft Windows 7/Server 2008/Vista SChannel Client Certificate Request denial of service
19170| [54774] Microsoft Word 2003 word_crash_11.8326.8324_poc.doc denial of service
19171| [54757] Microsoft SharePoint Server 2007 HTML Sanitization SafeHTML cross site scripting
19172| [4186] Microsoft Outlook 2002/2003/2007 Content Parser Heap-based memory corruption
19173| [54584] Microsoft Visual C++ 2005 AtlTraceTool8.exe unknown vulnerability
19174| [54554] Microsoft Groove 2007 mso.dll memory corruption
19175| [4187] Microsoft Windows 7/Server 2008/Vista TCP/IP Stack Ipv4SetEchoRequestCreate denial of service
19176| [54322] Microsoft Word 2002/2003 memory corruption
19177| [54321] Microsoft Office Compatibility Pack 2007 memory corruption
19178| [54320] Microsoft Office Compatibility Pack 2007 memory corruption
19179| [54319] Microsoft Office Compatibility Pack 2007 memory corruption
19180| [54318] Microsoft .NET Framework 2.0 SP1/2.0 SP2/3.5/3.5 SP1/3.5.1 Interfaces memory corruption
19181| [4165] Microsoft Windows 7/Server 2008/Vista TCP/IP Stack denial of service
19182| [4162] Microsoft Windows 7/Server 2008/Vista Kernel memory corruption
19183| [4159] Microsoft Excel 2002/2003 SXDB PivotTable Cache Data Record memory corruption
19184| [4149] Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Shell Shortcut Parser memory corruption
19185| [54083] Microsoft Access 2003 ActiveX Control ACCWIZ.dll memory corruption
19186| [4146] Microsoft Outlook 2002/2003/2007 SMB Attachment PR_ATTACH_METHOD memory corruption
19187| [4145] Microsoft Access 2003/2007 ActiveX ACCWIZ.dll memory corruption
19188| [54617] Microsoft Outlook Web Access up to 2007 cross site request forgery
19189| [4151] Microsoft Windows Server 2008/Vista NtUserCheckAccessForIntegrityLevel memory corruption
19190| [53591] Microsoft Windows Server 2003 GetServerName cross site scripting
19191| [53505] Microsoft Excel 2002/2007 memory corruption
19192| [53501] Microsoft Excel 2002 memory corruption
19193| [53500] Microsoft Excel 2002 memory corruption
19194| [53499] Microsoft Excel 2002 memory corruption
19195| [53495] Microsoft Excel 2002/2003/2007 memory corruption
19196| [53494] Microsoft Excel 2002 Stack-based memory corruption
19197| [53504] Microsoft Excel 2002 memory corruption
19198| [53503] Microsoft Excel 2002 Stack-Based memory corruption
19199| [53502] Microsoft Excel 2002 Heap-based memory corruption
19200| [53498] Microsoft Excel 2002 Stack-based memory corruption
19201| [53497] Microsoft Excel 2002 memory corruption
19202| [53496] Microsoft Excel 2002 memory corruption
19203| [53493] Microsoft Excel 2002/2003/2007 memory corruption
19204| [4133] Microsoft Office 2003/2007/Xp COM Object Instantiator memory corruption
19205| [53366] Microsoft ASP.NET 2.0 cross site scripting
19206| [53385] Microsoft Exchange Server 2007 Outlook Web Access cross site scripting
19207| [53164] Microsoft Office 2003/2007/Xp ActiveX Control VBE6.DLL memory corruption
19208| [53054] Microsoft VISIO 2002/2003/2007 VISIODWG.DLL memory corruption
19209| [4125] Microsoft SharePoint 2007/3.0 help.aspx cross site scripting
19210| [52777] Microsoft Publisher 2002/2003/2007 memory corruption
19211| [52773] Microsoft Visio 2002/2003/2007 memory corruption
19212| [52772] Microsoft Visio 2002/2003/2007 memory corruption
19213| [4107] Microsoft Windows 7/Server 2008 Kernel denial of service
19214| [4103] Microsoft Windows Server 2003 Media Services Stack-based memory corruption
19215| [52543] Microsoft Virtual PC 2007 unknown vulnerability
19216| [52148] Microsoft Office 2004/2007/2008 Uninitialized Memory memory corruption
19217| [52147] Microsoft Office 2004/2007/2008 Spreadsheet Uninitialized Memory memory corruption
19218| [52146] Microsoft Office 2004/2007/2008 Spreadsheet Heap-based memory corruption
19219| [52145] Microsoft Office 2004/2007/2008 Spreadsheet Heap-based memory corruption
19220| [52144] Microsoft Office 2004/2007/2008 Spreadsheet memory corruption
19221| [52143] Microsoft Office 2004/2007/2008 Spreadsheet memory corruption
19222| [4090] Microsoft Excel 2002/2003/2007 memory corruption
19223| [52036] Microsoft Windows 2000 MsgBox memory corruption
19224| [51995] Microsoft SharePoint Server up to 2006 cross site scripting
19225| [51810] Microsoft Office 2004/Xp MSO.DLL memory corruption
19226| [51802] Microsoft PowerPoint 2003 Stack-based memory corruption
19227| [51801] Microsoft PowerPoint 2003 Stack-based memory corruption
19228| [51800] Microsoft PowerPoint 2002/2003 Use-After-Free memory corruption
19229| [51799] Microsoft PowerPoint 2002/2003 memory corruption
19230| [51798] Microsoft PowerPoint 2002/2003 Heap-based memory corruption
19231| [4082] Microsoft PowerPoint 2002 SP3 memory corruption
19232| [54550] Microsoft PowerPoint 2007 rpawinet.dll memory corruption
19233| [54556] Microsoft Visio 2003 mfc71enu.dll unknown vulnerability
19234| [51497] Microsoft Windows Live Messenger 2009 ActiveX Control msnmsgr.exe denial of service
19235| [51133] Microsoft Windows 2000 SP4/Server 2003 SP2/SP3/XP SP2 memory corruption
19236| [51074] Microsoft Office 2002/2003 Integer memory corruption
19237| [4069] Microsoft Project 2003/2007 Project Memory Validator memory corruption
19238| [50794] Microsoft Office 2004/2008 Spreadsheet memory corruption
19239| [50793] Microsoft Office 2004/2008 Spreadsheet memory corruption
19240| [50792] Microsoft Office 2004/2008 Spreadsheet memory corruption
19241| [50791] Microsoft Office 2004/2008 Spreadsheet memory corruption
19242| [50790] Microsoft Office 2004/2008 Spreadsheet Heap-based memory corruption
19243| [50788] Microsoft Office 2004/2008 Spreadsheet memory corruption
19244| [50787] Microsoft Office 2004/2008 Spreadsheet memory corruption
19245| [50786] Microsoft Windows 2000 llssrv.exe memory corruption
19246| [50789] Microsoft Office 2004/2008 Spreadsheet memory corruption
19247| [4056] Microsoft Word 2002/2003 File Information Block Parser Stack-based memory corruption
19248| [50660] Microsoft SharePoint Server 2007 unknown vulnerability
19249| [50443] Microsoft PowerPoint 2007 Integer memory corruption
19250| [50432] Microsoft .NET Framework 2.0/2.0 SP1/2.0 SP2/3.5/3.5 SP1 memory corruption
19251| [49866] Microsoft Windows Server 2003 memory corruption
19252| [4031] Microsoft Windows Server 2008/Vista SMB Processor EducatedScholar memory corruption
19253| [4030] Microsoft Windows Server 2008/Vista Wireless LAN AutoConfig Service Heap-based memory corruption
19254| [4029] Microsoft Windows 2000/XP TCP/IP Window Size denial of service
19255| [49745] Microsoft Windows Server 2003 denial of service
19256| [49395] Microsoft Office 2000/2003/XP Office Web Components Heap-based memory corruption
19257| [49394] Microsoft Windows Server 2003 memory corruption
19258| [49389] Microsoft Office 2000/2003/XP Office Web Components memory corruption
19259| [49390] Microsoft Office 2000/2003/XP Office Web Components memory corruption
19260| [49198] Microsoft Visual Studio 2005 information disclosure
19261| [49047] Microsoft Virtual Server 2005 privilege escalation
19262| [49046] Microsoft Windows Server 2003 quartz.dll memory corruption
19263| [49045] Microsoft Windows Server 2003 quartz.dll memory corruption
19264| [49044] Microsoft ISA Server 2006 privilege escalation
19265| [3999] Microsoft Office 2007 Pointer memory corruption
19266| [4000] Microsoft Office 2003/Sp3/Xp Web Components memory corruption
19267| [48894] Microsoft Windows Server 2003 msvidctl.dll memory corruption
19268| [48572] Microsoft PowerPoint 2002 FL21WIN.DLL memory corruption
19269| [48517] Microsoft Windows 2000 Memory Leak memory corruption
19270| [48516] Microsoft Windows Server 2008 unknown vulnerability
19271| [48512] Microsoft Windows Server 2008 unknown vulnerability
19272| [48515] Microsoft Office Word Viewer 2003 memory corruption
19273| [48514] Microsoft Office Word Viewer 2003 Stack-based memory corruption
19274| [48554] Microsoft Excel 2000/2003/2007 memory corruption
19275| [48157] Microsoft PowerPoint 2002 Sound memory corruption
19276| [48156] Microsoft PowerPoint 2000 Stack-based memory corruption
19277| [48154] Microsoft PowerPoint 2002 Sound PP7X32.DLL memory corruption
19278| [48152] Microsoft PowerPoint 2002 PP4X32.DLL memory corruption
19279| [48150] Microsoft PowerPoint 2002 Sound memory corruption
19280| [48147] Microsoft PowerPoint 2002 Sound memory corruption
19281| [48146] Microsoft PowerPoint 2002 Integer memory corruption
19282| [48155] Microsoft PowerPoint 2002 Notes Container Heap-based memory corruption
19283| [48153] Microsoft PowerPoint 2002 Sound memory corruption
19284| [48151] Microsoft PowerPoint 2002 Stack-based memory corruption
19285| [48149] Microsoft PowerPoint 2002 memory corruption
19286| [48148] Microsoft PowerPoint 2002 Sound memory corruption
19287| [3974] Microsoft PowerPoint 2000/2002/2003 Sound Data Stack-based memory corruption
19288| [3973] Microsoft PowerPoint 2000/2002/2003 Notes Container Stack-based memory corruption
19289| [3972] Microsoft PowerPoint 2000/2002/2003 BuildList memory corruption
19290| [3971] Microsoft PowerPoint 2000/2002/2003 Object Stack-based memory corruption
19291| [3970] Microsoft PowerPoint 2000/2002/2003 Paragraph Stack-based memory corruption
19292| [3969] Microsoft PowerPoint 2000/2002/2003 Atom Stack-based memory corruption
19293| [47719] Microsoft Windows 2000 Stack-based memory corruption
19294| [47720] Microsoft Internet Security And Acceleration Server 2006 Forms Authentication cookieauth.dll cross site scripting
19295| [47716] Microsoft Office Converter Pack 2003 WPFT632.CNV memory corruption
19296| [47715] Microsoft Windows 2000 Wordpad memory corruption
19297| [47718] Microsoft Excel 2000/2002/2003/2007 Spreadsheet memory corruption
19298| [3960] Microsoft Windows 2000/Server 2003/XP DirectShow MJPEG memory corruption
19299| [3952] Microsoft ISA Server 2004/2006 denial of service
19300| [3946] Microsoft PowerPoint 2000/2002/2003/2004 memory corruption
19301| [47091] Microsoft Windows Server 2008 unknown vulnerability
19302| [47090] Microsoft Windows Server 2008 unknown vulnerability
19303| [3939] Microsoft Windows 2000 DNS spoofing
19304| [3938] Microsoft Windows 2000 SSL weak authentication
19305| [3937] Microsoft Windows 2000 memory corruption
19306| [3932] Microsoft Excel 2000/2002/2003/2004/2007 Object Reference memory corruption
19307| [46620] Microsoft Windows Live Messenger 2009 msnmsgr.exe denial of service
19308| [46455] Microsoft Exchange Server 2007 denial of service
19309| [46454] Microsoft Exchange Server 2007 memory corruption
19310| [46453] Microsoft Visio 2002/2003/2007 memory corruption
19311| [46452] Microsoft Visio 2002/2003/2007 memory corruption
19312| [46451] Microsoft Visio 2002/2003/2007 memory corruption
19313| [46327] Microsoft Word 2007 information disclosure
19314| [45758] Microsoft Money 2006 ActiveX Control prtstb06.dll denial of service
19315| [45381] Microsoft Windows Server 2008/Vista SP1 Explorer memory corruption
19316| [45380] Microsoft Windows Server 2008/Vista SP1 Search memory corruption
19317| [45379] Microsoft Office SharePoint Server 2007 denial of service
19318| [3896] Microsoft SQL Server up to 2005 sp_replwritetovarbin memory corruption
19319| [3892] Microsoft Excel 2000/2002/2003 Formula memory corruption
19320| [3891] Microsoft Excel 2000/2002/2003 memory corruption
19321| [3890] Microsoft Excel 2000/2002/2003 NAME Index memory corruption
19322| [3889] Microsoft Word 2000/2002/2003/2007 Table Property Stack-based memory corruption
19323| [3888] Microsoft Word 2000/2002/2003/2007 RTF Stylesheet memory corruption
19324| [3887] Microsoft Word 2000/2002/2003/2007 memory corruption
19325| [3886] Microsoft Word 2000/2002/2003/2007 ControlWord Heap-based memory corruption
19326| [3885] Microsoft Word 2000/2002/2003/2007 memory corruption
19327| [3884] Microsoft Word 2000/2002/2003/2007 memory corruption
19328| [3883] Microsoft Word 2000/2002/2003/2007 RTF Heap-based memory corruption
19329| [3882] Microsoft Word 2000/2002/2003/2007 LFO memory corruption
19330| [3880] Microsoft Visual Basic up to 2003 ActiveX Control Mschrt20.ocx memory corruption
19331| [3879] Microsoft Visual Basic up to 2003 ActiveX Control mscomct2.ocx memory corruption
19332| [3878] Microsoft Visual Basic up to 2003 ActiveX Control mshflxgd.ocx memory corruption
19333| [3877] Microsoft Visual Basic up to 2003 ActiveX Control msflxgrd.ocx memory corruption
19334| [3876] Microsoft Visual Basic up to 2003 ActiveX Control msdatgrd.ocx memory corruption
19335| [45197] Microsoft Windows 2000 nskey.dll memory corruption
19336| [45063] Microsoft Windows Server 2003 Active Directory unknown vulnerability
19337| [45040] Microsoft .NET Framework 2.0.50727 Code Access Security unknown vulnerability
19338| [44855] DjVu Activex Control For Microsoft Office 2000 3.0 ActiveX Control DjVu_ActiveX_MSOffice.dll memory corruption
19339| [44665] Microsoft Peachtree Accounting 2004 ActiveX Control PAWWeb11.ocx unknown vulnerability
19340| [44589] Microsoft Exchange Server 2003 Outlook Web Access unknown vulnerability
19341| [3845] Microsoft Windows 2000 SP4 Active Directory memory corruption
19342| [44533] Microsoft Windows 2000 mqsvc.exe memory corruption
19343| [3844] Microsoft Excel 2003 REPT memory corruption
19344| [3843] Microsoft Excel up to 2007 BIFF File Heap-based memory corruption
19345| [3842] Microsoft Excel 2003 VBA Performance Cache Stack-based memory corruption
19346| [44405] Microsoft Digital Image 2006 ActiveX Control PipPPush.DLL unknown vulnerability
19347| [44047] Microsoft SQL Server 2000 ActiveX Control SQLVDIRLib.SQLVDirControl memory corruption
19348| [43981] Microsoft Organization Chart 2.00 orgchart.exe memory corruption
19349| [43957] Microsoft Office 2003/2007/Xp gdiplus.dll memory corruption
19350| [43956] Microsoft Office 2003/2007/Xp gdiplus.dll memory corruption
19351| [43955] Microsoft Office 2003/2007/Xp gdiplus.dll memory corruption
19352| [43952] Microsoft Office 2003/2007/Xp URI memory corruption
19353| [43676] Microsoft Windows 2000/Server 2003/Vista/XP memory corruption
19354| [43675] Microsoft Windows 2000/Server 2003/Vista/XP of memory corruption
19355| [43662] Microsoft PowerPoint Viewer 2000 SP3/2002 SP3/2003 SP2/2007 SP1 memory corruption
19356| [43661] Microsoft PowerPoint Viewer 2003 memory corruption
19357| [43660] Microsoft PowerPoint Viewer 2003 Integer memory corruption
19358| [43657] Microsoft Office 2000/2003/Xp memory corruption
19359| [43654] Microsoft SharePoint Server 2007 memory corruption
19360| [43653] Microsoft Office 2000/2002/2004/2008 memory corruption
19361| [43652] Microsoft Office 2000/2002/2003/2004/2008 memory corruption
19362| [3797] Microsoft Windows Server 2008/Vista IPsec Policy Designfehler
19363| [3796] Microsoft Office 2000 WPG memory corruption
19364| [3795] Microsoft Office 2000/2003/Xp BMP Image BMPIMP32.FLT memory corruption
19365| [3794] Microsoft Office 2000/2003/Xp PICT bits_per_pixel memory corruption
19366| [3793] Microsoft Office 2000/2003/Xp PICT memory corruption
19367| [3792] Microsoft Office 2000 EPS File memory corruption
19368| [3783] Microsoft Word 2002 memory corruption
19369| [43103] Microsoft Exchange Srv 2007 Sp1 Outlook Web Access cross site scripting
19370| [43102] Microsoft Windows 2000 SP4/Server 2003 SP2/Server 2008 DNS Cache privilege escalation
19371| [3778] Microsoft Exchange 2003/2007 Outlook Web Access cross site scripting
19372| [3777] Microsoft Windows Server 2008/Vista SP1 Explorer memory corruption
19373| [43087] Microsoft Office Snapshot Viewer ActiveX up to Office 2003 Snapshot Viewer ActiveX Control snapview.ocx memory corruption
19374| [43096] Microsoft Publisher 2003/2007 Crypto API unknown vulnerability
19375| [42816] Microsoft Word 2000/2003 memory corruption
19376| [42732] Microsoft Windows Server 2003/Vista/XP denial of service
19377| [42731] Microsoft Windows Server 2003 denial of service
19378| [3732] Microsoft Windows 2000/Server 2003 WINS memory corruption
19379| [3701] Microsoft Word 2003 CSS Heap-based memory corruption
19380| [3700] Microsoft Word 2003 RTF Document Heap-based memory corruption
19381| [42065] Microsoft SharePoint Server 2.0 Rich Text Editor cross site scripting
19382| [41881] Microsoft Office 2003/2007/2007 Sp1/Xp memory corruption
19383| [41880] Microsoft Project 2000/2002/2003 memory corruption
19384| [41879] Microsoft Windows 2000/Server 2003/Vista Stack-based memory corruption
19385| [41878] Microsoft Windows 2000/Server 2003/Vista spoofing
19386| [41877] Microsoft Windows Server 2003 vbscript.dll memory corruption
19387| [3671] Microsoft Visio 2002/2003/2003 Sp3/2007/2007 Sp1 memory corruption
19388| [3670] Microsoft Visio 2002/2003/2003 Sp3/2007/2007 Sp1 Object memory corruption
19389| [41455] Microsoft Office 2000/2003/2004/Xp memory corruption
19390| [41454] Microsoft Excel 2000/2002/2003/2007 memory corruption
19391| [41453] Microsoft Excel 2000/2002/2003 memory corruption
19392| [41452] Microsoft Excel 2000/2002/2003/2007 memory corruption
19393| [41451] Microsoft Excel 2000/2002/2003 memory corruption
19394| [41450] Microsoft Excel 2000 memory corruption
19395| [41449] Microsoft Excel 2000/2002/2003 memory corruption
19396| [41448] Microsoft Office 2000/Xp Office Web Components memory corruption
19397| [3648] Microsoft Excel 2003 memory corruption
19398| [3647] Microsoft Outlook up to 2007 mailto URI memory corruption
19399| [41003] Microsoft Office 2000/2003/2004/Xp memory corruption
19400| [41002] Microsoft Office 2000/2003/Xp memory corruption
19401| [41001] Microsoft Works 2005/8.0 wkcvqd01.dll memory corruption
19402| [41000] Microsoft Works 2005/8.0 memory corruption
19403| [40998] Microsoft Publisher 2000/2002/2003 memory corruption
19404| [40994] Microsoft Works 2005/8.0 wkcvqd01.dll memory corruption
19405| [40987] Microsoft Windows 2000 denial of service
19406| [40736] Microsoft ActiveX 2.0 ActiveX Control privilege escalation
19407| [3552] Microsoft Excel 2000/2002/2003 File memory corruption
19408| [40242] Microsoft Publisher 2000/2002/2003/2007 Crash denial of service
19409| [40020] Microsoft Office 2007 ZIP Container unknown vulnerability
19410| [39769] Microsoft Windows 2000 cryptgenrandom weak encryption
19411| [39749] Microsoft Windows 2000 msjet40.dll memory corruption
19412| [39655] Microsoft Windows Server 2003 spoofing
19413| [39324] Microsoft Windows Mobile 2005 SMS unknown vulnerability
19414| [3373] Microsoft Word 2000/2002 memory corruption
19415| [38999] Microsoft Windows Server 2003 explorer.exe denial of service
19416| [38899] Microsoft ISA Server 2004 information disclosure
19417| [38728] Microsoft SQL Server 2005 Enterprise Manager sqldmo.dll memory corruption
19418| [38326] Microsoft Windows 2000 attemptwrite memory corruption
19419| [3241] Microsoft Excel 2000/2003/2004/XP SP3 rtWnDesk memory corruption
19420| [3223] Microsoft Windows Server 2003/XP URI privilege escalation
19421| [3212] Microsoft DirectX February 2006 RLE Compression Targa Files Heap-based memory corruption
19422| [37739] Microsoft Excel 2000/2002/2003/2004/2007 memory corruption
19423| [37738] Microsoft Office 2002/2003 memory corruption
19424| [3176] Microsoft Excel 2000/2002/2003/2007 File Attribute memory corruption
19425| [3175] Microsoft Excel 2000/2002/2003/2007 Active Worksheet memory corruption
19426| [3174] Microsoft Excel 2000/2002/2003/2007 Version Information memory corruption
19427| [3172] Microsoft Office Publisher 2007 Pointer memory corruption
19428| [37566] Microsoft Excel 2003 unknown vulnerability
19429| [37526] Microsoft Windows 2000/Server 2003 denial of service
19430| [37248] Microsoft Visio 2002 Packaging memory corruption
19431| [37251] Microsoft Windows 2000 memory corruption
19432| [3119] Microsoft Visio 2002 Object memory corruption
19433| [3118] Microsoft Visio 2002 Data memory corruption
19434| [37093] Microsoft Windows Server 2003 Error Message unknown vulnerability
19435| [37010] Microsoft Office 2000 ActiveX Control ouactrl.ocx memory corruption
19436| [36628] Microsoft Word 2000/2002/2003/2004 winword.exe memory corruption
19437| [36616] Microsoft Works 2004/2005/2006 memory corruption
19438| [36621] Microsoft Exchange Server 2000 Integer denial of service
19439| [36620] Microsoft Exchange Server 2000 Outlook Web Access cross site scripting
19440| [36619] Microsoft Exchange Server 2000/2003/2007 MIME Email memory corruption
19441| [36618] Microsoft Exchange Server 2000 NULL Pointer Dereference denial of service
19442| [36617] Microsoft Excel 2000/2002/2003/2004 memory corruption
19443| [36623] Microsoft BizTalk Server 2004 ActiveX Control capicom.dll memory corruption
19444| [3067] Microsoft Office 2000/2003/2004/2007/Xp Drawing Object memory corruption
19445| [3065] Microsoft Excel 2000/2002/2003/2007 Filter Stack-based memory corruption
19446| [3064] Microsoft Excel 2000/2002/2003/2004/2007 set Font memory corruption
19447| [3063] Microsoft Excel 2000/2002/2003/2007 BIFF Record Stack-based memory corruption
19448| [3012] Microsoft Windows 2000/Server 2003 DNS Service Stack-based memory corruption
19449| [36039] Microsoft Content Management Server 2001 memory corruption
19450| [36052] Microsoft Windows 2000 Heap-based memory corruption
19451| [36051] Microsoft Word 2007 file798-1.doc memory corruption
19452| [36050] Microsoft Word 2007 file789-1.doc memory corruption
19453| [36040] Microsoft Content Management Server 2001 cross site scripting
19454| [3004] Microsoft Windows up to 2003/XP URL Parser memory corruption
19455| [36041] Microsoft .NET Framework 2.0.50727.42 cross site scripting
19456| [36002] Microsoft Windows 2000/XP denial of service
19457| [2990] Microsoft Windows 2000/Vista/XP Animated Cursor Stack-based memory corruption
19458| [36515] Microsoft Windows 2000/Server 2003/XP memory corruption
19459| [35846] Microsoft Windows 2000/Server 2003 Default Configuration information disclosure
19460| [35373] Microsoft Excel 2003 denial of service
19461| [35372] Microsoft Office 2003 denial of service
19462| [35206] Microsoft Windows Server 2003/XP Crash denial of service
19463| [35161] Microsoft ISA Server 2004 unknown vulnerability
19464| [35236] Microsoft Publisher 2007 memory corruption
19465| [2939] Microsoft Word 2000 memory corruption
19466| [34994] Microsoft Windows 2000 OLE Dialog memory corruption
19467| [34993] Microsoft Office 2000/2003/Xp memory corruption
19468| [35001] Microsoft Office 2000/2003/2004/Xp memory corruption
19469| [35000] Microsoft Word 2000/2002/2003 memory corruption
19470| [2933] Microsoft Windows 2000 SP4/Server 2003 SP1/XP SP2 OLE Dialog Stack-based memory corruption
19471| [2894] Microsoft Office 2000/2003/2004/Xp Undefined String Format String
19472| [2884] Microsoft Word 2000/2002/2003 memory corruption
19473| [34321] Microsoft Office 2000/2003/2004/Xp Spreadsheet Heap-based memory corruption
19474| [34320] Microsoft Office 2000/2003/2004/Xp memory corruption
19475| [34319] Microsoft Office 2000/2003/2004/Xp memory corruption
19476| [34318] Microsoft Office 2000/2003/2004/Xp memory corruption
19477| [34322] Microsoft Office 2000/2003/Xp memory corruption
19478| [2811] Microsoft Windows 2000/Server 2003/XP VML Vector Markup Language Integer memory corruption
19479| [2810] Microsoft Outlook 2000/2002/2003 Office Saved Search OSS File memory corruption
19480| [2809] Microsoft Outlook 2000/2002/2003 Header denial of service
19481| [2808] Microsoft Outlook 2000/2002/2003 Meeting VEVENT memory corruption
19482| [2807] Microsoft Excel 2000/2002/2003 XLS File memory corruption
19483| [34126] Microsoft Office 2003 memory corruption
19484| [34122] Microsoft Office Web Components 2000 memory corruption
19485| [2789] Microsoft Windows 2000/XP RPC Request NetrWkstaUserEnum denial of service
19486| [2765] Microsoft Project Server 2003 pdsrequest.asp weak authentication
19487| [33851] Microsoft Word 2000/2002/2003 12122006-djtest.doc memory corruption
19488| [2739] Microsoft Windows 2000 Remote Installation Service Fehlende Authentifizierung
19489| [2738] Microsoft Windows 2000/Server 2003/XP SNMP memory corruption
19490| [2737] Microsoft Windows Server 2003/XP Manifest denial of service
19491| [33766] Microsoft Word 2000/2002/2003 memory corruption
19492| [2718] Microsoft Word 2000/2002/2003 DOC Document memory corruption
19493| [2717] Microsoft Windows 2000 Print Spooler Memory Consumption denial of service
19494| [2689] Microsoft Windows up to 2000 SP4 Active Directory denial of service
19495| [2688] Microsoft Windows 2000/Server 2003/XP Client Service for Netware denial of service
19496| [2687] Microsoft Windows 2000/Server 2003/XP Agent ActiveX ACF File Heap-based memory corruption
19497| [2686] Microsoft Windows 2000/Server 2003/XP Client Service for Netware memory corruption
19498| [2684] Microsoft Windows 2000/XP Workstation Service Stack-based memory corruption
19499| [2659] Microsoft Windows 2000/XP GDI Crash memory corruption
19500| [2655] Microsoft Windows 2000/Server 2003/XP XML Core Services memory corruption
19501| [33067] Microsoft Visual Studio .net 2005 ActiveX Control wmiscriptutils.dll memory corruption
19502| [2610] Microsoft PowerPoint 2003 PPT Document NULL Pointer Dereference denial of service
19503| [32693] Microsoft Word 2004 memory corruption
19504| [32686] Microsoft Office 2000/2001/2003/2004 Integer memory corruption
19505| [32690] Microsoft Office 2000/2003/2004/Xp memory corruption
19506| [32676] Microsoft Office 2000/2001/2003/2004 memory corruption
19507| [32675] Microsoft Office 2000/2003/2004/Xp memory corruption
19508| [32694] Microsoft Windows 2000 memory corruption
19509| [32689] Microsoft Excel 2000/2002/2003/2004/XP memory corruption
19510| [32688] Microsoft Excel 2000/2002/2003/2004/XP memory corruption
19511| [32687] Microsoft Word 2000/2002 memory corruption
19512| [32685] Microsoft Office 2000/2001/2003/2004 memory corruption
19513| [2601] Microsoft Windows Server 2003/XP IPv6 Stack denial of service
19514| [2600] Microsoft Windows Server 2003/XP IPv6 Stack TCP denial of service
19515| [2599] Microsoft Windows Server 2003/XP IPv6 Stack ICMP denial of service
19516| [2598] Microsoft Windows Server 2003/XP Object Packager privilege escalation
19517| [2597] Microsoft Office 2003/Xp Smart-Tag Parser memory corruption
19518| [2596] Microsoft Office 2000/2003/2004/Xp Value Read memory corruption
19519| [2595] Microsoft Office 2000/2001/2003/2004 Diagram Value memory corruption
19520| [2594] Microsoft Office 2000/2001/2003/2004 Document memory corruption
19521| [2593] Microsoft ASP.NET 2.0 cross site scripting
19522| [141652] Microsoft Windows up to Server 2019 Common Log File System Driver information disclosure
19523| [141639] Microsoft SharePoint Foundation 2013 SP1 cross site request forgery
19524| [141637] Microsoft Windows up to Server 2019 AppX Deployment Server privilege escalation
19525| [141636] Microsoft ASP.NET Core 2.1/2.2/3.0 Project Template privilege escalation
19526| [141635] Microsoft .NET Core 2.1/2.2 denial of service
19527| [141633] Microsoft Excel up to 2019 memory corruption
19528| [141631] Microsoft Windows up to Server 2019 SMB Client Driver information disclosure
19529| [141630] Microsoft Windows up to Server 2019 denial of service
19530| [141629] Microsoft Windows up to Server 2019 Update Delivery Optimization privilege escalation
19531| [141627] Microsoft Windows up to Server 2019 GDI information disclosure
19532| [141626] Microsoft Windows up to Server 2019 Win32k memory corruption
19533| [141621] Microsoft Windows up to Server 2019 Kernel information disclosure
19534| [141620] Microsoft Windows up to Server 2019 Active Directory Federation Services cross site scripting
19535| [141619] Microsoft Windows up to Server 2019 ALPC privilege escalation
19536| [141618] Microsoft Windows up to Server 2019 hdAudio.sys privilege escalation
19537| [141617] Microsoft Windows up to Server 2019 Store Installer privilege escalation
19538| [141616] Microsoft Windows up to Server 2019 ALPC privilege escalation
19539| [141615] Microsoft Windows up to Server 2019 Winlogon privilege escalation
19540| [141614] Microsoft Windows up to Server 2019 Compatibility Appraiser privilege escalation
19541| [141611] Microsoft Office up to 2019 Security Feature privilege escalation
19542| [141610] Microsoft Excel up to 2019 information disclosure
19543| [141609] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
19544| [141608] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site request forgery
19545| [141607] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016/2019 privilege escalation
19546| [141606] Microsoft Windows up to Server 2019 Win32k memory corruption
19547| [141605] Microsoft Windows up to Server 2019 Hyper-V information disclosure
19548| [141604] Microsoft Windows up to Server 2019 AppX Deployment Server privilege escalation
19549| [141603] Microsoft Windows up to Server 2019 GDI information disclosure
19550| [141602] Microsoft Windows up to Server 2019 DirectWrite information disclosure
19551| [141601] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19552| [141600] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19553| [141599] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19554| [141598] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19555| [141597] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19556| [141596] Microsoft Windows up to Server 2019 DirectWrite information disclosure
19557| [141595] Microsoft Windows up to Server 2019 DirectWrite information disclosure
19558| [141594] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19559| [141593] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19560| [141592] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19561| [141591] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19562| [141590] Microsoft Windows up to Server 2019 Text Service Framework command injection
19563| [141589] Microsoft Exchange Server 2016 CU12/2016 CU13/2019 CU1/2019 CU2 denial of service
19564| [141583] Microsoft Lync Server 2013 Conference directory traversal
19565| [141581] Microsoft Windows up to Server 2016 Hyper-V denial of service
19566| [141580] Microsoft Windows up to Server 2019 Transaction Manager information disclosure
19567| [141579] Microsoft Windows up to Server 2016 DirectX information disclosure
19568| [141577] Microsoft Windows up to Server 2019 Common Log File System Driver privilege escalation
19569| [141575] Microsoft Windows up to Server 2019 lnk File privilege escalation
19570| [141564] Microsoft SharePoint Enterprise Server 2010 SP1/2013 SP1/2016/2019 Markup Application Package privilege escalation
19571| [141561] Microsoft Windows up to Server 2019 Remote Desktop privilege escalation
19572| [141560] Microsoft Windows up to Server 2019 Remote Desktop privilege escalation
19573| [139972] Microsoft Windows up to Server 2019 HTTP2 HTTP.sys denial of service
19574| [139971] Microsoft Windows up to Server 2019 HTTP2 HTTP.sys denial of service
19575| [139970] Microsoft Windows up to Server 2019 HTTP2 HTTP.sys denial of service
19576| [139969] Microsoft Windows up to Server 2019 HTTP2 HTTP.sys denial of service
19577| [139968] Microsoft Windows up to Server 2019 HTTP2 HTTP.sys denial of service
19578| [139965] Microsoft Windows up to Server 2019 Kernel information disclosure
19579| [139963] Microsoft Windows up to Server 2019 Remote Desktop Protocol information disclosure
19580| [139962] Microsoft Windows up to Server 2019 Remote Desktop Protocol denial of service
19581| [139960] Microsoft Windows up to Server 2019 DHCP Server denial of service
19582| [139958] Microsoft Windows up to Server 2019 DHCP Server denial of service
19583| [139957] Microsoft SharePoint Server 2013 SP1/2016/2019 cross site scripting
19584| [139956] Microsoft SharePoint 2010 SP2/2013 SP1/2016/2019 Session Object information disclosure
19585| [139955] Microsoft Windows up to Server 2019 SyncController.dll privilege escalation
19586| [139949] Microsoft Windows up to Server 2019 XmlLite Runtime XmlLite.dll denial of service
19587| [139946] Microsoft Windows up to Server 2019 Core Shell COM Server Registrar COM Call privilege escalation
19588| [139942] Microsoft Windows up to Server 2019 rpcss.dll memory corruption
19589| [139941] Microsoft Windows up to Server 2019 DirectX memory corruption
19590| [139937] Microsoft Windows up to Server 2019 Azure Active Directory information disclosure
19591| [139936] Microsoft Windows up to Server 2019 SymCrypt information disclosure
19592| [139935] Microsoft Windows 10 1809/10 1903/Server 1903/Server 2019 NTFS privilege escalation
19593| [139934] Microsoft Windows 7 SP1/Server 2018 R2 SP1/Server 2018 SP2 Win32k memory corruption
19594| [139933] Microsoft Windows up to Server 2019 p2pimsvc privilege escalation
19595| [139932] Microsoft Windows up to Server 2019 Kernel memory corruption
19596| [139931] Microsoft Windows up to Server 2019 File Signature Security Feature CAB File privilege escalation
19597| [139930] Microsoft Windows up to Server 2019 ALPC privilege escalation
19598| [139928] Microsoft Windows up to Server 2019 Kernel memory corruption
19599| [139927] Microsoft Windows up to Server 2019 Graphics Component information disclosure
19600| [139926] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19601| [139925] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19602| [139924] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19603| [139922] Microsoft Windows up to Server 2019 Graphics Component information disclosure
19604| [139921] Microsoft Windows up to Server 2019 Graphics Component information disclosure
19605| [139920] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19606| [139919] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19607| [139918] Microsoft Windows up to Server 2019 Graphics Component information disclosure
19608| [139917] Microsoft Windows up to Server 2019 Graphics Component information disclosure
19609| [139916] Microsoft Windows up to Server 2019 XML Core Services MSXML Parser privilege escalation
19610| [139914] Microsoft Windows up to Server 2019 Hyper-V Network Switch denial of service
19611| [139913] Microsoft Windows up to Server 2019 Hyper-V Network Switch denial of service
19612| [139912] Microsoft Windows 10 1809/10 1903/Server 1903/Server 2019 Hyper-V Network Switch denial of service
19613| [139911] Microsoft Windows up to Server 2019 denial of service
19614| [139910] Microsoft Windows up to Server 2019 Hyper-V Network Switch denial of service
19615| [139909] Microsoft Windows up to Server 2019 Hyper-V Network Switch denial of service
19616| [139908] Microsoft Windows up to Server 2019 Bluetooth weak encryption
19617| [139907] Microsoft Windows up to Server 2019 Remote Desktop Service privilege escalation
19618| [139906] Microsoft Windows up to Server 2019 Remote Desktop Service privilege escalation
19619| [139902] Microsoft Word up to 2019 memory corruption
19620| [139901] Microsoft Outlook up to 2019 memory corruption
19621| [139895] Microsoft Windows up to Server 2019 lnk File privilege escalation
19622| [139894] Microsoft Windows up to Server 2019 VBScript Engine memory corruption
19623| [139893] Microsoft Windows up to Server 2019 Remote Desktop Service privilege escalation
19624| [139892] Microsoft Windows up to Server 2019 Remote Desktop Service privilege escalation
19625| [139891] Microsoft Windows up to Server 2019 Font Library memory corruption
19626| [139890] Microsoft Windows up to Server 2019 Font Library memory corruption
19627| [139889] Microsoft Windows up to Server 2019 Font Library memory corruption
19628| [139888] Microsoft Windows up to Server 2019 Font Library memory corruption
19629| [139887] Microsoft Windows up to Server 2019 Font Library memory corruption
19630| [139886] Microsoft Windows up to Server 2019 Font Library memory corruption
19631| [139880] Microsoft Windows up to Server 2019 Hyper-V memory corruption
19632| [139879] Microsoft Windows up to Server 2019 DHCP Client memory corruption
19633| [139878] Microsoft Windows up to Server 2019 Hyper-V Network Switch memory corruption
19634| [139877] Microsoft Outlook up to 2019 memory corruption
19635| [139876] Microsoft Windows up to Server 2019 Remote Desktop Service privilege escalation
19636| [139875] Microsoft Windows up to Server 2019 Remote Desktop Service privilege escalation
19637| [137590] Microsoft ASP.NET Core 2.1/2.2 Open Redirect
19638| [137589] Microsoft Exchange Server 2013 CU23/2016 CU12/2016 CU13/2019 CU1/2019 CU2 cross site scripting
19639| [137588] Microsoft Exchange Server 2010 SP3/2013 CU23/2016 CU12/2016 CU13 Web Services privilege escalation
19640| [137587] Microsoft SharePoint Server 2013 SP1/2016/2019 cross site scripting
19641| [137586] Microsoft Windows up to Server 2019 AppX Deployment Service privilege escalation
19642| [137585] Microsoft Windows up to Server 2019 AppX Deployment Service privilege escalation
19643| [137584] Microsoft Windows up to Server 2019 DirectWrite memory corruption
19644| [137583] Microsoft Windows up to Server 2019 DirectWrite memory corruption
19645| [137581] Microsoft Windows up to Server 2019 DirectWrite memory corruption
19646| [137580] Microsoft Windows up to Server 2019 DirectWrite memory corruption
19647| [137579] Microsoft Windows up to Server 2019 DirectWrite memory corruption
19648| [137578] Microsoft Windows up to Server 2019 DirectWrite memory corruption
19649| [137577] Microsoft Windows up to Server 2019 DirectWrite memory corruption
19650| [137576] Microsoft Windows up to Server 2019 DirectWrite memory corruption
19651| [137575] Microsoft Windows up to Server 2019 DirectWrite memory corruption
19652| [137574] Microsoft Windows up to Server 2019 DirectWrite memory corruption
19653| [137568] Microsoft Windows up to Server 2019 Remote Desktop Protocol information disclosure
19654| [137563] Microsoft Windows up to Server 2019 DirectWrite information disclosure
19655| [137562] Microsoft Windows up to Server 2019 Win32k information disclosure
19656| [137561] Microsoft Windows up to Server 2019 GDI information disclosure
19657| [137560] Microsoft Windows up to Server 2019 GDI information disclosure
19658| [137559] Microsoft Windows up to Server 2019 DirectWrite information disclosure
19659| [137555] Microsoft Windows up to Server 2019 Audio Service privilege escalation
19660| [137554] Microsoft Windows up to Server 2019 Audio Service privilege escalation
19661| [137553] Microsoft Windows up to Server 2019 Audio Service privilege escalation
19662| [137549] Microsoft Windows up to Server 2016 DLL privilege escalation
19663| [137544] Microsoft Windows up to Server 2019 Kernel information disclosure
19664| [137543] Microsoft Windows up to Server 2019 Kernel information disclosure
19665| [137542] Microsoft SQL Server 2014 SP2/2016 SP1/2017 privilege escalation
19666| [137541] Microsoft Windows up to Server 2019 memory corruption
19667| [137540] Microsoft Windows up to Server 2019 Error Reporting privilege escalation
19668| [137539] Microsoft Windows up to Server 2016 DirectX memory corruption
19669| [137538] Microsoft Windows Server 1803/Server 1903/Server 2016/Server 2019 ADFS Security Feature privilege escalation
19670| [137537] Microsoft Windows up to Server 2019 Hyper-V denial of service
19671| [137535] Microsoft Windows up to Server 2019 Remote Desktop Service privilege escalation
19672| [137533] Microsoft Windows up to Server 2019 SymCrypt denial of service
19673| [137527] Microsoft Windows up to Server 2019 GDI+ memory corruption
19674| [137512] Microsoft Windows up to Server 2019 DHCP memory corruption
19675| [136414] Microsoft Azure DevOps Server 2019 cross site request forgery
19676| [136349] Microsoft Windows up to Server 2019 Event Viewer eventvwr.msc XML External Entity
19677| [136348] Microsoft Windows up to Server 2019 Task Scheduler privilege escalation
19678| [136347] Microsoft Windows up to Server 2019 AppXSVC privilege escalation
19679| [136345] Microsoft Windows up to Server 2019 Windows Shell privilege escalation
19680| [136344] Microsoft Windows up to Server 2019 GDI information disclosure
19681| [136340] Microsoft Windows up to Server 2019 GDI information disclosure
19682| [136337] Microsoft Windows up to Server 2019 Comctl32.dll memory corruption
19683| [136336] Microsoft Windows up to Server 2019 Kernel privilege escalation
19684| [136335] Microsoft Windows up to Server 2019 NTLM Downgrade weak authentication
19685| [136334] Microsoft Windows up to Server 2019 Kernel information disclosure
19686| [136333] Microsoft SharePoint Server 2010 SP2/2013 SP1/2016/2019 cross site scripting
19687| [136330] Microsoft SharePoint Server 2010 SP2/2013 SP1/2016/2019 cross site scripting
19688| [136329] Microsoft SharePoint Server 2016/2019 cross site scripting
19689| [136328] Microsoft SharePoint Server 2010 SP2/2013 SP1/2016/2019 cross site scripting
19690| [136327] Microsoft Lync Server 2010/2013 denial of service
19691| [136326] Microsoft Windows up to Server 2019 Audio Service privilege escalation
19692| [136325] Microsoft Windows up to Server 2019 Audio Service privilege escalation
19693| [136324] Microsoft Windows up to Server 2019 Audio Service privilege escalation
19694| [136323] Microsoft Windows up to Server 2019 denial of service
19695| [136321] Microsoft Windows 10 1809/10 1903/Server 1903/Server 2019 Audio Service privilege escalation
19696| [136320] Microsoft Windows up to Server 2019 Audio Service privilege escalation
19697| [136319] Microsoft Windows up to Server 2019 Security Credentials information disclosure
19698| [136318] Microsoft Windows up to Server 2019 DirectX privilege escalation
19699| [136317] Microsoft Windows up to Server 2019 Win32k memory corruption
19700| [136314] Microsoft Windows up to Server 2019 Win32k memory corruption
19701| [136312] Microsoft Windows up to Server 2019 GDI information disclosure
19702| [136310] Microsoft Windows up to Server 2019 GDI information disclosure
19703| [136308] Microsoft Windows up to Server 2019 Audio Service privilege escalation
19704| [136306] Microsoft Windows up to Server 2019 Storage Service privilege escalation
19705| [136305] Microsoft Windows up to Server 2019 User Profile Service privilege escalation
19706| [136304] Microsoft Windows up to Server 2019 Common Log File System Driver privilege escalation
19707| [136303] Microsoft Windows up to Server 2019 Storage Service privilege escalation
19708| [136301] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19709| [136299] Microsoft Windows up to Server 2019 Local Security Authority Subsystem Service Reboot denial of service
19710| [136296] Microsoft Windows up to Server 2019 Common Log File System Driver memory corruption
19711| [136295] Microsoft Windows up to Server 2019 ALPC privilege escalation
19712| [136293] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19713| [136292] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19714| [136291] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19715| [136290] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19716| [136289] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19717| [136288] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19718| [136287] Microsoft Windows up to Server 2019 Hyper-V denial of service
19719| [136286] Microsoft Windows up to Server 2019 Hyper-V denial of service
19720| [136285] Microsoft Windows up to Server 2019 Hyper-V denial of service
19721| [136284] Microsoft Windows up to Server 2019 Kernel memory corruption
19722| [136276] Microsoft Windows up to Server 2019 Hyper-V memory corruption
19723| [136275] Microsoft Windows 10/10 1607/10 1703/10 1709/Server 2016 Hyper-V memory corruption
19724| [136274] Microsoft Windows up to Server 2019 ActiveX memory corruption
19725| [136273] Microsoft Windows up to Server 2019 Hyper-V memory corruption
19726| [134750] Microsoft ASP.NET Core 2.1/2.2 denial of service
19727| [134745] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
19728| [134744] Microsoft Windows up to Server 2019 GDI information disclosure
19729| [134743] Microsoft SharePoint Server 2013 SP1/2016 cross site scripting
19730| [134742] Microsoft SharePoint Enterprise Server 2016/2019 cross site scripting
19731| [134741] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
19732| [134740] Microsoft SharePoint Enterprise Server 2013 SP1/2016 privilege escalation
19733| [134739] Microsoft SharePoint Foundation 2010 SP2/2013 SP2 cross site scripting
19734| [134738] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
19735| [134737] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
19736| [134736] Microsoft Office 2010 SP2 Access Connectivity Engine memory corruption
19737| [134735] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
19738| [134734] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
19739| [134733] Microsoft Windows up to Server 2019 Unified Write Filter privilege escalation
19740| [134731] Microsoft Windows up to Server 2019 Symlink privilege escalation
19741| [134729] Microsoft Windows up to Server 2019 Storage Service privilege escalation
19742| [134725] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19743| [134724] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19744| [134723] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19745| [134722] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19746| [134721] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19747| [134720] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19748| [134719] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19749| [134718] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19750| [134717] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19751| [134716] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19752| [134715] Microsoft Windows up to Server 2019 Win32k memory corruption
19753| [134714] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19754| [134713] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19755| [134712] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19756| [134710] Microsoft Windows up to Server 2019 GDI information disclosure
19757| [134709] Microsoft Windows up to Server 2019 Kernel privilege escalation
19758| [134706] Microsoft Windows up to Server 2019 Error Reporting privilege escalation
19759| [134701] Microsoft Windows up to Server 2019 Windows Defender Application Control privilege escalation
19760| [134700] Microsoft Windows up to Server 2019 Diagnostic Hub privilege escalation
19761| [134699] Microsoft Windows up to Server 2019 NDIS ndis.sys memory corruption
19762| [134698] Microsoft Windows up to Server 2019 OLE memory corruption
19763| [134684] Microsoft Windows up to Server 2019 DHCP Server memory corruption
19764| [134678] Microsoft Windows up to Server 2019 GDI+ memory corruption
19765| [133236] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19766| [133234] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19767| [133232] Microsoft Azure DevOps Server 2019 cross site scripting
19768| [133229] Microsoft Azure DevOps Server 2019 cross site scripting
19769| [133224] Microsoft Exchange Server 2013 CU22/2016 CU11/2016 CU12/2019/2019 CU1 Outlook Web Access privilege escalation
19770| [133223] Microsoft Azure DevOps Server 2019 Content Security Policy privilege escalation
19771| [133222] Microsoft Windows up to Server 2019 Remote Registry Service memory corruption
19772| [133221] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19773| [133220] Microsoft Windows up to Server 2019 GDI Memory information disclosure
19774| [133219] Microsoft Windows up to Server 2019 Win32k Memory information disclosure
19775| [133218] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19776| [133217] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19777| [133216] Microsoft Windows up to Server 2019 Kernel Memory information disclosure
19778| [133215] Microsoft Windows up to Server 2019 VBScript Engine memory corruption
19779| [133214] Microsoft Windows up to Server 2019 AppX Deployment Service privilege escalation
19780| [133213] Microsoft Windows up to Server 2019 Kernel Memory information disclosure
19781| [133212] Microsoft Windows up to Server 2019 Terminal Services Memory information disclosure
19782| [133211] Microsoft Windows up to Server 2019 Task Scheduler information disclosure
19783| [133209] Microsoft Windows up to Server 2019 LUAFV Driver luafv.sys privilege escalation
19784| [133206] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016/2019 cross site scripting
19785| [133205] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site scripting
19786| [133204] Microsoft Office/Excel up to 2019 memory corruption
19787| [133203] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
19788| [133202] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
19789| [133201] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
19790| [133200] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
19791| [133199] Microsoft Office 2010 SP2 Access Connectivity Engine memory corruption
19792| [133198] Microsoft Exchange Server up to 2019 CU1 Outlook Web Access cross site scripting
19793| [133197] Microsoft ASP.NET Core 2.2 Request denial of service
19794| [133196] Microsoft Windows up to Server 2019 Win32k information disclosure
19795| [133195] Microsoft Windows up to Server 2019 LUAFV Driver luafv.sys privilege escalation
19796| [133194] Microsoft Windows up to Server 2019 GDI Memory information disclosure
19797| [133193] Microsoft Windows up to Server 2019 LUAFV Driver luafv.sys privilege escalation
19798| [133192] Microsoft Windows up to Server 2019 OLE Automation privilege escalation
19799| [133189] Microsoft Windows up to Server 2019 CSRSS memory corruption
19800| [133188] Microsoft Windows up to Server 2019 LUAFV Driver luafv.sys privilege escalation
19801| [133187] Microsoft Windows up to Server 2019 LUAFV Driver luafv.sys privilege escalation
19802| [133186] Microsoft Windows up to Server 2019 TCP/IP Stack Fragmented IP Packet information disclosure
19803| [133185] Microsoft Windows up to Server 2019 Win32k memory corruption
19804| [133183] Microsoft Windows up to Server 2019 Win32k memory corruption
19805| [133182] Microsoft Windows up to Server 2019 Win32k memory corruption
19806| [133181] Microsoft Office/Excel/PowerPoint up to 2019 URL Document Code Execution
19807| [133180] Microsoft Windows up to Server 2019 MS XML Code Execution
19808| [133179] Microsoft Windows up to Server 2019 MS XML Code Execution
19809| [133177] Microsoft Windows up to Server 2019 Device Guard luafv.sys privilege escalation
19810| [133174] Microsoft Windows up to Server 2019 GDI+ privilege escalation
19811| [133173] Microsoft Windows up to Server 2019 IOleCvt Interface privilege escalation
19812| [133166] Microsoft Windows up to Server 2019 MS XML Code Execution
19813| [133165] Microsoft Windows up to Server 2019 MS XML Code Execution
19814| [133164] Microsoft Windows up to Server 2019 MS XML Code Execution
19815| [133163] Microsoft Windows up to Server 2019 MS XML Code Execution
19816| [133162] Microsoft Windows up to Server 2019 MS XML Code Execution
19817| [131687] Microsoft Team Foundation Server 2017 Update 3.1/2018 Update 3.2/2018 Updated 1.2 cross site scripting
19818| [131685] Microsoft Windows up to Server 2019 SMB information disclosure
19819| [131684] Microsoft Visual Studio 2017 Version 15.9 C++ Redistributable Installer privilege escalation
19820| [131681] Microsoft Windows up to Server 2019 Win32k memory corruption
19821| [131679] Microsoft Windows up to Server 2019 Kernel information disclosure
19822| [131675] Microsoft SharePoint 2013 SP1/2016 cross site scripting
19823| [131674] Microsoft Windows up to Server 2019 Win32k information disclosure
19824| [131673] Microsoft Windows up to Server 2019 Kernel information disclosure
19825| [131672] Microsoft Windows up to Server 2019 GDI information disclosure
19826| [131671] Microsoft Windows up to Server 2019 VBScript Engine memory corruption
19827| [131668] Microsoft Windows up to Server 2019 AppX Deployment Server privilege escalation
19828| [131667] Microsoft Windows up to Server 2019 Comctl32.dll memory corruption
19829| [131663] Microsoft Windows up to Server 2019 Print Spooler information disclosure
19830| [131658] Microsoft Windows up to Server 2019 information disclosure
19831| [131657] Microsoft Windows up to Server 2019 denial of service
19832| [131656] Microsoft Office 2010 SP2 Connectivity Engine memory corruption
19833| [131653] Microsoft Windows up to Server 2019 SMB information disclosure
19834| [131652] Microsoft Windows up to Server 2019 SMB information disclosure
19835| [131651] Microsoft Windows up to Server 2019 Kernel information disclosure
19836| [131650] Microsoft Windows 10 1803/10 1809/Server 1803/Server 2019 Hyper-V denial of service
19837| [131649] Microsoft Windows up to Server 2019 Kernel memory corruption
19838| [131648] Microsoft Windows up to Server 2019 Hyper-V denial of service
19839| [131644] Microsoft Windows up to Server 2019 Hyper-V denial of service
19840| [131638] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19841| [131632] Microsoft Windows 10 1803/10 1809/Server 1803/Server 2019 DHCP Client memory corruption
19842| [131631] Microsoft Windows 10 1803/10 1809/Server 1803/Server 2019 DHCP Client memory corruption
19843| [131630] Microsoft Windows 10 1803/10 1809/Server 1803/Server 2019 DHCP Client memory corruption
19844| [131629] Microsoft Windows up to Server 2019 Deployment Services TFTP Server memory corruption
19845| [131628] Microsoft Windows up to Server 2019 ActiveX memory corruption
19846| [131619] Microsoft Windows up to Server 2019 MS XML privilege escalation
19847| [131334] Microsoft Team Foundation Server 2018 Update 3.2 cross site scripting
19848| [131333] Microsoft Team Foundation Server 2018 Update 3.2 cross site scripting
19849| [131328] Microsoft Windows up to Server 2016 Kernel information disclosure
19850| [130832] Microsoft 2013 SP1 spoofing
19851| [130828] Microsoft Exchange Server 2010 SP3/2013 CU22/2016 CU12/2019 CU1 EWS privilege escalation
19852| [130826] Microsoft Office 2010 SP2 Connectivity Engine memory corruption
19853| [130825] Microsoft Office up to 2019 Connectivity Engine memory corruption
19854| [130824] Microsoft Office up to 2019 Connectivity Engine memory corruption
19855| [130823] Microsoft Office up to 2019 Connectivity Engine privilege escalation
19856| [130822] Microsoft Office up to 2019 Connectivity Engine privilege escalation
19857| [130821] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
19858| [130820] Microsoft Windows up to Server 2012 R2 GDI information disclosure
19859| [130818] Microsoft Windows up to Server 2019 GDI information disclosure
19860| [130817] Microsoft Windows up to Server 2019 Storage Service privilege escalation
19861| [130814] Microsoft Windows up to Server 2019 privilege escalation
19862| [130809] Microsoft Windows up to Server 2019 Defender Firewall Security privilege escalation
19863| [130808] Microsoft Windows up to Server 2019 information disclosure
19864| [130807] Microsoft Windows up to Server 2019 Hyper-V information disclosure
19865| [130806] Microsoft Windows up to Server 2019 SMB privilege escalation
19866| [130805] Microsoft Windows up to Server 2019 Device Guard privilege escalation
19867| [130804] Microsoft Windows up to Server 2019 Device Guard privilege escalation
19868| [130803] Microsoft Windows up to Server 2019 SMB privilege escalation
19869| [130802] Microsoft Windows up to Server 2019 Win32k information disclosure
19870| [130801] Microsoft Windows up to Server 2019 Device Guard privilege escalation
19871| [130800] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19872| [130799] Microsoft Windows up to Server 2016 Win32k memory corruption
19873| [130798] Microsoft Windows up to Server 2019 GDI information disclosure
19874| [130797] Microsoft Windows up to Server 2019 GDI information disclosure
19875| [130796] Microsoft Windows up to Server 2019 GDI information disclosure
19876| [130793] Microsoft Windows up to Server 2019 GDI information disclosure
19877| [130792] Microsoft Windows up to Server 2019 HID information disclosure
19878| [130791] Microsoft Windows up to Server 2019 HID information disclosure
19879| [130790] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19880| [130789] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19881| [130788] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19882| [130787] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19883| [130786] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
19884| [130784] Microsoft Windows up to Server 2019 GDI+ memory corruption
19885| [130782] Microsoft Windows up to Server 2019 DHCP Server memory corruption
19886| [130781] Microsoft Windows up to Server 2019 GDI+ memory corruption
19887| [129847] Microsoft Team Foundation Server 2017 Update 3.1/2018 Update 1.2/2018 Update 3.2 information disclosure
19888| [129846] Microsoft Team Foundation Server 2018 Update 3.2 cross site scripting
19889| [129845] Microsoft Skype for Business 2015 CU 8 Request cross site scripting
19890| [128765] Microsoft Visual Studio 2017 Version 15.9 C++ Construct privilege escalation
19891| [128764] Microsoft Exchange Server 2010 SP3/2013 CU21/2016 CU10/2016 CU11/2019 PowerShell API information disclosure
19892| [128761] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
19893| [128760] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
19894| [128759] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
19895| [128758] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
19896| [128757] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
19897| [128756] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
19898| [128755] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
19899| [128754] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
19900| [128753] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
19901| [128752] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
19902| [128751] Microsoft Windows up to Server 2019 Data Sharing Service privilege escalation
19903| [128750] Microsoft Windows up to Server 2019 Runtime privilege escalation
19904| [128749] Microsoft Windows up to Server 2019 Kernel information disclosure
19905| [128747] Microsoft ASP.NET Core 2.1 Web Request denial of service
19906| [128746] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site scripting
19907| [128745] Microsoft Office up to 2019 Word Macro information disclosure
19908| [128742] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site scripting
19909| [128741] Microsoft SharePoint Enterprise Server 2016 cross site scripting
19910| [128740] Microsoft SharePoint Enterprise Server 2013 SP1 cross site scripting
19911| [128739] Microsoft Windows up to Server 2019 Kernel information disclosure
19912| [128738] Microsoft Windows up to Server 2019 Subsystem for Linux information disclosure
19913| [128737] Microsoft Windows up to Server 2019 COM Desktop Broker privilege escalation
19914| [128736] Microsoft Windows up to Server 2019 Kernel information disclosure
19915| [128735] Microsoft ASP.NET Core 2.1/2.2 Web Request denial of service
19916| [128733] Microsoft Windows up to Server 2019 Authentication Request privilege escalation
19917| [128729] Microsoft Visual Studio 2010 SP1/2012 Update 5 vscontent File information disclosure
19918| [128728] Microsoft Windows up to Server 2019 Kernel information disclosure
19919| [128727] Microsoft Windows up to Server 2019 Data Sharing Service privilege escalation
19920| [128726] Microsoft Windows up to Server 2019 Data Sharing Service privilege escalation
19921| [128725] Microsoft Windows up to Server 2019 Data Sharing Service privilege escalation
19922| [128718] Microsoft Windows up to Server 2019 Hyper-V memory corruption
19923| [128717] Microsoft Windows 10 1803/10 1809/Server 1803/Server 2019 Hyper-V memory corruption
19924| [127925] Microsoft SharePoint Enterprise Server 2016 Web Request cross site scripting
19925| [127882] Microsoft Dynamics NAV 2016/2017 Web Request cross site scripting
19926| [127881] Microsoft Windows 10 1809/Server 2019 Object denial of service
19927| [127880] Microsoft Windows up to Server 2019 Win32k Object memory corruption
19928| [127828] Microsoft Windows up to Server 2019 Win32k memory corruption
19929| [127827] Microsoft Windows 10 1809/Server 2019 DirectX information disclosure
19930| [127826] Microsoft Windows 10 1803/10 1809/Server 1803/Server 2019 Win32k ASLR privilege escalation
19931| [127825] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016 privilege escalation
19932| [127824] Microsoft Excel up to 2019 Out-of-Bounds memory corruption
19933| [127823] Microsoft Windows up to Server 2012 R2 Kernel information disclosure
19934| [127821] Microsoft Windows up to Server 2019 Connected User Experiences and Telemetry Service denial of service
19935| [127820] Microsoft Windows up to Server 2019 Kernel memory corruption
19936| [127819] Microsoft Exchange Server 2016 CU10/2016 CU11 Profile Data privilege escalation
19937| [127817] Microsoft Excel up to 2019 information disclosure
19938| [127816] Microsoft Windows up to Server 2019 GDI information disclosure
19939| [127815] Microsoft Windows up to Server 2019 GDI information disclosure
19940| [127814] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016 Search cross site request forgery
19941| [127812] Microsoft Windows up to Server 2019 Remote Procedure Call information disclosure
19942| [127806] Microsoft Outlook up to 2019 memory corruption
19943| [127805] Microsoft Excel up to 2019 memory corruption
19944| [127804] Microsoft Excel up to 2019 memory corruption
19945| [127803] Microsoft Windows up to Server 2019 Text-To-Speech memory corruption
19946| [127801] Microsoft Windows up to Server 2019 DNS Server privilege escalation
19947| [126938] Microsoft Team Foundation Server 2018 Update 1.1/2018 Update 3 Code Execution
19948| [126755] Microsoft .NET Core 2.1 privilege escalation
19949| [126754] Microsoft Skype for Business/Lync Server 2013 SP1/2016 Emoji denial of service
19950| [126750] Microsoft Windows up to Server 2019 ALPC privilege escalation
19951| [126749] Microsoft Exchange Server 2010/2013/2016/2019 privilege escalation
19952| [126747] Microsoft SharePoint Enterprise Server 2013 SP1 Folder information disclosure
19953| [126746] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
19954| [126745] Microsoft Project 2010 SP2/2013 SP1/2016 memory corruption
19955| [126744] Microsoft Office up to 2019 Word memory corruption
19956| [126743] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site scripting
19957| [126742] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site scripting
19958| [126739] Microsoft Windows up to Server 2012 R2 Win32k information disclosure
19959| [126737] Microsoft Windows up to Server 2012 R2 DirectX information disclosure
19960| [126736] Microsoft Windows up to Server 2019 Win32k memory corruption
19961| [126735] Microsoft Windows up to Server 2019 DirectX privilege escalation
19962| [126733] Microsoft Windows 10 1803/10 1809/Server 1803/Server 2019 DirectX memory corruption
19963| [126730] Microsoft Windows up to Server 2019 Active Directory Federation Services cross site scripting
19964| [126728] Microsoft Office/SharePoint 2010 SP2 Word memory corruption
19965| [126727] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
19966| [126726] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
19967| [126725] Microsoft Windows up to Server 2019 DirectX memory corruption
19968| [126722] Microsoft Windows up to Server 2019 PowerShell privilege escalation
19969| [126718] Microsoft Windows up to Server 2016 Search memory corruption
19970| [126717] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016/2019 memory corruption
19971| [126716] Microsoft Office up to 2019 Excel memory corruption
19972| [126714] Microsoft Windows up to Server 2019 PowerShell unknown vulnerability
19973| [126713] Microsoft Windows up to Server 2019 VBScript Engine memory corruption
19974| [126712] Microsoft Windows up to Server 2016 Graphics Component memory corruption
19975| [126711] Microsoft Windows up to Server 2019 Deployment Services TFTP Server memory corruption
19976| [125123] Microsoft Windows up to Server 2019 Codecs Library information disclosure
19977| [125122] Microsoft Windows up to Server 2016 TCP/IP information disclosure
19978| [125121] Microsoft Windows up to Server 2019 DirectX memory corruption
19979| [125120] Microsoft Windows up to Server 2019 Windows Media Player information disclosure
19980| [125119] Microsoft Windows up to Server 2019 Windows Media Player information disclosure
19981| [125116] Microsoft Exchange Server 2013 CU21/2016 CU10 privilege escalation
19982| [125115] Microsoft Windows up to Server 2019 Theme API privilege escalation
19983| [125114] Microsoft Windows up to Server 2019 Windows Shell privilege escalation
19984| [125113] Microsoft Windows up to Server 2019 Kernel memory corruption
19985| [125111] Microsoft Windows up to Server 2019 Device Guard Code Integrity Policy privilege escalation
19986| [125110] Microsoft Windows up to Server 2019 DNS Global Blocklist privilege escalation
19987| [125109] Microsoft Windows up to Server 2019 NTFS privilege escalation
19988| [125108] Microsoft Windows up to Server 2019 Filter Manager memory corruption
19989| [125107] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
19990| [125106] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
19991| [125105] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
19992| [125104] Microsoft SharePoint Enterprise Server 2016 cross site scripting
19993| [125102] Microsoft Office/Word 2010 SP2/2013 RT SP1/2013 SP1/2016/2019 Protected View memory corruption
19994| [125100] Microsoft Office/PowerPoint 2010 SP2/2013 RT SP1/2013 SP1/2016/2019 Protected View memory corruption
19995| [125099] Microsoft Office/Excel up to 2019 Protected View memory corruption
19996| [125098] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
19997| [125097] Microsoft Windows up to Server 2019 DirectX Graphics memory corruption
19998| [125096] Microsoft Windows up to Server 2019 Win32k memory corruption
19999| [125095] Microsoft Exchange Server 2013 CU21/2016 CU10 Outlook Web Access cross site scripting
20000| [125093] Microsoft Windows up to Server 2019 Hyper-V memory corruption
20001| [125092] Microsoft Windows up to Server 2019 Hyper-V memory corruption
20002| [125091] Microsoft Windows up to Server 2019 MS XML privilege escalation
20003| [124371] Microsoft Exchange Server up to 2010 SP3 Outlook Web Access /owa/auth/logon.aspx Parameter Server-Side Request Forgery
20004| [124217] Microsoft Windows Server 2012/Server 2016 Active Directory Federation Services /adfs/ls Server-Side Request Forgery
20005| [123995] Microsoft Lync 2011 on Mac Security Feature Messages Download privilege escalation
20006| [123881] Microsoft Windows up to Server 2016 Sandbox privilege escalation
20007| [123874] Microsoft Windows up to Server 2016 Kernel information disclosure
20008| [123872] Microsoft Windows 8.1/10/RT 8.1/Server 2012/Server 2012 R2 SMB information disclosure
20009| [123868] Microsoft Windows up to Server 2016 Hyper-V denial of service
20010| [123864] Microsoft Windows up to Server 2016 Hyper-V information disclosure
20011| [123862] Microsoft SharePoint Enterprise Server 2010 SP2/2013 RT SP1/2013 SP1/2016 cross site scripting
20012| [123861] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R information disclosure
20013| [123860] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
20014| [123859] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016 cross site scripting
20015| [123851] Microsoft Windows up to Server 2016 ALPC privilege escalation
20016| [123849] Microsoft Windows up to Server 2016 SMB denial of service
20017| [123846] Microsoft Office 2016 on Win/Mac memory corruption
20018| [123844] Microsoft Word 2013 RT SP1/2013 SP1/2016 PDF File memory corruption
20019| [123843] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
20020| [123842] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
20021| [123830] Microsoft Windows up to Server 2016 Hyper-V memory corruption
20022| [123828] Microsoft Windows up to Server 2016 Win32k Graphics privilege escalation
20023| [123827] Microsoft Windows up to Server 2016 Image memory corruption
20024| [123825] Microsoft Windows up to Server 2016 MSXML Parser privilege escalation
20025| [123823] Microsoft Windows up to Server 2016 Hyper-V privilege escalation
20026| [122887] Microsoft Office 2016 on Mac AutoUpdate memory corruption
20027| [122886] Microsoft Windows up to Server 2016 DirectX Graphics memory corruption
20028| [122885] Microsoft Windows up to Server 2016 DirectX Graphics memory corruption
20029| [122884] Microsoft Windows up to Server 2016 Win32k memory corruption
20030| [122883] Microsoft Windows up to Server 2016 DirectX Graphics memory corruption
20031| [122875] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R information disclosure
20032| [122874] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
20033| [122873] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R information disclosure
20034| [122871] Microsoft PowerPoint 2010 SP2 memory corruption
20035| [122870] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
20036| [122861] Microsoft Windows up to Server 2016 Microsoft COM for Windows privilege escalation
20037| [122850] Microsoft Visual Studio 2015 Update 3/2017/2017 Version 15.8 Diagnostic Hub privilege escalation
20038| [122849] Microsoft Windows up to Server 2016 Diagnostic Hub privilege escalation
20039| [122848] Microsoft Windows Security Feature 2FA weak authentication
20040| [122834] Microsoft Windows up to Server 2016 LNK memory corruption
20041| [122825] Microsoft Windows up to Server 2016 Graphics memory corruption
20042| [122823] Microsoft SQL Server 2016 SP1/2016 SP2/2017 memory corruption
20043| [121208] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R Attachment privilege escalation
20044| [121118] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
20045| [121116] Microsoft Windows up to Server 2016 Sandbox privilege escalation
20046| [121114] Microsoft Access 2013 SP1/2016/2016 C2R memory corruption
20047| [121111] Microsoft Windows up to Server 2016 Kernel memory corruption
20048| [121110] Microsoft Windows up to Server 2016 Wordpad privilege escalation
20049| [121107] Microsoft Windows up to Server 2016 DNSAPI DNSAPI.dll denial of service
20050| [121106] Microsoft SharePoint Enterprise Server 2013 SP1/2016 privilege escalation
20051| [121105] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
20052| [121098] Microsoft Office 2016/2016 C2R memory corruption
20053| [121092] Microsoft Windows up to Server 2016 FTP Server denial of service
20054| [121090] Microsoft Visual Studio up to 2017 Version 15.8 Preview privilege escalation
20055| [119479] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
20056| [119477] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016 information disclosure
20057| [119476] Microsoft Publisher 2010 SP2 OLE Object PUB File privilege escalation
20058| [119475] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016 Attachment privilege escalation
20059| [119474] Microsoft Windows up to Server 2016 GDI information disclosure
20060| [119470] Microsoft Windows up to Server 2016 HTTP HTTP.sys denial of service
20061| [119468] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
20062| [119467] Microsoft Windows up to Server 2016 Hypervisor privilege escalation
20063| [119465] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
20064| [119464] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
20065| [119463] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
20066| [119461] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
20067| [119460] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
20068| [119459] Microsoft Windows up to Server 2016 memory corruption
20069| [119457] Microsoft Windows up to Server 2016 Desktop Bridge privilege escalation
20070| [119456] Microsoft Windows up to Server 2016 Kernel information disclosure
20071| [119455] Microsoft Windows up to Server 2016 denial of service
20072| [119454] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
20073| [119452] Microsoft Windows up to Server 2016 HIDParser memory corruption
20074| [119448] Microsoft Windows up to Server 2016 Code Integrity Module denial of service
20075| [119447] Microsoft Windows up to Server 2016 NTFS privilege escalation
20076| [119441] Microsoft Windows up to Server 2016 Media Foundation memory corruption
20077| [119437] Microsoft Windows up to Server 2016 HTTP Protocol Stack Http.sys memory corruption
20078| [119436] Microsoft Windows up to Server 2016 memory corruption
20079| [119431] Microsoft Windows up to Server 2016 DNSAPI DNSAPI.dll DNS Response privilege escalation
20080| [118120] Microsoft Office 2016 on Mac XML Data Code Execution
20081| [117561] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1 Web Request cross site scripting
20082| [117560] Microsoft Exchange Server up to 2016 CU9 Code Execution memory corruption
20083| [117559] Microsoft Exchange Server 2016 CU8/2016 CU9 Outlook Web Access Web Request cross site scripting
20084| [117558] Microsoft Windows up to Server 2016 Code Execution memory corruption
20085| [117507] Microsoft Infopath 2013 SP1 memory corruption
20086| [117505] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R information disclosure
20087| [117504] Microsoft Office 2010 SP2 information disclosure
20088| [117503] Microsoft Exchange Server 2013 CU19/2013 CU20/2016 CU8/2016 CU9 Outlook Web Access cross site scripting
20089| [117502] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016 cross site scripting
20090| [117501] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
20091| [117500] Microsoft Exchange Server 2016 CU8/2016 CU9 Outlook Web Access cross site scripting
20092| [117499] Microsoft Exchange Server up to 2016 CU9 information disclosure
20093| [117498] Microsoft Office 2016 C2R Security Feature privilege escalation
20094| [117497] Microsoft SharePoint Enterprise Server 2010/2013 SP1/2016 cross site scripting
20095| [117480] Microsoft Windows up to Server 2016 COM Serialized privilege escalation
20096| [117473] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
20097| [117472] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
20098| [117471] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
20099| [117470] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
20100| [117469] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
20101| [117468] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
20102| [117444] Microsoft Windows up to Server 2016 Hyper-V vSMB memory corruption
20103| [117443] Microsoft Windows up to Server 2016 Hyper-V memory corruption
20104| [117442] Microsoft Windows up to Server 2016 VBScript Engine memory corruption
20105| [116132] Microsoft Office 2016 Memory information disclosure
20106| [116051] Microsoft SharePoint Enterprise Server 2016 cross site scripting
20107| [116050] Microsoft SharePoint Enterprise Server 2010 SP2/2013/2016 cross site scripting
20108| [116049] Microsoft SharePoint Enterprise Server 2013/2016 privilege escalation
20109| [116048] Microsoft Windows up to Server 2016 DirectX Graphics Kernel Subsystem memory corruption
20110| [116047] Microsoft Windows up to Server 2016 OpenType Font Driver atmfd.dll memory corruption
20111| [116046] Microsoft SharePoint Enterprise Server 2013/2016 Share cross site scripting
20112| [116045] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
20113| [116039] Microsoft Windows up to Server 2016 Remote Desktop Protocol denial of service
20114| [116031] Microsoft Windows up to Server 2016 Kernel ASLR information disclosure
20115| [116030] Microsoft Windows up to Server 2016 SNMP Service denial of service
20116| [116026] Microsoft Windows up to Server 2016 Kernel information disclosure
20117| [116024] Microsoft Windows up to Server 2016 HTTP.sys denial of service
20118| [116023] Microsoft Office up to 2016 C2R information disclosure
20119| [116022] Microsoft Excel 2010 SP2 memory corruption
20120| [116020] Microsoft Windows 10 1607/10 1703/10 1709/Server 1709/Server 2016 Active Directory privilege escalation
20121| [116019] Microsoft Windows up to Server 2016 Kernel information disclosure
20122| [116018] Microsoft Office 2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
20123| [116017] Microsoft Excel up to 2016 C2R memory corruption
20124| [116016] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 Graphics memory corruption
20125| [116014] Microsoft Office 2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
20126| [116013] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1 memory corruption
20127| [116008] Microsoft Windows up to Server 2016 Graphics memory corruption
20128| [116007] Microsoft Windows up to Server 2016 Graphics memory corruption
20129| [116006] Microsoft Windows up to Server 2016 Graphics memory corruption
20130| [116005] Microsoft Windows up to Server 2016 Graphics memory corruption
20131| [116004] Microsoft Windows up to Server 2016 Graphics memory corruption
20132| [116003] Microsoft Windows up to Server 2016 VBScript Engine memory corruption
20133| [115994] Microsoft Windows up to Server 2016 Malware Protection Engine memory corruption
20134| [115804] Microsoft Windows up to Server 2016 Malware Protection Engine privilege escalation
20135| [114579] Microsoft Exchange Server up to 2017 CU8 Outlook Web Access information disclosure
20136| [114574] Microsoft SharePoint Enterprise Server 2016 privilege escalation
20137| [114573] Microsoft SharePoint Enterprise Server 2016 cross site scripting
20138| [114571] Microsoft Exchange Server 2016 CU7/2016 CU8 Outlook Web Access information disclosure
20139| [114570] Microsoft Exchange Server 2010 SP3/2013 CU18/2013 CU19/2016 CU7/2016 CU8 Outlook Web Access Fake privilege escalation
20140| [114565] Microsoft Windows 10 1607/10 1703/10 1709/Server 1709/Server 2016 Kernel information disclosure
20141| [114564] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
20142| [114562] Microsoft SharePoint Enterprise Server 2016 cross site scripting
20143| [114560] Microsoft SharePoint Enterprise Server 2016 cross site scripting
20144| [114559] Microsoft SharePoint Enterprise Server 2016 cross site scripting
20145| [114558] Microsoft SharePoint Enterprise Server 2016 cross site scripting
20146| [114557] Microsoft SharePoint Enterprise Server 2016 cross site scripting
20147| [114556] Microsoft SharePoint Enterprise Server 2016 cross site scripting
20148| [114555] Microsoft SharePoint Enterprise Server 2016 cross site scripting
20149| [114554] Microsoft SharePoint Enterprise Server 2016 cross site scripting
20150| [114553] Microsoft SharePoint Enterprise Server 2016 cross site scripting
20151| [114552] Microsoft SharePoint Enterprise Server 2016 cross site scripting
20152| [114551] Microsoft Excel up to 2016 C2R Security Feature privilege escalation
20153| [114549] Microsoft Access 2010 SP2/2013 SP1/2016 memory corruption
20154| [114548] Microsoft Windows up to Server 2016 CNG Security Feature cng.sys privilege escalation
20155| [114547] Microsoft Windows up to Server 2016 Kernel information disclosure
20156| [114546] Microsoft Windows up to Server 2016 Kernel information disclosure
20157| [114545] Microsoft Windows up to Server 2016 Kernel information disclosure
20158| [114544] Microsoft Windows up to Server 2016 Kernel information disclosure
20159| [114543] Microsoft Windows up to Server 2016 Kernel information disclosure
20160| [114542] Microsoft Windows up to Server 2016 Kernel information disclosure
20161| [114541] Microsoft Windows up to Server 2016 Kernel information disclosure
20162| [114540] Microsoft Windows up to Server 2016 Kernel information disclosure
20163| [114536] Microsoft Windows up to Server 2016 CredSSP privilege escalation
20164| [114535] Microsoft Windows up to Server 2016 Hyper-V denial of service
20165| [114531] Microsoft Windows up to Server 2016 Windows Installer privilege escalation
20166| [114530] Microsoft Windows up to Server 2016 GDI privilege escalation
20167| [114529] Microsoft Windows up to Server 2016 GDI privilege escalation
20168| [114527] Microsoft Windows up to Server 2016 Kernel information disclosure
20169| [114526] Microsoft Windows up to Server 2016 Kernel information disclosure
20170| [114525] Microsoft Windows up to Server 2016 Kernel information disclosure
20171| [114522] Microsoft Windows 10 1607/10 1703/Server 2016 Desktop Bridge privilege escalation
20172| [114521] Microsoft Windows up to Server 2016 Video Control privilege escalation
20173| [114520] Microsoft Windows 10/Server 1709/Server 2016 Desktop Bridge privilege escalation
20174| [114518] Microsoft Windows up to Server 2016 Remote Assistance information disclosure
20175| [114517] Microsoft Windows 10/Server 1709/Server 2016 Desktop Bridge VFS privilege escalation
20176| [114516] Microsoft Windows up to Server 2016 Windows Shell privilege escalation
20177| [113835] Microsoft Identity Manager 2016 SP1 cross site scripting
20178| [113264] Microsoft Windows 8.1/RT 8.1/Server 2012 R2 SMBv2/SMBv3 denial of service
20179| [113260] Microsoft Windows up to Server 2016 Kernel memory corruption
20180| [113259] Microsoft Windows 10/Server 1709/Server 2016 NTFS privilege escalation
20181| [113254] Microsoft Windows up to Server 2016 Kernel information disclosure
20182| [113253] Microsoft Windows 10/Server 1709/Server 2016 Kernel memory corruption
20183| [113252] Microsoft Windows up to Server 2016 Kernel memory corruption
20184| [113250] Microsoft Windows 10/Server 1709/Server 2016 Kernel memory corruption
20185| [113249] Microsoft Windows up to Server 2016 Kernel memory corruption
20186| [113248] Microsoft Windows up to Server 2016 Kernel information disclosure
20187| [113243] Microsoft Windows 10/Server 2016 MultiPoint Management privilege escalation
20188| [113242] Microsoft Windows up to Server 2016 Common Log File System Driver memory corruption
20189| [113241] Microsoft Windows up to Server 2016 Common Log File System Driver memory corruption
20190| [113240] Microsoft Windows 10/Server 1709/Server 2016 AppContainer privilege escalation
20191| [113237] Microsoft SharePoint Enterprise Server 2016 cross site scripting
20192| [113236] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
20193| [113233] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 Uninitialized Memory information disclosure
20194| [113232] Microsoft Excel 2016 memory corruption
20195| [113230] Microsoft Windows up to Server 2016 Scripting Engine information disclosure
20196| [113229] Microsoft Windows up to Server 2016 StructuredQuery memory corruption
20197| [111580] Microsoft Office 2016 on Mac Email Attachment spoofing
20198| [111571] Microsoft SharePoint Enterprise Server 2013/2016 Access cross site scripting
20199| [111567] Microsoft Office 2010/2013/2016 memory corruption
20200| [111564] Microsoft Word 2016 memory corruption
20201| [111562] Microsoft SharePoint Server 2010/2013/2016 Web Request cross site scripting
20202| [111561] Microsoft SharePoint Server 2010/2013/2016 Web Request cross site scripting
20203| [128730] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
20204| [111358] Microsoft Windows up to Server 2016 IPsec denial of service
20205| [110553] Microsoft Office 2016 C2R information disclosure
20206| [110552] Microsoft SharePoint Enterprise Server 2016 Web Request privilege escalation
20207| [110551] Microsoft Excel 2016 C2R memory corruption
20208| [110550] Microsoft PowerPoint 2013 RT SP1/2013 SP1/2016 information disclosure
20209| [110549] Microsoft Exchange Server 2016 CU6/2016 CU7 Outlook Web Access privilege escalation
20210| [110547] Microsoft Windows up to Server 2016 its:// Protocol information disclosure
20211| [110531] Microsoft Windows 10/Server 2016 Device Guard privilege escalation
20212| [110522] Microsoft Windows up to Server 2016 RRAS privilege escalation
20213| [110350] Microsoft Windows up to Server 2016 Malware Protection Engine memory corruption
20214| [110318] Microsoft Windows up to Server 2016 Malware Protection Engine memory corruption
20215| [109391] Microsoft SharePoint Enterprise Server 2016 Project Server cross site request forgery
20216| [109389] Microsoft Excel 2016 Click-to-Run memory corruption
20217| [109360] Microsoft Windows up to Server 2016 Windows Search denial of service
20218| [107759] Microsoft Windows up to Server 2016 SMB denial of service
20219| [107757] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
20220| [107756] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
20221| [107753] Microsoft Windows 10/Server 2016 SMB privilege escalation
20222| [107744] Microsoft Windows up to Server 2016 DNSAPI DNSAPI.dll DNS Response privilege escalation
20223| [107741] Microsoft Outlook 2016 Secure Connection Mail information disclosure
20224| [107740] Microsoft Windows up to Server 2016 Graphics memory corruption
20225| [107739] Microsoft Windows up to Server 2016 Graphics memory corruption
20226| [107738] Microsoft Windows up to Server 2016 Search information disclosure
20227| [107734] Microsoft Windows 10/Server 2016 SMB privilege escalation
20228| [107732] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016 Bypass privilege escalation
20229| [107730] Microsoft Windows up to Server 2016 Search Remote memory corruption
20230| [107729] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
20231| [107728] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
20232| [107727] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
20233| [107724] Microsoft Windows up to Server 2016 Text Services Framework memory corruption
20234| [107723] Microsoft Windows up to Server 2016 SMB information disclosure
20235| [107698] Microsoft Office 2016 memory corruption
20236| [107593] InFocus Mondopad 2.2.08 Excel Spreadsheet Microsoft Office Document Credentials information disclosure
20237| [106544] Microsoft Exchange Server 2016 Outlook Web Access cross site scripting
20238| [106531] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
20239| [106529] Microsoft PowerPoint 2016 memory corruption
20240| [106523] Microsoft Windows up to Server 2016 PDF Library memory corruption
20241| [106518] Microsoft Edge on Win10/Server 2016 memory corruption
20242| [106516] Microsoft Windows up to Server 2016 PDF Library memory corruption
20243| [106498] Microsoft Windows up to Server 2016 Shell privilege escalation
20244| [106496] Microsoft Windows up to Server 2016 Uniscribe information disclosure
20245| [106495] Microsoft Windows up to Server 2012 R2 Uniscribe memory corruption
20246| [106492] Microsoft Windows Server 2012/Server 2012 R2/Server 2016 DHCP Service memory corruption
20247| [106489] Microsoft Windows up to Server 2016 Graphics Win32k win32k!fsc_CalcGrayRow memory corruption
20248| [106474] Microsoft Office 2016 memory corruption
20249| [106473] Microsoft SharePoint Server 2013 SP1 cross site scripting
20250| [106472] Microsoft Windows up to Server 2016 Bluetooth Driver Object BlueBorne spoofing
20251| [106470] Microsoft Excel 2011 on Mac memory corruption
20252| [106455] Microsoft Exchange Server 2013/2016 information disclosure
20253| [106454] Microsoft Windows up to Server 2016 Windows NetBT Session Services race condition memory corruption
20254| [105048] Microsoft Edge on Win10/Server 2016 Scripting Engine memory corruption
20255| [105047] Microsoft Edge on Win10/Server 2016 Scripting Engine EntryCall memory corruption
20256| [105046] Microsoft Edge on Win10/Server 2016 Javascript Engine memory corruption
20257| [105040] Microsoft Edge on Win10/Server 2016 Scripting Engine memory corruption
20258| [105038] Microsoft Edge on Win10/Server 2016 Javascript Engine Out-of-Bounds memory corruption
20259| [105037] Microsoft Edge on Win10/Server 2016 Javascript Engine PreVisitCatch memory corruption
20260| [105035] Microsoft SharePoint Server 2010 SP2 cross site scripting
20261| [105033] Microsoft Edge 38.14393.1066.0 on Win10/Server 2016 Use-After-Free information disclosure
20262| [105029] Microsoft Edge on Win10/Server 2016 Javascript Engine ProcessLinkFailedAsmJsModule memory corruption
20263| [105027] Microsoft Edge on Win10/Server 2016 _SelectValueInternal information disclosure
20264| [105024] Microsoft Edge on Win10/Server 2016 Javascript Engine memory corruption
20265| [105023] Microsoft Edge on Win10/Server 2016 Javascript Engine memory corruption
20266| [105017] Microsoft Windows up to Server 2016 Error Reporting information disclosure
20267| [105013] Microsoft Windows 10 1607/10 1703/Server 2016 Hyper-V denial of service
20268| [105011] Microsoft Windows up to Server 2016 Windows Search memory corruption
20269| [105010] Microsoft Windows up to Server 2016 Win32k memory corruption
20270| [105009] Microsoft Windows up to Server 2016 Input Method Editor memory corruption
20271| [105008] Microsoft SQL Server 2012/2014/2016 Analysis Services information disclosure
20272| [104990] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
20273| [104989] Microsoft Windows up to Server 2016 NetBIOS denial of service
20274| [104584] Microsoft Outlook up to 2016 C2R Document File privilege escalation
20275| [104583] Microsoft Outlook up to 2016 C2R Email memory corruption
20276| [104582] Microsoft Outlook up to 2016 C2R Object memory corruption
20277| [103468] Microsoft Exchange Server 2010 SP3/2013 CU16/2013 SP3/2016 CU5 Open Redirect
20278| [103446] Microsoft Windows up to Server 2016 Search Object privilege escalation
20279| [103445] Microsoft Windows up to Server 2016 Wordpad privilege escalation
20280| [103444] Microsoft Windows up to Server 2016 Explorer denial of service
20281| [103442] Microsoft Windows 10/Server 2016 HoloLens WiFi Packet privilege escalation
20282| [103441] Microsoft Windows up to Server 2016 Object HTTP.sys information disclosure
20283| [103431] Microsoft Windows up to Server 2016 PowerShell PSObject Object privilege escalation
20284| [103429] Microsoft Windows up to Server 2016 Kerberos weak authentication
20285| [103426] Microsoft Exchange Server 2010 SP3/2013 CU16/2013 SP3/2016 CU5 OWA Request cross site scripting
20286| [103425] Microsoft Exchange Server 2010 SP3/2013 CU16/2013 SP3/2016 CU5 OWA Request cross site scripting
20287| [103420] Microsoft Windows up to Server 2016 Kerberos Bypass privilege escalation
20288| [103417] Microsoft Windows up to Server 2016 Windows Shell privilege escalation
20289| [102544] Microsoft Edge on Win10/Server 2016 Fetch API information disclosure
20290| [102543] Microsoft Edge on Win10/Server 2016 Javascript XML DOM Object information disclosure
20291| [102463] Microsoft Project Server 2013 SP1 cross site scripting
20292| [102460] Microsoft Outlook 2016 on Mac HTML spoofing
20293| [102448] Microsoft SharePoint Enterprise Server 2016 Reflected cross site scripting
20294| [102446] Microsoft Office up to 2016 privilege escalation
20295| [102445] Microsoft Office 2010 SP2/2011/2013 RT SP1/2013 SP1/2016 privilege escalation
20296| [102443] Microsoft Office up to 2016 privilege escalation
20297| [102412] Microsoft Windows up to Server 2016 PDF information disclosure
20298| [102397] Microsoft Outlook 2010 SP1/2013 SP1/2016 DLL Loader privilege escalation
20299| [102396] Microsoft Office 2013 SP1/2016 DLL Loader privilege escalation
20300| [102386] Microsoft Windows up to Server 2012 R2 Uniscribe privilege escalation
20301| [102385] Microsoft Windows up to Server 2016 Font Library privilege escalation
20302| [102376] Microsoft Windows up to Server 2016 CAB File privilege escalation
20303| [102375] Microsoft Windows up to Server 2016 PDF Parser privilege escalation
20304| [102374] Microsoft Windows up to Server 2016 PDF Parser privilege escalation
20305| [102373] Microsoft Windows up to Server 2016 Uniscribe Font USP10!MergeLigRecords memory corruption
20306| [101817] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
20307| [101816] Microsoft Windows up to Server 2016 Malware Protection Engine setCaller memory corruption
20308| [101815] Microsoft Windows up to Server 2016 Malware Protection Engine Use-After-Free memory corruption
20309| [101814] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
20310| [101813] Microsoft Windows up to Server 2016 Malware Protection Engine memory corruption
20311| [101812] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
20312| [101811] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
20313| [101810] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
20314| [101028] Microsoft Windows 10/Server 2016 Hyper-V vSMB privilege escalation
20315| [101020] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
20316| [101019] Microsoft Skype for Business 2016 memory corruption
20317| [101018] Microsoft SharePoint 2010 SP2/2013 SP1/2016 memory corruption
20318| [101016] Microsoft PowerPoint 2011 on Mac memory corruption
20319| [101015] Microsoft PowerPoint 2011 on Mac memory corruption
20320| [101014] Microsoft Office 2010 SP2/2016 memory corruption
20321| [101013] Microsoft Office 2010 SP2/2016 memory corruption
20322| [101002] Microsoft Windows up to Server 2016 SMBv1 Server memory corruption
20323| [101001] Microsoft Windows up to Server 2016 SMBv1 Server memory corruption
20324| [101000] Microsoft Windows up to Server 2016 SMBv1 Server memory corruption
20325| [100999] Microsoft Windows up to Server 2016 SMBv1 Server memory corruption
20326| [100918] Microsoft Windows 8/8.1/10/Server 2012/Server 2016 Malware Protection Service Type Confusion privilege escalation
20327| [99697] Microsoft SharePoint Server 2010 SP1/2010 SP2 Excel Services cross site scripting
20328| [99683] Microsoft Windows 10 1607/10 1703/Server 2012 R2/Server 2016 Active Directory Lockout privilege escalation
20329| [99682] Microsoft Outlook 2011 on Mac HTML Tag Validator spoofing
20330| [99681] Microsoft Windows up to Server 2016 OLE Integrity-Level Check privilege escalation
20331| [99667] Microsoft Windows 10/Server 2016 Active Directory Service Unresponsive denial of service
20332| [98272] Microsoft Windows up to 10/Server 2016 Local Session privilege escalation
20333| [98096] Microsoft Exchange 2013 SP1 privilege escalation
20334| [98095] Microsoft Lync for Mac 2011 Certificate Validation weak authentication
20335| [98094] Microsoft SharePoint Server 2013 SP1 cross site scripting
20336| [98093] Microsoft SharePoint Server/Office Web Apps 2010 SP2 memory corruption
20337| [98091] Microsoft SharePoint Server/Office Web Apps 2010 SP2 memory corruption
20338| [98090] Microsoft SharePoint Server 2010 SP2/2013 SP1 information disclosure
20339| [98089] Microsoft Office Web Apps 2013 SP1 memory corruption
20340| [98082] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 denial of service
20341| [98081] Microsoft Excel up to 2016 information disclosure
20342| [98080] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
20343| [98079] Microsoft Word 2016 memory corruption
20344| [98076] Microsoft Lync/Skype for Business 2010/2013/2016 Graphics Component privilege escalation
20345| [98075] Microsoft Lync/Skype for Business 2010/2013/2016 GDI+ information disclosure
20346| [98074] Microsoft Lync/Skype for Business 2010/2013/2016 GDI+ information disclosure
20347| [98073] Microsoft Office 2010 SP2/Word Viewer Graphics Component information disclosure
20348| [98069] Microsoft Windows up to Server 2012 R2 Color Management memory corruption
20349| [98056] Microsoft Windows up to Server 2016 DNS Query information disclosure
20350| [98054] Microsoft Windows up to Server 2016 SMBv2/SMBv3 NULL Pointer Dereference memory corruption
20351| [98017] Microsoft Windows up to Server 2016 PDF memory corruption
20352| [98015] Microsoft Windows 10/Server 2016 Hyper-V denial of service
20353| [98013] Microsoft Windows 10/Server 2016 Hyper-V vSMB memory corruption
20354| [98007] Microsoft Windows 10/Server 2016 Hyper-V Network Switch denial of service
20355| [98006] Microsoft Windows 10/Server 2016 Hyper-V vSMB memory corruption
20356| [96521] Microsoft Windows 8.1/10/Server 2012/Server 2016 SMB Response mrxsmb20.sys denial of service
20357| [95781] Microsoft PowerPoint 2016 Java Embedded Object privilege escalation
20358| [95125] Microsoft Word/SharePoint Enterprise Server 2016 Document privilege escalation
20359| [94451] Microsoft Office 2011 memory corruption
20360| [94447] Microsoft Office 2010 SP2 memory corruption
20361| [94446] Microsoft Office 2016 memory corruption
20362| [94444] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 OLE DLL Loader memory corruption
20363| [94443] Microsoft Office up to 2016 information disclosure
20364| [94442] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 privilege escalation
20365| [93964] Microsoft Windows 7 Excel Starter 2010 XXE information disclosure
20366| [93543] Microsoft SQL Server 2016 FILESTREAM Path privilege escalation
20367| [93540] Microsoft Excel 2010 SP2/2011/2016 memory corruption
20368| [93416] Microsoft SQL Server 2014 SP2/2016/up to 2012 SP3 Server Agent atxcore.dll privilege escalation
20369| [93415] Microsoft SQL Server 2016 MDS API cross site scripting
20370| [93414] Microsoft SQL Server up to 2012 SP3 RDBMS Engine privilege escalation
20371| [93413] Microsoft SQL Server 2016/up to 2014 SP2 RDBMS Engine privilege escalation
20372| [93412] Microsoft SQL Server 2016 RDBMS Engine privilege escalation
20373| [93393] Microsoft Office up to 2016 memory corruption
20374| [93392] Microsoft Office up to 2016 memory corruption
20375| [93391] Microsoft Office up to 2016 memory corruption
20376| [93389] Microsoft Windows up to Server 2016 Media Foundation memory corruption
20377| [93388] Microsoft Windows up to Server 2016 Animation Manager Stylesheets memory corruption
20378| [92587] Microsoft Windows 8.1/10/RT 8.1/Server 2012/Server 2012 R2 Transaction Manager privilege escalation
20379| [92584] Microsoft Office up to 2016 memory corruption
20380| [91571] Microsoft Windows 8.1/10/RT 8.1/Server 2012/Server 2012 R2 PDF Library information disclosure
20381| [91570] Microsoft Windows 8.1/10/RT 8.1/Server 2012/Server 2012 R2 PDF Library information disclosure
20382| [91556] Microsoft Exchange 2016 Meeting Invation cross site scripting
20383| [91555] Microsoft Exchange 2013/2016 Link spoofing
20384| [91550] Microsoft Office 2016 memory corruption
20385| [91547] Microsoft Office 2010 memory corruption
20386| [91543] Microsoft Office up to 2016 memory corruption
20387| [91541] Microsoft Office 2013/2016 APP-V ASLR privilege escalation
20388| [90711] Microsoft Windows 8.1/10/RT 8.1/Server 2012/Server 2012 R2 PDF privilege escalation
20389| [90710] Microsoft Windows 8.1/RT 8.1/Server 2012/Server 2012 R2 Netlogon privilege escalation
20390| [90704] Microsoft Office 2013/2013 RT/2016 memory corruption
20391| [89043] Microsoft Office up to 2016 memory corruption
20392| [89041] Microsoft Office up to 2016 memory corruption
20393| [89040] Microsoft Office 2010 SP2/2011/2013 RT SP1/2013 SP1/2016 memory corruption
20394| [89038] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 Security Feature privilege escalation
20395| [89037] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
20396| [87961] Microsoft Windows up to Server 2012 R2 Search denial of service
20397| [87959] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 PDF information disclosure
20398| [87958] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 PDF memory corruption
20399| [87957] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 PDF information disclosure
20400| [87956] Microsoft Exchange 2013/2016 Oracle Outside In Libraries information disclosure
20401| [87944] Microsoft Windows Server 2012/Server 2012 R2 Virtual PCI Memory information disclosure
20402| [87940] Microsoft Windows Server 2012/Server 2012 R2 DNS Server Use-After-Free memory corruption
20403| [87936] Microsoft Office up to 2016 memory corruption
20404| [87166] Microsoft Windows up to Server 2012 R2 DirectX Graphics Kernel Subsystem privilege escalation
20405| [87156] Microsoft Windows 8.1/10/RT 8.1/Server 2012 R2 Shell memory corruption
20406| [87149] Microsoft Office up to 2016 memory corruption
20407| [87148] Microsoft Office 2010 Graphics memory corruption
20408| [87146] Microsoft Office 2011/2013/2013 RT/2016 memory corruption
20409| [82229] Microsoft Excel 2010 SP2 Office Document memory corruption
20410| [82223] Microsoft Windows 8.1/10/Server 2012 R2 Hyper-V Memory information disclosure
20411| [82222] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 Memory information disclosure
20412| [82221] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 Hyper-V privilege escalation
20413| [81274] Microsoft Office up to 2016 memory corruption
20414| [81270] Microsoft Windows 8.1/10/RT 8.1/Server 2012/Server 2012 R2 PDF Library memory corruption
20415| [81269] Microsoft Windows up to Server 2012 R2 Media Parser memory corruption
20416| [81268] Microsoft Windows up to Server 2012 R2 Media Parser memory corruption
20417| [80886] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
20418| [80885] Microsoft Windows 7 SP1/8.1/10/Server 2012/Server 2012 R2 RDP memory corruption
20419| [80878] Microsoft Windows Server 2012 R2 Active Directory Federation Service denial of service
20420| [80874] Microsoft Windows 7 SP1/8.1/10/Server 2012/Server 2012 R2 RDP privilege escalation
20421| [80870] Microsoft Office up to 2016 memory corruption
20422| [80868] Microsoft Office up to 2016 memory corruption
20423| [80867] Microsoft Office up to 2016 memory corruption
20424| [80865] Microsoft Windows 8.1/RT 8.1/Server 2012/Server 2012 R2 DLL Loader memory corruption
20425| [80860] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 Reader memory corruption
20426| [80859] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 PDF Library memory corruption
20427| [80231] Microsoft Excel up to 2016 Office Document memory corruption
20428| [80229] Microsoft Exchange Server 2013 CU 10/2013 CU 11/2013 SP1/2016 Outlook Web Access cross site scripting
20429| [80228] Microsoft Exchange Server 2016 Outlook Web Access cross site scripting
20430| [80227] Microsoft Exchange Server 2013 CU 10/2013 SP1/2016 Outlook Web Access cross site scripting
20431| [80226] Microsoft Exchange Server 2016 Outlook Web Access cross site scripting
20432| [80218] Microsoft Office up to 2016 ASLR privilege escalation
20433| [80217] Microsoft SharePoint Foundation 2013 SP1 Access Control Policy cross site scripting
20434| [80216] Microsoft Office up to 2016 Office Document memory corruption
20435| [80206] Microsoft SharePoint Foundation 2013 SP1 Access Control Policy cross site scripting
20436| [128763] Microsoft Exchange Server 2016 CU10/2016 CU11/2019 memory corruption
20437| [79508] Microsoft Windows up to Server 2012 R2 Library Loader memory corruption
20438| [79500] Microsoft Office 2010/2011/2016 memory corruption
20439| [79183] Microsoft Windows up to Server 2012 R2 IPsec denial of service
20440| [79173] Microsoft Windows up to Server 2012 R2 Graphics information disclosure
20441| [79117] Microsoft Outlook 2011/2016 on Mac HTML spoofing
20442| [78375] Microsoft SharePoint Server/SharePoint Foundation 2013 SP1 cross site scripting
20443| [77645] Microsoft Exchange Server 2013 CU8/2013 CU9 Outlook Web Access cross site scripting
20444| [77644] Microsoft Exchange Server 2013 CU8/2013 CU9 Outlook Web Access cross site scripting
20445| [77638] Microsoft Lync Server 2013 cross site scripting
20446| [77628] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
20447| [77612] Microsoft Exchange Server 2013 CU8/2013 CU9 Outlook Web Access Stack-Based information disclosure
20448| [77050] Microsoft Office up to 2016 memory corruption
20449| [77037] Microsoft Windows Server 2012/Server 2012 R2 System Center Operations Manager cross site scripting
20450| [76461] Microsoft Windows up to Server 2012 R2 Domain-Controller Communication Credentials information disclosure
20451| [76460] Microsoft Windows 7 SP1/8/Server 2012 RDP Server Service memory corruption
20452| [76448] Microsoft Windows 8.1/Server 2012 R2 Hyper-V memory corruption
20453| [75793] Microsoft Exchange Server 2013 CU8 cross site scripting
20454| [75792] Microsoft Exchange Server 2013 SP1 CU8 cross site request forgery
20455| [75791] Microsoft Office 2013 SP1 Office Document Uninitialized Memory memory corruption
20456| [75787] Microsoft Exchange Server 2013 SP1 CU8 Same Origin Policy privilege escalation
20457| [75786] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1 Office Document memory corruption
20458| [66976] Microsoft Access 2010 VBA Datatype denial of service
20459| [74848] Microsoft SharePoint Foundation/SharePoint Server 2013 SP1 cross site scripting
20460| [74842] Microsoft Windows 8.1/Server 2012 R2 Hyper-V denial of service
20461| [74836] Microsoft Project Server 2010 SP2/2013 SP1 cross site scripting
20462| [74835] Microsoft Office 2011 on Mac Use-After-Free cross site scripting
20463| [74834] Microsoft Windows Server 2012 R2 Active Directory Federation Services 3.0 privilege escalation
20464| [74833] Microsoft Windows 7 SP1/8/8.1/Server 2012/Server 2012 R2 HTTP Request HTTP.sys privilege escalation
20465| [74393] Microsoft SharePoint Server 2013 Foundation cross site scripting
20466| [73967] Microsoft Office up to 2013 SP1 Office File memory corruption
20467| [73966] Microsoft Office up to 2013 SP1 RTF File memory corruption
20468| [73965] Microsoft Office up to 2013 SP1 Use-After-Free memory corruption
20469| [73961] Microsoft Windows 7 SP1/8/8.1/Server 2012/Server 2012 R2 Remote Desktop Protocol Object Management denial of service
20470| [69162] Microsoft System Center Virtual Machine Manager 2012 privilege escalation
20471| [69160] Microsoft Windows up to Server 2012 Process privilege escalation
20472| [69156] Microsoft Office 2010 Object memory corruption
20473| [68593] Microsoft Windows up to Server 2012 Network Location Awareness Service privilege escalation
20474| [68417] Microsoft Exchange 2013 Outlook Web Access Token spoofing
20475| [68191] Microsoft SharePoint 2010 cross site scripting
20476| [67828] Microsoft ASP.NET MVC 2/3/4/5/5.1 System.Web.Mvc.dll cross site scripting
20477| [67518] Microsoft Lync 2013 denial of service
20478| [67517] Microsoft Lync 2013 Script Reflected cross site scripting
20479| [67516] Microsoft Lync 2010/2013 denial of service
20480| [67362] Microsoft Windows up to Server 2012 R2 Remote Procedure Call privilege escalation
20481| [67360] Microsoft SharePoint 2013 App Permission Management cross site scripting
20482| [13549] Microsoft Windows 7/8/8.1/Server 2012 Remote Desktop Protocol weak encryption
20483| [13547] Microsoft Lync 2010/2013 Meeting cross site scripting
20484| [13228] Microsoft Office 2013 Document privilege escalation
20485| [68577] Microsoft ASP.NET 2014.3.1209 Telerik UI RadAsyncUpload directory traversal
20486| [12267] Microsoft Forefront Security for Exchange Server 2010 Mail memory corruption
20487| [12263] Microsoft Windows up to Server 2012 Direct2D 2D Geometric Figure memory corruption
20488| [12238] Microsoft Windows 8/RT/Server 2012 IPv6 denial of service
20489| [12185] Microsoft .NET Framework 2/4 HMAC weak authentication
20490| [12183] Microsoft .NET Framework 2/4 DTD denial of service
20491| [11673] Microsoft Windows Live Movie Maker 2011 WAV File denial of service
20492| [11468] Microsoft Exchange 2010/2013 cross site scripting
20493| [11466] Microsoft Office 2013 File Response information disclosure
20494| [11457] Microsoft SharePoint Server/Office Web Apps 2010 SP1/2010 SP2/2013 W3WP Service Account privilege escalation
20495| [11150] Microsoft Windows 8/Server 2012 Hyper-V Data Structure Value Crash privilege escalation
20496| [11004] Microsoft Windows Server 2012 R2 RDP Restricted Admin Mode weak authentication
20497| [10250] Microsoft SharePoint Server up to 2013 W3WP Process denial of service
20498| [10249] Microsoft SharePoint 2010/2003/2007/2.0/3.0 Workflow memory corruption
20499| [10248] Microsoft SharePoint Server up to 2013 cross site scripting
20500| [9943] Microsoft Windows Server 2012 NAT Driver ICMP Packet denial of service
20501| [8739] Microsoft Windows Essentials up to 2012 Windows Writer Eingabe information disclosure
20502| [8725] Microsoft Lync 2010/2013 Use-After-Free memory corruption
20503| [8722] Microsoft Windows 8/RT/Server 2012 HTTP.sys denial of service
20504| [8206] Microsoft SharePoint Server 2010 SP1 HTML Sanitization Component cross site scripting
20505| [8203] Microsoft Windows up to 2012 AD LDAP Query denial of service
20506| [8200] Microsoft SharePoint Server 2013 ACL information disclosure
20507| [7971] Microsoft Office for Mac 2011 up to 14.3.1 on Mac HTML5 Mail Message Parser File information disclosure
20508| [7969] Microsoft OneNote 2010 SP1 ONE File information disclosure
20509| [7968] Microsoft SharePoint Server 2010 SP1 Input Validator Eingabe Crash denial of service
20510| [7967] Microsoft SharePoint Server 2010 SP1 User Account Eingabe Crash information disclosure
20511| [7966] Microsoft SharePoint Server 2010 SP1 Eingabe Crash cross site scripting
20512| [7965] Microsoft SharePoint Server 2010 SP1 User Account Callback URL privilege escalation
20513| [7964] Microsoft Visio 2010 Tree Object Type File memory corruption
20514| [7343] Microsoft Lync 2012 HTTP Format String
20515| [7258] Microsoft Windows up to 8/Server 2012 SSL/TLS race condition
20516| [7230] Microsoft Excel 2010 SP1 on 32-bit XLS File Formatting Information Crash denial of service
20517| [6831] Microsoft Office Picture Manager 2010 File memory corruption
20518| [62720] EMC NetWorker Module for Microsoft Applications up to 2.2.0 memory corruption
20519| [6624] Microsoft SQL Server up to 2012 Report Manager cross site scripting
20520| [62238] Microsoft Visual Studio Team Foundation Server 2010 cross site scripting
20521| [5946] Microsoft Visio/Visio Viewer up to 2010 SP1 File memory corruption
20522| [5644] Microsoft SharePoint 2010 scriptesx.ashx cross site scripting
20523| [5641] Microsoft SharePoint 2010 cross site scripting
20524| [60943] Microsoft Dynamics AX 2012 Enterprise Portal cross site scripting
20525| [12311] Microsoft Lync 2010 Search race condition
20526| [60570] Microsoft Forefront Unified Access Gateway 2010 information disclosure
20527| [60569] Microsoft Forefront Unified Access Gateway 2010 spoofing
20528| [60208] Microsoft Visio Viewer 2010 memory corruption
20529| [60207] Microsoft Visio Viewer 2010 memory corruption
20530| [60206] Microsoft Visio Viewer 2010 memory corruption
20531| [4640] Microsoft SharePoint 2010 inplview.aspx cross site scripting
20532| [4636] Microsoft SharePoint 2010 wizardlist.aspx cross site scripting
20533| [4635] Microsoft SharePoint 2010 themeweb.aspx cross site scripting
20534| [59008] Microsoft Forefront Unified Access Gateway 2010 Crash denial of service
20535| [58995] Microsoft Forefront Unified Access Gateway 2010 memory corruption
20536| [58994] Microsoft Forefront Unified Access Gateway 2010 Reflected cross site scripting
20537| [58993] Microsoft Forefront Unified Access Gateway 2010 Reflected cross site scripting
20538| [4424] Microsoft Host Integration Server up to 2010 denial of service
20539| [4420] Microsoft Forefront Unified Access Gateway 2010 memory corruption
20540| [58487] Microsoft SharePoint Foundation 2010 cross site scripting
20541| [58486] Microsoft SharePoint Foundation 2010 Reflected cross site scripting
20542| [58485] Microsoft SharePoint Foundation 2010 EditForm.aspx cross site scripting
20543| [4414] Microsoft SharePoint 2010 cross site scripting
20544| [4413] Microsoft SharePoint 2010/2007/3.0 XML/XLS unknown vulnerability
20545| [91971] Microsoft Skype 2.2.x/5.2.x/5.3.x denial of service
20546| [57693] Microsoft Forefront Threat Management Gateway 2010 NSPLookupServiceNext memory corruption
20547| [56028] Microsoft Data Access Components 2.8 memory corruption
20548| [55777] Microsoft Windows Movie Maker 2.6 memory corruption
20549| [55424] Microsoft Forefront Unified Access Gateway 2010 Signurl.asp cross site scripting
20550| [55415] Microsoft Forefront Unified Access Gateway 2010 cross site scripting
20551| [55414] Microsoft Forefront Unified Access Gateway 2010 cross site scripting
20552| [55413] Microsoft Forefront Unified Access Gateway 2010 spoofing
20553| [54341] Microsoft Windows Movie Maker 2.1 memory corruption
20554| [54549] Microsoft PowerPoint 2010 pptimpconv.dll memory corruption
20555| [4009] Microsoft NET Framework 2.x/3.x denial of service
20556| [45681] Microsoft Internet Explorer 8 Beta 2 privilege escalation
20557| [45449] Microsoft Internet Explorer 8 Beta 2 XSS Filter cross site scripting
20558| [45448] Microsoft Internet Explorer 8 Beta 2 XSS Filter cross site scripting
20559| [45446] Microsoft Internet Explorer 8 Beta 2 XSS Filter cross site scripting
20560| [2927] Microsoft Data Access Components 2.x ADODB.Connection ActiveX Control memory corruption
20561| [32692] Microsoft XML Core Services up to 2.6 memory corruption
20562| [32691] Microsoft XML Core Services up to 2.6 memory corruption
20563|
20564| MITRE CVE - https://cve.mitre.org:
20565| [CVE-2013-3661] The EPATHOBJ::bFlatten function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not check whether linked-list traversal is continually accessing the same list member, which allows local users to cause a denial of service (infinite traversal) via vectors that trigger a crafted PATHRECORD chain.
20566| [CVE-2013-3660] The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 does not properly initialize a pointer for the next object in a certain list, which allows local users to obtain write access to the PATHRECORD chain, and consequently gain privileges, by triggering excessive consumption of paged memory and then making many FlattenPath function calls, aka "Win32k Read AV Vulnerability."
20567| [CVE-2013-3174] DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 allows remote attackers to execute arbitrary code via a crafted GIF file, aka "DirectShow Arbitrary Memory Overwrite Vulnerability."
20568| [CVE-2013-3173] Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Win32k Buffer Overwrite Vulnerability."
20569| [CVE-2013-3172] Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to cause a denial of service (system hang) via a crafted application that leverages improper handling of objects in memory, aka "Win32k Buffer Overflow Vulnerability."
20570| [CVE-2013-3171] The serialization functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly check the permissions of delegate objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a partial-trust relationship, aka "Delegate Serialization Vulnerability."
20571| [CVE-2013-3167] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Information Disclosure Vulnerability."
20572| [CVE-2013-3154] The signature-update functionality in Windows Defender on Microsoft Windows 7 and Windows Server 2008 R2 relies on an incorrect pathname, which allows local users to gain privileges via a Trojan horse application in the %SYSTEMDRIVE% top-level directory, aka "Microsoft Windows 7 Defender Improper Pathname Vulnerability."
20573| [CVE-2013-3138] Integer overflow in the TCP/IP kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (system hang) via crafted TCP packets, aka "TCP/IP Integer Overflow Vulnerability."
20574| [CVE-2013-3136] The kernel in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, and Windows 8 on 32-bit platforms does not properly handle unspecified page-fault system calls, which allows local users to obtain sensitive information from kernel memory via a crafted application, aka "Kernel Information Disclosure Vulnerability."
20575| [CVE-2013-3134] The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 on 64-bit platforms does not properly allocate arrays of structures, which allows remote attackers to execute arbitrary code via a crafted .NET Framework application that changes array data, aka "Array Allocation Vulnerability."
20576| [CVE-2013-3133] Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "Anonymous Method Injection Vulnerability."
20577| [CVE-2013-3132] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "Delegate Reflection Bypass Vulnerability."
20578| [CVE-2013-3131] Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5, and Silverlight 5 before 5.1.20513.0, does not properly prevent changes to data in multidimensional arrays of structures, which allows remote attackers to execute arbitrary code via (1) a crafted .NET Framework application or (2) a crafted Silverlight application, aka "Array Access Violation Vulnerability."
20579| [CVE-2013-1345] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Vulnerability."
20580| [CVE-2013-1340] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Dereference Vulnerability."
20581| [CVE-2013-1339] The Print Spooler in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly manage memory during deletion of printer connections, which allows remote authenticated users to execute arbitrary code via a crafted request, aka "Print Spooler Vulnerability."
20582| [CVE-2013-1336] The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check signatures, which allows remote attackers to make undetected changes to signed XML documents via unspecified vectors that preserve signature validity, aka "XML Digital Signature Spoofing Vulnerability."
20583| [CVE-2013-1335] Microsoft Word 2003 SP3 and Word Viewer allow remote attackers to execute arbitrary code via crafted shape data in a Word document, aka "Word Shape Corruption Vulnerability."
20584| [CVE-2013-1334] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Window Handle Vulnerability."
20585| [CVE-2013-1332] dxgkrnl.sys (aka the DirectX graphics kernel subsystem) in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "DirectX Graphics Kernel Subsystem Double Fetch Vulnerability."
20586| [CVE-2013-1331] Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Office document, leading to improper memory allocation, aka "Office Buffer Overflow Vulnerability."
20587| [CVE-2013-1329] Integer signedness error in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers a buffer underflow, aka "Publisher Buffer Underflow Vulnerability."
20588| [CVE-2013-1328] Microsoft Publisher 2003 SP3, 2007 SP3, and 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers incorrect pointer handling, aka "Publisher Pointer Handling Vulnerability."
20589| [CVE-2013-1327] Integer signedness error in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers an improper memory allocation, aka "Publisher Signed Integer Vulnerability."
20590| [CVE-2013-1323] Microsoft Publisher 2003 SP3 does not properly handle NULL values for unspecified data items, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Incorrect NULL Value Handling Vulnerability."
20591| [CVE-2013-1322] Microsoft Publisher 2003 SP3 does not properly check table range data, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Invalid Range Check Vulnerability."
20592| [CVE-2013-1321] Microsoft Publisher 2003 SP3 does not properly check the data type of an unspecified return value, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Return Value Validation Vulnerability."
20593| [CVE-2013-1320] Buffer overflow in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Buffer Overflow Vulnerability."
20594| [CVE-2013-1319] Microsoft Publisher 2003 SP3 does not properly check the return value of an unspecified method, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Return Value Handling Vulnerability."
20595| [CVE-2013-1318] Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers access to an invalid pointer, aka "Publisher Corrupt Interface Pointer Vulnerability."
20596| [CVE-2013-1317] Integer overflow in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers an improper allocation-size calculation, aka "Publisher Integer Overflow Vulnerability."
20597| [CVE-2013-1316] Microsoft Publisher 2003 SP3 does not properly validate the size of an unspecified array, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Negative Value Allocation Vulnerability."
20598| [CVE-2013-1302] Microsoft Communicator 2007 R2, Lync 2010, Lync 2010 Attendee, and Lync Server 2013 do not properly handle objects in memory, which allows remote attackers to execute arbitrary code via an invitation that triggers access to a deleted object, aka "Lync RCE Vulnerability."
20599| [CVE-2013-1301] Microsoft Visio 2003 SP3 2007 SP3, and 2010 SP1 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, aka "XML External Entities Resolution Vulnerability."
20600| [CVE-2013-1300] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Memory Allocation Vulnerability."
20601| [CVE-2013-1295] The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "CSRSS Memory Corruption Vulnerability."
20602| [CVE-2013-1294] Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Kernel Race Condition Vulnerability."
20603| [CVE-2013-1293] The NTFS kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via a crafted application that leverages improper handling of objects in memory, aka "NTFS NULL Pointer Dereference Vulnerability."
20604| [CVE-2013-1292] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Win32k Race Condition Vulnerability."
20605| [CVE-2013-1291] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 Gold and SP1, and Windows 8 allows local users to cause a denial of service (reboot) via a crafted OpenType font, aka "OpenType Font Parsing Vulnerability" or "Win32k Font Parsing Vulnerability."
20606| [CVE-2013-1287] The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Windows USB Descriptor Vulnerability," a different vulnerability than CVE-2013-1285 and CVE-2013-1286.
20607| [CVE-2013-1286] The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Windows USB Descriptor Vulnerability," a different vulnerability than CVE-2013-1285 and CVE-2013-1287.
20608| [CVE-2013-1285] The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Windows USB Descriptor Vulnerability," a different vulnerability than CVE-2013-1286 and CVE-2013-1287.
20609| [CVE-2013-1283] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Win32k Race Condition Vulnerability."
20610| [CVE-2013-1281] The NFS server in Microsoft Windows Server 2008 R2 and R2 SP1 and Server 2012 allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via an attempted renaming of a file or folder located on a read-only share, aka "NULL Dereference Vulnerability."
20611| [CVE-2013-1280] The kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Reference Count Vulnerability."
20612| [CVE-2013-1279] Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages incorrect handling of objects in memory, aka "Kernel Race Condition Vulnerability," a different vulnerability than CVE-2013-1278.
20613| [CVE-2013-1278] Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages incorrect handling of objects in memory, aka "Kernel Race Condition Vulnerability," a different vulnerability than CVE-2013-1279.
20614| [CVE-2013-1277] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
20615| [CVE-2013-1276] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
20616| [CVE-2013-1275] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
20617| [CVE-2013-1274] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
20618| [CVE-2013-1273] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
20619| [CVE-2013-1272] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
20620| [CVE-2013-1271] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
20621| [CVE-2013-1270] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
20622| [CVE-2013-1269] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
20623| [CVE-2013-1268] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
20624| [CVE-2013-1267] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
20625| [CVE-2013-1266] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
20626| [CVE-2013-1265] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
20627| [CVE-2013-1264] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
20628| [CVE-2013-1263] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
20629| [CVE-2013-1262] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
20630| [CVE-2013-1261] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
20631| [CVE-2013-1260] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
20632| [CVE-2013-1259] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
20633| [CVE-2013-1258] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
20634| [CVE-2013-1257] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
20635| [CVE-2013-1256] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
20636| [CVE-2013-1255] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
20637| [CVE-2013-1254] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
20638| [CVE-2013-1253] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
20639| [CVE-2013-1252] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
20640| [CVE-2013-1251] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
20641| [CVE-2013-1250] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
20642| [CVE-2013-1249] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
20643| [CVE-2013-1248] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
20644| [CVE-2013-0095] Outlook in Microsoft Office for Mac 2008 before 12.3.6 and Office for Mac 2011 before 14.3.2 allows remote attackers to trigger access to a remote URL and consequently confirm the rendering of an HTML e-mail message by including unspecified HTML5 elements and leveraging the installation of a WebKit browser on the victim's machine, aka "Unintended Content Loading Vulnerability."
20645| [CVE-2013-0077] Quartz.dll in DirectShow in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows remote attackers to execute arbitrary code via crafted media content in (1) a media file, (2) a media stream, or (3) a Microsoft Office document, aka "Media Decompression Vulnerability."
20646| [CVE-2013-0076] The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Reference Count Vulnerability."
20647| [CVE-2013-0075] The TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (reboot) via a crafted packet that terminates a TCP connection, aka "TCP FIN WAIT Vulnerability."
20648| [CVE-2013-0073] The Windows Forms (aka WinForms) component in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly restrict the privileges of a callback function during object creation, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "WinForms Callback Elevation Vulnerability."
20649| [CVE-2013-0013] The SSL provider component in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle encrypted packets, which allows man-in-the-middle attackers to conduct SSLv2 downgrade attacks against (1) SSLv3 sessions or (2) TLS sessions by intercepting handshakes and injecting content, aka "Microsoft SSL Version 3 and TLS Protocol Security Feature Bypass Vulnerability."
20650| [CVE-2013-0011] The Print Spooler in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted print job, aka "Windows Print Spooler Components Vulnerability."
20651| [CVE-2013-0010] Cross-site scripting (XSS) vulnerability in Microsoft System Center Operations Manager 2007 SP1 and R2 allows remote attackers to inject arbitrary web script or HTML via crafted input, aka "System Center Operations Manager Web Console XSS Vulnerability," a different vulnerability than CVE-2013-0009.
20652| [CVE-2013-0009] Cross-site scripting (XSS) vulnerability in Microsoft System Center Operations Manager 2007 SP1 and R2 allows remote attackers to inject arbitrary web script or HTML via crafted input, aka "System Center Operations Manager Web Console XSS Vulnerability," a different vulnerability than CVE-2013-0010.
20653| [CVE-2013-0008] win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle window broadcast messages, which allows local users to gain privileges via a crafted application, aka "Win32k Improper Message Handling Vulnerability."
20654| [CVE-2013-0004] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate the permissions of objects in memory, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "Double Construction Vulnerability."
20655| [CVE-2013-0003] Buffer overflow in a System.DirectoryServices.Protocols (S.DS.P) namespace method in Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a missing array-size check during a memory copy operation, aka "S.DS.P Buffer Overflow Vulnerability."
20656| [CVE-2013-0002] Buffer overflow in the Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages improper counting of objects during a memory copy operation, aka "WinForms Buffer Overflow Vulnerability."
20657| [CVE-2013-0001] The Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 4, and 4.5 does not properly initialize memory arrays, which allows remote attackers to obtain sensitive information via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a pointer to an unmanaged memory location, aka "System Drawing Information Disclosure Vulnerability."
20658| [CVE-2012-5672] Microsoft Excel Viewer (aka Xlview.exe) and Excel in Microsoft Office 2007 (aka Office 12) allow remote attackers to cause a denial of service (read access violation and application crash) via a crafted spreadsheet file, as demonstrated by a .xls file with battery voltage data.
20659| [CVE-2012-4791] Microsoft Exchange Server 2007 SP3 and 2010 SP1 and SP2 allows remote authenticated users to cause a denial of service (Information Store service hang) by subscribing to a crafted RSS feed, aka "RSS Feed May Cause Exchange DoS Vulnerability."
20660| [CVE-2012-4786] The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allow remote attackers to execute arbitrary code via a crafted TrueType Font (TTF) file, aka "TrueType Font Parsing Vulnerability."
20661| [CVE-2012-4776] The Web Proxy Auto-Discovery (WPAD) functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not validate configuration data that is returned during acquisition of proxy settings, which allows remote attackers to execute arbitrary JavaScript code by providing crafted data during execution of (1) an XAML browser application (aka XBAP) or (2) a .NET Framework application, aka "Web Proxy Auto-Discovery Vulnerability."
20662| [CVE-2012-4774] Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allow remote attackers to execute arbitrary code via a crafted (1) file name or (2) subfolder name that triggers use of unallocated memory as the destination of a copy operation, aka "Windows Filename Parsing Vulnerability."
20663| [CVE-2012-2897] The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT, as used by Google Chrome before 22.0.1229.79 and other programs, do not properly handle objects in memory, which allows remote attackers to execute arbitrary code via a crafted TrueType font file, aka "Windows Font Parsing Vulnerability" or "TrueType Font Parsing Vulnerability."
20664| [CVE-2012-2556] The OpenType Font (OTF) driver in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to execute arbitrary code via a crafted OpenType font file, aka "OpenType Font Parsing Vulnerability."
20665| [CVE-2012-2553] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application, aka "Win32k Use After Free Vulnerability."
20666| [CVE-2012-2552] Cross-site scripting (XSS) vulnerability in the SQL Server Report Manager in Microsoft SQL Server 2000 Reporting Services SP2 and SQL Server 2005 SP4, 2008 SP2 and SP3, 2008 R2 SP1, and 2012 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "Reflected XSS Vulnerability."
20667| [CVE-2012-2551] The server in Kerberos in Microsoft Windows Server 2008 R2 and R2 SP1, and Windows 7 Gold and SP1, allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via a crafted session request, aka "Kerberos NULL Dereference Vulnerability."
20668| [CVE-2012-2543] Stack-based buffer overflow in Microsoft Excel 2007 SP2 and SP3 and 2010 SP1
20669| [CVE-2012-2539] Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1
20670| [CVE-2012-2536] Cross-site scripting (XSS) vulnerability in Microsoft Systems Management Server 2003 SP3 and System Center Configuration Manager 2007 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Reflected XSS Vulnerability."
20671| [CVE-2012-2530] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application, aka "Win32k Use After Free Vulnerability."
20672| [CVE-2012-2529] Integer overflow in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Windows Kernel Integer Overflow Vulnerability."
20673| [CVE-2012-2528] Use-after-free vulnerability in Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1
20674| [CVE-2012-2527] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application, aka "Win32k Use After Free Vulnerability."
20675| [CVE-2012-2524] Microsoft Office 2007 SP2 and SP3 and 2010 SP1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Computer Graphics Metafile (CGM) file, aka "CGM File Format Memory Corruption Vulnerability."
20676| [CVE-2012-2520] Cross-site scripting (XSS) vulnerability in Microsoft InfoPath 2007 SP2 and SP3 and 2010 SP1, Communicator 2007 R2, Lync 2010 and 2010 Attendee, SharePoint Server 2007 SP2 and SP3 and 2010 SP1, Groove Server 2010 SP1, Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010 SP1, and Office Web Apps 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted string, aka "HTML Sanitization Vulnerability."
20677| [CVE-2012-2519] Untrusted search path vulnerability in Entity Framework in ADO.NET in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, and 4 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .NET application, aka ".NET Framework Insecure Library Loading Vulnerability."
20678| [CVE-2012-1896] Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly consider trust levels during construction of output data, which allows remote attackers to obtain sensitive information via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka "Code Access Security Info Disclosure Vulnerability."
20679| [CVE-2012-1895] The reflection implementation in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4 does not properly enforce object permissions, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka "Reflection Bypass Vulnerability."
20680| [CVE-2012-1893] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate callback parameters during creation of a hook procedure, which allows local users to gain privileges via a crafted application, aka "Win32k Incorrect Type Handling Vulnerability."
20681| [CVE-2012-1890] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle keyboard-layout files, which allows local users to gain privileges via a crafted application, aka "Keyboard Layout Vulnerability."
20682| [CVE-2012-1887] Use-after-free vulnerability in Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 SP1, and Office 2008 and 2011 for Mac, allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel SST Invalid Length Use After Free Vulnerability."
20683| [CVE-2012-1886] Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 SP1
20684| [CVE-2012-1885] Heap-based buffer overflow in Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 SP1
20685| [CVE-2012-1870] The CBC mode in the TLS protocol, as used in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and other products, allows remote web servers to obtain plaintext data by triggering multiple requests to a third-party HTTPS server and sniffing the network during the resulting HTTPS session, aka "TLS Protocol Vulnerability."
20686| [CVE-2012-1867] Integer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted TrueType font file that triggers incorrect memory allocation, aka "Font Resource Refcount Integer Overflow Vulnerability."
20687| [CVE-2012-1866] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle user-mode input passed to kernel mode for driver objects, which allows local users to gain privileges via a crafted application, aka "Clipboard Format Atom Name Handling Vulnerability."
20688| [CVE-2012-1865] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle user-mode input passed to kernel mode for driver objects, which allows local users to gain privileges via a crafted application, aka "String Atom Class Name Handling Vulnerability," a different vulnerability than CVE-2012-1864.
20689| [CVE-2012-1864] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle user-mode input passed to kernel mode for driver objects, which allows local users to gain privileges via a crafted application, aka "String Atom Class Name Handling Vulnerability," a different vulnerability than CVE-2012-1865.
20690| [CVE-2012-1863] Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2007 SP2 and SP3 Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "SharePoint Reflected List Parameter Vulnerability."
20691| [CVE-2012-1862] Open redirect vulnerability in Microsoft Office SharePoint Server 2007 SP2 and SP3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka "SharePoint URL Redirection Vulnerability."
20692| [CVE-2012-1860] Microsoft Office SharePoint Server 2007 SP2 and SP3, SharePoint Server 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 do not properly check permissions for search scopes, which allows remote authenticated users to obtain sensitive information or cause a denial of service (data modification) by changing a parameter in a search-scope URL, aka "SharePoint Search Scope Vulnerability."
20693| [CVE-2012-1858] The toStaticHTML API (aka the SafeHTML component) in Microsoft Internet Explorer 8 and 9, Communicator 2007 R2, and Lync 2010 and 2010 Attendee does not properly handle event attributes and script, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted HTML document, aka "HTML Sanitization Vulnerability."
20694| [CVE-2012-1856] The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Server 2000 SP4, SQL Server 2005 SP4, SQL Server 2008 SP2, SP3, R2, R2 SP1, and R2 SP2, Commerce Server 2002 SP4, Commerce Server 2007 SP2, Commerce Server 2009 Gold and R2, Host Integration Server 2004 SP1, Visual FoxPro 8.0 SP1, Visual FoxPro 9.0 SP2, and Visual Basic 6.0 Runtime allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption, aka "MSCOMCTL.OCX RCE Vulnerability."
20695| [CVE-2012-1855] Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly handle function pointers, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka ".NET Framework Memory Access Vulnerability."
20696| [CVE-2012-1854] Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1
20697| [CVE-2012-1851] Format string vulnerability in the Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted response, aka "Print Spooler Service Format String Vulnerability."
20698| [CVE-2012-1850] The Remote Administration Protocol (RAP) implementation in the LanmanWorkstation service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle RAP responses, which allows remote attackers to cause a denial of service (service hang) via crafted RAP packets, aka "Remote Administration Protocol Denial of Service Vulnerability."
20699| [CVE-2012-1848] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly handle user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Scrollbar Calculation Vulnerability."
20700| [CVE-2012-1847] Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1
20701| [CVE-2012-1537] Heap-based buffer overflow in DirectPlay in DirectX 9.0 through 11.1 in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 allows remote attackers to execute arbitrary code via a crafted Office document, aka "DirectPlay Heap Overflow Vulnerability."
20702| [CVE-2012-1528] Integer overflow in Windows Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 allows local users to gain privileges via a crafted briefcase, aka "Windows Briefcase Integer Overflow Vulnerability."
20703| [CVE-2012-1527] Integer underflow in Windows Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 allows local users to gain privileges via a crafted briefcase, aka "Windows Briefcase Integer Underflow Vulnerability."
20704| [CVE-2012-1459] The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, nProtect Anti-Virus 2011-01-17.01, Panda Antivirus 10.0.2.7, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field corresponding to that entire entry, plus part of the header of the next entry. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
20705| [CVE-2012-1457] The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field that exceeds the total TAR file size. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
20706| [CVE-2012-1453] The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Trend Micro AntiVirus 9.120.0.1004, McAfee Gateway (formerly Webwasher) 2010.1C, Emsisoft Anti-Malware 5.1.0.1, CA eTrust Vet Antivirus 36.1.8511, Antiy Labs AVL SDK 2.0.3.7, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Rising Antivirus 22.83.00.03, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via a CAB file with a modified coffFiles field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.
20707| [CVE-2012-1443] The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Command Antivirus 5.2.11.5, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Emsisoft Anti-Malware 5.1.0.1, PC Tools AntiVirus 7.0.3.5, F-Prot Antivirus 4.6.2.117, VirusBuster 13.6.151.0, Fortinet Antivirus 4.2.254.0, Antiy Labs AVL SDK 2.0.3.7, K7 AntiVirus 9.77.3565, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Jiangmin Antivirus 13.0.900, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Sophos Anti-Virus 4.61.0, NOD32 Antivirus 5795, Avira AntiVir 7.11.1.163, Norman Antivirus 6.06.12, McAfee Anti-Virus Scanning Engine 5.400.0.1158, Panda Antivirus 10.0.2.7, McAfee Gateway (formerly Webwasher) 2010.1C, Trend Micro AntiVirus 9.120.0.1004, Comodo Antivirus 7424, Bitdefender 7.2, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, nProtect Anti-Virus 2011-01-17.01, AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, avast! Antivirus 4.8.1351.0 and 5.0.677.0, and VBA32 3.12.14.2 allows user-assisted remote attackers to bypass malware detection via a RAR file with an initial MZ character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different RAR parser implementations.
20708| [CVE-2012-1420] The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Panda Antivirus 10.0.2.7, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial \7fELF character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
20709| [CVE-2012-1194] The resolver in the DNS Server service in Microsoft Windows Server 2008 before R2 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack.
20710| [CVE-2012-0185] Heap-based buffer overflow in Microsoft Excel 2007 SP2 and SP3 and 2010 Gold and SP1, Excel Viewer, and Office Compatibility Pack SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet that triggers incorrect handling of memory during opening, aka "Excel MergeCells Record Heap Overflow Vulnerability."
20711| [CVE-2012-0184] Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1
20712| [CVE-2012-0183] Microsoft Word 2003 SP3 and 2007 SP2 and SP3, Office 2008 and 2011 for Mac, and Office Compatibility Pack SP2 and SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, aka "RTF Mismatch Vulnerability."
20713| [CVE-2012-0182] Microsoft Word 2007 SP2 and SP3 does not properly handle memory during the parsing of Word documents, which allows remote attackers to execute arbitrary code via a crafted document, aka "Word PAPX Section Corruption Vulnerability."
20714| [CVE-2012-0181] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly manage Keyboard Layout files, which allows local users to gain privileges via a crafted application, aka "Keyboard Layout File Vulnerability."
20715| [CVE-2012-0180] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly handle user-mode input passed to kernel mode for (1) windows and (2) messages, which allows local users to gain privileges via a crafted application, aka "Windows and Messages Vulnerability."
20716| [CVE-2012-0179] Double free vulnerability in tcpip.sys in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that binds an IPv6 address to a local interface, aka "TCP/IP Double Free Vulnerability."
20717| [CVE-2012-0178] Race condition in partmgr.sys in Windows Partition Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that makes multiple simultaneous Plug and Play (PnP) Configuration Manager function calls, aka "Plug and Play (PnP) Configuration Manager Vulnerability."
20718| [CVE-2012-0177] Heap-based buffer overflow in the Office Works File Converter in Microsoft Office 2007 SP2, Works 9, and Works 6-9 File Converter allows remote attackers to execute arbitrary code via a crafted Works (aka .wps) file, aka "Office WPS Converter Heap Overflow Vulnerability."
20719| [CVE-2012-0175] The Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted name for a (1) file or (2) directory, aka "Command Injection Vulnerability."
20720| [CVE-2012-0174] Windows Firewall in tcpip.sys in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly enforce firewall rules for outbound broadcast packets, which allows remote attackers to obtain potentially sensitive information by observing broadcast traffic on a local network, aka "Windows Firewall Bypass Vulnerability."
20721| [CVE-2012-0173] The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process packets in memory, which allows remote attackers to execute arbitrary code by sending crafted RDP packets triggering access to an object that (1) was not properly initialized or (2) is deleted, aka "Remote Desktop Protocol Vulnerability," a different vulnerability than CVE-2012-0002.
20722| [CVE-2012-0167] Heap-based buffer overflow in the Office GDI+ library in Microsoft Office 2003 SP3 and 2007 SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted EMF image in an Office document, aka "GDI+ Heap Overflow Vulnerability."
20723| [CVE-2012-0165] GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2 and Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1 does not properly validate record types in EMF images, which allows remote attackers to execute arbitrary code via a crafted image, aka "GDI+ Record Type Vulnerability."
20724| [CVE-2012-0163] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate function parameters, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka ".NET Framework Parameter Validation Vulnerability."
20725| [CVE-2012-0161] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly handle an unspecified exception during use of partially trusted assemblies to serialize input data, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka ".NET Framework Serialization Vulnerability."
20726| [CVE-2012-0160] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly serialize input data, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka ".NET Framework Serialization Vulnerability."
20727| [CVE-2012-0159] Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview
20728| [CVE-2012-0158] The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1
20729| [CVE-2012-0157] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle window messaging, which allows local users to gain privileges via a crafted application that calls the PostMessage function, aka "PostMessage Function Vulnerability."
20730| [CVE-2012-0156] DirectWrite in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly render Unicode characters, which allows remote attackers to cause a denial of service (application hang) via a (1) instant message or (2) web site, aka "DirectWrite Application Denial of Service Vulnerability."
20731| [CVE-2012-0154] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers keyboard layout errors, aka "Keyboard Layout Use After Free Vulnerability."
20732| [CVE-2012-0152] The Remote Desktop Protocol (RDP) service in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (application hang) via a series of crafted packets, aka "Terminal Server Denial of Service Vulnerability."
20733| [CVE-2012-0151] The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to execute arbitrary code via a modified file with additional content, aka "WinVerifyTrust Signature Validation Vulnerability."
20734| [CVE-2012-0150] Buffer overflow in msvcrt.dll in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted media file, aka "Msvcrt.dll Buffer Overflow Vulnerability."
20735| [CVE-2012-0149] afd.sys in the Ancillary Function Driver in Microsoft Windows Server 2003 SP2 does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."
20736| [CVE-2012-0148] afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 on 64-bit platforms does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "AfdPoll Elevation of Privilege Vulnerability."
20737| [CVE-2012-0143] Microsoft Excel 2003 SP3 and Office 2008 for Mac do not properly handle memory during the opening of files, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Memory Corruption Using Various Modified Bytes Vulnerability."
20738| [CVE-2012-0142] Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1
20739| [CVE-2012-0141] Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1
20740| [CVE-2012-0015] Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly calculate the length of an unspecified buffer, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka ".NET Framework Heap Corruption Vulnerability."
20741| [CVE-2012-0014] Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.1.10111, does not properly restrict access to memory associated with unmanaged objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4) a crafted Silverlight application, aka ".NET Framework Unmanaged Objects Vulnerability."
20742| [CVE-2012-0013] Incomplete blacklist vulnerability in the Windows Packager configuration in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted ClickOnce application in a Microsoft Office document, related to .application files, aka "Assembly Execution Vulnerability."
20743| [CVE-2012-0009] Untrusted search path vulnerability in the Windows Object Packager configuration in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a Trojan horse executable file in the current working directory, as demonstrated by a directory that contains a file with an embedded packaged object, aka "Object Packager Insecure Executable Launching Vulnerability."
20744| [CVE-2012-0008] Untrusted search path vulnerability in Microsoft Visual Studio 2008 SP1, 2010, and 2010 SP1 allows local users to gain privileges via a Trojan horse add-in in an unspecified directory, aka "Visual Studio Add-In Vulnerability."
20745| [CVE-2012-0006] The DNS server in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 does not properly handle objects in memory during record lookup, which allows remote attackers to cause a denial of service (daemon restart) via a crafted query, aka "DNS Denial of Service Vulnerability."
20746| [CVE-2012-0005] The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2, when a Chinese, Japanese, or Korean system locale is used, can access uninitialized memory during the processing of Unicode characters, which allows local users to gain privileges via a crafted application, aka "CSRSS Elevation of Privilege Vulnerability."
20747| [CVE-2012-0004] Unspecified vulnerability in DirectShow in DirectX in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted media file, related to Quartz.dll, Qdvd.dll, closed captioning, and the Line21 DirectShow filter, aka "DirectShow Remote Code Execution Vulnerability."
20748| [CVE-2012-0003] Unspecified vulnerability in winmm.dll in Windows Multimedia Library in Windows Media Player (WMP) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows remote attackers to execute arbitrary code via a crafted MIDI file, aka "MIDI Remote Code Execution Vulnerability."
20749| [CVE-2012-0002] The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process packets in memory, which allows remote attackers to execute arbitrary code by sending crafted RDP packets triggering access to an object that (1) was not properly initialized or (2) is deleted, aka "Remote Desktop Protocol Vulnerability."
20750| [CVE-2012-0001] The kernel in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly load structured exception handling tables, which allows context-dependent attackers to bypass the SafeSEH security feature by leveraging a Visual C++ .NET 2003 application, aka "Windows Kernel SafeSEH Bypass Vulnerability."
20751| [CVE-2011-5046] The Graphics Device Interface (GDI) in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted data, as demonstrated by a large height attribute of an IFRAME element rendered by Safari, aka "GDI Access Violation Vulnerability."
20752| [CVE-2011-4434] Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 do not properly enforce AppLocker rules, which allows local users to bypass intended access restrictions via a (1) macro or (2) scripting feature in an application, as demonstrated by Microsoft Office applications and the SANDBOX_INERT and LOAD_IGNORE_CODE_AUTHZ_LEVEL flags.
20753| [CVE-2011-3417] The Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0, when sliding expiry is enabled, does not properly handle cached content, which allows remote attackers to obtain access to arbitrary user accounts via a crafted URL, aka "ASP.NET Forms Authentication Ticket Caching Vulnerability."
20754| [CVE-2011-3416] The Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 allows remote authenticated users to obtain access to arbitrary user accounts via a crafted username, aka "ASP.Net Forms Authentication Bypass Vulnerability."
20755| [CVE-2011-3415] Open redirect vulnerability in the Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted return URL, aka "Insecure Redirect in .NET Form Authentication Vulnerability."
20756| [CVE-2011-3414] The CaseInsensitiveHashProvider.getHashCode function in the HashTable implementation in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters, aka "Collisions in HashTable May Cause DoS Vulnerability."
20757| [CVE-2011-3413] Microsoft PowerPoint 2007 SP2
20758| [CVE-2011-3412] Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, allows remote attackers to execute arbitrary code via a crafted Publisher file that leverages incorrect memory handling, aka "Publisher Memory Corruption Vulnerability."
20759| [CVE-2011-3411] Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that leverages incorrect handling of values in memory, aka "Publisher Invalid Pointer Vulnerability."
20760| [CVE-2011-3410] Array index error in Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, allows remote attackers to execute arbitrary code via a crafted Publisher file that leverages incorrect handling of values in memory, aka "Publisher Out-of-bounds Array Index Vulnerability."
20761| [CVE-2011-3408] Csrsrv.dll in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly check permissions for sending inter-process device-event messages from low-integrity processes to high-integrity processes, which allows local users to gain privileges via a crafted application, aka "CSRSS Local Privilege Elevation Vulnerability."
20762| [CVE-2011-3406] Buffer overflow in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote authenticated users to execute arbitrary code via a crafted query that leverages incorrect memory initialization, aka "Active Directory Buffer Overflow Vulnerability."
20763| [CVE-2011-3403] Microsoft Excel 2003 SP3 and Office 2004 for Mac do not properly handle objects in memory, which allows remote attackers to execute arbitrary code via a crafted Excel spreadsheet, aka "Record Memory Corruption Vulnerability."
20764| [CVE-2011-3402] Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via crafted font data in a Word document or web page, as exploited in the wild in November 2011 by Duqu, aka "TrueType Font Parsing Vulnerability."
20765| [CVE-2011-3400] Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 do not properly handle OLE objects in memory, which allows remote attackers to execute arbitrary code via a crafted object in a file, aka "OLE Property Vulnerability."
20766| [CVE-2011-3397] The Microsoft Time component in DATIME.DLL in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted web site that leverages an unspecified "binary behavior" in Internet Explorer, aka "Microsoft Time Remote Code Execution Vulnerability."
20767| [CVE-2011-3396] Untrusted search path vulnerability in Microsoft PowerPoint 2007 SP2 and 2010 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "PowerPoint Insecure Library Loading Vulnerability."
20768| [CVE-2011-2019] Untrusted search path vulnerability in Microsoft Internet Explorer 9 on Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains an HTML file, aka "Internet Explorer Insecure Library Loading Vulnerability."
20769| [CVE-2011-2018] The kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, and Windows 7 Gold and SP1 does not properly initialize objects, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Exception Handler Vulnerability."
20770| [CVE-2011-2016] Untrusted search path vulnerability in Windows Mail and Windows Meeting Space in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .eml or .wcinv file, aka "Windows Mail Insecure Library Loading Vulnerability."
20771| [CVE-2011-2014] The LDAP over SSL (aka LDAPS) implementation in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not examine Certificate Revocation Lists (CRLs), which allows remote authenticated users to bypass intended certificate restrictions and access Active Directory resources by leveraging a revoked X.509 certificate for a domain account, aka "LDAPS Authentication Bypass Vulnerability."
20772| [CVE-2011-2013] Integer overflow in the TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code by sending a sequence of crafted UDP packets to a closed port, aka "Reference Counter Overflow Vulnerability."
20773| [CVE-2011-2011] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, aka "Win32k Use After Free Vulnerability."
20774| [CVE-2011-2008] Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service outage) via crafted TCP or UDP traffic, aka "Access of Unallocated Memory DoS Vulnerability."
20775| [CVE-2011-2007] Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service outage) via crafted TCP or UDP traffic, aka "Endless Loop DoS in snabase.exe Vulnerability."
20776| [CVE-2011-2005] afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."
20777| [CVE-2011-2004] Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (reboot) via a crafted TrueType font file, aka "TrueType Font Parsing Vulnerability," a different vulnerability than CVE-2011-3402.
20778| [CVE-2011-2003] Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted .fon file, aka "Font Library File Buffer Overrun Vulnerability."
20779| [CVE-2011-2002] win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle TrueType fonts, which allows local users to cause a denial of service (system hang) via a crafted font file, aka "Win32k TrueType Font Type Translation Vulnerability."
20780| [CVE-2011-1991] Multiple untrusted search path vulnerabilities in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allow local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .doc, .rtf, or .txt file, related to (1) deskpan.dll in the Display Panning CPL Extension, (2) EAPHost Authenticator Service, (3) Folder Redirection, (4) HyperTerminal, (5) the Japanese Input Method Editor (IME), and (6) Microsoft Management Console (MMC), aka "Windows Components Insecure Library Loading Vulnerability."
20781| [CVE-2011-1990] Microsoft Excel 2007 SP2
20782| [CVE-2011-1989] Microsoft Excel 2003 SP3 and 2007 SP2
20783| [CVE-2011-1988] Microsoft Excel 2003 SP3 and 2007 SP2
20784| [CVE-2011-1987] Array index error in Microsoft Excel 2003 SP3 and 2007 SP2
20785| [CVE-2011-1986] Use-after-free vulnerability in Microsoft Excel 2003 SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Use after Free WriteAV Vulnerability."
20786| [CVE-2011-1985] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via a crafted application, aka "Win32k Null Pointer De-reference Vulnerability."
20787| [CVE-2011-1984] WINS in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 allows local users to gain privileges by sending crafted packets over the loopback interface, aka "WINS Local Elevation of Privilege Vulnerability."
20788| [CVE-2011-1983] Use-after-free vulnerability in Microsoft Office 2007 SP2 and SP3, Office 2010 Gold and SP1, and Office for Mac 2011 allows remote attackers to execute arbitrary code via a crafted Word document, aka "Word Use After Free Vulnerability."
20789| [CVE-2011-1982] Microsoft Office 2007 SP2, and 2010 Gold and SP1, does not initialize an unspecified object pointer during the opening of Word documents, which allows remote attackers to execute arbitrary code via a crafted document, aka "Office Uninitialized Object Pointer Vulnerability."
20790| [CVE-2011-1980] Untrusted search path vulnerability in Microsoft Office 2003 SP3 and 2007 SP2 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .doc, .ppt, or .xls file, aka "Office Component Insecure Library Loading Vulnerability."
20791| [CVE-2011-1979] Microsoft Visio 2003 SP3 and 2007 SP2 does not properly validate objects in memory during Visio file parsing, which allows remote attackers to execute arbitrary code via a crafted file, aka "Move Around the Block RCE Vulnerability."
20792| [CVE-2011-1978] Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4 does not properly validate the System.Net.Sockets trust level, which allows remote attackers to obtain sensitive information or trigger arbitrary outbound network traffic via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Socket Restriction Bypass Vulnerability."
20793| [CVE-2011-1976] Cross-site scripting (XSS) vulnerability in the Report Viewer Control in Microsoft Visual Studio 2005 SP1 and Report Viewer 2005 SP1 allows remote attackers to inject arbitrary web script or HTML via a parameter in a data source, aka "Report Viewer Controls XSS Vulnerability."
20794| [CVE-2011-1975] Untrusted search path vulnerability in the Data Access Tracing component in Windows Data Access Components (Windows DAC) 6.0 in Microsoft Windows 7 Gold and SP1 and Windows Server 2008 R2 and R2 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains an Excel .xlsx file, aka "Data Access Components Insecure Library Loading Vulnerability."
20795| [CVE-2011-1974] NDISTAPI.sys in the NDISTAPI driver in Remote Access Service (RAS) in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "NDISTAPI Elevation of Privilege Vulnerability."
20796| [CVE-2011-1972] Microsoft Visio 2003 SP3, 2007 SP2, and 2010 Gold and SP1 does not properly validate objects in memory during Visio file parsing, which allows remote attackers to execute arbitrary code via a crafted file, aka "pStream Release RCE Vulnerability."
20797| [CVE-2011-1971] The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly parse file metadata, which allows local users to cause a denial of service (reboot) via a crafted file, aka "Windows Kernel Metadata Parsing DOS Vulnerability."
20798| [CVE-2011-1970] The DNS server in Microsoft Windows Server 2003 SP2 and Windows Server 2008 SP2, R2, and R2 SP1 does not properly initialize memory, which allows remote attackers to cause a denial of service (service outage) via a query for a nonexistent domain, aka "DNS Uninitialized Memory Corruption Vulnerability."
20799| [CVE-2011-1968] The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 does not properly process packets in memory, which allows remote attackers to cause a denial of service (reboot) by sending crafted RDP packets triggering access to an object that (1) was not properly initialized or (2) is deleted, as exploited in the wild in 2011, aka "Remote Desktop Protocol Vulnerability."
20800| [CVE-2011-1967] Winsrv.dll in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly check permissions for sending inter-process device-event messages from low-integrity processes to high-integrity processes, which allows local users to gain privileges via a crafted application, aka "CSRSS Vulnerability."
20801| [CVE-2011-1966] The DNS server in Microsoft Windows Server 2008 SP2, R2, and R2 SP1 does not properly handle NAPTR queries that trigger recursive processing, which allows remote attackers to execute arbitrary code via a crafted query, aka "DNS NAPTR Query Vulnerability."
20802| [CVE-2011-1965] Tcpip.sys in the TCP/IP stack in Microsoft Windows 7 Gold and SP1 and Windows Server 2008 R2 and R2 SP1 does not properly implement URL-based QoS, which allows remote attackers to cause a denial of service (reboot) via a crafted URL to a web server, aka "TCP/IP QOS Denial of Service Vulnerability."
20803| [CVE-2011-1894] The MHTML protocol handler in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle a MIME format in a request for embedded content in an HTML document, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted EMBED element in a web page that is visited in Internet Explorer, aka "MHTML Mime-Formatted Request Vulnerability."
20804| [CVE-2011-1893] Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2010, Windows SharePoint Services 2.0 and 3.0 SP2, and SharePoint Foundation 2010 allows remote attackers to inject arbitrary web script or HTML via the URI, aka "SharePoint XSS Vulnerability."
20805| [CVE-2011-1892] Microsoft Office Groove 2007 SP2, SharePoint Workspace 2010 Gold and SP1, Office Forms Server 2007 SP2, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Office Groove Data Bridge Server 2007 SP2, Office Groove Management Server 2007 SP2, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, and Office Web Apps 2010 Gold and SP1 do not properly handle Web Parts containing XML classes referencing external entities, which allows remote authenticated users to read arbitrary files via a crafted XML and XSL file, aka "SharePoint Remote File Disclosure Vulnerability."
20806| [CVE-2011-1888] win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Null Pointer De-reference Vulnerability."
20807| [CVE-2011-1887] win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Null Pointer De-reference Vulnerability."
20808| [CVE-2011-1885] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Null Pointer De-reference Vulnerability."
20809| [CVE-2011-1884] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
20810| [CVE-2011-1883] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
20811| [CVE-2011-1882] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
20812| [CVE-2011-1881] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Null Pointer De-reference Vulnerability."
20813| [CVE-2011-1880] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Null Pointer De-reference Vulnerability."
20814| [CVE-2011-1879] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
20815| [CVE-2011-1878] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
20816| [CVE-2011-1877] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, aka "Win32k Use After Free Vulnerability."
20817| [CVE-2011-1876] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
20818| [CVE-2011-1875] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
20819| [CVE-2011-1874] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
20820| [CVE-2011-1873] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 on 64-bit platforms does not properly validate pointers during the parsing of OpenType (aka OTF) fonts, which allows remote attackers to execute arbitrary code via a crafted font file, aka "Win32k OTF Validation Vulnerability."
20821| [CVE-2011-1872] Hyper-V in Microsoft Windows Server 2008 Gold, SP2, R2, and R2 SP1 allows guest OS users to cause a denial of service (host OS infinite loop) via malformed machine instructions in a VMBus packet, aka "VMBus Persistent DoS Vulnerability."
20822| [CVE-2011-1871] Tcpip.sys in the TCP/IP stack in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (reboot) via a series of crafted ICMP messages, aka "ICMP Denial of Service Vulnerability."
20823| [CVE-2011-1870] Integer overflow in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP SrvWriteConsoleOutputString Vulnerability."
20824| [CVE-2011-1869] The Distributed File System (DFS) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote DFS servers to cause a denial of service (system hang) via a crafted referral response, aka "DFS Referral Response Vulnerability."
20825| [CVE-2011-1868] The Distributed File System (DFS) implementation in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate fields in DFS responses, which allows remote DFS servers to execute arbitrary code via a crafted response, aka "DFS Memory Corruption Vulnerability."
20826| [CVE-2011-1508] Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, does not properly manage memory allocations for function pointers, which allows user-assisted remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Function Pointer Overwrite Vulnerability."
20827| [CVE-2011-1284] Integer overflow in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP SrvWriteConsoleOutput Vulnerability."
20828| [CVE-2011-1283] The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2 does not ensure that an unspecified array index has a non-negative value before performing read and write operations, which allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP SrvSetConsoleNumberOfCommand Vulnerability."
20829| [CVE-2011-1282] The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly initialize memory and consequently uses a NULL pointer in an unspecified function call, which allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP SrvSetConsoleLocalEUDC Vulnerability."
20830| [CVE-2011-1281] The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly restrict the number of console objects for a process, which allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP AllocConsole Vulnerability."
20831| [CVE-2011-1280] The XML Editor in Microsoft InfoPath 2007 SP2 and 2010
20832| [CVE-2011-1279] Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel Out of Bounds WriteAV Vulnerability."
20833| [CVE-2011-1278] Microsoft Excel 2002 SP3 and Office 2004 for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel WriteAV Vulnerability."
20834| [CVE-2011-1277] Microsoft Excel 2002 SP3, Office 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel Memory Corruption Vulnerability."
20835| [CVE-2011-1276] Buffer overflow in Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2
20836| [CVE-2011-1275] Microsoft Excel 2002 SP3
20837| [CVE-2011-1274] Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2
20838| [CVE-2011-1273] Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010
20839| [CVE-2011-1272] Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2
20840| [CVE-2011-1270] Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "Presentation Buffer Overrun RCE Vulnerability."
20841| [CVE-2011-1269] Microsoft PowerPoint 2002 SP3, 2003 SP3, and 2007 SP2
20842| [CVE-2011-1268] The SMB client in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote SMB servers to execute arbitrary code via a crafted (1) SMBv1 or (2) SMBv2 response, aka "SMB Response Parsing Vulnerability."
20843| [CVE-2011-1267] The SMB server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (system hang) via a crafted (1) SMBv1 or (2) SMBv2 request, aka "SMB Request Parsing Vulnerability."
20844| [CVE-2011-1264] Cross-site scripting (XSS) vulnerability in Active Directory Certificate Services Web Enrollment in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, R2, and R2 SP1 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "Active Directory Certificate Services Vulnerability."
20845| [CVE-2011-1263] Cross-site scripting (XSS) vulnerability in the logon page in Remote Desktop Web Access (RD Web Access) in Microsoft Windows Server 2008 R2 and R2 SP1 allows remote attackers to inject arbitrary web script or HTML via the URI, aka "Remote Desktop Web Access Vulnerability."
20846| [CVE-2011-1253] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.0.60831, does not properly restrict inheritance, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4) a crafted Silverlight application, aka ".NET Framework Class Inheritance Vulnerability."
20847| [CVE-2011-1252] Cross-site scripting (XSS) vulnerability in the SafeHTML function in the toStaticHTML API in Microsoft Internet Explorer 7 and 8, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified strings, aka "toStaticHTML Information Disclosure Vulnerability" or "HTML Sanitization Vulnerability."
20848| [CVE-2011-1249] The Ancillary Function Driver (AFD) in afd.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."
20849| [CVE-2011-1248] WINS in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, R2, and R2 SP1 does not properly handle socket send exceptions, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted packets, related to unintended stack-frame values and buffer passing, aka "WINS Service Failed Response Vulnerability."
20850| [CVE-2011-1247] Untrusted search path vulnerability in the Microsoft Active Accessibility component in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "Active Accessibility Insecure Library Loading Vulnerability."
20851| [CVE-2011-1242] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
20852| [CVE-2011-1241] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
20853| [CVE-2011-1240] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
20854| [CVE-2011-1239] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
20855| [CVE-2011-1238] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
20856| [CVE-2011-1237] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
20857| [CVE-2011-1236] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
20858| [CVE-2011-1235] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
20859| [CVE-2011-1234] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
20860| [CVE-2011-1233] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
20861| [CVE-2011-1232] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
20862| [CVE-2011-1231] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
20863| [CVE-2011-1230] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
20864| [CVE-2011-1229] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
20865| [CVE-2011-1228] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
20866| [CVE-2011-1227] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
20867| [CVE-2011-1226] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
20868| [CVE-2011-1225] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
20869| [CVE-2011-0980] Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse Office Art objects, which allows remote attackers to execute arbitrary code via vectors related to a function pointer, aka "Excel Dangling Pointer Vulnerability."
20870| [CVE-2011-0979] Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010
20871| [CVE-2011-0978] Stack-based buffer overflow in Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2
20872| [CVE-2011-0977] Use-after-free vulnerability in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via malformed shape data in the Office drawing file format, aka "Microsoft Office Graphic Object Dereferencing Vulnerability."
20873| [CVE-2011-0976] Microsoft PowerPoint 2002 SP3, 2003 SP3, and 2007 SP2
20874| [CVE-2011-0677] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
20875| [CVE-2011-0676] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
20876| [CVE-2011-0675] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
20877| [CVE-2011-0674] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
20878| [CVE-2011-0672] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
20879| [CVE-2011-0671] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
20880| [CVE-2011-0670] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
20881| [CVE-2011-0667] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
20882| [CVE-2011-0666] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
20883| [CVE-2011-0665] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
20884| [CVE-2011-0664] Microsoft .NET Framework 2.0 SP1 and SP2, 3.5 Gold and SP1, 3.5.1, and 4.0, and Silverlight 4 before 4.0.60531.0, does not properly validate arguments to unspecified networking API functions, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4) a crafted Silverlight application, aka ".NET Framework Array Offset Vulnerability."
20885| [CVE-2011-0662] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
20886| [CVE-2011-0661] The SMB Server service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate fields in SMB requests, which allows remote attackers to execute arbitrary code via a malformed request in a (1) SMBv1 or (2) SMBv2 packet, aka "SMB Transaction Parsing Vulnerability."
20887| [CVE-2011-0660] The SMB client in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote SMB servers to execute arbitrary code via a crafted (1) SMBv1 or (2) SMBv2 response, aka "SMB Client Response Parsing Vulnerability."
20888| [CVE-2011-0658] Integer underflow in the OLE Automation protocol implementation in VBScript.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted WMF file, aka "OLE Automation Underflow Vulnerability."
20889| [CVE-2011-0657] DNSAPI.dll in the DNS client in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process DNS queries, which allows remote attackers to execute arbitrary code via (1) a crafted LLMNR broadcast query or (2) a crafted application, aka "DNS Query Vulnerability."
20890| [CVE-2011-0656] Microsoft PowerPoint 2002 SP3, 2003 SP3, 2007 SP2, and 2010
20891| [CVE-2011-0655] Microsoft PowerPoint 2007 SP2 and 2010
20892| [CVE-2011-0654] Integer underflow in the BowserWriteErrorLogEntry function in the Common Internet File System (CIFS) browser service in Mrxsmb.sys or bowser.sys in Active Directory in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via a malformed BROWSER ELECTION message, leading to a heap-based buffer overflow, aka "Browser Pool Corruption Vulnerability." NOTE: some of these details are obtained from third party information.
20893| [CVE-2011-0107] Untrusted search path vulnerability in Microsoft Office XP SP3, Office 2003 SP3, and Office 2007 SP2 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .docx file, aka "Office Component Insecure Library Loading Vulnerability."
20894| [CVE-2011-0105] Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac obtain a certain length value from an uninitialized memory location, which allows remote attackers to trigger a buffer overflow and execute arbitrary code via a crafted Excel file, aka "Excel Data Initialization Vulnerability."
20895| [CVE-2011-0104] Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HLink record in an Excel file, aka "Excel Buffer Overwrite Vulnerability."
20896| [CVE-2011-0103] Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted record information in an Excel file, aka "Excel Memory Corruption Vulnerability."
20897| [CVE-2011-0101] Microsoft Excel 2002 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted RealTimeData record, related to a stTopic field, doubly-byte characters, and an incorrect pointer calculation, aka "Excel Record Parsing WriteAV Vulnerability."
20898| [CVE-2011-0098] Integer signedness error in Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010
20899| [CVE-2011-0097] Integer underflow in Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010
20900| [CVE-2011-0096] The MHTML protocol handler in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle a MIME format in a request for content blocks in a document, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site that is visited in Internet Explorer, aka "MHTML Mime-Formatted Request Vulnerability."
20901| [CVE-2011-0093] ELEMENTS.DLL in Microsoft Visio 2002 SP2, 2003 SP3, and 2007 SP2 does not properly parse structures during the opening of a Visio file, which allows remote attackers to execute arbitrary code via a file containing a malformed structure, aka "Visio Data Type Memory Corruption Vulnerability."
20902| [CVE-2011-0092] The LZW stream decompression functionality in ORMELEMS.DLL in Microsoft Visio 2002 SP2, 2003 SP3, and 2007 SP2 allows remote attackers to execute arbitrary code via a Visio file with a malformed VisioDocument stream that triggers an exception handler that accesses an object that has not been fully initialized, which triggers memory corruption, aka "Visio Object Memory Corruption Vulnerability."
20903| [CVE-2011-0091] Kerberos in Microsoft Windows Server 2008 R2 and Windows 7 does not prevent a session from changing from strong encryption to DES encryption, which allows man-in-the-middle attackers to spoof network traffic and obtain sensitive information via a DES downgrade, aka "Kerberos Spoofing Vulnerability."
20904| [CVE-2011-0090] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Vulnerability."
20905| [CVE-2011-0089] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Window Class Improper Pointer Validation Vulnerability."
20906| [CVE-2011-0088] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Window Class Pointer Confusion Vulnerability."
20907| [CVE-2011-0087] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Insufficient User Input Validation Vulnerability."
20908| [CVE-2011-0086] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Improper User Input Validation Vulnerability."
20909| [CVE-2011-0043] Kerberos in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 supports weak hashing algorithms, which allows local users to gain privileges by operating a service that sends crafted service tickets, as demonstrated by the CRC32 algorithm, aka "Kerberos Unkeyed Checksum Vulnerability."
20910| [CVE-2011-0042] SBE.dll in the Stream Buffer Engine in Windows Media Player and Windows Media Center in Microsoft Windows XP SP2 and SP3, Windows XP Media Center Edition 2005 SP3, Windows Vista SP1 and SP2, Windows 7 Gold and SP1, and Windows Media Center TV Pack for Windows Vista does not properly parse Digital Video Recording (.dvr-ms) files, which allows remote attackers to execute arbitrary code via a crafted file, aka "DVR-MS Vulnerability."
20911| [CVE-2011-0041] Integer overflow in gdiplus.dll in GDI+ in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold and SP2, and Office XP SP3 allows remote attackers to execute arbitrary code via a crafted EMF image, aka "GDI+ Integer Overflow Vulnerability."
20912| [CVE-2011-0040] The server in Microsoft Active Directory on Windows Server 2003 SP2 does not properly handle an update request for a service principal name (SPN), which allows remote attackers to cause a denial of service (authentication downgrade or outage) via a crafted request that triggers name collisions, aka "Active Directory SPN Validation Vulnerability."
20913| [CVE-2011-0039] The Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly process authentication requests, which allows local users to gain privileges via a request with a crafted length, aka "LSASS Length Validation Vulnerability."
20914| [CVE-2011-0034] Stack-based buffer overflow in the OpenType Compact Font Format (aka OTF or CFF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via crafted parameter values in an OpenType font, aka "OpenType Font Stack Overflow Vulnerability."
20915| [CVE-2011-0033] The OpenType Compact Font Format (CFF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate parameter values in OpenType fonts, which allows remote attackers to execute arbitrary code via a crafted font, aka "OpenType Font Encoded Character Vulnerability."
20916| [CVE-2011-0032] Untrusted search path vulnerability in DirectShow in Microsoft Windows Vista SP1 and SP2, Windows 7 Gold and SP1, Windows Server 2008 R2 and R2 SP1, and Windows Media Center TV Pack for Windows Vista allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a Digital Video Recording (.dvr-ms), Windows Recorded TV Show (.wtv), or .mpg file, aka "DirectShow Insecure Library Loading Vulnerability."
20917| [CVE-2011-0031] The (1) JScript 5.8 and (2) VBScript 5.8 scripting engines in Microsoft Windows Server 2008 R2 and Windows 7 do not properly load decoded scripts obtained from web pages, which allows remote attackers to trigger memory corruption and consequently obtain sensitive information via a crafted web site, aka "Scripting Engines Information Disclosure Vulnerability."
20918| [CVE-2011-0030] The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly kill processes after a logout, which allows local users to obtain sensitive information or gain privileges via a crafted application that continues to execute throughout the logout of one user and the login session of the next user, aka "CSRSS Elevation of Privilege Vulnerability," a different vulnerability than CVE-2010-0023.
20919| [CVE-2011-0028] WordPad in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly parse fields in Word documents, which allows remote attackers to execute arbitrary code via a crafted .doc file, aka "WordPad Converter Parsing Vulnerability."
20920| [CVE-2010-5082] Untrusted search path vulnerability in colorcpl.exe 6.0.6000.16386 in the Color Control Panel in Microsoft Windows Server 2008 SP2, R2, and R2 SP1 allows local users to gain privileges via a Trojan horse sti.dll file in the current working directory, as demonstrated by a directory that contains a .camp, .cdmp, .gmmp, .icc, or .icm file, aka "Color Control Panel Insecure Library Loading Vulnerability."
20921| [CVE-2010-4701] Heap-based buffer overflow in the CDrawPoly::Serialize function in fxscover.exe in Microsoft Windows Fax Services Cover Page Editor 5.2 r2 in Windows XP Professional SP3, Server 2003 R2 Enterprise Edition SP2, and Windows 7 Professional allows remote attackers to execute arbitrary code via a long record in a Fax Cover Page (.cov) file. NOTE: some of these details are obtained from third party information.
20922| [CVE-2010-4669] The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Microsoft Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, and Windows 7 allows remote attackers to cause a denial of service (CPU consumption and system hang) by sending many Router Advertisement (RA) messages with different source addresses, as demonstrated by the flood_router6 program in the thc-ipv6 package.
20923| [CVE-2010-4562] Microsoft Windows 2008, 7, Vista, 2003, 2000, and XP, when using IPv6, allows remote attackers to determine whether a host is sniffing the network by sending an ICMPv6 Echo Request to a multicast address and determining whether an Echo Reply is sent, as demonstrated by thcping. NOTE: due to a typo, some sources map CVE-2010-4562 to a ProFTPd mod_sql vulnerability, but that issue is covered by CVE-2010-4652.
20924| [CVE-2010-4398] Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges, and bypass the User Account Control (UAC) feature, via a crafted REG_BINARY value for a SystemDefaultEUDCFont registry key, aka "Driver Improper Interaction with Windows Kernel Vulnerability."
20925| [CVE-2010-4182] Untrusted search path vulnerability in the Data Access Objects (DAO) library (dao360.dll) in Microsoft Windows XP Professional SP3, Windows Server 2003 R2 Enterprise Edition SP3, Windows Vista Business SP1, and Windows 7 Professional allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse msjet49.dll that is located in the same folder as a file that is processed by dao360.dll. NOTE: the provenance of this information is unknown
20926| [CVE-2010-3974] fxscover.exe in the Fax Cover Page Editor in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly parse FAX cover pages, which allows remote attackers to execute arbitrary code via a crafted .cov file, aka "Fax Cover Page Editor Memory Corruption Vulnerability."
20927| [CVE-2010-3970] Stack-based buffer overflow in the CreateSizedDIBSECTION function in shimgvw.dll in the Windows Shell graphics processor (aka graphics rendering engine) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted .MIC or unspecified Office document containing a thumbnail bitmap with a negative biClrUsed value, as reported by Moti and Xu Hao, aka "Windows Shell Graphics Processing Overrun Vulnerability."
20928| [CVE-2010-3966] Untrusted search path vulnerability in Microsoft Windows Server 2008 R2 and Windows 7, when BranchCache is supported, allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains an EML file, an RSS file, or a WPOST file, aka "BranchCache Insecure Library Loading Vulnerability."
20929| [CVE-2010-3965] Untrusted search path vulnerability in Windows Media Encoder 9 on Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a Windows Media Profile (PRX) file, aka "Insecure Library Loading Vulnerability."
20930| [CVE-2010-3964] Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Office SharePoint Server 2007 SP2, when the Document Conversions Load Balancer Service is enabled, allows remote attackers to execute arbitrary code via a crafted SOAP request to TCP port 8082, aka "Malformed Request Code Execution Vulnerability."
20931| [CVE-2010-3963] Buffer overflow in the Routing and Remote Access NDProxy component in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, related to the Routing and Remote Access service (RRAS) and improper copying from user mode to the kernel, aka "Kernel NDProxy Buffer Overflow Vulnerability."
20932| [CVE-2010-3961] The Consent User Interface (UI) in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly handle an unspecified registry-key value, which allows local users with SeImpersonatePrivilege rights to gain privileges via a crafted application, aka "Consent UI Impersonation Vulnerability."
20933| [CVE-2010-3960] Hyper-V in Microsoft Windows Server 2008 Gold, SP2, and R2 allows guest OS users to cause a denial of service (host OS hang) by sending a crafted encapsulated packet over the VMBus, aka "Hyper-V VMBus Vulnerability."
20934| [CVE-2010-3959] The OpenType Font (OTF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a crafted CMAP table in an OpenType font, aka "OpenType CMAP Table Vulnerability."
20935| [CVE-2010-3958] The x86 JIT compiler in Microsoft .NET Framework 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 does not properly compile function calls, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka ".NET Framework Stack Corruption Vulnerability."
20936| [CVE-2010-3957] Double free vulnerability in the OpenType Font (OTF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a crafted OpenType font, aka "OpenType Font Double Free Vulnerability."
20937| [CVE-2010-3956] The OpenType Font (OTF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly perform array indexing, which allows local users to gain privileges via a crafted OpenType font, aka "OpenType Font Index Vulnerability."
20938| [CVE-2010-3955] pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3 does not properly perform array indexing, which allows remote attackers to execute arbitrary code via a crafted Publisher file that uses an old file format, aka "Array Indexing Memory Corruption Vulnerability."
20939| [CVE-2010-3954] Microsoft Publisher 2002 SP3, 2003 SP3, and 2010 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Publisher file, aka "Microsoft Publisher Memory Corruption Vulnerability."
20940| [CVE-2010-3946] Integer overflow in the PICT image converter in the graphics filters in Microsoft Office XP SP3, Office 2003 SP3, and Office Converter Pack allows remote attackers to execute arbitrary code via a crafted PICT image in an Office document, aka "PICT Image Converter Integer Overflow Vulnerability."
20941| [CVE-2010-3945] Buffer overflow in the CGM image converter in the graphics filters in Microsoft Office XP SP3, Office 2003 SP3, and Office Converter Pack allows remote attackers to execute arbitrary code via a crafted CGM image in an Office document, aka "CGM Image Converter Buffer Overrun Vulnerability."
20942| [CVE-2010-3944] win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Vulnerability."
20943| [CVE-2010-3943] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly link driver objects, which allows local users to gain privileges via a crafted application that triggers linked-list corruption, aka "Win32k Cursor Linking Vulnerability."
20944| [CVE-2010-3942] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly allocate memory for copies from user mode, which allows local users to gain privileges via a crafted application, aka "Win32k WriteAV Vulnerability."
20945| [CVE-2010-3941] Double free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold and SP2, and Windows 7 allows local users to gain privileges via a crafted application, aka "Win32k Double Free Vulnerability."
20946| [CVE-2010-3940] Double free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a crafted application, aka "Win32k PFE Pointer Double Free Vulnerability."
20947| [CVE-2010-3939] Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via vectors related to improper memory allocation for copies from user mode, aka "Win32k Buffer Overflow Vulnerability."
20948| [CVE-2010-3937] Microsoft Exchange Server 2007 SP2 on the x64 platform allows remote authenticated users to cause a denial of service (infinite loop and MSExchangeIS outage) via a crafted RPC request, aka "Exchange Server Infinite Loop Vulnerability."
20949| [CVE-2010-3338] The Windows Task Scheduler in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly determine the security context of scheduled tasks, which allows local users to gain privileges via a crafted application, aka "Task Scheduler Vulnerability." NOTE: this might overlap CVE-2010-3888.
20950| [CVE-2010-3337] Untrusted search path vulnerability in Microsoft Office 2007 SP2 and 2010 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "Insecure Library Loading Vulnerability." NOTE: this might overlap CVE-2010-3141 and CVE-2010-3142.
20951| [CVE-2010-3336] Microsoft Office XP SP3, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "MSO Large SPID Read AV Vulnerability."
20952| [CVE-2010-3335] Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "Drawing Exception Handling Vulnerability."
20953| [CVE-2010-3334] Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via an Office document containing an Office Art Drawing record with crafted msofbtSp records and unspecified flags, which triggers memory corruption, aka "Office Art Drawing Records Vulnerability."
20954| [CVE-2010-3333] Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via crafted RTF data, aka "RTF Stack Buffer Overflow Vulnerability."
20955| [CVE-2010-3332] Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Services (IIS), provides detailed error codes during decryption attempts, which allows remote attackers to decrypt and modify encrypted View State (aka __VIEWSTATE) form data, and possibly forge cookies or read application files, via a padding oracle attack, aka "ASP.NET Padding Oracle Vulnerability."
20956| [CVE-2010-3324] The toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, Office SharePoint Server 2007 SP2, Groove Server 2010, and Office Web Apps, allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism and conduct XSS attacks via a crafted use of the Cascading Style Sheets (CSS) @import rule, aka "HTML Sanitization Vulnerability," a different vulnerability than CVE-2010-1257.
20957| [CVE-2010-3243] Cross-site scripting (XSS) vulnerability in the toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2 and Office SharePoint Server 2007 SP2, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "HTML Sanitization Vulnerability."
20958| [CVE-2010-3242] Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Ghost Record Type Parsing Vulnerability."
20959| [CVE-2010-3241] Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate binary file-format information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Out-of-Bounds Memory Write in Parsing Vulnerability."
20960| [CVE-2010-3240] Microsoft Excel 2002 SP3 and 2007 SP2
20961| [CVE-2010-3239] Microsoft Excel 2002 SP3 does not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Extra Out of Boundary Record Parsing Vulnerability."
20962| [CVE-2010-3238] Microsoft Excel 2002 SP3 and 2003 SP3, and Office 2004 for Mac, does not properly validate binary file-format information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Negative Future Function Vulnerability."
20963| [CVE-2010-3237] Microsoft Excel 2002 SP3 and Office 2004 for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Merge Cell Record Pointer Vulnerability."
20964| [CVE-2010-3236] Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Out Of Bounds Array Vulnerability."
20965| [CVE-2010-3235] Microsoft Excel 2002 SP3 does not properly validate formula information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Formula Biff Record Vulnerability."
20966| [CVE-2010-3234] Microsoft Excel 2002 SP3 does not properly validate formula information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Formula Substream Memory Corruption Vulnerability."
20967| [CVE-2010-3233] Microsoft Excel 2002 SP3 and 2003 SP3 does not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted .wk3 (aka Lotus 1-2-3 workbook) file, aka "Lotus 1-2-3 Workbook Parsing Vulnerability."
20968| [CVE-2010-3232] Microsoft Excel 2003 SP3 and 2007 SP2
20969| [CVE-2010-3231] Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Excel Record Parsing Memory Corruption Vulnerability."
20970| [CVE-2010-3230] Integer overflow in Microsoft Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel document with crafted record information, aka "Excel Record Parsing Integer Overflow Vulnerability."
20971| [CVE-2010-3229] The Secure Channel (aka SChannel) security package in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when IIS 7.x is used, does not properly process client certificates during SSL and TLS handshakes, which allows remote attackers to cause a denial of service (LSASS outage and reboot) via a crafted packet, aka "TLSv1 Denial of Service Vulnerability."
20972| [CVE-2010-3227] Stack-based buffer overflow in the UpdateFrameTitleForDocument method in the CFrameWnd class in mfc42.dll in the Microsoft Foundation Class (MFC) Library in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows context-dependent attackers to execute arbitrary code via a long window title that this library attempts to create at the request of an application, as demonstrated by the Trident PowerZip 7.2 Build 4010 application, aka "Windows MFC Document Title Updating Buffer Overflow Vulnerability."
20973| [CVE-2010-3223] The user interface in Microsoft Cluster Service (MSCS) in Microsoft Windows Server 2008 R2 does not properly set administrative-share permissions for new cluster disks that are shared as part of a failover cluster, which allows remote attackers to read or modify data on these disks via requests to the associated share, aka "Permissions on New Cluster Disks Vulnerability."
20974| [CVE-2010-3222] Stack-based buffer overflow in the Remote Procedure Call Subsystem (RPCSS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted LPC message that requests an LRPC connection from an LPC server to a client, aka "LPC Message Buffer Overrun Vulnerability."
20975| [CVE-2010-3221] Microsoft Word 2002 SP3 and 2003 SP3, Office 2004 for Mac, and Word Viewer do not properly handle a malformed record during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Parsing Vulnerability."
20976| [CVE-2010-3220] Unspecified vulnerability in Microsoft Word 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Word document that triggers memory corruption, aka "Word Parsing Vulnerability."
20977| [CVE-2010-3219] Array index vulnerability in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via a crafted Word document that triggers memory corruption, aka "Word Index Parsing Vulnerability."
20978| [CVE-2010-3218] Heap-based buffer overflow in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via malformed records in a Word document, aka "Word Heap Overflow Vulnerability."
20979| [CVE-2010-3217] Double free vulnerability in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via a Word document with crafted List Format Override (LFO) records, aka "Word Pointer Vulnerability."
20980| [CVE-2010-3216] Microsoft Word 2002 SP3 and Office 2004 for Mac allow remote attackers to execute arbitrary code via a crafted Word document containing bookmarks that trigger use of an invalid pointer and memory corruption, aka "Word Bookmarks Vulnerability."
20981| [CVE-2010-3215] Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly handle unspecified return values during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Return Value Vulnerability."
20982| [CVE-2010-3214] Stack-based buffer overflow in Microsoft Word 2002 SP3, 2003 SP3, 2007 SP2, and 2010
20983| [CVE-2010-3213] Cross-site request forgery (CSRF) vulnerability in Microsoft Outlook Web Access (owa/ev.owa) 2007 through SP2 allows remote attackers to hijack the authentication of e-mail users for requests that perform Outlook requests, as demonstrated by setting the auto-forward rule.
20984| [CVE-2010-3200] MSO.dll in Microsoft Word 2003 SP3 11.8326.11.8324 allows remote attackers to cause a denial of service (NULL pointer dereference and multiple-instance application crash) via a crafted buffer in a Word document, as demonstrated by word_crash_11.8326.8324_poc.doc.
20985| [CVE-2010-3190] Untrusted search path vulnerability in the Microsoft Foundation Class (MFC) Library in Microsoft Visual Studio .NET 2003 SP1
20986| [CVE-2010-3148] Untrusted search path vulnerability in Microsoft Visio 2003 SP3 allows local users to gain privileges via a Trojan horse mfc71enu.dll file in the current working directory, as demonstrated by a directory that contains a .vsd, .vdx, .vst, or .vtx file, aka "Microsoft Visio Insecure Library Loading Vulnerability."
20987| [CVE-2010-3147] Untrusted search path vulnerability in wab.exe 6.00.2900.5512 in Windows Address Book in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a Trojan horse wab32res.dll file in the current working directory, as demonstrated by a directory that contains a Windows Address Book (WAB), VCF (aka vCard), or P7C file, aka "Insecure Library Loading Vulnerability." NOTE: the codebase for this product may overlap the codebase for the product referenced in CVE-2010-3143.
20988| [CVE-2010-3146] Multiple untrusted search path vulnerabilities in Microsoft Groove 2007 SP2 allow local users to gain privileges via a Trojan horse (1) mso.dll or (2) GroovePerfmon.dll file in the current working directory, as demonstrated by a directory that contains a Groove vCard (.vcg) or Groove Tool Archive (.gta) file, aka "Microsoft Groove Insecure Library Loading Vulnerability."
20989| [CVE-2010-3144] Untrusted search path vulnerability in the Internet Connection Signup Wizard in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a Trojan horse smmscrpt.dll file in the current working directory, as demonstrated by a directory that contains an ISP or INS file, aka "Internet Connection Signup Wizard Insecure Library Loading Vulnerability."
20990| [CVE-2010-3142] Untrusted search path vulnerability in Microsoft Office PowerPoint 2007 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse rpawinet.dll that is located in the same folder as a .odp, .pothtml, .potm, .potx, .ppa, .ppam, .pps, .ppt, .ppthtml, .pptm, .pptxml, .pwz, .sldm, .sldx, and .thmx file.
20991| [CVE-2010-2750] Array index error in Microsoft Word 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Word document that triggers memory corruption, aka "Word Index Vulnerability."
20992| [CVE-2010-2748] Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly check an unspecified boundary during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Boundary Check Vulnerability."
20993| [CVE-2010-2747] Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly handle an uninitialized pointer during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Uninitialized Pointer Vulnerability."
20994| [CVE-2010-2746] Heap-based buffer overflow in Comctl32.dll (aka the common control library) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when a third-party SVG viewer is used, allows remote attackers to execute arbitrary code via a crafted HTML document that triggers unspecified messages from this viewer, aka "Comctl32 Heap Overflow Vulnerability."
20995| [CVE-2010-2744] The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly manage a window class, which allows local users to gain privileges by creating a window, then using (1) the SetWindowLongPtr function to modify the popup menu structure, or (2) the SwitchWndProc function with a switch window information pointer, which is not re-initialized when a WM_NCCREATE message is processed, aka "Win32k Window Class Vulnerability."
20996| [CVE-2010-2742] The Netlogon RPC Service in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, and R2, when the domain controller role is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via a crafted RPC packet, aka "Netlogon RPC Null dereference DOS Vulnerability."
20997| [CVE-2010-2741] The OpenType Font (OTF) format driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 performs an incorrect integer calculation during font processing, which allows local users to gain privileges via a crafted application, aka "OpenType Font Validation Vulnerability."
20998| [CVE-2010-2740] The OpenType Font (OTF) format driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly perform memory allocation during font parsing, which allows local users to gain privileges via a crafted application, aka "OpenType Font Parsing Vulnerability."
20999| [CVE-2010-2739] Buffer overflow in the CreateDIBPalette function in win32k.sys in Microsoft Windows XP SP3, Server 2003 R2 Enterprise SP2, Vista Business SP1, Windows 7, and Server 2008 SP2 allows local users to cause a denial of service (crash) and possibly execute arbitrary code by performing a clipboard operation (GetClipboardData API function) with a crafted bitmap with a palette that contains a large number of colors.
21000| [CVE-2010-2738] The Uniscribe (aka new Unicode Script Processor) implementation in USP10.DLL in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2, and Microsoft Office XP SP3, 2003 SP3, and 2007 SP2, does not properly validate tables associated with malformed OpenType fonts, which allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) Office document, aka "Uniscribe Font Parsing Engine Memory Corruption Vulnerability."
21001| [CVE-2010-2729] The Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when printer sharing is enabled, does not properly validate spooler access permissions, which allows remote attackers to create files in a system directory, and consequently execute arbitrary code, by sending a crafted print request over RPC, as exploited in the wild in September 2010, aka "Print Spooler Service Impersonation Vulnerability."
21002| [CVE-2010-2728] Heap-based buffer overflow in Microsoft Outlook 2002 SP3, 2003 SP3, and 2007 SP2, when Online Mode for an Exchange Server is enabled, allows remote attackers to execute arbitrary code via a crafted e-mail message, aka "Heap Based Buffer Overflow in Outlook Vulnerability."
21003| [CVE-2010-2573] Integer underflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3, PowerPoint Viewer SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint Integer Underflow Causes Heap Corruption Vulnerability."
21004| [CVE-2010-2572] Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95 document, aka "PowerPoint Parsing Buffer Overflow Vulnerability."
21005| [CVE-2010-2571] Array index error in pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher 97 file, aka "Memory Corruption Due To Invalid Index Into Array in Pubconv.dll Vulnerability."
21006| [CVE-2010-2570] Heap-based buffer overflow in pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3, 2003 SP3, 2007 SP2, and 2010 allows remote attackers to execute arbitrary code via a crafted Publisher file that uses an old file format, aka "Heap Overrun in pubconv.dll Vulnerability."
21007| [CVE-2010-2569] pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3, 2003 SP3, and 2007 SP2 does not properly handle an unspecified size field in certain older file formats, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted Publisher file, aka "Size Value Heap Corruption in pubconv.dll Vulnerability."
21008| [CVE-2010-2568] Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code via a crafted (1) .LNK or (2) .PIF shortcut file, which is not properly handled during icon display in Windows Explorer, as demonstrated in the wild in July 2010, and originally reported for malware that leverages CVE-2010-2772 in Siemens WinCC SCADA systems.
21009| [CVE-2010-2567] The RPC client implementation in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly allocate memory during the parsing of responses, which allows remote RPC servers and man-in-the-middle attackers to execute arbitrary code via a malformed response, aka "RPC Memory Corruption Vulnerability."
21010| [CVE-2010-2566] The Secure Channel (aka SChannel) security package in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, does not properly validate certificate request messages from TLS and SSL servers, which allows remote servers to execute arbitrary code via a crafted SSL response, aka "SChannel Malformed Certificate Request Remote Code Execution Vulnerability."
21011| [CVE-2010-2563] The Word 97 text converter in the WordPad Text Converters in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly parse malformed structures in Word 97 documents, which allows remote attackers to execute arbitrary code via a crafted document containing an unspecified value that is used in a loop counter, aka "WordPad Word 97 Text Converter Memory Corruption Vulnerability."
21012| [CVE-2010-2562] Microsoft Office Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Excel file, aka "Excel Memory Corruption Vulnerability."
21013| [CVE-2010-2555] The Tracing Feature for Services in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly determine the length of strings in the registry, which allows local users to gain privileges or cause a denial of service (memory corruption) via vectors involving a long string, aka "Tracing Memory Corruption Vulnerability."
21014| [CVE-2010-2554] The Tracing Feature for Services in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 has incorrect ACLs on its registry keys, which allows local users to gain privileges via vectors involving a named pipe and impersonation, aka "Tracing Registry Key ACL Vulnerability."
21015| [CVE-2010-2552] Stack consumption vulnerability in the SMB Server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to cause a denial of service (system hang) via a malformed SMBv2 compounded request, aka "SMB Stack Exhaustion Vulnerability."
21016| [CVE-2010-2551] The SMB Server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate an internal variable in an SMB packet, which allows remote attackers to cause a denial of service (system hang) via a crafted (1) SMBv1 or (2) SMBv2 packet, aka "SMB Variable Validation Vulnerability."
21017| [CVE-2010-2550] The SMB Server in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate fields in an SMB request, which allows remote attackers to execute arbitrary code via a crafted SMB packet, aka "SMB Pool Overflow Vulnerability."
21018| [CVE-2010-2549] Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2 and Server 2008 Gold and SP2 allows local users to gain privileges or cause a denial of service (system crash) by using a large number of calls to the NtUserCheckAccessForIntegrityLevel function to trigger a failure in the LockProcessByClientId function, leading to deletion of an in-use process object, aka "Win32k Reference Count Vulnerability."
21019| [CVE-2010-2265] Cross-site scripting (XSS) vulnerability in the GetServerName function in sysinfo/commonFunc.js in Microsoft Windows Help and Support Center for Windows XP and Windows Server 2003 allows remote attackers to inject arbitrary web script or HTML via the svr parameter to sysinfo/sysinfomain.htm. NOTE: this can be leveraged with CVE-2010-1885 to execute arbitrary commands without user interaction.
21020| [CVE-2010-2091] Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7 on Windows Server 2003 is used, does not properly handle the id parameter in a Folder IPF.Note action to the default URI, which might allow remote attackers to obtain sensitive information or conduct cross-site scripting (XSS) attacks via an invalid value.
21021| [CVE-2010-2084] Microsoft ASP.NET 2.0 does not prevent setting the InnerHtml property on a control that inherits from HtmlContainerControl, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to an attribute.
21022| [CVE-2010-1903] Microsoft Office Word 2002 SP3 and 2003 SP3, and Office Word Viewer, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed record in a Word file, aka "Word HTML Linked Objects Memory Corruption Vulnerability."
21023| [CVE-2010-1902] Buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2
21024| [CVE-2010-1901] Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2
21025| [CVE-2010-1900] Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2
21026| [CVE-2010-1898] The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP1, 2.0 SP2, 3.5, 3.5 SP1, and 3.5.1, and Microsoft Silverlight 2 and 3 before 3.0.50611.0 on Windows and before 3.0.41130.0 on Mac OS X, does not properly handle interfaces and delegations to virtual methods, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft Silverlight and Microsoft .NET Framework CLR Virtual Method Delegate Vulnerability."
21027| [CVE-2010-1897] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly validate pseudo-handle values in callback parameters during window creation, which allows local users to gain privileges via a crafted application, aka "Win32k Window Creation Vulnerability."
21028| [CVE-2010-1896] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2 do not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Win32k User Input Validation Vulnerability."
21029| [CVE-2010-1895] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, do not properly perform memory allocation before copying user-mode data to kernel mode, which allows local users to gain privileges via a crafted application, aka "Win32k Pool Overflow Vulnerability."
21030| [CVE-2010-1894] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, do not properly handle unspecified exceptions, which allows local users to gain privileges via a crafted application, aka "Win32k Exception Handling Vulnerability."
21031| [CVE-2010-1893] Integer overflow in the TCP/IP stack in Microsoft Windows Vista SP1, Windows Server 2008 Gold and R2, and Windows 7 allows local users to gain privileges via a buffer of user-mode data that is copied to kernel mode, aka "Integer Overflow in Windows Networking Vulnerability."
21032| [CVE-2010-1892] The TCP/IP stack in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly handle malformed IPv6 packets, which allows remote attackers to cause a denial of service (system hang) via multiple crafted packets, aka "IPv6 Memory Corruption Vulnerability."
21033| [CVE-2010-1891] The Client/Server Runtime Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2, when a Chinese, Japanese, or Korean locale is enabled, does not properly allocate memory for transactions, which allows local users to gain privileges via a crafted application, aka "CSRSS Local Elevation of Privilege Vulnerability."
21034| [CVE-2010-1890] The kernel in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate ACLs on kernel objects, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Improper Validation Vulnerability."
21035| [CVE-2010-1889] Double free vulnerability in the kernel in Microsoft Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2, allows local users to gain privileges via a crafted application, related to object initialization during error handling, aka "Windows Kernel Double Free Vulnerability."
21036| [CVE-2010-1887] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly validate an unspecified system-call argument, which allows local users to cause a denial of service (system hang) via a crafted application, aka "Win32k Bounds Checking Vulnerability."
21037| [CVE-2010-1886] Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2, and Windows 7 allow local users to gain privileges by leveraging access to a process with NetworkService credentials, as demonstrated by TAPI Server, SQL Server, and IIS processes, and related to the Windows Service Isolation feature. NOTE: the vendor states that privilege escalation from NetworkService to LocalSystem does not cross a "security boundary."
21038| [CVE-2010-1885] The MPC::HexToNum function in helpctr.exe in Microsoft Windows Help and Support Center in Windows XP and Windows Server 2003 does not properly handle malformed escape sequences, which allows remote attackers to bypass the trusted documents whitelist (fromHCP option) and execute arbitrary commands via a crafted hcp:// URL, aka "Help Center URL Validation Vulnerability."
21039| [CVE-2010-1883] Integer overflow in the Embedded OpenType (EOT) Font Engine in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to execute arbitrary code via a crafted table in an embedded font, aka "Embedded OpenType Font Integer Overflow Vulnerability."
21040| [CVE-2010-1882] Multiple buffer overflows in the MPEG Layer-3 Audio Codec for Microsoft DirectShow in l3codecx.ax in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allow remote attackers to execute arbitrary code via an MPEG Layer-3 audio stream in (1) a crafted media file or (2) crafted streaming content, aka "MPEG Layer-3 Audio Decoder Buffer Overflow Vulnerability."
21041| [CVE-2010-1881] The FieldList ActiveX control in the Microsoft Access Wizard Controls in ACCWIZ.dll in Microsoft Office Access 2003 SP3 does not properly interact with the memory-access approach used by Internet Explorer and Office during instantiation, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via an HTML document that references this control along with crafted persistent storage data, aka "ACCWIZ.dll Uninitialized Variable Vulnerability."
21042| [CVE-2010-1880] Unspecified vulnerability in Quartz.dll for DirectShow on Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1, and Server 2008 allows remote attackers to execute arbitrary code via a media file with crafted compression data, aka "MJPEG Media Decompression Vulnerability."
21043| [CVE-2010-1735] The SfnLOGONNOTIFY function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service (system crash) via a 0x4c value in the second argument (aka the Msg argument) of a PostMessage function call for the DDEMLEvent window.
21044| [CVE-2010-1734] The SfnINSTRING function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service (system crash) via a 0x18d value in the second argument (aka the Msg argument) of a PostMessage function call for the DDEMLEvent window.
21045| [CVE-2010-1690] The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 does not verify that transaction IDs of responses match transaction IDs of queries, which makes it easier for man-in-the-middle attackers to spoof DNS responses, a different vulnerability than CVE-2010-0024 and CVE-2010-0025.
21046| [CVE-2010-1689] The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 uses predictable transaction IDs that are formed by incrementing a previous ID by 1, which makes it easier for man-in-the-middle attackers to spoof DNS responses, a different vulnerability than CVE-2010-0024 and CVE-2010-0025.
21047| [CVE-2010-1263] Windows Shell and WordPad in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7
21048| [CVE-2010-1257] Cross-site scripting (XSS) vulnerability in the toStaticHTML API, as used in Microsoft Office InfoPath 2003 SP3, 2007 SP1, and 2007 SP2
21049| [CVE-2010-1255] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 Gold and SP2, Windows 7, and Server 2008 R2 allows local users to execute arbitrary code via vectors related to "glyph outline information" and TrueType fonts, aka "Win32k TrueType Font Parsing Vulnerability."
21050| [CVE-2010-1253] Microsoft Office Excel 2002 SP3, 2007 SP1, and SP2
21051| [CVE-2010-1252] Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Excel file, aka "Excel String Variable Vulnerability."
21052| [CVE-2010-1251] Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Excel file, aka "Excel Record Stack Corruption Vulnerability."
21053| [CVE-2010-1250] Heap-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with malformed (1) EDG (0x88) and (2) Publisher (0x89) records, aka "Excel EDG Memory Corruption Vulnerability."
21054| [CVE-2010-1249] Buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed ExternName (0x23) record, aka "Excel Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0823 and CVE-2010-1247.
21055| [CVE-2010-1248] Buffer overflow in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed HFPicture (0x866) record, aka "Excel HFPicture Memory Corruption Vulnerability."
21056| [CVE-2010-1247] Unspecified vulnerability in Microsoft Office Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel file with a malformed RTD (0x813) record that triggers heap corruption, aka "Excel Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0823 and CVE-2010-1249.
21057| [CVE-2010-1246] Stack-based buffer overflow in Microsoft Office Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel file with a malformed RTD (0x813) record, aka "Excel RTD Memory Corruption Vulnerability."
21058| [CVE-2010-1245] Unspecified vulnerability in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed SxView (0xB0) record, aka "Excel Record Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0824 and CVE-2010-0821.
21059| [CVE-2010-1225] The memory-management implementation in the Virtual Machine Monitor (aka VMM or hypervisor) in Microsoft Virtual PC 2007 Gold and SP1, Virtual Server 2005 Gold and R2 SP1, and Windows Virtual PC does not properly restrict access from the guest OS to memory locations in the VMM work area, which allows context-dependent attackers to bypass certain anti-exploitation protection mechanisms on the guest OS via crafted input to a vulnerable application. NOTE: the vendor reportedly found that only systems with an otherwise vulnerable application are affected, because "the memory areas accessible from the guest cannot be leveraged to achieve either remote code execution or elevation of privilege and ... no data from the host is exposed to the guest OS."
21060| [CVE-2010-1175] Microsoft Internet Explorer 7.0 on Windows XP and Windows Server 2003 allows remote attackers to have an unspecified impact via a certain XML document that references a crafted web site in the SRC attribute of an image element, related to a "0day Vulnerability."
21061| [CVE-2010-0917] Stack-based buffer overflow in VBScript in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, might allow user-assisted remote attackers to execute arbitrary code via a long string in the fourth argument (aka helpfile argument) to the MsgBox function, leading to code execution when the F1 key is pressed, a different vulnerability than CVE-2010-0483.
21062| [CVE-2010-0824] Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed WOPT (0x80B) record, aka "Excel Record Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0821 and CVE-2010-1245.
21063| [CVE-2010-0823] Unspecified vulnerability in Microsoft Office Excel 2002 SP3, 2003 SP3, 2007 SP1 and SP2
21064| [CVE-2010-0822] Stack-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a crafted OBJ (0x5D) record, aka "Excel Object Stack Overflow Vulnerability."
21065| [CVE-2010-0821] Unspecified vulnerability in Microsoft Office Excel 2002 SP3, 2003 SP3, 2007 SP1 and SP2
21066| [CVE-2010-0820] Heap-based buffer overflow in the Local Security Authority Subsystem Service (LSASS), as used in Active Directory in Microsoft Windows Server 2003 SP2 and Windows Server 2008 Gold, SP2, and R2
21067| [CVE-2010-0819] Unspecified vulnerability in the Windows OpenType Compact Font Format (CFF) driver in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users to execute arbitrary code via unknown vectors related to improper validation when copying data from user mode to kernel mode, aka "OpenType CFF Font Driver Memory Corruption Vulnerability."
21068| [CVE-2010-0818] The MPEG-4 codec in the Windows Media codecs in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 does not properly handle crafted media content with MPEG-4 video encoding, which allows remote attackers to execute arbitrary code via a file in an unspecified "supported format," aka "MPEG-4 Codec Vulnerability."
21069| [CVE-2010-0817] Cross-site scripting (XSS) vulnerability in _layouts/help.aspx in Microsoft SharePoint Server 2007 12.0.0.6421 and possibly earlier, and SharePoint Services 3.0 SP1 and SP2, versions, allows remote attackers to inject arbitrary web script or HTML via the cid0 parameter.
21070| [CVE-2010-0815] VBE6.DLL in Microsoft Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Visual Basic for Applications (VBA), and VBA SDK 6.3 through 6.5 does not properly search for ActiveX controls that are embedded in documents, which allows remote attackers to execute arbitrary code via a crafted document, aka "VBE6.DLL Stack Memory Corruption Vulnerability."
21071| [CVE-2010-0814] The Microsoft Access Wizard Controls in ACCWIZ.dll in Microsoft Office Access 2003 SP3 and 2007 SP1 and SP2 do not properly interact with the memory-allocation approach used by Internet Explorer during instantiation, which allows remote attackers to execute arbitrary code via a web site that references multiple ActiveX controls, as demonstrated by the ImexGrid and FieldList controls, aka "Access ActiveX Control Vulnerability."
21072| [CVE-2010-0812] Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to bypass intended IPv4 source-address restrictions via a mismatched IPv6 source address in a tunneled ISATAP packet, aka "ISATAP IPv6 Source Address Spoofing Vulnerability."
21073| [CVE-2010-0811] Multiple unspecified vulnerabilities in the Microsoft Internet Explorer 8 Developer Tools ActiveX control in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allow remote attackers to execute arbitrary code via unknown vectors that "corrupt the system state," aka "Microsoft Internet Explorer 8 Developer Tools Vulnerability."
21074| [CVE-2010-0810] The kernel in Microsoft Windows Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2, does not properly handle unspecified exceptions, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Exception Handler Vulnerability."
21075| [CVE-2010-0719] An unspecified API in Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, and Windows 7 does not validate arguments, which allows local users to cause a denial of service (system crash) via a crafted application.
21076| [CVE-2010-0487] The Authenticode Signature verification functionality in cabview.dll in Cabinet File Viewer Shell Extension 5.1, 6.0, and 6.1 in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly use unspecified fields in a file digest, which allows remote attackers to execute arbitrary code via a modified cabinet (aka .CAB) file that incorrectly appears to have a valid signature, aka "Cabview Corruption Validation Vulnerability."
21077| [CVE-2010-0486] The WinVerifyTrust function in Authenticode Signature Verification 5.1, 6.0, and 6.1 in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly use unspecified fields in a file digest, which allows user-assisted remote attackers to execute arbitrary code via a modified (1) Portable Executable (PE) or (2) cabinet (aka .CAB) file that incorrectly appears to have a valid signature, aka "WinVerifyTrust Signature Validation Vulnerability."
21078| [CVE-2010-0485] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 Gold and SP2, Windows 7, and Server 2008 R2 "do not properly validate all callback parameters when creating a new window," which allows local users to execute arbitrary code, aka "Win32k Window Creation Vulnerability."
21079| [CVE-2010-0484] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 "do not properly validate changes in certain kernel objects," which allows local users to execute arbitrary code via vectors related to Device Contexts (DC) and the GetDCEx function, aka "Win32k Improper Data Validation Vulnerability."
21080| [CVE-2010-0483] vbscript.dll in VBScript 5.1, 5.6, 5.7, and 5.8 in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, allows user-assisted remote attackers to execute arbitrary code by referencing a (1) local pathname, (2) UNC share pathname, or (3) WebDAV server with a crafted .hlp file in the fourth argument (aka helpfile argument) to the MsgBox function, leading to code execution involving winhlp32.exe when the F1 key is pressed, aka "VBScript Help Keypress Vulnerability."
21081| [CVE-2010-0482] The kernel in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate relocation sections of image files, which allows local users to cause a denial of service (reboot) via a crafted file, aka "Windows Kernel Malformed Image Vulnerability."
21082| [CVE-2010-0481] The kernel in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly translate a registry key's virtual path to its real path, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Virtual Path Parsing Vulnerability."
21083| [CVE-2010-0480] Multiple stack-based buffer overflows in the MPEG Layer-3 audio codecs in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to execute arbitrary code via a crafted AVI file, aka "MPEG Layer-3 Audio Decoder Stack Overflow Vulnerability."
21084| [CVE-2010-0479] Buffer overflow in Microsoft Office Publisher 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Microsoft Office Publisher File Conversion TextBox Processing Buffer Overflow Vulnerability."
21085| [CVE-2010-0478] Stack-based buffer overflow in nsum.exe in the Windows Media Unicast Service in Media Services for Microsoft Windows 2000 Server SP4 allows remote attackers to execute arbitrary code via crafted packets associated with transport information, aka "Media Services Stack-based Buffer Overflow Vulnerability."
21086| [CVE-2010-0477] The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly handle (1) SMBv1 and (2) SMBv2 response packets, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted packet that causes the client to read the entirety of the response, and then improperly interact with the Winsock Kernel (WSK), aka "SMB Client Message Size Vulnerability."
21087| [CVE-2010-0476] The SMB client in Microsoft Windows Server 2003 SP2, Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2 allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and reboot) via a crafted SMB transaction response that uses (1) SMBv1 or (2) SMBv2, aka "SMB Client Response Parsing Vulnerability."
21088| [CVE-2010-0278] A certain ActiveX control in msgsc.14.0.8089.726.dll in Microsoft Windows Live Messenger 2009 build 14.0.8089.726 on Windows Vista and Windows 7 allows remote attackers to cause a denial of service (msnmsgr.exe crash) by calling the ViewProfile method with a crafted argument during an MSN Messenger session.
21089| [CVE-2010-0270] The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate fields in SMB transaction responses, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and reboot) via a crafted (1) SMBv1 or (2) SMBv2 response, aka "SMB Client Transaction Vulnerability."
21090| [CVE-2010-0269] The SMB client in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly allocate memory for SMB responses, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted (1) SMBv1 or (2) SMBv2 response, aka "SMB Client Memory Allocation Vulnerability."
21091| [CVE-2010-0268] Unspecified vulnerability in the Windows Media Player ActiveX control in Windows Media Player (WMP) 9 on Microsoft Windows 2000 SP4 and XP SP2 and SP3 allows remote attackers to execute arbitrary code via crafted media content, aka "Media Player Remote Code Execution Vulnerability."
21092| [CVE-2010-0266] Microsoft Office Outlook 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 does not properly verify e-mail attachments with a PR_ATTACH_METHOD property value of ATTACH_BY_REFERENCE, which allows user-assisted remote attackers to execute arbitrary code via a crafted message, aka "Microsoft Outlook SMB Attachment Vulnerability."
21093| [CVE-2010-0265] Buffer overflow in Microsoft Windows Movie Maker 2.1, 2.6, and 6.0, and Microsoft Producer 2003, allows remote attackers to execute arbitrary code via a crafted project (.MSWMM) file, aka "Movie Maker and Producer Buffer Overflow Vulnerability."
21094| [CVE-2010-0264] Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Microsoft Office Excel DbOrParamQry Record Parsing Vulnerability."
21095| [CVE-2010-0263] Microsoft Office Excel 2007 SP1 and SP2
21096| [CVE-2010-0262] Microsoft Office Excel 2007 SP1 and SP2 and Office 2004 for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet that triggers access of an uninitialized stack variable, aka "Microsoft Office Excel FNGROUPNAME Record Uninitialized Memory Vulnerability."
21097| [CVE-2010-0261] Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2 and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted spreadsheet in which "a MDXSET record is broken up into several records," aka "Microsoft Office Excel MDXSET Record Heap Overflow Vulnerability."
21098| [CVE-2010-0260] Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2
21099| [CVE-2010-0258] Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
21100| [CVE-2010-0257] Microsoft Office Excel 2002 SP3 does not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Microsoft Office Excel Record Memory Corruption Vulnerability."
21101| [CVE-2010-0256] Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 and SP2 does not properly calculate unspecified indexes associated with Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Visio Index Calculation Memory Corruption Vulnerability."
21102| [CVE-2010-0254] Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 and SP2 does not properly validate attributes in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Visio Attribute Validation Memory Corruption Vulnerability."
21103| [CVE-2010-0252] The Microsoft Data Analyzer ActiveX control (aka the Office Excel ActiveX control for Data Analysis) in max3activex.dll in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to execute arbitrary code via a crafted web page that corrupts the "system state," aka "Microsoft Data Analyzer ActiveX Control Vulnerability."
21104| [CVE-2010-0250] Heap-based buffer overflow in DirectShow in Microsoft DirectX, as used in the AVI Filter on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2, and in Quartz on Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, allows remote attackers to execute arbitrary code via an AVI file with a crafted length field in an unspecified video stream, which is not properly handled by the RLE video decompressor, aka "DirectShow Heap Overflow Vulnerability."
21105| [CVE-2010-0249] Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4
21106| [CVE-2010-0243] Buffer overflow in MSO.DLL in Microsoft Office XP SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Office document, aka "MSO.DLL Buffer Overflow."
21107| [CVE-2010-0242] The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows remote attackers to cause a denial of service (system hang) via crafted packets with malformed TCP selective acknowledgement (SACK) values, aka "TCP/IP Selective Acknowledgement Vulnerability."
21108| [CVE-2010-0241] The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when IPv6 is enabled, does not properly perform bounds checking on ICMPv6 Route Information packets, which allows remote attackers to execute arbitrary code via crafted packets, aka "ICMPv6 Route Information Vulnerability."
21109| [CVE-2010-0240] The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when a custom network driver is used, does not properly handle local fragmentation of Encapsulating Security Payload (ESP) over UDP packets, which allows remote attackers to execute arbitrary code via crafted packets, aka "Header MDL Fragmentation Vulnerability."
21110| [CVE-2010-0239] The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when IPv6 is enabled, does not properly perform bounds checking on ICMPv6 Router Advertisement packets, which allows remote attackers to execute arbitrary code via crafted packets, aka "ICMPv6 Router Advertisement Vulnerability."
21111| [CVE-2010-0238] Unspecified vulnerability in registry-key validation in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Registry Key Vulnerability."
21112| [CVE-2010-0237] The kernel in Microsoft Windows 2000 SP4 and XP SP2 and SP3 allows local users to gain privileges by creating a symbolic link from an untrusted registry hive to a trusted registry hive, aka "Windows Kernel Symbolic Link Creation Vulnerability."
21113| [CVE-2010-0236] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold does not properly allocate memory for the destination key associated with a symbolic-link registry key, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Allocation Vulnerability."
21114| [CVE-2010-0235] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold does not perform the expected validation before creating a symbolic link, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Symbolic Link Value Vulnerability."
21115| [CVE-2010-0234] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not properly validate a registry-key argument to an unspecified system call, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Null Pointer Vulnerability."
21116| [CVE-2010-0233] Double free vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows local users to gain privileges via a crafted application, aka "Windows Kernel Double Free Vulnerability."
21117| [CVE-2010-0232] The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges by crafting a VDM_TIB data structure in the Thread Environment Block (TEB), and then calling the NtVdmControl function to start the Windows Virtual DOS Machine (aka NTVDM) subsystem, leading to improperly handled exceptions involving the #GP trap handler (nt!KiTrap0D), aka "Windows Kernel Exception Handler Vulnerability."
21118| [CVE-2010-0231] The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not use a sufficient source of entropy, which allows remote attackers to obtain access to files and other SMB resources via a large number of authentication requests, related to server-generated challenges, certain "duplicate values," and spoofing of an authentication token, aka "SMB NTLM Authentication Lack of Entropy Vulnerability."
21119| [CVE-2010-0035] The Key Distribution Center (KDC) in Kerberos in Microsoft Windows 2000 SP4, Server 2003 SP2, and Server 2008 Gold and SP2, when a trust relationship with a non-Windows Kerberos realm exists, allows remote authenticated users to cause a denial of service (NULL pointer dereference and domain controller outage) via a crafted Ticket Granting Ticket (TGT) renewal request, aka "Kerberos Null Pointer Dereference Vulnerability."
21120| [CVE-2010-0034] Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "Office PowerPoint Viewer TextCharsAtom Record Stack Overflow Vulnerability."
21121| [CVE-2010-0033] Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint Viewer TextBytesAtom Record Stack Overflow Vulnerability."
21122| [CVE-2010-0032] Use-after-free vulnerability in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "OEPlaceholderAtom Use After Free Vulnerability."
21123| [CVE-2010-0031] Array index error in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3, and PowerPoint in Office 2004 for Mac, allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint OEPlaceholderAtom 'placementId' Invalid Array Indexing Vulnerability."
21124| [CVE-2010-0030] Heap-based buffer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint LinkedSlideAtom Heap Overflow Vulnerability."
21125| [CVE-2010-0029] Buffer overflow in Microsoft Office PowerPoint 2002 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint File Path Handling Buffer Overflow Vulnerability."
21126| [CVE-2010-0028] Integer overflow in Microsoft Paint in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted JPEG (.JPG) file, aka "MS Paint Integer Overflow Vulnerability."
21127| [CVE-2010-0027] The URL validation functionality in Microsoft Internet Explorer 5.01, 6, 6 SP1, 7 and 8, and the ShellExecute API function in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."
21128| [CVE-2010-0026] The Hyper-V server implementation in Microsoft Windows Server 2008 Gold, SP2, and R2 on the x64 platform allows guest OS users to cause a denial of service (host OS hang) via a crafted application that executes a malformed series of machine instructions, aka "Hyper-V Instruction Set Validation Vulnerability."
21129| [CVE-2010-0025] The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2000 SP3, does not properly allocate memory for SMTP command replies, which allows remote attackers to read fragments of e-mail messages by sending a series of invalid commands and then sending a STARTTLS command, aka "SMTP Memory Allocation Vulnerability."
21130| [CVE-2010-0024] The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2003 SP2, does not properly parse MX records, which allows remote DNS servers to cause a denial of service (service outage) via a crafted response to a DNS MX record query, aka "SMTP Server MX Record Vulnerability."
21131| [CVE-2010-0023] The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly kill processes after a logout, which allows local users to obtain sensitive information or gain privileges via a crafted application that continues to execute throughout the logout of one user and the login session of the next user, aka "CSRSS Local Privilege Elevation Vulnerability."
21132| [CVE-2010-0022] The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate the share and servername fields in SMB packets, which allows remote attackers to cause a denial of service (system hang) via a crafted packet, aka "SMB Null Pointer Vulnerability."
21133| [CVE-2010-0021] Multiple race conditions in the SMB implementation in the Server service in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allow remote attackers to cause a denial of service (system hang) via a crafted (1) SMBv1 or (2) SMBv2 Negotiate packet, aka "SMB Memory Corruption Vulnerability."
21134| [CVE-2010-0020] The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate request fields, which allows remote authenticated users to execute arbitrary code via a malformed request, aka "SMB Pathname Overflow Vulnerability."
21135| [CVE-2010-0018] Integer overflow in the Embedded OpenType (EOT) Font Engine (t2embed.dll) in Microsoft Windows 2000 SP4
21136| [CVE-2010-0017] Race condition in the SMB client implementation in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code, and in the SMB client implementation in Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows local users to gain privileges, via a crafted SMB Negotiate response, aka "SMB Client Race Condition Vulnerability."
21137| [CVE-2010-0016] The SMB client implementation in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly validate response fields, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted response, aka "SMB Client Pool Corruption Vulnerability."
21138| [CVE-2009-4313] ir32_32.dll 3.24.15.3 in the Indeo32 codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to cause a denial of service (heap corruption) or execute arbitrary code via malformed data in a stream in a media file, as demonstrated by an AVI file.
21139| [CVE-2009-4312] Unspecified vulnerability in the Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via crafted media content, as reported to Microsoft by Dave Lenoe of Adobe.
21140| [CVE-2009-4311] Unspecified vulnerability in the Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via crafted media content, as reported to Microsoft by Paul Byrne of NGS Software. NOTE: this might overlap CVE-2008-3615.
21141| [CVE-2009-4310] Stack-based buffer overflow in the Intel Indeo41 codec for Windows Media Player in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via crafted compressed video data in an IV41 stream in a media file, leading to many loop iterations, as demonstrated by data in an AVI file.
21142| [CVE-2009-4309] Heap-based buffer overflow in the Intel Indeo41 codec for Windows Media Player in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a large size value in a movi record in an IV41 stream in a media file, as demonstrated by an AVI file.
21143| [CVE-2009-4210] The Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted media content.
21144| [CVE-2009-3830] The download functionality in Team Services in Microsoft Office SharePoint Server 2007 12.0.0.4518 and 12.0.0.6219 allows remote attackers to read ASP.NET source code via pathnames in the SourceUrl and Source parameters to _layouts/download.aspx.
21145| [CVE-2009-3678] Integer overflow in cdd.dll in the Canonical Display Driver (CDD) in Microsoft Windows Server 2008 R2 and Windows 7 on 64-bit platforms, when the Windows Aero theme is installed, allows context-dependent attackers to cause a denial of service (reboot) or possibly execute arbitrary code via a crafted image file that triggers incorrect data parsing after user-mode data is copied to kernel mode, as demonstrated using "Browse with Irfanview" and certain actions on a folder containing a large number of thumbnail images in Resample mode, possibly related to the ATI graphics driver or win32k.sys, aka "Canonical Display Driver Integer Overflow Vulnerability."
21146| [CVE-2009-3677] The Internet Authentication Service (IAS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly verify the credentials in an MS-CHAP v2 Protected Extensible Authentication Protocol (PEAP) authentication request, which allows remote attackers to access network resources via a malformed request, aka "MS-CHAP Authentication Bypass Vulnerability."
21147| [CVE-2009-3676] The SMB client in the kernel in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle attackers to cause a denial of service (infinite loop and system hang) via a (1) SMBv1 or (2) SMBv2 response packet that contains (a) an incorrect length value in a NetBIOS header or (b) an additional length field at the end of this response packet, aka "SMB Client Incomplete Response Vulnerability."
21148| [CVE-2009-3675] LSASS.exe in the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote authenticated users to cause a denial of service (CPU consumption) via a malformed ISAKMP request over IPsec, aka "Local Security Authority Subsystem Service Resource Exhaustion Vulnerability."
21149| [CVE-2009-3450] Multiple cross-site scripting (XSS) vulnerabilities in WebCoreModule.ashx in RADactive I-Load before 2008.2.5.0 allow remote attackers to inject arbitrary web script or HTML via parameters with names beginning with __ (underscore underscore) sequences, which are incompatible with an XSS protection mechanism provided by Microsoft ASP.NET.
21150| [CVE-2009-3135] Stack-based buffer overflow in Microsoft Office Word 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, Open XML File Format Converter for Mac, Office Word Viewer 2003 SP3, and Office Word Viewer allow remote attackers to execute arbitrary code via a Word document with a malformed File Information Block (FIB) structure, aka "Microsoft Office Word File Information Memory Corruption Vulnerability."
21151| [CVE-2009-3134] Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
21152| [CVE-2009-3133] Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a spreadsheet containing a malformed object that triggers memory corruption, related to "loading Excel records," aka "Excel Document Parsing Memory Corruption Vulnerability."
21153| [CVE-2009-3132] Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
21154| [CVE-2009-3131] Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
21155| [CVE-2009-3130] Heap-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via a spreadsheet containing a malformed Binary File Format (aka BIFF) record that triggers memory corruption, aka "Excel Document Parsing Heap Overflow Vulnerability."
21156| [CVE-2009-3129] Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
21157| [CVE-2009-3128] Microsoft Office Excel 2002 SP3 and 2003 SP3, and Office Excel Viewer 2003 SP3, does not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a spreadsheet with a malformed record object, aka "Excel SxView Memory Corruption Vulnerability."
21158| [CVE-2009-3127] Microsoft Office Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, Open XML File Format Converter for Mac, and Office Excel Viewer 2003 SP3 do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Cache Memory Corruption Vulnerability."
21159| [CVE-2009-3126] Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted PNG image file, aka "GDI+ PNG Integer Overflow Vulnerability."
21160| [CVE-2009-3103] Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via an & (ampersand) character in a Process ID High header field in a NEGOTIATE PROTOCOL REQUEST packet, which triggers an attempted dereference of an out-of-bounds memory location, aka "SMBv2 Negotiation Vulnerability." NOTE: some of these details are obtained from third party information.
21161| [CVE-2009-3020] win32k.sys in Microsoft Windows Server 2003 SP2 allows remote attackers to cause a denial of service (system crash) by referencing a crafted .eot file in the src descriptor of an @font-face Cascading Style Sheets (CSS) rule in an HTML document, possibly related to the Embedded OpenType (EOT) Font Engine, a different vulnerability than CVE-2006-0010, CVE-2009-0231, and CVE-2009-0232. NOTE: some of these details are obtained from third party information.
21162| [CVE-2009-2653] ** DISPUTED ** The NtUserConsoleControl function in win32k.sys in Microsoft Windows XP SP2 and SP3, and Server 2003 before SP1, allows local administrators to bypass unspecified "security software" and gain privileges via a crafted call that triggers an overwrite of an arbitrary memory location. NOTE: the vendor disputes the significance of this report, stating that 'the Administrator to SYSTEM "escalation" is not a security boundary we defend.'
21163| [CVE-2009-2532] Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC do not properly process the command value in an SMB Multi-Protocol Negotiate Request packet, which allows remote attackers to execute arbitrary code via a crafted SMBv2 packet to the Server service, aka "SMBv2 Command Value Vulnerability."
21164| [CVE-2009-2526] Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 do not properly validate fields in SMBv2 packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted packet to the Server service, aka "SMBv2 Infinite Loop Vulnerability."
21165| [CVE-2009-2524] Integer underflow in the NTLM authentication feature in the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to cause a denial of service (reboot) via a malformed packet, aka "Local Security Authority Subsystem Service Integer Overflow Vulnerability."
21166| [CVE-2009-2523] The License Logging Server (llssrv.exe) in Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrary code via an RPC message containing a string without a null terminator, which triggers a heap-based buffer overflow in the LlsrLicenseRequestW method, aka "License Logging Server Heap Overflow Vulnerability."
21167| [CVE-2009-2519] The DHTML Editing Component ActiveX control in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly format HTML markup, which allows remote attackers to execute arbitrary code via a crafted web site that triggers "system state" corruption, aka "DHTML Editing Component ActiveX Control Vulnerability."
21168| [CVE-2009-2517] The kernel in Microsoft Windows Server 2003 SP2 does not properly handle unspecified exceptions when an error condition occurs, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Exception Handler Vulnerability."
21169| [CVE-2009-2516] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly validate data sent from user mode, which allows local users to gain privileges via a crafted PE .exe file that triggers a NULL pointer dereference during chain traversal, aka "Windows Kernel NULL Pointer Dereference Vulnerability."
21170| [CVE-2009-2515] Integer underflow in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows local users to gain privileges via a crafted application that triggers an incorrect truncation of a 64-bit integer to a 32-bit integer, aka "Windows Kernel Integer Underflow Vulnerability."
21171| [CVE-2009-2514] win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not correctly parse font code during construction of a directory-entry table, which allows remote attackers to execute arbitrary code via a crafted Embedded OpenType (EOT) font, aka "Win32k EOT Parsing Vulnerability."
21172| [CVE-2009-2513] The Graphics Device Interface (GDI) in win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Insufficient Data Validation Vulnerability."
21173| [CVE-2009-2511] Integer overflow in the CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows man-in-the-middle attackers to spoof arbitrary SSL servers and other entities via an X.509 certificate that has a malformed ASN.1 Object Identifier (OID) and was issued by a legitimate Certification Authority, aka "Integer Overflow in X.509 Object Identifiers Vulnerability."
21174| [CVE-2009-2510] The CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, as used by Internet Explorer and other applications, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, aka "Null Truncation in X.509 Common Name Vulnerability," a related issue to CVE-2009-2408.
21175| [CVE-2009-2509] Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly validate headers in HTTP requests, which allows remote authenticated users to execute arbitrary code via a crafted request to an IIS web server, aka "Remote Code Execution in ADFS Vulnerability."
21176| [CVE-2009-2508] The single sign-on implementation in Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly remove credentials at the end of a network session, which allows physically proximate attackers to obtain the credentials of a previous user of the same web browser by using data from the browser's cache, aka "Single Sign On Spoofing in ADFS Vulnerability."
21177| [CVE-2009-2507] A certain ActiveX control in the Indexing Service in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly process URLs, which allows remote attackers to execute arbitrary programs via unspecified vectors that cause a "vulnerable binary" to load and run, aka "Memory Corruption in Indexing Service Vulnerability."
21178| [CVE-2009-2506] Integer overflow in the text converters in Microsoft Office Word 2002 SP3 and 2003 SP3
21179| [CVE-2009-2505] The Internet Authentication Service (IAS) in Microsoft Windows Vista SP2 and Server 2008 SP2 does not properly validate MS-CHAP v2 Protected Extensible Authentication Protocol (PEAP) authentication requests, which allows remote attackers to execute arbitrary code via crafted structures in a malformed request, aka "Internet Authentication Service Memory Corruption Vulnerability."
21180| [CVE-2009-2504] Multiple integer overflows in unspecified APIs in GDI+ in Microsoft .NET Framework 1.1 SP1, .NET Framework 2.0 SP1 and SP2, Windows XP SP2 and SP3, Windows Server 2003 SP2, Vista Gold and SP1, Server 2008 Gold, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allow remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "GDI+ .NET API Vulnerability."
21181| [CVE-2009-2503] GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 does not properly allocate an unspecified buffer, which allows remote attackers to execute arbitrary code via a crafted TIFF image file that triggers memory corruption, aka "GDI+ TIFF Memory Corruption Vulnerability."
21182| [CVE-2009-2502] Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted TIFF image file, aka "GDI+ TIFF Buffer Overflow Vulnerability."
21183| [CVE-2009-2501] Heap-based buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted PNG image file, aka "GDI+ PNG Heap Overflow Vulnerability."
21184| [CVE-2009-2500] Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted WMF image file, aka "GDI+ WMF Integer Overflow Vulnerability."
21185| [CVE-2009-2498] Microsoft Windows Media Format Runtime 9.0, 9.5, and 11 and Windows Media Services 9.1 and 2008 do not properly parse malformed headers in Advanced Systems Format (ASF) files, which allows remote attackers to execute arbitrary code via a crafted (1) .asf, (2) .wmv, or (3) .wma file, aka "Windows Media Header Parsing Invalid Free Vulnerability."
21186| [CVE-2009-2497] The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0, 2.0 SP1, 2.0 SP2, 3.5, and 3.5 SP1, and Silverlight 2, does not properly handle interfaces, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted Silverlight application, (3) a crafted ASP.NET application, or (4) a crafted .NET Framework application, aka "Microsoft Silverlight and Microsoft .NET Framework CLR Vulnerability."
21187| [CVE-2009-2496] Heap-based buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 SP1, and Office Small Business Accounting 2006 allows remote attackers to execute arbitrary code via unspecified parameters to unknown methods, aka "Office Web Components Heap Corruption Vulnerability."
21188| [CVE-2009-2495] The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1 does not properly enforce string termination, which allows remote attackers to obtain sensitive information via a crafted HTML document with an ATL (1) component or (2) control that triggers a buffer over-read, related to ATL headers and buffer allocation, aka "ATL Null String Vulnerability."
21189| [CVE-2009-2494] The Active Template Library (ATL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via vectors related to erroneous free operations after reading a variant from a stream and deleting this variant, aka "ATL Object Type Mismatch Vulnerability."
21190| [CVE-2009-2493] The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1
21191| [CVE-2009-1930] The Telnet service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote Telnet servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user, aka "Telnet Credential Reflection Vulnerability," a related issue to CVE-2000-0834.
21192| [CVE-2009-1929] Heap-based buffer overflow in the Microsoft Terminal Services Client ActiveX control running RDP 6.1 on Windows XP SP2, Vista SP1 or SP2, or Server 2008 Gold or SP2
21193| [CVE-2009-1928] Stack consumption vulnerability in the LDAP service in Active Directory on Microsoft Windows 2000 SP4, Server 2003 SP2, and Server 2008 Gold and SP2
21194| [CVE-2009-1926] Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to cause a denial of service (TCP outage) via a series of TCP sessions that have pending data and a (1) small or (2) zero receive window size, and remain in the FIN-WAIT-1 or FIN-WAIT-2 state indefinitely, aka "TCP/IP Orphaned Connections Vulnerability."
21195| [CVE-2009-1925] The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 does not properly manage state information, which allows remote attackers to execute arbitrary code by sending packets to a listening service, and thereby triggering misinterpretation of an unspecified field as a function pointer, aka "TCP/IP Timestamps Code Execution Vulnerability."
21196| [CVE-2009-1924] Integer overflow in the Windows Internet Name Service (WINS) component for Microsoft Windows 2000 SP4 allows remote WINS replication partners to execute arbitrary code via crafted data structures in a packet, aka "WINS Integer Overflow Vulnerability."
21197| [CVE-2009-1923] Heap-based buffer overflow in the Windows Internet Name Service (WINS) component for Microsoft Windows 2000 SP4 and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted WINS replication packet that triggers an incorrect buffer-length calculation, aka "WINS Heap Overflow Vulnerability."
21198| [CVE-2009-1922] The Message Queuing (aka MSMQ) service for Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP2, and Vista Gold does not properly validate unspecified IOCTL request data from user mode before passing this data to kernel mode, which allows local users to gain privileges via a crafted request, aka "MSMQ Null Pointer Vulnerability."
21199| [CVE-2009-1546] Integer overflow in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windows allows remote attackers to execute arbitrary code on a Windows 2000 SP4 system via a crafted AVI file, or cause a denial of service on a Windows XP SP2 or SP3, Server 2003 SP2, Vista Gold, SP1, or SP2, or Server 2008 Gold or SP2 system via a crafted AVI file, aka "AVI Integer Overflow Vulnerability."
21200| [CVE-2009-1545] Unspecified vulnerability in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a malformed header in a crafted AVI file, aka "Malformed AVI Header Vulnerability."
21201| [CVE-2009-1544] Double free vulnerability in the Workstation service in Microsoft Windows allows remote authenticated users to gain privileges via a crafted RPC message to a Windows XP SP2 or SP3 or Server 2003 SP2 system, or cause a denial of service via a crafted RPC message to a Vista Gold, SP1, or SP2 or Server 2008 Gold or SP2 system, aka "Workstation Service Memory Corruption Vulnerability."
21202| [CVE-2009-1542] The Virtual Machine Monitor (VMM) in Microsoft Virtual PC 2004 SP1, 2007, and 2007 SP1, and Microsoft Virtual Server 2005 R2 SP1, does not enforce CPU privilege-level requirements for all machine instructions, which allows guest OS users to execute arbitrary kernel-mode code and gain privileges within the guest OS via a crafted application, aka "Virtual PC and Virtual Server Privileged Instruction Decoding Vulnerability."
21203| [CVE-2009-1539] The QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 does not properly validate unspecified size fields in QuickTime media files, which allows remote attackers to execute arbitrary code via a crafted file, aka "DirectX Size Validation Vulnerability."
21204| [CVE-2009-1538] The QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 performs updates to pointers without properly validating unspecified data values, which allows remote attackers to execute arbitrary code via a crafted QuickTime media file, aka "DirectX Pointer Validation Vulnerability."
21205| [CVE-2009-1537] Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted QuickTime media file, as exploited in the wild in May 2009, aka "DirectX NULL Byte Overwrite Vulnerability."
21206| [CVE-2009-1536] ASP.NET in Microsoft .NET Framework 2.0 SP1 and SP2 and 3.5 Gold and SP1, when ASP 2.0 is used in integrated mode on IIS 7.0, does not properly manage request scheduling, which allows remote attackers to cause a denial of service (daemon outage) via a series of crafted HTTP requests, aka "Remote Unauthenticated Denial of Service in ASP.NET Vulnerability."
21207| [CVE-2009-1534] Buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2000 Web Components SP3, Office XP Web Components SP3, BizTalk Server 2002, and Visual Studio .NET 2003 SP1 allows remote attackers to execute arbitrary code via crafted property values, aka "Office Web Components Buffer Overflow Vulnerability."
21208| [CVE-2009-1533] Buffer overflow in the Works for Windows document converters in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, Office 2007 SP1, and Works 8.5 and 9 allows remote attackers to execute arbitrary code via a crafted Works .wps file that triggers memory corruption, aka "File Converter Buffer Overflow Vulnerability."
21209| [CVE-2009-1491] McAfee GroupShield for Microsoft Exchange on Exchange Server 2000, and possibly other anti-virus or anti-spam products from McAfee or other vendors, does not scan X- headers for malicious content, which allows remote attackers to bypass virus detection via a crafted message, as demonstrated by a message with an X-Testing header and no message body.
21210| [CVE-2009-1216] Multiple unspecified vulnerabilities in (1) unlzh.c and (2) unpack.c in the gzip libraries in Microsoft Windows Server 2008, Windows Services for UNIX 3.0 and 3.5, and the Subsystem for UNIX-based Applications (SUA)
21211| [CVE-2009-1141] Microsoft Internet Explorer 6 for Windows XP SP2 and SP3 and Server 2003 SP2 allows remote attackers to execute arbitrary code via unspecified DHTML function calls related to a tr element and the "insertion, deletion and attributes of a table cell," which trigger memory corruption when the window is destroyed, aka "DHTML Object Memory Corruption Vulnerability."
21212| [CVE-2009-1139] Memory leak in the LDAP service in Active Directory on Microsoft Windows 2000 SP4 and Server 2003 SP2, and Active Directory Application Mode (ADAM) on Windows XP SP2 and SP3 and Server 2003 SP2, allows remote attackers to cause a denial of service (memory consumption and service outage) via (1) LDAP or (2) LDAPS requests with unspecified OID filters, aka "Active Directory Memory Leak Vulnerability."
21213| [CVE-2009-1138] The LDAP service in Active Directory on Microsoft Windows 2000 SP4 does not properly free memory for LDAP and LDAPS requests, which allows remote attackers to execute arbitrary code via a request that uses hexadecimal encoding, whose associated memory is not released, related to a "DN AttributeValue," aka "Active Directory Invalid Free Vulnerability." NOTE: this issue is probably a memory leak.
21214| [CVE-2009-1137] Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0223, CVE-2009-0226, and CVE-2009-0227.
21215| [CVE-2009-1136] The Microsoft Office Web Components Spreadsheet ActiveX control (aka OWC10 or OWC11), as distributed in Office XP SP3 and Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 Gold and SP1, and Office Small Business Accounting 2006, when used in Internet Explorer, allows remote attackers to execute arbitrary code via a crafted call to the msDataSourceObject method, as exploited in the wild in July and August 2009, aka "Office Web Components HTML Script Vulnerability."
21216| [CVE-2009-1135] Microsoft Internet Security and Acceleration (ISA) Server 2006 Gold and SP1, when Radius OTP is enabled, uses the HTTP-Basic authentication method, which allows remote attackers to gain the privileges of an arbitrary account, and access published web pages, via vectors involving attempted access to a network resource behind the ISA Server, aka "Radius OTP Bypass Vulnerability."
21217| [CVE-2009-1134] Excel in 2007 Microsoft Office System SP1 and SP2
21218| [CVE-2009-1133] Heap-based buffer overflow in Microsoft Remote Desktop Connection (formerly Terminal Services Client) running RDP 5.0 through 6.1 on Windows, and Remote Desktop Connection Client for Mac 2.0, allows remote attackers to execute arbitrary code via unspecified parameters, aka "Remote Desktop Connection Heap Overflow Vulnerability."
21219| [CVE-2009-1132] Heap-based buffer overflow in the Wireless LAN AutoConfig Service (aka Wlansvc) in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a malformed wireless frame, aka "Wireless Frame Parsing Remote Code Execution Vulnerability."
21220| [CVE-2009-1131] Multiple stack-based buffer overflows in Microsoft Office PowerPoint 2000 SP3 allow remote attackers to execute arbitrary code via a large amount of data associated with unspecified atoms in a PowerPoint file that triggers memory corruption, aka "Data Out of Bounds Vulnerability."
21221| [CVE-2009-1130] Heap-based buffer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a crafted structure in a Notes container in a PowerPoint file that causes PowerPoint to read more data than was allocated when creating a C++ object, leading to an overwrite of a function pointer, aka "Heap Corruption Vulnerability."
21222| [CVE-2009-1129] Multiple stack-based buffer overflows in the PowerPoint 95 importer (PP7X32.DLL) in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allow remote attackers to execute arbitrary code via an inconsistent record length in sound data in a file that uses a PowerPoint 95 (PPT95) native file format, aka "PP7 Memory Corruption Vulnerability," a different vulnerability than CVE-2009-1128.
21223| [CVE-2009-1128] Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 95 native file format, leading to memory corruption, aka "PP7 Memory Corruption Vulnerability," a different vulnerability than CVE-2009-1129.
21224| [CVE-2009-1127] win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not correctly validate an argument to an unspecified system call, which allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, aka "Win32k NULL Pointer Dereferencing Vulnerability."
21225| [CVE-2009-1126] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly validate the user-mode input associated with the editing of an unspecified desktop parameter, which allows local users to gain privileges via a crafted application, aka "Windows Desktop Parameter Edit Vulnerability."
21226| [CVE-2009-1125] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate an argument to an unspecified system call, which allows local users to gain privileges via a crafted application, aka "Windows Driver Class Registration Vulnerability."
21227| [CVE-2009-1124] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate user-mode pointers in unspecified error conditions, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Pointer Validation Vulnerability."
21228| [CVE-2009-1123] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Desktop Vulnerability."
21229| [CVE-2009-1122] The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote attackers to bypass authentication, and possibly read or create files, via a crafted HTTP request, aka "IIS 5.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1535.
21230| [CVE-2009-1043] Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors triggered by clicking on a link, as demonstrated by Nils during a PWN2OWN competition at CanSecWest 2009.
21231| [CVE-2009-1011] Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on reliable researcher claims that this issue is for multiple integer overflows in a function that parses an optional data stream within a Microsoft Office file, leading to a heap-based buffer overflow.
21232| [CVE-2009-0901] The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold, and Visual C++ 2005 SP1 and 2008 Gold and SP1
21233| [CVE-2009-0568] The RPC Marshalling Engine (aka NDR) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly maintain its internal state, which allows remote attackers to overwrite arbitrary memory locations via a crafted RPC message that triggers incorrect pointer reading, related to "IDL interfaces containing a non-conformant varying array" and FC_SMVARRAY, FC_LGVARRAY, FC_VARIABLE_REPEAT, and FC_VARIABLE_OFFSET, aka "RPC Marshalling Engine Vulnerability."
21234| [CVE-2009-0566] Microsoft Office Publisher 2007 SP1 does not properly calculate object handler data for Publisher files, which allows remote attackers to execute arbitrary code via a crafted file in a legacy format that triggers memory corruption, aka "Pointer Dereference Vulnerability."
21235| [CVE-2009-0565] Buffer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, and 2007 SP1 and SP2
21236| [CVE-2009-0563] Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
21237| [CVE-2009-0562] The Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 SP1, and Office Small Business Accounting 2006 does not properly allocate memory, which allows remote attackers to execute arbitrary code via unspecified vectors that trigger "system state" corruption, aka "Office Web Components Memory Allocation Vulnerability."
21238| [CVE-2009-0561] Integer overflow in Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac
21239| [CVE-2009-0560] Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac
21240| [CVE-2009-0559] Stack-based buffer overflow in Excel in Microsoft Office 2000 SP3 and Office XP SP3 allows remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "String Copy Stack-Based Overrun Vulnerability."
21241| [CVE-2009-0558] Array index error in Excel in Microsoft Office 2000 SP3 and Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac, allows remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Array Indexing Memory Corruption Vulnerability."
21242| [CVE-2009-0557] Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac
21243| [CVE-2009-0556] Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an an invalid index value that triggers memory corruption, as exploited in the wild in April 2009 by Exploit:Win32/Apptom.gen, aka "Memory Corruption Vulnerability."
21244| [CVE-2009-0554] Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka "Uninitialized Memory Corruption Vulnerability."
21245| [CVE-2009-0553] Microsoft Internet Explorer 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka "Uninitialized Memory Corruption Vulnerability."
21246| [CVE-2009-0552] Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 on Windows XP SP2 and SP3, and 6 on Windows Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka "Uninitialized Memory Corruption Vulnerability."
21247| [CVE-2009-0551] Microsoft Internet Explorer 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 does not properly handle transition errors in a request for one HTTP document followed by a request for a second HTTP document, which allows remote attackers to execute arbitrary code via vectors involving (1) multiple crafted pages on a web site or (2) a web page with crafted inline content such as banner advertisements, aka "Page Transition Memory Corruption Vulnerability."
21248| [CVE-2009-0550] Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008
21249| [CVE-2009-0549] Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac
21250| [CVE-2009-0320] Microsoft Windows XP, Server 2003 and 2008, and Vista exposes I/O activity measurements of all processes, which allows local users to obtain sensitive information, as demonstrated by reading the I/O Other Bytes column in Task Manager (aka taskmgr.exe) to estimate the number of characters that a different user entered at a runas.exe password prompt, related to a "benchmarking attack."
21251| [CVE-2009-0239] Cross-site scripting (XSS) vulnerability in Windows Search 4.0 for Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted file that appears in a preview in a search result, aka "Script Execution in Windows Search Vulnerability."
21252| [CVE-2009-0238] Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1
21253| [CVE-2009-0235] Stack-based buffer overflow in the Word 97 text converter in WordPad in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted Word 97 file that triggers memory corruption, related to use of inconsistent integer data sizes for an unspecified length field, aka "WordPad Word 97 Text Converter Stack Overflow Vulnerability."
21254| [CVE-2009-0234] The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008 does not properly cache crafted DNS responses, which makes it easier for remote attackers to predict transaction IDs and poison caches by sending many crafted DNS queries that trigger "unnecessary lookups," aka "DNS Server Response Validation Vulnerability."
21255| [CVE-2009-0233] The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not reuse cached DNS responses in all applicable situations, which makes it easier for remote attackers to predict transaction IDs and poison caches by simultaneously sending crafted DNS queries and responses, aka "DNS Server Query Validation Vulnerability."
21256| [CVE-2009-0232] Integer overflow in the Embedded OpenType (EOT) Font Engine in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted name table, aka "Embedded OpenType Font Integer Overflow Vulnerability."
21257| [CVE-2009-0231] The Embedded OpenType (EOT) Font Engine (T2EMBED.DLL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted name table in a data record that triggers an integer truncation and a heap-based buffer overflow, aka "Embedded OpenType Font Heap Overflow Vulnerability."
21258| [CVE-2009-0230] The Windows Print Spooler in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows remote authenticated users to gain privileges via a crafted RPC message that triggers loading of a DLL file from an arbitrary directory, aka "Print Spooler Load Library Vulnerability."
21259| [CVE-2009-0229] The Windows Printing Service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows local users to read arbitrary files via a crafted separator page, aka "Print Spooler Read File Vulnerability."
21260| [CVE-2009-0228] Stack-based buffer overflow in the EnumeratePrintShares function in Windows Print Spooler Service (win32spl.dll) in Microsoft Windows 2000 SP4 allows remote printer servers to execute arbitrary code via a a crafted ShareName in a response to an RPC request, related to "printing data structures," aka "Buffer Overflow in Print Spooler Vulnerability."
21261| [CVE-2009-0227] Stack-based buffer overflow in the PowerPoint 4.2 conversion filter (PP4X32.DLL) in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via a large number of structures in sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0223, CVE-2009-0226, and CVE-2009-1137.
21262| [CVE-2009-0226] Stack-based buffer overflow in the PowerPoint 4.2 conversion filter in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via a long string in sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0223, CVE-2009-0227, and CVE-2009-1137.
21263| [CVE-2009-0225] Microsoft Office PowerPoint 2002 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 95 native file format, leading to improper "array indexing" and memory corruption, aka "PP7 Memory Corruption Vulnerability."
21264| [CVE-2009-0224] Microsoft Office PowerPoint 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
21265| [CVE-2009-0223] Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0226, CVE-2009-0227, and CVE-2009-1137.
21266| [CVE-2009-0222] Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 4.0 native file format, leading to a "pointer overwrite" and memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0223, CVE-2009-0226, CVE-2009-0227, and CVE-2009-1137.
21267| [CVE-2009-0221] Integer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a PowerPoint file containing a crafted record type for "collaboration information for different slides" that contains a field that specifies a large number of records, which triggers an under-allocated buffer and a heap-based buffer overflow, aka "Integer Overflow Vulnerability."
21268| [CVE-2009-0220] Multiple stack-based buffer overflows in the PowerPoint 4.0 importer (PP4X32.DLL) in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allow remote attackers to execute arbitrary code via crafted formatting data for paragraphs in a file that uses a PowerPoint 4.0 native file format, related to (1) an incorrect calculation from a record header, or (2) an interget that is used to specify the number of bytes to copy, aka "Legacy File Format Vulnerability."
21269| [CVE-2009-0202] Array index error in FL21WIN.DLL in the PowerPoint Freelance Windows 2.1 Translator in Microsoft PowerPoint 2000 and 2002 allows remote attackers to execute arbitrary code via a Freelance file with unspecified "layout information" that triggers a heap-based buffer overflow.
21270| [CVE-2009-0102] Microsoft Project 2000 SR1 and 2002 SP1, and Office Project 2003 SP3, does not properly handle memory allocation for Project files, which allows remote attackers to execute arbitrary code via a malformed file, aka "Project Memory Validation Vulnerability."
21271| [CVE-2009-0100] Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1
21272| [CVE-2009-0099] The Electronic Messaging System Microsoft Data Base (EMSMDB32) provider in Microsoft Exchange 2000 Server SP3 and Exchange Server 2003 SP2, as used in Exchange System Attendant, allows remote attackers to cause a denial of service (application outage) via a malformed MAPI command, aka "Literal Processing Vulnerability."
21273| [CVE-2009-0098] Microsoft Exchange 2000 Server SP3, Exchange Server 2003 SP2, and Exchange Server 2007 SP1 do not properly interpret Transport Neutral Encapsulation (TNEF) properties, which allows remote attackers to execute arbitrary code via a crafted TNEF message, aka "Memory Corruption Vulnerability."
21274| [CVE-2009-0097] Microsoft Office Visio 2002 SP2 and 2003 SP3 does not properly validate memory allocation for Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Memory Corruption Vulnerability."
21275| [CVE-2009-0096] Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 does not properly perform memory copy operations for object data, which allows remote attackers to execute arbitrary code via a crafted Visio document, aka "Memory Corruption Vulnerability."
21276| [CVE-2009-0095] Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 does not properly validate object data in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Memory Validation Vulnerability."
21277| [CVE-2009-0094] The WINS server in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 does not restrict registration of the (1) "wpad" and (2) "isatap" NetBIOS names, which allows remote authenticated users to hijack the Web Proxy Auto-Discovery (WPAD) and Intra-Site Automatic Tunnel Addressing Protocol (ISATAP) features, and conduct man-in-the-middle attacks by spoofing a proxy server or ISATAP route, by registering one of these names in the WINS database, aka "WPAD WINS Server Registration Vulnerability," a related issue to CVE-2007-1692.
21278| [CVE-2009-0093] Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not restrict registration of the "wpad" hostname, which allows remote authenticated users to hijack the Web Proxy Auto-Discovery (WPAD) feature, and conduct man-in-the-middle attacks by spoofing a proxy server, via a Dynamic Update request for this hostname, aka "DNS Server Vulnerability in WPAD Registration Vulnerability," a related issue to CVE-2007-1692.
21279| [CVE-2009-0091] Microsoft .NET Framework 2.0, 2.0 SP1, and 3.5 does not properly enforce a certain type-equality constraint in .NET verifiable code, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft .NET Framework Type Verification Vulnerability."
21280| [CVE-2009-0090] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, and 2.0 SP1 does not properly validate .NET verifiable code, which allows remote attackers to obtain unintended access to stack memory, and execute arbitrary code, via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft .NET Framework Pointer Verification Vulnerability."
21281| [CVE-2009-0089] Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Vista Gold allows remote web servers to impersonate arbitrary https web sites by using DNS spoofing to "forward a connection" to a different https web site that has a valid certificate matching its own domain name, but not a certificate matching the domain name of the host requested by the user, aka "Windows HTTP Services Certificate Name Mismatch Vulnerability."
21282| [CVE-2009-0088] The WordPerfect 6.x Converter (WPFT632.CNV, 1998.1.27.0) in Microsoft Office Word 2000 SP3 and Microsoft Office Converter Pack does not properly validate the length of an unspecified string, which allows remote attackers to execute arbitrary code via a crafted WordPerfect 6.x file, related to an unspecified counter and control structures on the stack, aka "Word 2000 WordPerfect 6.x Converter Stack Corruption Vulnerability."
21283| [CVE-2009-0087] Unspecified vulnerability in the Word 6 text converter in WordPad in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2
21284| [CVE-2009-0086] Integer underflow in Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote HTTP servers to execute arbitrary code via crafted parameter values in a response, related to error handling, aka "Windows HTTP Services Integer Underflow Vulnerability."
21285| [CVE-2009-0085] The Secure Channel (aka SChannel) authentication component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008, when certificate authentication is used, does not properly validate the client's key exchange data in Transport Layer Security (TLS) handshake messages, which allows remote attackers to spoof authentication by crafting a TLS packet based on knowledge of the certificate but not the private key, aka "SChannel Spoofing Vulnerability."
21286| [CVE-2009-0083] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 does not properly handle invalid pointers, which allows local users to gain privileges via an application that triggers use of a crafted pointer, aka "Windows Kernel Invalid Pointer Vulnerability."
21287| [CVE-2009-0082] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate handles, which allows local users to gain privileges via a crafted application that triggers unspecified "actions," aka "Windows Kernel Handle Validation Vulnerability."
21288| [CVE-2009-0081] The graphics device interface (GDI) implementation in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate input received from user mode, which allows remote attackers to execute arbitrary code via a crafted (1) Windows Metafile (aka WMF) or (2) Enhanced Metafile (aka EMF) image file, aka "Windows Kernel Input Validation Vulnerability."
21289| [CVE-2009-0079] The RPCSS service in Microsoft Windows XP SP2 and SP3 and Server 2003 SP1 and SP2 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by accessing the resources of one of the processes, aka "Windows RPCSS Service Isolation Vulnerability."
21290| [CVE-2009-0078] The Windows Management Instrumentation (WMI) provider in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by accessing the resources of one of the processes, aka "Windows WMI Service Isolation Vulnerability."
21291| [CVE-2008-7217] Microsoft Office 2008 for Mac, when running on Macintosh systems that restrict Office access to administrators, does not enforce this restriction for user ID 502, which allows local users with that ID to bypass intended security policy and access Office programs, related to permissions and ownership for certain directories.
21292| [CVE-2008-6819] win32k.sys in Microsoft Windows Server 2003 and Vista allows local users to cause a denial of service (system crash) via vectors related to CreateWindow, TranslateMessage, and DispatchMessage, possibly a race condition between threads, a different vulnerability than CVE-2008-1084. NOTE: some of these details are obtained from third party information.
21293| [CVE-2008-6219] nsrexecd.exe in multiple EMC Networker products including EMC NetWorker Server, Storage Node, and Client 7.3.x and 7.4, 7.4.1, 7.4.2, Client and Storage Node for Open VMS 7.3.2 ECO6 and earlier, Module for Microsoft Exchange 5.1 and earlier, Module for Microsoft Applications 2.0 and earlier, Module for Meditech 2.0 and earlier, and PowerSnap 2.4 SP1 and earlier does not properly control the allocation of memory, which allows remote attackers to cause a denial of service (memory exhaustion) via multiple crafted RPC requests.
21294| [CVE-2008-6063] Microsoft Word 2007, when the "Save as PDF" add-on is enabled, places an absolute pathname in the Subject field during an "Email as PDF" operation, which allows remote attackers to obtain sensitive information such as the sender's account name and a Temporary Internet Files subdirectory name.
21295| [CVE-2008-5912] An unspecified function in the JavaScript implementation in Microsoft Internet Explorer creates and exposes a "temporary footprint" when there is a current login to a web site, which makes it easier for remote attackers to trick a user into acting upon a spoofed pop-up message, aka an "in-session phishing attack." NOTE: as of 20090116, the only disclosure is a vague pre-advisory with no actionable information. However, because it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.
21296| [CVE-2008-5823] An ActiveX control in prtstb06.dll in Microsoft Money 2006, when used with WScript in Windows Script Host (WSH) on Windows Vista, allows remote attackers to cause a denial of service (access violation and application crash) via a zero value for the Startup property.
21297| [CVE-2008-5416] Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier
21298| [CVE-2008-5232] Buffer overflow in the CallHTMLHelp method in the Microsoft Windows Media Services ActiveX control in nskey.dll 4.1.00.3917 in Windows Media Services on Microsoft Windows NT and 2000, and Avaya Media and Message Application servers, allows remote attackers to execute arbitrary code via a long argument. NOTE: the provenance of this information is unknown
21299| [CVE-2008-5112] The LDAP server in Active Directory in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 responds differently to a failed bind attempt depending on whether the user account exists and is permitted to login, which allows remote attackers to enumerate valid usernames via a series of LDAP bind requests, as demonstrated by ldapuserenum.
21300| [CVE-2008-5100] The strong name (SN) implementation in Microsoft .NET Framework 2.0.50727 relies on the digital signature Public Key Token embedded in the pathname of a DLL file instead of the digital signature of this file itself, which makes it easier for attackers to bypass Global Assembly Cache (GAC) and Code Access Security (CAS) protection mechanisms, aka MSRC ticket MSRC8566gs.
21301| [CVE-2008-5044] Race condition in Microsoft Windows Server 2003 and Vista allows local users to cause a denial of service (crash or hang) via a multi-threaded application that makes many calls to UnhookWindowsHookEx while certain other desktop activity is occurring.
21302| [CVE-2008-4844] Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via DSO bindings involving (1) an XML Island, (2) XML DSOs, or (3) Tabular Data Control (TDC) in a crafted HTML or XML document, as demonstrated by nested SPAN or MARQUEE elements, and exploited in the wild in December 2008.
21303| [CVE-2008-4841] The WordPad Text Converter for Word 97 files in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf Word 97 file that triggers memory corruption, as exploited in the wild in December 2008. NOTE: As of 20081210, it is unclear whether this vulnerability is related to a WordPad issue disclosed on 20080925 with a 2008-crash.doc.rar example, but there are insufficient details to be sure.
21304| [CVE-2008-4837] Stack-based buffer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
21305| [CVE-2008-4835] SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside the SMB packets" in an NT Trans2 request, related to "insufficiently validating the buffer size," aka "SMB Validation Remote Code Execution Vulnerability."
21306| [CVE-2008-4834] Buffer overflow in SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside the SMB packets" in an NT Trans request, aka "SMB Buffer Overflow Remote Code Execution Vulnerability."
21307| [CVE-2008-4493] Microsoft PicturePusher ActiveX control (PipPPush.DLL 7.00.0709), as used in Microsoft Digital Image 2006 Starter Edition, allows remote attackers to force the upload of arbitrary files by using the AddString and Post methods and a modified PostURL to construct an HTTP POST request. NOTE: this issue might only be exploitable in limited environments or non-default browser settings.
21308| [CVE-2008-4295] Microsoft Windows Mobile 6.0 on HTC Wiza 200 and HTC MDA 8125 devices does not properly handle the first attempt to establish a Bluetooth connection to a peer with a long name, which allows remote attackers to cause a denial of service (device reboot) by configuring a Bluetooth device with a long hci name and (1) connecting directly to the Windows Mobile system or (2) waiting for the Windows Mobile system to scan for nearby devices.
21309| [CVE-2008-4269] The search-ms protocol handler in Windows Explorer in Microsoft Windows Vista Gold and SP1 and Server 2008 uses untrusted parameter data obtained from incorrect parsing, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "Windows Search Parsing Vulnerability."
21310| [CVE-2008-4268] The Windows Search component in Microsoft Windows Vista Gold and SP1 and Server 2008 does not properly free memory during a save operation for a Windows Search file, which allows remote attackers to execute arbitrary code via a crafted saved-search file, aka "Windows Saved Search Vulnerability."
21311| [CVE-2008-4266] Array index vulnerability in Microsoft Office Excel 2000 SP3, 2002 SP3, and 2003 SP3
21312| [CVE-2008-4265] Microsoft Office Excel 2000 SP3 allows remote attackers to execute arbitrary code via a crafted Excel spreadsheet that contains a malformed object, which triggers memory corruption during the loading of records from this spreadsheet, aka "File Format Parsing Vulnerability."
21313| [CVE-2008-4264] Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
21314| [CVE-2008-4261] Stack-based buffer overflow in Microsoft Internet Explorer 5.01 SP4, 6 SP1 on Windows 2000, and 6 on Windows XP and Server 2003 does not properly handle extraneous data associated with an object embedded in a web page, which allows remote attackers to execute arbitrary code via crafted HTML tags that trigger memory corruption, aka "HTML Rendering Memory Corruption Vulnerability."
21315| [CVE-2008-4256] The Charts ActiveX control in Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the "system state," aka "Charts Control Memory Corruption Vulnerability."
21316| [CVE-2008-4255] Heap-based buffer overflow in mscomct2.ocx (aka Windows Common ActiveX control or Microsoft Animation ActiveX control) in Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2, and Office Project 2003 SP3 and 2007 Gold and SP1 allows remote attackers to execute arbitrary code via an AVI file with a crafted stream length, which triggers an "allocation error" and memory corruption, aka "Windows Common AVI Parsing Overflow Vulnerability."
21317| [CVE-2008-4253] The FlexGrid ActiveX control in Microsoft Visual Basic 6.0, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2, Office FrontPage 2002 SP3, and Office Project 2003 SP3 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the "system state," aka "FlexGrid Control Memory Corruption Vulnerability."
21318| [CVE-2008-4250] The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by Gimmiv.A in October 2008, aka "Server Service Vulnerability."
21319| [CVE-2008-4114] srv.sys in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via an SMB WRITE_ANDX packet with an offset that is inconsistent with the packet size, related to "insufficiently validating the buffer size," as demonstrated by a request to the \PIPE\lsarpc named pipe, aka "SMB Validation Denial of Service Vulnerability."
21320| [CVE-2008-4110] Buffer overflow in the SQLVDIRLib.SQLVDirControl ActiveX control in Tools\Binn\sqlvdir.dll in Microsoft SQL Server 2000 (aka SQL Server 8.0) allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a long URL in the second argument to the Connect method. NOTE: this issue is not a vulnerability in many environments, since the control is not marked as safe for scripting and would not execute with default Internet Explorer settings.
21321| [CVE-2008-4038] Buffer underflow in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via a Server Message Block (SMB) request that contains a filename with a crafted length, aka "SMB Buffer Underflow Vulnerability."
21322| [CVE-2008-4037] Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote SMB servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user, as demonstrated by backrush, aka "SMB Credential Reflection Vulnerability." NOTE: some reliable sources report that this vulnerability exists because of an insufficient fix for CVE-2000-0834.
21323| [CVE-2008-4036] Integer overflow in Memory Manager in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows local users to gain privileges via a crafted application that triggers an erroneous decrement of a variable, related to validation of parameters for Virtual Address Descriptors (VADs) and a "memory allocation mapping error," aka "Virtual Address Descriptor Elevation of Privilege Vulnerability."
21324| [CVE-2008-4032] Microsoft Office SharePoint Server 2007 Gold and SP1 and Microsoft Search Server 2008 do not properly perform authentication and authorization for administrative functions, which allows remote attackers to cause a denial of service (server load), obtain sensitive information, and "create scripts that would run in the context of the site" via requests to administrative URIs, aka "Access Control Vulnerability."
21325| [CVE-2008-4031] Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
21326| [CVE-2008-4030] Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
21327| [CVE-2008-4028] Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
21328| [CVE-2008-4027] Double free vulnerability in Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
21329| [CVE-2008-4026] Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
21330| [CVE-2008-4025] Integer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
21331| [CVE-2008-4024] Microsoft Office Word 2000 SP3 and 2002 SP3 and Office 2004 for Mac allow remote attackers to execute arbitrary code via a Word document with a crafted lcbPlcfBkfSdt field in the File Information Block (FIB), which bypasses an initialization step and triggers an "arbitrary free," aka "Word Memory Corruption Vulnerability."
21332| [CVE-2008-4023] Active Directory in Microsoft Windows 2000 SP4 does not properly allocate memory for (1) LDAP and (2) LDAPS requests, which allows remote attackers to execute arbitrary code via a crafted request, aka "Active Directory Overflow Vulnerability."
21333| [CVE-2008-4019] Integer overflow in the REPT function in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1
21334| [CVE-2008-3956] orgchart.exe in Microsoft Organization Chart 2.00 allows user-assisted attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted .opx file.
21335| [CVE-2008-3704] Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions before 6.0.84.18, in Microsoft Visual Studio 6.0, Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 allows remote attackers to execute arbitrary code via a long Mask parameter, related to not "validating property values with boundary checks," as exploited in the wild in August 2008, aka "Masked Edit Control Memory Corruption Vulnerability."
21336| [CVE-2008-3648] nslookup.exe in Microsoft Windows XP SP2 allows user-assisted remote attackers to execute arbitrary code, as demonstrated by an attempted DNS zone transfer, and as exploited in the wild in August 2008.
21337| [CVE-2008-3636] Integer overflow in the IopfCompleteRequest API in the kernel in Microsoft Windows 2000, XP, Server 2003, and Vista allows context-dependent attackers to gain privileges. NOTE: this issue was originally reported for GEARAspiWDM.sys 2.0.7.5 in Gear Software CD DVD Filter driver before 4.001.7, as used in other products including Apple iTunes and multiple Symantec and Norton products, which allows local users to gain privileges via repeated IoAttachDevice IOCTL calls to \\.\GEARAspiWDMDevice in this GEARAspiWDM.sys. However, the root cause is the integer overflow in the API call itself.
21338| [CVE-2008-3479] Heap-based buffer overflow in the Microsoft Message Queuing (MSMQ) service (mqsvc.exe) in Microsoft Windows 2000 SP4 allows remote attackers to read memory contents and execute arbitrary code via a crafted RPC call, related to improper processing of parameters to string APIs, aka "Message Queuing Service Remote Code Execution Vulnerability."
21339| [CVE-2008-3477] Microsoft Excel 2000 SP3, 2002 SP3, and 2003 SP2 and SP3 does not properly validate data in the VBA Performance Cache when processing an Office document with an embedded object, which allows remote attackers to execute arbitrary code via an Excel file containing a crafted value, leading to heap-based buffer overflows, integer overflows, array index errors, and memory corruption, aka "Calendar Object Validation Vulnerability."
21340| [CVE-2008-3471] Stack-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1
21341| [CVE-2008-3466] Microsoft Host Integration Server (HIS) 2000, 2004, and 2006 does not limit RPC access to administrative functions, which allows remote attackers to bypass authentication and execute arbitrary programs via a crafted SNA RPC message using opcode 1 or 6 to call the CreateProcess function, aka "HIS Command Execution Vulnerability."
21342| [CVE-2008-3465] Heap-based buffer overflow in an API in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows context-dependent attackers to cause a denial of service or execute arbitrary code via a WMF file with a malformed file-size parameter, which would not be properly handled by a third-party application that uses this API for a copy operation, aka "GDI Heap Overflow Vulnerability."
21343| [CVE-2008-3464] afd.sys in the Ancillary Function Driver (AFD) component in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP1 and SP2 does not properly validate input sent from user mode to the kernel, which allows local users to gain privileges via a crafted application, as demonstrated using crafted pointers and lengths that bypass intended ProbeForRead and ProbeForWrite restrictions, aka "AFD Kernel Overwrite Vulnerability."
21344| [CVE-2008-3460] WPGIMP32.FLT in Microsoft Office 2000 SP3, XP SP3, and 2003 SP2
21345| [CVE-2008-3068] Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times and IP addresses of recipients, and port-scan results, via a crafted certificate with an Authority Information Access (AIA) extension.
21346| [CVE-2008-3021] Microsoft Office 2000 SP3, XP SP3, and 2003 SP2
21347| [CVE-2008-3020] Microsoft Office 2000 SP3 and XP SP3
21348| [CVE-2008-3019] Microsoft Office 2000 SP3, XP SP3, and 2003 SP2
21349| [CVE-2008-3018] Microsoft Office 2000 SP3, XP SP3, and 2003 SP2
21350| [CVE-2008-3015] Integer overflow in gdiplus.dll in GDI+ in Microsoft Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a BMP image file with a malformed BitMapInfoHeader that triggers a buffer overflow, aka "GDI+ BMP Integer Overflow Vulnerability."
21351| [CVE-2008-3014] Buffer overflow in gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a malformed WMF image file that triggers improper memory allocation, aka "GDI+ WMF Buffer Overrun Vulnerability."
21352| [CVE-2008-3013] gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a malformed GIF image file containing many extension markers for graphic control extensions and subsequent unknown labels, aka "GDI+ GIF Parsing Vulnerability."
21353| [CVE-2008-3012] gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 does not properly perform memory allocation, which allows remote attackers to execute arbitrary code via a malformed EMF image file, aka "GDI+ EMF Memory Corruption Vulnerability."
21354| [CVE-2008-3009] Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1, 9, and 2008 do not properly use the Service Principal Name (SPN) identifier when validating replies to authentication requests, which allows remote servers to execute arbitrary code via vectors that employ NTLM credential reflection, aka "SPN Vulnerability."
21355| [CVE-2008-3007] Argument injection vulnerability in a URI handler in Microsoft Office XP SP3, 2003 SP2 and SP3, 2007 Office System Gold and SP1, and Office OneNote 2007 Gold and SP1 allow remote attackers to execute arbitrary code via a crafted onenote:// URL, aka "Uniform Resource Locator Validation Error Vulnerability."
21356| [CVE-2008-3006] Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1
21357| [CVE-2008-3005] Array index vulnerability in Microsoft Office Excel 2000 SP3 and 2002 SP3, and Office 2004 and 2008 for Mac allows remote attackers to execute arbitrary code via an Excel file with a crafted array index for a FORMAT record, aka the "Excel Index Array Vulnerability."
21358| [CVE-2008-3004] Microsoft Office Excel 2000 SP3, 2002 SP3, and 2003 SP2 and SP3
21359| [CVE-2008-3003] Microsoft Office Excel 2007 Gold and SP1 does not properly delete the PWD (password) string from connections.xml when a .xlsx file is configured not to save the remote data session password, which allows local users to obtain sensitive information and obtain access to a remote data source, aka the "Excel Credential Caching Vulnerability."
21360| [CVE-2008-2752] Microsoft Word 2000 9.0.2812 and 2003 11.8106.8172 does not properly handle unordered lists, which allows user-assisted remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .doc file. NOTE: some of these details are obtained from third party information.
21361| [CVE-2008-2540] Apple Safari on Mac OS X, and before 3.1.2 on Windows, does not prompt the user before downloading an object that has an unrecognized content type, which allows remote attackers to place malware into the (1) Desktop directory on Windows or (2) Downloads directory on Mac OS X, and subsequently allows remote attackers to execute arbitrary code on Windows by leveraging an untrusted search path vulnerability in (a) Internet Explorer 7 on Windows XP or (b) the SearchPath function in Windows XP, Vista, and Server 2003 and 2008, aka a "Carpet Bomb" and a "Blended Threat Elevation of Privilege Vulnerability," a different issue than CVE-2008-1032. NOTE: Apple considers this a vulnerability only because the Microsoft products can load application libraries from the desktop and, as of 20080619, has not covered the issue in an advisory for Mac OS X.
21362| [CVE-2008-2463] The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snapshot Viewer and Microsoft Office Access 2000 through 2003, allows remote attackers to download arbitrary files to a client machine via a crafted HTML document or e-mail message, probably involving use of the SnapshotPath and CompressedPath properties and the PrintSnapshot method. NOTE: this can be leveraged for code execution by writing to a Startup folder.
21363| [CVE-2008-2252] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate parameters sent from user mode to the kernel, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Corruption Vulnerability."
21364| [CVE-2008-2251] Double free vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows local users to gain privileges via a crafted application that makes system calls within multiple threads, aka "Windows Kernel Unhandled Exception Vulnerability." NOTE: according to Microsoft, this is not a duplicate of CVE-2008-4510.
21365| [CVE-2008-2250] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate window properties sent from a parent window to a child window during creation of a new window, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Window Creation Vulnerability."
21366| [CVE-2008-2249] Integer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via a malformed header in a crafted WMF file, which triggers a buffer overflow, aka "GDI Integer Overflow Vulnerability."
21367| [CVE-2008-2246] Microsoft Windows Vista through SP1 and Server 2008 do not properly import the default IPsec policy from a Windows Server 2003 domain to a Windows Server 2008 domain, which prevents IPsec rules from being enforced and allows remote attackers to bypass intended access restrictions.
21368| [CVE-2008-2245] Heap-based buffer overflow in the InternalOpenColorProfile function in mscms.dll in Microsoft Windows Image Color Management System (MSCMS) in the Image Color Management (ICM) component on Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted image file.
21369| [CVE-2008-2244] Microsoft Office Word 2002 SP3 allows remote attackers to execute arbitrary code via a .doc file that contains malformed data, as exploited in the wild in July 2008, and as demonstrated by attachement.doc.
21370| [CVE-2008-1898] A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and 2007, allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via an invalid WksPictureInterface property value, which triggers an improper function call.
21371| [CVE-2008-1888] Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 2.0 allows remote attackers to inject arbitrary web script or HTML via the Picture Source (aka picture object source) field in the Rich Text Editor.
21372| [CVE-2008-1547] Open redirect vulnerability in exchweb/bin/redir.asp in Microsoft Outlook Web Access (OWA) for Exchange Server 2003 SP2 (aka build 6.5.7638) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the URL parameter.
21373| [CVE-2008-1457] The Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate per-user subscriptions, which allows remote authenticated users to execute arbitrary code via a crafted event subscription request.
21374| [CVE-2008-1456] Array index vulnerability in the Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote authenticated users to execute arbitrary code via a crafted event subscription request that is used to access an array of function pointers.
21375| [CVE-2008-1455] A "memory calculation error" in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, 2003 SP2, and 2007 through SP1
21376| [CVE-2008-1454] Unspecified vulnerability in Microsoft DNS in Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008 allows remote attackers to conduct cache poisoning attacks via unknown vectors related to accepting "records from a response that is outside the remote server's authority," aka "DNS Cache Poisoning Vulnerability," a different vulnerability than CVE-2008-1447.
21377| [CVE-2008-1451] The WINS service on Microsoft Windows 2000 SP4, and Server 2003 SP1 and SP2, does not properly validate data structures in WINS network packets, which allows local users to gain privileges via a crafted packet, aka "Memory Overwrite Vulnerability."
21378| [CVE-2008-1446] Integer overflow in the Internet Printing Protocol (IPP) ISAPI extension in Microsoft Internet Information Services (IIS) 5.0 through 7.0 on Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to execute arbitrary code via an HTTP POST request that triggers an outbound IPP connection from a web server to a machine operated by the attacker, aka "Integer Overflow in IPP Service Vulnerability."
21379| [CVE-2008-1445] Active Directory on Microsoft Windows 2000 Server SP4, XP Professional SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to cause a denial of service (system hang or reboot) via a crafted LDAP request.
21380| [CVE-2008-1444] Stack-based buffer overflow in Microsoft DirectX 7.0 and 8.1 on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a Synchronized Accessible Media Interchange (SAMI) file with crafted parameters for a Class Name variable, aka the "SAMI Format Parsing Vulnerability."
21381| [CVE-2008-1441] Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to cause a denial of service (system hang) via a series of Pragmatic General Multicast (PGM) packets with invalid fragment options, aka the "PGM Malformed Fragment Vulnerability."
21382| [CVE-2008-1440] Microsoft Windows XP SP2 and SP3, and Server 2003 SP1 and SP2, does not properly validate the option length field in Pragmatic General Multicast (PGM) packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted PGM packet, aka the "PGM Invalid Length Vulnerability."
21383| [CVE-2008-1436] Microsoft Windows XP Professional SP2, Vista, and Server 2003 and 2008 does not properly assign activities to the (1) NetworkService and (2) LocalService accounts, which might allow context-dependent attackers to gain privileges by using one service process to capture a resource from a second service process that has a LocalSystem privilege-escalation ability, related to improper management of the SeImpersonatePrivilege user right, as originally reported for Internet Information Services (IIS), aka Token Kidnapping.
21384| [CVE-2008-1435] Windows Explorer in Microsoft Windows Vista up to SP1, and Server 2008, allows user-assisted remote attackers to execute arbitrary code via crafted saved-search (.search-ms) files that are not properly handled when saving, aka "Windows Saved Search Vulnerability."
21385| [CVE-2008-1434] Use-after-free vulnerability in Microsoft Word in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 Office System SP1 and earlier allows remote attackers to execute arbitrary code via an HTML document with a large number of Cascading Style Sheets (CSS) selectors, related to a "memory handling error" that triggers memory corruption.
21386| [CVE-2008-1092] Buffer overflow in msjet40.dll before 4.0.9505.0 in Microsoft Jet Database Engine allows remote attackers to execute arbitrary code via a crafted Word file, as exploited in the wild in March 2008. NOTE: as of 20080513, Microsoft has stated that this is the same issue as CVE-2007-6026.
21387| [CVE-2008-1091] Unspecified vulnerability in Microsoft Word in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 Office System SP1 and earlier allows remote attackers to execute arbitrary code via a Rich Text Format (.rtf) file with a malformed string that triggers a "memory calculation error" and a heap-based buffer overflow, aka "Object Parsing Vulnerability."
21388| [CVE-2008-1090] Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows user-assisted remote attackers to execute arbitrary code via a crafted .DXF file, aka "Visio Memory Validation Vulnerability."
21389| [CVE-2008-1089] Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows user-assisted remote attackers to execute arbitrary code via a Visio file containing crafted object header data, aka "Visio Object Header Vulnerability."
21390| [CVE-2008-1088] Microsoft Project 2000 Service Release 1, 2002 SP1, and 2003 SP2 allows user-assisted remote attackers to execute arbitrary code via a crafted Project file, related to improper validation of "memory resource allocations."
21391| [CVE-2008-1087] Stack-based buffer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to execute arbitrary code via an EMF image file with crafted filename parameters, aka "GDI Stack Overflow Vulnerability."
21392| [CVE-2008-1086] The HxTocCtrl ActiveX control (hxvz.dll), as used in Microsoft Internet Explorer 5.01 SP4 and 6 SP1, in Windows XP SP2, Server 2003 SP1 and SP2, Vista SP1, and Server 2008, allows remote attackers to execute arbitrary code via malformed arguments, which triggers memory corruption.
21393| [CVE-2008-1084] Unspecified vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, through Vista SP1, and Server 2008 allows local users to execute arbitrary code via unknown vectors related to improper input validation. NOTE: it was later reported that one affected function is NtUserFnOUTSTRING in win32k.sys.
21394| [CVE-2008-1083] Heap-based buffer overflow in the CreateDIBPatternBrushPt function in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to execute arbitrary code via an EMF or WMF image file with a malformed header that triggers an integer overflow, aka "GDI Heap Overflow Vulnerability."
21395| [CVE-2008-0121] A "memory calculation error" in Microsoft PowerPoint Viewer 2003 allows remote attackers to execute arbitrary code via a PowerPoint file with an invalid picture index that triggers memory corruption, aka "Memory Calculation Vulnerability."
21396| [CVE-2008-0120] Integer overflow in Microsoft PowerPoint Viewer 2003 allows remote attackers to execute arbitrary code via a PowerPoint file with a malformed picture index that triggers memory corruption, related to handling of CString objects, aka "Memory Allocation Vulnerability."
21397| [CVE-2008-0119] Unspecified vulnerability in Microsoft Publisher in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 SP1 and earlier allows remote attackers to execute arbitrary code via a Publisher file with crafted object header data that triggers memory corruption, aka "Publisher Object Handler Validation Vulnerability."
21398| [CVE-2008-0118] Unspecified vulnerability in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, Excel Viewer 2003 up to SP3, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption from an "allocation error," aka "Microsoft Office Memory Corruption Vulnerability."
21399| [CVE-2008-0117] Unspecified vulnerability in Microsoft Excel 2000 SP3 and 2002 SP2, and Office 2004 and 2008 for Mac, allows user-assisted remote attackers to execute arbitrary code via crafted conditional formatting values, aka "Excel Conditional Formatting Vulnerability."
21400| [CVE-2008-0116] Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, Compatibility Pack, and Office 2004 and 2008 for Mac allows user-assisted remote attackers to execute arbitrary code via malformed tags in rich text, aka "Excel Rich Text Validation Vulnerability."
21401| [CVE-2008-0115] Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2007, Viewer 2003, Compatibility Pack, and Office for Mac 2004 allows user-assisted remote attackers to execute arbitrary code via malformed formulas, aka "Excel Formula Parsing Vulnerability."
21402| [CVE-2008-0114] Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office for Mac 2004 allows user-assisted remote attackers to execute arbitrary code via crafted Style records that trigger memory corruption.
21403| [CVE-2008-0113] Unspecified vulnerability in Microsoft Office Excel Viewer 2003 up to SP3 allows user-assisted remote attackers to execute arbitrary code via an Excel document with malformed cell comments that trigger memory corruption from an "allocation error," aka "Microsoft Office Cell Parsing Memory Corruption Vulnerability."
21404| [CVE-2008-0112] Unspecified vulnerability in Microsoft Excel 2000 SP3, and Office for Mac 2004 and 2008 allows user-assisted remote attackers to execute arbitrary code via a crafted .SLK file that is not properly handled when importing the file, aka "Excel File Import Vulnerability."
21405| [CVE-2008-0111] Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2007, Viewer 2003, Compatibility Pack, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted data validation records, aka "Excel Data Validation Record Vulnerability."
21406| [CVE-2008-0110] Unspecified vulnerability in Microsoft Outlook in Office 2000 SP3, XP SP3, 2003 SP2 and Sp3, and Office System allows user-assisted remote attackers to execute arbitrary code via a crafted mailto URI.
21407| [CVE-2008-0109] Word in Microsoft Office 2000 SP3, XP SP3, Office 2003 SP2, and Office Word Viewer 2003 allows remote attackers to execute arbitrary code via crafted fields within the File Information Block (FIB) of a Word file, which triggers length calculation errors and memory corruption.
21408| [CVE-2008-0108] Stack-based buffer overflow in wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted field lengths, aka "Microsoft Works File Converter Field Length Vulnerability."
21409| [CVE-2008-0106] Buffer overflow in Microsoft SQL Server 2005 SP1 and SP2, and 2005 Express Edition SP1 and SP2, allows remote authenticated users to execute arbitrary code via a crafted insert statement.
21410| [CVE-2008-0105] Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section header index table information, aka "Microsoft Works File Converter Index Table Vulnerability."
21411| [CVE-2008-0104] Unspecified vulnerability in Microsoft Office Publisher 2000, 2002, and 2003 SP2 allows remote attackers to execute arbitrary code via a crafted .pub file, aka "Publisher Memory Corruption Vulnerability."
21412| [CVE-2008-0103] Unspecified vulnerability in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Office document that contains a malformed object, related to a "memory handling error," aka "Microsoft Office Execution Jump Vulnerability."
21413| [CVE-2008-0102] Unspecified vulnerability in Microsoft Office Publisher 2000, 2002, and 2003 SP2 allows remote attackers to execute arbitrary code via a crafted .pub file, related to invalid "memory values," aka "Publisher Invalid Memory Reference Vulnerability."
21414| [CVE-2008-0088] Unspecified vulnerability in Active Directory on Microsoft Windows 2000 and Windows Server 2003, and Active Directory Application Mode (ADAM) on XP and Server 2003, allows remote attackers to cause a denial of service (hang and restart) via a crafted LDAP request.
21415| [CVE-2008-0087] The DNS client in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, and Vista uses predictable DNS transaction IDs, which allows remote attackers to spoof DNS responses.
21416| [CVE-2008-0086] Buffer overflow in the convert function in Microsoft SQL Server 2000 SP4, 2000 Desktop Engine (MSDE 2000) SP4, and 2000 Desktop Engine (WMSDE) allows remote authenticated users to execute arbitrary code via a crafted SQL expression.
21417| [CVE-2008-0083] The (1) VBScript (VBScript.dll) and (2) JScript (JScript.dll) scripting engines 5.1 and 5.6, as used in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2, do not properly decode script, which allows remote attackers to execute arbitrary code via unknown vectors.
21418| [CVE-2008-0081] Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted macros, aka "Macro Validation Vulnerability," a different vulnerability than CVE-2007-3490.
21419| [CVE-2008-0080] Heap-based buffer overflow in the WebDAV Mini-Redirector in Microsoft Windows XP SP2, Server 2003 SP1 and SP2, and Vista allows remote attackers to execute arbitrary code via a crafted WebDAV response.
21420| [CVE-2008-0020] Unspecified vulnerability in the Load method in the IPersistStreamInit interface in the Active Template Library (ATL), as used in the Microsoft Video ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via unknown vectors that trigger memory corruption, aka "ATL Header Memcopy Vulnerability," a different vulnerability than CVE-2008-0015.
21421| [CVE-2008-0015] Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted web page, as exploited in the wild in July 2009, aka "Microsoft Video ActiveX Control Vulnerability."
21422| [CVE-2008-0011] Microsoft DirectX 8.1 through 9.0c, and DirectX on Microsoft XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008, does not properly perform MJPEG error checking, which allows remote attackers to execute arbitrary code via a crafted MJPEG stream in a (1) AVI or (2) ASF file, aka the "MJPEG Decoder Vulnerability."
21423| [CVE-2007-6753] Untrusted search path vulnerability in Shell32.dll in Microsoft Windows 2000, Windows XP, Windows Vista, Windows Server 2008, and Windows 7, when using an environment configured with a string such as %APPDATA% or %PROGRAMFILES% in a certain way, allows local users to gain privileges via a Trojan horse DLL under the current working directory, as demonstrated by iTunes and Safari.
21424| [CVE-2007-6357] Stack-based buffer overflow in Microsoft Office Access allows remote, user-assisted attackers to execute arbitrary code via a crafted Microsoft Access Database (.mdb) file. NOTE: due to the lack of details as of 20071210, it is not clear whether this issue is the same as CVE-2007-6026 or CVE-2005-0944.
21425| [CVE-2007-6329] Microsoft Office 2007 12.0.6015.5000 and MSO 12.0.6017.5000 do not sign the metadata of Office Open XML (OOXML) documents, which makes it easier for remote attackers to modify Dublin Core metadata fields, as demonstrated by the (1) LastModifiedBy and (2) creator fields in docProps/core.xml in the OOXML ZIP container.
21426| [CVE-2007-6043] The CryptGenRandom function in Microsoft Windows 2000 generates predictable values, which makes it easier for context-dependent attackers to reduce the effectiveness of cryptographic mechanisms, as demonstrated by attacks on (1) forward security and (2) backward security, related to use of eight instances of the RC4 cipher, and possibly a related issue to CVE-2007-3898.
21427| [CVE-2007-6026] Stack-based buffer overflow in Microsoft msjet40.dll 4.0.8618.0 (aka Microsoft Jet Engine), as used by Access 2003 in Microsoft Office 2003 SP3, allows user-assisted attackers to execute arbitrary code via a crafted MDB file database file containing a column structure with a modified column count. NOTE: this might be the same issue as CVE-2005-0944.
21428| [CVE-2007-5587] Buffer overflow in Macrovision SafeDisc secdrv.sys before 4.3.86.0, as shipped in Microsoft Windows XP SP2, XP Professional x64 and x64 SP2, Server 2003 SP1 and SP2, and Server 2003 x64 and x64 SP2 allows local users to overwrite arbitrary memory locations and gain privileges via a crafted argument to a METHOD_NEITHER IOCTL, as originally discovered in the wild.
21429| [CVE-2007-5352] Unspecified vulnerability in Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows local users to gain privileges via a crafted local procedure call (LPC) request.
21430| [CVE-2007-5348] Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via an image file with crafted gradient sizes in gradient fill input, which triggers a heap-based buffer overflow related to GdiPlus.dll and VGX.DLL, aka "GDI+ VML Buffer Overrun Vulnerability."
21431| [CVE-2007-4991] The SOCKS4 Proxy in Microsoft Internet Security and Acceleration (ISA) Server 2004 SP1 and SP2 allows remote attackers to obtain potentially sensitive information (the destination IP address of another user's session) via an empty packet.
21432| [CVE-2007-4916] Heap-based buffer overflow in the FileFind::FindFile method in (1) MFC42.dll, (2) MFC42u.dll, (3) MFC71.dll, and (4) MFC71u.dll in Microsoft Foundation Class (MFC) Library 8.0, as used by the ListFiles method in hpqutil.dll 2.0.0.138 in Hewlett-Packard (HP) All-in-One and Photo & Imaging Gallery 1.1 and probably other products, allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long first argument.
21433| [CVE-2007-4814] Buffer overflow in the SQLServer ActiveX control in the Distributed Management Objects OLE DLL (sqldmo.dll) 2000.085.2004.00 in Microsoft SQL Server Enterprise Manager 8.05.2004 allows remote attackers to execute arbitrary code via a long second argument to the Start method.
21434| [CVE-2007-3930] Interpretation conflict between Microsoft Internet Explorer and DocuWiki before 2007-06-26b allows remote attackers to inject arbitrary JavaScript and conduct cross-site scripting (XSS) attacks when spellchecking UTF-8 encoded messages via the spell_utf8test function in lib/exe/spellcheck.php, which triggers HTML document identification and script execution by Internet Explorer even though the Content-Type header is text/plain.
21435| [CVE-2007-3924] Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Netscape installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a -chrome argument to the navigatorurl URI, which are inserted into the command line that is created when invoking netscape.exe, a related issue to CVE-2007-3670. NOTE: there has been debate about whether the issue is in Internet Explorer or Netscape. As of 20070713, it is CVE's opinion that IE appears to not properly delimit the URL argument when invoking Netscape
21436| [CVE-2007-3899] Unspecified vulnerability in Microsoft Word 2000 SP3, Word 2002 SP3, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a malformed string in a Word file, aka "Word Memory Corruption Vulnerability."
21437| [CVE-2007-3898] The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS servers, which allows remote attackers to spoof DNS replies, poison the DNS cache, and facilitate further attack vectors.
21438| [CVE-2007-3896] The URL handling in Shell32.dll in the Windows shell in Microsoft Windows XP and Server 2003, with Internet Explorer 7 installed, allows remote attackers to execute arbitrary programs via invalid "%" sequences in a mailto: or other URI handler, as demonstrated using mIRC, Outlook, Firefox, Adobe Reader, Skype, and other applications. NOTE: this issue might be related to other issues involving URL handlers in Windows systems, such as CVE-2007-3845. There also might be separate but closely related issues in the applications that are invoked by the handlers.
21439| [CVE-2007-3890] Microsoft Excel in Office 2000 SP3, Office XP SP3, Office 2003 SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via a Workspace with a certain index value that triggers memory corruption.
21440| [CVE-2007-3670] Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Firefox installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a (1) FirefoxURL or (2) FirefoxHTML URI, which are inserted into the command line that is created when invoking firefox.exe. NOTE: it has been debated as to whether the issue is in Internet Explorer or Firefox. As of 20070711, it is CVE's opinion that IE appears to be failing to properly delimit the URL argument when invoking Firefox, and this issue could arise with other protocol handlers in IE as well. However, Mozilla has stated that it will address the issue with a "defense in depth" fix that will "prevent IE from sending Firefox malicious data."
21441| [CVE-2007-3490] Unspecified vulnerability in Microsoft Excel 2003 SP2 allows remote attackers to have an unknown impact via unspecified vectors, possibly related to the sheet name, as demonstrated by 2670.xls.
21442| [CVE-2007-3300] Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070619 allow remote attackers to bypass scanning via a crafted header in a (1) LHA or (2) RAR archive.
21443| [CVE-2007-3040] Stack-based buffer overflow in agentdpv.dll 2.0.0.3425 in Microsoft Agent on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a crafted URL to the Agent (Agent.Control) ActiveX control, which triggers an overflow within the Agent Service (agentsrv.exe) process, a different issue than CVE-2007-1205.
21444| [CVE-2007-3039] Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Windows 2000 Professional SP4, and Windows XP SP2 allows attackers to execute arbitrary code via a long string in an opnum 0x06 RPC call to port 2103. NOTE: this is remotely exploitable on Windows 2000 Server.
21445| [CVE-2007-3036] Unspecified vulnerability in the (1) Windows Services for UNIX 3.0 and 3.5, and (2) Subsystem for UNIX-based Applications in Microsoft Windows 2000, XP, Server 2003, and Vista allows local users to gain privileges via unspecified vectors related to "certain setuid binary files."
21446| [CVE-2007-3034] Integer overflow in the AttemptWrite function in Graphics Rendering Engine (GDI) on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted metafile (image) with a large record length value, which triggers a heap-based buffer overflow.
21447| [CVE-2007-3030] Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, and 2003 Viewer allows user-assisted remote attackers to execute arbitrary code via a malformed Excel file involving the "denoting [of] the start of a Workspace designation", which results in memory corruption, aka the "Workbook Memory Corruption Vulnerability".
21448| [CVE-2007-3029] Unspecified vulnerability in Microsoft Excel 2002 SP3 and 2003 SP2 allows user-assisted remote attackers to execute arbitrary code via a malformed Excel file containing multiple active worksheets, which results in memory corruption.
21449| [CVE-2007-3028] The LDAP service in Windows Active Directory in Microsoft Windows 2000 Server SP4 does not properly check "the number of convertible attributes", which allows remote attackers to cause a denial of service (service unavailability) via a crafted LDAP request, related to "client sent LDAP request logic," aka "Windows Active Directory Denial of Service Vulnerability". NOTE: this is probably a different issue than CVE-2007-0040.
21450| [CVE-2007-2999] Microsoft Windows Server 2003, when time restrictions are in effect for user accounts, generates different error messages for failed login attempts with a valid user name than for those with an invalid user name, which allows context-dependent attackers to determine valid Active Directory account names.
21451| [CVE-2007-2967] Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070522 allow remote attackers to cause a denial of service (file scanning infinite loop) via certain crafted (1) ARJ archives or (2) FSG packed files.
21452| [CVE-2007-2966] Buffer overflow in the LHA decompresion component in F-Secure anti-virus products for Microsoft Windows and Linux before 20070529 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted LHA archive, related to an integer wrap, a similar issue to CVE-2006-4335.
21453| [CVE-2007-2903] Buffer overflow in the HelpPopup method in the Microsoft Office 2000 Controllo UA di Microsoft Office ActiveX control (OUACTRL.OCX) 1.0.1.9 allows remote attackers to cause a denial of service (probably winhlp32.exe crash) via a long first argument. NOTE: it is not clear whether this issue crosses privilege boundaries.
21454| [CVE-2007-2593] The Terminal Server in Microsoft Windows 2003 Server, when using TLS, allows remote attackers to bypass SSL and self-signed certificate requirements, downgrade the server security, and possibly conduct man-in-the-middle attacks via unspecified vectors, as demonstrated using the Remote Desktop Protocol (RDP) 6.0 client. NOTE: a third party claims that the vendor may have fixed this in approximately 2006.
21455| [CVE-2007-2581] Multiple cross-site scripting (XSS) vulnerabilities in Microsoft Windows SharePoint Services 3.0 for Windows Server 2003 and Office SharePoint Server 2007 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (query string) in "every main page," as demonstrated by default.aspx.
21456| [CVE-2007-2374] Unspecified vulnerability in Microsoft Windows 2000, XP, and Server 2003 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors. NOTE: this information is based upon a vague pre-advisory with no actionable information. However, the advisory is from a reliable source.
21457| [CVE-2007-2228] rpcrt4.dll (aka the RPC runtime library) in Microsoft Windows XP SP2, XP Professional x64 Edition, Server 2003 SP1 and SP2, Server 2003 x64 Edition and x64 Edition SP2, and Vista and Vista x64 Edition allows remote attackers to cause a denial of service (RPCSS service stop and system restart) via an RPC request that uses NTLMSSP PACKET authentication with a zero-valued verification trailer signature, which triggers an invalid dereference. NOTE: this also affects Windows 2000 SP4, although the impact is an information leak.
21458| [CVE-2007-2224] Object linking and embedding (OLE) Automation, as used in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Office 2004 for Mac, and Visual Basic 6.0 allows remote attackers to execute arbitrary code via the substringData method on a TextNode object, which causes an integer overflow that leads to a buffer overflow.
21459| [CVE-2007-2221] Unspecified vulnerability in the mdsauth.dll COM object in Microsoft Windows Media Server in the Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4
21460| [CVE-2007-2219] Unspecified vulnerability in the Win32 API on Microsoft Windows 2000, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via certain parameters to an unspecified function.
21461| [CVE-2007-2218] Unspecified vulnerability in the Windows Schannel Security Package for Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2, allows remote servers to execute arbitrary code or cause a denial of service via crafted digital signatures that are processed during an SSL handshake.
21462| [CVE-2007-2217] Kodak Image Viewer in Microsoft Windows 2000 SP4, and in some cases XP SP2 and Server 2003 SP1 and SP2, allows remote attackers to execute arbitrary code via crafted image files that trigger memory corruption, as demonstrated by a certain .tif (TIFF) file.
21463| [CVE-2007-1911] Multiple unspecified vulnerabilities in Microsoft Word 2007 allow remote attackers to cause a denial of service (CPU consumption) via crafted documents, as demonstrated by (1) file798-1.doc and (2) file613-1.doc, possibly related to a buffer overflow.
21464| [CVE-2007-1910] Buffer overflow in wwlib.dll in Microsoft Word 2007 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted document, as demonstrated by file789-1.doc.
21465| [CVE-2007-1765] Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malformed ANI file, which results in memory corruption when processing cursors, animated cursors, and icons, a similar issue to CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this issue might be a duplicate of CVE-2007-0038
21466| [CVE-2007-1756] Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, and Office Excel 2007 does not properly validate version information, which allows user-assisted remote attackers to execute arbitrary code via a crafted Excel file, aka "Calculation Error Vulnerability".
21467| [CVE-2007-1754] PUBCONV.DLL in Microsoft Office Publisher 2007 does not properly clear memory when transferring data from disk to memory, which allows user-assisted remote attackers to execute arbitrary code via a malformed .pub page via a certain negative value, which bypasses a sanitization procedure that initializes critical pointers to NULL, aka the "Publisher Invalid Memory Reference Vulnerability".
21468| [CVE-2007-1748] Stack-based buffer overflow in the RPC interface in the Domain Name System (DNS) Server Service in Microsoft Windows 2000 Server SP 4, Server 2003 SP 1, and Server 2003 SP 2 allows remote attackers to execute arbitrary code via a long zone name containing character constants represented by escape sequences.
21469| [CVE-2007-1747] Unspecified vulnerability in MSO.dll in Microsoft Office 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and 2007 allows user-assisted remote attackers to execute arbitrary code via a malformed drawing object, which triggers memory corruption.
21470| [CVE-2007-1645] Buffer overflow in FutureSoft TFTP Server 2000 on Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrary code via a long request on UDP port 69. NOTE: this issue might overlap CVE-2006-4781 or CVE-2005-1812.
21471| [CVE-2007-1537] \Device\NdisTapi (NDISTAPI.sys) in Microsoft Windows XP SP2 and 2003 SP1 uses weak permissions, which allows local users to write to the device and cause a denial of service, as demonstrated by using an IRQL to acquire a spinlock on paged memory via the NdisTapiDispatch function.
21472| [CVE-2007-1512] Stack-based buffer overflow in the AfxOleSetEditMenu function in the MFC component in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 Gold and SP1, and Visual Studio .NET 2002 Gold and SP1, and 2003 Gold and SP1 allows user-assisted remote attackers to have an unknown impact (probably crash) via an RTF file with a malformed OLE object, which results in writing two 0x00 characters past the end of szBuffer, aka the "MFC42u.dll Off-by-Two Overflow." NOTE: this issue is due to an incomplete patch (MS07-012) for CVE-2007-0025.
21473| [CVE-2007-1347] Microsoft Windows Explorer on Windows 2000 SP4 FR and XP SP2 FR, and possibly other versions and platforms, allows remote attackers to cause a denial of service (memory corruption and crash) via an Office file with crafted document summary information, which causes an error in Ole32.dll.
21474| [CVE-2007-1239] Microsoft Excel 2003 does not properly parse .XLS files, which allows remote attackers to cause a denial of service (application crash) via a file with a (1) corrupted XML format or a (2) corrupted XLS format, which triggers a NULL pointer dereference.
21475| [CVE-2007-1238] Microsoft Office 2003 allows user-assisted remote attackers to cause a denial of service (application crash) by attempting to insert a corrupted WMF file.
21476| [CVE-2007-1215] Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4
21477| [CVE-2007-1214] Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, and 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a crafted AutoFilter filter record in an Excel BIFF8 format XLS file, which triggers memory corruption.
21478| [CVE-2007-1213] The TrueType Fonts rasterizer in Microsoft Windows 2000 SP4 allows local users to gain privileges via crafted TrueType fonts, which result in an uninitialized function pointer.
21479| [CVE-2007-1212] Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4
21480| [CVE-2007-1211] Unspecified kernel GDI functions in Microsoft Windows 2000 SP4
21481| [CVE-2007-1205] Unspecified vulnerability in Microsoft Agent (msagent\agentsvr.exe) in Windows 2000 SP4, XP SP2, and Server 2003, 2003 SP1, and 2003 SP2 allows remote attackers to execute arbitrary code via crafted URLs, which result in memory corruption.
21482| [CVE-2007-1203] Unspecified vulnerability in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, 2004 for Mac, and 2007 allows user-assisted remote attackers to execute arbitrary code via a crafted set font value in an Excel file, which results in memory corruption.
21483| [CVE-2007-1202] Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006 does not properly parse certain rich text "property strings of certain control words," which allows user-assisted remote attackers to trigger heap corruption and execute arbitrary code, aka the "Word RTF Parsing Vulnerability."
21484| [CVE-2007-1201] Unspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user-assisted remote attackers to execute arbitrary code via vectors related to DataSource that trigger memory corruption, aka "Office Web Components DataSource Vulnerability."
21485| [CVE-2007-1117] Unspecified vulnerability in Publisher 2007 in Microsoft Office 2007 allows remote attackers to execute arbitrary code via unspecified vectors, related to a "file format vulnerability." NOTE: this information is based upon a vague pre-advisory with no actionable information. However, the advisory is from a reliable source.
21486| [CVE-2007-1090] Microsoft Windows Explorer on Windows XP and 2003 allows remote user-assisted attackers to cause a denial of service (crash) via a malformed WMF file, which triggers the crash when the user browses the folder.
21487| [CVE-2007-1083] Buffer overflow in the Configuration Checker (ConfigChk) ActiveX control in VSCnfChk.dll 2.0.0.2 for Verisign Managed PKI Service, Secure Messaging for Microsoft Exchange, and Go Secure! allows remote attackers to execute arbitrary code via long arguments to the VerCompare method.
21488| [CVE-2007-0948] Heap-based buffer overflow in Microsoft Virtual PC 2004 and PC for Mac 7.1 and 7, and Virtual Server 2005 and 2005 R2, allows local guest OS administrators to execute arbitrary code on the host OS via unspecified vectors related to "interaction and initialization of components."
21489| [CVE-2007-0947] Use-after-free vulnerability in Microsoft Internet Explorer 7 on Windows XP SP2, Windows Server 2003 SP1 or SP2, or Windows Vista allows remote attackers to execute arbitrary code via crafted HTML objects, resulting in accessing deallocated memory of CMarkup objects, aka the second of two "HTML Objects Memory Corruption Vulnerabilities" and a different issue than CVE-2007-0946.
21490| [CVE-2007-0946] Unspecified vulnerability in Microsoft Internet Explorer 7 on Windows XP SP2, Windows Server 2003 SP1 or SP2, or Windows Vista allows remote attackers to execute arbitrary code via crafted HTML objects, which results in memory corruption, aka the first of two "HTML Objects Memory Corruption Vulnerabilities" and a different issue than CVE-2007-0947.
21491| [CVE-2007-0945] Microsoft Internet Explorer 6 SP1 on Windows 2000 SP4
21492| [CVE-2007-0944] Unspecified vulnerability in the CTableCol::OnPropertyChange method in Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4
21493| [CVE-2007-0942] Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4
21494| [CVE-2007-0940] Unspecified vulnerability in the Cryptographic API Component Object Model Certificates ActiveX control (CAPICOM.dll) in Microsoft CAPICOM and BizTalk Server 2004 SP1 and SP2 allows remote attackers to execute arbitrary code via unspecified vectors, aka the "CAPICOM.Certificates Vulnerability."
21495| [CVE-2007-0939] Cross-site scripting (XSS) vulnerability in Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving HTML redirection queries, aka "Cross-site Scripting and Spoofing Vulnerability."
21496| [CVE-2007-0938] Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 does not properly handle certain characters in a crafted HTTP GET request, which allows remote attackers to execute arbitrary code, aka the "CMS Memory Corruption Vulnerability."
21497| [CVE-2007-0936] Multiple unspecified vulnerabilities in Microsoft Visio 2002 allow remote user-assisted attackers to execute arbitrary code via a Visio (.VSD, VSS, .VST) file with a crafted packed object that triggers memory corruption, aka "Visio Document Packaging Vulnerability."
21498| [CVE-2007-0934] Unspecified vulnerability in Microsoft Visio 2002 allows remote user-assisted attackers to execute arbitrary code via a Visio (.VSD, VSS, .VST) file with a crafted version number that triggers memory corruption.
21499| [CVE-2007-0913] Unspecified vulnerability in Microsoft Powerpoint allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as exploited by Trojan.PPDropper.G. NOTE: as of 20070213, it is not clear whether this is the same issue as CVE-2006-5296, CVE-2006-4694, CVE-2006-3876, CVE-2006-3877, or older issues.
21500| [CVE-2007-0870] Unspecified vulnerability in Microsoft Word 2000 allows remote attackers to cause a denial of service (crash) via unknown vectors, a different vulnerability than CVE-2006-5994, CVE-2006-6456, CVE-2006-6561, and CVE-2007-0515, a variant of Exploit-MS06-027.
21501| [CVE-2007-0843] The ReadDirectoryChangesW API function on Microsoft Windows 2000, XP, Server 2003, and Vista does not check permissions for child objects, which allows local users to bypass permissions by opening a directory with LIST (READ) access and using ReadDirectoryChangesW to monitor changes of files that do not have LIST permissions, which can be leveraged to determine filenames, access times, and other sensitive information.
21502| [CVE-2007-0811] Microsoft Internet Explorer 6.0 SP1 on Windows 2000, and 6.0 SP2 on Windows XP, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an HTML document containing a certain JavaScript for loop with an empty loop body, possibly involving getElementById.
21503| [CVE-2007-0671] Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.
21504| [CVE-2007-0612] Multiple ActiveX controls in Microsoft Windows 2000, XP, 2003, and Vista allows remote attackers to cause a denial of service (Internet Explorer crash) by accessing the bgColor, fgColor, linkColor, alinkColor, vlinkColor, or defaultCharset properties in the (1) giffile, (2) htmlfile, (3) jpegfile, (4) mhtmlfile, (5) ODCfile, (6) pjpegfile, (7) pngfile, (8) xbmfile, (9) xmlfile, (10) xslfile, or (11) wdfile objects in (a) mshtml.dll
21505| [CVE-2007-0515] Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of service on Word 2003, via unknown attack vectors that trigger memory corruption, as exploited by Trojan.Mdropper.W and later by Trojan.Mdropper.X, a different issue than CVE-2006-6456, CVE-2006-5994, and CVE-2006-6561.
21506| [CVE-2007-0351] Microsoft Windows XP and Windows Server 2003 do not properly handle user logoff, which might allow local users to gain the privileges of a previous system user, possibly related to user profile unload failure. NOTE: it is not clear whether this is an issue in Windows itself, or an interaction with another product. The issue might involve ZoneAlarm not being able to terminate processes when it cannot prompt the user.
21507| [CVE-2007-0221] Integer overflow in the IMAP (IMAP4) support in Microsoft Exchange Server 2000 SP3 allows remote attackers to cause a denial of service (service hang) via crafted literals in an IMAP command, aka the "IMAP Literal Processing Vulnerability."
21508| [CVE-2007-0220] Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2000 SP3, and 2003 SP1 and SP2 allows remote attackers to execute arbitrary scripts, spoof content, or obtain sensitive information via certain UTF-encoded, script-based e-mail attachments, involving an "incorrectly handled UTF character set label".
21509| [CVE-2007-0216] wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section length headers, aka "Microsoft Works File Converter Input Validation Vulnerability."
21510| [CVE-2007-0215] Stack-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, and 2003 Viewer allows user-assisted remote attackers to execute arbitrary code via a .XLS BIFF file with a malformed Named Graph record, which results in memory corruption.
21511| [CVE-2007-0214] The HTML Help ActiveX control (Hhctrl.ocx) in Microsoft Windows 2000 SP3, XP SP2 and Professional, 2003 SP1 allows remote attackers to execute arbitrary code via unspecified functions, related to uninitialized parameters.
21512| [CVE-2007-0213] Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 does not properly decode certain MIME encoded e-mails, which allows remote attackers to execute arbitrary code via a crafted base64-encoded MIME e-mail message.
21513| [CVE-2007-0211] The hardware detection functionality in the Windows Shell in Microsoft Windows XP SP2 and Professional, and Server 2003 SP1 allows local users to gain privileges via an unvalidated parameter to a function related to the "detection and registration of new hardware."
21514| [CVE-2007-0209] Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a Word file with a malformed drawing object, which leads to memory corruption.
21515| [CVE-2007-0208] Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac does not correctly check the properties of certain documents and warn the user of macro content, which allows user-assisted remote attackers to execute arbitrary code.
21516| [CVE-2007-0069] Unspecified vulnerability in the kernel in Microsoft Windows XP SP2, Server 2003, and Vista allows remote attackers to cause a denial of service (CPU consumption) and possibly execute arbitrary code via crafted (1) IGMPv3 and (2) MLDv2 packets that trigger memory corruption, aka "Windows Kernel TCP/IP/IGMPv3 and MLDv2 Vulnerability."
21517| [CVE-2007-0066] The kernel in Microsoft Windows 2000 SP4, XP SP2, and Server 2003, when ICMP Router Discovery Protocol (RDP) is enabled, allows remote attackers to cause a denial of service via fragmented router advertisement ICMP packets that trigger an out-of-bounds read, aka "Windows Kernel TCP/IP/ICMP Vulnerability."
21518| [CVE-2007-0065] Heap-based buffer overflow in Object Linking and Embedding (OLE) Automation in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, Office 2004 for Mac, and Visual basic 6.0 SP6 allows remote attackers to execute arbitrary code via a crafted script request.
21519| [CVE-2007-0064] Heap-based buffer overflow in Windows Media Format Runtime 7.1, 9, 9.5, 9.5 x64 Edition, 11, and Windows Media Services 9.1 for Microsoft Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via a crafted Advanced Systems Format (ASF) file.
21520| [CVE-2007-0043] The Just In Time (JIT) Compiler service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer," probably a buffer overflow, aka ".NET JIT Compiler Vulnerability".
21521| [CVE-2007-0042] Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to access configuration files and obtain sensitive information, and possibly bypass security mechanisms that try to constrain the final substring of a string, via %00 characters, related to use of %00 as a string terminator within POSIX functions but a data character within .NET strings, aka "Null Byte Termination Vulnerability."
21522| [CVE-2007-0041] The PE Loader service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer" and unvalidated message lengths, probably a buffer overflow.
21523| [CVE-2007-0040] The LDAP service in Windows Active Directory in Microsoft Windows 2000 Server SP4, Server 2003 SP1 and SP2, Server 2003 x64 Edition and SP2, and Server 2003 for Itanium-based Systems SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted LDAP request with an unspecified number of "convertible attributes."
21524| [CVE-2007-0039] The Exchange Collaboration Data Objects (EXCDO) functionality in Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 allows remote attackers to cause a denial of service (crash) via an Internet Calendar (iCal) file containing multiple X-MICROSOFT-CDO-MODPROPS (MODPROPS) properties in which the second MODPROPS is longer than the first, which triggers a NULL pointer dereference and an unhandled exception.
21525| [CVE-2007-0038] Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a large length value in the second (or later) anih block of a RIFF .ANI, cur, or .ico file, which results in memory corruption when processing cursors, animated cursors, and icons, a variant of CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this might be a duplicate of CVE-2007-1765
21526| [CVE-2007-0035] Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006 does not properly handle data in a certain array, which allows user-assisted remote attackers to execute arbitrary code, aka the "Word Array Overflow Vulnerability."
21527| [CVE-2007-0034] Buffer overflow in the Advanced Search (Finder.exe) feature of Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted Outlook Saved Searches (OSS) file that triggers memory corruption, aka "Microsoft Outlook Advanced Find Vulnerability."
21528| [CVE-2007-0033] Microsoft Outlook 2002 and 2003 allows user-assisted remote attackers to execute arbitrary code via a malformed VEVENT record in an .iCal meeting request or ICS file.
21529| [CVE-2007-0031] Heap-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via a BIFF8 spreadsheet with a PALETTE record that contains a large number of entries.
21530| [CVE-2007-0030] Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via an Excel file with an out-of-range Column field in certain BIFF8 record types, which references arbitrary memory.
21531| [CVE-2007-0029] Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via a malformed string, aka "Excel Malformed String Vulnerability."
21532| [CVE-2007-0028] Microsoft Excel 2000, 2002, 2003, Viewer 2003, Office 2004 for Mac, and Office v.X for Mac does not properly handle certain opcodes, which allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file, which results in an "Improper Memory Access Vulnerability." NOTE: an early disclosure of this issue used CVE-2006-3432, but only CVE-2007-0028 should be used.
21533| [CVE-2007-0027] Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via malformed IMDATA records that trigger memory corruption.
21534| [CVE-2007-0026] The OLE Dialog component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption.
21535| [CVE-2007-0025] The MFC component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 and Visual Studio .NET 2000, 2002 SP1, 2003, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption. NOTE: this might be due to a stack-based buffer overflow in the AfxOleSetEditMenu function in MFC42u.dll.
21536| [CVE-2007-0024] Integer overflow in the Vector Markup Language (VML) implementation (vgx.dll) in Microsoft Internet Explorer 5.01, 6, and 7 on Windows 2000 SP4, XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted web page that contains unspecified integer properties that cause insufficient memory allocation and trigger a buffer overflow, aka the "VML Buffer Overrun Vulnerability."
21537| [CVE-2006-7210] Microsoft Windows 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (cpu consumption) via a PNG image with crafted (1) Width and (2) Height values in the IHDR block.
21538| [CVE-2006-7192] Microsoft ASP .NET Framework 2.0.50727.42 does not properly handle comment (/* */) enclosures, which allows remote attackers to bypass request filtering and conduct cross-site scripting (XSS) attacks, or cause a denial of service, as demonstrated via an xss:expression STYLE attribute in a closing XSS HTML tag.
21539| [CVE-2006-7027] Microsoft Internet Security and Acceleration (ISA) Server 2004 logs unusual ASCII characters in the Host header, including the tab, which allows remote attackers to manipulate portions of the log file and possibly leverage this for other attacks.
21540| [CVE-2006-6723] The Workstation service in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to cause a denial of service (memory consumption) via a large maxlen value in an NetrWkstaUserEnum RPC request.
21541| [CVE-2006-6696] Double free vulnerability in Microsoft Windows 2000, XP, 2003, and Vista allows local users to gain privileges by calling the MessageBox function with a MB_SERVICE_NOTIFICATION message with crafted data, which sends a HardError message to Client/Server Runtime Server Subsystem (CSRSS) process, which is not properly handled when invoking the UserHardError and GetHardErrorText functions in WINSRV.DLL.
21542| [CVE-2006-6617] projectserver/logon/pdsrequest.asp in Microsoft Project Server 2003 allows remote authenticated users to obtain the MSProjectUser password for a SQL database via a GetInitializationData request, which includes the information in the UserName and Password tags of the response.
21543| [CVE-2006-6561] Unspecified vulnerability in Microsoft Word 2000, 2002, and Word Viewer 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted DOC file that triggers memory corruption, as demonstrated via the 12122006-djtest.doc file, a different issue than CVE-2006-5994 and CVE-2006-6456.
21544| [CVE-2006-6456] Unspecified vulnerability in Microsoft Word 2000, 2002, and 2003 and Word Viewer 2003 allows remote attackers to execute code via unspecified vectors related to malformed data structures that trigger memory corruption, a different vulnerability than CVE-2006-5994.
21545| [CVE-2006-6296] The RpcGetPrinterData function in the Print Spooler (spoolsv.exe) service in Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 and earlier, allows remote attackers to cause a denial of service (memory consumption) via an RPC request that specifies a large 'offered' value (output buffer size), a variant of CVE-2005-3644.
21546| [CVE-2006-6134] Heap-based buffer overflow in the WMCheckURLScheme function in WMVCORE.DLL in Microsoft Windows Media Player (WMP) 10.00.00.4036 on Windows XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via a long HREF attribute, using an unrecognized protocol, in a REF element in an ASX PlayList file.
21547| [CVE-2006-6133] Stack-based buffer overflow in Visual Studio Crystal Reports for Microsoft Visual Studio .NET 2002 and 2002 SP1, .NET 2003 and 2003 SP1, and 2005 and 2005 SP1 (formerly Business Objects Crystal Reports XI Professional) allows user-assisted remote attackers to execute arbitrary code via a crafted RPT file.
21548| [CVE-2006-5994] Unspecified vulnerability in Microsoft Word 2000 and 2002, Office Word and Word Viewer 2003, Word 2004 and 2004 v. X for Mac, and Works 2004, 2005, and 2006 allows remote attackers to execute arbitrary code via a Word document with a malformed string that triggers memory corruption, a different vulnerability than CVE-2006-6456.
21549| [CVE-2006-5758] The Graphics Rendering Engine in Microsoft Windows 2000 through 2000 SP4 and Windows XP through SP2 maps GDI Kernel structures on a global shared memory section that is mapped with read-only permissions, but can be remapped by other processes as read-write, which allows local users to cause a denial of service (memory corruption and crash) and gain privileges by modifying the kernel structures.
21550| [CVE-2006-5586] The Graphics Rendering Engine in Microsoft Windows 2000 SP4 and XP SP2 allows local users to gain privileges via "invalid application window sizes" in layered application windows, aka the "GDI Invalid Window Size Elevation of Privilege Vulnerability."
21551| [CVE-2006-5585] The Client-Server Run-time Subsystem in Microsoft Windows XP SP2 and Server 2003 allows local users to gain privileges via a crafted file manifest within an application, aka "File Manifest Corruption Vulnerability."
21552| [CVE-2006-5584] The Remote Installation Service (RIS) in Microsoft Windows 2000 SP4 uses a TFTP server that allows anonymous access, which allows remote attackers to upload and overwrite arbitrary files to gain privileges on systems that use RIS.
21553| [CVE-2006-5583] Buffer overflow in the SNMP Service in Microsoft Windows 2000 SP4, XP SP2, Server 2003, Server 2003 SP1, and possibly other versions allows remote attackers to execute arbitrary code via a crafted SNMP packet, aka "SNMP Memory Corruption Vulnerability."
21554| [CVE-2006-5574] Unspecified vulnerability in the Brazilian Portuguese Grammar Checker in Microsoft Office 2003 and the Multilingual Interface for Office 2003, Project 2003, and Visio 2003 allows user-assisted remote attackers to execute arbitrary code via crafted text that is not properly parsed.
21555| [CVE-2006-5296] PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record length, which allows user-assisted attackers to cause a denial of service (NULL dereference and application crash) via a crafted PowerPoint (.PPT) file, as demonstrated by Nanika.ppt, and a different vulnerability than CVE-2006-3435, CVE-2006-3876, CVE-2006-3877, and CVE-2006-4694. NOTE: the impact of this issue was originally claimed to be arbitrary code execution, but later analysis demonstrated that this was erroneous.
21556| [CVE-2006-4854] ** REJECT ** Unspecified vulnerability in Microsoft Office 2000 (Chinese Edition) and Microsoft PowerPoint 2000 (Chinese Edition) allows user-assisted attackers to execute arbitrary code via a crafted PPT document, as exploited by malware such as Trojan.PPDropper.E. NOTE: on 20060919, Microsoft notified CVE that this is a duplicate of CVE-2006-0009.
21557| [CVE-2006-4704] Cross-zone scripting vulnerability in the WMI Object Broker (WMIScriptUtils.WMIObjectBroker2) ActiveX control (WmiScriptUtils.dll) in Microsoft Visual Studio 2005 allows remote attackers to bypass Internet zone restrictions and execute arbitrary code by instantiating dangerous objects, aka "WMI Object Broker Vulnerability."
21558| [CVE-2006-4702] Buffer overflow in the Windows Media Format Runtime in Microsoft Windows Media Player (WMP) 6.4 and Windows XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted Advanced Systems Format (ASF) file.
21559| [CVE-2006-4696] Unspecified vulnerability in the Server service in Microsoft Windows 2000 SP4, Server 2003 SP1 and earlier, and XP SP2 and earlier allows remote attackers to execute arbitrary code via a crafted packet, aka "SMB Rename Vulnerability."
21560| [CVE-2006-4695] Unspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user-assisted remote attackers to execute arbitrary code via a crafted URL, aka "Office Web Components URL Parsing Vulnerability."
21561| [CVE-2006-4694] Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office XP and Office 2003 allows user-assisted attackers to execute arbitrary code via a crafted record in a PPT file, as exploited by malware such as Exploit:Win32/Controlppt.W, Exploit:Win32/Controlppt.X, and Exploit-PPT.d/Trojan.PPDropper.F. NOTE: it has been reported that the attack vector involves SlideShowWindows.View.GotoNamedShow.
21562| [CVE-2006-4693] Unspecified vulnerability in Microsoft Word 2004 for Mac and v.X for Mac allows remote user-assisted attackers to execute arbitrary code via a crafted string in a Word file, a different issue than CVE-2006-3647 and CVE-2006-3651.
21563| [CVE-2006-4692] Argument injection vulnerability in the Windows Object Packager (packager.exe) in Microsoft Windows XP SP1 and SP2 and Server 2003 SP1 and earlier allows remote user-assisted attackers to execute arbitrary commands via a crafted file with a "/" (slash) character in the filename of the Command Line property, followed by a valid file extension, which causes the command before the slash to be executed, aka "Object Packager Dialogue Spoofing Vulnerability."
21564| [CVE-2006-4691] Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to execute arbitrary code via NetrJoinDomain2 RPC messages with a long hostname.
21565| [CVE-2006-4689] Unspecified vulnerability in the driver for the Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to cause a denial of service (hang and reboot) via has unknown attack vectors, aka "NetWare Driver Denial of Service Vulnerability."
21566| [CVE-2006-4688] Buffer overflow in Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via crafted messages, aka "Client Service for NetWare Memory Corruption Vulnerability."
21567| [CVE-2006-4534] Unspecified vulnerability in Microsoft Word 2000, 2002, and Office 2003 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors involving a crafted file resulting in a malformed stack, as exploited by malware with names including Trojan.Mdropper.Q, Mofei, and Femo.
21568| [CVE-2006-4495] Microsoft Internet Explorer allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Windows 2000 ActiveX COM Objects including (1) ciodm.dll, (2) myinfo.dll, (3) msdxm.ocx, and (4) creator.dll.
21569| [CVE-2006-4274] ** REJECT ** Unknown vulnerability in Microsoft PowerPoint allows user-assisted attackers to execute arbitrary code via a crafted PPT document, as exploited by malware such as TROJ_MDROPPER.BH. NOTE: on 20060822, it was determined that TROJ_MDROPPER.BH was exploiting CVE-2006-0009, so this is not a new vulnerability.
21570| [CVE-2006-4219] The Terminal Services COM object (tsuserex.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by instantiating it as an ActiveX object in Internet Explorer 6.0 SP1 on Microsoft Windows 2003 EE SP1 CN.
21571| [CVE-2006-4183] Heap-based buffer overflow in Microsoft DirectX SDK (February 2006) and probably earlier, including 9.0c End User Runtimes, allows context-dependent attackers to execute arbitrary code via a crafted Targa file with a run-length-encoding (RLE) compression that produces more data than expected when decoding.
21572| [CVE-2006-4071] Sign extension vulnerability in the createBrushIndirect function in the GDI library (gdi32.dll) in Microsoft Windows XP, Server 2003, and possibly other versions, allows user-assisted attackers to cause a denial of service (application crash) via a crafted WMF file.
21573| [CVE-2006-3992] Unspecified vulnerability in the Centrino (1) w22n50.sys, (2) w22n51.sys, (3) w29n50.sys, and (4) w29n51.sys Microsoft Windows drivers for Intel 2200BG and 2915ABG PRO/Wireless Network Connection before 10.5 with driver 9.0.4.16 allows remote attackers to execute arbitrary code via certain frames that trigger memory corruption.
21574| [CVE-2006-3942] The server driver (srv.sys) in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (system crash) via an SMB_COM_TRANSACTION SMB message that contains a string without null character termination, which leads to a NULL dereference in the ExecuteTransaction function, possibly related to an "SMB PIPE," aka the "Mailslot DOS" vulnerability. NOTE: the name "Mailslot DOS" was derived from incomplete initial research
21575| [CVE-2006-3897] Stack overflow in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a denial of service (application crash) by creating an NMSA.ASFSourceMediaDescription.1 ActiveX object with a long dispValue property.
21576| [CVE-2006-3880] ** DISPUTED ** Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Small Business Server 2003 allow remote attackers to cause a denial of service (IP stack hang) via a continuous stream of packets on TCP port 135 that have incorrect TCP header checksums and random numbers in certain TCP header fields, as demonstrated by the Achilles Windows Attack Tool. NOTE: the researcher reports that the Microsoft Security Response Center has stated "Our investigation which has included code review, review of the TCPDump, and attempts on reproing the issue on multiple fresh installs of various Windows Operating Systems have all resulted in non confirmation."
21577| [CVE-2006-3877] Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via an unspecified "crafted file," a different vulnerability than CVE-2006-3435, CVE-2006-4694, and CVE-2006-3876.
21578| [CVE-2006-3876] Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via a crafted Data record in a PPT file, a different vulnerability than CVE-2006-3435 and CVE-2006-4694.
21579| [CVE-2006-3875] Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, and Excel Viewer 2003 allows user-assisted attackers to execute arbitrary code via a crafted COLINFO record in an XLS file, a different vulnerability than CVE-2006-2387 and CVE-2006-3867.
21580| [CVE-2006-3873] Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP SP1, with versions the MS06-042 patch before 20060912, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL in a GZIP-encoded website that was the target of an HTTP redirect, due to an incomplete fix for CVE-2006-3869.
21581| [CVE-2006-3869] Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP SP1, with versions the MS06-042 patch before 20060824, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL on a website that uses HTTP 1.1 compression.
21582| [CVE-2006-3868] Unspecified vulnerability in Microsoft Office XP and 2003 allows remote user-assisted attackers to execute arbitrary code via a malformed Smart Tag.
21583| [CVE-2006-3867] Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, and Excel Viewer 2003 allows user-assisted attackers to execute arbitrary code via a crafted Lotus 1-2-3 file, a different vulnerability than CVE-2006-2387 and CVE-2006-3875.
21584| [CVE-2006-3864] Unspecified vulnerability in mso.dll in Microsoft Office 2000, XP, and 2003, and Microsoft PowerPoint 2000, XP, and 2003, allows remote user-assisted attackers to execute arbitrary code via a malformed record in a (1) .DOC, (2) .PPT, or (3) .XLS file that triggers memory corruption, related to an "array boundary condition" (possibly an array index overflow), a different vulnerability than CVE-2006-3434, CVE-2006-3650, and CVE-2006-3868.
21585| [CVE-2006-3841] Cross-site scripting (XSS) vulnerability in WebScarab before 20060718-1904, when used with Microsoft Internet Explorer 6 SP2 or Konqueror 3.5.3, allows remote attackers to inject arbitrary web script or HTML via the URL, which is not sanitized before being returned in an error message when WebScarab is not able to access the URL.
21586| [CVE-2006-3660] Unspecified vulnerability in Microsoft PowerPoint 2003 has unknown impact and user-assisted attack vectors related to powerpnt.exe. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3655, CVE-2006-3656, and CVE-2006-3590, although it is possible that they are all different.
21587| [CVE-2006-3656] Unspecified vulnerability in Microsoft PowerPoint 2003 allows user-assisted attackers to cause memory corruption via a crafted PowerPoint file, which triggers the corruption when the file is closed. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3655, CVE-2006-3660, and CVE-2006-3590, although it is possible that they are all different.
21588| [CVE-2006-3655] Unspecified vulnerability in mso.dll in Microsoft PowerPoint 2003 allows user-assisted attackers to execute arbitrary code via a crafted PowerPoint file. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3656, CVE-2006-3660, and CVE-2006-3590, although it is possible that they are all different.
21589| [CVE-2006-3652] Microsoft Internet Security and Acceleration (ISA) Server 2004 allows remote attackers to bypass file extension filters via a request with a trailing "#" character. NOTE: as of 20060715, this could not be reproduced by third parties.
21590| [CVE-2006-3651] Unspecified vulnerability in Microsoft Word 2000, 2002, and Office 2003 allows remote user-assisted attackers to execute arbitrary code via a crafted mail merge file, a different vulnerability than CVE-2006-3647 and CVE-2006-4693.
21591| [CVE-2006-3650] Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac do not properly parse the length of a chart record, which allows remote user-assisted attackers to execute arbitrary code via a Word document with an embedded malformed chart record that triggers an overwrite of pointer values with values from the document, a different vulnerability than CVE-2006-3434, CVE-2006-3864, and CVE-2006-3868.
21592| [CVE-2006-3649] Buffer overflow in Microsoft Visual Basic for Applications (VBA) SDK 6.0 through 6.4, as used by Microsoft Office 2000 SP3, Office XP SP3, Project 2000 SR1, Project 2002 SP1, Access 2000 Runtime SP3, Visio 2002 SP2, and Works Suite 2004 through 2006, allows user-assisted attackers to execute arbitrary code via unspecified document properties that are not verified when VBA is invoked to open documents.
21593| [CVE-2006-3648] Unspecified vulnerability in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 and 2003 SP1, allows remote attackers to execute arbitrary code via unspecified vectors involving unhandled exceptions, memory resident applications, and incorrectly "unloading chained exception."
21594| [CVE-2006-3647] Integer overflow in Microsoft Word 2000, 2002, 2003, 2004 for Mac, and v.X for Mac allows remote user-assisted attackers to execute arbitrary code via a crafted string in a Word document, which overflows a 16-bit integer length value, aka "Memmove Code Execution," a different vulnerability than CVE-2006-3651 and CVE-2006-4693.
21595| [CVE-2006-3643] Cross-site scripting (XSS) vulnerability in Internet Explorer 5.01 and 6 in Microsoft Windows 2000 SP4 permits access to local "HTML-embedded resource files" in the Microsoft Management Console (MMC) library, which allows remote authenticated users to execute arbitrary commands, aka "MMC Redirect Cross-Site Scripting Vulnerability."
21596| [CVE-2006-3590] mso.dll, as used by Microsoft PowerPoint 2000 through 2003, allows user-assisted attackers to execute arbitrary commands via a malformed shape container in a PPT file that leads to memory corruption, as exploited by Trojan.PPDropper.B, a different issue than CVE-2006-1540 and CVE-2006-3493.
21597| [CVE-2006-3510] The Remote Data Service Object (RDS.DataControl) in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a denial of service (crash) via a series of operations that result in an invalid length calculation when using SysAllocStringLen, then triggers a buffer over-read.
21598| [CVE-2006-3493] Buffer overflow in LsCreateLine function (mso_203) in mso.dll and mso9.dll, as used by Microsoft Word and possibly other products in Microsoft Office 2003, 2002, and 2000, allows remote user-assisted attackers to cause a denial of service (crash) via a crafted Word DOC or other Office file type. NOTE: this issue was originally reported to allow code execution, but on 20060710 Microsoft stated that code execution is not possible, and the original researcher agrees.
21599| [CVE-2006-3449] Unspecified vulnerability in Microsoft PowerPoint 2000 through 2003, possibly a buffer overflow, allows user-assisted remote attackers to execute arbitrary commands via a malformed record in the BIFF file format used in a PPT file, a different issue than CVE-2006-1540, aka "Microsoft PowerPoint Malformed Record Vulnerability."
21600| [CVE-2006-3448] Buffer overflow in the Step-by-Step Interactive Training in Microsoft Windows 2000 SP4, XP SP2 and Professional, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a long Syllabus string in crafted bookmark link files (cbo, cbl, or .cbm), a different issue than CVE-2005-1212.
21601| [CVE-2006-3445] Integer overflow in the ReadWideString function in agentdpv.dll in Microsoft Agent on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a large length value in an .ACF file, which results in a heap-based buffer overflow.
21602| [CVE-2006-3444] Unspecified vulnerability in the kernel in Microsoft Windows 2000 SP4, probably a buffer overflow, allows local users to obtain privileges via unspecified vectors involving an "unchecked buffer."
21603| [CVE-2006-3443] Untrusted search path vulnerability in Winlogon in Microsoft Windows 2000 SP4, when SafeDllSearchMode is disabled, allows local users to gain privileges via a malicious DLL in the UserProfile directory, aka "User Profile Elevation of Privilege Vulnerability."
21604| [CVE-2006-3441] Buffer overflow in the DNS Client service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted record response. NOTE: while MS06-041 implies that there is a single issue, there are multiple vectors, and likely multiple vulnerabilities, related to (1) a heap-based buffer overflow in a DNS server response to the client, (2) a DNS server response with malformed ATMA records, and (3) a length miscalculation in TXT, HINFO, X25, and ISDN records.
21605| [CVE-2006-3440] Buffer overflow in the Winsock API in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka "Winsock Hostname Vulnerability."
21606| [CVE-2006-3439] Buffer overflow in the Server Service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers, including anonymous users, to execute arbitrary code via a crafted RPC message, a different vulnerability than CVE-2006-1314.
21607| [CVE-2006-3436] Cross-site scripting (XSS) vulnerability in Microsoft .NET Framework 2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving "ASP.NET controls that set the AutoPostBack property to true".
21608| [CVE-2006-3435] PowerPoint in Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac does not properly parse the slide notes field in a document, which allows remote user-assisted attackers to execute arbitrary code via crafted data in this field, which triggers an erroneous object pointer calculation that uses data from within the document. NOTE: this issue is different than other PowerPoint vulnerabilities including CVE-2006-4694.
21609| [CVE-2006-3434] Unspecified vulnerability in Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac allows remote user-assisted attackers to execute arbitrary code via a crafted string that triggers memory corruption.
21610| [CVE-2006-3431] Buffer overflow in certain Asian language versions of Microsoft Excel might allow user-assisted attackers to execute arbitrary code via a crafted STYLE record in a spreadsheet that triggers the overflow when the user attempts to repair the document or selects the "Style" option, as demonstrated by nanika.xls. NOTE: Microsoft has confirmed to CVE via e-mail that this is different than the other Excel vulnerabilities announced before 20060707, including CVE-2006-3059 and CVE-2006-3086.
21611| [CVE-2006-3059] Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors. NOTE: this is a different vulnerability than CVE-2006-3086.
21612| [CVE-2006-2492] Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 20060519 for a zero-day attack.
21613| [CVE-2006-2389] Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via an Office file with a malformed property that triggers memory corruption related to record lengths, aka "Microsoft Office Property Vulnerability," a different vulnerability than CVE-2006-1316.
21614| [CVE-2006-2388] Microsoft Office Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via malformed cell comments, which lead to modification of "critical data offsets" during the rebuilding process.
21615| [CVE-2006-2387] Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, Excel Viewer 2003, and Microsoft Works Suite 2004 through 2006 allows user-assisted attackers to execute arbitrary code via a crafted DATETIME record in an XLS file, a different vulnerability than CVE-2006-3867 and CVE-2006-3875.
21616| [CVE-2006-2380] Microsoft Windows 2000 SP4 does not properly validate an RPC server during mutual authentication over SSL, which allows remote attackers to spoof an RPC server, aka the "RPC Mutual Authentication Vulnerability."
21617| [CVE-2006-2379] Buffer overflow in the TCP/IP Protocol driver in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via unknown vectors related to IP source routing.
21618| [CVE-2006-2378] Buffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and Sp2, Server 2003 SP1 and earlier, and Windows 98 and Me allows remote attackers to execute arbitrary code via a crafted ART image that causes heap corruption.
21619| [CVE-2006-2374] The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to cause a denial of service (hang) by calling the MrxSmbCscIoctlCloseForCopyChunk with the file handle of the shadow device, which results in a deadlock, aka the "SMB Invalid Handle Vulnerability."
21620| [CVE-2006-2373] The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to execute arbitrary code by calling the MrxSmbCscIoctlOpenForCopyChunk function with the METHOD_NEITHER method flag and an arbitrary address, possibly for kernel memory, aka the "SMB Driver Elevation of Privilege Vulnerability."
21621| [CVE-2006-2372] Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a crafted DHCP response.
21622| [CVE-2006-2371] Buffer overflow in the Remote Access Connection Manager service (RASMAN) service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," that lead to registry corruption and stack corruption, aka the "RASMAN Registry Corruption Vulnerability."
21623| [CVE-2006-2370] Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," aka the "RRAS Memory Corruption Vulnerability."
21624| [CVE-2006-2334] The RtlDosPathNameToNtPathName_U API function in NTDLL.DLL in Microsoft Windows 2000 SP4 and XP SP2 does not properly convert DOS style paths with trailing spaces into NT style paths, which allows context-dependent attackers to create files that cannot be accessed through the expected DOS path or prevent access to other similarly named files in the same directory, which prevents those files from being detected or disinfected by certain anti-virus and anti-spyware software.
21625| [CVE-2006-2094] Microsoft Internet Explorer before Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1, when Prompt is configured in Security Settings, uses modal dialogs to verify that a user wishes to run an ActiveX control or perform other risky actions, which allows user-assisted remote attackers to construct a race condition that tricks a user into clicking an object or pressing keys that are actually applied to a "Yes" approval for executing the control.
21626| [CVE-2006-2055] Argument injection vulnerability in Microsoft Outlook 2003 SP1 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via " (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft Outlook with an arbitrary filename as an attachment. NOTE: it is not clear whether this issue is implementation-specific or a problem in the Microsoft API.
21627| [CVE-2006-1654] Directory traversal vulnerability in the HP Color LaserJet 2500 Toolbox and Color LaserJet 4600 Toolbox on Microsoft Windows before 20060402 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request to TCP port 5225.
21628| [CVE-2006-1651] ** DISPUTED ** Microsoft ISA Server 2004 allows remote attackers to bypass certain filtering rules, including ones for (1) ICMP and (2) TCP, via IPv6 packets. NOTE: An established researcher has disputed this issue, saying that "Neither ISA Server 2004 nor Windows 2003 Basic Firewall support IPv6 filtering ... This is different network protocol."
21629| [CVE-2006-1540] MSO.DLL in Microsoft Office 2000, Office XP (2002), and Office 2003 allows user-assisted attackers to cause a denial of service and execute arbitrary code via multiple attack vectors, as originally demonstrated using a crafted document record with a malformed string, as demonstrated by replacing a certain "01 00 00 00" byte sequence with an "FF FF FF FF" byte sequence, possibly causing an invalid array index, in (1) an Excel .xls document, which triggers an access violation in ole32.dll
21630| [CVE-2006-1316] Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via an Office file with malformed string that triggers memory corruption related to record lengths, aka "Microsoft Office Parsing Vulnerability," a different vulnerability than CVE-2006-2389.
21631| [CVE-2006-1315] The Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to obtain sensitive information via crafted requests that leak information in SMB buffers, which are not properly initialized, aka "SMB Information Disclosure Vulnerability."
21632| [CVE-2006-1314] Heap-based buffer overflow in the Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to execute arbitrary code via crafted first-class Mailslot messages that triggers memory corruption and bypasses size restrictions on second-class Mailslot messages.
21633| [CVE-2006-1313] Microsoft JScript 5.1, 5.5, and 5.6 on Windows 2000 SP4, and 5.6 on Windows XP, Server 2003, Windows 98 and Windows Me, will "release objects early" in certain cases, which results in memory corruption and allows remote attackers to execute arbitrary code.
21634| [CVE-2006-1311] The RichEdit component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1
21635| [CVE-2006-1309] Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted LABEL record that triggers memory corruption.
21636| [CVE-2006-1308] Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted FNGROUPCOUNT value.
21637| [CVE-2006-1306] Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted BIFF record with an attacker-controlled array index that is used for a function pointer, aka "Malformed OBJECT record Vulnerability."
21638| [CVE-2006-1305] Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to cause a denial of service (memory exhaustion and interrupted mail recovery) via malformed e-mail header information, possibly related to (1) long subject lines or (2) large numbers of recipients in To or CC headers.
21639| [CVE-2006-1304] Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted COLINFO record, which triggers the overflow during a "data filling operation."
21640| [CVE-2006-1302] Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with certain crafted fields in a SELECTION record, which triggers memory corruption, aka "Malformed SELECTION record Vulnerability."
21641| [CVE-2006-1301] Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted SELECTION record that triggers memory corruption, a different vulnerability than CVE-2006-1302.
21642| [CVE-2006-1300] Microsoft .NET framework 2.0 (ASP.NET) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to bypass access restrictions via unspecified "URL paths" that can access Application Folder objects "explicitly by name."
21643| [CVE-2006-1257] The sample files in the authfiles directory in Microsoft Commerce Server 2002 before SP2 allow remote attackers to bypass authentication by logging in to authfiles/login.asp with a valid username and any password, then going to the main site twice.
21644| [CVE-2006-1193] Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2000 SP1 through SP3, when running Outlook Web Access (OWA), allows user-assisted remote attackers to inject arbitrary HTML or web script via unknown vectors related to "HTML parsing."
21645| [CVE-2006-1184] Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0, 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to cause a denial of service (crash) via a BuildContextW request with a large (1) UuidString or (2) GuidIn of a certain length, which causes an out-of-range memory access, aka the MSDTC Denial of Service Vulnerability. NOTE: this is a variant of CVE-2005-2119.
21646| [CVE-2006-0988] The default configuration of the DNS Server service on Windows Server 2003 and Windows 2000, and the Microsoft DNS Server service on Windows NT 4.0, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed source IP addresses.
21647| [CVE-2006-0935] Microsoft Word 2003 allows remote attackers to cause a denial of service (application crash) via a crafted file, as demonstrated by 101_filefuzz.
21648| [CVE-2006-0187] By design, Microsoft Visual Studio 2005 automatically executes code in the Load event of a user-defined control (UserControl1_Load function), which allows user-assisted attackers to execute arbitrary code by tricking the user into opening a malicious Visual Studio project file.
21649| [CVE-2006-0034] Heap-based buffer overflow in the CRpcIoManagerServer::BuildContext function in msdtcprx.dll for Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0 and Windows 2000 SP2 and SP3 allows remote attackers to execute arbitrary code via a long fifth argument to the BuildContextW or BuildContext opcode, which triggers a bug in the NdrAllocate function, aka the MSDTC Invalid Memory Access Vulnerability.
21650| [CVE-2006-0033] Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted PNG image that triggers memory corruption when it is parsed.
21651| [CVE-2006-0032] Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL, which is injected into an error message whose charset is set to UTF-7.
21652| [CVE-2006-0031] Stack-based buffer overflow in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed record with a modified length value, which leads to memory corruption.
21653| [CVE-2006-0030] Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed graphic, which leads to memory corruption.
21654| [CVE-2006-0029] Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed description, which leads to memory corruption.
21655| [CVE-2006-0028] Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via a BIFF parsing format file containing malformed BOOLERR records that lead to memory corruption, probably involving invalid pointers.
21656| [CVE-2006-0023] Microsoft Windows XP SP1 and SP2 before August 2004, and possibly other operating systems and versions, uses insecure default ACLs that allow the Authenticated Users group to gain privileges by modifying critical configuration information for the (1) Simple Service Discovery Protocol (SSDP), (2) Universal Plug and Play Device Host (UPnP), (3) NetBT, (4) SCardSvr, (5) DHCP, and (6) DnsCache services, aka "Permissive Windows Services DACLs." NOTE: the NetBT, SCardSvr, DHCP, DnsCache already require privileged access to exploit.
21657| [CVE-2006-0022] Unspecified vulnerability in Microsoft PowerPoint in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP1 and SP2, Office 2004 for Mac, and v. X for Mac allows user-assisted attackers to execute arbitrary code via a PowerPoint document with a malformed record, which triggers memory corruption.
21658| [CVE-2006-0021] Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang) via an IGMP packet with an invalid IP option, aka the "IGMP v3 DoS Vulnerability."
21659| [CVE-2006-0020] An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a crafted WMF file with a manipulated WMF header size, possibly involving an integer overflow, a different vulnerability than CVE-2005-4560, and aka "WMF Image Parsing Memory Corruption Vulnerability."
21660| [CVE-2006-0015] Cross-site scripting (XSS) vulnerability in _vti_bin/_vti_adm/fpadmdll.dll in Microsoft FrontPage Server Extensions 2002 and SharePoint Team Services allows remote attackers to inject arbitrary web script or HTML, then leverage the attack to execute arbitrary programs or create new accounts, via the (1) operation, (2) command, and (3) name parameters.
21661| [CVE-2006-0013] Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote authenticated users or Guests to execute arbitrary code via crafted RPC requests, a different vulnerability than CVE-2005-1207.
21662| [CVE-2006-0012] Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and "crafted files and directories," aka the "Windows Shell Vulnerability."
21663| [CVE-2006-0010] Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.
21664| [CVE-2006-0009] Buffer overflow in Microsoft Office 2000 SP3, XP SP3, and other versions and packages, allows user-assisted attackers to execute arbitrary code via a routing slip that is longer than specified by the provided length field, as exploited by malware such as TROJ_MDROPPER.BH and Trojan.PPDropper.E in attacks against PowerPoint.
21665| [CVE-2006-0008] The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program that displays the about box.
21666| [CVE-2006-0007] Buffer overflow in GIFIMP32.FLT, as used in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted GIF image that triggers memory corruption when it is parsed.
21667| [CVE-2006-0006] Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap (.BMP) file that specifies a size of 0 but contains additional data.
21668| [CVE-2006-0004] Microsoft PowerPoint 2000 in Office 2000 SP3 has an interaction with Internet Explorer that allows remote attackers to obtain sensitive information via a PowerPoint presentation that attempts to access objects in the Temporary Internet Files Folder (TIFF).
21669| [CVE-2006-0002] Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.
21670| [CVE-2006-0001] Stack-based buffer overflow in Microsoft Publisher 2000 through 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted PUB file, which causes an overflow when parsing fonts.
21671| [CVE-2005-4717] Microsoft Internet Explorer 6.0 on Windows NT 4.0 SP6a, Windows 2000 SP4, Windows XP SP1, Windows XP SP2, and Windows Server 2003 SP1 allows remote attackers to cause a denial of service (client crash) via a certain combination of a malformed HTML file and a CSS file that triggers a null dereference, probably related to rendering of a DIV element that contains a malformed IMG tag, as demonstrated by IEcrash.htm and IEcrash.rar.
21672| [CVE-2005-4269] mshtml.dll in Microsoft Windows XP, Server 2003, and Internet Explorer 6.0 SP1 allows attackers to cause a denial of service (access violation) by causing mshtml.dll to process button-focus events at the same time that a document is reloading, as seen in Microsoft Office InfoPath 2003 by repeatedly clicking the "Delete" button in a repeating section in a form. NOTE: the normal operation of InfoPath appears to involve a local user without any privilege boundaries, so this might not be a vulnerability in InfoPath. If no realistic scenarios exist for this problem in other products, then perhaps it should be excluded from CVE.
21673| [CVE-2005-4131] Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed range, which could lead to memory corruption involving an argument to the msvcrt.memmove function, aka "Brand new Microsoft Excel Vulnerability," as originally placed for sale on eBay as item number 7203336538.
21674| [CVE-2005-3981] ** DISPUTED ** NOTE: this issue has been disputed by third parties. Microsoft Windows XP, 2000, and 2003 allows local users to kill a writable process by using the CreateRemoteThread function with certain arguments on a process that has been opened using the OpenProcess function, possibly involving an invalid address for the start routine. NOTE: followup posts have disputed this issue, saying that if a user already has privileges to write to a process, then other functions could be called or the process could be terminated using PROCESS_TERMINATE.
21675| [CVE-2005-3945] The SynAttackProtect protection in Microsoft Windows 2003 before SP1 and Windows 2000 before SP4 with Update Roll-up uses a hash of predictable data, which allows remote attackers to cause a denial of service (CPU consumption) via a flood of SYN packets that produce identical hash values, which slows down the hash table lookups.
21676| [CVE-2005-3644] PNP_GetDeviceList (upnp_getdevicelist) in UPnP for Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 and earlier, allows remote attackers to cause a denial of service (memory consumption) via a DCE RPC request that specifies a large output buffer size, a variant of CVE-2006-6296, and a different vulnerability than CVE-2005-2120.
21677| [CVE-2005-3177] CHKDSK in Microsoft Windows 2000 before Update Rollup 1 for SP4, Windows XP, and Windows Server 2003, when running in fix mode, does not properly handle security descriptors if the master file table contains a large number of files or if the descriptors do not satisfy certain NTFS conventions, which could cause ACLs for some files to be reverted to less secure defaults, or cause security descriptors to be removed.
21678| [CVE-2005-3176] Microsoft Windows 2000 before Update Rollup 1 for SP4 does not record the IP address of a Windows Terminal Services client in a security log event if the client connects successfully, which could make it easier for attackers to escape detection.
21679| [CVE-2005-3175] Microsoft Windows 2000 before Update Rollup 1 for SP4 allows a local administrator to unlock a computer even if it has been locked by a domain administrator, which allows the local administrator to access the session as the domain administrator.
21680| [CVE-2005-3174] Microsoft Windows 2000 before Update Rollup 1 for SP4 allows users to log on to the domain, even when their password has expired, if the fully qualified domain name (FQDN) is 8 characters long.
21681| [CVE-2005-3173] Microsoft Windows 2000 before Update Rollup 1 for SP4 does not apply group policies if the user logs on using UPN credentials with a trailing dot, which prevents Windows 2000 from finding the correct domain controller and could allow the user to bypass intended restrictions.
21682| [CVE-2005-3172] The WideCharToMultiByte function in Microsoft Windows 2000 before Update Rollup 1 for SP4 does not properly convert strings with Japanese composite characters in the last character, which could prevent the string from being null terminated and lead to data corruption or enable buffer overflow attacks.
21683| [CVE-2005-3171] Microsoft Windows 2000 before Update Rollup 1 for SP4 records Event ID 1704 to indicate that Group Policy security settings were successfully updated, even when the processing fails such as when Ntuser.pol cannot be accessed, which could cause system administrators to believe that the system is compliant with the specified settings.
21684| [CVE-2005-3170] The LDAP client on Microsoft Windows 2000 before Update Rollup 1 for SP4 accepts certificates using LDAP Secure Sockets Layer (LDAPS) even when the Certificate Authority (CA) is not trusted, which could allow attackers to trick users into believing that they are accessing a trusted site.
21685| [CVE-2005-3169] Microsoft Windows 2000 before Update Rollup 1 for SP4, when the "audit directory service access" policy is enabled, does not record a 565 event message for File Delete Child operations on an Active Directory object in the security event log, which could allow attackers to conduct unauthorized activities without detection.
21686| [CVE-2005-3168] The SECEDIT command on Microsoft Windows 2000 before Update Rollup 1 for SP4, when using a security template to set Access Control Lists (ACLs) on folders, does not apply ACLs on folders that are listed after a long folder entry, which could result in less secure permissions than specified by the template.
21687| [CVE-2005-2122] Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to execute arbitrary commands via a shortcut (.lnk) file with long font properties that lead to a buffer overflow in the Client/Server Runtime Server Subsystem (CSRSS), a different vulnerability than CVE-2005-2118.
21688| [CVE-2005-2120] Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of "\" (backslash) characters in a registry key name, which triggers the overflow in a wsprintfW function call.
21689| [CVE-2005-2118] Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote user-assisted attackers to execute arbitrary commands via a crafted shortcut (.lnk) file with long font properties that lead to a buffer overflow when the user views the file's properties using Windows Explorer, a different vulnerability than CVE-2005-2122.
21690| [CVE-2005-2117] Web View in Windows Explorer on Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 does not properly handle certain HTML characters in preview fields, which allows remote user-assisted attackers to execute arbitrary code.
21691| [CVE-2005-1985] The Client Service for NetWare (CSNW) on Microsoft Windows 2000 SP4, XP SP1 and Sp2, and Server 2003 SP1 and earlier, allows remote attackers to execute arbitrary code due to an "unchecked buffer" when processing certain crafted network messages.
21692| [CVE-2005-1984] Buffer overflow in the Print Spooler service (Spoolsv.exe) for Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via a malicious message.
21693| [CVE-2005-1983] Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1 allows remote attackers to execute arbitrary code via a crafted packet, and local users to gain privileges via a malicious application, as exploited by the Zotob (aka Mytob) worm.
21694| [CVE-2005-1982] Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.
21695| [CVE-2005-1981] Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message.
21696| [CVE-2005-1907] The ISA Firewall service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (Wspsrv.exe crash) via a large amount of SecureNAT network traffic.
21697| [CVE-2005-1683] Buffer overflow in winword.exe 10.2627.6714 and earlier in Microsoft Word for the Macintosh, before SP3 for Word 2002, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted mcw file.
21698| [CVE-2005-1218] The Microsoft Windows kernel in Microsoft Windows 2000 Server, Windows XP, and Windows Server 2003 allows remote attackers to cause a denial of service (crash) via crafted Remote Desktop Protocol (RDP) requests.
21699| [CVE-2005-1216] Microsoft ISA Server 2000 allows remote attackers to connect to services utilizing the NetBIOS protocol via a NetBIOS connection with an ISA Server that uses the NetBIOS (all) predefined packet filter.
21700| [CVE-2005-1215] Microsoft ISA Server 2000 allows remote attackers to poison the ISA cache or bypass content restriction policies via a malformed HTTP request packet containing multiple Content-Length headers.
21701| [CVE-2005-1208] Integer overflow in Microsoft Windows 98, 2000, XP SP2 and earlier, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via a crafted compiled Help (.CHM) file with a large size field that triggers a heap-based buffer overflow, as demonstrated using a "ms-its:" URL in Internet Explorer.
21702| [CVE-2005-1207] Buffer overflow in the Web Client service in Microsoft Windows XP and Windows Server 2003 allows remote authenticated users to execute arbitrary code via a crafted WebDAV request containing special parameters.
21703| [CVE-2005-1206] Buffer overflow in the Server Message Block (SMB) functionality for Microsoft Windows 2000, XP SP1 and SP2, and Server 2003 and SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka the "Server Message Block Vulnerability."
21704| [CVE-2005-1205] The Telnet client for Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX allows remote attackers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.
21705| [CVE-2005-1052] Microsoft Outlook 2003 and Outlook Web Access (OWA) 2003 do not properly display comma separated addresses in the From field in an e-mail message, which could allow remote attackers to spoof e-mail addresses.
21706| [CVE-2005-0921] Microsoft Outlook 2002 Connector for IBM Lotus Domino 2.0 allows local users to save passwords and login credentials locally, even when password caching is disabled by a group policy.
21707| [CVE-2005-0820] Microsoft Office InfoPath 2003 SP1 includes sensitive information in the Manifest.xsf file in a custom .xsn form, which allows attackers to obtain printer and network information, obtain the database name, username, and password, or obtain the internal web server name.
21708| [CVE-2005-0738] Stack consumption vulnerability in Microsoft Exchange Server 2003 SP1 allows users to cause a denial of service (hang) by deleting or moving a folder with deeply nested subfolders, which causes Microsoft Exchange Information Store service (Store.exe) to hang as a result of a large number of recursive calls.
21709| [CVE-2005-0564] Stack-based buffer overflow in Microsoft Word 2000 and Word 2002, and Microsoft Works Suites 2000 through 2004, might allow remote attackers to execute arbitrary code via a .doc file with long font information.
21710| [CVE-2005-0558] Buffer overflow in Microsoft Word 2000, Word 2002, and Word 2003 allows remote attackers to execute arbitrary code via a crafted document.
21711| [CVE-2005-0551] Stack-based buffer overflow in WINSRV.DLL in the Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application that provides console window information with a long FaceName value.
21712| [CVE-2005-0550] Buffer overflow in Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to cause a denial of service (i.e., system crash) via a malformed request, aka "Object Management Vulnerability".
21713| [CVE-2005-0545] Microsoft Windows XP Pro SP2 and Windows 2000 Server SP4 running Active Directory allow local users to bypass group policies that restrict access to hidden drives by using the browse feature in Office 10 applications such as Word or Excel, or using a flash drive. NOTE: this issue has been disputed in a followup post.
21714| [CVE-2005-0063] The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.
21715| [CVE-2005-0061] The kernel of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via certain access requests.
21716| [CVE-2005-0060] Buffer overflow in the font processing component of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application.
21717| [CVE-2005-0059] Buffer overflow in the Message Queuing component of Microsoft Windows 2000 and Windows XP SP1 allows remote attackers to execute arbitrary code via a crafted message.
21718| [CVE-2005-0058] Buffer overflow in the Telephony Application Programming Interface (TAPI) for Microsoft Windows 98, Windows 98 SE, Windows ME, Windows 2000, Windows XP, and Windows Server 2003 allows attackers elevate privileges or execute arbitrary code via a crafted message.
21719| [CVE-2005-0048] Microsoft Windows XP SP2 and earlier, 2000 SP3 and SP4, Server 2003, and older operating systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IP packets with malformed options, aka the "IP Validation Vulnerability."
21720| [CVE-2004-2527] The local and remote desktop login screens in Microsoft Windows XP before SP2 and 2003 allow remote attackers to cause a denial of service (CPU and memory consumption) by repeatedly using the WinKey+"U" key combination, which causes multiple copies of Windows Utility Manager to be loaded more quickly than they can be closed when the copies detect that another instance is running.
21721| [CVE-2004-2482] Microsoft Outlook 2000 and 2003, when configured to use Microsoft Word 2000 or 2003 as the e-mail editor and when forwarding e-mail, does not properly handle an opening OBJECT tag that does not have a closing OBJECT tag, which causes Outlook to automatically download the URI in the data property of the OBJECT tag and might allow remote attackers to execute arbitrary code.
21722| [CVE-2004-2365] Memory leak in Microsoft Windows XP and Windows Server 2003 allows local users to cause a denial of service (memory exhaustion) by repeatedly creating and deleting directories using a non-standard tool such as smbmount.
21723| [CVE-2004-2339] ** DISPUTED ** Microsoft Windows 2000, XP, and possibly 2003 allows local users with the SeDebugPrivilege privilege to execute arbitrary code as kernel and read or write kernel memory via the NtSystemDebugControl function, which does not verify its pointer arguments. Note: this issue has been disputed, since Administrator privileges are typically required to exploit this issue, thus privilege boundaries are not crossed.
21724| [CVE-2004-1080] The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42, aka the "Association Context Vulnerability."
21725| [CVE-2004-0963] Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause a denial of service (application exception) and possibly execute arbitrary code in winword.exe via certain unexpected values in a .doc file, including (1) an offset that triggers an out-of-bounds memory access, (2) a certain value that causes a large memory copy as triggered by an integer conversion error, and other values.
21726| [CVE-2004-0897] The Indexing Service for Microsoft Windows XP and Server 2003 does not properly validate the length of a message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.
21727| [CVE-2004-0892] Microsoft Proxy Server 2.0 and Microsoft ISA Server 2000 (which is included in Small Business Server 2000 and Small Business Server 2003 Premium Edition) allows remote attackers to spoof trusted Internet content on a specially crafted webpage via spoofed reverse DNS lookup results.
21728| [CVE-2004-0846] Unknown vulnerability in Microsoft Excel 2000, 2002, 2001 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via a malicious file containing certain parameters that are not properly validated.
21729| [CVE-2004-0840] The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows Server 2003 64-bit Edition, and the Exchange Routing Engine component of Exchange Server 2003, allows remote attackers to execute arbitrary code via a malicious DNS response message containing length values that are not properly validated.
21730| [CVE-2004-0728] The Remote Control Client service in Microsoft's Systems Management Server (SMS) 2.50.2726.0 allows remote attackers to cause a denial of service (crash) via a data packet to TCP port 2702 that causes the server to read or write to an invalid memory address.
21731| [CVE-2004-0726] The Windows Media Player control in Microsoft Windows 2000 allows remote attackers to execute arbitrary script in the local computer zone via an ASX filename that contains javascript, which is executed in the local context in a preview panel.
21732| [CVE-2004-0575] Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit Edition allows remote attackers to execute arbitrary code via compressed (zipped) folders that involve an "unchecked buffer" and improper length validation.
21733| [CVE-2004-0574] The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an "unchecked buffer," leading to off-by-one and heap-based buffer overflows.
21734| [CVE-2004-0573] Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website.
21735| [CVE-2004-0540] Microsoft Windows 2000, when running in a domain whose Fully Qualified Domain Name (FQDN) is exactly 8 characters long, does not prevent users with expired passwords from logging on to the domain.
21736| [CVE-2004-0503] Microsoft Outlook 2003 allows remote attackers to bypass the default zone restrictions and execute script within media files via a Rich Text Format (RTF) message containing an OLE object for the Windows Media Player, which bypasses Media Player's setting to disallow scripting and may lead to unprompted installation of an executable when exploited in conjunction with predictable-file-location exposures such as CVE-2004-0502.
21737| [CVE-2004-0379] Multiple cross-site scripting (XSS) vulnerabilities in Microsoft SharePoint Portal Server 2001 allow remote attackers to process arbitrary web content and steal cookies via certain server scripts.
21738| [CVE-2004-0284] Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if "Do not save encrypted pages to disk" is disabled, via a web site or HTML e-mail that contains two null characters (%00) after the host name.
21739| [CVE-2004-0214] Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.
21740| [CVE-2004-0211] The kernel for Microsoft Windows Server 2003 does not reset certain values in CPU data structures, which allows local users to cause a denial of service (system crash) via a malicious program.
21741| [CVE-2004-0210] The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.
21742| [CVE-2004-0209] Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats that involve "an unchecked buffer."
21743| [CVE-2004-0208] The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions.
21744| [CVE-2004-0207] "Shatter" style vulnerability in the Window Management application programming interface (API) for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to gain privileges by using certain API functions to change properties of privileged programs using the SetWindowLong and SetWIndowLongPtr API functions.
21745| [CVE-2004-0206] Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow.
21746| [CVE-2004-0204] Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and other products, allows remote attackers to read and delete arbitrary files via ".." sequences in the dynamicimag argument to crystalimagehandler.aspx.
21747| [CVE-2004-0202] IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.
21748| [CVE-2004-0201] Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.
21749| [CVE-2004-0199] Help and Support Center in Microsoft Windows XP and Windows Server 2003 SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code, as demonstrated using certain hcp:// URLs that access the DVD Upgrade capability (dvdupgrd.htm).
21750| [CVE-2004-0124] The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability."
21751| [CVE-2004-0121] Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.
21752| [CVE-2004-0120] The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages.
21753| [CVE-2004-0116] An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field.
21754| [CVE-2003-1378] Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs via an HTML email with the CODEBASE parameter set to the program, a vulnerability similar to CAN-2002-0077.
21755| [CVE-2003-1106] The SMTP service in Microsoft Windows 2000 before SP4 allows remote attackers to cause a denial of service (crash or hang) via an e-mail message with a malformed time stamp in the FILETIME attribute.
21756| [CVE-2003-0908] The Utility Manager in Microsoft Windows 2000 executes winhlp32.exe with system privileges, which allows local users to execute arbitrary code via a "Shatter" style attack using a Windows message that accesses the context sensitive help button in the GUI, as demonstrated using the File Open dialog in the Help window, a different vulnerability than CVE-2004-0213.
21757| [CVE-2003-0906] Buffer overflow in the rendering for (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1 allows remote attackers to execute arbitrary code via a malformed WMF or EMF image.
21758| [CVE-2003-0904] Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reuse HTTP connections, which can cause OWA users to view mailboxes of other users when Kerberos has been disabled as an authentication method for IIS 6.0, e.g. when SharePoint Services 2.0 is installed.
21759| [CVE-2003-0839] Directory traversal vulnerability in the "Shell Folders" capability in Microsoft Windows Server 2003 allows remote attackers to read arbitrary files via .. (dot dot) sequences in a "shell:" link.
21760| [CVE-2003-0825] The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code.
21761| [CVE-2003-0824] Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.
21762| [CVE-2003-0822] Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to execute arbitrary code via a crafted chunked encoded request.
21763| [CVE-2003-0821] Microsoft Excel 97, 2000, and 2002 allows remote attackers to execute arbitrary code via a spreadsheet with a malicious XLM (Excel 4) macro that bypasses the macro security model.
21764| [CVE-2003-0820] Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.
21765| [CVE-2003-0819] Buffer overflow in the H.323 filter of Microsoft Internet Security and Acceleration Server 2000 allows remote attackers to execute arbitrary code in the Microsoft Firewall Service via certain H.323 traffic, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.
21766| [CVE-2003-0818] Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.
21767| [CVE-2003-0807] Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a crafted request.
21768| [CVE-2003-0806] Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1, when a member of a domain, allows remote attackers to execute arbitrary code.
21769| [CVE-2003-0719] Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets.
21770| [CVE-2003-0665] Buffer overflow in the ActiveX control for Microsoft Access Snapshot Viewer for Access 97, 2000, and 2002 allows remote attackers to execute arbitrary code via long parameters to the control.
21771| [CVE-2003-0664] Microsoft Word 2002, 2000, 97, and 98(J) does not properly check certain properties of a document, which allows attackers to bypass the macro security model and automatically execute arbitrary macros via a malicious document.
21772| [CVE-2003-0662] Buffer overflow in Troubleshooter ActiveX Control (Tshoot.ocx) in Microsoft Windows 2000 SP4 and earlier allows remote attackers to execute arbitrary code via an HTML document with a long argument to the RunQuery2 method.
21773| [CVE-2003-0660] The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to download and install ActiveX controls when the system is low on memory, which could allow remote attackers execute arbitrary code without user approval.
21774| [CVE-2003-0533] Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.
21775| [CVE-2003-0526] Cross-site scripting (XSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to inject arbitrary web script via a URL containing the script in the domain name portion, which is not properly cleansed in the default error pages (1) 500.htm for "500 Internal Server error" or (2) 404.htm for "404 Not Found."
21776| [CVE-2003-0506] Microsoft NetMeeting 3.01 2000 before SP4 allows remote attackers to cause a denial of service (shutdown of NetMeeting conference) via malformed packets, as demonstrated via the chat conversation.
21777| [CVE-2003-0505] Directory traversal vulnerability in Microsoft NetMeeting 3.01 2000 before SP4 allows remote attackers to read arbitrary files via "..\.." (dot dot) sequences in a file transfer request.
21778| [CVE-2003-0496] Microsoft SQL Server before Windows 2000 SP4 allows local users to gain privileges as the SQL Server user by calling the xp_fileexist extended stored procedure with a named pipe as an argument instead of a normal file.
21779| [CVE-2003-0352] Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message, as exploited by the Blaster/MSblast/LovSAN and Nachi/Welchia worms.
21780| [CVE-2003-0345] Buffer overflow in the SMB capability for Microsoft Windows XP, 2000, and NT allows remote attackers to cause a denial of service and possibly execute arbitrary code via an SMB packet that specifies a smaller buffer length than is required.
21781| [CVE-2003-0232] Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local Procedure Calls (LPC) port that leads to a buffer overflow.
21782| [CVE-2003-0231] Microsoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial of service (crash or hang) via a long request to a named pipe.
21783| [CVE-2003-0230] Microsoft SQL Server 7, 2000, and MSDE allows local users to gain privileges by hijacking a named pipe during the authentication of another user, aka the "Named Pipe Hijacking" vulnerability.
21784| [CVE-2003-0227] The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft Windows NT 4.0 and 2000, nsiislog.dll, allows remote attackers to cause a denial of service in Internet Information Server (IIS) and execute arbitrary code via a certain network request.
21785| [CVE-2003-0118] SQL injection vulnerability in the Document Tracking and Administration (DTA) website of Microsoft BizTalk Server 2000 and 2002 allows remote attackers to execute operating system commands via a request to (1) rawdocdata.asp or (2) RawCustomSearchField.asp containing an embedded SQL statement.
21786| [CVE-2003-0117] Buffer overflow in the HTTP receiver function (BizTalkHTTPReceive.dll ISAPI) of Microsoft BizTalk Server 2002 allows attackers to execute arbitrary code via a certain request to the HTTP receiver.
21787| [CVE-2003-0110] The Winsock Proxy service in Microsoft Proxy Server 2.0 and the Microsoft Firewall service in Internet Security and Acceleration (ISA) Server 2000 allow remote attackers to cause a denial of service (CPU consumption or packet storm) via a spoofed, malformed packet to UDP port 1745.
21788| [CVE-2003-0109] Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0.
21789| [CVE-2003-0011] Unknown vulnerability in the DNS intrusion detection application filter for Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (blocked traffic to DNS servers) via a certain type of incoming DNS request that is not properly handled.
21790| [CVE-2003-0007] Microsoft Outlook 2002 does not properly handle requests to encrypt email messages with V1 Exchange Server Security certificates, which causes Outlook to send the email in plaintext, aka "Flaw in how Outlook 2002 handles V1 Exchange Server Security Certificates could lead to Information Disclosure."
21791| [CVE-2003-0003] Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter information.
21792| [CVE-2003-0002] Cross-site scripting vulnerability (XSS) in ManualLogin.asp script for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary script via the REASONTXT parameter.
21793| [CVE-2002-2101] Microsoft Outlook 2002 allows remote attackers to execute arbitrary JavaScript code, even when scripting is disabled, via an "about:" or "javascript:" URI in the href attribute of an "a" tag.
21794| [CVE-2002-2100] Microsoft Outlook 2002 allows remote attackers to embed bypass the file download restrictions for attachments via an HTML email message that uses an IFRAME to reference malicious content.
21795| [CVE-2002-1984] Microsoft Internet Explorer 5.0.1 through 6.0 on Windows 2000 or Windows XP allows remote attackers to cause a denial of service (crash) via an OBJECT tag that contains a crafted CLASSID (CLSID) value of "CLSID:00022613-0000-0000-C000-000000000046".
21796| [CVE-2002-1981] Microsoft SQL Server 2000 through SQL Server 2000 SP2 allows the "public" role to execute the (1) sp_MSSetServerProperties or (2) sp_MSsetalertinfo stored procedures, which allows attackers to modify configuration including SQL server startup and alert settings.
21797| [CVE-2002-1933] The terminal services screensaver for Microsoft Windows 2000 does not automatically lock the terminal window if the window is minimized, which could allow local users to gain access to the terminal server window.
21798| [CVE-2002-1932] Microsoft Windows XP and Windows 2000, when configured to send administrative alerts and the "Do not overwrite events (clear log manually)" option is set, does not notify the administrator when the log reaches its maximum size, which allows local users and remote attackers to avoid detection.
21799| [CVE-2002-1876] Microsoft Exchange 2000 allows remote authenticated attackers to cause a denial of service via a large number of rapid requests, which consumes all of the licenses that are granted to Exchange by IIS.
21800| [CVE-2002-1873] Microsoft Exchange 2000, when used with Microsoft Remote Procedure Call (MSRPC), allows remote attackers to cause a denial of service (crash or memory consumption) via malformed MSRPC calls.
21801| [CVE-2002-1872] Microsoft SQL Server 6.0 through 2000, with SQL Authentication enabled, uses weak password encryption (XOR), which allows remote attackers to sniff and decrypt the password.
21802| [CVE-2002-1776] ** DISPUTED ** NOTE: this issue has been disputed by the vendor. Symantec Norton AntiVirus 2002 allows remote attackers to bypass virus protection via a Word Macro virus with a .nch or .dbx extension, which is automatically recognized and executed as a Microsoft Office document. NOTE: the vendor has disputed this issue, acknowledging that the initial scan is bypassed, but the Office plug-in would detect the virus before it is executed.
21803| [CVE-2002-1712] Microsoft Windows 2000 allows remote attackers to cause a denial of service (memory consumption) by sending a flood of empty TCP/IP packets with the ACK and FIN bits set to the NetBIOS port (TCP/139), as demonstrated by stream3.
21804| [CVE-2002-1256] The SMB signing capability in the Server Message Block (SMB) protocol in Microsoft Windows 2000 and Windows XP allows attackers to disable the digital signing settings in an SMB session to force the data to be sent unsigned, then inject data into the session without detection, e.g. by modifying group policy information sent from a domain controller.
21805| [CVE-2002-1255] Microsoft Outlook 2002 allows remote attackers to cause a denial of service (repeated failure) via an email message with a certain invalid header field that is accessed using POP3, IMAP, or WebDAV, aka "E-mail Header Processing Flaw Could Cause Outlook 2002 to Fail."
21806| [CVE-2002-1214] Buffer overflow in Microsoft PPTP Service on Windows XP and Windows 2000 allows remote attackers to cause a denial of service (hang) and possibly execute arbitrary code via a certain PPTP packet with malformed control data.
21807| [CVE-2002-1184] The system root folder of Microsoft Windows 2000 has default permissions of Everyone group with Full access (Everyone:F) and is in the search path when locating programs during login or application launch from the desktop, which could allow attackers to gain privileges as other users via Trojan horse programs.
21808| [CVE-2002-1145] The xp_runwebtask stored procedure in the Web Tasks component of Microsoft SQL Server 7.0 and 2000, Microsoft Data Engine (MSDE) 1.0, and Microsoft Desktop Engine (MSDE) 2000 can be executed by PUBLIC, which allows an attacker to gain privileges by updating a webtask that is owned by the database owner through the msdb.dbo.mswebtasks table, which does not have strong permissions.
21809| [CVE-2002-1141] An input validation error in the Sun Microsystems RPC library Services for Unix 3.0 Interix SD, as implemented on Microsoft Windows NT4, 2000, and XP, allows remote attackers to cause a denial of service via malformed fragmented RPC client packets, aka "Denial of service by sending an invalid RPC request."
21810| [CVE-2002-1140] The Sun Microsystems RPC library Services for Unix 3.0 Interix SD, as implemented on Microsoft Windows NT4, 2000, and XP, allows remote attackers to cause a denial of service (service hang) via malformed packet fragments, aka "Improper parameter size check leading to denial of service."
21811| [CVE-2002-1138] Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, writes output files for scheduled jobs under its own privileges instead of the entity that launched it, which allows attackers to overwrite system files, aka "Flaw in Output File Handling for Scheduled Jobs."
21812| [CVE-2002-1137] Buffer overflow in the Database Console Command (DBCC) that handles user inputs in Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, allows attackers to execute arbitrary code via a long SourceDB argument in a "non-SQL OLEDB data source" such as FoxPro, a variant of CAN-2002-0644.
21813| [CVE-2002-1123] Buffer overflow in the authentication function for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows remote attackers to execute arbitrary code via a long request to TCP port 1433, aka the "Hello" overflow.
21814| [CVE-2002-1117] Veritas Backup Exec 8.5 and earlier requires that the "RestrictAnonymous" registry key for Microsoft Exchange 2000 must be set to 0, which enables anonymous listing of the SAM database and shares.
21815| [CVE-2002-1056] Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary scripts via an email that the user forwards or replies to.
21816| [CVE-2002-0982] Microsoft SQL Server 2000 SP2, when configured as a distributor, allows attackers to execute arbitrary code via the @scriptfile parameter to the sp_MScopyscript stored procedure.
21817| [CVE-2002-0975] Buffer overflow in Microsoft DirectX Files Viewer ActiveX control (xweb.ocx) 2.0.6.15 and earlier allows remote attackers to execute arbitrary via a long File parameter.
21818| [CVE-2002-0863] Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka "Weak Encryption in RDP Protocol."
21819| [CVE-2002-0861] Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to bypass the "Allow paste operations via script" setting, even when it is disabled, via the (1) Copy method of the Cell object or (2) the Paste method of the Range object.
21820| [CVE-2002-0860] The LoadText method in the spreadsheet component in Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to read arbitrary files through Internet Explorer via a URL that redirects to the target file.
21821| [CVE-2002-0859] Buffer overflow in the OpenDataSource function of the Jet engine on Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code.
21822| [CVE-2002-0729] Microsoft SQL Server 2000 allows remote attackers to cause a denial of service via a malformed 0x08 packet that is missing a colon separator.
21823| [CVE-2002-0727] The Host function in Microsoft Office Web Components (OWC) 2000 and 2002 is exposed in components that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via the setTimeout method.
21824| [CVE-2002-0724] Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows attackers to cause a denial of service (crash) via a SMB_COM_TRANSACTION packet with a request for the (1) NetShareEnum, (2) NetServerEnum2, or (3) NetServerEnum3, aka "Unchecked Buffer in Network Share Provider Can Lead to Denial of Service".
21825| [CVE-2002-0721] Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could allow unprivileged users, and possibly remote attackers, to run stored procedures with administrator privileges via (1) xp_execresultset, (2) xp_printstatements, or (3) xp_displayparamstmt.
21826| [CVE-2002-0719] SQL injection vulnerability in the function that services for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary commands via an MCMS resource request for image files or other files.
21827| [CVE-2002-0718] Web authoring command in Microsoft Content Management Server (MCMS) 2001 allows attackers to authenticate and upload executable content, by modifying the upload location, aka "Program Execution via MCMS Authoring Function."
21828| [CVE-2002-0700] Buffer overflow in a system function that performs user authentication for Microsoft Content Management Server (MCMS) 2001 allows attackers to execute code in the Local System context by authenticating to a web page that calls the function, aka "Unchecked Buffer in MDAC Function Could Enable SQL Server Compromise."
21829| [CVE-2002-0699] Unknown vulnerability in the Certificate Enrollment ActiveX Control in Microsoft Windows 98, Windows 98 Second Edition, Windows Millennium, Windows NT 4.0, Windows 2000, and Windows XP allow remote attackers to delete digital certificates on a user's system via HTML.
21830| [CVE-2002-0695] Buffer overflow in the Transact-SQL (T-SQL) OpenRowSet component of Microsoft Data Access Components (MDAC) 2.5 through 2.7 for SQL Server 7.0 or 2000 allows remote attackers to execute arbitrary code via a query that calls the OpenRowSet command.
21831| [CVE-2002-0694] The HTML Help facility in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP uses the Local Computer Security Zone when opening .chm files from the Temporary Internet Files folder, which allows remote attackers to execute arbitrary code via HTML mail that references or inserts a malicious .chm file containing shortcuts that can be executed, aka "Code Execution via Compiled HTML Help File."
21832| [CVE-2002-0693] Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute code via (1) a long parameter to the Alink function, or (2) script containing a long argument to the showHelp function.
21833| [CVE-2002-0692] Buffer overflow in SmartHTML Interpreter (shtml.dll) in Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to cause a denial of service (CPU consumption) or run arbitrary code, respectively, via a certain type of web file request.
21834| [CVE-2002-0650] The keep-alive mechanism for Microsoft SQL Server 2000 allows remote attackers to cause a denial of service (bandwidth consumption) via a "ping" style packet to the Resolution Service (UDP port 1434) with a spoofed IP address of another SQL Server system, which causes the two servers to exchange packets in an infinite loop.
21835| [CVE-2002-0649] Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSDE) allow remote attackers to cause a denial of service or execute arbitrary code via UDP packets to port 1434 in which (1) a 0x04 byte that causes the SQL Monitor thread to generate a long registry key name, or (2) a 0x08 byte with a long string causes heap corruption, as exploited by the Slammer/Sapphire worm.
21836| [CVE-2002-0645] SQL injection vulnerability in stored procedures for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 may allow authenticated users to execute arbitrary commands.
21837| [CVE-2002-0644] Buffer overflow in several Database Consistency Checkers (DBCCs) for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows members of the db_owner and db_ddladmin roles to execute arbitrary code.
21838| [CVE-2002-0643] The installation of Microsoft Data Engine 1.0 (MSDE 1.0), and Microsoft SQL Server 2000 creates setup.iss files with insecure permissions and does not delete them after installation, which allows local users to obtain sensitive data, including weakly encrypted passwords, to gain privileges, aka "SQL Server Installation Process May Leave Passwords on System."
21839| [CVE-2002-0642] The registry key containing the SQL Server service account information in Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, has insecure permissions, which allows local users to gain privileges, aka "Incorrect Permission on SQL Server Service Account Registry Key."
21840| [CVE-2002-0641] Buffer overflow in bulk insert procedure of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows attackers with database administration privileges to execute arbitrary code via a long filename in the BULK INSERT query.
21841| [CVE-2002-0624] Buffer overflow in the password encryption function of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows remote attackers to gain control of the database and execute arbitrary code via SQL Server Authentication, aka "Unchecked Buffer in Password Encryption Procedure."
21842| [CVE-2002-0623] Buffer overflow in AuthFilter ISAPI filter on Microsoft Commerce Server 2000 and 2002 allows remote attackers to execute arbitrary code via long authentication data, aka "New Variant of the ISAPI Filter Buffer Overrun".
21843| [CVE-2002-0622] The Office Web Components (OWC) package installer for Microsoft Commerce Server 2000 allows remote attackers to execute commands by passing the commands as input to the OWC package installer, aka "OWC Package Command Execution".
21844| [CVE-2002-0621] Buffer overflow in the Office Web Components (OWC) package installer used by Microsoft Commerce Server 2000 allows remote attackers to cause the process to fail or run arbitrary code in the LocalSystem security context via certain input to the OWC package installer.
21845| [CVE-2002-0620] Buffer overflow in the Profile Service of Microsoft Commerce Server 2000 allows remote attackers to cause the server to fail or run arbitrary code in the LocalSystem security context via an input field using an affected API.
21846| [CVE-2002-0619] The Mail Merge Tool in Microsoft Word 2002 for Windows, when Microsoft Access is present on a system, allows remote attackers to execute Visual Basic (VBA) scripts within a mail merge document that is saved in HTML format, aka a "Variant of MS00-071, Word Mail Merge Vulnerability" (CVE-2000-0788).
21847| [CVE-2002-0618] The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code in the Local Computer zone by embedding HTML scripts within an Excel workbook that contains an XSL stylesheet, aka "Excel XSL Stylesheet Script Execution".
21848| [CVE-2002-0617] The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code by creating a hyperlink on a drawing shape in a source workbook that points to a destination workbook containing an autoexecute macro, aka "Hyperlinked Excel Workbook Macro Bypass."
21849| [CVE-2002-0616] The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code by attaching an inline macro to an object within an Excel workbook, aka the "Excel Inline Macros Vulnerability."
21850| [CVE-2002-0597] LANMAN service on Microsoft Windows 2000 allows remote attackers to cause a denial of service (CPU/memory exhaustion) via a stream of malformed data to microsoft-ds port 445.
21851| [CVE-2002-0444] Microsoft Windows 2000 running the Terminal Server 90-day trial version, and possibly other versions, does not apply group policies to incoming users when the number of connections to the SYSVOL share exceeds the maximum, e.g. with a maximum number of licenses, which can allow remote authenticated users to bypass group policies.
21852| [CVE-2002-0443] Microsoft Windows 2000 allows local users to bypass the policy that prohibits reusing old passwords by changing the current password before it expires, which does not enable the check for previous passwords.
21853| [CVE-2002-0373] The Windows Media Device Manager (WMDM) Service in Microsoft Windows Media Player 7.1 on Windows 2000 systems allows local users to obtain LocalSystem rights via a program that calls the WMDM service to connect to an invalid local storage device, aka "Privilege Elevation through Windows Media Device Manager Service".
21854| [CVE-2002-0371] Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote attackers to execute arbitrary code via a gopher:// URL that redirects the user to a real or simulated gopher server that sends a long response.
21855| [CVE-2002-0368] The Store Service in Microsoft Exchange 2000 allows remote attackers to cause a denial of service (CPU consumption) via a mail message with a malformed RFC message attribute, aka "Malformed Mail Attribute can Cause Exchange 2000 to Exhaust CPU Resources."
21856| [CVE-2002-0224] The MSDTC (Microsoft Distributed Transaction Service Coordinator) for Microsoft Windows 2000, Microsoft IIS 5.0 and SQL Server 6.5 through SQL 2000 0.0 allows remote attackers to cause a denial of service (crash or hang) via malformed (random) input.
21857| [CVE-2002-0187] Cross-site scripting vulnerability in the SQLXML component of Microsoft SQL Server 2000 allows an attacker to execute arbitrary script via the root parameter as part of an XML SQL query, aka "Script Injection via XML Tag."
21858| [CVE-2002-0186] Buffer overflow in the SQLXML ISAPI extension of Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code via data queries with a long content-type parameter, aka "Unchecked Buffer in SQLXML ISAPI Extension."
21859| [CVE-2002-0154] Buffer overflows in extended stored procedures for Microsoft SQL Server 7.0 and 2000 allow remote attackers to cause a denial of service or execute arbitrary code via a database query with certain long arguments.
21860| [CVE-2002-0152] Buffer overflow in various Microsoft applications for Macintosh allows remote attackers to cause a denial of service (crash) or execute arbitrary code by invoking the file:// directive with a large number of / characters, which affects Internet Explorer 5.1, Outlook Express 5.0 through 5.0.2, Entourage v. X and 2001, PowerPoint v. X, 2001, and 98, and Excel v. X and 2001 for Macintosh.
21861| [CVE-2002-0055] SMTP service in Microsoft Windows 2000, Windows XP Professional, and Exchange 2000 allows remote attackers to cause a denial of service via a command with a malformed data transfer (BDAT) request.
21862| [CVE-2002-0054] SMTP service in (1) Microsoft Windows 2000 and (2) Internet Mail Connector (IMC) in Exchange Server 5.5 does not properly handle responses to NTLM authentication, which allows remote attackers to perform mail relaying via an SMTP AUTH command using null session credentials.
21863| [CVE-2002-0050] Buffer overflow in AuthFilter ISAPI filter on Microsoft Commerce Server 2000 allows remote attackers to execute arbitrary code via long authentication data.
21864| [CVE-2002-0049] Microsoft Exchange Server 2000 System Attendant gives "Everyone" group privileges to the WinReg key, which could allow remote attackers to read or modify registry keys.
21865| [CVE-2002-0034] The Microsoft CONVERT.EXE program, when used on Windows 2000 and Windows XP systems, does not apply the default NTFS permissions when converting a FAT32 file system, which could cause the conversion to produce a file system with less secure permissions than expected.
21866| [CVE-2002-0018] In Microsoft Windows NT and Windows 2000, a trusting domain that receives authorization information from a trusted domain does not verify that the trusted domain is authoritative for all listed SIDs, which allows remote attackers to gain Domain Administrator privileges on the trusting domain by injecting SIDs from untrusted domains into the authorization data that comes from from the trusted domain.
21867| [CVE-2001-1533] ** DISPUTED * Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets. NOTE: the vendor disputes this issue, saying that it requires high bandwidth to exploit, and the server does not experience any instability. Therefore this "laws of physics" issue might not be included in CVE.
21868| [CVE-2001-1451] Memory leak in the SNMP LAN Manager (LANMAN) MIB extension for Microsoft Windows 2000 before SP3, when the Print Spooler is not running, allows remote attackers to cause a denial of service (memory consumption) via a large number of GET or GETNEXT requests.
21869| [CVE-2001-1319] Microsoft Exchange 5.5 2000 allows remote attackers to cause a denial of service (hang) via exceptional BER encodings for the LDAP filter type field, as demonstrated by the PROTOS LDAPv3 test suite.
21870| [CVE-2001-1099] The default configuration of Norton AntiVirus for Microsoft Exchange 2000 2.x allows remote attackers to identify the recipient's INBOX file path by sending an email with an attachment containing malicious content, which includes the path in the rejection notice.
21871| [CVE-2001-0986] SQLQHit.asp sample file in Microsoft Index Server 2.0 allows remote attackers to obtain sensitive information such as the physical path, file attributes, or portions of source code by directly calling sqlqhit.asp with a CiScope parameter set to (1) webinfo, (2) extended_fileinfo, (3) extended_webinfo, or (4) fileinfo.
21872| [CVE-2001-0718] Vulnerability in (1) Microsoft Excel 2002 and earlier and (2) Microsoft PowerPoint 2002 and earlier allows attackers to bypass macro restrictions and execute arbitrary commands by modifying the data stream in the document.
21873| [CVE-2001-0666] Outlook Web Access (OWA) in Microsoft Exchange 2000 allows an authenticated user to cause a denial of service (CPU consumption) via a malformed OWA request for a deeply nested folder within the user's mailbox.
21874| [CVE-2001-0658] Cross-site scripting (CSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause other clients to execute certain script or read cookies via malicious script in an invalid URL that is not properly quoted in an error message.
21875| [CVE-2001-0628] Microsoft Word 2000 does not check AutoRecovery (.asd) files for macros, which allows a local attacker to execute arbitrary macros with the user ID of the Word user.
21876| [CVE-2001-0547] Memory leak in the proxy service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows local attackers to cause a denial of service (resource exhaustion).
21877| [CVE-2001-0546] Memory leak in H.323 Gatekeeper Service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (resource exhaustion) via a large amount of malformed H.323 data.
21878| [CVE-2001-0542] Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow attackers with access to SQL Server to execute arbitrary code through the functions (1) raiserror, (2) formatmessage, or (3) xp_sprintf. NOTE: the C runtime format string vulnerability reported in MS01-060 is identified by CVE-2001-0879.
21879| [CVE-2001-0538] Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTML e-mail message or web page.
21880| [CVE-2001-0509] Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs.
21881| [CVE-2001-0505] Multiple memory leaks in Microsoft Services for Unix 2.0 allow remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed requests to (1) the Telnet service, or (2) the NFS service.
21882| [CVE-2001-0504] Vulnerability in authentication process for SMTP service in Microsoft Windows 2000 allows remote attackers to use incorrect credentials to gain privileges and conduct activites such as mail relaying.
21883| [CVE-2001-0501] Microsoft Word 2002 and earlier allows attackers to automatically execute macros without warning the user by embedding the macros in a manner that escapes detection by the security scanner.
21884| [CVE-2001-0351] Microsoft Windows 2000 telnet service allows a local user to make a certain system call that allows the user to terminate a Telnet session and cause a denial of service.
21885| [CVE-2001-0350] Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the second of two variants of this vulnerability.
21886| [CVE-2001-0349] Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the first of two variants of this vulnerability.
21887| [CVE-2001-0348] Microsoft Windows 2000 telnet service allows attackers to cause a denial of service (crash) via a long logon command that contains a backspace.
21888| [CVE-2001-0347] Information disclosure vulnerability in Microsoft Windows 2000 telnet service allows remote attackers to determine the existence of user accounts such as Guest, or log in to the server without specifying the domain name, via a malformed userid.
21889| [CVE-2001-0346] Handle leak in Microsoft Windows 2000 telnet service allows attackers to cause a denial of service by starting a large number of sessions and terminating them.
21890| [CVE-2001-0345] Microsoft Windows 2000 telnet service allows attackers to prevent idle Telnet sessions from timing out, causing a denial of service by creating a large number of idle sessions.
21891| [CVE-2001-0344] An SQL query method in Microsoft SQL Server 2000 Gold and 7.0 using Mixed Mode allows local database users to gain privileges by reusing a cached connection of the sa administrator account.
21892| [CVE-2001-0340] An interaction between the Outlook Web Access (OWA) service in Microsoft Exchange 2000 Server and Internet Explorer allows attackers to execute malicious script code against a user's mailbox via a message attachment that contains HTML code, which is executed automatically.
21893| [CVE-2001-0261] Microsoft Windows 2000 Encrypted File System does not properly destroy backups of files that are encrypted, which allows a local attacker to recover the text of encrypted files.
21894| [CVE-2001-0245] Microsoft Index Server 2.0 in Windows NT 4.0, and Indexing Service in Windows 2000, allows remote attackers to read server-side include files via a malformed search request, aka a new variant of the "Malformed Hit-Highlighting" vulnerability.
21895| [CVE-2001-0244] Buffer overflow in Microsoft Index Server 2.0 allows remote attackers to execute arbitrary commands via a long search parameter.
21896| [CVE-2001-0240] Microsoft Word before Word 2002 allows attackers to automatically execute macros without warning the user via a Rich Text Format (RTF) document that links to a template with the embedded macro.
21897| [CVE-2001-0239] Microsoft Internet Security and Acceleration (ISA) Server 2000 Web Proxy allows remote attackers to cause a denial of service via a long web request with a specific type.
21898| [CVE-2001-0237] Memory leak in Microsoft 2000 domain controller allows remote attackers to cause a denial of service by repeatedly connecting to the Kerberos service and then disconnecting without sending any data.
21899| [CVE-2001-0146] IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly sending a series of specially formatted URL's.
21900| [CVE-2001-0048] The "Configure Your Server" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to install malicious programs, aka the "Directory Service Restore Mode Password" vulnerability.
21901| [CVE-2001-0005] Buffer overflow in the parsing mechanism of the file loader in Microsoft PowerPoint 2000 allows attackers to execute arbitrary commands.
21902| [CVE-2001-0003] Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials and possibly obtain the password, aka the "Web Client NTLM Authentication" vulnerability.
21903| [CVE-2000-1218] The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query, which allows remote attackers to poison the DNS cache.
21904| [CVE-2000-1217] Microsoft Windows 2000 before Service Pack 2 (SP2), when running in a non-Windows 2000 domain and using NTLM authentication, and when credentials of an account are locally cached, allows local users to bypass account lockout policies and make an unlimited number of login attempts, aka the "Domain Account Lockout" vulnerability.
21905| [CVE-2000-1209] The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq Insight Manager, and (6) Visio 2000, which allows remote attackers to gain privileges, as exploited by worms such as Voyager Alpha Force and Spida.
21906| [CVE-2000-1139] The installation of Microsoft Exchange 2000 before Rev. A creates a user account with a known password, which could allow attackers to gain privileges, aka the "Exchange User Account" vulnerability.
21907| [CVE-2000-1088] The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
21908| [CVE-2000-1087] The xp_proxiedmetadata function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
21909| [CVE-2000-1086] The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
21910| [CVE-2000-1085] The xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
21911| [CVE-2000-1079] Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote attackers to modify dynamic NetBIOS name cache entries via a spoofed Browse Frame Request in a unicast or UDP broadcast datagram.
21912| [CVE-2000-0942] The CiWebHitsFile component in Microsoft Indexing Services for Windows 2000 allows remote attackers to conduct a cross site scripting (CSS) attack via a CiRestriction parameter in a .htw request, aka the "Indexing Services Cross Site Scripting" vulnerability.
21913| [CVE-2000-0854] When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as riched20.dll and msi.dll, which could allow an attacker to execute arbitrary commands by inserting a Trojan Horse DLL into the same directory as the document.
21914| [CVE-2000-0771] Microsoft Windows 2000 allows local users to cause a denial of service by corrupting the local security policy via malformed RPC traffic, aka the "Local Security Policy Corruption" vulnerability.
21915| [CVE-2000-0765] Buffer overflow in the HTML interpreter in Microsoft Office 2000 allows an attacker to execute arbitrary commands via a long embedded object tag, aka the "Microsoft Office HTML Object Tag" vulnerability.
21916| [CVE-2000-0756] Microsoft Outlook 2000 does not properly process long or malformed fields in vCard (.vcf) files, which allows attackers to cause a denial of service.
21917| [CVE-2000-0710] The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers determine the physical path of the server components by requesting an invalid URL whose name includes a standard DOS device name.
21918| [CVE-2000-0709] The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to cause a denial of service in some components by requesting a URL whose name includes a standard DOS device name.
21919| [CVE-2000-0637] Microsoft Excel 97 and 2000 allows an attacker to execute arbitrary commands by specifying a malicious .dll using the Register.ID function, aka the "Excel REGISTER.ID Function" vulnerability.
21920| [CVE-2000-0621] Microsoft Outlook 98 and 2000, and Outlook Express 4.0x and 5.0x, allow remote attackers to read files on the client's system via a malformed HTML message that stores files outside of the cache, aka the "Cache Bypass" vulnerability.
21921| [CVE-2000-0597] Microsoft Office 2000 (Excel and PowerPoint) and PowerPoint 97 are marked as safe for scripting, which allows remote attackers to force Internet Explorer or some email clients to save files to arbitrary locations via the Visual Basic for Applications (VBA) SaveAs function, aka the "Office HTML Script" vulnerability.
21922| [CVE-2000-0331] Buffer overflow in Microsoft command processor (CMD.EXE) for Windows NT and Windows 2000 allows a local user to cause a denial of service via a long environment variable, aka the "Malformed Environment Variable" vulnerability.
21923| [CVE-2000-0277] Microsoft Excel 97 and 2000 does not warn the user when executing Excel Macro Language (XLM) macros in external text files, which could allow an attacker to execute a macro virus, aka the "XLM Text Macro" vulnerability.
21924| [CVE-2013-2557] The sandbox protection mechanism in Microsoft Internet Explorer 9 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, as demonstrated against Adobe Flash Player by VUPEN during a Pwn2Own competition at CanSecWest 2013.
21925| [CVE-2013-2556] Unspecified vulnerability in Microsoft Windows 7 allows attackers to bypass the ASLR protection mechanism via unknown vectors, as demonstrated against Adobe Flash Player by VUPEN during a Pwn2Own competition at CanSecWest 2013.
21926| [CVE-2013-2554] Unspecified vulnerability in Microsoft Windows 7 allows attackers to bypass the ASLR and DEP protection mechanisms via unknown vectors, as demonstrated against Firefox by VUPEN during a Pwn2Own competition at CanSecWest 2013, a different vulnerability than CVE-2013-0787.
21927| [CVE-2013-2553] Unspecified vulnerability in the kernel in Microsoft Windows 7 allows local users to gain privileges via unknown vectors, as demonstrated by Nils and Jon of MWR Labs during a Pwn2Own competition at CanSecWest 2013, a different vulnerability than CVE-2013-0912.
21928| [CVE-2013-2552] Unspecified vulnerability in Microsoft Internet Explorer 10 on Windows 8 allows remote attackers to bypass the sandbox protection mechanism by leveraging access to a Medium integrity process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013.
21929| [CVE-2013-2551] Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1308 and CVE-2013-1309.
21930| [CVE-2013-1347] Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly allocated or (2) is deleted, as exploited in the wild in May 2013.
21931| [CVE-2013-1305] HTTP.sys in Microsoft Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (infinite loop) via a crafted HTTP header, aka "HTTP.sys Denial of Service Vulnerability."
21932| [CVE-2013-1290] Microsoft SharePoint Server 2013, in certain configurations involving legacy My Sites, does not properly establish default access controls for a SharePoint list, which allows remote authenticated users to bypass intended restrictions on reading list items via a direct request for a list's location, aka "Incorrect Access Rights Information Disclosure Vulnerability."
21933| [CVE-2013-1289] Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1, Groove Server 2010 SP1, SharePoint Foundation 2010 SP1, and Office Web Apps 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted string, aka "HTML Sanitization Vulnerability."
21934| [CVE-2013-1284] Race condition in the kernel in Microsoft Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Kernel Race Condition Vulnerability."
21935| [CVE-2013-0096] Writer in Microsoft Windows Essentials 2011 and 2012 allows remote attackers to bypass proxy settings and overwrite arbitrary files via crafted URL parameters, aka "Windows Essentials Improper URI Handling Vulnerability."
21936| [CVE-2013-0086] Microsoft OneNote 2010 SP1 does not properly determine buffer sizes during memory allocation, which allows remote attackers to obtain sensitive information via a crafted OneNote file, aka "Buffer Size Validation Vulnerability."
21937| [CVE-2013-0085] Buffer overflow in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to cause a denial of service (W3WP process crash and site outage) via a crafted URL, aka "Buffer Overflow Vulnerability."
21938| [CVE-2013-0084] Directory traversal vulnerability in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to bypass intended read restrictions for content, and hijack user accounts, via a crafted URL, aka "SharePoint Directory Traversal Vulnerability."
21939| [CVE-2013-0083] Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via crafted content, leading to administrative command execution, aka "SharePoint XSS Vulnerability."
21940| [CVE-2013-0080] Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allow remote attackers to bypass intended read restrictions for content, and hijack user accounts, via a crafted URL, aka "Callback Function Vulnerability."
21941| [CVE-2013-0079] Microsoft Visio Viewer 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Visio file that triggers incorrect memory allocation, aka "Visio Viewer Tree Object Type Confusion Vulnerability."
21942| [CVE-2013-0005] The WCF Replace function in the Open Data (aka OData) protocol implementation in Microsoft .NET Framework 3.5, 3.5 SP1, 3.5.1, and 4, and the Management OData IIS Extension on Windows Server 2012, allows remote attackers to cause a denial of service (resource consumption and daemon restart) via crafted values in HTTP requests, aka "Replace Denial of Service Vulnerability."
21943| [CVE-2012-4969] Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site, as exploited in the wild in September 2012.
21944| [CVE-2012-4792] Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object, and exploited in the wild in December 2012.
21945| [CVE-2012-3456] Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in Calligra 2.4.3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ODF style in an ODF document. NOTE: this is the same vulnerability as CVE-2012-3455, but it was SPLIT by the CNA even though Calligra and KOffice share the same codebase.
21946| [CVE-2012-3455] Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in KOffice 2.3.3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ODF style in an ODF document. NOTE: this is the same vulnerability as CVE-2012-3456, but it was SPLIT by the CNA even though Calligra and KOffice share the same codebase.
21947| [CVE-2012-2290] The client in EMC NetWorker Module for Microsoft Applications (NMM) 2.2.1, 2.3 before build 122, and 2.4 before build 375 allows remote attackers to execute arbitrary code by sending a crafted message over a TCP communication channel.
21948| [CVE-2012-2284] The (1) install and (2) upgrade processes in EMC NetWorker Module for Microsoft Applications (NMM) 2.2.1, 2.3 before build 122, and 2.4 before build 375, when Exchange Server is used, allow local users to read cleartext administrator credentials via unspecified vectors.
21949| [CVE-2012-1945] Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allow local users to obtain sensitive information via an HTML document that loads a shortcut (aka .lnk) file for display within an IFRAME element, as demonstrated by a network share implemented by (1) Microsoft Windows or (2) Samba.
21950| [CVE-2012-1894] Microsoft Office for Mac 2011 uses world-writable permissions for the "Applications/Microsoft Office 2011/" directory and certain other directories, which allows local users to gain privileges by placing a Trojan horse executable file in one of these directories, aka "Office for Mac Improper Folder Permissions Vulnerability."
21951| [CVE-2012-1892] Cross-site scripting (XSS) vulnerability in Microsoft Visual Studio Team Foundation Server 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "XSS Vulnerability."
21952| [CVE-2012-1891] Heap-based buffer overflow in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2 and Windows Data Access Components (WDAC) 6.0 allows remote attackers to execute arbitrary code via crafted XML data that triggers access to an uninitialized object in memory, aka "ADO Cachesize Heap Overflow RCE Vulnerability."
21953| [CVE-2012-1888] Buffer overflow in Microsoft Visio 2010 SP1 and Visio Viewer 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Visio file, aka "Visio DXF File Format Buffer Overflow Vulnerability."
21954| [CVE-2012-1876] Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by attempting to access a nonexistent object, leading to a heap-based buffer overflow, aka "Col Element Remote Code Execution Vulnerability," as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012.
21955| [CVE-2012-1861] Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 Gold and SP1, SharePoint Foundation 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "SharePoint Script in Username Vulnerability."
21956| [CVE-2012-1859] Cross-site scripting (XSS) vulnerability in scriptresx.ashx in Microsoft SharePoint Server 2010 Gold and SP1, SharePoint Foundation 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "XSS scriptresx.ashx Vulnerability."
21957| [CVE-2012-1857] Cross-site scripting (XSS) vulnerability in the Enterprise Portal component in Microsoft Dynamics AX 2012 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Dynamics AX Enterprise Portal XSS Vulnerability."
21958| [CVE-2012-1849] Untrusted search path vulnerability in Microsoft Lync 2010, 2010 Attendee, and 2010 Attendant allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .ocsmeet file, aka "Lync Insecure Library Loading Vulnerability."
21959| [CVE-2012-1545] Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, allows remote attackers to bypass Protected Mode or cause a denial of service (memory corruption) by leveraging access to a Low integrity process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012.
21960| [CVE-2012-1436] The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \2D\6C\68 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.
21961| [CVE-2012-1435] The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \50\4B\4C\49\54\45 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.
21962| [CVE-2012-1434] The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \19\04\00\10 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.
21963| [CVE-2012-1433] The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \4a\46\49\46 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.
21964| [CVE-2012-0447] Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize data for image/vnd.microsoft.icon images, which allows remote attackers to obtain potentially sensitive information by reading a PNG image that was created through conversion from an ICO image.
21965| [CVE-2012-0147] Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 does not properly configure the default web site, which allows remote attackers to obtain sensitive information via a crafted HTTPS request, aka "Unfiltered Access to UAG Default Website Vulnerability."
21966| [CVE-2012-0146] Open redirect vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka "UAG Blind HTTP Redirect Vulnerability."
21967| [CVE-2012-0145] Cross-site scripting (XSS) vulnerability in wizardlist.aspx in Microsoft Office SharePoint Server 2010 Gold and SP1 and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in wizardlist.aspx Vulnerability."
21968| [CVE-2012-0144] Cross-site scripting (XSS) vulnerability in themeweb.aspx in Microsoft Office SharePoint Server 2010 Gold and SP1 and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in themeweb.aspx Vulnerability."
21969| [CVE-2012-0138] Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0019, CVE-2012-0020, CVE-2012-0136, and CVE-2012-0137.
21970| [CVE-2012-0137] Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0019, CVE-2012-0020, CVE-2012-0136, and CVE-2012-0138.
21971| [CVE-2012-0136] Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0019, CVE-2012-0020, CVE-2012-0137, and CVE-2012-0138.
21972| [CVE-2012-0020] Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0019, CVE-2012-0136, CVE-2012-0137, and CVE-2012-0138.
21973| [CVE-2012-0019] Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0020, CVE-2012-0136, CVE-2012-0137, and CVE-2012-0138.
21974| [CVE-2012-0018] Microsoft Visio Viewer 2010 Gold and SP1 does not properly validate attributes in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "VSD File Format Memory Corruption Vulnerability."
21975| [CVE-2012-0017] Cross-site scripting (XSS) vulnerability in inplview.aspx in Microsoft SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in inplview.aspx Vulnerability."
21976| [CVE-2011-4695] Unspecified vulnerability in Microsoft Windows 7 SP1, when Java is installed, allows local users to bypass Internet Explorer sandbox restrictions and gain privileges via unknown vectors, as demonstrated by the White Phosphorus wp_ie_sandbox_escape module for Immunity CANVAS. NOTE: as of 20111207, this disclosure has no actionable information. However, because the module author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.
21977| [CVE-2011-2012] Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 does not properly validate session cookies, which allows remote attackers to cause a denial of service (IIS outage) via unspecified network traffic, aka "Null Session Cookie Crash."
21978| [CVE-2011-2010] The Microsoft Office Input Method Editor (IME) for Simplified Chinese in Microsoft Pinyin IME 2010, Office Pinyin SimpleFast Style 2010, and Office Pinyin New Experience Style 2010 does not properly restrict access to configuration options, which allows local users to gain privileges via the Microsoft Pinyin (aka MSPY) IME toolbar, aka "Pinyin IME Elevation Vulnerability."
21979| [CVE-2011-1969] Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 provides the MicrosoftClient.jar file containing a signed Java applet, which allows remote attackers to execute arbitrary code on client machines via unspecified vectors, aka "Poisoned Cup of Code Execution Vulnerability."
21980| [CVE-2011-1897] Cross-site scripting (XSS) vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Default Reflected XSS Vulnerability."
21981| [CVE-2011-1896] Cross-site scripting (XSS) vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "ExcelTable Reflected XSS Vulnerability."
21982| [CVE-2011-1895] CRLF injection vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary HTTP headers, and conduct HTTP response splitting attacks and cross-site scripting (XSS) attacks, via unspecified vectors, aka "ExcelTable Response Splitting XSS Vulnerability."
21983| [CVE-2011-1891] Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in a request to a script, aka "Contact Details Reflected XSS Vulnerability."
21984| [CVE-2011-1890] Cross-site scripting (XSS) vulnerability in EditForm.aspx in Microsoft Office SharePoint Server 2010 and SharePoint Foundation 2010 allows remote attackers to inject arbitrary web script or HTML via a post, aka "Editform Script Injection Vulnerability."
21985| [CVE-2011-1889] The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute arbitrary code via vectors involving unspecified requests, aka "TMG Firewall Client Memory Corruption Vulnerability."
21986| [CVE-2011-1417] Integer overflow in QuickLook, as used in Apple Mac OS X before 10.6.7 and MobileSafari in Apple iOS before 4.2.7 and 4.3.x before 4.3.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a Microsoft Office document with a crafted size field in the OfficeArtMetafileHeader, related to OfficeArtBlip, as demonstrated on the iPhone by Charlie Miller and Dion Blazakis during a Pwn2Own competition at CanSecWest 2011.
21987| [CVE-2011-1347] Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to bypass Protected Mode and create arbitrary files by leveraging access to a Low integrity process, as demonstrated by Stephen Fewer as the third of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011.
21988| [CVE-2011-1346] Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors, as demonstrated by Stephen Fewer as the second of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011.
21989| [CVE-2011-1345] Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, as demonstrated by Stephen Fewer as the first of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011, aka "Object Management Memory Corruption Vulnerability."
21990| [CVE-2011-1265] The Bluetooth Stack 2.1 in Microsoft Windows Vista SP1 and SP2 and Windows 7 Gold and SP1 does not prevent access to objects in memory that (1) were not properly initialized or (2) have been deleted, which allows remote attackers to execute arbitrary code via crafted Bluetooth packets, aka "Bluetooth Stack Vulnerability."
21991| [CVE-2011-0653] Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2010 Gold and SP1, and SharePoint Foundation 2010, allows remote attackers to inject arbitrary web script or HTML via the URI, aka "XSS in SharePoint Calendar Vulnerability."
21992| [CVE-2011-0647] The irccd.exe service in EMC Replication Manager Client before 5.3 and NetWorker Module for Microsoft Applications 2.1.x and 2.2.x allows remote attackers to execute arbitrary commands via the RunProgram function to TCP port 6542.
21993| [CVE-2011-0627] Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content, as possibly exploited in the wild in May 2011 by a Microsoft Office document with an embedded .swf file.
21994| [CVE-2011-0037] Microsoft Malware Protection Engine before 1.1.6603.0, as used in Microsoft Malicious Software Removal Tool (MSRT), Windows Defender, Security Essentials, Forefront Client Security, Forefront Endpoint Protection 2010, and Windows Live OneCare, allows local users to gain privileges via a crafted value of an unspecified user registry key.
21995| [CVE-2011-0027] Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, does not properly validate memory allocation for internal data structures, which allows remote attackers to execute arbitrary code, possibly via a large CacheSize property that triggers an integer wrap and a buffer overflow, aka "ADO Record Memory Vulnerability." NOTE: this might be a duplicate of CVE-2010-1117 or CVE-2010-1118.
21996| [CVE-2011-0026] Integer signedness error in the SQLConnectW function in an ODBC API (odbc32.dll) in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, allows remote attackers to execute arbitrary code via a long string in the Data Source Name (DSN) and a crafted szDSN argument, which bypasses a signed comparison and leads to a buffer overflow, aka "DSN Overflow Vulnerability."
21997| [CVE-2010-4643] Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Truevision TGA (TARGA) file in an ODF or Microsoft Office document.
21998| [CVE-2010-4253] Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file in an ODF or Microsoft Office document, as demonstrated by a PowerPoint (aka PPT) document.
21999| [CVE-2010-4121] ** DISPUTED ** The TCP-to-ODBC gateway in IBM Tivoli Provisioning Manager for OS Deployment 7.1.1.3 does not require authentication for SQL statements, which allows remote attackers to modify, create, or read database records via a session on TCP port 2020. NOTE: the vendor disputes this issue, stating that the "default Microsoft Access database is not password protected because it is intended to be used for evaluation purposes only."
22000| [CVE-2010-3967] Untrusted search path vulnerability in Microsoft Windows Movie Maker (WMM) 2.6 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a Movie Maker (MSWMM) file, aka "Insecure Library Loading Vulnerability."
22001| [CVE-2010-3962] Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token sequences and the clip attribute, aka an "invalid flag reference" issue or "Uninitialized Memory Corruption Vulnerability," as exploited in the wild in November 2010.
22002| [CVE-2010-3936] Cross-site scripting (XSS) vulnerability in Signurl.asp in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "XSS in Signurl.asp Vulnerability."
22003| [CVE-2010-3889] Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the wild in July 2010 by the Stuxnet worm, and identified by Microsoft researchers and other researchers.
22004| [CVE-2010-3888] Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the wild in July 2010 by the Stuxnet worm, and identified by Kaspersky Lab researchers and other researchers.
22005| [CVE-2010-3497] Symantec Norton AntiVirus 2011 does not properly interact with the processing of hcp:// URLs by the Microsoft Help and Support Center, which makes it easier for remote attackers to execute arbitrary code via malware that is correctly detected by this product, but with a detection approach that occurs too late to stop the code execution. NOTE: the researcher indicates that a vendor response was received, stating that this issue "falls into the work of our Firewall and not our AV (per our methodology of layers of defense)."
22006| [CVE-2010-3454] Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted typography information in a Microsoft Word .DOC file that triggers an out-of-bounds write.
22007| [CVE-2010-3453] The WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle an unspecified number of list levels in user-defined list styles in WW8 data in a Microsoft Word document, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted .DOC file that triggers an out-of-bounds write.
22008| [CVE-2010-3141] Untrusted search path vulnerability in Microsoft PowerPoint 2010 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse pptimpconv.dll that is located in the same folder as a .odp, .pot, .potm, .potx, .ppa, .pps, .ppsm, .ppsx, .ppt, .pptm, .pptx, .pwz, .sldm, or .sldx file.
22009| [CVE-2010-2743] The kernel-mode drivers in Microsoft Windows XP SP3 do not properly perform indexing of a function-pointer table during the loading of keyboard layouts from disk, which allows local users to gain privileges via a crafted application, as demonstrated in the wild in July 2010 by the Stuxnet worm, aka "Win32k Keyboard Layout Vulnerability." NOTE: this might be a duplicate of CVE-2010-3888 or CVE-2010-3889.
22010| [CVE-2010-2734] Cross-site scripting (XSS) vulnerability in the mobile portal in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "XSS Issue on UAG Mobile Portal Website in Forefront Unified Access Gateway Vulnerability."
22011| [CVE-2010-2733] Cross-site scripting (XSS) vulnerability in the Web Monitor in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "UAG XSS Allows EOP Vulnerability."
22012| [CVE-2010-2732] Open redirect vulnerability in the web interface in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka "UAG Redirection Spoofing Vulnerability."
22013| [CVE-2010-2564] Buffer overflow in Microsoft Windows Movie Maker (WMM) 2.1, 2.6, and 6.0 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted project file, aka "Movie Maker Memory Corruption Vulnerability."
22014| [CVE-2010-1184] The Microsoft wireless keyboard uses XOR encryption with a key derived from the MAC address, which makes it easier for remote attackers to obtain keystroke information and inject arbitrary commands via a nearby wireless device, as demonstrated by Keykeriki 2.
22015| [CVE-2010-1118] Unspecified vulnerability in Internet Explorer 8 on Microsoft Windows 7 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to a use-after-free issue, as demonstrated by Peter Vreugdenhil during a Pwn2Own competition at CanSecWest 2010.
22016| [CVE-2010-1117] Heap-based buffer overflow in Internet Explorer 8 on Microsoft Windows 7 allows remote attackers to discover the base address of a Windows .dll file, and possibly have unspecified other impact, via unknown vectors, as demonstrated by Peter Vreugdenhil during a Pwn2Own competition at CanSecWest 2010.
22017| [CVE-2010-0806] Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object, as exploited in the wild in March 2010, aka "Uninitialized Memory Corruption Vulnerability."
22018| [CVE-2010-0716] _layouts/Upload.aspx in the Documents module in Microsoft SharePoint before 2010 uses URLs with the same hostname and port number for a web site's primary files and individual users' uploaded files (aka attachments), which allows remote authenticated users to leverage same-origin relationships and conduct cross-site scripting (XSS) attacks by uploading TXT files, a related issue to CVE-2008-5026. NOTE: the vendor disputes the significance of this issue, because cross-domain isolation can be implemented when needed.
22019| [CVE-2009-3555] The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.
22020| [CVE-2008-5750] Argument injection vulnerability in Microsoft Internet Explorer 8 beta 2 on Windows XP SP3 allows remote attackers to execute arbitrary commands via the --renderer-path option in a chromehtml: URI.
22021| [CVE-2008-5556] ** DISPUTED ** The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 does not recognize attack patterns designed to operate against web pages that are encoded with utf-7, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting crafted utf-7 content. NOTE: the vendor reportedly disputes this issue, stating "Behaviour is by design."
22022| [CVE-2008-5555] Microsoft Internet Explorer 8.0 Beta 2 relies on the XDomainRequestAllowed HTTP header to authorize data exchange between domains, which allows remote attackers to bypass the product's XSS Filter protection mechanism, and conduct XSS and cross-domain attacks, by injecting this header after a CRLF sequence, related to "XDomainRequest Allowed Injection (XAI)." NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
22023| [CVE-2008-5554] The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 does not properly handle some HTTP headers that appear after a CRLF sequence in a URI, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS or redirection attacks, as demonstrated by the (1) Location and (2) Set-Cookie HTTP headers. NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
22024| [CVE-2008-5553] The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 disables itself upon encountering a certain X-XSS-Protection HTTP header, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting this header after a CRLF sequence. NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
22025| [CVE-2008-5552] The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks via a CRLF sequence in conjunction with a crafted Content-Type header, as demonstrated by a header with a utf-7 charset value. NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
22026| [CVE-2008-5551] The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting data at two different positions within an HTML document, related to STYLE elements and the CSS expression property, aka a "double injection."
22027| [CVE-2008-5180] Microsoft Communicator, and Communicator in Microsoft Office 2010 beta, allows remote attackers to cause a denial of service (memory consumption) via a large number of SIP INVITE requests, which trigger the creation of many sessions.
22028| [CVE-2008-4211] Integer signedness error in (1) QuickLook in Apple Mac OS X 10.5.5 and (2) Office Viewer in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted Microsoft Excel file that triggers an out-of-bounds memory access, related to "handling of columns."
22029| [CVE-2007-5351] Unspecified vulnerability in Server Message Block Version 2 (SMBv2) signing support in Microsoft Windows Vista allows remote attackers to force signature re-computation and execute arbitrary code via a crafted SMBv2 packet, aka "SMBv2 Signing Vulnerability."
22030| [CVE-2007-2729] Comodo Firewall Pro 2.4.18.184 and Comodo Personal Firewall 2.3.6.81, and probably older Comodo Firewall versions, do not properly test for equivalence of process identifiers for certain Microsoft Windows API functions in the NT kernel 5.0 and greater, which allows local users to call these functions, and bypass firewall rules or gain privileges, via a modified identifier that is one, two, or three greater than the canonical identifier.
22031| [CVE-2007-1534] DFSR.exe in Windows Meeting Space in Microsoft Windows Vista remains available for remote connections on TCP port 5722 for 2 minutes after Windows Meeting Space is closed, which allows remote attackers to have an unknown impact by connecting to this port during the time window.
22032| [CVE-2007-0341] Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.1 and earlier, when Microsoft Internet Explorer 6 is used, allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in a CSS style in the convcharset parameter to the top-level URI, a different vulnerability than CVE-2005-0992.
22033| [CVE-2006-5559] The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the second argument is a BSTR, which allows remote attackers to cause a denial of service (Internet Explorer crash) and possibly execute arbitrary code via certain strings in the second and third arguments.
22034| [CVE-2006-4686] Buffer overflow in the Extensible Stylesheet Language Transformations (XSLT) processing in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 allows remote attackers to execute arbitrary code via a crafted Web page.
22035| [CVE-2006-4685] The XMLHTTP ActiveX control in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 does not properly handle HTTP server-side redirects, which allows remote user-assisted attackers to access content from other domains.
22036| [CVE-2006-1359] Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer.
22037| [CVE-2006-0761] Buffer overflow in BlackBerry Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server 2.2 and 4.0 before SP3 Hotfix 4 for IBM Lotus Domino, 3.6 before SP7 and 5.0 before SP3 Hotfix 3 for Microsoft Exchangem, and 4.0 for Novell GroupWise before SP3 Hotfix 1 might allow user-assisted remote attackers to execute arbitrary code on the server via a crafted Microsoft Word document that is opened on a wireless device.
22038| [CVE-2006-0753] Memory leak in Microsoft Internet Explorer 6 for Windows XP Service Pack 2 allows remote attackers to cause a denial of service (memory consumption) via JavaScript that uses setInterval to repeatedly call a function to set the value of window.status.
22039| [CVE-2006-0544] urlmon.dll in Microsoft Internet Explorer 7.0 beta 2 (aka 7.0.5296.0) allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a BGSOUND element with its SRC attribute set to "file://" followed by a large number of "-" (dash of hyphen) characters.
22040| [CVE-2006-0003] Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and distributed in Microsoft Data Access Components (MDAC) 2.7 and 2.8, allows remote attackers to execute arbitrary code via unknown attack vectors.
22041| [CVE-2005-1929] Multiple heap-based buffer overflows in (1) isaNVWRequest.dll and (2) relay.dll in Trend Micro ServerProtect Management Console 5.58 and earlier, as used in Control Manager 2.5 and 3.0 and Damage Cleanup Server 1.1, allow remote attackers to execute arbitrary code via "wrapped" length values in Chunked transfer requests. NOTE: the original report suggests that the relay.dll issue is related to a problem in which a Microsoft Foundation Classes (MFC) static library returns invalid values under heavy load. As such, this might not be a vulnerability in Trend Micro's product.
22042| [CVE-2005-0852] Microsoft Windows XP SP1 allows local users to cause a denial of service (system crash) via an empty datagram to a raw IP over IP socket (IP protocol 4), as originally demonstrated using code in Python 2.3.
22043| [CVE-2004-1322] Cisco Unity 2.x, 3.x, and 4.x, when integrated with Microsoft Exchange, has several hard coded usernames and passwords, which allows remote attackers to gain unauthorized access and change configuration settings or read outgoing or incoming e-mail messages.
22044| [CVE-2003-1306] Microsoft URLScan 2.5, with the RemoveServerHeader option enabled, allows remote attackers to obtain sensitive information (server name and version) via an HTTP request that generates certain errors such as 400 "Bad Request," which leak the Server header in the response.
22045| [CVE-2003-0903] Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request.
22046| [CVE-2003-0353] Buffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary code via a long response to a broadcast request to UDP port 1434.
22047| [CVE-2002-1918] Buffer overflow in Microsoft Active Data Objects (ADO) in Microsoft MDAC 2.5 through 2.7 allows remote attackers to have unknown impact with unknown attack vectors. NOTE: due to the lack of details available regarding this issue, perhaps it should be REJECTED.
22048| [CVE-2002-1142] Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.
22049| [CVE-2002-1015] RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to execute arbitrary script in the Local computer zone by inserting the script into the skin.ini file of an RJS archive, then referencing skin.ini from a web page after it has been extracted, which is parsed as HTML by Internet Explorer or other Microsoft-based web readers.
22050| [CVE-2002-0697] Microsoft Metadirectory Services (MMS) 2.2 allows remote attackers to bypass authentication and modify sensitive data by using an LDAP client to directly connect to MMS and bypass the checks for MMS credentials.
22051| [CVE-2002-0057] XMLHTTP control in Microsoft XML Core Services 2.6 and later does not properly handle IE Security Zone settings, which allows remote attackers to read arbitrary files by specifying a local file as an XML Data Source.
22052| [CVE-2001-1218] Microsoft Internet Explorer for Unix 5.0SP1 allows local users to possibly cause a denial of service (crash) in CDE or the X server on Solaris 2.6 by rapidly scrolling Chinese characters or maximizing the window.
22053| [CVE-2000-0563] The URLConnection function in MacOS Runtime Java (MRJ) 2.1 and earlier and the Microsoft virtual machine (VM) for MacOS allows a malicious web site operator to connect to arbitrary hosts using a HTTP redirection, in violation of the Java security model.
22054| [CVE-1999-1097] Microsoft NetMeeting 2.1 allows one client to read the contents of another client's clipboard via a CTRL-C in the chat box when the box is empty.
22055|
22056| SecurityFocus - https://www.securityfocus.com/bid/:
22057| [83154] Microsoft Windows 2000 Server CVE-2004-0540 Remote Security Vulnerability
22058| [45297] Microsoft Exchange Server 2007 Infinite Loop Remote Denial of Service Vulnerability
22059| [43419] Microsoft Excel 2002 Memory Corruption Vulnerability
22060| [43189] Microsoft Visual C++ 2008 Redistributable Package DLL Loading Arbitrary Code Execution Vulnerability
22061| [42742] Microsoft PowerPoint 2007 Multiple DLL Loading Arbitrary Code Execution Vulnerability
22062| [42695] Microsoft Groove 2007 'mso.dll' DLL Loading Arbitrary Code Execution Vulnerability
22063| [42681] Microsoft Visio 2003 'mfc71enu.dll' DLL Loading Arbitrary Code Execution Vulnerability
22064| [41843] Microsoft Outlook Web Access for Exchange Server 2003 Cross Site Request Forgery Vulnerability
22065| [39776] Microsoft SharePoint Server 2007 '_layouts/help.aspx' Cross Site Scripting Vulnerability
22066| [37196] RETIRED: Microsoft December 2009 Advance Notification Multiple Vulnerabilities
22067| [36940] RETIRED: Microsoft November 2009 Advance Notification Multiple Vulnerabilities
22068| [36633] RETIRED: Microsoft October 2009 Advance Notification Multiple Vulnerabilities
22069| [36239] RETIRED: Microsoft September 2009 Advance Notification Multiple Vulnerabilities
22070| [35974] RETIRED: Microsoft August 2009 Advance Notification Multiple Vulnerabilities
22071| [35617] RETIRED: Microsoft July 2009 Advance Notification Multiple Vulnerabilities
22072| [35213] RETIRED: Microsoft June 2009 Advance Notification Multiple Vulnerabilities
22073| [34867] RETIRED: Microsoft May 2009 Advance Notification Multiple Vulnerabilities
22074| [34532] Microsoft IAG 2007 ActiveX Control Multiple Stack Based Buffer Overflow Vulnerabilities
22075| [34469] Microsoft Word 2000 WordPerfect Converter Remote Code Execution Vulnerability
22076| [34450] RETIRED: Microsoft April 2009 Advance Notification Multiple Vulnerabilities
22077| [34005] RETIRED: Microsoft March 2009 Advance Notification Multiple Vulnerabilities
22078| [33639] RETIRED: Microsoft February 2009 Advance Notification Multiple Vulnerabilities
22079| [33170] RETIRED: Microsoft January 2009 Advance Notification Multiple Vulnerabilities
22080| [32632] RETIRED: Microsoft December 2008 Advance Notification Multiple Vulnerabilities
22081| [32153] Retired: Microsoft November 2008 Advance Notification Multiple Vulnerabilities
22082| [31667] Retired: Microsoft October 2008 Advance Notification Multiple Vulnerabilities
22083| [31129] RETIRED: Microsoft SQL Server 2000 'sqlvdir.dll' ActiveX Buffer Overflow Vulnerability
22084| [31014] RETIRED: Microsoft September 2008 Advance Notification Multiple Vulnerabilities
22085| [30593] RETIRED: Microsoft August 2008 Advance Notification Multiple Vulnerabilities
22086| [30075] RETIRED: Microsoft July 2008 Advance Notification Multiple Vulnerabilities
22087| [29576] RETIRED: Microsoft June 2008 Advance Notification Multiple Vulnerabilities
22088| [29108] RETIRED: Microsoft May 2008 Advance Notification Multiple Vulnerabilities
22089| [28598] RETIRED: Microsoft April 2008 Advance Notification Multiple Vulnerabilities
22090| [28124] Retired: Microsoft March 2008 Advance Notification Multiple Vulnerabilities
22091| [27674] RETIRED: Microsoft February 2008 Advance Notification Multiple Vulnerabilities
22092| [27119] RETIRED: Microsoft January 2008 Advance Notification Multiple Vulnerabilities
22093| [26739] RETIRED: Microsoft December 2007 Advance Notification Multiple Vulnerabilities
22094| [26414] Microsoft Forms 2.0 ActiveX Control Memory Access Violation Denial of Service Vulnerabilities
22095| [26380] Retired: Microsoft November 2007 Advance Notification Multiple Vulnerabilities
22096| [25991] RETIRED: Microsoft Office 2000 and XP Unspecified Word Document Handling DoS Vulnerability
22097| [25922] RETIRED: Microsoft October 2007 Advance Notification Multiple Vulnerabilities
22098| [25573] RETIRED: Microsoft September 2007 Advance Notification Multiple Vulnerabilities
22099| [25247] Retired: Microsoft August 2007 Advance Notification Multiple Vulnerabilities
22100| [24771] Retired: Microsoft July 2007 Advance Notification Multiple Vulnerabilities
22101| [24366] RETIRED: Microsoft June 2007 Advance Notification Multiple Vulnerabilities
22102| [24118] Microsoft Office 2000 UA OUACTRL.OCX ActiveX Control Buffer Overflow Vulnerability
22103| [23800] RETIRED: Microsoft May 2007 Advance Notification Multiple Vulnerabilities
22104| [23380] Microsoft Word 2007 WWLib.DLL Unspecified Document File Buffer Overflow Vulnerability
22105| [23335] RETIRED: Microsoft April 2007 Advance Notification Multiple Vulnerabilities
22106| [22716] Microsoft Office 2003 Denial of Service Vulnerability
22107| [22567] Microsoft Word 2000/2002 Document Stream Remote Code Execution Vulnerability
22108| [22328] RETIRED: Microsoft Word 2003 Unspecified Code Execution Vulnerability
22109| [22225] Microsoft Word 2000 Malformed Function Code Execution Vulnerability
22110| [21611] Microsoft Project Server 2003 PDSRequest.ASP XML Request Information Disclosure Vulnerability
22111| [21495] Microsoft Windows 2000 Remote Installation Service Remote Code Execution Vulnerability
22112| [20843] Microsoft Visual Studio 2005 WMI Object Broker Remote Code Execution Vulnerability
22113| [19636] Microsoft Windows 2000 Multiple COM Object Instantiation Code Execution Vulnerabilities
22114| [19388] Microsoft Windows 2000 Kernel Local Privilege Escalation Vulnerability
22115| [17134] Microsoft Commerce Server 2002 Authentication Bypass Vulnerability
22116| [16634] Microsoft PowerPoint 2000 Remote Information Disclosure Vulnerability
22117| [14772] Microsoft Exchange Server 2003 Exchange Information Store Denial Of Service Vulnerability
22118| [14093] Microsoft Update Rollup 1 for Windows 2000 SP4 Released - Multiple Vulnerabilities Fixed
22119| [13564] Microsoft SQL Server 2000 Multiple Vulnerabilities
22120| [13008] Microsoft Windows Server 2003 SMB Redirector Local Denial Of Service Vulnerability
22121| [12972] Microsoft Windows Server 2003 Service Pack 1 Released - Multiple Vulnerabilities Fixed
22122| [12913] Microsoft Outlook 2002 Connector For IBM Lotus Domino Policy Bypass Vulnerability
22123| [12824] Microsoft InfoPath 2003 Insecure Information Storage Vulnerability
22124| [12641] Microsoft Windows 2000 Group Policy Bypass Vulnerability
22125| [12141] Microsoft FrontPage 2000 Internet Publishing Service Provider DAV File Upload Vulnerability
22126| [11820] Microsoft Windows 2000 Resource Kit W3Who.DLL Multiple Remote Vulnerabilities
22127| [11446] Microsoft Outlook 2003 Security Policy Bypass Vulnerability
22128| [11387] Microsoft Windows 2003 Services Default SACL Access Right Weakness
22129| [10901] Microsoft Windows 2000/XP CRL File Failed Integrity Check Denial Of Service Vulnerability
22130| [10693] Microsoft Windows 2000 Media Player Control Media Preview Script Execution Vulnerability
22131| [10484] Microsoft ISA Server 2000 FTP Bounce Filtering Vulnerability
22132| [10480] Microsoft ISA Server 2000 Site And Content Rule Bypass Vulnerability
22133| [10440] Microsoft Windows 2000 Domain Expired Account Security Policy Violation Weakness
22134| [10369] Microsoft Outlook 2003 Media File Script Execution Vulnerability
22135| [10307] Microsoft Outlook 2003 Predictable File Location Weakness
22136| [10114] Microsoft Windows 2000 Domain Controller LDAP Denial Of Service Vulnerability
22137| [9409] Microsoft Exchange Server 2003 Outlook Web Access Random Mailbox Access Vulnerability
22138| [9408] Microsoft ISA Server 2000 H.323 Filter Remote Buffer Overflow Vulnerability
22139| [9118] Microsoft Exchange Server 2003 Outlook Web Access Lowered Security Settings Weakness
22140| [8833] Microsoft Windows 2000 TroubleShooter ActiveX Control Buffer Overflow Vulnerability
22141| [8522] Multiple Microsoft Windows 2003 Stack Protection Implementation Weaknesses
22142| [8397] Microsoft Windows 2000 Subnet Bandwidth Manager RSVP Server Authority Hijacking Vulnerability
22143| [8104] Microsoft Windows 2000 Unauthorized RPC Connection Weakness
22144| [8098] Microsoft Windows 2000 Terminal Services Named Pipe System Account Access Vulnerability
22145| [8093] Microsoft Windows 2000 Active Directory Forest Origin Validation Vulnerability
22146| [8090] Microsoft Windows 2000 ShellExecute() Buffer Overflow Vulnerability
22147| [8089] Microsoft Windows 2000 Unspecified Cryptnet.DLL Memory Leakage Vulnerability
22148| [8086] Microsoft Windows 2000 Port Name Buffers Potential Buffer Overflow Vulnerability
22149| [8085] Microsoft Windows 2000 ModifyDN Request Denial of Service Vulnerability
22150| [8083] Microsoft Windows 2000 Domain Controller Spoofing Vulnerability
22151| [8081] Microsoft Windows 2000 USBH_IoctlGetNodeConnectionDriverKeyName Information Disclosure Vulnerability
22152| [8063] Microsoft Commerce Server 2002 Weak Registry Key Permissions Weakness
22153| [8045] Microsoft Windows 2000 SP4 Released - Multiple Vulnerabilities Fixed
22154| [7930] Microsoft Windows 2000 Active Directory Remote Stack Overflow Vulnerability
22155| [7788] Microsoft Windows 2000/XP/2003 IPV6 ICMP Flood Denial Of Service Vulnerability
22156| [7469] Microsoft BizTalk Server 2002 HTTP Receiver Buffer Overflow Vulnerability
22157| [7360] Microsoft Windows 2000/XP Registry Editor Custom Permissions Weakness
22158| [7102] Microsoft Windows 2000 Help Facility .CNT File :Link Buffer Overflow Vulnerability
22159| [6769] Microsoft Windows 2000 RPC Service Privilege Escalation Vulnerability
22160| [6766] Microsoft Windows 2000 NetBIOS Continuation Packets Kernel Memory Leak Vulnerability
22161| [6667] Microsoft Outlook 2002 V1 Exchange Server Security Certificate Information Leakage Vulnerability
22162| [6319] Microsoft Outlook 2002 Email Header Processing Denial of Service Vulnerability
22163| [6030] Microsoft Windows 2000 SNMP Printer Query Denial of Service Vulnerability
22164| [5972] Microsoft Windows 2000/XP Full Event Log Administrative Alert Weakness
22165| [5922] Microsoft Content Management Server 2001 Cross-Site Scripting Vulnerability
22166| [5480] Microsoft Windows 2000 Network Connection Manager Privilege Elevation Vulnerability
22167| [5422] Microsoft Content Management Server 2001 SQL Injection Vulnerability
22168| [5421] Microsoft Content Management Server 2001 Arbitrary Upload Location Vulnerability
22169| [5420] Microsoft Content Management Server 2001 User Authentication Buffer Overflow Vulnerability
22170| [5415] Microsoft Windows 2000 Insecure Default File Permissions Vulnerability
22171| [5413] Microsoft Exchange 2000 Post Authorization License Exhaustion Denial Of Service Vulnerability
22172| [5412] Microsoft Exchange 2000 Multiple MSRPC Denial Of Service Vulnerabilities
22173| [5312] Microsoft SQL Server 2000 Resolution Service Denial of Service Vulnerability
22174| [5311] Microsoft SQL Server 2000 Resolution Service Stack Overflow Vulnerability
22175| [5310] Microsoft SQL Server 2000 Resolution Service Heap Overflow Vulnerability
22176| [5309] Microsoft SQL Server 2000 sp_MScopyscript SQL Injection Vulnerability
22177| [5307] Microsoft SQL Server 2000 Database Consistency Checkers Buffer Overflow Vulnerability
22178| [5253] Microsoft Windows 2000 Narrator Password Disclosure Vulnerability
22179| [5205] Microsoft SQL Server 2000 Incorrect Registry Key Permissions Vulnerability
22180| [5111] Microsoft Commerce Server 2000 OWC Package Installer Local Command Execution Vulnerability
22181| [5014] Microsoft SQL Server 2000 Password Encrypt Procedure Buffer Overflow Vulnerability
22182| [4881] Microsoft Exchange 2000 Malformed Mail Attribute DoS Vulnerability
22183| [4853] Microsoft Commerce Server 2000 Profile Service Buffer Overflow Vulnerability
22184| [4852] Microsoft Windows 2000 Remote Access Service Buffer Overflow Vulnerability
22185| [4847] Microsoft SQL Server 2000 Bulk Insert Procedure Buffer Overflow Vulnerability
22186| [4797] Microsoft MSDE/SQL Server 2000 Desktop Engine Default Configuration Vulnerability
22187| [4683] Microsoft Windows 2000 / NT Path Precedence Vulnerability
22188| [4532] Microsoft Windows 2000 Lanman Denial of Service Vulnerability
22189| [4438] Microsoft Windows 2000 Group Policy Evasion Vulnerability
22190| [4426] Microsoft Windows 2000 / NT / XP MUP UNC Request Buffer Overflow Vulnerability
22191| [4287] Microsoft Windows 2000 / NT 4.0 Process Handle Local Privilege Elevation Vulnerability
22192| [4256] Microsoft Windows 2000 Password Policy Bypass Vulnerability
22193| [4157] Microsoft Commerce Server 2000 ISAPI Buffer Overflow Vulnerability
22194| [4095] Microsoft Windows 2000 Server Terminal Services Failure To Lock Terminal Vulnerability
22195| [3652] Microsoft Windows 2000 Internet Key Exchange DoS Vulnerability
22196| [3481] Microsoft Windows 2000/XP GDI Denial of Service Vulnerability
22197| [3479] Microsoft Windows 2000 NTFS With Macintosh Client Directory Permission Vulnerability
22198| [3445] Microsoft Windows 2000/NT Terminal Server Service RDP DoS Vulnerability
22199| [3339] Microsoft Index Server 2.0 File Information and Path Disclosure Vulnerability
22200| [3305] Norton AntiVirus for Microsoft Exchange 2000 Information Disclosure Vulnerability
22201| [3291] Microsoft Windows 2000 RunAs Service Denial of Services Vulnerability
22202| [3215] Microsoft Windows 2000 IrDA Buffer Overflow Denial of Service Vulnerability
22203| [3185] Microsoft Windows 2000 RunAs Service Named Pipe Hijacking Vulnerability
22204| [3184] Microsoft Windows 2000 RunAs User Credentials Exposure Vulnerability
22205| [3146] Microsoft Windows 2000 System File Replacement Vulnerability
22206| [3115] Microsoft Windows NT and 2000 Command Prompt Reboot Vulnerability
22207| [3063] Microsoft Windows 2000 Unauthorized Password Change Vulnerability
22208| [3033] Microsoft Windows 2000 Task Manager Process Termination Vulnerability
22209| [2988] Microsoft Windows 2000 SMTP Improper Authentication Vulnerability
22210| [2929] Microsoft Windows 2000 LDAP SSL Password Modification Vulnerability
22211| [2849] Microsoft Windows 2000 Telnet Privilege Escalation Vulnerability
22212| [2846] Microsoft Windows 2000 Telnet System Call DoS Vulnerability
22213| [2844] Microsoft Windows 2000 Telnet Service DoS Vulnerability
22214| [2843] Microsoft Windows 2000 Telnet Multiple Sessions DoS Vulnerability
22215| [2838] Microsoft Windows 2000 Telnet Username DoS Vulnerability
22216| [2460] Microsoft Windows 2000 Event Viewer Buffer Overflow Vulnerability
22217| [2441] Microsoft Exchange 2000 / IIS 5.0 Multiple Invalid URL Request DoS Vulnerability
22218| [2394] Microsoft Windows 2000 Domain Controller DoS Vulnerability
22219| [2341] Microsoft Windows 2000 Network DDE Escalated Privileges Vulnerability
22220| [2326] Microsoft Windows 2000 RDP DoS Vulnerability
22221| [2133] Microsoft Windows 2000 Directory Services Restore Mode Blank Password Vulnerability
22222| [2066] Microsoft Windows NT 4.0 / 2000 SNMP Registry Key Modification Vulnerability
22223| [2018] Microsoft Windows 2000 Telnet Session Timeout DoS Vulnerability
22224| [2007] Microsoft Windows 2000 DNS Memory Leak Vulnerability
22225| [1973] Microsoft Windows 2000 Domain Account Lockout Bypass Vulnerability
22226| [1958] Microsoft Exchange 2000 Server EUSR_EXSTOREEVENT Account Vulnerability
22227| [1933] Microsoft Indexing Services for Windows 2000 File Verification Vulnerability
22228| [1899] Microsoft Windows 2000 ActiveX Control Buffer Overflow Vulnerability
22229| [1811] Microsoft Site Server 2.0 with IIS 4.0 Malicious File Upload Vulnerability
22230| [1758] Microsoft Windows 2000 Unattended Install OEMPreinstall Vulnerability
22231| [1753] Microsoft Windows NT 4.0 / 2000 Spoofed LPC Request Vulnerability
22232| [1748] Microsoft Windows NT 4.0 / 2000 Predictable LPC Message Identifier Multiple Vulnerabilities
22233| [1745] Microsoft Windows NT 4.0 / 2000 LPC Zone Memory Depletion DoS Vulnerability
22234| [1729] Microsoft Windows 2000 Simplified Chinese IME Vulnerability
22235| [1695] Microsoft Proxy 2.0 FTP Permissions Bypass Vulnerability
22236| [1692] Microsoft Proxy 2.0 Internal Network Access Vulnerability
22237| [1683] Microsoft Windows 2000 telnet.exe NTLM Authentication Vulnerability
22238| [1673] Microsoft Windows 2000 Malformed RPC Packet DoS Vulnerability
22239| [1651] Microsoft Windows 2000 Still Image Service Privilege Escalation Vulnerability
22240| [1632] Microsoft Windows 98 / NT 4.0 / 2000 File Extension Validation Vulnerability
22241| [1620] Microsoft Windows 9x / NT 4.0 / 2000 NetBIOS Cache Corruption Vulnerability
22242| [1613] Microsoft Windows 2000 Local Security Policy Corruption Vulnerability
22243| [1566] Microsoft Word 97 / 2000 Mail Merge Code Execution Vulnerability
22244| [1561] Microsoft Word / Excel / Powerpoint 2000 Object Tag Buffer Overflow Vulnerability
22245| [1535] Microsoft Windows 2000 Named Pipes Predictability Vulnerability
22246| [1507] Microsoft Windows NT 4.0 / 2000 Unspecified Executable Path Vulnerability
22247| [1451] Microsoft Excel 97 / 2000 Register.ID Vulnerability
22248| [1435] Microsoft FrontPage 2000 Server Extensions Denial Of Service Vulnerability
22249| [1415] Microsoft Windows 2000 Remote CPU-overload Vulnerability
22250| [1414] Microsoft Windows 2000 Telnet Server DoS Vulnerability
22251| [1399] Microsoft Internet Explorer 5.01 and Excel/Powerpoint 2000 ActiveX Object Execution Vulnerability
22252| [1398] Microsoft Internet Explorer 5.01 and Access 2000 / 97 VBA Code Execution Vulnerability
22253| [1350] Microsoft Windows 2000 Windows Station Access Vulnerability
22254| [1304] Microsoft Windows NT 4.0 / 2000 SMB Write Request DoS Vulnerability
22255| [1301] Microsoft Windows NT 4.0 / 2000 Ignored SMB Response DoS Vulnerability
22256| [1295] Microsoft Windows 2000 Default 40-bit Encrypted Protected Store Vulnerability
22257| [1198] Microsoft Windows 2000 Default SYSKEY Configuration Vulnerability
22258| [1197] Microsoft Office 2000 UA Control Vulnerability
22259| [990] Microsoft Windows 2000 Install Unprotected ADMIN$ Share Vulnerability
22260| [945] Microsoft SMS 2.0 Default Permissions Vulnerability
22261| [539] Microsoft Windows 2000 EFS Vulnerability
22262| [180] Microsoft Windows April Fools 2001 Vulnerability
22263| [71487] Microsoft December 2014 Advance Notification Multiple Vulnerabilities
22264| [70966] RETIRED: Microsoft November 2014 Advance Notification Multiple Vulnerabilities
22265| [70367] RETIRED: Microsoft October 2014 Advance Notification Multiple Vulnerabilities
22266| [69636] RETIRED: Microsoft September 2014 Advance Notification Multiple Vulnerabilities
22267| [69108] Microsoft August 2014 Advance Notification Multiple Vulnerabilities
22268| [68367] Microsoft July 2014 Advance Notification Multiple Vulnerabilities
22269| [67905] Microsoft June 2014 Advance Notification Multiple Vulnerabilities
22270| [67298] Microsoft May 2014 Advance Notification Multiple Vulnerabilities
22271| [66639] RETIRED: Microsoft April 2014 Advance Notification Multiple Vulnerabilities
22272| [66016] Microsoft March 2014 Notification Multiple Vulnerabilities
22273| [65426] Microsoft February 2014 Notification Multiple Vulnerabilities
22274| [64757] RETIRED: Microsoft January 2014 Advance Notification Multiple Vulnerabilities
22275| [64083] RETIRED: Microsoft December 2013 Advance Notification Multiple Vulnerabilities
22276| [63604] RETIRED: Microsoft November 2013 Advance Notification Multiple Vulnerabilities
22277| [62797] RETIRED: Microsoft October 2013 Advance Notification Multiple Vulnerabilities
22278| [62228] RETIRED: Microsoft September 2013 Advance Notification Multiple Vulnerabilities
22279| [62181] Microsoft Office Pinyin IME 2010 CVE-2013-3859 Local Privilege Escalation Vulnerability
22280| [61686] Microsoft August 2013 Advance Notification Multiple Vulnerabilities
22281| [60960] RETIRED: Microsoft July 2013 Advance Notification Multiple Vulnerabilities
22282| [60394] Microsoft June 2013 Advance Notification Multiple Vulnerabilities
22283| [59785] RETIRED: Microsoft May 2013 Advance Notification Multiple Vulnerabilities
22284| [58881] RETIRED: Microsoft April 2013 Advance Notification Multiple Vulnerabilities
22285| [58380] RETIRED: Microsoft March 2013 Advance Notification Multiple Vulnerabilities
22286| [57846] RETIRED: Microsoft February 2013 Advance Notification Multiple Vulnerabilities
22287| [57137] RETIRED: Microsoft January 2013 Advance Notification Multiple Vulnerabilities
22288| [56838] RETIRED: Microsoft December 2012 Advance Notification Multiple Vulnerabilities
22289| [56450] RETIRED: Microsoft November 2012 Advance Notification Multiple Vulnerabilities
22290| [56304] Microsoft Office Excel 2010 Memory Corruption Denial of Service Vulnerability
22291| [55794] RETIRED: Microsoft October 2012 Advance Notification Multiple Vulnerabilities
22292| [55472] RETIRED: Microsoft September 2012 Advance Notification Multiple Vulnerabilities
22293| [54944] RETIRED: Microsoft August 2012 Advance Notification Multiple Vulnerabilities
22294| [54318] RETIRED: Microsoft July 2012 Advance Notification Multiple Vulnerabilities
22295| [53862] RETIRED: Microsoft June 2012 Advance Notification Multiple Vulnerabilities
22296| [53372] RETIRED: Microsoft May 2012 Advance Notification Multiple Vulnerabilities
22297| [52910] RETIRED: Microsoft April 2012 Advance Notification Multiple Vulnerabilities
22298| [52366] RETIRED: Microsoft March 2012 Advance Notification Multiple Vulnerabilities
22299| [51944] RETIRED: Microsoft February 2012 Advance Notification Multiple Vulnerabilities
22300| [51289] RETIRED: Microsoft January 2012 Advance Notification Multiple Vulnerabilities
22301| [50980] RETIRED: Microsoft December 2011 Advance Notification Multiple Vulnerabilities
22302| [50513] RETIRED: Microsoft November 2011 Advance Notification Multiple Vulnerabilities
22303| [49994] RETIRED: Microsoft October 2011 Advance Notification Multiple Vulnerabilities
22304| [49515] RETIRED: Microsoft September 2011 Advance Notification Multiple Vulnerabilities
22305| [49017] RETIRED: Microsoft August 2011 Advance Notification Multiple Vulnerabilities
22306| [48616] RETIRED: Microsoft July 2011 Advance Notification Multiple Vulnerabilities
22307| [48235] Microsoft Lync Server 2010 'ReachJoin.aspx' Remote Command Injection Vulnerability
22308| [48193] RETIRED: Microsoft June 2011 Advance Notification Multiple Vulnerabilities
22309| [47725] RETIRED: Microsoft May 2011 Advance Notification Multiple Vulnerabilities
22310| [47255] RETIRED: Microsoft April 2011 Advance Notification Multiple Vulnerabilities
22311| [46675] RETIRED: Microsoft March 2011 Advance Notification Multiple Vulnerabilities
22312| [46132] RETIRED: Microsoft February 2011 Advance Notification Multiple Vulnerabilities
22313| [45696] RETIRED: Microsoft January 2011 Advance Notification Multiple Vulnerabilities
22314| [45307] RETIRED: Microsoft December 2010 Advance Notification Multiple Vulnerabilities
22315| [44649] RETIRED: Microsoft November 2010 Advance Notification Multiple Vulnerabilities
22316| [43831] RETIRED: Microsoft October 2010 Advance Notification Multiple Vulnerabilities
22317| [43115] RETIRED: Microsoft September 2010 Advance Notification Multiple Vulnerabilities
22318| [42234] RETIRED: Microsoft August 2010 Advance Notification Multiple Vulnerabilities
22319| [41474] RETIRED: Microsoft July 2010 Advance Notification Multiple Vulnerabilities
22320| [40548] RETIRED: Microsoft June 2010 Advance Notification Multiple Vulnerabilities
22321| [39961] RETIRED: Microsoft May 2010 Advance Notification Multiple Vulnerabilities
22322| [39313] RETIRED: Microsoft April 2010 Advance Notification Multiple Vulnerabilities
22323| [38540] RETIRED: Microsoft March 2010 Advance Notification Multiple Vulnerabilities
22324| [38096] RETIRED: Microsoft February 2010 Advance Notification Multiple Vulnerabilities
22325| [37887] RETIRED: Microsoft January 2010 Advance Notification Multiple Vulnerabilities
22326| [37664] RETIRED: Microsoft January 2010 Advance Notification Multiple Vulnerabilities
22327| [32642] Microsoft Word RTF Malformed Control Word Variant 2 Remote Code Execution Vulnerability
22328|
22329| IBM X-Force - https://exchange.xforce.ibmcloud.com:
22330| [82417] Microsoft Windows Knowledge Base Article 2801261 update is not installed
22331| [82415] Microsoft Windows Knowledge Base Article 2807986 update is not installed
22332| [82410] Microsoft Windows Knowledge Base Article 2809289 update is not installed
22333| [81859] Microsoft Windows Knowledge Base Article 2802968 update is not installed
22334| [81857] Microsoft Windows Knowledge Base Article 2809279 update is not installed
22335| [81668] Microsoft Windows Knowledge Base Article 2800277 update is not installed
22336| [77323] Microsoft Windows Knowledge Base Article 2706045 update is not installed
22337| [75949] Microsoft Windows Knowledge Base Article 2707960 update is not installed
22338| [75942] Microsoft Windows Knowledge Base Article 2706726 update is not installed
22339| [75934] Microsoft Windows Knowledge Base Article 2709162 update is not installed
22340| [75926] Microsoft Windows Knowledge Base Article 2709100 update is not installed
22341| [75905] Microsoft Windows Knowledge Base Article 2707956 update is not installed
22342| [71991] Microsoft Windows Knowledge Base Article 2607664 update is not installed
22343| [71542] Microsoft Windows Knowledge Base Article 2607702 update is not installed
22344| [70945] Microsoft Windows Knowledge Base Article 2603381 update is not installed
22345| [70150] Microsoft Windows Knowledge Base Article 2607670 update is not installed
22346| [67755] Microsoft Windows Knowledge Base Article 2503665 update is not installed
22347| [67749] Microsoft Windows Knowledge Base Article 2507938 update is not installed
22348| [66845] Microsoft Windows Knowledge Base Article 2506014 update is not installed
22349| [66844] Microsoft Windows Knowledge Base Article 2501584 update is not installed
22350| [66448] Microsoft Windows Knowledge Base Article 2508272 update is not installed
22351| [66442] Microsoft Windows Knowledge Base Article 2509553 update is not installed
22352| [66440] Microsoft Windows Knowledge Base Article 2508429 update is not installed
22353| [66438] Microsoft Windows Knowledge Base Article 2507618 update is not installed
22354| [66430] Microsoft Windows Knowledge Base Article 2503658 update is not installed
22355| [66425] Microsoft Windows Knowledge Base Article 2506223 update is not installed
22356| [65570] Microsoft Windows Knowledge Base Article 2500212 update is not installed
22357| [65568] Microsoft Windows Knowledge Base Article 2508062 update is not installed
22358| [63840] Microsoft Visual C++ 2008 Redistributable Package dynamic-linked library (DLL) code execution
22359| [63780] Microsoft PowerPoint 2007 dynamic-linked library (rpawinet.dll) code execution
22360| [63775] Microsoft Visio 2003 dynamic-linked library (mfc71enu.dll) code execution
22361| [63586] Microsoft Windows Knowledge Base Article 2207559 update is not installed
22362| [63573] Microsoft Windows Knowledge Base Article 2407132 update is not installed
22363| [62797] Microsoft Windows Knowledge Base Article 2305420 update is not installed
22364| [62149] Microsoft Windows Knowledge Base Article 2207566 update is not installed
22365| [62133] Microsoft Windows Knowledge Base Article 2405882 update is not installed
22366| [53980] Microsoft Windows 2000 License Logging Server buffer overflow
22367| [53601] Microsoft Office 2008 for Mac user ID 502 security bypass
22368| [50973] Microsoft Windows Server 2003 and Vista win32k.sys denial of service
22369| [50759] Microsoft Windows 2000 Active Directory LDAP code execution
22370| [48595] Microsoft Word 2007 Email as PDF information disclosure
22371| [46102] Microsoft Windows 2003 SP2 is not installed on the system
22372| [46101] Microsoft Windows 2003 SP1 is not installed on the system
22373| [45186] Microsoft SQL Server 2000 SQLVDIRLib.SQLVDirControl ActiveX control buffer overflow
22374| [37200] Microsoft SQL Server 2000 Service Pack 1 update is not installed
22375| [37198] Microsoft SQL Server 2000 Service Pack 3 update is not installed
22376| [34634] Microsoft Windows Server 2003 Active Directory information disclosure
22377| [34599] Microsoft Windows Server 2003 terminal server security bypass
22378| [34473] Microsoft Office 2000 ActiveX control buffer overflow
22379| [33713] Microsoft Word 2007 multiple unspecified denial of service
22380| [33712] Microsoft Word 2007 wwlib.dll buffer overflow
22381| [32631] Microsoft SQL Server 2000 Service Pack 2 update is not installed
22382| [31821] Microsoft Windows time zone update for year 2007
22383| [31196] Microsoft Office 2003 Brazilian Grammar Checker buffer overflow
22384| [30905] Microsoft Project Server 2003 pdsrequest.asp information disclosure
22385| [29546] Microsoft Windows 2000/2003 user logoff initiated
22386| [29545] Microsoft Windows 2000/2003 system time changed
22387| [29544] Microsoft Windows 2000/2003 system security access removed
22388| [29543] Microsoft Windows 2000/2003 security access granted
22389| [29542] Microsoft Windows 2000/2003 SAM notification package loaded
22390| [29541] Microsoft Windows 2000/2003 primary security token issued
22391| [29540] Microsoft Windows 2000/2003 user password reset successful
22392| [29539] Microsoft Windows 2000/2003 object indirectly accessed
22393| [29538] Microsoft Windows 2000/2003 object handle duplicated
22394| [29537] Microsoft Windows 2000/2003 logon with explicit credentials success
22395| [29536] Microsoft Windows 2000/2003 logon attempt using explicit credentials unsuccessful
22396| [29535] Microsoft Windows 2000/2003 IPSEC policy agent failed
22397| [29534] Microsoft Windows 2000/2003 IPSEC policy agent disabled
22398| [29533] Microsoft Windows 2000/2003 IPSEC policy agent changed
22399| [29532] Microsoft Windows 2000/2003 IKE security association established
22400| [29531] Microsoft Windows 2000/2003 IKE quick mode association ended
22401| [29530] Microsoft Windows 2000/2003 IKE main mode association ended
22402| [29529] Microsoft Windows 2000/2003 IKE association negotiation failed
22403| [29528] Microsoft Windows 2000/2003 IKE association peer authentication failed
22404| [29527] Microsoft Windows 2000/2003 IKE association failed invalid proposal
22405| [29526] Microsoft Windows 2000/2003 IKE association failed authentication parameters
22406| [29525] Microsoft Windows 2000/2003 DPAPI master key backup attempted
22407| [29524] Microsoft Windows 2000/2003 DPAPI key recovery attempted
22408| [29523] Microsoft Windows 2000/2003 DPAPI auditable data unprotected
22409| [29522] Microsoft Windows 2000/2003 administrative group security descriptor set
22410| [29521] Microsoft Windows 2000/2003 account name changed
22411| [29507] Microsoft Office 2003 unspecified PowerPoint NULL pointer dereference denial of service
22412| [28512] Microsoft Internet Explorer multiple Windows 2000 COM object denial of service
22413| [28005] Microsoft Windows 2000 Management Console (MMC) resource file cross-site scripting
22414| [26118] Microsoft Office 2003 mailto: information disclosure
22415| [25330] Microsoft Commerce Server 2002 authfiles/login.asp authentication bypass
22416| [24474] Microsoft Windows 2000 LDAP client accepts untrusted CA
22417| [24473] Microsoft Windows 2000 event ID 565 not logged
22418| [24472] Microsoft Windows 2000 Event ID 1704 records incorrect group policy settings
22419| [24407] Microsoft Windows 2000 SECEDIT command fails to set ACLs correctly
22420| [24405] Microsoft Windows 2000 UPN credentials with trailing dot group policy bypass
22421| [24403] Microsoft Windows 2000 WideCharToMultiByte() incorrect Japanese character conversion
22422| [24402] Microsoft Windows 2000 Terminal Service client IP not logged
22423| [24400] Microsoft Windows 2000 domain authentication can be bypassed by a local administrator
22424| [23066] Microsoft Windows XP and 2000 Server MSRPC memory allocation denial of service
22425| [22318] Microsoft SQL Server 2000 Service Pack 4 update is not installed
22426| [22183] Microsoft Exchange Server 2003 public folder denial of service
22427| [21345] Microsoft Windows 2000 Update Rollup 1 for Service Pack 4 has not been installed
22428| [21315] Microsoft Outlook 2002 connector for Domino bypass restrictions
22429| [19969] Multiple Microsoft Windows Server 2003 Edition printer driver denial of service
22430| [19965] Multiple Microsoft Windows Server 2003 Editions SMB redirector denial of service
22431| [19727] Microsoft Windows 2000 GDI32.DLL denial of service
22432| [19629] Microsoft Exchange Server 2003 folder denial of service
22433| [17826] Microsoft Outlook 2003 CID security bypass
22434| [17624] Microsoft Windows XP and Windows Server 2003 Compressed Folders buffer overflow
22435| [17621] Microsoft Windows 2003 SMTP service code execution
22436| [17560] Microsoft Windows 2000 and XP GDI library denial of service
22437| [17521] Microsoft Windows 2000 Service Pack 4 is not installed
22438| [16913] Microsoft Windows 2003 users with Synchronize directory service data privilege
22439| [16912] Microsoft Windows 2003 groups with Synchronize directory service data privilege
22440| [16909] Microsoft Windows 2003 groups with Remove computer from docking station privilege
22441| [16907] Microsoft Windows 2003 users with Create global objects privilege
22442| [16905] Microsoft Windows 2003 users or groups with Create global objects privilege
22443| [16851] Microsoft Windows 2003 and XP WinKey and U key denial of service
22444| [16704] Microsoft Windows 2000 Media Player control code execution
22445| [16582] Microsoft Windows Server 2003 kernel CPU denial of service
22446| [16572] Microsoft Windows 2003 Users with Impersonate a client after authentication privilege
22447| [16570] Microsoft Windows 2003 Users with Create global objects privilege
22448| [16564] Microsoft Windows 2003 Groups with Create global objects privilege
22449| [16562] Microsoft Windows 2003 Groups with "
22450| [16522] Microsoft Windows 2003 Impersonate a client after authentication privilege
22451| [16521] Microsoft Windows 2003 Deny Logon Through Terminal Services privilege
22452| [16520] Microsoft Windows 2003 Create global objects privilege
22453| [16276] Microsoft Windows 2000 Advanced Server fully qualified domain name security bypass
22454| [16173] Microsoft Outlook 2003 OLE object bypass restricted security zone
22455| [16119] Microsoft Outlook 2000 URL spoofing
22456| [16104] Microsoft Outlook 2003 predictable file location could allow code execution
22457| [16095] Microsoft Windows XP and Windows Server 2003 HCP URL code execution
22458| [15704] Microsoft Windows XP and Windows Server 2003 HCP URL code execution
22459| [15700] Microsoft Windows 2000 Domain Controller LSASS LDAP message denial of service
22460| [15632] Microsoft Windows 2000 Utility Manger allows privilege escalation
22461| [15414] Microsoft Outlook 2002 mailto URL allows execution of code
22462| [15263] Microsoft Windows XP and 2000 Server kernel allows elevated privileges
22463| [15057] Microsoft Windows XP and Windows Server 2003 smbmount Linux client denial of service
22464| [15038] Microsoft Windows 2000 Server Windows Media Services denial of service
22465| [15037] Microsoft Windows Server 2003 WINS /GS flag denial of service
22466| [14178] Microsoft ISA Exchange Server 2003 MS04-002 patch is not installed
22467| [14167] Microsoft ISA Server 2000 H.323 filter buffer overflow
22468| [13426] Microsoft Windows 2000 and XP RPC race condition
22469| [13423] Microsoft Windows 2000 Local Troubleshooter ActiveX control buffer overflow
22470| [13407] Microsoft Windows 2000 Server mqsvc.exe MQLocateBegin packet buffer overflow
22471| [13385] Microsoft Windows Server 2003 "
22472| [13211] Microsoft Windows 2000 and XP URG memory leak
22473| [13171] Microsoft Windows Server 2003 can allow attacker to bypass mechanism used to detect buffer overflows
22474| [13131] Microsoft Windows 2000 Message Queue Manager buffer overflow
22475| [12684] Microsoft Exchange Server OWA Outlook 2003 denial of service
22476| [12652] Microsoft Windows 2000 and NT 4.0 Server IIS ISAPI nsiislog.dll extension POST request buffer overflow
22477| [12620] Microsoft Windows 2000 Server SMTP FILETIME denial of service
22478| [12543] Microsoft Windows 2000 Accessibility Utility Manager could allow an attacker to gain privileges
22479| [12493] Microsoft Windows Shell32.dll 2000 ShellExecute function buffer overflow
22480| [12489] Microsoft Windows 2000 Server Active Directory buffer overflow
22481| [12128] Microsoft Windows 2000 and Windows NT MS03-019 patch is not installed
22482| [12092] Microsoft Windows 2000 and NT 4.0 Server IIS ISAPI nsiislog.dll extension buffer overflow
22483| [12048] Microsoft Windows 2000 and Windows Server 2003 LAN Manager hash creation enabled
22484| [11901] Microsoft BizTalk Server 2002 SQL injection
22485| [11900] Microsoft BizTalk Server 2002 HTTP Receiver function buffer overflow
22486| [11816] Microsoft Windows 2000 Terminal Services MSGINA.DLL insecure access permissions
22487| [11696] Microsoft Windows 2000 Terminal Services man-in-the-middle attack
22488| [11617] Microsoft Windows 2000 MS03-007 patch is not installed on the system
22489| [11546] Microsoft Windows 2000 Windows Help Facility .cnt file buffer overflow
22490| [11329] Microsoft Windows NT and 2000 cmd.exe CD path name buffer overflow
22491| [11274] Microsoft Windows 2000 NetBIOS continuation packets denial of service
22492| [11273] Microsoft Windows 2000 RPC service could allow an attacker to gain elevated privileges
22493| [11216] Microsoft Windows NT and 2000 command prompt denial of service
22494| [11141] Microsoft Windows 2000 Terminal Services MSGINA.DLL denial of service
22495| [11133] Microsoft Outlook 2002 using V1 Exchange Server Security certificates transmits plaintext emails
22496| [10843] Microsoft Windows 2000 and XP SMB signing group policy modification
22497| [10431] Microsoft Windows 2000 SNMP LANMAN Extension memory leak denial of service
22498| [10400] Microsoft Windows 2000 RPC TCP port 135 denial of service
22499| [10377] Microsoft Windows XP and 2000 administrative alerts fail when security event log is full
22500| [10199] Microsoft Windows 2000/XP PPTP packet buffer overflow
22501| [10195] Microsoft FrontPage Server Extensions (FPSE) 2002 SmartHTML Interpreter buffer overflow
22502| [10194] Microsoft FrontPage Server Extensions (FPSE) 2000 SmartHTML Interpreter denial of service
22503| [9946] Microsoft Windows 2000 Terminal Services session screensaver fails to lock the console
22504| [9856] Microsoft Windows 2000 NCM handler routine could allow elevated privileges
22505| [9779] Microsoft Windows 2000 weak system partition permissions
22506| [9752] Microsoft Windows 2000 Service Pack 3 is not installed
22507| [9746] Microsoft Windows 2000 HTML Help item parameter buffer overflow
22508| [9625] Microsoft Windows 2000 Narrator allows login information to be audible
22509| [9154] Microsoft Data Engine (MSDE) and Microsoft SQL Server 2000 Desktop Engine have a default blank "
22510| [8867] Microsoft Windows 2000 LanMan denial of service
22511| [8813] Microsoft Windows 2000 Terminal Services allows attacker to bypass group policy settings
22512| [8759] Microsoft Windows 2000 could allow an attacker to block the application of Group Policy settings
22513| [8752] Microsoft Windows NT, 2000, and XP MUP buffer overflow
22514| [8739] Microsoft Windows 2000 DCOM memory leak
22515| [8708] Microsoft Outlook 2000 and 2002 executes embedded script in object tag when replying or forwarding HTML mail
22516| [8402] Microsoft Windows 2000 allows an attacker to bypass password policy
22517| [8307] Microsoft Windows 2000, Windows XP, and Exchange 2000 SMTP data transfer command denial of service
22518| [8304] Microsoft Windows 2000 and Exchange 5.5 SMTP service unauthorized mail privileges
22519| [8254] Microsoft Commerce Server 2000 AuthFilter ISAPI filter buffer overflow
22520| [8199] Microsoft Windows 2000 Terminal Services unlocked client
22521| [8094] Microsoft Windows 2000 and Interix 2.2 Telnet protocol option buffer overflow
22522| [8092] Microsoft Exchange 2000 System Attendant sets incorrect registry permissions
22523| [8043] Microsoft Windows NT, 2000, and XP using NTFS could allow files to be hidden
22524| [8037] Microsoft Windows 2000 empty TCP packet denial of service
22525| [8023] Microsoft Windows NT and Windows 2000 SIDs could allow an attacker to gain elevated privileges in another domain
22526| [7919] Microsoft IIS 4.0 and Norton Internet Security 2001 default permissions could allow an attacker to modify log files
22527| [7667] Microsoft Windows 2000 IKE UDP packet flood denial of service
22528| [7566] Microsoft IIS 2.0 and 3.0 upgraded to Microsoft IIS 4.0 fails to remove the ism.dll file
22529| [7538] Microsoft Windows 2000 and XP Terminal services allow an attacker to spoof IP addresses
22530| [7533] Microsoft Windows 2000 RunAs service denial of service
22531| [7532] Microsoft Windows 2000 RunAs service allows local attacker to bypass pipe authentication
22532| [7531] Microsoft Windows 2000 RunAs service reveals sensitive information
22533| [7528] Microsoft Windows NT and Windows 2000 malformed RPC request denial of service
22534| [7409] Microsoft Windows 2000 and Windows XP GDI denial of service
22535| [7302] Microsoft Windows NT and 2000 Terminal Server malformed RDP packet series denial of service
22536| [7008] Microsoft Windows 2000 IrDA device denial of service
22537| [6977] Microsoft Windows NT and 2000 NNTP memory leak denial of service
22538| [6931] Microsoft Windows 2000 without Service Pack 2
22539| [6919] Microsoft Windows 2000 Task Manager does not terminate malicious files with the same name as a system process
22540| [6912] Microsoft Windows NT and 2000 Terminal Server RDP memory leak denial of service
22541| [6876] Microsoft Windows 2000 could allow an attacker to change network passwords
22542| [6803] Microsoft Windows 2000 SMTP service allows mail relaying
22543| [6745] Microsoft Windows 2000 LDAP function could allow domain user password change
22544| [6669] Microsoft Windows 2000 Telnet system call denial of service
22545| [6668] Microsoft Windows 2000 Telnet handle leak denial of service
22546| [6667] Microsoft Windows 2000 Telnet multiple idle sessions denial of service
22547| [6666] Microsoft Windows 2000 Telnet username denial of service
22548| [6665] Microsoft Windows 2000 Telnet service weak domain authentication
22549| [6664] Microsoft Windows 2000 Telnet service predictable pipe names could allow elevation of privileges
22550| [6652] Microsoft Exchange 2000 OWA script execution
22551| [6590] Microsoft Windows 2000 debug registers allow attacker to gain elevated privileges
22552| [6506] Microsoft Windows 2000 Server Kerberos denial of service
22553| [6443] Microsoft Windows 2000 catalog file could remove installed hotfixes
22554| [6160] Microsoft Windows 2000 event viewer buffer overflow
22555| [6136] Microsoft Windows 2000 domain controller denial of service
22556| [6035] Microsoft Windows 2000 Server RDP denial of service
22557| [5973] Microsoft Windows 2000 EFS allows local user to recover sensitive data
22558| [5936] Microsoft Windows 2000 Server Directory Service Restore Mode allows user to login with blank password
22559| [5800] Microsoft Windows 2000 Index Service ActiveX controls allow unauthorized access to file information
22560| [5623] Microsoft Windows NT and 2000 Phone Book service buffer overflow
22561| [5598] Microsoft Windows 2000 Telnet daemon could allow a denial of service
22562| [5585] Microsoft Windows 2000 brute force attack
22563| [5502] Microsoft Windows 2000 Indexing Services ixsso.query
22564| [5467] Microsoft Windows 2000 System Monitor ActiveX control buffer overflow
22565| [5399] Microsoft Windows NT and 2000 Network Monitor buffer overflow
22566| [5301] Microsoft Windows 2000 Simplified Chinese IME State Recognition
22567| [5263] Microsoft Office 2000 executes .dll without users knowledge
22568| [5242] Microsoft Windows 2000 Telnet client NTLM authentication weakness
22569| [5222] Microsoft Windows 2000 malformed RPC packet denial of service
22570| [5203] Microsoft Windows 2000 still image service
22571| [5171] Microsoft Windows 2000 Local Security Policy corruption
22572| [5080] Microsoft Office 2000 HTML object tag buffer overflow
22573| [5033] Microsoft Windows 2000 without Service Pack 1
22574| [5031] Microsoft Windows 2000 Service Control Manager named pipe could allow a unauthorized user to gain privileges
22575| [5015] Microsoft Windows NT and 2000 executable path
22576| [4887] Microsoft Windows 2000 Kerberos ticket renewed
22577| [4886] Microsoft Windows 2000 logon session reconnected
22578| [4885] Microsoft Windows 2000 logon session disconnected
22579| [4882] Microsoft Windows 2000 Kerberos pre-authentication failed
22580| [4873] Microsoft Windows 2000 user account mapped for logon
22581| [4872] Microsoft Windows 2000 account logon failed
22582| [4871] Microsoft Windows 2000 account used for logon
22583| [4855] Microsoft Windows 2000 group type change
22584| [4842] Microsoft Internet Explorer and Microsoft Powerpoint 2000 ActiveX object execution
22585| [4841] Microsoft Internet Explorer and Microsoft Access 2000 VBA code execution
22586| [4823] Microsoft Windows 2000 Telnet server binary stream denial of service
22587| [4819] Microsoft Windows 2000 default SYSKEY configuration
22588| [4787] Microsoft Windows 2000 user account locked out
22589| [4786] Microsoft Windows 2000 computer account created
22590| [4785] Microsoft Windows 2000 computer account changed
22591| [4784] Microsoft Windows 2000 computer account deleted
22592| [4714] Microsoft Windows 2000 "
22593| [4589] Microsoft Windows 2000 protected store can be compromised by brute force attack
22594| [4278] Microsoft Windows 2000 unattended install does not secure All Users profile
22595| [4138] Microsoft Windows 2000 system file integrity feature is disabled
22596| [4086] Microsoft Windows 2000 may not start Jaz drives correctly
22597| [4085] Microsoft Windows 2000 non-Gregorial calendar error
22598| [4084] Microsoft Windows 2000 may prevent Adobe FrameMaker files from being saved in some formats
22599| [4083] Microsoft Windows 2000 Terminal Services may damage Office files saved as HTML
22600| [4082] Microsoft Windows 2000 and Iomega parallel port drives display error
22601| [4080] Microsoft Windows 2000 AOL image support
22602| [4079] Microsoft Windows 2000 High Encryption Pack
22603| [3854] Microsoft Office 2000 security setting
22604| [1376] Microsoft Proxy 2.0 denial of service
22605| [86256] Microsoft Windows Knowledge Base Article 2876063 update is not installed
22606| [86097] Microsoft Windows Knowledge Base Article 2859537 update is not installed
22607| [86091] Microsoft Windows Knowledge Base Article 2868623 update is not installed
22608| [86089] Microsoft Windows Knowledge Base Article 2862772 update is not installed
22609| [86075] Microsoft Windows Knowledge Base Article 2850869 update is not installed
22610| [86073] Microsoft Windows Knowledge Base Article 2873872 update is not installed
22611| [86070] Microsoft Windows Knowledge Base Article 2849568 update is not installed
22612| [85245] Microsoft Windows Knowledge Base Article 2848295 update is not installed
22613| [85244] Microsoft Windows Knowledge Base Article 2847927 update is not installed
22614| [85243] Microsoft Windows Knowledge Base Article 2861561 update is not installed
22615| [85236] Microsoft Windows Knowledge Base Article 2850851 update is not installed
22616| [85227] Microsoft Windows Knowledge Base Article 2847883 update is not installed
22617| [85223] Microsoft Windows Knowledge Base Article 2846071 update is not installed
22618| [85205] Microsoft Windows Knowledge Base Article 2845187 update is not installed
22619| [84621] Microsoft Windows Knowledge Base Article 2845690 update is not installed
22620| [84619] Microsoft Windows Knowledge Base Article 2839894 update is not installed
22621| [84617] Microsoft Windows Knowledge Base Article 2839571 update is not installed
22622| [84615] Microsoft Windows Knowledge Base Article 2839229 update is not installed
22623| [84613] Microsoft Windows Knowledge Base Article 2838727 update is not installed
22624| [84156] Microsoft Windows Knowledge Base Article 2847204 update is not installed
22625| [83912] Microsoft Windows Knowledge Base Article 2829254 update is not installed
22626| [83910] Microsoft Windows Knowledge Base Article 2829530 update is not installed
22627| [83898] Microsoft Windows Knowledge Base Article 2830397 update is not installed
22628| [83886] Microsoft Windows Knowledge Base Article 2830399 update is not installed
22629| [83884] Microsoft Windows Knowledge Base Article 2834692 update is not installed
22630| [83882] Microsoft Windows Knowledge Base Article 2834695 update is not installed
22631| [83880] Microsoft Windows Knowledge Base Article 2836440 update is not installed
22632| [83876] Microsoft Windows Knowledge Base Article 2840221 update is not installed
22633| [83192] Microsoft Windows Knowledge Base Article 2817183 update is not installed
22634| [83100] Microsoft Windows Knowledge Base Article 2830914 update is not installed
22635| [83098] Microsoft Windows Knowledge Base Article 2829996 update is not installed
22636| [83093] Microsoft Windows Knowledge Base Article 2828223 update is not installed
22637| [83091] Microsoft Windows Knowledge Base Article 2813170 update is not installed
22638| [83088] Microsoft Windows Knowledge Base Article 2827663 update is not installed
22639| [83086] Microsoft Windows Knowledge Base Article 2823482 update is not installed
22640| [83084] Microsoft Windows Knowledge Base Article 2821818 update is not installed
22641| [83082] Microsoft Windows Knowledge Base Article 2820917 update is not installed
22642| [82600] Microsoft Windows Knowledge Base Article 2813707 update is not installed
22643| [82424] Microsoft Windows Knowledge Base Article 2814124 update is not installed
22644| [82422] Microsoft Windows Knowledge Base Article 2780176 update is not installed
22645| [82401] Microsoft Windows Knowledge Base Article 2813682 update is not installed
22646| [82399] Microsoft Windows Knowledge Base Article 2816264 update is not installed
22647| [81683] Microsoft Windows Knowledge Base Article 2780091 update is not installed
22648| [81681] Microsoft Windows Knowledge Base Article 2784242 update is not installed
22649| [81680] Microsoft Windows Knowledge Base Article 2790113 update is not installed
22650| [81678] Microsoft Windows Knowledge Base Article 2790655 update is not installed
22651| [81676] Microsoft Windows Knowledge Base Article 2790978 update is not installed
22652| [81674] Microsoft Windows Knowledge Base Article 2797052 update is not installed
22653| [81672] Microsoft Windows Knowledge Base Article 2799494 update is not installed
22654| [81666] Microsoft Windows Knowledge Base Article 2778344 update is not installed
22655| [81634] Microsoft Windows Knowledge Base Article 2792100 update is not installed
22656| [81339] Microsoft Windows Knowledge Base Article 2799329 update is not installed
22657| [80875] Microsoft Windows Knowledge Base Article 2756145 update is not installed
22658| [80872] Microsoft Windows Knowledge Base Article 2769324 update is not installed
22659| [80867] Microsoft Windows Knowledge Base Article 2769327 update is not installed
22660| [80865] Microsoft Windows Knowledge Base Article 2769369 update is not installed
22661| [80863] Microsoft Windows Knowledge Base Article 2778930 update is not installed
22662| [80861] Microsoft Windows Knowledge Base Article 2785220 update is not installed
22663| [80365] Microsoft Windows Knowledge Base Article 2761465 update is not installed
22664| [80360] Microsoft Windows Knowledge Base Article 2765809 update is not installed
22665| [80358] Microsoft Windows Knowledge Base Article 2770660 update is not installed
22666| [80356] Microsoft Windows Knowledge Base Article 2780642 update is not installed
22667| [80352] Microsoft Windows Knowledge Base Article 2783534 update is not installed
22668| [80349] Microsoft Windows Knowledge Base Article 2784126 update is not installed
22669| [79693] Microsoft Windows Knowledge Base Article 2745030 update is not installed
22670| [79687] Microsoft Windows Knowledge Base Article 2761451 update is not installed
22671| [79683] Microsoft Windows Knowledge Base Article 2761226 update is not installed
22672| [79679] Microsoft Windows Knowledge Base Article 2758857 update is not installed
22673| [79677] Microsoft Windows Knowledge Base Article 2727528 update is not installed
22674| [78864] Microsoft Windows Knowledge Base Article 2754670 update is not installed
22675| [78862] Microsoft Windows Knowledge Base Article 2743555 update is not installed
22676| [78858] Microsoft Windows Knowledge Base Article 2754849 update is not installed
22677| [78856] Microsoft Windows Knowledge Base Article 2724197 update is not installed
22678| [78853] Microsoft Windows Knowledge Base Article 2741517 update is not installed
22679| [78851] Microsoft Windows Knowledge Base Article 2742319 update is not installed
22680| [78848] Microsoft Windows Knowledge Base Article 2742321 update is not installed
22681| [78760] Microsoft Windows Knowledge Base Article 2744842 update is not installed
22682| [78077] Microsoft Windows Knowledge Base Article 2741528 update is not installed
22683| [78075] Microsoft Windows Knowledge Base Article 2720184 update is not installed
22684| [78071] Microsoft Windows Knowledge Base Article 2748552 update is not installed
22685| [77512] Microsoft Windows Knowledge Base Article 2740358 update is not installed
22686| [77362] Microsoft Windows Knowledge Base Article 2733918 update is not installed
22687| [77360] Microsoft Windows Knowledge Base Article 2733829 update is not installed
22688| [77357] Microsoft Windows Knowledge Base Article 2733594 update is not installed
22689| [77352] Microsoft Windows Knowledge Base Article 2731879 update is not installed
22690| [77350] Microsoft Windows Knowledge Base Article 2731847 update is not installed
22691| [77348] Microsoft Windows Knowledge Base Article 2723135 update is not installed
22692| [77346] Microsoft Windows Knowledge Base Article 2722913 update is not installed
22693| [77342] Microsoft Windows Knowledge Base Article 2720573 update is not installed
22694| [77325] Microsoft Windows Knowledge Base Article 2719584 update is not installed
22695| [76808] Microsoft Windows Knowledge Base Article 2721015 update is not installed
22696| [76725] Microsoft Windows Knowledge Base Article 2722479 update is not installed
22697| [76724] Microsoft Windows Knowledge Base Article 2719177 update is not installed
22698| [76721] Microsoft Windows Knowledge Base Article 2718523 update is not installed
22699| [76718] Microsoft Windows Knowledge Base Article 2698365 update is not installed
22700| [76711] Microsoft Windows Knowledge Base Article 2695502 update is not installed
22701| [76704] Microsoft Windows Knowledge Base Article 2691442 update is not installed
22702| [76702] Microsoft Windows Knowledge Base Article 2655992 update is not installed
22703| [75963] Microsoft Windows Knowledge Base Article 2699988 update is not installed
22704| [75939] Microsoft Windows Knowledge Base Article 2685939 update is not installed
22705| [75928] Microsoft Windows Knowledge Base Article 2711167 update is not installed
22706| [75136] Microsoft Windows Knowledge Base Article 2693777 update is not installed
22707| [75132] Microsoft Windows Knowledge Base Article 2690533 update is not installed
22708| [75130] Microsoft Windows Knowledge Base Article 2688338 update is not installed
22709| [75127] Microsoft Windows Knowledge Base Article 2681578 update is not installed
22710| [75123] Microsoft Windows Knowledge Base Article 2680352 update is not installed
22711| [75116] Microsoft Windows Knowledge Base Article 2597981 update is not installed
22712| [74556] Microsoft Windows Knowledge Base Article 2639185 update is not installed
22713| [74384] Microsoft Windows Knowledge Base Article 2675157 update is not installed
22714| [74378] Microsoft Windows Knowledge Base Article 2671605 update is not installed
22715| [74373] Microsoft Windows Knowledge Base Article 2664258 update is not installed
22716| [74369] Microsoft Windows Knowledge Base Article 2663860 update is not installed
22717| [73543] Microsoft Windows Knowledge Base Article 2671387 update is not installed
22718| [73540] Microsoft Windows Knowledge Base Article 2665364 update is not installed
22719| [73538] Microsoft Windows Knowledge Base Article 2651019 update is not installed
22720| [73536] Microsoft Windows Knowledge Base Article 2651018 update is not installed
22721| [73533] Microsoft Windows Knowledge Base Article 2647170 update is not installed
22722| [73530] Microsoft Windows Knowledge Base Article 2641653 update is not installed
22723| [72887] Microsoft Windows Knowledge Base Article 2663841 update is not installed
22724| [72873] Microsoft Windows Knowledge Base Article 2663830 update is not installed
22725| [72867] Microsoft Windows Knowledge Base Article 2663510 update is not installed
22726| [72857] Microsoft Windows Knowledge Base Article 2661637 update is not installed
22727| [72855] Microsoft Windows Knowledge Base Article 2660465 update is not installed
22728| [72853] Microsoft Windows Knowledge Base Article 2653956 update is not installed
22729| [72851] Microsoft Windows Knowledge Base Article 2654428 update is not installed
22730| [72849] Microsoft Windows Knowledge Base Article 2651026 update is not installed
22731| [72846] Microsoft Windows Knowledge Base Article 2647516 update is not installed
22732| [72841] Microsoft Windows Knowledge Base Article 2645640 update is not installed
22733| [72838] Microsoft Windows Knowledge Base Article 2643719 update is not installed
22734| [72029] Microsoft Windows Knowledge Base Article 2638420 update is not installed
22735| [72003] Microsoft Windows Knowledge Base Article 2646524 update is not installed
22736| [71998] Microsoft Windows Knowledge Base Article 2644615 update is not installed
22737| [71995] Microsoft Windows Knowledge Base Article 2643584 update is not installed
22738| [71994] Microsoft Windows Knowledge Base Article 2636391 update is not installed
22739| [71565] Microsoft Windows Knowledge Base Article 2648048 update is not installed
22740| [71562] Microsoft Windows Knowledge Base Article 2640241 update is not installed
22741| [71560] Microsoft Windows Knowledge Base Article 2640045 update is not installed
22742| [71558] Microsoft Windows Knowledge Base Article 2639417 update is not installed
22743| [71557] Microsoft Windows Knowledge Base Article 2639142 update is not installed
22744| [71554] Microsoft Windows Knowledge Base Article 2633171 update is not installed
22745| [71552] Microsoft Windows Knowledge Base Article 2624667 update is not installed
22746| [71550] Microsoft Windows Knowledge Base Article 2620712 update is not installed
22747| [71548] Microsoft Windows Knowledge Base Article 2618451 update is not installed
22748| [71546] Microsoft Windows Knowledge Base Article 2618444 update is not installed
22749| [71538] Microsoft Windows Knowledge Base Article 2590602 update is not installed
22750| [70951] Microsoft Windows Knowledge Base Article 2630837 update is not installed
22751| [70949] Microsoft Windows Knowledge Base Article 2620704 update is not installed
22752| [70947] Microsoft Windows Knowledge Base Article 2617657 update is not installed
22753| [70943] Microsoft Windows Knowledge Base Article 2588516 update is not installed
22754| [70152] Microsoft Windows Knowledge Base Article 2623699 update is not installed
22755| [70140] Microsoft Windows Knowledge Base Article 2652016 update is not installed
22756| [70130] Microsoft Windows Knowledge Base Article 2586448 update is not installed
22757| [70115] Microsoft Windows Knowledge Base Article 2567053 update is not installed
22758| [69501] Microsoft Windows Knowledge Base Article 2587634 update is not installed
22759| [69498] Microsoft Windows Knowledge Base Article 2587505 update is not installed
22760| [69492] Microsoft Windows Knowledge Base Article 2571621 update is not installed
22761| [69490] Microsoft Windows Knowledge Base Article 2570947 update is not installed
22762| [68840] Microsoft Windows Knowledge Base Article 2451858 update is not installed
22763| [68833] Microsoft Windows Knowledge Base Article 2567943 update is not installed
22764| [68831] Microsoft Windows Knowledge Base Article 2570222 update is not installed
22765| [68829] Microsoft Windows Knowledge Base Article 2567951 update is not installed
22766| [68827] Microsoft Windows Knowledge Base Article 2578230 update is not installed
22767| [68825] Microsoft Windows Knowledge Base Article 2546250 update is not installed
22768| [68823] Microsoft Windows Knowledge Base Article 2559049 update is not installed
22769| [68816] Microsoft Windows Knowledge Base Article 2556532 update is not installed
22770| [68814] Microsoft Windows Knowledge Base Article 2560656 update is not installed
22771| [68812] Microsoft Windows Knowledge Base Article 2560978 update is not installed
22772| [68809] Microsoft Windows Knowledge Base Article 2562485 update is not installed
22773| [68806] Microsoft Windows Knowledge Base Article 2566454 update is not installed
22774| [68804] Microsoft Windows Knowledge Base Article 2563894 update is not installed
22775| [68801] Microsoft Windows Knowledge Base Article 2567680 update is not installed
22776| [68315] Microsoft Windows Knowledge Base Article 2555917 update is not installed
22777| [68299] Microsoft Windows Knowledge Base Article 2566220 update is not installed
22778| [68283] Microsoft Windows Knowledge Base Article 2560847 update is not installed
22779| [67955] Microsoft Windows Knowledge Base Article 2530548 update is not installed
22780| [67943] Microsoft Windows Knowledge Base Article 2544521 update is not installed
22781| [67762] Microsoft Windows Knowledge Base Article 2543893 update is not installed
22782| [67759] Microsoft Windows Knowledge Base Article 2544893 update is not installed
22783| [67757] Microsoft Windows Knowledge Base Article 2476490 update is not installed
22784| [67753] Microsoft Windows Knowledge Base Article 2514842 update is not installed
22785| [67751] Microsoft Windows Knowledge Base Article 2518295 update is not installed
22786| [67737] Microsoft Windows Knowledge Base Article 2520426 update is not installed
22787| [67733] Microsoft Windows Knowledge Base Article 2525694 update is not installed
22788| [67731] Microsoft Windows Knowledge Base Article 2525835 update is not installed
22789| [67728] Microsoft Windows Knowledge Base Article 2535512 update is not installed
22790| [67725] Microsoft Windows Knowledge Base Article 2536275 update is not installed
22791| [67722] Microsoft Windows Knowledge Base Article 2536276 update is not installed
22792| [67718] Microsoft Windows Knowledge Base Article 2537146 update is not installed
22793| [67709] Microsoft Windows Knowledge Base Article 2538814 update is not installed
22794| [67302] Microsoft Windows Knowledge Base Article 2545814 update is not installed
22795| [67101] Microsoft Windows Knowledge Base Article 2524426 update is not installed
22796| [66446] Microsoft Windows Knowledge Base Article 2514666 update is not installed
22797| [66444] Microsoft Windows Knowledge Base Article 2511455 update is not installed
22798| [66436] Microsoft Windows Knowledge Base Article 2497640 update is not installed
22799| [66432] Microsoft Windows Knowledge Base Article 2527308 update is not installed
22800| [66428] Microsoft Windows Knowledge Base Article 2489979 update is not installed
22801| [66423] Microsoft Windows kernel-mode driver (win32k.sys) variant 29 privilege escalation
22802| [66422] Microsoft Windows kernel-mode driver (win32k.sys) variant 28 privilege escalation
22803| [66421] Microsoft Windows kernel-mode driver (win32k.sys) variant 27 privilege escalation
22804| [66420] Microsoft Windows kernel-mode driver (win32k.sys) variant 26 privilege escalation
22805| [66419] Microsoft Windows kernel-mode driver (win32k.sys) variant 25 privilege escalation
22806| [66418] Microsoft Windows kernel-mode driver (win32k.sys) variant 24 privilege escalation
22807| [66417] Microsoft Windows kernel-mode driver (win32k.sys) variant 23 privilege escalation
22808| [66416] Microsoft Windows kernel-mode driver (win32k.sys) variant 22 privilege escalation
22809| [66415] Microsoft Windows kernel-mode driver (win32k.sys) variant 21 privilege escalation
22810| [66414] Microsoft Windows kernel-mode driver (win32k.sys) variant 20 privilege escalation
22811| [66396] Microsoft Windows kernel-mode driver (win32k.sys) variant 2 privilege escalation
22812| [66394] Microsoft Windows Knowledge Base Article 2485663 update is not installed
22813| [65588] Microsoft Windows Knowledge Base Article 2489279 update is not installed
22814| [65581] Microsoft Windows Knowledge Base Article 2510030 update is not installed
22815| [65580] Microsoft Windows Knowledge Base Article 2489283 update is not installed
22816| [65575] Microsoft Windows Knowledge Base Article 2489293 update is not installed
22817| [65573] Microsoft Windows Knowledge Base Article 2494047 update is not installed
22818| [64973] Microsoft Windows Knowledge Base Article 2478960 update is not installed
22819| [64971] Microsoft Windows Knowledge Base Article 2479628 update is not installed
22820| [64927] Microsoft Windows Knowledge Base Article 2393802 update is not installed
22821| [64925] Microsoft Windows Knowledge Base Article 2451879 update is not installed
22822| [64920] Microsoft Windows Knowledge Base Article 2475792 update is not installed
22823| [64918] Microsoft Windows Knowledge Base Article 2476687 update is not installed
22824| [64916] Microsoft Windows Knowledge Base Article 2478953 update is not installed
22825| [64914] Microsoft Windows Knowledge Base Article 2482017 update is not installed
22826| [64910] Microsoft Windows Knowledge Base Article 2483185 update is not installed
22827| [64909] Microsoft Windows Knowledge Base Article 2484015 update is not installed
22828| [64907] Microsoft Windows Knowledge Base Article 2485376 update is not installed
22829| [64905] Microsoft Windows Knowledge Base Article 2489256 update is not installed
22830| [64902] Microsoft Windows Knowledge Base Article 2496930 update is not installed
22831| [64342] Microsoft Windows Knowledge Base Article 2451910 update is not installed
22832| [64339] Microsoft Windows Knowledge Base Article 2478935 update is not installed
22833| [63584] Microsoft Windows Knowledge Base Article 2424434 update is not installed
22834| [63582] Microsoft Windows Knowledge Base Article 2423089 update is not installed
22835| [63580] Microsoft Windows Knowledge Base Article 2436673 update is not installed
22836| [63571] Microsoft Windows Knowledge Base Article 2440591 update is not installed
22837| [63569] Microsoft Windows Knowledge Base Article 2385678 update is not installed
22838| [63566] Microsoft Windows Knowledge Base Article 2442962 update is not installed
22839| [63564] Microsoft Windows Knowledge Base Article 2345316 update is not installed
22840| [63562] Microsoft Windows Knowledge Base Article 2296199 update is not installed
22841| [63558] Microsoft Windows Knowledge Base Article 2416400 update is not installed
22842| [63550] Microsoft Windows Knowledge Base Article 2447961 update is not installed
22843| [63548] Microsoft Windows Knowledge Base Article 2443105 update is not installed
22844| [63546] Microsoft Windows Knowledge Base Article 2455005 update is not installed
22845| [63544] Microsoft Windows Knowledge Base Article 2292970 update is not installed
22846| [62805] Microsoft Windows Knowledge Base Article 2316074 update is not installed
22847| [62793] Microsoft Windows Knowledge Base Article 2293386 update is not installed
22848| [62789] Microsoft Windows Knowledge Base Article 2423930 update is not installed
22849| [62170] Microsoft Windows Knowledge Base Article 2296011 update is not installed
22850| [62166] Microsoft Windows Knowledge Base Article 2294255 update is not installed
22851| [62163] Microsoft Windows Knowledge Base Article 2281679 update is not installed
22852| [62154] Microsoft Windows Knowledge Base Article 2279986 update is not installed
22853| [62147] Microsoft Windows Knowledge Base Article 2160841 update is not installed
22854| [62134] Microsoft Windows Knowledge Base Article 2412048 update is not installed
22855| [62129] Microsoft Windows Knowledge Base Article 2387149 update is not installed
22856| [62126] Microsoft Windows Knowledge Base Article 2378111 update is not installed
22857| [62123] Microsoft Windows Knowledge Base Article 2360937 update is not installed
22858| [62118] Microsoft Windows Knowledge Base Article 2293211 update is not installed
22859| [62104] Microsoft Windows Knowledge Base Article 2360131 update is not installed
22860| [62098] Microsoft Windows Knowledge Base Article 2293194 update is not installed
22861| [62069] Microsoft Windows Knowledge Base Article 2418042 update is not installed
22862| [61519] Microsoft Windows Knowledge Base Article 2121546 update is not installed
22863| [61517] Microsoft Windows Knowledge Base Article 2259922 update is not installed
22864| [61514] Microsoft Windows Knowledge Base Article 2267960 update is not installed
22865| [61510] Microsoft Windows Knowledge Base Article 2315011 update is not installed
22866| [61507] Microsoft Windows Knowledge Base Article 2320113 update is not installed
22867| [61504] Microsoft Windows Knowledge Base Article 2347290 update is not installed
22868| [60736] Microsoft Windows Knowledge Base Article 2265906 update is not installed
22869| [60734] Microsoft Windows Knowledge Base Article 2269638 update is not installed
22870| [60728] Microsoft Windows Knowledge Base Article 2269707 update is not installed
22871| [60724] Microsoft Windows Knowledge Base Article 2286198 update is not installed
22872| [60713] Microsoft Windows Knowledge Base Article 2183461 update is not installed
22873| [60698] Microsoft Windows Knowledge Base Article 2160329 update is not installed
22874| [60686] Microsoft Windows Knowledge Base Article 2115168 update is not installed
22875| [60684] Microsoft Windows Knowledge Base Article 2079403 update is not installed
22876| [60680] Microsoft Windows Knowledge Base Article 2264072 update is not installed
22877| [59901] Microsoft Windows Knowledge Base Article 2229593 update is not installed
22878| [59898] Microsoft Windows Knowledge Base Article 2229593 update is not installed
22879| [58913] Microsoft Windows Knowledge Base Article 2027452 update is not installed
22880| [58891] Microsoft Windows Knowledge Base Article 2028554 update is not installed
22881| [17004] Microsoft Windows XP Service Pack 2 is not installed on the system
22882| [9187] Microsoft Passport SDK 2.1 Component Configuration Document (CCD) permission
22883| [9146] Microsoft Passport SDK 2.1 events reporting disabled
22884| [9068] Microsoft Passport SDK 2.1 registry default permission exposure
22885| [9067] Microsoft Passport SDK 2.1 default test site exposure
22886| [9066] Microsoft Passport SDK 2.1 Adventure Works Sample Site exposure
22887| [9065] Microsoft Passport SDK 2.1 Adventure Works Sample Site global.asa file default permission exposure
22888| [9064] Microsoft Passport SDK 2.1 default time window exposure
22889| [1271] Microsoft IIS version 2 installed
22890| [621] Microsoft IIS 3.0 script source revealed by appending 2E to requests
22891|
22892| Exploit-DB - https://www.exploit-db.com:
22893| [30756] Microsoft Forms 2.0 ActiveX Control 2.0 Memory Access Violation Denial of Service Vulnerabilities
22894| [30749] Microsoft Office 2003 Web Component Memory Access Violation Denial of Service Vulnerability
22895| [30636] Microsoft Windows 2000/2003 Recursive DNS Spoofing Vulnerability (2)
22896| [30635] Microsoft Windows 2000/2003 Recursive DNS Spoofing Vulnerability (1)
22897| [30281] Microsoft .Net Framework <= 2.0 - Multiple Null Byte Injection Vulnerabilities
22898| [29664] Microsoft Office Publisher 2007 - Remote Denial of Service (DoS) Vulnerability
22899| [29660] Microsoft Office 2003 - Denial of Service (DoS) Vulnerability
22900| [29630] Microsoft Windows 2003/XP ReadDirectoryChangesW Information Disclosure Vulnerability
22901| [29524] Microsoft Word 2000 - Malformed Function Code Execution Vulnerability
22902| [28420] Microsoft Windows 2000 Multiple COM Object Instantiation Code Execution Vulnerabilities
22903| [28357] Microsoft Windows Explorer 2000/2003/XP Drag and Drop Remote Code Execution Vulnerability
22904| [28227] Microsoft Windows 2000/XP Registry Access Local Denial of Service Vulnerability
22905| [28226] Microsoft PowerPoint 2003 PPT File Closure Memory Corruption
22906| [28225] Microsoft PowerPoint 2003 powerpnt.exe Unspecified Issue
22907| [28224] Microsoft PowerPoint 2003 mso.dll PPT Processing Unspecified Code Execution
22908| [28198] Microsoft Office 2000/2002 Property Code Execution Vulnerability
22909| [28189] Microsoft Excel 2000-2004 Style Handling and Repair Remote Code Execution Vulnerability
22910| [28087] Microsoft Office 2003 Embedded Shockwave Flash Object Security Bypass Weakness
22911| [28005] Microsoft Exchange Server 2000/2003 Outlook Web Access Script Injection Vulnerability
22912| [26690] Microsoft Windows 2000/2003/XP CreateRemoteThread Local Denial of Service Vulnerability
22913| [26517] Microsoft Office PowerPoint 2007 - Crash PoC
22914| [26341] Microsoft Windows 2000/2003/XP MSDTC TIP Denial of Service Vulnerability
22915| [26222] Microsoft Windows 2000/2003/XP Keyboard Event Privilege Escalation Weakness
22916| [25384] Microsoft Windows 2000/XP Internet Protocol Validation Remote Code Execution Vulnerability (2)
22917| [25383] Microsoft Windows 2000/XP Internet Protocol Validation Remote Code Execution Vulnerability (1)
22918| [25231] Microsoft Windows 2000/2003/XP Graphical Device Interface Library Denial of Service Vulnerability
22919| [25085] Microsoft Office XP 2000/2002 HTML Link Processing Remote Buffer Overflow Vulnerability
22920| [25084] Microsoft Outlook 2003 Web Access Login Form Remote URI Redirection Vulnerability
22921| [25050] Microsoft Windows 2000/2003/XP winhlp32 Phrase Heap Overflow Vulnerability
22922| [25049] Microsoft Windows 2000/2003/XP winhlp32 Phrase Integer Overflow Vulnerability
22923| [24686] Microsoft Outlook 2003 Security Policy Bypass Vulnerability
22924| [24277] Microsoft Windows 2000/NT 4 POSIX Subsystem Buffer Overflow Local Privilege Escalation Vulnerability
22925| [24114] Microsoft Outlook 2003Mail Client E-mail Address Verification Weakness
22926| [24101] Microsoft Outlook 2003 Predictable File Location Weakness
22927| [23989] Microsoft Windows 2000/NT 4 Local Descriptor Table Local Privilege Escalation Vulnerability
22928| [23796] Microsoft Outlook 2002 Mailto Parameter Quoting Zone Bypass Vulnerability
22929| [23019] Microsoft Windows 2000 Subnet Bandwidth Manager RSVP Server Authority Hijacking Vulnerability
22930| [22919] Microsoft ISA Server 2000 Cross-Site Scripting Vulnerabilities
22931| [22883] Microsoft Windows 2000 CreateFile API Named Pipe Privilege Escalation Vulnerability (2)
22932| [22882] Microsoft Windows 2000 CreateFile API Named Pipe Privilege Escalation Vulnerability (1)
22933| [22837] Microsoft Windows 2000/NT 4 Media Services NSIISlog.DLL Remote Buffer Overflow
22934| [22782] Microsoft Windows 2000 Active Directory Remote Stack Overflow Vulnerability
22935| [22591] Microsoft Office Excel 2007 - WriteAV Crash PoC
22936| [22555] Microsoft BizTalk Server 2000/2002 DTA RawCustomSearchField.asp SQL Injection
22937| [22554] Microsoft BizTalk Server 2000/2002 DTA rawdocdata.asp SQL Injection Vulnerability
22938| [22553] Microsoft BizTalk Server 2002 HTTP Receiver Buffer Overflow Vulnerability
22939| [22528] Microsoft Windows 2000 RegEdit.EXE Registry Key Value Buffer Overflow Vulnerability
22940| [22354] Microsoft Windows 2000 Help Facility .CNT File :Link Buffer Overflow Vulnerability
22941| [21920] Microsoft Content Management Server 2001 Cross-Site Scripting Vulnerability
22942| [21718] Microsoft SQL 2000/7.0 Agent Jobs Privilege Elevation Vulnerability
22943| [21693] Microsoft SQL Server 2000 User Authentication Remote Buffer Overflow Vulnerability
22944| [21652] Microsoft SQL Server 2000 Resolution Service Heap Overflow Vulnerability
22945| [21651] Microsoft SQL Server 2000 sp_MScopyscript SQL Injection Vulnerability
22946| [21650] Microsoft SQL Server 2000 Database Consistency Checkers Buffer Overflow Vulnerability
22947| [21549] Microsoft SQL Server 2000 Password Encrypt Procedure Buffer Overflow Vulnerability
22948| [21541] Microsoft SQL Server 2000 SQLXML Script Injection Vulnerability
22949| [21540] Microsoft SQL Server 2000 SQLXML Buffer Overflow Vulnerability
22950| [21389] Microsoft Windows 2000 Lanman Denial of Service Vulnerability (2)
22951| [21388] Microsoft Windows 2000 Lanman Denial of Service Vulnerability (1)
22952| [21344] Microsoft Windows 2000 / NT 4.0 Process Handle Local Privilege Elevation Vulnerability
22953| [21258] Microsoft Windows 2000/NT 4 NTFS File Hiding Vulnerability
22954| [21246] Microsoft Windows 2000/NT 4 TCP Stack DoS Vulnerability (2)
22955| [21245] Microsoft Windows 2000/NT 4 TCP Stack DoS Vulnerability (1)
22956| [21172] Microsoft Windows 2000 Internet Key Exchange DoS Vulnerability (2)
22957| [21171] Microsoft Windows 2000 Internet Key Exchange DoS Vulnerability (1)
22958| [21131] Microsoft Windows 2000/XP GDI Denial of Service Vulnerability
22959| [21123] Microsoft Windows 2000/NT Terminal Server Service RDP DoS Vulnerability
22960| [21113] Microsoft Index Server 2.0 File Information and Path Disclosure Vulnerability
22961| [21099] Microsoft Windows 2000 RunAs Service Denial of Services Vulnerability
22962| [21069] Microsoft Windows 2000 RunAs Service Named Pipe Hijacking Vulnerability
22963| [20907] Microsoft Windows 2000 Telnet Username DoS Vulnerability
22964| [20802] Microsoft IIS 2.0/3.0 Long URL Denial of Service Vulnerability
22965| [20763] Microsoft ISA Server 2000 Web Proxy DoS Vulnerability
22966| [20571] Microsoft Outlook 2000 0/98 0/Express 5.5 Concealed Attachment Vulnerability
22967| [20481] Microsoft IIS 2.0/3.0 Appended Dot Script Source Disclosure Vulnerability
22968| [20399] Microsoft Indexing Services for Windows 2000 File Verification Vulnerability
22969| [20335] Microsoft Indexing Services for Windows 2000/NT 4.0 .htw Cross-Site Scripting Vulnerability
22970| [20305] Microsoft Site Server 2.0 with IIS 4.0 - File Upload Vulnerability
22971| [20265] Microsoft Windows NT 4.0 / 2000 Spoofed LPC Request Vulnerability
22972| [20257] Microsoft Windows NT 4.0 / 2000 Predictable LPC Message Identifier Multiple Vulnerabilities
22973| [20255] Microsoft Windows NT 4.0 / 2000 LPC Zone Memory Depletion DoS Vulnerability
22974| [20222] Microsoft Windows 2000 telnet.exe NTLM Authentication Vulnerability
22975| [20209] Microsoft Windows 2000 Still Image Service Privilege Escalation Vulnerability
22976| [20133] Microsoft Windows 2000 Named Pipes Predictability Vulnerability
22977| [20122] Microsoft Office SharePoint Server 2007 Remote Code Execution
22978| [20096] Microsoft IIS 2.0/3.0/4.0/5.0/5.1 Internal IP Address Disclosure Vulnerability
22979| [20048] Microsoft Windows 2000 Remote CPU-overload Vulnerability
22980| [20047] Microsoft Windows 2000 Telnet Server DoS Vulnerability
22981| [19830] Microsoft Index Server 2.0 '%20' ASP Source Disclosure Vulnerability
22982| [19742] microsoft iis 3.0/4.0,microsoft index server 2.0 - Directory Traversal
22983| [19734] Microsoft Virtual Machine 2000 Series/3000 Series getSystemResource Vulnerability
22984| [19731] microsoft index server 2.0/indexing services for windows 2000 - Directory Traversal
22985| [19728] Microsoft Systems Management Server 2.0 Default Permissions Vulnerability
22986| [19425] Microsoft Data Access Components (MDAC) <= 2.1,Microsoft IIS 3.0/4.0,Microsoft Index Server 2.0,Microsoft Site Server Commerce Edition 3.0 i386 MDAC RDS Vulnerability (2)
22987| [19424] Microsoft Data Access Components (MDAC) <= 2.1,Microsoft IIS 3.0/4.0,Microsoft Index Server 2.0,Microsoft Site Server Commerce Edition 3.0 i386 MDAC RDS Vulnerability (1)
22988| [19376] Microsoft IIS 2.0/3.0/4.0 ISAPI GetExtensionVersion() Vulnerability
22989| [19143] "Microsoft Windows ""April Fools 2001"" Vulnerability"
22990| [19118] Microsoft IIS 3.0/4.0,Microsoft Personal Web Server 2.0/3.0/4.0 ASP Alternate Data Streams Vulnerability
22991| [18334] Microsoft Office 2003 Home/Pro 0day
22992| [18087] MS11-021 Microsoft Office 2007 Excel .xlb Buffer Overflow
22993| [18078] Microsoft Excel 2003 11.8335.8333 Use After Free
22994| [18067] Microsoft Excel 2007 SP2 Buffer Overwrite Exploit
22995| [17305] "Microsoft Windows Vista/Server 2008 ""nsiproxy.sys"" Local Kernel DoS Exploit"
22996| [14971] MOAUB #11 - Microsoft Office Word 2007 sprmCMajority Buffer Overflow
22997| [14782] Microsoft Office PowerPoint 2007 DLL Hijacking Exploit (rpawinet.dll)
22998| [14746] Microsoft Office Groove 2007 DLL Hijacking Exploit (mso.dll)
22999| [14744] Microsoft Visio 2003 DLL Hijacking Exploit (mfc71enu.dll)
23000| [12450] Microsoft SharePoint Server 2007 XSS Vulnerability
23001| [10068] Microsoft Windows 2000-2008 Embedded OpenType Font Engine Remote Code Execution
23002| [4121] Microsoft Excel 2000/2003 Sheet Name Vulnerability PoC
23003| [3973] Microsoft Office 2000 (OUACTRL.OCX 1.0.1.9) - Remote DoS Exploit
23004| [3690] microsoft office word 2007 - Multiple Vulnerabilities
23005| [3260] Microsoft Word 2000 Unspecified Code Execution Exploit (0day)
23006| [2523] Microsoft Office 2003 PPT Local Buffer Overflow PoC
23007| [2091] Microsoft PowerPoint 2003 SP2 Local Code Execution Exploit (french)
23008| [2001] Microsoft Word 2000/2003 Unchecked Boundary Condition Vulnerability
23009| [1999] Microsoft Word 2000/2003 Hlink Local Buffer Overflow Exploit PoC
23010| [1988] Microsoft Excel 2003 Hlink Local Buffer Overflow Exploit (italian)
23011| [1986] Microsoft Excel 2000/2003 Hlink Local Buffer Overflow Exploit (french)
23012| [1958] Microsoft Excel 2003 Hlink Stack/SEH Buffer Overflow Exploit
23013| [28238] Microsoft SharePoint 2013 (Cloud) - Persistent Exception Handling Vulnerability MS13-067
23014| [23034] Microsoft URLScan 2.5/ RSA Security SecurID 5.0 Configuration Enumeration Weakness
23015| [22850] Microsoft Office OneNote 2010 Crash PoC
23016| [22679] Microsoft Visio 2010 Crash PoC
23017| [22655] Microsoft Publisher 2013 Crash PoC
23018| [22621] Microsoft Netmeeting 2.1/3.0.1 4.4.3385 CALLTO URL Buffer Overflow Vulnerability
23019| [22330] Microsoft Office Excel 2010 Crash PoC
23020| [22310] Microsoft Office Publisher 2010 Crash PoC
23021| [22237] Microsoft Office Picture Manager 2010 Crash PoC
23022| [22215] Microsoft Office Word 2010 Crash PoC
23023| [19451] Microsoft Windows 98 a/98 b/98SE,Solaris 2.6 IRDP Vulnerability
23024| [19440] Microsoft Windows NT 4.0/SP 1/SP 2/Sp 3/SP 4/SP 5 Malformed Dialer Entry Vulnerability
23025| [19372] Microsoft Windows NT 4.0/SP 1/SP 2/SP 3/SP 4/SP 5 Null Session Admin Name Vulnerability
23026| [17164] Microsoft Reader <= 2.1.1.3143 NULL Byte Write
23027| [17163] Microsoft Reader <= 2.1.1.3143 Array Overflow
23028| [17162] Microsoft Reader <= 2.1.1.3143 Integer Overflow
23029| [17161] Microsoft Reader <= 2.1.1.3143 Heap Overflow
23030| [17160] Microsoft Reader <= 2.1.1.3143 Integer Overflow
23031| [14731] Microsoft Windows Movie Maker <= 2.6.4038.0 DLL Hijacking Exploit (hhctrl.ocx)
23032| [14723] Microsoft Power Point 2010 DLL Hijacking Exploit (pptimpconv.dll)
23033|
23034| OpenVAS (Nessus) - http://www.openvas.org:
23035| [902250] Microsoft Word 2003 'MSO.dll' Null Pointer Dereference Vulnerability
23036| [900125] Microsoft SQL Server 2000 sqlvdir.dll ActiveX Buffer Overflow Vulnerability
23037| [801597] Microsoft Office Excel 2003 Invalid Object Type Remote Code Execution Vulnerability
23038| [801596] Microsoft Excel 2007 Office Drawing Layer Remote Code Execution Vulnerability
23039| [801594] Microsoft PowerPoint 2007 OfficeArt Atom Remote Code Execution Vulnerability
23040| [800687] Microsoft Windows Server 2003 OpenType Font Engine DoS Vulnerability
23041| [800577] Microsoft Windows Server 2003 win32k.sys DoS Vulnerability
23042| [800343] Microsoft Word 2007 Sensitive Information Disclosure Vulnerability
23043| [103254] Microsoft SharePoint Server 2007 '_layouts/help.aspx' Cross Site Scripting Vulnerability
23044| [11992] Vulnerability in Microsoft ISA Server 2000 H.323 Filter(816458)
23045| [902931] Microsoft Office Remote Code Execution Vulnerabilities - 2720184 (Mac OS X)
23046| [902678] Microsoft Silverlight Code Execution Vulnerabilities - 2681578 (Mac OS X)
23047| [901210] Microsoft Office Privilege Elevation Vulnerability - 2721015 (Mac OS X)
23048|
23049| SecurityTracker - https://www.securitytracker.com:
23050| [1015347] Microsoft Windows 2000 Kernel APC Queue Bug Lets Local Users Gain Elevated Privileges
23051| [1013454] Microsoft Office InfoPath 2003 May Disclose System and Authentication Information to Remote Users
23052| [1013284] Microsoft Windows 2000 and XP Group Policy Can Be Bypassed By Microsoft Office Applications and By Flash Drives
23053| [1010687] Microsoft Windows 2000/NT POSIX Subsystem Buffer Overflow Lets Local Users Gain Elevated Privileges
23054| [1010352] Microsoft Windows 2000 Domains With Eight Characters May Let Remote Users With Expired Passwords Login
23055| [1010189] Microsoft Outlook 2003 Scripting Restrictions Can Be Bypassed By Remote Users
23056| [1010125] Microsoft Outlook 2003 Lets Remote Users Send E-mail to Cause the Recipient's Client to Contact a Remote Server
23057| [1009767] Microsoft Windows 2000 Domain Controller LDAP Flaw May Let Remote Users Restart the Authentication Service
23058| [1008324] Microsoft Exchange 2003 With Outlook Web Access and Windows SharePoint Services May Grant Incorrect E-mail Account Access to Remote Authenticated Users
23059| [1007905] Microsoft Windows Server 2003 Shell Folders Can Be Referenced Using Directory Traversal Characters
23060| [1007238] Microsoft Outlook Web Access Can Be Crashed By Remote Authenticated Users With an Outlook 2003 Client
23061| [1007152] Microsoft Windows 2000 Accessibility Utility Manager Lets Local Users Gain Elevated Privileges
23062| [1007099] Microsoft Windows 2000 ShellExecute() Buffer Overflow May Let Users Execute Arbitrary Code
23063| [1007093] Microsoft Active Directory Stack Overflow in 'Lsaas.exe' Lets Remote Users Crash the Windows 2000 Server
23064| [1006959] Microsoft Windows Server 2003 Drivers May Leak Information From Memory Via Ethernet Packets Containing TCP Streams
23065| [1006580] Microsoft Windows 2003 'win2k.sys' Printing Bug Lets Users Crash the System
23066| [1006534] Microsoft Proxy Service in Proxy Server 2.0 Has Unspecified Flaw That Lets Remote Users Stop Traffic
23067| [1006286] Microsoft Windows 2000/XP PostMessage() API Flaw May Let Local Users Grab Passwords from Local Dialog Boxes
23068| [1006280] Protegrity Secure.Data for Microsoft SQL Server 2000 Contains Buffer Oveflows That Let Remote Users Execute Arbitrary Code
23069| [1005254] Microsoft NT, 2000, and XP Operating Systems May Execute a 16-bit Application Even When The File Has No Execute Permissions
23070| [1005068] Microsoft NTFS Filesystem in Windows NT and Windows 2000 Has Auditing Hole That Lets Local Users Access Files Without the File Access Being Audited
23071| [1004587] Microsoft SQL Server 2000 Buffer Overflow in OpenDataSource() Function May Let Remote Users Gain SYSTEM Privileges on the Server
23072| [1004528] Microsoft SQLXML Component of Microsoft SQL Server 2000 Contains an Input Validation Flaw in an XML SQL Tag That Allows Cross-Site Scripting Attacks
23073| [1004527] Microsoft SQLXML Component of Microsoft SQL Server 2000 Contains a Buffer Overflow That Lets Remote Users Take Full Control of the System
23074| [1004407] Microsoft Exchange 2000 Flaw in Processing a Certain Malformed SMTP Command Allows Remote Users to Deny Service to the Server
23075| [1004357] Microsoft Windows Debugging Facility for Windows NT4 and 2000 Has Authentication Hole That Lets Local Users Execute Arbitrary Code with SYSTEM Privileges
23076| [1004083] Microsoft Windows 2000 'microsoft-ds' Service Flaw Allows Remote Users to Create Denial of Service Conditions By Sending Malformed Packets
23077| [1004022] Microsoft Windows 2000 Group Policy Object Enforcement Can Be Circumvented if User License Limits are Exceeded
23078| [1003975] Microsoft Windows NT, 2000, and XP Kernel Buffer Overflow in Processing Multiple UNC Provider (MUP) Requests May Let Local Users Obtain System Level Privileges
23079| [1003949] Microsoft Windows 2000 DCOM Implementation Flaw May Disclose Memory Contents to Remote Users
23080| [1003816] Microsoft Windows 2000 Automatic Log Off Policy Fails to Expire Sessions in Progress
23081| [1003688] Microsoft Exchange Server 2000 Command Processing Bug Lets Remote Users Cause the SMTP Service to Crash
23082| [1003687] Microsoft Windows 2000 and Windows XP SMTP Service Command Processing Bug Lets Remote Users Cause the SMTP Service to Crash
23083| [1003634] Microsoft XML Core Services in SQL Server 2000 Lets Remote Scripts Access and Send Local Files
23084| [1003629] Microsoft Commerce Server 2000 AuthFilter Buffer Overflow Lets Remote Users Execute Arbitrary Code on the Server With LocalSystem Privileges to Gain Full Control of the Server
23085| [1003472] Microsoft Telnet Server for Windows 2000 and for Interix Has a Buffer Overflow That May Let Remote Users Execute Code on the Server with System Level Privileges
23086| [1003469] Microsoft Exchange 2000 Server Allows Remote Users to View and Possibly Modify Registry Settings
23087| [1003402] Microsoft Windows NT 4.0 and Windows 2000 Domain Controllers May Give Elevated Privileges to Remote Users Who Are Valid Administrators on Other Trusted Domains
23088| [1002922] Microsoft Windows 2000 Internet Key Exchange (IKE) Service Can Be Crashed By Remote Users
23089| [1002754] Terminal Services on Microsoft Windows 2000 and XP Allow Remote Users to Log Bogus IP Addresses Instead of the User's Genuine Address
23090| [1002731] Microsoft Windows 2000 RunAs Service May Disclose Authentication Credentials to Local Users
23091| [1002730] Microsoft Windows 2000 RunAs Utility May Disclose Sensitive Information to Local Users
23092| [1002729] Microsoft Windows 2000 RunAs Service Allows Local Users to Disable the Service
23093| [1002356] Microsoft Outlook 2000 Animated Assistant Prevents the Screen Saver from Activating, Allowing Physically Local Users to Access the System
23094| [1002206] Microsoft Internet Security and Acceleration (ISA) Server 2000 Can Be Disrupted By Remote Users Due to Memory Leaks and Also Allows Cross-Site Scripting Attacks
23095| [1002106] Microsoft Windows 2000 and Windows NT 4.0 RPC Input Validation Failure Lets Remote Users Destabilize the Operating System
23096| [1002099] Microsoft Windows 2000 Telnet Service Can Be Crashed By Remote Users
23097| [1002098] Windows Terminal Services in Microsoft Windows 2000 and NT 4.0 Can Be Crashed By Remote Users Due to a Memory Leak
23098| [1001993] Microsoft Windows 2000, Linux 2.4, NetBSD, FreeBSD, and OpenBSD May Let Remote Users Affect TCP Performance
23099| [1001931] Microsoft Windows 2000 SMTP Service May Allow Unauthorized Remote Users to Relay E-mail via the Service
23100| [1001832] Microsoft Windows 2000 LDAP Server Lets Remote Users Gain Administrator Access to the Domain Controller When Configured to Support LDAP over SSL
23101| [1001701] Microsoft Windows 2000 Telnet Server Allows Local Users to Gain System-Level Privileges and Lets Remote Users Crash the Server
23102| [1001605] Microsoft Windows 2000 Allows Local Users to Elevate Privileges
23103| [1001565] Microsoft IIS Web Server on Windows 2000 Allows Remote Users to Cause the Server to Consume All Available Memory Due to Memory Leak in WebDAV Lock Method
23104| [1001513] Microsoft Windows 2000 Indexing Service Allows Remote Users to View Include Programming Files
23105| [1001501] Microsoft Windows 2000 Domain Controllers Can Be Effectively Halted By Remote Users
23106| [1001464] Microsoft Internet Information Server IIS 5.0 for Windows 2000 Lets Remote Users Execute Arbitrary Code on the Server and Gain Control of the Server
23107| [1001240] Microsoft FTP Client for Windows 2000 Still Vulnerable to Executing Arbitrary Code in Limited Situations
23108| [1001088] Microsoft Internet Explorer with Services for Unix 2.0 Can Create Malicious Files on the User's Host
23109|
23110| OSVDB - http://www.osvdb.org:
23111| [90257] Microsoft Windows Server 2003 ICACLS.EXE Permission Inheritance Weakness
23112| [86790] Microsoft Virtual PC 2007 Crafted x86 Instruction Sequence Handling Local DoS
23113| [86061] Microsoft Windows Server 2008 R1 CSRSS ReadConsole / CloseHandle Local DoS
23114| [79442] Microsoft Windows Server 2008 DNS Server Service Cache Update Policy Deleted Domain Name Resolving Weakness
23115| [72670] Microsoft Windows Server 2003 ActiveDirectory BROWSER ELECTION Remote Overflow
23116| [68554] Microsoft Windows Server 2008 Shared Cluster Disks Addition Default Permission Weakness
23117| [62251] Microsoft Windows Server 2008 Hyper-V Crafted Instruction Sequence DoS
23118| [60329] Microsoft Windows 2000 NetBIOS Continuation Packet Remote DoS
23119| [59733] Microsoft Windows 2000 Terminal Services Screensaver Screen Minimization Locking Weakness
23120| [59731] Microsoft Windows 2000 DCOM Client Alter Context Request Remote Information Disclosure
23121| [59730] Microsoft Windows 2000 Terminal Services Disconnect Feature Local Privilege Escalation
23122| [59514] Microsoft Windows 2000 Task Manager Uppercase Process Name Termination Weakness
23123| [59509] Microsoft Windows 2000 Encrypted File System Cleartext Backup File Local Disclosure
23124| [59346] Microsoft Windows 2000 Crafted TCP/UDP Traffic CPU Consumption Remote DoS
23125| [55836] Microsoft ISA Server 2006 Radius OTP Security Bypass
23126| [53663] Microsoft Office Word 2000 WordPerfect 6.x Converter Document Handling Stack Corruption
23127| [50589] Microsoft SQL Server 2000 sp_replwritetovarbin() Stored Procedure Overflow
23128| [37629] Microsoft Windows 2000 RPC Authentication Unspecified Information Disclosure
23129| [37628] Microsoft Windows 2000 RPC Authentication Crafted Request Remote DoS
23130| [36034] Microsoft Office 2000 Controllo ActiveX (OUACTRL.OCX) HelpPopup Method Overflow
23131| [34489] Microsoft Office 2003 Malformed WMF File Handling DoS
23132| [34488] Microsoft Excel 2003 XLS Handling Corrupt Format DoS
23133| [31251] Microsoft Office 2003 Brazilian Portuguese Grammar Checker Arbitrary Code Execution
23134| [29529] Microsoft Windows 2000 creator.dll ActiveX COM Object Memory Corruption
23135| [29528] Microsoft Windows 2000 msdxm.ocx ActiveX COM Object Memory Corruption
23136| [29527] Microsoft Windows 2000 myinfo.dll ActiveX COM Object Memory Corruption
23137| [29526] Microsoft Windows 2000 ciodm.dll ActiveX COM Object Memory Corruption
23138| [28539] Microsoft Word 2000 Unspecified Code Execution
23139| [24121] Microsoft Commerce Server 2002 authfiles/login.asp Authentication Bypass
23140| [24081] Microsoft Outlook 2003 Unspecified Malformed Word Attachment DoS
23141| [23484] Microsoft SQLServer 2000 sp_addalias Procedure Privileged Alias Creation
23142| [23234] Microsoft SQLServer 2000 Unspecified Invalid Client Buffer DoS
23143| [23231] Microsoft SQL Server 2000 SQL Profiler Multiple Method DoS
23144| [23205] Microsoft SQLServer 2000 Crafted Sort Command User Mode Scheduler (UMS) Bypass DoS
23145| [23203] Microsoft SQL Server 2000 Database Name Transact-SQL Statement Privilege Escalation
23146| [23202] Microsoft SQLServer 2000 sysmembers Virtual Table Query Overflow
23147| [23201] Microsoft SQL Server 2000 Dynamic Transact-SQL Statement Disclosure
23148| [23200] Microsoft SQLServer 2000 Encrypted Stored Procedure Dynamic Query Disclosure
23149| [21907] Microsoft Office InfoPath 2003 Mshtml.dll Form Handling DoS
23150| [21598] Microsoft Windows 2000 NetBIOS Port Malformed TCP Packet Parsing Remote DoS
23151| [20256] Microsoft Windows 2000 NTFS Volume Macintosh Client Directory Permission Modification
23152| [20222] Microsoft Windows 2000 runas.exe Named Pipe Spoofing Information Disclosure
23153| [20221] Microsoft Windows 2000 runas.exe Named Pipe Single Thread DoS
23154| [20220] Microsoft Windows 2000 runas.exe Cleartext Authentication Information Disclosure
23155| [20002] Microsoft Windows 2000 CHKDSK Fix Mode File ACL Failure
23156| [20001] Microsoft Windows 2000 Terminal Service Client Connection IP Logging Failure
23157| [20000] Microsoft Windows 2000 Domain Administrator Computer Lock Bypass
23158| [19999] Microsoft Windows 2000 FQDN Domain Login Password Expiry Bypass
23159| [19998] Microsoft Windows 2000 UPN Credentialed Login Group Policy Failure
23160| [19997] Microsoft Windows 2000 WideCharToMultiByte Function String Termination Issue
23161| [19996] Microsoft Windows 2000 Event ID 1704 Group Policy Failure
23162| [19995] Microsoft Windows 2000 SECEDIT Long Folder ACL Set Issue
23163| [19994] Microsoft Windows 2000 audit directory service access 565 Event Logging Failure
23164| [19993] Microsoft Windows 2000 LDAPS CA Trust Issue
23165| [19264] Microsoft Exchange Server 2003 Crafted IMAP4 Folder Listing Request DoS
23166| [17031] Microsoft ISA Server 2000 SecureNAT Traffic Saturation DoS
23167| [15343] Microsoft Windows Server 2003 Malformed HTTP Cookie Header CGI DoS
23168| [15341] Microsoft Windows Server 2003 SMB Redirector Processing DoS
23169| [15340] Microsoft Windows Server 2003 Terminal Service Client Print DoS
23170| [15338] Microsoft Windows Server 2003 Terminal Session Close DoS
23171| [15337] Microsoft Windows Server 2003 CreateProcessWithLogonW() Function Process Disclosure
23172| [15336] Microsoft Windows Server 2003 Shutdown.exe Shut Down Failure
23173| [15335] Microsoft Windows Server 2003 MIT Kerberos Realm Authentication Group Policy Failure
23174| [15334] Microsoft Windows Server 2003 Shared Folder Permission Weakness
23175| [15333] Microsoft Windows Server 2003 EFS File Copy LDAP Connection DoS
23176| [15332] Microsoft Windows Server 2003 Citrix Metaframe Encryption Policy Failure
23177| [15331] Microsoft Windows Server 2003 Home Folder Path Permission Inheritance Failure
23178| [14617] Microsoft Exchange Server 2003 Folder Handling DoS
23179| [14430] Microsoft Commerce Server 2000 Profile Service Affected API Overflow
23180| [13996] Microsoft Windows 2000 IKE Malformed Packet Saturation Remote DoS
23181| [13762] Microsoft 2000 Domain Controller Directory Service Restore Mode Blank Password
23182| [13761] Microsoft Exchange 2000 Malformed URL Request DoS
23183| [13475] Microsoft Windows 2000 Telnet Service Predictable Named Pipe Arbitrary Command Execution Variant
23184| [13474] Microsoft Windows 2000 Telnet Service Predictable Named Pipe Arbitrary Command Execution
23185| [13441] Microsoft Windows 2000 Security Interface Change Password Option Account Enumeration
23186| [13437] Microsoft Windows 2000 Debug Register Local Privilege Escalation
23187| [13424] Microsoft Windows 2000 Current Password Change Policy Bypass
23188| [13423] Microsoft Windows 2000 Terminal Server SYSVOL Share Connection Saturation Restriction Bypass
23189| [13415] Microsoft Windows 2000 System Root Folder Search Path Permission Weakness
23190| [13410] Microsoft Windows 2000 Accessibility Utility Manager Arbitrary Code Execution
23191| [11958] Microsoft Outlook 2003 Image Rendering Security Policy Bypass
23192| [11945] Microsoft Outlook 2002 IFRAME Tag Embedded URL
23193| [11944] Microsoft Outlook 2002 HREF Tag Embedded JavaScript Execution
23194| [11750] Microsoft Windows 2000 Message Queue Manager Queue Registration Request Overflow DoS
23195| [11712] Microsoft ISA Server 2000 H.323 Filter Overflow
23196| [10633] Microsoft Windows 2000 Protected Store Weak Encryption Default
23197| [9386] Microsoft Windows 2000 msinfo32.exe msinfo_file Variable Overflow
23198| [8243] Microsoft SMS Port 2702 DoS
23199| [7202] Microsoft PowerPoint 2000 File Loader Overflow
23200| [7179] Microsoft Windows 2000 Event Viewer Snap-in Overflow
23201| [6971] Microsoft ISA Server 2000 ICMP Rule Bypass During Startup
23202| [6970] Microsoft ISA Server 2000 Web Publishing Unencrypted Credentials Disclosure
23203| [6969] Microsoft ISA Server 2000 Invalid DNS Request DoS
23204| [6968] Microsoft ISA Server 2000 FTP Port Scan Bounce Weakness
23205| [6967] Microsoft ISA Server 2000 UDP Packet Winsock DoS
23206| [6965] Microsoft ISA Server 2000 SSL Packet DoS
23207| [6964] Microsoft ISA Server 2000 DNS Intrusion Detection Filter DoS
23208| [6515] Microsoft Windows 2000 Domain Expired Account Authentication
23209| [5179] Microsoft Windows 2000 microsoft-ds DoS
23210| [5171] Microsoft Word 2002 Mail Merge Tool Execute Arbitrary Script
23211| [4779] Microsoft Desktop Engine (MSDE) 2000 Stored Procedure SQL Injection
23212| [4778] Microsoft SQL Server 2000 Stored Procedure SQL Injection
23213| [4777] Microsoft Desktop Engine (MSDE) 2000 Database Consistency Checkers (DBCCs) Overflow
23214| [4776] Microsoft SQL Server 2000 Database Consistency Checkers (DBCCs) 2000 Overflow
23215| [4170] Microsoft Windows 2000 Server Media Services TCP Packet Handling Remote DoS
23216| [4168] Microsoft Outlook 2002 mailto URI Script Injection
23217| [3490] Microsoft Exchange 2003 OWA Mailbox Access Information Disclosure
23218| [2705] Microsoft Windows 2000 Windows Troubleshooter ActiveX Overflow
23219| [2655] Microsoft Windows Server 2003 Shell Folders Arbitrary File Access
23220| [2540] Microsoft Windows 2003 Server Buffer Overflow Protection Mechanism Bypass
23221| [2244] Microsoft Windows 2000 ShellExecute() API Let
23222| [2237] Microsoft Windows 2000 Active Directory Lsass.exe Overflow
23223| [1949] Symantec Norton Anti-Virus for Microsoft Exchange 2000 INBOX Path Information Disclosure
23224| [1764] Microsoft Windows 2000 Domain Controller DoS
23225| [1758] Microsoft Windows 2000 Network DDE Escalated Privileges
23226| [1755] Microsoft Windows 2000 RDP Malformed Packet Handling Remote DoS
23227| [1672] Microsoft Windows 2000 Telnet Session Timeout DoS
23228| [1633] Microsoft Windows 2000 System Monitor ActiveX LogFileName Parameter Validation Overflow
23229| [1621] Microsoft Indexing Services for Windows 2000 .htw XSS
23230| [1591] Microsoft Windows 2000 OEMPreinstall Installation Permission Weakness
23231| [1578] Microsoft Windows 2000 Simplified Chinese IME Local Privilege Escalation
23232| [1500] Microsoft Word / Excel / Powerpoint 2000 Object Tag Buffer Overflow
23233| [1437] Microsoft Windows 2000 Telnet Server Binary Zero Parsing Remote DoS
23234| [1399] Microsoft Windows 2000 Windows Station Access
23235| [1328] Microsoft Office 2000 UA Control ActiveX (Ouactrl.ocx) Show Me Function Remote Code Execution
23236| [1297] Microsoft Windows 2000 Active Directory Object Attribute
23237| [1292] Microsoft Windows NT 4.0 / 2000 cmd.exe Buffer Overflow
23238| [773] Microsoft Windows 2000 Group Policy File Lock DoS
23239| [515] Microsoft Windows 2000 LDAP Server Arbitrary User Password Modification
23240| [454] Microsoft Windows 2000 NTLM Domain Account Lockout Policy Bypass
23241| [403] Microsoft Windows 2000 Still Image Service WM_USER Message Local Overflow
23242| [398] Microsoft Windows 2000 Malformed RPC Traffic Local Security Policy Corruption DoS
23243| [307] Microsoft FrontPage 2000 Server Extensions shtml.exe Path Disclosure
23244| [69085] Microsoft Office 2010 RTF File Handling pFragments Buffer Overflow Arbitrary Code Execution
23245|_
23246445/tcp closed microsoft-ds
23247Device type: general purpose|WAP
23248Running (JUST GUESSING): Linux 2.6.X|2.4.X (90%), Microsoft Windows 2012 (85%)
23249OS CPE: cpe:/o:linux:linux_kernel:2.6 cpe:/o:linux:linux_kernel:2.4.20 cpe:/o:microsoft:windows_server_2012:r2
23250Aggressive OS guesses: Linux 2.6.18 - 2.6.22 (90%), Tomato 1.27 - 1.28 (Linux 2.4.20) (86%), Microsoft Windows Server 2012 or Windows Server 2012 R2 (85%), Microsoft Windows Server 2012 R2 (85%)
23251No exact OS matches for host (test conditions non-ideal).
23252Uptime guess: 15.009 days (since Fri Sep 27 09:10:44 2019)
23253Network Distance: 2 hops
23254TCP Sequence Prediction: Difficulty=263 (Good luck!)
23255IP ID Sequence Generation: Incremental
23256Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
23257
23258TRACEROUTE (using port 445/tcp)
23259HOP RTT ADDRESS
232601 54.98 ms 10.243.204.1
232612 36.72 ms a67-209-250-173.cust.mi.winntel.net (67.209.250.173)
23262
23263NSE: Script Post-scanning.
23264Initiating NSE at 09:23
23265Completed NSE at 09:23, 0.00s elapsed
23266Initiating NSE at 09:23
23267Completed NSE at 09:23, 0.00s elapsed
23268#######################################################################################################################################
23269Starting Nmap 7.80 ( https://nmap.org ) at 2019-10-12 09:23 EDT
23270NSE: Loaded 47 scripts for scanning.
23271NSE: Script Pre-scanning.
23272Initiating NSE at 09:23
23273Completed NSE at 09:23, 0.00s elapsed
23274Initiating NSE at 09:23
23275Completed NSE at 09:23, 0.00s elapsed
23276Initiating Parallel DNS resolution of 1 host. at 09:23
23277Completed Parallel DNS resolution of 1 host. at 09:23, 0.02s elapsed
23278Initiating UDP Scan at 09:23
23279Scanning a67-209-250-173.cust.mi.winntel.net (67.209.250.173) [15 ports]
23280Completed UDP Scan at 09:23, 1.68s elapsed (15 total ports)
23281Initiating Service scan at 09:23
23282Scanning 13 services on a67-209-250-173.cust.mi.winntel.net (67.209.250.173)
23283Service scan Timing: About 7.69% done; ETC: 09:44 (0:19:36 remaining)
23284Completed Service scan at 09:24, 102.60s elapsed (13 services on 1 host)
23285Initiating OS detection (try #1) against a67-209-250-173.cust.mi.winntel.net (67.209.250.173)
23286Retrying OS detection (try #2) against a67-209-250-173.cust.mi.winntel.net (67.209.250.173)
23287Initiating Traceroute at 09:25
23288Completed Traceroute at 09:25, 7.07s elapsed
23289Initiating Parallel DNS resolution of 1 host. at 09:25
23290Completed Parallel DNS resolution of 1 host. at 09:25, 0.00s elapsed
23291NSE: Script scanning 67.209.250.173.
23292Initiating NSE at 09:25
23293Completed NSE at 09:25, 7.13s elapsed
23294Initiating NSE at 09:25
23295Completed NSE at 09:25, 1.01s elapsed
23296Nmap scan report for a67-209-250-173.cust.mi.winntel.net (67.209.250.173)
23297Host is up (0.035s latency).
23298
23299PORT STATE SERVICE VERSION
2330053/udp open|filtered domain
2330167/udp open|filtered dhcps
2330268/udp open|filtered dhcpc
2330369/udp open|filtered tftp
2330488/udp open|filtered kerberos-sec
23305123/udp open|filtered ntp
23306137/udp filtered netbios-ns
23307138/udp filtered netbios-dgm
23308139/udp open|filtered netbios-ssn
23309161/udp open|filtered snmp
23310162/udp open|filtered snmptrap
23311389/udp open|filtered ldap
23312500/udp open|filtered isakmp
23313|_ike-version: ERROR: Script execution failed (use -d to debug)
23314520/udp open|filtered route
233152049/udp open|filtered nfs
23316Too many fingerprints match this host to give specific OS details
23317
23318TRACEROUTE (using port 138/udp)
23319HOP RTT ADDRESS
233201 43.34 ms 10.243.204.1
233212 ... 3
233224 40.89 ms 10.243.204.1
233235 37.10 ms 10.243.204.1
233246 37.11 ms 10.243.204.1
233257 37.12 ms 10.243.204.1
233268 37.12 ms 10.243.204.1
233279 37.13 ms 10.243.204.1
2332810 37.17 ms 10.243.204.1
2332911 ... 18
2333019 26.32 ms 10.243.204.1
2333120 42.72 ms 10.243.204.1
2333221 31.82 ms 10.243.204.1
2333322 ... 29
2333430 17.36 ms 10.243.204.1
23335
23336NSE: Script Post-scanning.
23337Initiating NSE at 09:25
23338Completed NSE at 09:25, 0.00s elapsed
23339Initiating NSE at 09:25
23340Completed NSE at 09:25, 0.00s elapsed
23341Read data files from: /usr/bin/../share/nmap
23342OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
23343Nmap done: 1 IP address (1 host up) scanned in 122.69 seconds
23344 Raw packets sent: 150 (10.432KB) | Rcvd: 108 (13.008KB)
23345#######################################################################################################################################
23346Hosts
23347=====
23348
23349address mac name os_name os_flavor os_sp purpose info comments
23350------- --- ---- ------- --------- ----- ------- ---- --------
2335167.209.250.173 a67-209-250-173.cust.mi.winntel.net Linux 2.6.X server
23352
23353Services
23354========
23355
23356host port proto name state info
23357---- ---- ----- ---- ----- ----
2335867.209.250.173 25 tcp smtp closed
2335967.209.250.173 53 udp domain unknown
2336067.209.250.173 67 udp dhcps unknown
2336167.209.250.173 68 udp dhcpc unknown
2336267.209.250.173 69 udp tftp unknown
2336367.209.250.173 80 tcp http open Microsoft HTTPAPI httpd 2.0 SSDP/UPnP
2336467.209.250.173 88 udp kerberos-sec unknown
2336567.209.250.173 113 tcp ident closed
2336667.209.250.173 123 udp ntp unknown
2336767.209.250.173 137 udp netbios-ns filtered
2336867.209.250.173 138 udp netbios-dgm filtered
2336967.209.250.173 139 tcp netbios-ssn closed
2337067.209.250.173 139 udp netbios-ssn unknown
2337167.209.250.173 161 udp snmp unknown
2337267.209.250.173 162 udp snmptrap unknown
2337367.209.250.173 389 udp ldap unknown
2337467.209.250.173 443 tcp ssl/http open Microsoft HTTPAPI httpd 2.0 SSDP/UPnP
2337567.209.250.173 445 tcp microsoft-ds closed
2337667.209.250.173 500 udp isakmp unknown
2337767.209.250.173 520 udp route unknown
2337867.209.250.173 2049 udp nfs unknown
23379#######################################################################################################################################
23380 Anonymous #OpKilluminati JTSEC Full Recon #18